Designing a GRC Framework

Presented by

Richard Hollis, Director, Risk Factory

About this talk

What is the essence of information security governance, risk & compliance? How do you meet your governance, risk and compliance requirements and prevent a data breach? The key is to understand the spirit of risk management and create a customised information security management system (ISMS) for your business. This presentation details a practical, step-by-step guide for designing and implementing a cost-effective ISMS to minimise your risk of a breach and meet your Association’s legislative (Data Protection Act), regulatory (Payment Card Industry), or industry standard (ISO-27001) compliance requirements to include: · Practical ISMS documentation structure · Scope, objectives & risk strategy examples · Risk treatment plan, asset register & classification guide examples · Policy frameworks · Control objectives, evidence & policy examples · Audit & testing documentation examples

Related topics:

More from this channel

Upcoming talks (8)
On-demand talks (1835)
Subscribers (188277)
This channel features presentations by leading experts in the field of information security. From application, computer, network and Internet security to access control management, data privacy and other hot topics, you will walk away with practical advice for your strategic and tactical information security initiatives.