<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GRC Tool(s) in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/GRC-Tool-s/m-p/50085#M636</link>
    <description>&lt;P&gt;I have been struggling to find a good resource for juggling GRC and ITAM in a better way than spreadsheet tracking for a few months now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can easily create a risk register for a single system, and I can track my GRC compliance for an individual project in a separate spreadsheet fairly easily.&amp;nbsp; However, attempting to tie-in/track the overall program risks (both IT and operational) is something that has proven too difficult for me to track this way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm curious about the solutions in use in this community (ISC² professionals) and if you have any recommendations of things to avoid or look into.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried my best to look into Eramba as so many people recommend it, but the time investment required to get it to a usable state is too much for me.&amp;nbsp; I would much rather build a database from scratch than try to understand someone else's concept of what makes for a good GRC solution, but I do not have the time for that either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to be able to create a database of threats, link those to a database of targets, link those to departments and assign individual departmental impacts, and then generate a risk register.&amp;nbsp; Ideally, I could already have a database that links assets to departments and assigns a criticality to that department's workflow so when I assign a threat to the asset I would not have to manually assign an impact to the various departments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything out there like that?&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 10:07:48 GMT</pubDate>
    <dc:creator>noel</dc:creator>
    <dc:date>2023-10-09T10:07:48Z</dc:date>
    <item>
      <title>GRC Tool(s)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/GRC-Tool-s/m-p/50085#M636</link>
      <description>&lt;P&gt;I have been struggling to find a good resource for juggling GRC and ITAM in a better way than spreadsheet tracking for a few months now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can easily create a risk register for a single system, and I can track my GRC compliance for an individual project in a separate spreadsheet fairly easily.&amp;nbsp; However, attempting to tie-in/track the overall program risks (both IT and operational) is something that has proven too difficult for me to track this way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm curious about the solutions in use in this community (ISC² professionals) and if you have any recommendations of things to avoid or look into.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried my best to look into Eramba as so many people recommend it, but the time investment required to get it to a usable state is too much for me.&amp;nbsp; I would much rather build a database from scratch than try to understand someone else's concept of what makes for a good GRC solution, but I do not have the time for that either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to be able to create a database of threats, link those to a database of targets, link those to departments and assign individual departmental impacts, and then generate a risk register.&amp;nbsp; Ideally, I could already have a database that links assets to departments and assigns a criticality to that department's workflow so when I assign a threat to the asset I would not have to manually assign an impact to the various departments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything out there like that?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:07:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/GRC-Tool-s/m-p/50085#M636</guid>
      <dc:creator>noel</dc:creator>
      <dc:date>2023-10-09T10:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Tool(s)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/GRC-Tool-s/m-p/50091#M637</link>
      <description>&lt;P&gt;&amp;nbsp;A question before I attempt to answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you done Data and System Classification?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason, I ask, is that I was faced with similar issues working for a Global corporation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found many of my problems went away, once I classified the data and the systems (with the Business system owners).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2022 05:49:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/GRC-Tool-s/m-p/50091#M637</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2022-03-12T05:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Tool(s)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/GRC-Tool-s/m-p/50598#M661</link>
      <description>I have used ComplyAssistant. Affordable and robust, and good risk register and tracking, and auto send nag emails, etc.</description>
      <pubDate>Mon, 18 Apr 2022 15:06:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/GRC-Tool-s/m-p/50598#M661</guid>
      <dc:creator>jweller001</dc:creator>
      <dc:date>2022-04-18T15:06:19Z</dc:date>
    </item>
  </channel>
</rss>

