3 Common Pitfalls

Compliance and Risk Management for Technical Professionals · 4:06

Listen on 93

Lyrics

[Verse 1]
Sarah wrote a policy late one night
"Users shall be careful" seemed just right
But when audit season came around
No way to verify what she had found
The team just shrugged and walked away
How do you measure "careful" anyway?

[Chorus]
Don't be vague, don't be weak, don't leave questions hanging
Who does what, when and how, get specifics banging
Verify, quantify, make it attributable
Three pitfalls waiting for the control that's disputable
Who-What-When-How, prove it now
That's the way to write it down

[Verse 2]
Mike said "Systems shall be protected well"
But what's adequate? Nobody could tell
Fifty percent uptime or ninety-nine?
Without a metric, you're walking blind
The board demands to see the score
But "adequate" won't tell them more

[Chorus]
Don't be vague, don't be weak, don't leave questions hanging
Who does what, when and how, get specifics banging
Verify, quantify, make it attributable
Three pitfalls waiting for the control that's disputable
Who-What-When-How, prove it now
That's the way to write it down

[Bridge]
"Security measures shall be maintained"
Sounds professional but it's half-brained
Maintained by who? The night shift crew?
The vendor or the team in blue?
Without assignment, nothing's done
Everyone thinks someone's the one

[Verse 3]
Now listen close to this advice
Write controls that are precise
Name the person, name the task
Monthly reviews of what they ask
Document proof in black and white
Evidence that stands up to sight

[Chorus]
Don't be vague, don't be weak, don't leave questions hanging
Who does what, when and how, get specifics banging
Verify, quantify, make it attributable
Three pitfalls waiting for the control that's disputable
Who-What-When-How, prove it now
That's the way to write it down

[Outro]
Unverifiable, unmeasurable, unattributable too
These three mistakes will come for you
But with Who-What-When-How you'll make it through
Controls that work and audits too

← 2 Language Precision | 4 Template Control Statement Patterns →