A practical guide to risk quantification: what it is, why to quantify by scenario rather than risk by risk, how Monte Carlo simulation works (VaR, TVaR, loss tail), and how to get started without perfect data.
Latest news and updates
The Compliance Officer and the Compliance Committee
Within the framework of implementing a Legal Compliance project, there is a compliance body which is responsible for managing and updating the project and any other matters relating to it.…
Business continuity planning with GRC
What is business continuity? Business Continuity is a set of procedures and measures adopted by a company to ensure that essential functions can continue during and after any incident or…
ISO 27036 – Information Security for Supplier Relationships
What is the ISO 27036 standard? ISO 27000 is a series of information security standards developed and published by the International Organization for Standardization (ISO), which provides a globally recognized…
Key Indicators in a Risk Program
What are Risk Indicators? Key risk indicators, known as KRI (Key Risk Indicator), are used to determine the level of risk an organization has in the face of a specific…
What is ITIL and what is it for?
What is ITIL? The acronym ITIL stands for Information Technology Infrastructure Library,which we would literally translate as Information Technology Infrastructure Library. ITIL is a good practice guide for the management…
What is the NIST Cybersecurity Framework?
Introduction The Framework for Improving Critical Infrastructure Cybersecurity, better known as the NIST Cybersecurity Framework, was initially issued in the United States in February 2014. The current version is 1.1,…
What is the Internal Audit Report?
Internal Audit Report, What should it Include? The Audit report, according to the definition of the ISO standard, specifies that it is: “a systematic, independent and documented process for obtaining…
Balanced Scorecard: What is it and What is its Potential?
Balanced Scorecard or Integrated Management Dashboard The Concept and Definition of BSC The concept of Integrated Management Dashboard (IMD), also known as Balanced Scorecard (BSC), was first introduced in 1992…
What is the SOX Act and What is it For?
SOX Act – Sarbanes-Oxley History of the creation of SOX The United States Securities Act of 1933 regulated the securities market until 2002. It required companies to publish a prospectus…
GDPR and conservation periods of personal data
Personal Data Retention: Non-Compliance in Companies More than two years after the entry into force of the General Data Protection Regulation (GDPR), there are still many questions about the principle…
Risk Assessment Methods: Mehari, Ebios, Octave
Risk Assessment Methods Since the financial crisis that began in 2008, risk analysis has taken on special relevance in the internal management of organizations. Previously, work in this area was…
What are the Advantages Offered by the ISO 37001 Standard?
ISO 37001 and the Advantages of its Implementation ISO 37001 is a certifiable international standard published in 2017 by the International Certification Organization, ISO. This standard is aimed at managing…
ISO 14001: Keys and Principles of the Standard
ISO 14001 Standard, Fundamental Requirements It is common to consider that environmental standards are only related to companies that directly affect the environment, such as those in the industrial sector;…
How to implement an IT risk framework
The search for the IT risk framework All organizations have risks, the difference between them is the way they are managed. A mature organization has a risk management process that…
Security Audits
Security Audit Project Management By definition, we understand the concept of audit as a systematic review of an activity or process, in order to evaluate its relative compliance against a…
















