From the course: Governance, Risk, and Compliance (GRC) for the Cloud-Native Revolution

Unlock this course with a free trial

Join today to access over 25,300 courses taught by industry experts.

From manual point-in-time testing to continuous monitoring

From manual point-in-time testing to continuous monitoring

- [Instructor] If you work in GRC, you know very well that audits are both challenging and overwhelming. Getting all the evidence you need in time and in the right format can be a struggle, and you probably thought of quitting your job a dozen times during the audit cycle. Trust me, I've been there. In this video, we'll walk through what an audit cycle looks like in compliance and what we can do to infuse more automation in through the process. Let's go through some simple definitions first. A control, like classification over information or disposal of media, is a mechanism through which a company reduces its risk. You test the control to know if it does the job it is supposed to do. If the control is effective, then it is compliant. This is a very helve of a definition, as each body and standard has a different take on this. A compliance audit cycle is often a yearly process. Every single year, you would have to…

Contents