Communicating Compliance News and Status
S/T (Situation/Task)
One of the problem is ensuring that security compliance news is transparent from top to bottom of the organization. And finding out a way to communicating compliance status.
Any audits coming up
Any processes that we changed or any new processes that was created
Any documenting what security controls that are passing
And documenting any security controls that need attention
And if any gaps have been found or detected.
And any upcoming internal audits like User Access Review or sampling of background checks of employees.
And any new vulnerabilities found via our bug bounty program or application security engineer
Any vulnerabilities that have been remedidated.
A (Approach)
R (Results)
Last updated