RiskWatch Implementation Rescue - Total Implementation in Eight Weeks or Less - <read more ERM, Cybersecurity, and Incident Response>
RiskWatch program implements a SharePoint or Access Database enabled Risk Management system, with assessment reports, documented process, purpose-built to satisfy board regulatory requirements. We customize any SQL-based GRC system to meet your specific industry. EnterpriseGRC Solutions comes on-site or works remotely to provide all required products training, documentation to successfully run a RiskWatch program. Once operational, EnterpriseGRC can either maintain the program or assure you of in-house training for complete knowledge transfer.
Organized according to:

Week One:
Team review of existing process and documentation, and future state agreement.
- Create Custom online training slides.
- Identify risk team and kick off process.
- Distribute Risk Criteria Matrix to key stakeholders
Week Two:
- Present training: Assist managers to document risks as aligned to position and department responsibilities.
- Input High Profile Job Descriptions; Organization Titles and map to aligned to ISO/IEC 27001, CSF, CCM v4, NIST RMF 800-37 controls, with an emphasis towards segregated duties as recommended by Information Systems and Audit Control Association
- Generate by consensus with all IT Directors first Agenda
- Conduct first Meeting
- Post Minutes and establish Portal for RiskWatch meetings, agenda, archives
- Collect Risk Criteria first response summary
Week Three:
- Assist managers to document risks
- Generate Agenda and Post Minutes
- Establish method for remote attendees and be on site to Conduct Second Meeting
- Present initial job descriptions for affirmation, review standard associated duties and alignment to "CobiT/ISO" controls
- Deliver Visio with job profiles (DSN) (see image)
- Risk Criteria Matrix Second Run validation
- Based on interview with managers, document job-related control anomalies; suggest changes in job definitions as might be indicated by organization chart
- Kick off - Fragile Artifacts, Technology Resource Risk
- Collect Application Names; System Names; Factors for review of system-based Risk
- Determine minimum monitoring profile and automated source data
Week Four:
- Assist managers to document risks
- Generate Agenda and Post Minutes
- Conduct Third Meeting
- Train new Risk Coordinator
- Input and validate controlled objects; adding some items to RiskWatch as determined by significance and relative risk
Week Five:
- Team confirmation of final risk criteria matrix; documented model explaining relationships between core systems and established risks
- Continue to assist managers in documenting risks
- Generate Agenda and Post Minutes
- Conduct Fourth Meeting
- Create Custom Reports and modify web forms using agreed logo and style sheet
Week Six:
- Assist managers to document risks
- Generate Agenda and Post Minutes
- Conduct Fifth Meeting
- Provide Peer Review to New Risk Coordinator
- Refine Custom Reports and modify web forms for usability and consistency with other in-house products
Weeks Seven and Eight:
(Remote support/teleconference 4 hours, project management 16 hours)
- Critique risks as they relate to compliance requirements.
- Supervise posting agenda and minutes.
- Attend and critique risk watch meeting.
- Further customize reports and data access to support custom lists such as usernames, application names, infrastructure items, provide risk response implementation plan oversight
- Provide final Risk Management Assessment as measured by ISO/IEC 27001, CCM, COSO ERM and NIST CSF control titled "Assess Risk" and as relates to their specific industry regulatory requirements and business priorities
Form and Recording - RiskWatch Items (We do this in SharePoint and provide reports in Access. We are happy to use any SQL-based GRC interface the client may already have in place. The data is the data, and the process remains the same.
Sometimes the best risk management actually does live on a spreadsheet, or at least, we can output the mapping model and scoring to explain how the interface is tracking and ranking according to any risk management model. This image shows unification against the CCM 4. We could also have done this using the NIST Cybersecurity Framework, CSF SP 800-37. Any risk model can serve as the left side collection and any other array of mapped controls can factor into that topic.
- EnterpriseGRC Solutions will provide process and recording of key classes in Risk, allowing for an accredited process of risk management.

RiskWatch process is built for Technology, Enterprise Corporate, Project Management Office and Internal Audit




Application for Management and Reporting Enterprise Risk – Meets AS5 and OMB related requirements

Immediate High-Level Reporting – One of hundreds of existing reports – Easily customized

Heat Map Shows Residual and Inherent Risk – Accounting Oversight Ready
Track your regulations

Regulatory Mapping and associated laws that might also benefit or be affected by same requirements





Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics