26 articles in the GRC & Control Reality track of the Deep Trust Governance Series.
Risk that enters an organization through acquisition, outsourcing, partnership, or technology adoption does not carry with it a reduced governance obligation.
The quarterly governance report showed improvement across eight of twelve tracked metrics. Patching coverage up four percent. Training completion at 97 percent, a three-y…
Governance programs are typically designed and validated in environments of manageable complexity: a defined set of systems, a stable organizational structure, a bounded…
Policy is written by humans reasoning about how systems should behave. Systems behave according to how they were configured, integrated, and deployed — which reflects the…
Control frameworks describe how organizations should manage risk. They specify what controls should exist, how they should be designed, and what evidence should demonstra…
Governance programs are measured on activity because activity is measurable. The number of controls assessed, the number of findings remediated, the number of training co…
The post-incident risk register still showed the affected system at a score of 2.3 out of 10. The scoring model had evaluated the system six months earlier against the st…
Every significant governance policy in a mature organization has a named owner. The data protection policy is owned by the DPO. The information security policy is owned b…
A governance program without a blind spot is not a governance program — it is a theoretical construct. Every program is built around what its designers knew, what the org…
GRC platforms are sophisticated, expensive, and widely deployed. They link controls to frameworks, track evidence, manage findings, produce dashboards, and generate audit…
A control that exists is not a control that works. Enterprise governance programs measure control implementation: whether a control has been defined, deployed, and docume…
Compliance evidence documents the state of controls at the time evidence was collected. Risk accumulates in the space between evidence collection events.
An audit that confirms compliance confirms that the required elements exist. It does not confirm that those elements produce the intended outcomes.
Every compliance assessment produces a result that was accurate when it was produced. The environment that assessment described has continued changing from the moment it…
An audit finding identifies what was observed: a control was absent, a process was not followed, evidence was missing, a configuration was incorrect.
Governance programs map controls to systems. Data does not follow system boundaries. It moves between systems, through integrations, across vendor boundaries, and into en…
GRC platforms are excellent at tracking what organizations have documented about their control environments. They track policy assignments, control mappings, audit eviden…
Security and governance metrics are designed to show improvement over time. They measure training completion, patch coverage, vulnerability closure rates, and control ass…
Audit readiness programs are designed to produce passing audit outcomes. They are effective at this objective. The governance problem is that passing an audit and having…
Control testing programs are designed around the controls that can be tested within defined timeframes, with available tooling, and against stable system configurations.
Risk registers document the risks that were identified during risk assessments conducted by the people who were in the room when the risk assessment was conducted.
Governance frameworks describe how organizations should control their information assets. Enterprise architectures describe how organizations actually operate their infor…
The difference between a control that works and a control that is assumed to work is the gap between governance that reduces risk and governance that documents the intent…
Audit readiness programs treat evidence collection as something that happens before an audit. In reality, the conditions that make evidence collection possible, or imposs…