Compliance and Risk Management for Technical Professionals

38 chapters

Chapters

  1. 1 Understanding the Document Pyramid
    Compliance and Risk Management for Technical Professionals · 4:24
    Explore the five-layer document pyramid that forms the backbone of organizational governance, learning how each level—from high-level policies to detailed procedures—works together to keep processes structured and compliant.
  2. 2 Referencing Controls Across the Hierarchy
    Compliance and Risk Management for Technical Professionals · 3:07
    Exploring how compliance controls flow seamlessly across all four levels of an organization's hierarchy, this chapter reveals how Policy, Standard, Procedure, and Baseline work together in a unified, interconnected framework.
  3. 3 Cross-Referencing Between Documents
    Compliance and Risk Management for Technical Professionals · 3:00
    A deep dive into the essential practice of cross-referencing compliance documents, teaching professionals three key methods—including traceability matrices and inline references—to build stronger, interconnected policy frameworks.
  4. 1 Design and Implementation
    Compliance and Risk Management for Technical Professionals · 3:39
    A deep dive into the foundational steps of building effective controls, covering how to document design objectives, define clear goals, and establish ownership and accountability from the ground up.
  5. 2 Monitoring and Testing
    Compliance and Risk Management for Technical Professionals · 3:46
    Effective compliance doesn't end when controls are put in place — discover why continuous monitoring and regular testing are essential to keeping security measures strong and catching vulnerabilities before they become costly failures.
  6. 3 Remediation
    Compliance and Risk Management for Technical Professionals · 3:25
    Explore the critical process of addressing compliance gaps and control failures, from documenting findings in a risk register to executing effective remediation that closes vulnerabilities for good.
  7. 4 Continuous Improvement
    Compliance and Risk Management for Technical Professionals · 3:11
    Continuous improvement in compliance and risk management takes center stage as listeners discover how to keep pace with an ever-evolving threat landscape through a practical four-step framework of reviewing, responding, refreshing, and renewing controls.
  8. 1 The Anatomy of a Good Control Statement
    Compliance and Risk Management for Technical Professionals · 3:31
    A breakdown of the five essential elements that make up an effective control statement, teaching listeners how to craft clear, actionable policy language that specifies who does what, to what, and how often.
  9. 2 Language Precision
    Compliance and Risk Management for Technical Professionals · 3:44
    Mastering the precise language of compliance documentation, this track breaks down the critical distinctions between "shall," "should," and "may" — words that carry serious legal and operational weight in policy writing.
  10. 3 Common Pitfalls
    Compliance and Risk Management for Technical Professionals · 4:06
    A cautionary exploration of the most frequent mistakes professionals make when drafting compliance policies, revealing why vague, unmeasurable language can render even well-intentioned guidelines completely unenforceable.
  11. 4 Template Control Statement Patterns
    Compliance and Risk Management for Technical Professionals · 4:24
    Mastering four essential template patterns for writing clear, structured compliance policies, covering how to properly sequence roles, actions, objects, and frequency to create unambiguous procedural standards.
  12. Exercise 1: Control Classification
    Compliance and Risk Management for Technical Professionals · 3:52
    Dive into hands-on practice classifying 20 real-world controls by function and nature, learning to distinguish between preventive, detective, and corrective control types with confidence.
  13. Exercise 2: Policy-to-Control Traceability
    Compliance and Risk Management for Technical Professionals · 3:31
    A hands-on exercise tracing three foundational business policies — data protection, access control, and disaster recovery — down to their actionable controls, revealing how policy statements connect to real-world compliance mechanisms.
  14. Exercise 3: Framework Mapping
    Compliance and Risk Management for Technical Professionals · 3:42
    A hands-on exercise walking through the process of mapping access control requirements across four major compliance frameworks—SOC 2, CMMC, HIPAA, and ISO 27001—showing how users, roles, and permissions align to each standard's controls.
  15. Exercise 4: Control Statement Writing
    Compliance and Risk Management for Technical Professionals · 3:54
    A hands-on exercise challenges listeners to diagnose and repair five flawed control statements, reinforcing the essential components of effective controls—actor, action, object, frequency, and conditions.
  16. Exercise 5: Compensating Control Design
    Compliance and Risk Management for Technical Professionals · 3:29
    When primary controls fall short due to budget constraints or technical limitations, compensating controls offer a practical alternative—this track walks through designing layered backup measures that maintain compliance and keep your risk management strategy intact.
  17. Key Standards and Frameworks
    Compliance and Risk Management for Technical Professionals · 3:30
    Dive into the essential frameworks that govern data security in federal systems, with a focus on NIST 800-53 and its structured approach to security controls built around confidentiality, integrity, and availability.
  18. Glossary of Key Terms
    Compliance and Risk Management for Technical Professionals · 3:48
    A musical glossary that demystifies essential compliance terminology, walking listeners through critical concepts like control objectives, control activities, and design effectiveness to build a solid foundation for understanding risk management frameworks.
  19. 1 Defense in Depth
    Compliance and Risk Management for Technical Professionals · 3:32
    A foundational security strategy comes to life through the metaphor of a medieval castle, teaching listeners why relying on a single layer of protection is never enough and how combining administrative, technical, and physical controls creates a resilient, multi-layered defense.
  20. Pages of Nested XML
    Compliance and Risk Management for Technical Professionals · 2:52
    Diving into the notorious verbosity of XACML, this chapter exposes how even straightforward access control policies can balloon into dense, unwieldy XML structures that challenge readability and maintainability.
  21. Personal Priority 3 — URGENT (0–12 months)
    Compliance and Risk Management for Technical Professionals · 3:23
    A forward-looking deep dive into Canada's incoming CPCSC mandate and its urgent timeline for SMEs lacking dedicated security teams, revealing how existing CMMC knowledge transfers directly to this emerging compliance framework.
  22. A Curriculum for Technical and Compliance Professionals
    Compliance and Risk Management for Technical Professionals · 3:39
    A Curriculum for Technical and Compliance Professionals explores the frustrating reality of compliance experts who possess deep knowledge yet remain sidelined from strategic decision-making, revealing how technical professionals can bridge the gap between operational expertise and executive influence.
  23. 1 Understanding the Document Pyramid
    Compliance and Risk Management for Technical Professionals · 3:49
    Explore the foundational concept of the Document Pyramid, a hierarchical structure where policies, procedures, and supporting documents work together to form a cohesive compliance framework. Listeners will discover how each level of documentation serves a distinct purpose, from high-level board-approved policies down to flexible operational guidelines.
  24. 3 Principle 17: Pursues Improvement in Enterprise Risk Management
    Compliance and Risk Management for Technical Professionals · 4:54
    Exploring how organizations continuously evolve their risk management practices, this chapter guides listeners through maturity models, RIMS assessments, and benchmarking tools that help identify gaps and elevate enterprise risk capabilities to meet board expectations and industry standards.
  25. 2 Referencing Controls Across the Hierarchy
    Compliance and Risk Management for Technical Professionals · 3:29
    Discover how compliance controls flow through an organization's hierarchy, from high-level policy language down to precise technical specifications, and why consistent cross-referencing between these layers is essential for airtight risk management.
  26. 3 — Promotion and Succession
    Compliance and Risk Management for Technical Professionals · 3:24
    Exploring how organizations can build fairer career advancement systems, this chapter examines the risks of opaque promotion practices and what transparent, documented criteria mean for both employees and compliance.
  27. Building a Risk Transfer Strategy
    Compliance and Risk Management for Technical Professionals · 4:49
    A deep dive into the five-layer framework for building a robust risk transfer strategy, equipping technical professionals with the knowledge to protect their organizations from catastrophic, unexpected events.
  28. 2 — Performance Improvement Plans (PIPs)
    Compliance and Risk Management for Technical Professionals · 2:55
    Explore the critical decision points managers face when employee performance declines, and learn how a properly structured Performance Improvement Plan can protect both the organization and the employee while avoiding costly legal disputes.
  29. 4 — Leadership Development
    Compliance and Risk Management for Technical Professionals · 3:49
    A deep dive into leadership development at every career stage, from first-time managers navigating new responsibilities to executives refining their vision, exploring how structured programs and 360-degree feedback help professionals uncover blind spots and grow their impact.
  30. 1 Establishing an ERM Program
    Compliance and Risk Management for Technical Professionals · 4:36
    Laying the groundwork for Enterprise Risk Management, this chapter walks through how organizations establish a formal ERM program by securing leadership commitment, allocating resources, and building a framework that embeds risk awareness across the entire enterprise.
  31. 3 HIPAA Security Rule
    Compliance and Risk Management for Technical Professionals · 3:29
    Dive into the three core safeguards of the HIPAA Security Rule — administrative, physical, and technical — and discover how each layer works together to protect sensitive health data from breach and unauthorized access.
  32. Exercise 6.1: Acceptance Audit
    Compliance and Risk Management for Technical Professionals · 4:32
    A hands-on audit exercise walking through how to identify and categorize accepted risks in your register, distinguishing between those with proper documentation and sign-off versus those that quietly slipped through without a formal paper trail.
  33. The Hidden Costs of Standard Language
    Compliance and Risk Management for Technical Professionals · 5:06
    A cautionary exploration of why blindly reusing standard legal templates can expose your firm to catastrophic liability, revealing the hidden dangers buried in boilerplate indemnification clauses that even experienced professionals overlook.
  34. 3 — When to Hold the Line
    Compliance and Risk Management for Technical Professionals · 3:27
    Exploring the critical moments when HR professionals must stand firm against unethical pressures, this chapter equips listeners with the judgment to recognize when compliance requires courage — from silencing retaliation attempts to refusing shortcuts that compromise safety.
  35. The Post-Compliance Trap
    Compliance and Risk Management for Technical Professionals · 4:14
    Earning a compliance certification is a major milestone, but The Post-Compliance Trap reveals why crossing the finish line can actually be the moment your risk exposure begins to grow.
  36. Why the Fractional Model Fits This Condition
    Compliance and Risk Management for Technical Professionals · 3:31
    Exploring why the fractional model is the ideal solution for budget-conscious organizations that need credentialed InfoSec coverage, listeners will discover the three key conditions that make fractional design a cost-effective alternative to building full-time security teams.
  37. 5 Client Relationship Management
    Compliance and Risk Management for Technical Professionals · 4:33
    Explores the critical role of trust and transparency in managing client relationships within defense infrastructure, revealing how ISSMs and ISSOs can strengthen partnerships through clear communication and honest risk reporting.
  38. 2 Legal Framework
    Compliance and Risk Management for Technical Professionals · 3:53
    A deep dive into the legal frameworks governing compliance and risk, including the False Claims Act and its serious financial consequences, giving technical professionals essential knowledge about contractor liability, treble damages, and whistleblower protections.