


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-
What is IT GRC?
Confusion leads to chaos. One area of confusion is IT-GRC. Major analyst firms are in a hubbub trying to get their arms around IT-GRC. IT security vendors are pulling in many directions trying to get IT-GRC to be defined to cover their respective niche. Others are lobbying to define IT-GRC as everything technology that relates…
-
Getting It Right
One of my pet peeves in the GRC space is the misuse of words. I frequently have vendors come to me and tell me that they are an enterprise risk management solution – when in fact it is obvious that what they are doing is something specific like IT risk management. My response to these…
-
GRC 2.0 – The GRC.EcoSystem
GRC 1.0 – it was a good start. When I originally defined the GRC market, unlike other analysts, I had a holistic view of business processes in mind that needed to participate in a GRC vision and strategy. The goal was to make sure that GRC was not limited to SOX/finance or IT. GRC needed…
-
Understanding GRC
Governance, Risk, and Compliance can each be confusing to understand in their individual capacities – bring them together as GRC and it can be even more confounding. GRC is more than a catchy acronym used by technology providers and consultants to market their solutions – it is a philosophy of business. This philosophy permeates the…
-
Why Integrity?
Integrity is a mirror revealing the truth about an individual or a corporation. It involves walking the talk — not just talking it. On a personal level, integrity is measured by what an individual does and does not do when no one is looking. Do they hold to their values, beliefs, and ethics? Or do…
