Facilitated Compliance Management™
Every client has unique goals and capabilities. Typical engagements include Policy Baseline, Configuration Management, Control Assessment, Enterprise Risk Management
- Policy Mapping is the Foundation of Actionable, Auditable Control
- RunBooks Identify Expected and KEY Services and Systems, resulting in Establishing a Technology Baseline Supporting Critical Automated Business Controls
- RiskWatch iterates the gap between Policy, Standards and Business Realities
- Assessment Reviews, CMDB – Configuration Management Alignment to Security Policy and Service Standards (such as the selected control frameworks)

Organizations face challenges that drive the need for IT governance:
- Keeping IT running
- Delivering value to customers
- Managing IT costs
- Master complexity
- Align IT with business
- Ensure regulatory compliance
- Manage security
EnterpriseGRC Solutions® has custom tools that facilitate mapping client documentation and artifacts to their industry-specific array of requirements. Recent projects have involved creating a single risk framework with client policies mapped and risk ranked against collections of the following cybersecurity and cloud frameworks.
- Cloud Controls Matrixv4 as CCM WG leader for the mapping to NIST SP 800-53 and new ISO/IEC FDIS 27002
- 21 CFR Part 11
- 21 CFR Part 820
- HIPAA-HITECH CFR 45
- Eudralex V4 Annex 11
- GAMP® 5*
- HITRUST 9.3* (if associated to valid client license with HITRUST)
- ISO 13485:2016
- ISO/IEC 30111:2019
- ISO/IEC 27001:2013 €
- ISO/IEC 27017:2015 € 27002 for cloud services
- ISO/IEC 27799:2016 €
- ISO/IEC 27002:2013 € New ISO/IEC FDIS 27002 and mapping to CCM V4 and NIST 171 Assessment
- ISO/IEC 27018:2019 €
- ISO/IEC 27701:2019 €
- NIST SP 800-171r2, NIST SP 800-171A, NIST SP 800-172, NIST.HB.162
- NIST SP 800-53 r5
- FedRamp SP 800-53B now NIST SP 800-53C
- GDPR
- CCPA 1798
- AICPA SOC 2 2017
- NIST Cybersecurity Framework, CSF
- CIS Benchmarks - OSCAL & SCAP integration, mapping to custom cybersecurity products
- CIS CSC v7.1-> 8.1 - the top 18
- PCI DSS V3.2.1
- COSO 2013 as mapped to IT and Cybersecurity standards and ISMS
- FFIEC
- NCSC NATIONAL CYBERSECURITY STRATEGY 2016-2021
- UK Cyber Essentials
- Criminal Justice Information Services (CJIS) Security Policy
- Compliance Controls Catalogue (C5)
- More upon request.
Note that as of October 17th, 2011, products created by Phoenix Business and Systems Process, Inc., to include Facilitated Compliance Management TM, are now owned and distributed exclusively through EnterpriseGRC Solutions Inc ®

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics