State of Security: Expert Insights on Cybersecurity Operations and the Business of Cyber

SOS8 - Building a Resilient GRC Program (with Rick Leib & Susan Woyton)


Listen Later

Summary

This episode focuses on governance, risk, and compliance (GRC) and how organizations can strengthen their GRC programs.

Key recommendations include:

  1. Ensure executive buy-in and support for GRC initiatives.
  2. Review and update policies, procedures, and documentation regularly.
  3. Implement continuous monitoring and improvement of GRC processes.
  4. Incorporate GRC elements into contracts with third parties.
  5. Conduct regular internal and third-party risk assessments.
  6. Provide security awareness training to employees.
  7. Consider the impact of AI on GRC, but maintain a human element in the process.

Chapters

00:00 Introduction

03:21 The Importance of Resilient GRC

08:33 Challenges and Failures in GRC

25:58 Executive Buy-In and Documentation

30:38 Continuous Monitoring and Improvement

35:24 Strengthening GRC Programs

...more
View all episodesView all episodes
Download on the App Store

State of Security: Expert Insights on Cybersecurity Operations and the Business of CyberBy Access Point Consulting