Skip to main content

Kendall Morris

Showing posts by Kendall Morris.

A GRC Tool is Not a GRC Program

A GRC tool can provide many benefits to your GRC program. However, before you chase shiny objects, you must understand what a GRC program is and how a…

Read more

How to Provide Audit Evidence

So, you’ve been tasked with providing evidence for an audit. You may be wondering what your auditor is even looking for. Let’s take a look behind the …

Read more

Implementing Continuity in Your GRC Program

Every company must deal with governance, risk, and compliance. Often abbreviated as GRC, this business function is responsible for ensuring that major…

Read more

4 Benefits of a GRC Tool

A GRC tool can help an organization manage its governance, risk, and compliance program. But why use a GRC tool instead of managing your GRC program m…

Read more

How to Perform a Risk Assessment (Part 2)

After you perform a risk assessment, what do you do with the results? Find out the answers to that and other common risk assessment questions in part …

Read more

How to Perform a Risk Assessment (Part 1)

How do you perform a risk assessment, and what do you do with the results? Find answers to some common risk assessment questions in Part 1 of our two-…

Read more

How to Read a SOC 2 System Description

In this blog, we’ll dive into one of the most important parts of a SOC 2 report, the SOC 2 System Description! During your due diligence process, a ve…

Read more

HITRUST Validated Assessment: 5 Things to Prepare For

Preparing for your HITRUST Validated Assessment is no small task. With a little bit of preparation, you can ensure that the assessment goes smoothly. …

Read more

SOC 2 vs ISO 27001: What's The Difference?

Navigating the ins and outs of two of the most popular compliance frameworks. When it comes to vendor due diligence, many companies are raising the ba…

Read more

Common Misconceptions About the ISO 27001 Framework

Answering some of the most commonly asked questions around ISO 27001 implementation. At risk3sixty, we have helped many clients implement ISO 27001. T…

Read more

Securing the Work-from-Home Environment During COVID-19

Tips for security administrators during the COVID-19 pandemic We have seen a massive increase in the number of employees working from home due to the …

Read more

How to Read a HITRUST Validated Assessment

Understanding the results of a HITRUST engagement and how to use them. During your vendor due diligence process, a vendor sends you their HITRUST repo…

Read more

Tags

See all