IT Governance Risk and Compliance GRC
IT Governance Risk and Compliance GRC
IT Governance Risk and Compliance GRC
GRC WORKSHOP
PRESENTATION OUTLINE
1
2
3
4
5
Information
Protection
Management
Div.
What
is
Governance,
Risk
&
Compliance?
Enterprise
Governance,
Risk
&
Compliance
IT
Governance,
Risk
&
Compliance
IT
Control
Frameworks
Risk
Management
vIs
the
process
of
iden:ca:on,
analysis
and
either
acceptance
or
mi:ga:on
of
uncertainty
in
decision-making.
Compliance
vIs
the
process
of
adherence
to
policies
and
decisions.
Governance
GRC
Risk
management
assesses
the
areas
of
exposure
and
poten7al
impacts.
Risk
Compliance
This puts organiza:ons at greater risk and makes it dicult and costly for Management to do their jobs eec:vely.
Eec7veness
Governance
&
Processes
Risk
Risk management, including key risk indicators and risk dashboards
Compliance
Compliance assessment, monitoring and reporting
ENTERPRISE GRC
Governance
Strategy
Risk
Management
Assessment
Compliance
Assessment
Reporting
Planning
Mitigation
MANAGEMEMT
PROCESSES
PEOPLE
IT
Risk
management
v An
IT
risk
management
program
performs
risk
assessment
to
develop
and
priori:ze
op:ons
for
remedia:on
IT
Compliance
v An
IT
compliance
program
to
measure
the
level
of
compliance
within
an
IT
environment
IT-GRC
IT
CONTROL
FRAMEWORKS
COBIT
CONTROL
OBJECTIVES
FOR
INFORMATION
AND
RELATED
TECHNOLOGY
SUMMARY
IT
GRC
is
a
subset
of
Corporate
Governance
IT
GRC
comprises
of:
vIT
Governance
vIT
Risk
vIT
Compliance
Governance
GRC
Risk
Compliance
Thank you !
BREAK