From the course: Governance, Risk, and Compliance (GRC) for the Cloud-Native Revolution
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
From manual point-in-time testing to continuous monitoring - Amazon Web Services (AWS) Tutorial
From the course: Governance, Risk, and Compliance (GRC) for the Cloud-Native Revolution
From manual point-in-time testing to continuous monitoring
- [Instructor] If you work in GRC, you know very well that audits are both challenging and overwhelming. Getting all the evidence you need in time and in the right format can be a struggle, and you probably thought of quitting your job a dozen times during the audit cycle. Trust me, I've been there. In this video, we'll walk through what an audit cycle looks like in compliance and what we can do to infuse more automation in through the process. Let's go through some simple definitions first. A control, like classification over information or disposal of media, is a mechanism through which a company reduces its risk. You test the control to know if it does the job it is supposed to do. If the control is effective, then it is compliant. This is a very helve of a definition, as each body and standard has a different take on this. A compliance audit cycle is often a yearly process. Every single year, you would have to…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.