Email Alerts
-
Will EU data protection reforms help or hurt business?
Reforms to the EU's data protection framework are designed to enhance privacy and create uniform regulations. But what will be the cost to businesses? AIOG
-
Briefing: Governing risk management and compliance
Organizations can waste resources by not syncing risk management and compliance efforts. Here’s how to adapt risk management and stay compliant. AIOG
-
Briefing: Governing risk management and compliance
Compliance Briefing
-
FAQ: How do corporate social media policies hold up against labor law?
Corporate social media policies are designed to protect against employees posting job complaints online, but cases show labor laws’ interpretation of these rules is fuzzy at best. FAQ
-
Do corporate social media policies hold up in court?
Corporate social media policies are designed to protect against employees posting job complaints online, but cases show labor laws’ interpretation of these rules is fuzzy at best. AIOG
-
Quiz: How are online security threats influencing business processes?
Businesses and their employees have proven vulnerable to the latest online security threats. Take our quiz to see if you’re ready to protect your business, and its bottom line. Quiz
-
FAQ: What is the Computer Fraud and Abuse Act?
The Computer Fraud and Abuse Act of 1986 was originally designed to combat hacking, but amendments that dramatically broadened its scope and penalties have drawn some criticism. Compliance FAQ
-
Guide to balancing risk management and compliance
Protection from risk does not equal compliance, and vice versa. Here are strategies for balancing the two to protect your company from all angles. AIOG
-
Guide to balancing risk management and compliance
Protection from risk does not equal compliance, and vice versa. Here are strategies for balancing the two to protect your company from all angles. Compliance Briefing
-
Up to speed on data security and privacy? Take our quiz to find out
Data breaches. Malware. Social media. These are just a few of the areas causing data security and privacy headaches. Take our quiz to see how aware you are of the latest trends. Quiz
- See More: Essential Knowledge on Risk management and compliance
-
Emerging technology both a boon and bane to GRC strategy
Advanced technologies create more data than ever for companies to protect, but it's not all bad news. Here's why using the latest cutting-edge tools can help your GRC strategy. News | 14 May 2012
-
As GRC technology becomes more complex, so do buying decisions
The GRC technology market has become increasingly targeted but companies' buying decisions have not followed suit. How can you make sure you're getting the most bang for your buck? News | 14 May 2012
-
Corporate compliance program tips to prevent breaches
Every modern business is vulnerable to data breaches, but here’s advice on creating a solid corporate compliance program to protect your vital information. News | 08 May 2012
-
Governing the complications of social media security and compliance
Technology law expert Jeffrey Ritter discusses the obstacles to governing social media security in 21st century business and what companies can do to protect their information. News | 07 May 2012
-
Summit organizers promise real-world examples of leading GRC strategy
Presenters at the upcoming GRC Summit Boston preview what attendees can expect to learn about optimizing their GRC strategy in today's regulatory landscape. News | 27 Apr 2012
-
A bit late: Wal-Mart to name global compliance officer
Already neck deep in a Mexican bribery scandal, retail giant Wal-Mart now says it will name a global compliance officer to police the company. News | 24 Apr 2012
-
ISACA: Update to COBIT 5 governance framework maximizes IT assets
ISACA’s update to its popular COBIT 5 framework incorporates a business-wide approach the organization says helps enterprises maximize their information and technology assets. News | 23 Apr 2012
-
EU, US promise continued online data privacy dialogue
The E.U. and U.S. have announced a joint commitment to an online data privacy framework. How will it impact Internet-based international trade compliance? News | 20 Mar 2012
-
Excellence.gov proves innovation and compliance not mutually exclusive
The annual Excellence.gov Awards recognize the best service-enhancing government IT programs -- and the winners prove that innovation does not have to come at the expense of compliance. News | 16 Mar 2012
-
Beware all costs of electronic health record systems
The push for universal electronic health record systems could drive up costs and make providers more susceptible to data breaches, according to new reports. News | 07 Mar 2012
- See More: News on Risk management and compliance
-
How regulation should -- and shouldn't -- influence cybersecurity policy
Recent breaches display the importance of cybersecurity policy, and regulations provide a decent data protection roadmap. But compliance does not automatically equal security. Tip
-
Pilot program best practices to help determine your GRC requirements
It’s important to be familiar with your organization's exact GRC requirements when choosing which tools to buy, build or outsource. Here’s how a pilot program can help guide you. Tip
-
Disk encryption, data protection to stay compliant with HIPAA, HITECH
Staying vigilant about encryption and data protection not only keeps you compliant with HIPAA and HITECH, but also helps reduce overall business risk. Tip
-
New and not-so-new security twists in the Cybersecurity Act of 2012
The Cybersecurity Act of 2012 gives the government more control over the private sector’s information security. But are the new rules really needed? Our expert says no. Tip
-
Our dangerous overdependence on information technology audits
Although information technology audits can uncover GRC gaps, lower-level issues are often overlooked when relying on them for security assurance, says contributor Kevin Beaver. Tip
-
Vulnerabilities exposed during disposal of used computers
Upgrading equipment? Proper disposal of used computers is necessary to reduce risk, because sensitive data is vulnerable when old electronics go out the door. Tip
-
Avoid the 'oops' moment: Tips for encryption management best practices
Effective encryption management can help your business stay compliant, protect its reputation and avoid embarrassment. But encryption should supplement security, not replace it. Tip
-
False alarms: Analyzing your leading risk management indicators
To alleviate risk, it’s necessary to validate risk management indicators specific to your organization. Here’s how, and why avoiding it could negatively affect your GRC program. Tip
-
Using governance, risk and compliance to improve business performance
Governance, risk and compliance are vital to every successful business, but our expert says companies often don’t take advantage of GRC’s critical influence on performance. Tip
-
Best practices to help meet your organizational compliance objectives
Meeting compliance objectives is not just up to IT anymore -- a collaborative approach is necessary. Here’s advice to achieve top-down organizational compliance at your company. Tip
- See More: Tips on Risk management and compliance
-
Occupational Safety and Health Administration (OSHA)
Occupational Safety and Health Administration (OSHA) is a federal organization (part of the Department of Labor) that ensures safe and healthy working conditions for Americans by enforcing standards and providing workplace safety training. Definition
-
data governance policy
A data governance policy is an organization’s set of information management processes that are designed to assist business administration and protect company assets. Definition
-
enterprise security governance
Enterprise security governance is a company's strategy to reduce risk by protecting systems and information, as well as its execution of that strategy. Definition
-
social media policy
A social media policy (also called a social networking policy) is a corporate code of conduct that provides guidelines for employees who post content on the Internet either as part of their job or as a private person. Definition
-
Chief Risk Officer (CRO)
The chief risk officer (CRO) is the corporate executive tasked with assessing and mitigating significant competitive, regulatory and technological risks across the enterprise. Definition
-
compliance audit
A compliance audit is a comprehensive review of an organization's adherence to regulatory guidelines. Independent accounting, security or IT consultants evaluate the strength and thoroughness of compliance preparations. Auditors review security polic... Definition
-
IT investments for manufacturers managing global supply chains
In this podcast, Jane Barrett of AMR Research Inc. discusses the best places for manufacturers to invest in IT to overcome challenges and maximize opportunities that globalization creates for supply chains. Podcast
-
Business model risk is a key part of your risk management strategy
Management consultants Amit Sen and John Vaughan discuss business model risk, a way to apply risk management policies to new or changed business processes. Podcast transcript
-
A closer look at computer forensics and e-discovery processes
This podcast defines both computer forensics and e-discovery processes and provides examples of how some CIOs are increasing awareness of these disciplines in the enterprise. Podcast
-
Emerging technology both a boon and bane to GRC strategy
Advanced technologies create more data than ever for companies to protect, but it's not all bad news. Here's why using the latest cutting-edge tools can help your GRC strategy. News
-
As GRC technology becomes more complex, so do buying decisions
The GRC technology market has become increasingly targeted but companies' buying decisions have not followed suit. How can you make sure you're getting the most bang for your buck? News
-
Corporate compliance program tips to prevent breaches
Every modern business is vulnerable to data breaches, but here’s advice on creating a solid corporate compliance program to protect your vital information. News
-
Governing the complications of social media security and compliance
Technology law expert Jeffrey Ritter discusses the obstacles to governing social media security in 21st century business and what companies can do to protect their information. News
-
How regulation should -- and shouldn't -- influence cybersecurity policy
Recent breaches display the importance of cybersecurity policy, and regulations provide a decent data protection roadmap. But compliance does not automatically equal security. Tip
-
Occupational Safety and Health Administration (OSHA)
Occupational Safety and Health Administration (OSHA) is a federal organization (part of the Department of Labor) that ensures safe and healthy working conditions for Americans by enforcing standards and providing workplace safety training. Definition
-
Summit organizers promise real-world examples of leading GRC strategy
Presenters at the upcoming GRC Summit Boston preview what attendees can expect to learn about optimizing their GRC strategy in today's regulatory landscape. News
-
A bit late: Wal-Mart to name global compliance officer
Already neck deep in a Mexican bribery scandal, retail giant Wal-Mart now says it will name a global compliance officer to police the company. News
-
ISACA: Update to COBIT 5 governance framework maximizes IT assets
ISACA’s update to its popular COBIT 5 framework incorporates a business-wide approach the organization says helps enterprises maximize their information and technology assets. News
-
Pilot program best practices to help determine your GRC requirements
It’s important to be familiar with your organization's exact GRC requirements when choosing which tools to buy, build or outsource. Here’s how a pilot program can help guide you. Tip
- See More: All on Risk management and compliance
About Risk management and compliance
Risk management is an essential part of compliance planning. Find news, advice, commentary and best practices on coordinating your risk management initiatives with your compliance goals.