- Business Continuity & DR Test Exercise — Business Operations; with IT · 6 steps
Run one operating cycle of a BC/DR plan-testing control: plan and execute a business continuity or disaster recovery exercise against RTO and RPO objectives, capture gaps as findings, and fold them back into the BC and DR plans.
- Control Design — Business Operations; with Risk Management · 3 steps
Design a new control from objective definition through attribute specification, risk mapping, evidence and test approach definition, and final control record creation.
- Data Governance Council Operations — Business Operations; with Privacy, IT · 6 steps
Run quarterly data governance and required integrity-board oversight: review charter standing, lifecycle policy, quality and integrity trends and sharing agreements, then approve minutes and report owned actions at the defined interval.
- Enterprise Risk Treatment Operations Cycle — Business Operations; with Risk Management · 5 steps
Assess enterprise threats and opportunities, implement owned treatment for tolerance breaches and reassess residual exposure; obtain required senior acceptance and approve a current register, portfolio report and change-monitoring record.
- Incident Management Lifecycle — Business Operations; with IT, Compliance & Legal · 7 steps
Assess and govern an incident from its detection clock through verified recovery and approved notifications; determine corrective actions or risk acceptance and retain the evidence, reporting handoff and follow-up schedule.
- Issue Remediation and Verification — Risk Management; with Business Operations · 2 steps
Agree cause-based, separately owned remediation actions and validate each by its committed method; approve the finding’s closure only when every linked action is validated and closed.
- Remediation Delivery — Business Operations · 1 steps
Agree observable closure criteria and deliver one owned corrective action; independent validation remains in the parent finding workflow.
- Remediation Delivery & Validation — Business Operations · 3 steps
Plan and deliver corrective action, independently validate it against agreed closure criteria, and approve a traceable remediation record.
- Risk & Control Self-Assessment (RCSA) Program — Business Operations; with Risk Management · 8 steps
Run first-line risk and control self-assessment with evidence-backed owner ratings and native attestations, second-line challenge and calibration, explicit unassessed units, risk-register updates, remediation or acceptance handoffs, and risk-committee reporting.