Compliance Assessment

FCMWhiteOnly.png

Search

User Menu

Who's Online

We have 5535 guests and 52 members online
Compliance Assessment
Written by Robin Basham
Monday, 28 November 2011 20:10
Print E-mail
User Rating: / 6
PoorBest 
EnterpriseGRC Facilitated Compliance Management - EnterpriseGRC Solutions Services
Article Index
Compliance Assessment
All tools and procedures
Methodology in Achievement of these objectives
Common Language in Controls and Application Controls
All Pages

approach

Assessment Services - EnterpriseGRC Solutions®, Implementing a Compliance Framework

EnterpriseGRC Solutions will supply consulting and recommendation in support of IT resource assignment and organization structure as it pertains to support of the Control Objectives for Information and Related Technology.  EnterpriseGRC Solutions focuses corporations in implementing an overall framework for control and assessment.  EnterpriseGRC Solutions, Inc.® guides clients to:

  • Insure preparation to demonstrate effective internal control structure and procedure
  • Demonstrate appropriate standards for gathering evidence and reporting against these findings
  • Establish a system of enterprise wide Risk Assessment
  • Identify financial exposures along with management steps to monitor and control such exposures
  • The scope of IT auditing includes:
    • Reviewing the reliability and integrity of information and the means used to identify measure, classify, and report such information.
    • Reviewing the systems established to ensure compliance with those policies, plans, procedures, laws, and regulations, which could have a significant impact on operations and reports, and determining whether the organization is in compliance.
    • Reviewing the means of safeguarding information (backups), verifying the existence of such backup sets.
    • Appraising the efficiency with which resources are employed.
    • Reviewing operations or programs to ascertain whether results are consistent with established objectives and goals and whether the operations or programs are being carried out as planned.
  • All tools and procedures supported by EnterpriseGRC Solutions International(EnterpriseGRC Solutions) facilitate meeting SEC requirements on internal control over financial reporting.  EnterpriseGRC Solutions provides consulting and products that isolate internal control deficiency while supplying both internal assessment reporting and response in the form of written and implemented IT procedures and controls.  Three major elements work together to provide content, guidance and criteria toward a consensus driven strategy for a properly controlled business environment. We refer to this as our compliance framework:
    framework

    • ITIL® is FORM, content and concept behind IT Control Programs
    • Facilitated Compliance Management™ is the FUNCTION, a working data and process model of HOW we manage and capture IT control events
    • CobiT®, COSO and other Security Program control programs are the MEASURE or criteria by which we agree to define an IT environment as appropriately controlled.

    ITIL CobiT ISO

    Review enterprisegrc.com on alexa.com Call 800 847-6821800 847 6821 or reach out via Skype My status

     

    New and increasing business regulations bring added context to the need for highly mature IT programs.  The main purpose of Sarbanes-Oxley Act, for example, is to protect investors by improving accuracy and reliability of Corporate Disclosures.  This legislation has made it necessary for all publicly traded companies to insure corporate preparation to demonstrate "effective internal control structure and procedure."   EnterpriseGRC Solutions facilitates definition of effective internal control, while supplying tools and project implementation to reach this goal.  In addition, non public companies are increasingly aware of SEC driven requirements around security, data management and the demonstrations of other IT controls as required by SAS70 (SSAE no. 16).

    So, what is the EnterpriseGRC Solutions® approach?

    Plan Do Act

    EnterpriseGRC Solutions® works with many current and relevant organizations and standards including BS7799/ISO17799, PMBOK, NIST and ITL, ITIL® Service Support, Six Sigma Process Control, ISO 9000 and14000, FCAPS, CMM, TMN, to name only a few.  The goal of EnterpriseGRC Solutions is to assess the implementation of process across all areas of IT.

    For broad and comprehensive IT assessment EnterpriseGRC Solutions uses CobiT®.
    "CobiT® provides management and business process owners with an Information Technology (IT) governance model that helps in understanding and managing the risks associated with IT. CobiT® helps bridge the gaps between business risks, control needs and technical issues. It is a control model to meet the needs of IT governance and ensure the integrity of information and information systems."
    CobiT® (Control Objectives for Information and Related Technology) doesn't suggest that it replace all standards, but that it is used to assess whether and to what extent standards are in place both across the IT infrastructure and in the corporate management IT.   
    Risk Management and IT Control

    • Sarbanes-Oxley Section 404 and CobiT®. Client Training, compliance review
    • Establishing guidelines and policies representing good governance.
    • Prescriptive tools approach to remediate low control maturity, matching tools with areas of defined exposure to risk
    • Security Assessment and risk mitigation plan


    Last Updated on Thursday, 03 May 2012 09:19
     
    New Services
    The GRC Buzz

     

    Now Available - Cloud & Virtualization Essentials™

     

     

     

    Push 2 Check

    http://rymatech.com/

     

    HISPIHolistic Information Security Practitioner Institute (HISPI) welcomes EnterpriseGRC Solutions as member of their HISP Certification Board/Committee Read More

    GRC Solutions

    ITpreneursITpreneurs is proud to name EnterpriseGRC Solutions as its newest certified partner. ITpreneurs and EnterpriseGRC Solutions will collaborate to increase Cloud and Virtualization concepts and controls, ISO 27001, COBIT and ITIL courses offered through EnterpriseGRC Solutions. “Every member of my organization has achieved at least one certification through ITpreneurs, and this is the second company that I’ve founded with that same promise. [...] It is a proud day, that we can be a part of ITpreneurs’ landmark efforts to bring forward CompTIA Cloud Essentials training and certification. - Robin Basham, Managing Partner.

    ComplianceExchange A Blog We Love

    Spontaneous Kudos - We've really been digging our digest from The Compliance Exchange

    Review enterprisegrc.com on alexa.com

    Have you read Value of a Conversation?

    Please Join us on Facebook

    Read More

    Partners and Client Information
    EnterpriseGRC Solutions is recently named as a member of the Cloud Credential Council. Holistic Information Security Practitioner Institute names CEO, Robin Basham, to their Education Advisory Board.

    Ryma Technology Solutions names EnterpriseGRC Solutions as an Affiliate Partner.  More. Recent Wins: EnterpriseGRC Provides IS0 27001 Policy and SOA readiness for NetSuite Inc.  EnterpriseGRC Solutions Sponsor to ISACA ITGI.  Recent Partner Alignments include ITpreneurs, Control Solutions International

    Request For Information? Please fill out our Wufoo form.

    Wordle: EnterpriseGRC.com Blog
    Cloud Credential Council
    Read More

    ISACA Silicon Valley LogoAre you attending "Enabling Trust: Business In the Cloud"? Learn more.