ITGC


Managing the human dimension of Cyber Security.
Solution Features Solution Lifecycle

ITGC Lifecycle

The ITGC lifecycle includes the following steps, all automatically enacted by the ProcessGene GRC software Suite:

Lifecycle step IT GRC activity
ITGC context establishment
  1. Definition of related ITGC business processes
  2. Delineation of process diagrams (optional)
  3. Definition of IT Systems (using EA methods)
  4. Standardization and documentation of ITGC related policies and procedures
Risk identification and evaluation
  1. Risk description, identification of risk stakeholders
  2. Risk classification and determination of heat-maps
  3. Risk tolerance determination
  4. Risk prioritization
Control management
  1. Definition of controls to mitigate identified ITGC risks
  2. Assignment of ITGC control owners
  3. Scheduling and monitoring ITGC control execution
  4. Assessment of residual risk levels
ITGC audits
  1. Definition of ITGC audit plans
  2. Assign auditors and schedule audit tasks
  3. Collection, analysis and storage of ITGC audit results
  4. Remediation plan definition, execution and follow-up
Event management
  1. Collect and document IT related events
  2. Assess event implications
  3. Amendment of risk assessment and controls according to historical events
Data analysis
  1. View summarizing dashboards
  2. Extract and save user-defined reports
  3. Search data using ProcessGene’s robust and user-friendly search engine
Multi-Org ITGC
  1. Determination of a global ITGC compliance baseline with mandatory components
  2. Establishing a workflow for examining local (subsidiary) variants
  3. Enforcement of enterprise guidelines, regulations and frameworks within subsidiaries
  4. Control ITGC compliance level both locally (per subsidiary) and globally from a central HQ cockpit

The ProcessGene IT GRC Software Users

The ProcessGene IT GRC software solution provides value to the following users:
  1. C-level management (CEO, CFO, CIO, CRO, COO)
  2. Board of directors
  3. IT solution architects
  4. IT risk managers
  5. IT auditors
  6. Compliance officers