Products Included in this section: Downloads for ERA Risk Management software by Methodware Review of RiskLabs RMIS (all good!) Tripwire in action, using Change Management to control risk: The Movie Gartner provides to paying clients, comprehensive review of risk management products. Although we were happy to see all the products we like in their top right quadrant, we can't link to the report. Some of the clients reviewed have posted the document. Since we feel it is meant to be paid for, we are not posting the Gartner link. NIST Special Publications (NIST 53A Guidance from Dr. Stu Katz)
Enterprise Risk Assessor (ERA) provides your organisation with:
SARBANES-OXLEY Implementation Guide using Enterprise Risk Assessor
About Methodware Methodware specializes in providing software for Risk Management, Operational Risk Management, Enterprise-wide Risk Management, Internal Audit, and Financial Institution Risk Management. Methodware was established in 1993 and for more than a decade Methodware has been developing and supplying internal audit software solutions and risk management software solutions to organizations worldwide. Methodware has an established Partner network, and Methodware's software can be made available in most European languages. We can meet your company's risk management and/or internal audit needs no matter your company's location or organization size. Methodware's software for Risk Management, and Methodware's software for Internal Audit incorporates industry recognized standards and guidelines including: Methodware has developed risk management and internal audit software using consultants who have real life experience in Risk Management or Internal Auditing to ensure that it is relevant to your company and industry requirements. Requirements
Have you narrowed and refined your RegWatch™? Can you manage and respond to your specific industry and internal corporations validated and evaluated risk? Maybe you need RMIS support. In that case, you need to know about RiskLabs. We believe you MUST NOT skip understanding, trying and implementing AON-Risklab's RiskConsole. Scalable, managable, intuitive, developed and managed by an entirely US based seasoned development team, you will quickly fall in love with this platform and suite of product. As fast as you can identify the rules and values of risk in your business, the client services team is there to assist your immediate control over business impacting events. RiskConsole is the core product of AON RiskLabs. Sometimes referred to as “Console”, the platform is used both internally by business units including Information Technology, and externally by AON clients. RiskConsole is a web-based Risk Management Information System (RMIS) that uses claim, exposure, policy, and other risk- related data to provide risk managers with a comprehensive view of their organization's risk. The RiskLabs Data Center provides highly available Internet-based solutions for the risk management industry. These service offerings include sufficient bandwidth to suport large organization use, secure per user authentication, encryption of all system traffic, delivery of HTML system interface, as well as storage and management of confidential client data. RiskConsole integrity, functionality and availability is the primary goal for all of Information Technology. RiskConsole uptime is above 99.9%, and with highly structured maintenance agreements between AON and it’s clients. System enhancements and optimization is a full time committement at AON RiskLabs. Product Management works through committee to capture and respond to all client requirements, requests and concerns. Changes to the RiskConsole platform are controlled by formal Product Management Release and approved Change Management.
© Copyright 2005, FRS Belgium. All Rights Reserved. Legal terms & notices. Operational Risk Management and Sarbanes-Oxley Compliance In the drive for corporate transparency, accountability and good governance, there is no turning back. The immediate pressures of Sarbanes-Oxley compliance have provided financial institutions with a powerful impetus to enhance visibility and oversight of internal controls. Basel II offers additional motivation for banks to modernize their risk practices, holding out the promise of reduced economic and regulatory capital requirements. Market forces that create additional risk — such as globalization and time-to-market — further heighten the need for effective risk strategies. Operational risk management (ORM) identifies, manages and mitigates risks and losses that are associated with people, processes, IT systems and external events. ORM encompasses risks and losses that are associated with compliance initiatives, such as fines for non-compliance. Moving beyond immediate compliance objectives, financial institutions realize they can no longer treat operational risk, compliance and corporate governance as separate concerns — addressed via "stovepipe" applications or repurposed applications. Instead, institutions are seeking converged ORM solutions that address the shared needs for transparency, mandated financial disclosures and timely reporting across complex organizational structures. Detecting Risk. Protecting Value. RiskResolve™ is the first Operational Risk Management (ORM) solution to provide strategic value for protecting financial institutions from unexpected risks and financial losses. Designed expressly for the needs of financial institutions, RiskResolve empowers managers to actively and continuously manage operational risks and controls across all lines of business and at the enterprise level — providing real-time visibility into early warning signals that indicate corrective action may be required. RiskResolve reflects the intimate knowledge that FRS has of operational risk management and compliance requirements in complex financial institutions. In contrast to single-purpose solutions or repurposed applications, FRS RiskResolve software provides financial institutions with a true enterprise-class solution for scoring, tracking and managing risks and controls in a disciplined, consistent manner. This real-time transparency and reporting of risks, associated controls, as well as control failures and loss events translates into an Active Risk Management™ discipline that aligns with the organization's strategic objectives and risk tolerance levels. This approach sheds unprecedented light on operational risks so that managers can make more informed decisions — improving operational efficiencies and financial performance. Download the RiskResolve Datasheet Business Benefits:
CobiT® On Line from ISACA and ITGI and CobiT Advisor 3rd Ed from Methodware™
Grand slams go to the teams producing harmonization and synergy across standards and regulatory requirements. CobiT® 4.0 and the recent release of Aligning CobiT®., ITIL® and ISO 17799® for Business Benefit: A Management Briefing, as well as the combined Booz Allen Hamilton, ISACA, ISSA and ASIS release "Convergence of Enterprise Security Organizations" To paraphrase just a few of the points by Gary Hardy and Erik Guldentops, who introduced CobiT®.4.0 in Volume 6, 2005 Information Systems Control Journal, (Professional publication produced by The Information Systems Audit and Control Association), CobiT®.4.0 adds to the already valuable framework:
"CobiT®.Online is a web-based resource where you can browse and search the very latest best practices, download customized guidance, perform benchmarking and more. A variety of subscription levels are available, each allowing different amounts and types of access and functionality. ISACA membership provides for Basic access rights and discounts on purchasing Full access." Resources and Publications on Internal Audit: Excellence takes teams, time and money: Pay your dues, buy your tools, because none of us is as smart as all of us...
Good stuff :
Special Thanks to Bruce Winters for his article Compliance CHOOSE THE RIGHT TOOLS FOR INTERNAL CONTROL REPORTING Bruce I. Winters New federal regulations require public companies to assess the effectiveness of their internal control structure and financial reporting procedures. Complex software is essential to such analysis. Here’s how to determine what kind is needed and how it should link to—or replace—a company’s existing systems., Dan Swanson, ISACA List Serve Community. Special Thanks to the IIA and again especially, Dan Swanson, CIA, CMA, CISA, CISSP, CAP, who coauthored with others mentioned on every page of this site in his long and productive career as Director of Professional Practices, The Institute of Internal Auditors. He frequently writes on IT audit, IT security, and various management practices. He is a past Winnipeg chapter president for both The IIA and ISACA and chaired ISACA International's publication committee for two years. Swanson has also been on the Board of Directors of The IIA
Logos belong to affiliated organizations and suggest PB&SP support and sponsorship/ membership. Use of logos is based in written agreement with the third party. They are not meant to imply ownership, creation or collaboration in any product. We
stand behind experience and consensus among our clients to suggest these highlighted
products / organizations are the best audit and compliance resources
in the world. We are not paid to advertise and we do not sell software. Westand behind their greatness because we witness their results. |
||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
More Information Compare these products ENTERPRISE RISK ASSESSOR Enterprise Risk Management software for organisations requiring a company wide, systemic and consistent approach to operational risk management. [More...] ENTERPRISE RISK ASSESSORLITE Risk management tool for the single user in charge of risk management or for consultants performing one-off risk assessments. [More...] ORCAS Operational risk management software tool for organisations that require Basel & FSA compliance. [More...] Downloading English Demonstration Software Downloading the Spanish engine and Spanish Demonstration Software To download English Demonstration Software please simply complete the English Demo Registration Form. After you have submitted the form, if you select to download only one Demo, a Download window should appear, in which case follow the instructions below. If the download process does not happen automatically, then follow the instructions on the page that appeared after you clicked 'Submit.' If you selected to download a number of Demos, a Download window should appear with links to each of the demo install files. Simply click on each link and follow the instructions below. In Internet Explorer: After you have clicked on the link choose the 'Save this program to Disc' option and click 'OK', select the directory on your PC where you want to save the file to (eg, demo_proaudit3.exe) and click 'Save.' Once the download is complete (ie - you have saved the file to your PC), you then need to run the install file (eg, demo_proaudit3.exe) to install the Demo on your PC. Locate where on your PC you saved the (eg, 'demo_proaudit3.exe') file to, and then double-click on the file to begin the installation of the Demo. At some stage in the installation process you will need to enter a code. Code/s and full installation instructions are included in the email that we send to you within one working day of you having completed the Demo registration form. Please note - when evaluating our demos please bear in mind the software has had limitations placed in it that do not appear should you purchase the full product - eg you are limited in the number of items you can add into the structure, some reports are limited in the number of items shown on them, etc. The Spanish Demo Methodware Engine needs to be downloaded and then installed on your PC before you can use any of our Spanish Demo software. It helps to power the functionality in our software. Please note - the Spanish Demo Methodware Engine provides less functionality than the Spanish Methodware Engine that is provided when you purchase Methodware software. As a result, when evaluating our demos you are limited in the number of items you can add into the structure, some reports are limited in the number of items shown on them, etc. If you have already installed the Spanish Demo Methodware Engine on your PC and it was prior to the date listed in the link below, we recommend that you download the most recent Spanish Demo Methodware Engine as shown below. Make sure that you close out of any Methodware applications before you proceed below. To start downloading the install for it please click on the link below: Download the Spanish Demo Methodware Engine (12 Mb - approx) To download the engine install from an alternative link on another server click here In Internet Explorer: After you have clicked on the link choose the 'Save this program to Disc' option and click 'OK', select the directory on your PC where you want to save the file to (install_engineS.exe) and click 'Save.' Once the download is complete (ie - you have saved the file to your PC), run the install file to install the Spanish Demo Methodware Engine on your PC. Locate where on your PC you saved the 'install_engineS.exe' file to, and then double-click the 'install_engineS.exe' file to begin the installation of the Demo Methodware Engine. After that process is complete, download/install the Demo that you are interested in. To download Spanish Demonstration Software, please complete the Spanish Demo form and follow the instructions on the form. After you have submitted the form, if you select to download only one Demo, a Download window should appear, in which case follow the instructions below. If the download process does not happen automatically, then follow the instructions on the page that appeared after you clicked 'Submit.' If you selected to download a number of Demos, a Download window should appear with links to each of the demo install files. Simply click on the link and follow the instructions below. In Internet Explorer: After you have clicked on the link choose the 'Save this program to Disc' option and click 'OK', select the directory on your PC where you want to save the file to (eg, demo_proaudit3.exe) and click 'Save.' Once the download is complete (ie - you have saved the file to your PC), you then need to run the install file (eg, demo_proaudit3.exe) to install the Demo on your PC. Locate where on your PC you saved the (eg, 'demo_proaudit3.exe') file to, and then double-click on the file to begin the installation of the Demo. At some stage in the installation process you will need to enter a code. Code/s and full installation instructions are included in the email that we send to you within one working day of you having completed the Demo regsitration form Please click here to email Methodware with any questions or comments you have about Methodware products, services, or website. . Please select Contact PB&SP for US based support in selection of any compliance product as aligned to your unique corporation's needs. Using Tripwire to manage compliance and reduce risk as defined by CobiT and COSO...the movie
|







Microsoft Security and Risk Resources:








IIA releases practice guidelines for risk management 

