on ‎2009 Apr 14 9:42 AM
Good day all,
I have been tasked with creating "generic" mitigating controls for all risks in our 5.3 GRC installation. This means I must develop about 280 general mitigating controls. This is so that when we do an install at a client, we can assist them quickly to populate the mitigating risks. Has anyone done this? If so would you be able to share the information with me.
Thank you
Regards
Jill
Help others by sharing your knowledge.
AnswerRequest clarification before answering.
Hello Jill,
Never really tried this in practical but yes, considering how much efforts can be avoided for the re-work by doing this; this surely sounds like a good planing task.
However, for this to work effectively there would be an underlying assumption that all the clients acknowledge to take all these risks and Mitigation Controls for their landscapes. So for this, you should be very particular about the word "Generic" and identify them as per the best practices across clients which might be from the same industry or different, as per your scope of work.
Regards,
Hersh.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.