April 20, 2024, 1:40 a.m. | /u/PlushiePunch

cybersecurity www.reddit.com

Probably mainly for GRC folks out there. My team is looking to start implementing control self-assessments (CSAs) where we have control owners attesting to their own controls which could possibly decrease the number of times that their controls are tested a year. Have any of you implemented or seen something similar and if so, how have CSAs been used? Good idea? Bad idea?

TIA!

assessments control controls cybersecurity grc own start team

Senior Security Specialist, Forsah Technical and Vocational Education and Training (Forsah TVET) (NEW)

@ IREX | Ramallah, West Bank, Palestinian National Authority

Consultant(e) Junior Cybersécurité

@ Sia Partners | Paris, France

Senior Network Security Engineer

@ NielsenIQ | Mexico City, Mexico

Senior Consultant, Payment Intelligence

@ Visa | Washington, DC, United States

Corporate Counsel, Compliance

@ Okta | San Francisco, CA; Bellevue, WA; Chicago, IL; New York City; Washington, DC; Austin, TX

Security Operations Engineer

@ Samsara | Remote - US