Governance of Information Governance, Risk Management and Security Programmes at Eye-Able
Governance of Information Governance, Risk Management and Security Programmes at Eye-Able
This article gives an overview of Eye-Able's information governance framework and the management of risk management and security programmes with the involvement of company leadership.
Information governance framework
Eye-Able has a formally established information governance framework that is supported, documented and regularly updated by company management.
Review and adjustment of policies and procedures
All relevant policies and procedures are reviewed at least annually or adjusted in the event of significant organisational changes.
Enterprise Risk Management (ERM)
A company-wide Enterprise Risk Management (ERM) is implemented and covers, among other things, the identification, assessment, treatment and acceptance of risks in the areas of cloud security, data protection and compliance.
Roles, responsibilities and exceptions
Roles and responsibilities within the governance structures are clearly defined and documented.
Deviations from established policies are subject to a formalised, approval-based exception process.
Security programme and legal requirements
The entire security programme covers all relevant control areas of the Cloud Controls Matrix (CCM) and forms part of the overarching ISMS.
Legal, contractual and regulatory requirements are documented centrally and regularly reconciled against new legal sources and industry standards.
Industry-specific collaboration
In addition, Eye-Able actively maintains an exchange with industry-specific working groups, interest associations and standardisation bodies in the cloud and data protection sector. This enables new regulatory developments to be taken into account at an early stage in governance practice.
Further help
Do you have further questions or need personal support? The following article explains how you can get in touch with us: