<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Risk Assessment in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37114#M31</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I use "Airtable" for this purpose. It is a super-vitamin "excel" software that provides more dynamic views, tables, and reports. I use it in my company and so far so good. I highly recommend you.&lt;BR /&gt;Best&lt;BR /&gt;Diego</description>
    <pubDate>Thu, 09 Jul 2020 13:55:58 GMT</pubDate>
    <dc:creator>DiegoRojas</dc:creator>
    <dc:date>2020-07-09T13:55:58Z</dc:date>
    <item>
      <title>Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37061#M26</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello ISC2 Community,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am 2 weeks into a new role leading Information Security with the initial goal of gaining SOC 2 certification.&amp;nbsp; This is a small 200+ private company with lots of work to do, developing policies, procedures, etc.&amp;nbsp; Question, is there a good Risk Assessment tool I could gain access to and use internally?&amp;nbsp; Would like to start internally prior to spending $$$ with a 3rd party.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Welcome feedback and guidance.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Linda&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:34:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37061#M26</guid>
      <dc:creator>Lwhite</dc:creator>
      <dc:date>2023-10-09T09:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37063#M27</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;There are some open source tools which can be helpfull. Most probably you could also get away with excel spreedsheet (just google for templates as there are tones of them).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://github.com/Risk-Assessment-Framework/RiskAssessmentFramework" target="_blank"&gt;https://github.com/Risk-Assessment-Framework/RiskAssessmentFramework&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 15:57:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37063#M27</guid>
      <dc:creator>Wiktor</dc:creator>
      <dc:date>2020-07-08T15:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37080#M28</link>
      <description>&amp;gt; Lwhite (Newcomer II) posted a new topic in Governance, Risk, Compliance on&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Hello ISC2 Community, I am 2 weeks into a new role leading Information Security&lt;BR /&gt;&amp;gt; with the initial goal of gaining SOC 2 certification.Â&amp;nbsp; This is a small 200+&lt;BR /&gt;&amp;gt; private company with lots of work to do, developing policies, procedures, etc.Â&amp;nbsp;&lt;BR /&gt;&amp;gt; Question, is there a good Risk Assessment tool I could gain access to and use&lt;BR /&gt;&amp;gt; internally?&lt;BR /&gt;&lt;BR /&gt;Would start off with Allegro (cut down OCTAVE) from Carnegie Mellon:&lt;BR /&gt;&lt;A href="https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=8419" target="_blank"&gt;https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=8419&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;See also NIST publications on the topic.&lt;BR /&gt;&lt;BR /&gt;Those should start you off with a good basis at no cost ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;I loved when my father made use of my mother's hands when he ran&lt;BR /&gt;out of useful digits on his own, during complicated&lt;BR /&gt;demonstrations, folding her fingers into stress coordinates, said&lt;BR /&gt;Avery. Years later, I remembered this habit of his and began to&lt;BR /&gt;wonder if my father had used other parts of my mother in private&lt;BR /&gt;demonstrations I never saw. I liked the idea that perhaps I was&lt;BR /&gt;the result of an intricate equation.&lt;BR /&gt;- `The Winter Vault,' Anne Michaels&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413" target="_blank"&gt;https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413&lt;/A&gt;</description>
      <pubDate>Wed, 08 Jul 2020 19:01:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37080#M28</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-07-08T19:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37081#M29</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1098899787"&gt;@Lwhite&lt;/a&gt;I also love Open Source GRC products such as eramba, which you can spin up the Docker container in seconds! (&lt;A href="https://github.com/digitorus/eramba" target="_blank" rel="noopener"&gt;here&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's not much more work to build a risk management solution on your own (except for the hours you'll put into defining the structure) then it is with a commercial product. I always joke/cry that you can get commercial software nothing but a song and dance, but then you will spend the next 3 years and 4 FTEs making it actually work for your company. Caveat emptor!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 19:03:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37081#M29</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-07-08T19:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37114#M31</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I use "Airtable" for this purpose. It is a super-vitamin "excel" software that provides more dynamic views, tables, and reports. I use it in my company and so far so good. I highly recommend you.&lt;BR /&gt;Best&lt;BR /&gt;Diego</description>
      <pubDate>Thu, 09 Jul 2020 13:55:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37114#M31</guid>
      <dc:creator>DiegoRojas</dc:creator>
      <dc:date>2020-07-09T13:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37284#M33</link>
      <description>&lt;P&gt;Thank you I'll take a look!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 17:20:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37284#M33</guid>
      <dc:creator>Lwhite</dc:creator>
      <dc:date>2020-07-14T17:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37285#M34</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp; This will be good for later. Right now I need something very simple and then will grow.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 17:21:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37285#M34</guid>
      <dc:creator>Lwhite</dc:creator>
      <dc:date>2020-07-14T17:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37985#M62</link>
      <description>&lt;P&gt;You can use a self-assesment based on ISO 27002 measures.(114)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your first work, is to defined your perimiter and the exlusions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use the commitment of your management and security policie&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 10:51:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/37985#M62</guid>
      <dc:creator>Benabdelmoumene</dc:creator>
      <dc:date>2020-08-11T10:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/38177#M73</link>
      <description>&lt;P&gt;The CIS RAM (&lt;A href="https://learn.cisecurity.org/cis-ram" target="_blank"&gt;https://learn.cisecurity.org/cis-ram&lt;/A&gt;) helped me get through risks assessment hurdles in the past. Last year I used this tool to get an organization ISO 27001 certified, and at my old organization it was useful in fulfilling the requirements of our SOC 2 audit.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 02:53:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/38177#M73</guid>
      <dc:creator>BillyAnglin</dc:creator>
      <dc:date>2020-08-16T02:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/48222#M539</link>
      <description>HI DiegoRojas&lt;BR /&gt;I am new to a role in Security Risk and Compliance and have been asked to use Airtable for a Risk Register, is this something you would be willing to share on how it works for you? I havent used Airtable before. I am happy to setup a meeting with you if you are willing? Thanks Nicole</description>
      <pubDate>Mon, 08 Nov 2021 02:27:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Risk-Assessment/m-p/48222#M539</guid>
      <dc:creator>nn4370</dc:creator>
      <dc:date>2021-11-08T02:27:08Z</dc:date>
    </item>
  </channel>
</rss>

