Enterprise Risk Management Implementation

Enterprise Risk Management Implementation
RiskWatch Implementation
Written by Robin Basham
Sunday, 27 November 2011 00:49
Print E-mail
User Rating: / 3
PoorBest 
EnterpriseGRC Facilitated Compliance Management - EnterpriseGRC Solutions Services
Article Index
RiskWatch Implementation
Week Four:
Form and Recording - RiskWatch Items
All Pages

RiskWatch Implementation Rescue - Total Implementation in Eight Weeks or Less

Life Preserver

 

This proven program achieves implementation of Risk Management, satisfying regulatory requirements as described by your specific industry and location, providing all required products and training, documentation and on line LMS compliant knowledge transfer.

Week One:

Team review of desired process, existing documentation and future state documentation.

  • Create Custom on line training slides.
  • Identify risk team and kick off process.
  • Distribute Risk Criteria Matrix to key stakeholders

Week Two:

  • Present training; Assist managers to document risks as aligned to position and department responsibilities;
  • Input High Profile Job Descriptions; Organization Titles and map to aligned to CobiT / ISO/IEC 17799:2005 controls, with emphasis towards segregated duties as recommended by Information Systems and Audit Control Association
  • Generate by consensus with all IT Directors first Agenda
  • Conduct first Meeting
  • Post Minutes and establish Portal for RiskWatch meetings, agenda, archives
  • Collect Risk Criteria first response summary

Week Three:

  • Assist managers to document risks
  • Generate Agenda and Post Minutes
  • Establish method for remote attendees and be on site to Conduct Second Meeting
  • Present initial job descriptions for affirmation, review standard associated duties and alignment to "CobiT/ISO" controls
  • Deliver Visio with job profiles (DSN) (see image)
  • Risk Criteria Matrix Second Run validation
  • Based in interview with managers, document job related control anomalies; suggest changes in job definitions as might be indicated by organization chart
  • Kick off - Fragile Artifacts; Technology Resource Risk
  • Collect Application Names; System Names; Factors for review of system based Risk
  • Determine minimum monitoring profile and automated source data


Last Updated on Thursday, 03 May 2012 09:22
 
New Services
The GRC Buzz

 

Now Available - Cloud & Virtualization Essentials™

 

 

 

Push 2 Check

http://rymatech.com/

 

HISPIHolistic Information Security Practitioner Institute (HISPI) welcomes EnterpriseGRC Solutions as member of their HISP Certification Board/Committee Read More

GRC Solutions

ITpreneursITpreneurs is proud to name EnterpriseGRC Solutions as its newest certified partner. ITpreneurs and EnterpriseGRC Solutions will collaborate to increase Cloud and Virtualization concepts and controls, ISO 27001, COBIT and ITIL courses offered through EnterpriseGRC Solutions. “Every member of my organization has achieved at least one certification through ITpreneurs, and this is the second company that I’ve founded with that same promise. [...] It is a proud day, that we can be a part of ITpreneurs’ landmark efforts to bring forward CompTIA Cloud Essentials training and certification. - Robin Basham, Managing Partner.

ComplianceExchange A Blog We Love

Spontaneous Kudos - We've really been digging our digest from The Compliance Exchange

Review enterprisegrc.com on alexa.com

Have you read Value of a Conversation?

Please Join us on Facebook

Read More

Partners and Client Information
EnterpriseGRC Solutions is recently named as a member of the Cloud Credential Council. Holistic Information Security Practitioner Institute names CEO, Robin Basham, to their Education Advisory Board.

Ryma Technology Solutions names EnterpriseGRC Solutions as an Affiliate Partner.  More. Recent Wins: EnterpriseGRC Provides IS0 27001 Policy and SOA readiness for NetSuite Inc.  EnterpriseGRC Solutions Sponsor to ISACA ITGI.  Recent Partner Alignments include ITpreneurs, Control Solutions International

Request For Information? Please fill out our Wufoo form.

Wordle: EnterpriseGRC.com Blog
Cloud Credential Council
Read More

ISACA Silicon Valley LogoAre you attending "Enabling Trust: Business In the Cloud"? Learn more.