Comment
  1. Javier Lopez says:

    May 17, 2011 at 9:43 am

    Thanks for the article. These are great guidelines to follow. I especially appreciate #5 regarding identifying a standard suitable for the organization. This is something I find particularly difficult when the culture of a company has never been around security or compliance.

    If possible, could you elaborate on #11 (tool). What tools do other companies and organizations use? And do you find that they vary depending on compliance requirements and company size?

    • Thiru says:

      May 18, 2011 at 1:04 am

      Thanks for your comments Javier.
      As for the tools,yes, size and compliance requirements do matter in the selection of the right tool for you.
      1.CRAMM from Siemens is popular and is definitely useful.
      2.ISMS RAT is the simplest of all i guess.
      3.Others are RiskPac, RiskWatch
      There are other solutions, so called GRC suites that are more expansive in coverage & application. GRC solutions can manage policies, controls, assess risks, manage audit and report on complianc with good data analytics & reporting. GRC is offered by Protivity, Thomson Paisley, MEthodware, Metricstream, SAPGRC, Oract GRC manager, EMC2s’ Archer eGRC, CCH TeamMate, Modulo, etc., THese can be very expensive.

Leave a Comment
Your email address will not be published. Required fields are marked *
Name *
Email *
Comment*
 


Archives
Find us on
Facebook LinkedIn Twitter Youtube Slideshare
Tumblr Pinterest
BlogCatalog Member