175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.
Control testing programs are designed around the controls that can be tested within defined timeframes, with available tooling, and against stable system configurations.
Risk registers document the risks that were identified during risk assessments conducted by the people who were in the room when the risk assessment was conducted.
Governance frameworks describe how organizations should control their information assets. Enterprise architectures describe how organizations actually operate their infor…
The difference between a control that works and a control that is assumed to work is the gap between governance that reduces risk and governance that documents the intent…
Audit readiness programs treat evidence collection as something that happens before an audit. In reality, the conditions that make evidence collection possible, or imposs…
Compliance programs document what controls have been implemented. They answer the existence question: is a control in place? They are not designed to answer the effective…
Audits confirm that controls exist and were operating as described at the time of assessment. Incidents reveal how controls perform under adversarial conditions, at opera…