News, Updates, & Resources
DON’T WAIT FOR A RISK EVENT TO HAPPEN BEFORE YOU ADDRESS YOUR ENTERPRISE RISKS.
As I write this blog, I am experiencing a business disruption, and it is very frustrating. Should I blame my vendor, or is it my fault for not effectively managing my business risks? I outsource my email and my provider has been down for several days with no end in...
RISK APPETITE – MORE IMPORTANT NOW THAN EVER
The concept of risk appetite and tolerance is commonly referred to in today’s volatile and unpredictable business environment. Based on my conversations with multiple businesses over the last several months I’ve found that it is a widely understood, but often...
RESURRECTING THE THREE LINES OF DEFENSE MODEL
Rapidly changing environments Today’s constantly transforming environment is like nothing our industry has experienced in the past. When you consider the pressures facing enterprises to balance performance (the need to meet objectives) and conformance (the need to be...
STAY ON TOP OF IT GOVERNANCE TRENDS WITH THE NEWLY UPDATED CGEIT CERTIFICATION
In July ISACA released the new and updated version of their flagship governance framework, CGEIT, and the timing couldn’t be better. This is a certification you might want to check out. ISACA’s Certified in the Governance of Enterprise IT® (CGEIT®) professional...
WHAT DOES A GOOD IT GOVERNANCE STRUCTURE LOOK LIKE?
Over the last several months I’ve been asked by many organizations, companies and industry experts about my opinion on what the perfect governance structure looks like. I have good and bad news for you. The bad news first. There’s no single blueprint that can be...
REVIEW OF IMPLEMENTING THE NIST CYBERSECURITY FRAMEWORK USING COBIT 2019.
I normally don’t do book reviews, but this blog focuses on my personal review of one of ISACA’s latest publications that personally, I really like. Recently, ISACA published Implementing the NIST Cybersecurity Framework using COBIT 2019. This guide illustrates how...
ASSESSING POLICY FRAMEWORK MATURITY
In my last blog on policy frameworks I stressed the importance of principles, policies and procedures as an important ingredient to a governance framework. I mentioned that my quest for a policy framework maturity model came about when I was completing a process...
DON’T LET YOUR DIGITAL TRANSFORMATION EFFORTS OUTPACE YOUR ABILITY TO GOVERN THEM – REVIEW AND ASSESS YOUR POLICY FRAMEWORK NOW
In today’s high velocity business environment, it’s easy to lose sight of some basic governing principles that might be viewed as cumbersome and restrictive. Be careful, because governance principles exist to ensure the proper balance of performance and conformance...
HOW DO I INTERPRET COBIT PROCESS GUIDANCE IN THE UPDATED 2019 VERSION OF COBIT?
This year ISACA released the latest edition of the COBIT framework and one of my favorite parts is the introduction of governance and management objectives. Check out this short video blog on what these are and how to interpret them. [video width="1914" height="1080"...