April 20, 2024, 1:40 a.m. | /u/PlushiePunch

cybersecurity www.reddit.com

Probably mainly for GRC folks out there. My team is looking to start implementing control self-assessments (CSAs) where we have control owners attesting to their own controls which could possibly decrease the number of times that their controls are tested a year. Have any of you implemented or seen something similar and if so, how have CSAs been used? Good idea? Bad idea?

TIA!

assessments control controls cybersecurity grc own start team

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Consultant Sécurité SI Gouvernance - Risques - Conformité H/F - Strasbourg

@ Hifield | Strasbourg, France

Lead Security Specialist

@ KBR, Inc. | USA, Dallas, 8121 Lemmon Ave, Suite 550, Texas

Consultant SOC / CERT H/F

@ Hifield | Sèvres, France