How do you apply design factors to IT Audits. Just overheard someone explain 'level of aggregation' for IT Security policies by describing how many people have access to it. Why is this a thing???

like
Posting as :
works at
You are currently posting as works at

I agree. For the most part it doesn’t really make sense for IT controls. One example for a user review control.... if you have an ERP system with hundreds of users and only one person is performing the review.. I would say the level of aggregation is high as the review is not partitioned out and therefore predictability would be low.

like

Related Posts

Who all started hating Globant India…. Because of stupid..idiotic studio culture

For new joiners…. You have to slog in project….but in appraisal only a**licking of studio leadrs is considered…
Share your experiences.

P.S. left globant 3 months back only because of this reason
P.S.S. New joiners if you mind your own business… you are not good at chamchagiri… avoid globant please

What do you all think about AWS cloud practitioner
Cert? Not worth if I'm studying for cissp?

like

I got offer from Aioneers. Does anyone know about the work culture in Aioneers.?

like
like

Hi Fishers,
anyone who can refer me to Altimetrik.
I'm serving notice period looking for job switch.

Thank

Hello everyone !
I just graduated and I have made it pass the third interview which was a two part working interview that I will receive compensation for. I have BS degree in healthcare professions and wanted to know if 40k is too low of salary to start off as a compliance officer for a pharmacy that provides discounted medications. My first 3 months will be training for my position but I will be paid the same. The job hasn’t offered me a dollar amount yet and I want to be best prepared.

like

How did you give notice you were lateraling to people you like? Particularly if you haven't been there that long?

I'm lateraling to another firm because frankly I think the management of this one is terrible, but the people (and individual partners) I actually work with are awesome. I've only been here for about 18 months, so I imagine that short time frame will make it extra awkward 😬

like
like

I was released without cause today but my boss mentioned my battle with mental health and that I’m looking for other jobs before canning me. Should I address this with the board or leave it alone?

like

How consistent are everyone's engagements across clients? I feel like I bounce around a lot between NIST/PCI/ISO compliance reviews, pen tests, specific reviews for AD, VMware, networking, SQL cont...

like

Hello! I’m looking for study materials for the PHR. Does anyone have recommendations for cost effective resources or perhaps willing to part with your study materials?

like

Do you think social media has helped us or hurt us more as an industry?

like

Where in Healthcare Consulting can a registered nurse succeed? I read about healthcare consulting companies and the services they offer and they appear heavy IT/comp-sci based. What are healthcare consulting specialties where an RN can leverage their clinical background?

like

I cleared Accenture interview and today got an email to upload documents on their portal. Also, got a call from HR and she asked about the salary expectations and other details. And few minutes later I found that my profile has been put on hold.

question is, they will negotiate with me or they have rejected my profile ?

like

Any insights on Ares Management NYC office? Looking at private equity role there, wondering about firm culture, what differences to expect coming from a consulting firm, etc

like

I have 10+ Year experience. My expertise are Java, Springboot, Micro-service, docker and kubernates. What salary I should expect in EXFO Company as Principal Software.

like

Getting an email saying "variable compensation" may be affected makes me feel like a vampire in a silver mine.

like

Just curious about salaries in Morgan Stanley Investment Management India, particularly Marketing department. What's the pay like for Associate, Senior Associate and VP? Do share your Yoe as well! Thanks.

like

I’ve been freelancing at a bigger NYC agency for a while and just found out that some of the FT creatives/account folks with significant responsibility make <45k. How is that okay?

like

Additional Posts in Risk Assurance

I have an interview coming up for internal audit manager. Currently in external audit. When asked about my experience in ERM - what would you say Is transferable skills that I can leverage in my answer?

like

Anyone moved from NE Risk Advisory to big tech firms?
Google / Amazon / Facebook
Just wanna know what roles/positions you guys are taking?
Got few interview calls but I think profiles don’t match

like

How do we go about renaming this bowl to Technology Risk? #ey

likefunny

Anyone hiring for entry level risk compliance roles?

like

When is busy season over for the SOX side of stuff? Please tell it doesn’t go past 12/31.

funny

How do we shift to investment banking/wealth management and is it worth it?

like

Be honest, do you see yourself staying in the game to make partner?

likehelpful

Interviewing around right now. What comp should I ask for M1 roles? IT Audit, NYC

like

Is anyone here in KPMG’s CRM Risk practice? If so do you know if they are still hiring??

like

How do you all keep up with trends in risk and internal audit?

like

So I was offered a role in Strategy Consulting in after 2 years in Risk Consulting however, after 2 years I’ve only worked on Internal audit engagements few ad hocs such as updating risk register and the delegation of authority matrix.

Honestly speaking I am doing good and I am up for promotion in October however I am not fully enjoying my time but I fear that the move would not be a good and I can’t hit the ground running which scares me.

Any advice and past experiences in such career shit?

like

Anyone can give insight in B4 Risk in Houston/Dallas market?

like

Got an offer at a smaller firm for $115k, is that good? I have almost 4 years of experience

like

What’s the level of evidence of review needed for controls that are not management review controls (MRC)? I’m an internal auditor and I’m documenting what is needed for lower risk controls in the SOX environment.

Does management need to have review
comments or checklist even for low or medium risk controls? And should I document those? Thanks!

like

Any model risk auditors out there? Curious of the required skillset needed for the role.

Any recommendations on lower mid market IT risk advisors who are good at looking at IT controls for data warehousing? Should we be talking to LMM accounting firms or specialist boutiques?

We're a lower mid market tech company looking for some consulting help to look at our current data warehousing setup and getting recommendations on control remediations

TIA!

like

Any strong performing seniors looking for a pay increase and potential fast track to manager? Reach out to me. Expanding the team and would love to bring in some new talent.

like

I have a Deputy CISO who constantly instructs us to not go to HR with top level compliance issues (because JP Morgan Chase frowned upon it). But these issues are pervasive to tone at the top and could cause non compliance. What should I do?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal