This is Yo Delmar's Typepad Profile.
Join Typepad and start following Yo Delmar's activity
Yo Delmar
A MetricStream exec with a passion for Governance, Risk and Compliance
Interests: travel, chocolate, oil painting, hiking, cosmology, and any excuse to visit to her homeland canada!
Recent Activity
GRC Framework - Stable Stakes for Good Management
Posted May 10, 2012 at Yo Delmar's GRC and Beyond Blog
Comment
0
GRC and Risk Appetite formulation – A critical skill that executive management must develop to thrive in today’s climate.
If there is one element of a GRC framework upon which all else depends, it is the correct formulation of risk appetite, and the translation of appetite into tolerances, thresholds and limits that the organization must operate within. Without this, it’s simply impossible to manage risks effectively.
Risk appetite can be defined as the quantity and types of risk that an organization is willing to assume in pursuit of its strategic objectives. Boards are typically responsible for setting risk appetites, and executive teams then implement them into the business by translate those appetites into more granular risk-taking limits within the most fundamental operating processes. Continue reading
Posted Apr 11, 2012 at Yo Delmar's GRC and Beyond Blog
Comment
1
Risk Framework: Managing Content – What’s the best practice governance process?
Posted Feb 8, 2012 at Yo Delmar's GRC and Beyond Blog
Comment
0
Risk Framework: Five Easy Steps (yes, you can try this at work)
Posted Jan 21, 2012 at Yo Delmar's GRC and Beyond Blog
Comment
0
GRC Fundamental Component: Risk Ontology
Posted Oct 21, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
1
Why do we need GRC? Five Forcing Functions - Video!
Why do we have governance, risk, and compliance? here is an interactive video on why GRC is so important supported by an overview of the 5 forcing functions of governance, risk, and compliance. Continue reading
Posted Sep 14, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
0
GRC Forcing Function: The Digital Universe
EMC has been sponsoring the annual IDC Digital Universe Study for five years – and we’ve been saying the horrendous growth in information is one of the main Five Forcing Functions driving growth and adoption of GRC. The 2011 Digital universe Study is in – and the numbers will shock you. Here's a taste: Digital information in the world is doubling every two years Continue reading
Posted Jun 30, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
0
Privacy and GRC – What the New Ponemon Study and the GAPP is Telling Us
Posted May 25, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
1
Five Simple Questions Core to GRC Program Success
Posted Mar 31, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
0
Japan Disaster: Reminding us why we need GRC that integrates Business Resilience, Risk and Incident Management
Japan's devastating earthquake, subsequent tsunami and current power plant threats remind us that we live in a world where the combination and cascading effect of threats raises risks beyond what we consider a reasonable threshold. Centralizing approaches to business continuity, disaster recovery, risk and crisis management is a pure GRC use case. And increasingly an urgent one. Continue reading
Posted Mar 18, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
0
GRC in the Cloud - Control + Visibility = Trust – Some examples from VmWare and RSA
GRC in the Cloud - Control + Visibility = Trust – Some examples from VmWare and RSA
Here’s the basic problem: Information in the cloud is constantly on the move – that’s the side effect of cloud’s basic benefits of resource utilization and service availability. This mobility, of course, is what drives security and GRC people crazy because it implies we don’t have visibility into where our information is, or control over where it goes, how it is used or who accesses it. Hybrid cloud GRC platforms can gain unprecedented levels of visibility and control by harvesting from monitoring systems to ensure that the hybrid cloud infrastructure conforms to security specifications, and that information is controlled in compliance with policies and regulations. Continue reading
Posted Feb 24, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
0
Why the Hybrid Cloud will Accelerate GRC Platform Adoption
After this week at the RSA Conference I’m convinced more than ever that one of the five forcing functions – virtualization and cloud computing- in particular, the hybrid cloud - is going to give GRC a majorly big push this year – driving the need for more standardization, visibility and control that GRC can provide. Hybrid Cloud makes GRC all that more vital. Why? Think of the hybrid cloud as meta-silos – now we aren’t just dealing with the need to integrate GRC across the internal organization – but now across the entire extended enterprise. Continue reading
Posted Feb 18, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
0
Cloud Assessments – Try the Cloud Security Alliance Consensus Questionnaire
Check out the of CSA’s main accomplishments has been advancing the adoption of the Cloud Controls Matrix into international standards communities. An important new development is the Consensus Assessments Initiative (CAI) Questionnaire – a spreadsheet that cloud consumers and assessors can use to understand what security controls Cloud Service Providers (CSPs) have implemented in their exist in IaaS, PaaS, and SaaS offerings. The Questionnaire is a companion to the CSA Guidance and the CSA Cloud Controls Matrix. Use it with CSPs you are considering – test it and give feedback to on what works and what doesn’t to the CSA working groups. Continue reading
Posted Jan 21, 2011 at Yo Delmar's GRC and Beyond Blog
Comment
0
Cloud Trust – Are you keeping up with your organization’s plans for monetizing the cloud?
Cloud Trust – Are you keeping up with your organization’s plans for monetizing the cloud? Many enterprises are now embracing cloud computing – especially as a model to quickly launch new products and services. As GRC professionals, we are not always privy to these plans until they are well underway and can find ourselves in the position where we are trying to assure governance and security controls are in place in hosted environments – after the fact. Continue reading
Posted Oct 14, 2010 at Yo Delmar's GRC and Beyond Blog
Comment
0
Cloud Security -Certification of Cloud Security Knowledge
Cloud Security -Certification of Cloud Security Knowledge - there is a good certification now available online (for $195 through Dec 2010) at the Cloud Security Alliance. Launched in July, it is a 50 question, multiple choice test that must be completed in 60 minutes - but don't worry - there is a study guide available at CCSK Study Guide. Continue reading
Posted Sep 12, 2010 at Yo Delmar's GRC and Beyond Blog
Comment
2
Cloud Audit – Paving the Way to the GRC Enabled Cloud
I’ve just joined one of the Cloud Audit working groups – focused on developing controls for cloud computing. What has been holding us back are consistent and standardized frameworks, open standards and interfaces that address not only controls but also easy to implement processes to provide assurances on levels of GRC and security in cloud environments. Enter Cloud Audit, designed to smash down the roadblocks and getting us flying in the cloud.
Central to the groups’ work is something called A6 – which stands for Automated Audit, Assertion, Assessment, and Assurance API. The idea is that cloud providers and consumers of their services should be able to leverage an open, extensible and secure set of interfaces for Cloud GRC and Security. Continue reading
Posted Aug 23, 2010 at Yo Delmar's GRC and Beyond Blog
Comment
0
IT GRC Lifecycles – supporting each of Governance, Risk and Compliance – how about ITIL?
Posted Apr 16, 2010 at Yo Delmar's GRC and Beyond Blog
Comment
0
Yo Delmar is now following The Typepad Team
Mar 16, 2010
The Web is 20 years old, what now in the next 20?
Posted Feb 3, 2010 at Yo Delmar's GRC and Beyond Blog
Comment
5
Journey to the GRC-enabled Cloud - What are likely scenarios?
As the Cloud evolves to become GRC-enabled, there are likely to be events that force its evolution. I am thinking of a few, and you may have many others. They may happen sequentially, but a more likely to happen simultaneously for all practical purposes… 1. Bad things happen early on, forcing adoption of GRC-enabled cloud services. Cloud consolidates lots of information in one world, making it attractive to those who would benefit from exploits. Clouds will be tested by some of the best criminal minds, not to mention the best intentioned humans who simply mess up. We will learn where... Continue reading
Posted Dec 5, 2009 at Yo Delmar's GRC and Beyond Blog
Comment
0
The GRC-enabled Cloud – governance, risk and compliance may be simpler, faster, cheaper, more trusted – eventually
When we talk about the Cloud, whether it is an internal cloud and external cloud (i.e. public cloud) or a private cloud (i.e. hybrid cloud), we are inevitably led to consider GRC. To date the Cloud GRC discussion has been limited to issues of privacy, trust, reliability and availability, narrowly focused at times on security. Going forward, we need to broaden the Cloud discussion to imagine the scenarios where the Cloud is GRC-enabled, at the appropriate level, matching the precise needs of its diverse and distinct user communities. Continue reading
Posted Nov 17, 2009 at Yo Delmar's GRC and Beyond Blog
Comment
0
GRC is Transforming - BELIEVING with emperical, granular evidence
Posted Nov 9, 2009 at Yo Delmar's GRC and Beyond Blog
Comment
0
GRC is Transforming - UNDERSTANDING with Contextual Relevance and Traceability
Posted Nov 1, 2009 at Yo Delmar's GRC and Beyond Blog
Comment
0
GRC is transforming…. SEEING with Visualization and Analytics
Posted Oct 21, 2009 at Yo Delmar's GRC and Beyond Blog
Comment
0
Good point Steph - I think if we had to boil it down to one word, transparency would be a good candidate. It implies visibility - but not so much accuracy......Mike Rasmussen likes to think about it as crossing the BOUNDARIES, which implies that there exists a notion a threshold....
GRC: Managing the Pursuit of Shareholder Wealth at the Margins
I’ve been thinking more lately about what GRC really is, in its purist, simplest form. How do we explain the real motivation behind combining these three basic elements? I had one of those thoughts that makes you smile during dinner last week with a few of my EMC colleagues. It’s this: Enterpri...
More...
Subscribe to Yo Delmar’s Recent Activity