- Most enterprises view compliance as a "must-do" expense rather than a "should-do," value-added activity.
- IT is often left out of compliance discussions and is unaware of compliance requirements or non-compliance gaps.
- Organizations generally wait to improve compliance until mandated changes are dictated following an adverse audit or assessment.
Our Advice
Critical Insight
- Don’t gamble recklessly with external compliance. Play a winning system and take calculated risks to stack the odds in your favor.
- Take an agile approach to analyze your gaps and prioritize your remediations. You don’t always have to be fully compliant as long as your organization understands and can live with the consequences.
Impact and Result
Approach compliance proactively and derive value from the process by managing your compliance initiatives using a constant cycle.
- You need to initiate the drive to conform with regulations and improve compliance.
- You need to consistently assess the regulatory and business landscape to determine your compliance gaps.
- You need to improve compliance and remediate non-compliance in an effective, tactical manner.
- You need to confirm and assure compliance through regular adherence checks.
Info-Tech’s framework presented in this blueprint is compliant with COBIT MEA03 – Monitor, Evaluate, and Assess Compliance with External Compliance.
Member Testimonials
After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve. See our top member experiences for this blueprint and what our clients have to say.
7.0/10
Overall Impact
$2,599
Average $ Saved
5
Average Days Saved
Client
Experience
Impact
$ Saved
Days Saved
State of Wyoming
Guided Implementation
7/10
$2,599
5
Love having a sounding board who can readily digest my challenges and offer their own experiences of what has worked for them in the past. Would h... Read More
Government of Cayman Islands
Guided Implementation
10/10
$47,750
20
Andy Woyzbun was very knowledgeable which he provided valuable feedback is resourceful for moving the Cayman Islands Government Computer Services D... Read More
ISG Central Services Ltd.
Guided Implementation
7/10
N/A
N/A
External Compliance
Don't gamble recklessly with external compliance. Play a winning system and take calculated risks to stack the odds in your favor.
This course makes up part of the Security & Risk Certificate.
- Course Modules: 5
- Estimated Completion Time: 2-2.5 hours
- Featured Analysts:
- David Yackness, Sr. Research Director, CIO Practice
- James Alexander, SVP of Research and Advisory, CIO Practice
Workshop: Take Control of Compliance Improvement to Conquer Every Audit
Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.
Module 1: Launch Proactive Compliance
The Purpose
- Identify areas for compliance improvement.
- Identify benefits of compliance management.
- Identify: compliance priority, capability, budget, capacity requirements, and resource constraints.
- Establish External Compliance Management Working Group and compliance goals.
- Establish a starting point for compliance improvement.
Key Benefits Achieved
- Clearly defined pain points of compliance management.
- Defined compliance improvement plan.
- Defined compliance team, mandate, scope, and goals for compliance improvement.
Activities
Outputs
Define scope and mandate of compliance committee.
- Defined project charter.
Define roles and responsibilities.
- Defined roles and responsibilities.
Establish compliance goals.
- Defined compliance goals.
Module 2: Assess Compliance
The Purpose
- Identify relevant regulatory requirements.
- Determine a change management process.
- Determine compliance gaps within a limited workshop scope.
- Prioritize compliance gaps based on risk likelihood and impact.
Key Benefits Achieved
- Defined regulatory requirements.
- Determined change management process.
- Identified compliance gaps.
- Prioritized gaps.
Activities
Outputs
Define regulatory requirements.
- List of relevant regulations.
Define change management process.
- Assigned change management owner.
Conduct a sneak audit and prioritize gaps.
- List of prioritized compliance gaps (within limited workshop scope).
Module 3: Remediate Non-Compliance
The Purpose
- Determine plausible remediation plans for high priority gaps.
Key Benefits Achieved
- Planned remediation measures.
Activities
Outputs
Determine remediation plans.
- List of remediation plans.
Module 4: Confirm Compliance
The Purpose
- Confirm and assure compliance.
Key Benefits Achieved
- Identify recurring compliance gaps.
- Confirm adherence to remediation.
- Assure compliance.
Activities
Outputs
Conduct stakeholder interviews.
- List of recurring gaps.
Conduct sneak audit.
- List of root causes.
Conduct external/internal formal audit.
- Official findings.