Fundamentals of Information Risk Management Auditing: An introduction for managers and auditors
by Christopher Wright
CHAPTER 3: RISK MANAGEMENT ASSURANCE AND AUDIT
Overview
Having established a risk assessment and control framework, the Board/senior management of an organisation will need comfort or assurance that it is designed and operating effectively. To achieve this, as part of their ERM process, many organisations are adopting the three lines of defence model. In this chapter we will consider this model for risk management and compare and contrast internal and external audit roles and responsibilities. Each of these has their own culture, their own roles and responsibilities. As an information risk manager, I have been required to work in all of these capacities. In this chapter we will consider:
• The three lines of defence model
• First line of ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access