So many organizations struggle with policy exceptions. While exceptions are a reality, the prevalence of them leads one to believe that risk management is not quite working.
While organizations try to pivot from risk to compliance focal points to enforce adherance to security / privacy best practices, the reality is that most entities are not agile, and they also lack the resources to migrate from legacy workdlows to secure processes and systems.
While the cloud and ITO / BPO of the past have promised more agility, many orgs leverage traditional internal models due to cost constraints.
GRC, risk management, and IT audit professionals have a legit argument to focus on policies, standards, and guidelines; however, for orgs to be and remain secure these days, an offensive, proactive model is more of a necessity.
Showing posts with label GRC. Show all posts
Showing posts with label GRC. Show all posts
Tuesday, August 8, 2017
Friday, September 16, 2016
Leveraging ITIL PPT for GRC, TVM, & DevSecOps / InfoSecOps
Many orgs now have some form of ITIL investment (PPT) in place (e.g., ServiceNow: SNOW, ServiceDesk, SAP Ariba) these days.
Why not leverage that for PCI DSS / GPDR / HIPAA / Privacy Shield compliance, let alone for other purposes (e.g., TVM, DevSecOps / InfoSecOps)?
Many ITIL tools have workflows that can automate tracking, reporting, etc.
Leverage existing tools for data processing in your ecosystem, and your ROI will increase dramatically.
Why not leverage that for PCI DSS / GPDR / HIPAA / Privacy Shield compliance, let alone for other purposes (e.g., TVM, DevSecOps / InfoSecOps)?
Many ITIL tools have workflows that can automate tracking, reporting, etc.
Leverage existing tools for data processing in your ecosystem, and your ROI will increase dramatically.
Labels:
Ariba,
DevSecOps,
GPDR,
GRC,
HIPAA,
InfoSecOps,
ITIL,
PCI DSS,
Privacy Shield,
ROI,
ServiceDesk,
ServiceNow,
TVM
Subscribe to:
Posts (Atom)