article thumbnail

ISO 27001 Certification Requirements & Standards

Reciprocity

Doing this right is critical because a scope that is too large will increase the project’s time and expense, and a scope that is too narrow may expose your firm to unanticipated hazards. Human error has often been identified as the weakest link in cybersecurity. Launch High-Level Policy Development. Staff Training.

Audit 52
article thumbnail

IRM, ERM, and GRC: Is There a Difference?

Reciprocity

Not long ago, risk managers concerned themselves mainly with hazards such as fires and floods; or in the financial sector, loan defaults (credit risk). Are there differences at all? Which is best? This article will try to answer those questions. ERM: A Short History. “The differences between them don’t matter,” he says.