Some of these organizations produce a shared practice guidance while
others share practices. Both help improve the profession and practice
in the industry.
• IT Governance Institute IT-Enterprise Risk Management Task Force to
produce RiskIT
• Open Compliance & Ethics Group, Foundation Review Committee
• Shared Assessment Program –Technical
Development Committee and AUP Committee
• Risk Management Association, operational risk
• Financial Services Technology Consortium, Business Continuity Standing
Committee
In addition to these, we also track a range of others that are
industry-specific, country-specific or domain-specific. These
include:
- ISACA RiskIT
- ISACA ValIT
- ISACA COBIT
- COSO ERM
- A Risk Management Standard (UK)
- ISO 31000 (Risk Management)
- Range of quality control practices
- UK OGC ITIL
- Various Business Continuity practices
- and more...
This knowledge
brings a library of information to your doorstep, short-cutting your efforts
to get to business results.Using such practices is more than
just an accelerator. They also make it easier for you to communicate with
external parties such as supply chain partners, customers and auditors.
They provide a common language and approach based on the experience of many
firms.
Using these, we focus on tailoring to your specific needs, not
reinventing the wheel. To do this, we use workshops and other approaches to
bring together aspects of various best practices in a way that helps you
most, given your maturity, your business objectives and your priorities.