Category: Guides
-
Board reporting on IT risk: one page that asks for decisions
How to turn a risk register into a one-page board report: residual risk against appetite, plain language, honest scores and clear decisions to take.
-
Audit preparation: evidence, populations and operating effectiveness
What an auditor tests, how to build an evidence register, what good evidence looks like, and how to handle exceptions without damaging credibility.
-
Risk treatment and residual risk: mitigate, transfer, avoid or accept
How to choose and record a treatment, what residual risk means, why insurance is not a control, and how to write acceptance that can be defended.
-
User access reviews: design, evidence and the commands to start
How to run an access review a manager can actually complete, with read-only commands for Windows, Linux and AWS and the evidence an auditor expects.
-
Vendor and third-party IT risk: tiering, evidence and exit
Tier suppliers by access and criticality, read SOC 2 reports and certificates properly, check the contract terms that matter, and plan the exit.
-
IT risk scoring: qualitative, semi-quantitative and the ordinal-scale trap
A written-out 4 by 4 scoring scale, a worked example, and an honest account of why multiplying ordinal scores misleads and what to do about it.
-
The IT risk register: what to record, who owns it and how to keep it alive
How to build an IT risk register that people use: the fields that matter, risk statements that can be scored, ownership, review cadence and common failures.