<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Compliance Software &#187; risk management</title>
	<atom:link href="http://compliancesoftware.org/tag/risk-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://compliancesoftware.org</link>
	<description>Regulatory Compliance Software - News Information and Links</description>
	<lastBuildDate>Mon, 21 May 2012 13:30:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>FISMA capstone document released by NIST &#8212; Government Computer News</title>
		<link>http://compliancesoftware.org/2010/12/16/fisma-capstone-document-released-by-nist-government-computer-news/</link>
		<comments>http://compliancesoftware.org/2010/12/16/fisma-capstone-document-released-by-nist-government-computer-news/#comments</comments>
		<pubDate>Fri, 17 Dec 2010 00:00:54 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[FISMA]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=1267</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2010/12/16/fisma-capstone-document-released-by-nist-government-computer-news/" title="FISMA capstone document released by NIST -- Government Computer News"></a>The National Institute of Standards and Technology has released a draft of its guidelines for implementing enterprisewide information risk management. The document defines the underlying principles for implementing the Federal Information Security Management Act. via FISMA capstone document released by &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2010/12/16/fisma-capstone-document-released-by-nist-government-computer-news/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2010/12/16/fisma-capstone-document-released-by-nist-government-computer-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>In 2011 The GRC Market Will Grow 20%, Driven More By Breadth Than Maturity &#124; Forrester Blogs</title>
		<link>http://compliancesoftware.org/2010/12/12/in-2011-the-grc-market-will-grow-20-driven-more-by-breadth-than-maturity-forrester-blogs/</link>
		<comments>http://compliancesoftware.org/2010/12/12/in-2011-the-grc-market-will-grow-20-driven-more-by-breadth-than-maturity-forrester-blogs/#comments</comments>
		<pubDate>Mon, 13 Dec 2010 01:17:31 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[GRC]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[grc]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[regulatory]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=1256</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2010/12/12/in-2011-the-grc-market-will-grow-20-driven-more-by-breadth-than-maturity-forrester-blogs/" title="In 2011 The GRC Market Will Grow 20%, Driven More By Breadth Than Maturity | Forrester Blogs"></a>On the heels of Forrester&#8217;s GRC Market Overview last month, this week we published my Governance, Risk, And Compliance Predictions: 2011 And Beyond report. Based on our research with GRC vendors, buyers, and users, this paper highlights the aggressive regulatory &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2010/12/12/in-2011-the-grc-market-will-grow-20-driven-more-by-breadth-than-maturity-forrester-blogs/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2010/12/12/in-2011-the-grc-market-will-grow-20-driven-more-by-breadth-than-maturity-forrester-blogs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-crime Now More Common Than Real Crime</title>
		<link>http://compliancesoftware.org/2010/10/20/e-crime-now-more-common-than-real-crime/</link>
		<comments>http://compliancesoftware.org/2010/10/20/e-crime-now-more-common-than-real-crime/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 01:14:19 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[pan]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=1198</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2010/10/20/e-crime-now-more-common-than-real-crime/" title="E-crime Now More Common Than Real Crime"></a>If there was any doubt about the popularity of electronic dupery, it should be put to rest with a report on global fraud released the week by the risk management consulting firm Kroll. For the first time since 2007, when &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2010/10/20/e-crime-now-more-common-than-real-crime/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2010/10/20/e-crime-now-more-common-than-real-crime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enterprise risk management: Get started in six steps</title>
		<link>http://compliancesoftware.org/2010/09/08/enterprise-risk-management-get-started-in-six-steps/</link>
		<comments>http://compliancesoftware.org/2010/09/08/enterprise-risk-management-get-started-in-six-steps/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 21:17:22 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=1133</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2010/09/08/enterprise-risk-management-get-started-in-six-steps/" title="Enterprise risk management: Get started in six steps"></a>I propose that ERM is worth doing and doesn&#8217;t have to be so complex if you simply &#8220;begin with the end in mind,&#8221; as Stephen Covey says in The 7 Habits of Highly Successful Security Leaders. Or would have said &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2010/09/08/enterprise-risk-management-get-started-in-six-steps/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2010/09/08/enterprise-risk-management-get-started-in-six-steps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GRC goes into the Cloud &#8211; Express Computer</title>
		<link>http://compliancesoftware.org/2010/03/06/grc-goes-into-the-cloud-express-computer/</link>
		<comments>http://compliancesoftware.org/2010/03/06/grc-goes-into-the-cloud-express-computer/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 22:25:53 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[GRC]]></category>
		<category><![CDATA[announce]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[grc]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=900</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2010/03/06/grc-goes-into-the-cloud-express-computer/" title="GRC goes into the Cloud - Express Computer"></a>eGestalt has announced the availability of SecureGRC, a solution that provides an end-to-end integration of security monitoring with IT-Governance, Risk Management and Compliance (IT-GRC) management solutions using a cloud-based delivery model. via GRC goes into the Cloud &#8211; Express Computer.]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2010/03/06/grc-goes-into-the-cloud-express-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SEC Approves Enhanced Disclosure About Risk, Compensation and Corporate Governance</title>
		<link>http://compliancesoftware.org/2009/12/18/sec-approves-enhanced-disclosure-about-risk-compensation-and-corporate-governance/</link>
		<comments>http://compliancesoftware.org/2009/12/18/sec-approves-enhanced-disclosure-about-risk-compensation-and-corporate-governance/#comments</comments>
		<pubDate>Sat, 19 Dec 2009 03:33:23 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[pan]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[state]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=806</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2009/12/18/sec-approves-enhanced-disclosure-about-risk-compensation-and-corporate-governance/" title="SEC Approves Enhanced Disclosure About Risk, Compensation and Corporate Governance"></a>In particular, the new rules require disclosures in proxy and information statements about: * The relationship of a company&#8217;s compensation policies and practices to risk management. via Press Release: SEC Approves Enhanced Disclosure About Risk, Compensation and Corporate Governance; 2009-268; &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2009/12/18/sec-approves-enhanced-disclosure-about-risk-compensation-and-corporate-governance/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2009/12/18/sec-approves-enhanced-disclosure-about-risk-compensation-and-corporate-governance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO 31000 Risk management</title>
		<link>http://compliancesoftware.org/2009/12/02/iso-31000-risk-management/</link>
		<comments>http://compliancesoftware.org/2009/12/02/iso-31000-risk-management/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 00:41:35 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[ISO/IEC 27002]]></category>
		<category><![CDATA[iso]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=770</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2009/12/02/iso-31000-risk-management/" title="ISO 31000 Risk management"></a>By now, many of you have read the newly released ISO 31000 Risk management &#8212; Principles and guidelines standard. (Others may have seen its release draft or be familiar with its predecessor the AS/NZS 4360 standard.) It provides a well-written, &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2009/12/02/iso-31000-risk-management/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2009/12/02/iso-31000-risk-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISACA to host IT security conference in Las Vegas &#124;</title>
		<link>http://compliancesoftware.org/2009/07/28/isaca-to-host-it-security-conference-in-las-vegas/</link>
		<comments>http://compliancesoftware.org/2009/07/28/isaca-to-host-it-security-conference-in-las-vegas/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 12:47:54 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[pan]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=585</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2009/07/28/isaca-to-host-it-security-conference-in-las-vegas/" title="ISACA to host IT security conference in Las Vegas |"></a>The role of the IT security professional has expanded from securing an enterprise’s information to also managing the associated risk. ISACA has responded by offering the new Information Security and Risk Management Conference, which combines the most timely material from &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2009/07/28/isaca-to-host-it-security-conference-in-las-vegas/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2009/07/28/isaca-to-host-it-security-conference-in-las-vegas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is IT Risk Management Compatible With ERM?</title>
		<link>http://compliancesoftware.org/2009/07/22/is-it-risk-management-compatible-with-erm/</link>
		<comments>http://compliancesoftware.org/2009/07/22/is-it-risk-management-compatible-with-erm/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 18:02:27 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=573</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2009/07/22/is-it-risk-management-compatible-with-erm/" title="Is IT Risk Management Compatible With ERM?"></a>But in spite of these warnings, my conversations with enterprise risk and IT risk professionals still reveal many disconnects, including that IT risks are not measured consistently with other enterprise risks. In addition, many IT risk professionals do not see &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2009/07/22/is-it-risk-management-compatible-with-erm/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2009/07/22/is-it-risk-management-compatible-with-erm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Incident Response: The Legal Perspective #PCI</title>
		<link>http://compliancesoftware.org/2009/07/09/pci-dss-incident-response-the-legal-perspective-pci/</link>
		<comments>http://compliancesoftware.org/2009/07/09/pci-dss-incident-response-the-legal-perspective-pci/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 12:00:38 +0000</pubDate>
		<dc:creator>compliancesoftware</dc:creator>
				<category><![CDATA[PCI]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[card]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[payment]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://compliancesoftware.org/?p=548</guid>
		<description><![CDATA[<a href="http://compliancesoftware.org/2009/07/09/pci-dss-incident-response-the-legal-perspective-pci/" title="PCI DSS Incident Response: The Legal Perspective #PCI"></a>The SANS Institute InfoSec Reading Room recently published an article by Christian J. Moldes entitled PCI DSS and Incident Handling: What is required before, during and after an incident. Moldes’ whitepaper is a good starting point for developing an incident &#8230;<p class="read-more"><a href="http://compliancesoftware.org/2009/07/09/pci-dss-incident-response-the-legal-perspective-pci/">Read more &#187;</a></p>]]></description>
		<wfw:commentRss>http://compliancesoftware.org/2009/07/09/pci-dss-incident-response-the-legal-perspective-pci/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

