


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-
Effective Policy Management & Communication Workshop
GRC 20/20 Workshops provide interactive training to groups of people on a range of GRC topics. These workshops provide a collaborative learning environment in which the attendees will be guided through lectures, problems, activities, and discussion. GRC 20/20 can be engaged to deliver workshops internally to organizations as well as sponsored by GRC solution providers…
-
Mature Governance, Risk Management & Compliance Needs an Enterprise Architecture Approach
Mature GRC requires an understanding of the business – its strategy, organizational structure, processes, risks, obligations, commitments, and objectives. The goal of GRC is to enable the organization to govern the organization and manage risk and compliance in the context of business. Achieving GRC maturity requires a GRC architecture that leverages an understanding of enterprise…
-
2014 GRC Value Award Nominations are Being Accepted
The 2014 GRC Value awards are to recognize GRC solutions that have returned significant and measurable value to an organization. Whether technology, content, or professional service providers – all can submit an award about a solution or service. However, the nomination must be on a specific implementation/project in a verifiable client. No generalizations or consolidations…
-
Inevitable Failure: Disconnected Risk & Policy Management
Business is complex. Gone are the years of simplicity in business operations. Exponential growth and change in regulations, globalization, distributed operations, changing processes, competitive velocity, business relationships, disruptive technology, legacy technology and business data encumbers organizations of all sizes. Keeping this complexity and change in sync is a significant challenge for boards, executives, as well…
-
The GRC Pundit Discusses ERP Maestro's 2014 Innovation Award
GRC 20/20 Discusses the reasons behind ERP Maestro’s 2014 Innovation Award from ERP Maestro® on Vimeo.
-
GRC Analyst Rant: Throwing Down the GRC Analyst Gauntlet
All organizations do GRC (governance, risk management, and compliance). It does not matter if the organization uses the acronym or not, every organization has some approach to the elements of governance, risk management and compliance whether it is non-integrated and siloed across scattered areas of the organization or a federated GRC strategy that links GRC…
-
ERP Maestro: Automated Security & Access Controls Through the Cloud
Executive Summary Organizations face increased pressure to ensure business applications such as Enterprise Resource Planning (ERP) systems are secure and access control risks are managed in the context of a dynamic business environment. Segregation of Duties (SoD), inherited rights, critical and super user access, and changes to roles are too much for today’s organization to…
-
2014 GRC Technology Innovation Award: ACL Integrates Automated GRC Monitoring with Proactive Surveys & Questionnaires
The 2014 GRC Technology Innovation Awards was filled with competition. Nominations increased to 62 over last year’s awards, and fifteen winners were selected. GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected 15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive…
-
2014 GRC Technology Innovation Award: ACL Goes Mobile with the Most Complete and Intuitive Mobile Interface for GRC
The 2014 GRC Technology Innovation Awards was filled with competition. Nominations increased to 62 over last year’s awards, and fifteen winners were selected. GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this…
