<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>GRC on Sinetris's viewpoints</title><link>https://sinetris.info/glossary-contexts/grc/</link><description>Recent content in GRC on Sinetris's viewpoints</description><generator>Sine Die theme for Hugo</generator><language>en</language><webMaster>duilio@sinetris.info (Duilio Ruggiero)</webMaster><lastBuildDate>Sun, 07 Dec 2025 23:58:31 GMT</lastBuildDate><atom:link href="https://sinetris.info/glossary-contexts/grc/index.rss.xml" rel="self" type="application/rss+xml"/><item><title>Risk Owner</title><link>https://sinetris.info/glossary/risk-owner/</link><pubDate>Sun, 07 Dec 2025 23:58:31 GMT</pubDate><guid>https://sinetris.info/glossary/risk-owner/</guid><description>Person directly responsible for identifying, assessing, monitoring, reporting,
responding to, and defining intervention strategies in relation to risks associated
with an &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT asset&lt;/a&gt;.</description></item><item><title>Information Technology Asset</title><link>https://sinetris.info/glossary/information-technology-asset/</link><pubDate>Sun, 07 Dec 2025 23:19:32 GMT</pubDate><guid>https://sinetris.info/glossary/information-technology-asset/</guid><description>Hardware and software (e.g., applications, systems, virtual resources, data) that
an organization uses to support its business objectives.</description></item><item><title>Access Recertification Campaigns</title><link>https://sinetris.info/glossary/access-recertification-campaigns/</link><pubDate>Mon, 01 Dec 2025 10:25:02 GMT</pubDate><guid>https://sinetris.info/glossary/access-recertification-campaigns/</guid><description>Periodic review of user &lt;a class="glossary-term" href="https://sinetris.info/glossary/entitlements/"&gt;entitlements&lt;/a&gt;
to enforce the &lt;a class="glossary-term" href="https://sinetris.info/glossary/principle-of-least-privilege/"&gt;Principle of Least Privilege&lt;/a&gt;,
ensure &lt;a class="glossary-term" href="https://sinetris.info/glossary/orphaned-account/"&gt;orphaned accounts&lt;/a&gt; are removed,
and reduce internal threats and compliance violations.</description></item><item><title>Birthright Access</title><link>https://sinetris.info/glossary/birthright-access/</link><pubDate>Sat, 29 Nov 2025 15:32:02 GMT</pubDate><guid>https://sinetris.info/glossary/birthright-access/</guid><description>&lt;a class="glossary-term" href="https://sinetris.info/glossary/entitlements/"&gt;Entitlements&lt;/a&gt; automatically granted to a user when
they join an organization or change roles within it.</description></item><item><title>Subject Matter Expert</title><link>https://sinetris.info/glossary/subject-matter-expert/</link><pubDate>Mon, 24 Nov 2025 07:28:53 GMT</pubDate><guid>https://sinetris.info/glossary/subject-matter-expert/</guid><description>A professional with in-depth, specialized knowledge in a particular field, process,
or technology who acts as a trusted advisor, guiding teams, validating information,
and solving complex problems to ensure accuracy, efficiency, and successful project
outcomes.</description></item><item><title>Asset Administrator</title><link>https://sinetris.info/glossary/asset-administrator/</link><pubDate>Mon, 24 Nov 2025 01:27:13 GMT</pubDate><guid>https://sinetris.info/glossary/asset-administrator/</guid><description>Manages user roles, account assignments, and performs access reviews and audits
for an &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT asset&lt;/a&gt;.</description></item><item><title>Authentication Assurance Level</title><link>https://sinetris.info/glossary/authentication-assurance-level/</link><pubDate>Sat, 22 Nov 2025 08:02:00 GMT</pubDate><guid>https://sinetris.info/glossary/authentication-assurance-level/</guid><description>NIST standard to assess the degree of confidence and reliability of an authentication
process.</description></item><item><title>Asset Owner</title><link>https://sinetris.info/glossary/asset-owner/</link><pubDate>Sat, 22 Nov 2025 08:01:09 GMT</pubDate><guid>https://sinetris.info/glossary/asset-owner/</guid><description>Person or group responsible for an &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT asset&lt;/a&gt;.</description></item><item><title>Information Technology Asset Management</title><link>https://sinetris.info/glossary/information-technology-asset-management/</link><pubDate>Mon, 10 Nov 2025 14:55:30 GMT</pubDate><guid>https://sinetris.info/glossary/information-technology-asset-management/</guid><description>Systems to manage the lifecycle of &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT assets&lt;/a&gt;, including tracking, maintaining and disposing of hardware
and software.</description></item><item><title>Segregation of Duties</title><link>https://sinetris.info/glossary/segregation-of-duties/</link><pubDate>Thu, 04 Sep 2025 12:33:22 GMT</pubDate><guid>https://sinetris.info/glossary/segregation-of-duties/</guid><description>&lt;h2 id="description"&gt;Description&lt;/h2&gt;
&lt;p&gt;Segregation of Duties (SoD) is a mechanism designed to prevent the risks of errors and fraudulent behavior by dividing the actions required to complete a task among different employees.&lt;/p&gt;
&lt;h3 id="examples"&gt;Examples&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;To prevent financial fraud: the person approving an invoice cannot be the same person who issued it.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Reason:&lt;/strong&gt; they could potentially approve and pay fraudulent invoices to themselves or a fictitious supplier.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;To prevent both fraud and errors: the software engineer that approve code changes to critical assets cannot be the same person who submitted the changes.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Reason:&lt;/strong&gt; they could miss mistakes made by them (prevent errors) or abuse the system to their own advantage (prevent fraud).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;[Truncated]&lt;/div&gt;</description></item><item><title>Information Assurance</title><link>https://sinetris.info/glossary/information-assurance/</link><pubDate>Mon, 17 Mar 2025 10:43:09 GMT</pubDate><guid>https://sinetris.info/glossary/information-assurance/</guid><description>&lt;p&gt;Information Assurance (IA) is the practice of assuring information quality and managing risks related to the use, processing, storage, and transmission of information.&lt;/p&gt;
&lt;p&gt;The 5 pillars of information assurance includes protection of the &lt;strong&gt;Confidentiality&lt;/strong&gt;, &lt;strong&gt;Integrity&lt;/strong&gt;, &lt;strong&gt;Availability&lt;/strong&gt;, &lt;strong&gt;Authenticity&lt;/strong&gt;, and &lt;strong&gt;Non-repudiation&lt;/strong&gt; of information.&lt;/p&gt;
&lt;p&gt;In IT systems, when possible, assets should be tagged/labeled with proper Information Assurance level.&lt;/p&gt;
&lt;h2 id="confidentiality"&gt;Confidentiality&lt;/h2&gt;
&lt;p&gt;The property that information is not made available or disclosed to unauthorized individuals, entities, or processes.&lt;/p&gt;
&lt;div&gt;[Truncated]&lt;/div&gt;</description></item><item><title>Recovery Point Objective</title><link>https://sinetris.info/glossary/recovery-point-objective/</link><pubDate>Sun, 06 Aug 2023 10:10:15 GMT</pubDate><guid>https://sinetris.info/glossary/recovery-point-objective/</guid><description>Targeted duration of time between the event of failure and the point where operations resume.</description></item><item><title>Recovery Time Objective</title><link>https://sinetris.info/glossary/recovery-time-objective/</link><pubDate>Sun, 06 Aug 2023 10:10:15 GMT</pubDate><guid>https://sinetris.info/glossary/recovery-time-objective/</guid><description>Agreed maximum time, based on risk analysis, between the failure event and the restoration of operations.</description></item><item><title>Software Bill of Materials</title><link>https://sinetris.info/glossary/software-bill-of-materials/</link><pubDate>Sun, 06 Aug 2023 10:10:15 GMT</pubDate><guid>https://sinetris.info/glossary/software-bill-of-materials/</guid><description>&lt;p&gt;A Software Bill of Materials (SBOM) is a comprehensive inventory of all the components,
including dependencies and related installed tools, used in a software.&lt;/p&gt;</description></item></channel></rss>