Reporting & Analytics Overview Flashcards
Reporting & Analytics Overview
-Due diligence data
-Reporting on residual risk
-Contract language
-Analytics drive decisions
-Risk acceptance and escalations
-Enhanced continuous monitoring
Due Diligence Data
Where to get it?
How to Rate it?
Due Diligence Data:
Where do you get it?
-Risk assessments
-Security reports
-Continuing monitoring reports
-Incident notifications
-Negative news alerts, etc.
Come from a number of places, IRA, remote questionnaires, continuous monitoring.
Due Diligence Data:
How to rate it?
-Based on your organization’s risk appetite
-Not all due diligence data is the same.
-You weigh remote questionnaire different than a physical on site review.
-Rate things lighter from a security tool than a physical validation.
-You will not treat all data the same.