I write about Cyber security related management tips, related news, while I am working on Cyber security framework ideas to enhancing the maturity of the Cyber security program.
-
Defining Third-parties or Vendors from IT GRC perspective
The focus is on a risk-based approach to managing third-party vendors in IT governance, risk, and compliance. Instead of encompassing all vendors, a vendor portfolio with essential information is recommended. Maintaining current information and conducting litmus tests to identify critical vendors is crucial, especially those handling proprietary information.
-
Establishing a Third-party or Vendor Management program
The approach to integrating cyber security into the procurement process varies based on organization size and complexity. Companies with business experience typically have a Procurement and Contract Management (ProCam) program in place. Cyber security should assess vendor risk and advise on legal contracts. Stakeholders must be identified and a roadmap devised for future vendor management…
-
The role of Cyber security within Vendor Management
Cyber security has a key role in the Vendor management process
-
Creation of IT Asset Portfolio
An organization’s choice between using a spreadsheet, a purpose-built CMDB, or another GRC tool depends on present and future needs, asset information volume, and user/stakeholder access. A spreadsheet may suffice for initial asset management, but a purpose-built GRC tool is essential for long-term governance, offering robust information capture, user access control, and workflow automation.
-
Criticality of an IT Asset Portfolio
An IT Asset portfolio is crucial for IT governance, providing a clear understanding of an organization’s assets. Key information includes business owner, technology owner, location, platform, and business impact assessment results. Regular review and metadata inclusion enhance reliability. Commercial CMDB software caters to this, but it can be created with minimal resources if budget is…
Join 900+ subscribers
Stay in the loop with everything you need to know.