GRC Journal - (Page 96) BUILDING A BRIDGE “Frameworks, technology, standards, and guidelines can only be effective if an organization has a deep understanding of the breadth and scope of what it seeks to accomplish.” - Scott Mitchell resources to reduce cost and improve performance at almost every step of a GRC program. Setting up the initial GRC program, gap remediation, benchmarking and an effective approach to assessments are all business benefits of the OCEG Framework. In addition, the OCEG Framework underwent an open and public development and review process to help ensure that it is an armslength, objective standard. What are the first steps organizations should take when approaching GRC? SM First and foremost, get organized. Identify risks, requirements and obligations, inventory existing systems, processes and precedents, and make an honest assessment of the prevailing corporate culture. Identify and communicate what objectives must be met and the roles and individuals that must come together to hit these objectives. Frameworks, technologies, standards, and guidelines can only be effective if an organization has a deep understanding of the breadth and scope of what it seeks to accomplish. What is the role of IT in the development implementation and automation of GRC practices? SH IT has a dual role – the first is its traditional role of providing technology and service to support its internal constituencies such as finance, legal, and HR to ensure that they have the best tools and technology practices to fulfill their GRC requirements; the second role is to act as its own internal client. The second role is new to most organizations, but IT has its own set of governance, risk, and compliance management requirements that it must meet as a part of an organization’s broader obligations and objectives. Q3 2006 | www.btquarterly.com BTQ Business Trends Quarterly 23 http://btquarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.