Risk Management Should Drive Decisions, Not Just Maintain a Risk Register
Many organizations maintain a risk register. Risks are documented, assigned ratings, given owners, and reviewed periodically. Yet the information in […]
Many organizations maintain a risk register. Risks are documented, assigned ratings, given owners, and reviewed periodically. Yet the information in […]
NIST SP 800-171 requirements can easily become a checklist exercise. A requirement is reviewed, evidence is located, a status is […]
For organizations subject to Cybersecurity Maturity Model Certification requirements, the assessment should not be the event that determines whether the […]
Organizations sometimes use the terms security and compliance interchangeably. They are related, but they are not the same thing. Compliance […]
Service management, governance, and risk management are often treated as separate disciplines. In practice, they are deeply connected. Services create […]
When service management is not working effectively, organizations often look for a technology solution. A new ITSM platform promises better […]