accelerated-mobile-pages domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121easy-digital-downloads domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121edd_cfm domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121edds domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121edd-recurring domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121edd-recurring domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121Newsmag domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121The post Customized Automation: How to Optimize VRM appeared first on CISO MAG | Cyber Security Magazine.
]]>By Mike Kelly, CEO of ProcessBolt, and Gaurav Gaur, CTO and Co-founder of ProcessBolt
According to a survey conducted by Deloitte, only 1% of firms rate their VRM process as “optimized” and fully up to the task of reducing vendor risk.
So, what is the path to optimizing such an important business process?
An important first effort is standardization — creating uniform methods for completing VRM tasks. Then these standard methods are automated by integrating them into VRM software. This saves time, enabling the information security team to identify and remediate vendor risks.
But over-use of standardization can hinder VRM optimization. This is where customization plays a critical role.
VRM customization accommodates higher complexity. It allows companies to support process variations that increase complexity but reduce vendor risk exposure.
Does your VRM software facilitate customization?
If not, you have a substantial VRM optimization opportunity.
The path to VRM optimization begins with identifying repetitive manual tasks that can be standardized. Standardization emphasizes simplicity and efficiency. There are hundreds of specific VRM tasks that can be streamlined.
Cloud-based survey capability is a great example of a VRM process to simplify. Spreadsheet uploading errors, such as duplications or missing data, are greatly reduced. This leads to improved decision-making and vast savings in administrative time and effort.
As companies strive to automate, they can err on the side of too much standardization. They eliminate important nuances and complexities which sub-optimizes VRM effectiveness.
Customization lets you take the best parts of standardized formats like NIST (National Institute of Standards and Technology) or a SIG questionnaire (Standardized Information Gathering) but you then add other important questions. For example, maybe you should ask questions about regulatory compliance that are unique to your industry or your firm. Maybe you need GDPR-related (General Data Protection Regulation) questions if you do business in Europe. Other questions may be needed to explore CCPA compliance (California Consumer Privacy Act). Or, companies increasingly have ESG (Environment, Social, and Governance) issues that call for very specific compliance questions.
The solution is to strike the right balance between standardization and customization:
The VRM process can be summarized as flowing through five steps. Each affords opportunities to improve efficiency through standardization and effectiveness through customization. Here’s an abbreviated checklist of typical opportunities within each of the five VRM process steps.
A common complaint about GRC (Governance Risk Management & Compliance) solutions is that they go too far with VRM standardization, sacrificing customization for standardization. The result, sacrificing VRM effectiveness and risk reduction.
These solutions emphasize standardization because they deal with the whole enterprise’s internal cybersecurity. Then VRM is added along with other services such as disaster recovery and regulatory compliance to create a total business risk management solution. So, even without customization, GRC systems are highly complex. Adding customization is unthinkable … a bridge too far.
Just because you have a GRC solution does not mean you need to rely on it exclusively for VRM. A customized VRM solution can automatically feed your GRC platform with primary outputs such as:
By integrating a customized VRM solution with GRC, you can have the best of both worlds: a fine-tuned VRM solution and enterprise-wide integration with risk management.
About the Authors
Mike Kelly is the CEO of ProcessBolt, Inc., a Saas company that automates regulatory compliance and third-party risk assessments both for companies issuing assessments and those responding to assessments. Before joining ProcessBolt, Kelly led and ultimately grew and sold several software and analytics businesses in a variety of industries from healthcare to business and legal services.
Gaurav Gaur is the CTO and Co-founder of ProcessBolt. He has an extensive background in cybersecurity, vendor management, and software engineering. Before starting ProcessBolt, Gaur was the VP of Software Development at NetSPI Inc., a cybersecurity-focused software and consulting firm.
Disclaimer
Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.
The post Customized Automation: How to Optimize VRM appeared first on CISO MAG | Cyber Security Magazine.
]]>