Defense in Depth

Is Governance the Most Important Part of GRC?

Mar 26, 2020
Mustapha Kebbeh, CISO at Brinks, shares his deep insights on the intersection of governance, risk management, and compliance (GRC). He emphasizes that strong governance practices are essential for meaningful GRC programs. Without effective leadership, achieving compliance becomes challenging. The discussion covers how actionable and accountable policies drive successful outcomes and the significance of integrating stakeholder perspectives for cohesive risk management. Discover how prioritizing governance can help organizations navigate the complexities of cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Effective GRC Implementation

  • Focus on actionable, accountable, and achievable GRC requirements.
  • Align the CISO's agenda with the GRC program for better harmony.
INSIGHT

Meaningful Governance and Enforcement

  • Governance and policies are useless without enforcement, requiring alignment with the tech stack.
  • Make risk meaningful to stakeholders by shaping behavior and guiding actions, not forcing compliance.
ADVICE

Policy and Procedure Documentation

  • Keep policy documents concise and high-level to encourage understanding and avoid overwhelming readers.
  • Separate detailed procedures from high-level policy for clarity and easier implementation.
Get the Snipd Podcast app to discover more snips from this episode
Get the app