Many organisations still document emergency and communication plans in Word or Excel files, which makes it difficult to link them to business processes. A GRC approach is significantly enhanced by the integration of an IT service management tool and offers organisations numerous additional benefits: By using such a tool, all relevant information – such as emergency plans, business processes, services and contracts – can be centrally consolidated in a Configuration Management Database (CMDB). This centralised database provides transparency regarding dependencies and interrelationships within the organisation, which makes it considerably easier to plan and implement measures.
What is GRC?
GRC stands for Governance, Risk and Compliance and describes a holistic, integrated approach that supports organisations in acting ethically and adhering to internal and external requirements. In doing so, GRC takes into account an organisation’s risk appetite – that is, its willingness to take risks.
A key component of GRC is governance – the internal guidelines a company sets for itself in order to achieve objectives such as growth, new markets, sustainability or operational resilience. This is not just about setting objectives, but also about communicating them clearly and putting them into practice. Risks play an important role, as companies must clearly define their risk appetite.
The ‘Risk’ component focuses on the analysis, assessment and minimisation of risks. Companies determine which risks they are willing to take and develop strategies to reduce them. Regular analyses, system-based monitoring and fixed schedules for reassessing risks are essential in this regard. Risk and governance are closely interlinked, as clear objectives always take risk appetite into account.
Compliance ensures adherence to legal and regulatory requirements. Industry- and region-specific regulations such as BAIT, VAIT, DORA or KRITIS define requirements, particularly for critical infrastructure such as energy or water. With the NIS2 Directive, even more organisations are affected by these regulations to ensure the smooth operation of IT systems and infrastructure.
Practical implementation in IT service management
Compliance issues are closely linked to risk management, particularly in the field of IT. Organisations must develop contingency plans, identify risks and make their IT infrastructure resilient. At the same time, regulations often specify which measures are required within the governance framework, such as the filing of contingency plans. Implementing effective emergency management proves difficult if contingency plans and communication strategies are managed solely in Word or Excel documents. In such cases, the necessary context is often missing, and it becomes difficult to align these plans with the overarching business processes.
When all these issues are considered within the context of IT service management or enterprise service management, their benefits become clear. Contingency plans designed to support specific services, as well as business processes based on these services, can be linked to a CMDB. This CMDB is an essential component of an IT Service Management suite and forms the basis for the implementation of contingency measures. The workflow engine of service management suites enables the step-by-step and (partially) automated execution of such contingency plans. For example, when a measure from a contingency plan is implemented, it often involves change management issues. Through changes or releases, specific measures can be carried out that alter the infrastructure of the environment. These changes are documented in the CMDB and are incorporated into future contingency plans or used to improve existing ones.
Integration is key
This foundation is already present in Business Continuity Management (BCM), particularly in contingency plans, risk registers and other relevant documents. The same applies to SecOps and contract management. Here, too, tasks can be assigned, which is a fundamental function of service management: allocating tasks and ensuring that the right people are informed. This can be achieved through automated emails or via Teams chat groups, which are used in IT service management to notify the relevant people quickly.
In risk management, monitoring systems, vulnerability management and SIEM can be used to monitor risks. When security incidents are handled as part of Security Event Management and Security Incident Management, these issues are integrated into the IT service management context, which is based on the CMDB and works in conjunction with other IT incidents. Risk management is closely intertwined with IT service management processes, which also helps to ensure compliance with regulatory requirements.
Everything at a glance
GRC solutions such as those from OpenText also offer the option of managing IT contracts – such as maintenance, licence and purchase agreements – and linking them to infrastructure and services. This also enables comprehensive document management. Contracts play a central role in compliance and are relevant in many areas – be it licences, equipment or service providers. Service contracts must be stored in the CMDB so that they are accessible at all times. It is important to be familiar with the Service Level Agreements (SLAs) and to know who to contact in the event of an incident. Contract management must also be kept informed at all times of which contracts exist, what terms and conditions apply, and whether these contracts require regulatory assessment, whilst the infrastructure must also have access to these contracts.
The close integration of business continuity management, SecOps, contracts, and governance, risk and compliance can be mapped within an IT service management tool. All these processes draw on the same IT service management processes, which are interlinked and serve as a common foundation.
Further information is available on the Governance, Risk and Compliance with OpenText webpage. There you will also find the first part of our webcast series on the topic, as well as the latest white paper.