March 14, 2010 3:59 AM
Posted by: David Schneier
assessment,
Audit,
framework,
GLBA,
GRC,
IT General Controls,
ITGC,
Regulatory Compliance,
risk,
risk managementI had an email exchange with a colleague last week in which GRC (governance, risk and compliance as a unified methodology) was central to the discussion. She felt that there's been a blurring of the lines in how people view GRC versus ERM (enterprise risk management) as disciplines and wanted to...
February 12, 2010 11:38 PM
Posted by: David Schneier
Audit,
corruption,
fraud,
GLBA,
Information Technology General Controls,
infrastructure,
IT,
IT General Controls,
ITGC,
NCUA,
Regulatory ComplianceI was reading the local newspaper this morning and was surprised to find a front page story ripped from the headlines of my professional life (ironic, I know).
Right there on the front page of today's News and Observer was a story about how a recent audit claimed corruption at a local college...
December 29, 2009 5:30 PM
Posted by: David Schneier
Audit,
business continuity planning,
GLBA,
information security,
IT General Controls,
red flags,
red flags identity theft,
Regulatory Compliance,
Vendor ManagementWhen I sat down to write my last blog post for 2009, I was planning to write either about my predictions for 2010 or a retrospective of 2009. But that’s just so clichéd; everyone does that or tries to. And as I’d wrote in a recent post about...