Enterprise Resource Planning solutions will typically be critical vendors with high risk driven by the companies data involved. The answer is yes, consider the implementation, not just the solution/vendor level of due-diligence. This is because solution ... More
Hi, Yes, I'd recommend the following: Classifications: High. Medium, Low. Risk Assessment gauges risk across Inherent risk categories include the following: Business Continuity, Compliance, Concentration, Country, Credit, Cyber, ... More
This message was posted by a user wishing to remain anonymous Hi We are a FS firm that operates in multiple regulated jurisdictions, each with their own, albeit similar Outsourcing regulations. How do others approach the classification and risk ... More
This message was posted by a user wishing to remain anonymous Hello Community, How are folks scoping and conducting assessments for enterprise solutions such as big name ERP solutions? SOC2's and long lists of compliance certifications are readily ... More
Yes, being notified of a data sharing change would be a part of TPRM's ongoing monitoring practices. The next step would be to assess what the change is and the impacts of that change. For example, if the change includes one of the vendors processing ... More