Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • What is risk management?

    Risk management is maturing, but as a result needs to be understood correctly and reminded that it does not rule the roost. I have three teenage boys (19, 18, and 16).  At times my boys get to big for their britches and need to be reminded what the pecking order is.  It does not mean…

  • Concluding the GRC Analyst Rant

    If you have been following my posts, you will know that I created a firestorm of discussion on: Rethinking GRC, Analyst Rant, Gartner’s 2012 EGRC Magic Quadrant.  If you go to this link you will see the range of comments – many anonymous – from on the topic. French Caldwell, who continues to be a gracious…

  • Accepting Nominations for the 2013 GRC Technology Innovation Awards

    ANNOUNCEMENT: GRC 20/20 is accepting nominations for the 2013 GRC Technology Innovation Awards. To nominate a technology solution – please download the form. The GRC Technology Innovation Awards are to recognize technologies that are revolutionizing Governance, Risk Management, and Compliance (GRC).  Please understand what it is NOT: The purpose of these awards is NOT to…

  • Effective Policy Enforcement Involves Technology

    I find that ineffective and unenforced policies are rampant within organizations, and are a thorn in the side of compliance and policy managers.   Mismanagement of policy has grown exponentially with the proliferation of documents, collaboration software, file shares, and Websites. Organizations end up with policies scattered on dozens of sites with no defined understanding…

  • Policy Communication in a YouTube Generation

    So you wrote a policy—now what? Policies are only effective if you can show that they have been communicated and understood. Having a written policy that nobody knows about is just like having no policy at all. You cannot hold people accountable to a policy until you have made them aware of the policy. Unfortunately,…

  • Maintaining Policies and Keeping Them Relevant

    The webinar on policy management addresses a common flaw – the failure to properly maintain policies once issued.  Every policy should go into a periodic review to ensure it remains accurate and necessary.  And given the number of policies in most organizations, and the numerous factors that may give rise to a need for change, this…

  • Measuring Policy Compliance and Metrics

    This webinar looks at the critical issue of ensuring policy adherence, compliance, and metrics for managing polices.  Attendees will learn the challenges, best practices, and benefits of a measurable and trackable system for policy enforcement. Learning Objectives: Understand monitoring and validation of compliance to policies Define methods for compliance metrics and assessments Determine how to manage…

  • Increasing Compliance Effectiveness, Efficiency, and Agility with Technology

    Compliance obligations and risk to the business is like the hydra in mythology — organizations combat risk, only to find more risk springing up to threaten the organization. Managing GRC activities in disconnected silos leads the organization to inevitable failure. Reactive, document-centric, siloed applications, and manual processes for GRC fail to actively manage compliance in…

  • Effective Policy Awareness and Training

    This webinar explores the best practices for distributing policies and determining when and how to provide training.  We often think that once a policy has been formally issued the job is done, but that is far from the truth.  Properly communicating about the availability of the policy is only the start.  Attendees will learn the challenges,…

  • Rethinking GRC: Analyst Rant, Gartner's 2012 EGRC Magic Quadrant

    Yes, the latest Gartner EGRC Magic Quadrant is out and I am left questioning what value it provides.  My first impression is that it is best for the compost pile to be used as fertilizer for the garden next spring and not used in organizations that may rely on it to make misinformed GRC technology…

  • Accountability and Consistency in Policy Development

    In my experience, policy management processes are in disarray when operating autonomously, introducing risk in today’s complex, dynamic, and distributed business environment. The typical organization lacks a structured means of policy development and governance with an inconsistent maze of templates and processes. Inconsistency in policy management means processes, partners, employees, and systems that behave like…

  • Rethinking GRC

    2012 marks the 10th anniversary since I first modeled a market for technology, content, and professional services and labeled it GRC. It all started with a vendor briefing with a software firm in which they demonstrated an integrated view of controls, policies, and assessments. A light bulb flashed within my head that there is a…