REGISTER

email 14 48

Landing Pages


Lockpath White LogoThe 7 Elements in Building an Advanced IT Security Defense System

Download Now 

Digital transformation offers promise but also brings peril. Bad actors, hackers, black hats, whatever you want to call them, are constantly probing and attacking company networks. In fact, researchers have found it only takes seconds before hackers attack newly connected devices and services.

In this new e-book, Lockpath, a leader in IT GRC and Continuous Security Monitoring solutions, provides insights into the core elements of an advanced IT security defense system and how companies can evolve the way they protect against threats.

 

 

Download the E-Book Now!
Copyright © 2019 Executive IT Forums, Inc. All Rights Reserved.

About the IT GRC Forum
CPEThe IT GRC Forum is the premier online resource  for Governance, Risk Management, and Compliance (GRC) Executives. We produce educational events and provide market intelligence for our members, and offer CPE credits via our programs. Executive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education.

Address: 1 Penn Plaza, Suite 6272, West 34th Street New York, NY 10119

Phone: (646) 525-4801Visit us at www.executiveitforums.org

 


Galvanize white hKRI Basics for IT Governance

Download Now 

As an IT risk or security professional, you bear the responsibility of safeguarding your organization from IT threats. Establishing the right set of Key Risk Indicators (KRIs) plays a critical role in detecting potential risks that can halt business operations or cause reputational damage. But many IT departments aren’t sure of where to get started.

This white paper will provide you with a foundational understanding of KRIs and give actionable tips to help you overcome the common challenges of implementing, managing, and maintaining KRIs. Plus, we provide three jam-packed pages of example KRIs for IT professionals. By the time you’re done reading, you’ll have a roadmap to ensure your IT governance program is a success. 

 

 

Download White Paper Now!
Copyright © 2019 Executive IT Forums, Inc. All Rights Reserved.

About the IT GRC Forum
CPEThe IT GRC Forum is the premier online resource  for Governance, Risk Management, and Compliance (GRC) Executives. We produce educational events and provide market intelligence for our members, and offer CPE credits via our programs. Executive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education.

Address: 1 Penn Plaza, Suite 6272, West 34th Street New York, NY 10119

Phone: (646) 525-4801Visit us at www.executiveitforums.org

 


 

Galvanize white h

Vendor Risk Management Solution Checklist

 

As companies continue to outsource more aspects of their operations to third parties, they expose themselves to more shared risk. Most organizations understand the need to automate vendor risk management (VRM) activities to keep up with increasing scope and scrutiny. Yet they struggle to identify and prioritize the key features their VRM solution must provide so they can make a significant impact quickly.

To help with this challenge this checklist outlines features to look for in a VRM solution and explains key areas where you can start mitigating vendor risk today.

 

 

Download your checklist now >>
Copyright © 2019 Executive IT Forums, Inc. All Rights Reserved.

About the IT GRC Forum
CPEThe IT GRC Forum is the premier online resource  for Governance, Risk Management, and Compliance (GRC) Executives. We produce educational events and provide market intelligence for our members, and offer CPE credits via our programs. Executive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education.

Address: 1 Penn Plaza, Suite 6272, West 34th Street New York, NY 10119

Phone: (646) 525-4801Visit us at www.executiveitforums.org

 

IT GRC Forum    Research   

  pdf Cloud Risk Surface Report (1.54 MB)


cloudriskreportNavigating safely in cloudy condition

This report (re)uses the same data set behind the Internet Risk Surface Report. It is derived from RiskRecon’s work in providing companies objective visibility into their third-party cybersecurity risk. For each organization analyzed, RiskRecon trains machine learning algorithms to discover internet facing systems, domains, and networks. For every asset discovered, RiskRecon analyzes the publicly accessible content, code, and configurations to assess system security and the inherent risk value of the system based on attributes such as observable data types collected and transaction capabilities. RiskRecon provided Cyentia a large anonymized sample of their production data set for this research. 

Having studied several broad aspects of the Internet risk surface, we now seek to narrow the focus to consider how the cloud shapes that surface. The benefits of migrating data, workloads, applications, and business processes to the cloud are incredibly compelling. But as a steady string of headlines reporting large data exposures from cloud environments suggest, those benefits don’t come risk-free. Is the risk worth it? To help you answer that for your organization, we leverage a massive dataset supplied by RiskRecon spanning 18,000 organizations and over 5 million hosts yielding 32 million security findings. Read on for a preview of the fascinating facts and figures we share in this report.

pdf Download (1.54 MB)

 


About the IT GRC Forum

The IT GRC Forum is an online resource and networking platform for Governance, Risk Management, and Compliance (GRC) Professionals. We produce educational events and provide market intelligence for our members, and it is our goal to help industry stakeholders, government regulators, and end-users better understand and manage the increasingly complex GRC landscape across their organization. Visit us at www.executiveitforums.org

 

 

 

 


Galvanize white hMaking ITGC testing easier through automation

Register Now! 

There’s no question that providing assurance on the effectiveness of IT controls is time-consuming and repetitive. And as cloud-use and mobile apps become more prevalent, external auditors want even more assurance over data validity, integrity, and completeness of testing. But performing access testing by manually downloading user lists and running reports is highly inefficient and not a sustainable way to get the assurance you need.

Join us on this 60-minute webinar to discover how to improve your ITGC testing, including:

  • how to automatically connect to systems like Active Directory, SAP ERP, and Salesforce to maximize the efficiency of user access control testing.
  • how to apply a standardized user access matrix to speed up quarterly system access reviews and certifications.
  • how to work in HighBond to centralize and coordinate user access reviews across the business to reinforce the completeness and validity of testing.
 

 

Register Now!
Copyright © 2019 Executive IT Forums, Inc. All Rights Reserved.

About the IT GRC Forum
CPEThe IT GRC Forum is the premier online resource  for Governance, Risk Management, and Compliance (GRC) Executives. We produce educational events and provide market intelligence for our members, and offer CPE credits via our programs. Executive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education.

Address: 1 Penn Plaza, Suite 6272, West 34th Street New York, NY 10119

Phone: (646) 525-4801Visit us at www.executiveitforums.org

 


 

Galvanize white h

        Strategy to Tactics:           How to Tackle Third-Party Risk Management

 

The use of third-party vendors has increased exponentially, exposing organizations to high-profile risks like never before. This is why third-party risk management (TPRM) now consistently features on board agendas in forward-thinking companies.

Join this virtual event and discover how to build a strategy and implement practical tactics to tackle the common challenges of TPRM.

Session 1: Strategy | Your blueprint for an effective TPRM strategy
Get a blueprint for building an effective, cross-functional strategy for managing third parties in today’s dynamic environment of evolving business, regulatory, and risk challenges.

Session 2: Tactics | Why automation is key to a successful TPRM process
Discover how to automatically collect and screen vendor information so you can more effectively mitigate risk and provide a consistent onboarding process.

Session 3: Demo | How to minimize and manage your third-party risk exposure
See how the Galvanize solution, ThirdPartyBond, automates the entire TPRM lifecycle—from onboarding, assessment, and remediation, to performance monitoring and ongoing review.

 

 

Register Now!
Copyright © 2019 Executive IT Forums, Inc. All Rights Reserved.

About the IT GRC Forum
CPEThe IT GRC Forum is the premier online resource  for Governance, Risk Management, and Compliance (GRC) Executives. We produce educational events and provide market intelligence for our members, and offer CPE credits via our programs. Executive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education.

Address: 1 Penn Plaza, Suite 6272, West 34th Street New York, NY 10119

Phone: (646) 525-4801Visit us at www.executiveitforums.org

 

IT GRC Forum    Research   

  pdf GDPR for Third-party Risk Management eBook (5.68 MB)


RRgdprtnEverything you need to know to stay compliant

Europe’s GDPR is widely-discussed in today’s news cycles and for good reason. The regulation impacts many organizations throughout the world, and violations of the regulation can result in material fines. One big question remains for many businesses, how do third-party services fit into this new regulation and what can organizations do to protect themselves from third-party risks to meet the standards?

In this eBook we explore three key topics related to GDPR:

  • How organizations go from violations to fines
  • What the new fines mean for you and what your organization can do
  • Third-party risk management obligations

 

pdf Download (5.68 MB)  a complimentary copy of the eBook now to learn how to stay GDPR compliant.

 


About the IT GRC Forum

The IT GRC Forum is an online resource and networking platform for Governance, Risk Management, and Compliance (GRC) Professionals. We produce educational events and provide market intelligence for our members, and it is our goal to help industry stakeholders, government regulators, and end-users better understand and manage the increasingly complex GRC landscape across their organization. Visit us at www.executiveitforums.org

 

 

 

 


 

Galvanize white h

CISOs in the Boardroom: Presenting Cyber Risk Storyboards with Confidence

Register Now! 

With cybersecurity becoming a top concern for boards of directors, CISOs finally have a seat at the table. But what happens when you have to deliver information on cybersecurity policies, risks, threats, and incident response plans to stakeholders who often don’t have the same technical understanding as you?

Join us on this 60-minute webinar, where we share how CISOs can overcome the challenge of transforming their tactical plans to a higher-level story that’s tailored for the board. You'll also learn:

  • How online storyboards make it easy to confidently communicate risk with a specific focus on the business value.
  • How combining and analyzing data from different sources results in a more effective explanation of your security maturity.
  • How to build a culture that religiously uses metrics to consistently make strategic, data-driven decisions.
 

 

Register Now!
Copyright © 2019 Executive IT Forums, Inc. All Rights Reserved.

About the IT GRC Forum
CPEThe IT GRC Forum is the premier online resource  for Governance, Risk Management, and Compliance (GRC) Executives. We produce educational events and provide market intelligence for our members, and offer CPE credits via our programs. Executive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education.

Address: 1 Penn Plaza, Suite 6272, West 34th Street New York, NY 10119

Phone: (646) 525-4801Visit us at www.executiveitforums.org

 


 

Galvanize white h

Live webinar: Is your IT VRM program ready for 2020?

 

The new year is just around the corner. Do you know which trends and technologies will hit your organization the hardest—and increase its vendor risk exposure the most? Equip yourself with the right industry research and tactics to improve your IT vendor risk management (VRM) strategy.

Join us online on December 11th to find out if your IT VRM program is ready for 2020. In this session, we’ll discuss how to approach VRM in a climate of digitalization and diverse emerging technologies (think cloud, mobile, AI, and IoT). Plus, you’ll hear real-life lessons learned to help you build a strong VRM program for your organization.

Key takeaways:
• The emerging trends affecting IT VRM and how to respond
• Which areas to invest in to enhance your IT VRM program
• How to get stakeholder buy-in when making program changes
• The common challenges and pitfalls to avoid in your IT VRM strategy
• How technology helps you focus on what matters most
 

 

Register Now!
Copyright © 2019 Executive IT Forums, Inc. All Rights Reserved.

About the IT GRC Forum
CPEThe IT GRC Forum is the premier online resource  for Governance, Risk Management, and Compliance (GRC) Executives. We produce educational events and provide market intelligence for our members, and offer CPE credits via our programs. Executive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education.

Address: 1 Penn Plaza, Suite 6272, West 34th Street New York, NY 10119

Phone: (646) 525-4801Visit us at www.executiveitforums.org

 

The 2019 Gartner Magic Quadrant for IT Vendor Risk Management Tools

Most organizations today are looking for opportunities to use new technologies like cloud, mobile, AI and IoT to better serve customers, grow revenues, and cut costs. As a result, IT departments must increasingly rely on external vendors—which introduces new, unprecedented risks.

Managing these risks is an ongoing challenge for many risk and security professionals. Having the right tools and processes in place is critical for success.

The Gartner Magic Quadrant for IT Vendor Risk Management Tools is an evaluation of 16 solutions within the growing IT vendor risk management landscape. We believe it will help you identify solutions that will improve the efficiency, effectiveness, and confidence in your vendor risk processes. Download the full report to evaluate this growing and dynamic technology market.

Download your copy »

 

IT grc logo 1


CPE Webinar:

Key Steps to Mature Your Third-Party Risk Management Program

Hi [fname],

High-Profile Data Breaches have placed a spotlight on the risk of cyber security breaches with vendors and subcontractors, expanding the need to have greater rigor in third party risk management and ongoing risk assessments. Maintaining an effective third-party risk management program doesn't happen overnight. It's a journey that involves continual learning, refinement and evolution.

And as a program matures over time, it results in the management of vendors and other third parties with fewer risks, lower costs, better performance and stronger compliance. Since every company is at a different place in their journey towards better vendor management, it's important to identify steps that you can follow as you mature your program, and to consider your vendor risk ecosystem and the data and services that can have an enormous impact on risk reduction. On this CPE accredited webinar our panel of experts will address some key steps to mature your third-party risk management program.

Attend live to earn 1 CPE Credit and learn how to:

  • Create a third-party risk-management maturity roadmap,
  • Connect with enterprise systems to create a centralized data repository and enable seamless vetting activities across processes,
  • Incorporate external content sources for a more wholistic view of your vendors plus more sustainable ongoing monitoring,
  • Strengthen and streamline your third-party risk management efforts.

Speakers:

Colin Whittaker (Moderator), Founder and Director at Informed Risk Decisions;
Todd Boehler, VP of Product Strategy, at Process Unity;
Mark Deluca, SVP at Coupa;
Chris Poulin, Principal Consulting Engineer at BitSight;
Jason Sabourin, Product Manager at OneTrust.

Register for the Webinar Now
 
Copyright © 2019 Executive IT Forums, Inc. All Rights Reserved.

About the IT GRC Forum
CPEThe IT GRC Forum is the premier online resource for Governance, Risk Management, and Compliance (GRC) Executives. We produce educational events and provide market intelligence for our members, and offer CPE credits via our programs. Executive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education.

Address: 1 Penn Plaza, Suite 6272, West 34th Street New York, NY 10119

Phone: (646) 525-4801 | Visit us at www.executiveitforums.org

 
IT GRC Forum    Research   

  pdf The Forrester New Wave™: Cybersecurity Risk Rating Solutions, Q4 2018 (703 KB)


Forrester New Wave Social imageThe Nine Providers That Matter Most And How They Stack Up

In Forrester’s evaluation of the emerging market for cybersecurity risk rating solutions, we identified the nine most significant providers in the category — Bitsight, Fico, iTrust, Normshield, Panorays, Prevalent, Riskrecon, SecurityScorecard, and upGuard — and evaluated them. This report details our findings about how well each vendor scored against 10 criteria and where they stand in relation to each other. Security and risk (s&r) professionals can use this review to select the right partner for their cybersecurity risk rating solution needs.

Key Takeaways

Forrester’s research uncovered a market in which Bitsight, RiskRecon, Prevalent, and SecurityScorecard are leaders; Panorays and Fico are strong Performers; and upGuard, Normshield, and iTrust are challengers. Risk Analytics, entity Attribution, and Rating Consistency are key differentiators. The best cyber-risk rating solutions don’t merely report on your third-party partners’ security flaws, they contextualize and prioritize the risk information they collect so you can more strategically allocate resources and mitigate risk.

pdf Download (703 KB)

 


About the IT GRC Forum

The IT GRC Forum is an online resource and networking platform for Governance, Risk Management, and Compliance (GRC) Professionals. We produce educational events and provide market intelligence for our members, and it is our goal to help industry stakeholders, government regulators, and end-users better understand and manage the increasingly complex GRC landscape across their organization. Visit us at www.executiveitforums.org

 

 

 

 

IT grc logo 1

 

ProcessUnity Scores Highest in Gartner Review of IT Vendor Risk Management Software

In the newly published 2019 Critical Capabilities for IT Vendor Risk Management Tools, Gartner has given ProcessUnity the highest scores for two Vendor Risk Management use cases most requested by Gartner clients.

gartner-vendor-risk-management-cc-2019.jpg

The report evaluates IT Vendor Risk Management solution providers across key functional areas including:

  • Assessments
  • Workflows and Collaboration
  • Access and User Controls
  • User Interface and Navigation
  • Connectors and Integration
  • Configurability
  • Remediation Management
  • Vendor Profile Management

See how each vendor was scored. Get your complimentary copy of the 2019 Gartner Critical Capabilities for IT Vendor Risk Management Tools report now.

GET THE REPORT
Gartner Critical Capabilities for IT Vendor Risk Management Tools, December 19, 2019, Christopher Ambrose and Joanne Spencer

This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from ProcessUnity. Disclaimer: Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
 
Log in Register

Please Login to download this file

Username *
Password *
Remember Me
Go to top