Security
Security · IT GRC
Explore Security for IT governance, risk and compliance: diagnosis, frameworks, and how WAAC can help.
Pages in this category
- Essential evidence for a security audit checklist
Learn which security audit evidence is required, including documents, logs, controls, and traceability practices for compliance reviews.
- How to Assess ISMS Maturity Before ISO 27001
Learn how to assess your ISMS maturity before ISO 27001, identify gaps, prioritize improvements, and build a structured implementation roadmap.
- How to identify security audit nonconformities
Learn how to identify security audit nonconformities, assess risks, document findings, and prioritize corrective actions.
- How to implement SBOM in a development pipeline?
Learn how to implement SBOM in DevSecOps pipelines, automate software inventories, and improve vulnerability management processes.
- How to Perform an ISO 27001 Maturity Assessment
Learn how to perform an ISO 27001 maturity assessment, identify ISMS gaps, prioritize improvements, and build a structured implementation roadmap.
- IT Infrastructure Risk Assessment: How to Evaluate Controls
Learn how to perform an IT infrastructure risk assessment to evaluate security controls, identify vulnerabilities, classify risks, and prioritize actions.
- IT Risk Assessment in Corporate Environments
Learn how to perform an IT risk assessment to identify technology risks, evaluate controls, classify criticality, and prioritize actions.
- Secure Software Supply Chain Architecture Guide
Learn how to design a Secure Software Supply Chain architecture with DevSecOps, artifact security, traceability, and risk controls.
