Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • The Value of a Common Architecture for GRC Platforms

    Business is complex and dynamic, and requires agility to stay competitive. Market leadership requires the organization be quick to respond to changing conditions – to pause means loss. Governance, risk, and compliance (GRC) processes often work against business agility. Requirements and initiatives managed across numerous silos, using manual or varying technology approaches, burden the business.…

  • Wanted: GRC Psychologist

    When you think you have heard everything . . . One of the attendees at the San Jose GRC Fundamentals, Strategy, and Technology Bootcamp today shared an interesting conversation she had. In pursuing discussion with other organizations that have implemented GRC strategies, one told her that they actually had to get a psychologist involved. That…

  • Top GRC Questions & Issues

    The San Jose GRC Fundamentals, Strategy, & Technology bootcamp is underway with terrific interaction. The bootcamp is comprised of implementers of large down to medium sized organizations, professional service firms, and a few technology providers. The top questions/issues that the attendees are trying to resolve over the course of three days are (coming directly from…

  • BPS & Resolver – Synergetic Merger

    2010 is proving to be an interesting year for the reorganization of the GRC space. It kicked off with the public announcement of the EMC/RSA acquisition of Archer Technologies. Shortly thereafter you had the announcement of the merger of BPS and Resolver.   The merger of BPS and Resolver is intriguing. Unlike the acquisition of…

  • CCEP – Certified Compliance & Ethics Professional

    I just passed the Certified Compliance & Ethics Professional (CCEP) exam from the Society of Corporate Compliance & Ethics (SCCE). While I meant to do this years a go – I never got around to it.   The certification requires so many years of professional experience and training. While many assume that you have to…

  • Corporate Policies in Disarray and Chaos

      Policies are a critical component of a GRC strategy – but often the most overlooked or neglected component. It amazes me the number of companies I go into that have complete disarray and chaos in their approach to managing corporate policies and procedures. Simply put – organizations cannot ignore policy management. Consider that: Policies…

  • GRC Reference Architecture: Industry, Geographic, & Technology Views

      Over the past few months we have explored together the various components of my GRC Reference Architecture. This embodies the technology end of my broader GRC EcoSystem – which to date has over 1300 technology providers, professional service firms, and content providers of GRC cataloged into the GRC market. The components of the GRC…

  • 2010 GRC Research Agenda & Education

      Happy New Year! I trust that 2010 will bring you success and direction in your personal and professional life. First I need to state a deep thank you to all of my subscribers that have reached out to me over the past several weeks with your sympathy and prayers for my family as my…

  • EMC/RSA Acquisition of Archer: 1 + 1 = 3

    For the past two years Archer Technologies has been a disruptive force in the GRC market. They have been going strong in the IT/information security segment of GRC for several years – but the past two years has shown them to be a formidable competitor in what is referred to as the enterprise GRC (eGRC)…

  • Enhancing Business Performance through Risk Management

      The following is an abstract from my latest research piece “Enhancing Business Performance through Risk Management“ While the market seems eager to grasp onto the phrase “risk intelligence,” it means nothing if corporations cannot take action on the intelligence it provides. Being intelligent is not the same as being wise – most organizations lack…

  • GRC Reference Architecture: Role/Process Specific Applications

      Over the past few weeks we have looked at both theinformation model and the enterprise application core of Corporate Integrity’s GRC Reference Architecture. The GRC Reference Architecture provides the framework to approach technology, classify software offerings, and is part of my broader GRC EcoSystem (which includes over 1300 technology, professional service, and information providers).…

  • Good Risk Management Guidance – Here At Last in ISO 31000

    We interrupt this broadcast . . . yes, I know many of you have been waiting in eager participation for my next installment of the GRC Reference Architecture which is to focus on the application taxonomy of specific business roles/functions that are part of GRC (in previous weeks we looked at the core enterprise GRC…