Governance Risk Compliance

  • Entity Relationship Diagram (ER)

    The complex GRC structure demands a complex relational database, and in some cases would require replication of various data to allow to store specific data aggregations.

    While the ER is in development and will undergo changes, the overall structure begin to emerge

    (more…)

  • GRC Platform Scope

    Concentrate on the Information Security Space, or the Operational Risk at the most

    • Define Objects:
      • Organizations
      • Assets
      • Authority (like Regs, Frameworks)
      • Glossary
      • Data Classifications and Atributes
      • Documents (Policies etc)
      • Risks
      • Controls
    (more…)

  • GRC Platform Development – inception

    Decided to spin this blog to document some of my GRC platform development.

    Some thoughts:

    Building a GRC platform isn’t an easy task, especially considering that different companies have different approaches to GRC processes. Some companies are less mature and require the barebones, other companies manage their GRC processes with lots of sophistication.

    (more…)