The Story Must be Told

GRC slider image - discover Continuum GRC ITAM for automated compliance AI-powered cybersecurity 2025 zero trust ransomware protection supply chain security regulatory compliance operational resilience
0

Regardless of the control framework or standard we work with, the following fundamental narrative elements apply.

Each control response and test design description narrative must contain as many of the following four (4) categories as possible to be considered complete.

  • People: Who is involved with ensuring a control requirement is compliant and effective? The Who might be the HR Department, or the CISO, or Jane Doe specifically.

  • Processes: Every company has a method of operating and performing tasks. These processes should be defined in a way that everyone understands how that process works to enforce control effectiveness.

  • Policies: There is frequently a policy, or procedural document in place (or should be!) to define how a client sets the standard, or process, or regulatory requirement.

  • Technologies: Most control requirements have a technical implementation for effectiveness and enforcement. It may be an external service provider, or an internal technology, but regardless, define it. Provide product names, platform names, third-party names, and all the details needed to completely articulate what is in scope and under test.

Michael Peters

Website:

Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015. A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA. Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.