SlideShare a Scribd company logo
How Resolver
Uses Resolver
Hello!
I am James Patterson
Chief Operating Officer at Resolver
james.patterson@resolver.com
Overview
â–Ș InfoSec Controls Documentation
â–Ș SOC2, ISO27001
â–Ș Policy Management
â–Ș Op Risk
â–Ș Vendor Risk Management
â–Ș Application Management
â–Ș Asset Management
â–Ș Legal Requests
â–Ș Project Tracker
InfoSec Controls Documentation
Control
Documentation
Controls Linked to
SOC2, ISO 27001
Linked to
Policies
Operating Evidence
Attached to Controls
Policy Management
Policy
Repository
Basic Approval
Process
Operational Risk Management
Supports Annual Risk
Assessment Process
Interview –
Risk Identification
Risk
Assessment
Application Risk Management
Applications Are
Assigned an
Owner
Annual Criticality
Assessment by
Owner
â–Ș Confidential
data, PII data or
critical business
process = High
Risk
â–Ș Otherwise =
Low Risk
Hosted
High Risk
Applications
â–Ș Must have annual
SOC2 or similar
audit
â–Ș Request most
recent audit result
â–Ș Review and
document results
Internal
High Risk
Applications
â–Ș Undergo an
internal
InfoSec audit
Low Risk
Applications
â–Ș Not reviewed
Application Access Management
Annual Review of
Application User
Access
Done by all department
heads
State Access per
Employee
Which applications they
should have access to
Read, Edit or Admin
Application Owners
Review the Output
Ensure user access is
correct
Asset Management
All Assets Are
Tracked
â–Ș With Owner,
Location

Thanks!
Any questions?
james.patterson@resolver.com

More Related Content

PPTX
CISSP Chapter 1 BCP
PDF
Alliance session 4373 risk management from on premise to the cloud – a foc...
PPT
Cisa Certification Overview
PPTX
Hernan Huwyler - Identity and Access Management CIO & CISO Nordics
PPTX
Information Systems Audit & CISA Prep 2010
PPT
The security sdlc
PPTX
How to build a change workflow process
 
PPT
CISSP Chapter 1 BCP
Alliance session 4373 risk management from on premise to the cloud – a foc...
Cisa Certification Overview
Hernan Huwyler - Identity and Access Management CIO & CISO Nordics
Information Systems Audit & CISA Prep 2010
The security sdlc
How to build a change workflow process
 

What's hot (20)

PPTX
IT Audit - Evolve and Stay in the Game
PPTX
CISA Training - Chapter 1 - 2016
PDF
Hernan Huwyler - Boards in a Digitalized World
PDF
The CSA STAR Program: Certification & Attestation
PDF
PA-DSS and Application Penetration Testing
PDF
CNIT 160: Ch 2b: Security Strategy Development
PPTX
Five biggest secrets to an it audit webinar slides
PDF
Minimizing Privacy Risk - Prof. Hernan Huwyler, CPA MBA
PPTX
Msp saner 2.0
PPT
Altran Financial Services
 
PDF
CSA STAR Program
PPT
Security audit
PDF
Surviving a HIPAA Audit: Five Crucial Steps
PDF
Functional safety-overview
PPTX
Log Monitoring, FIM– PCI DSS, ISO 27001, HIPAA, FISMA and EI3PA
PPTX
Senseity
PDF
Audit and compliance services
PDF
Financial Domain Testing: The Breakdown
PDF
Everything You Need To Know About SOC 1
PPTX
Iso27001 Audit Services
IT Audit - Evolve and Stay in the Game
CISA Training - Chapter 1 - 2016
Hernan Huwyler - Boards in a Digitalized World
The CSA STAR Program: Certification & Attestation
PA-DSS and Application Penetration Testing
CNIT 160: Ch 2b: Security Strategy Development
Five biggest secrets to an it audit webinar slides
Minimizing Privacy Risk - Prof. Hernan Huwyler, CPA MBA
Msp saner 2.0
Altran Financial Services
 
CSA STAR Program
Security audit
Surviving a HIPAA Audit: Five Crucial Steps
Functional safety-overview
Log Monitoring, FIM– PCI DSS, ISO 27001, HIPAA, FISMA and EI3PA
Senseity
Audit and compliance services
Financial Domain Testing: The Breakdown
Everything You Need To Know About SOC 1
Iso27001 Audit Services
Ad

More from Resolver Inc. (20)

PDF
How to Prove the Value of Security Investments
PDF
ERM Benchmarking Survey Results
PPTX
Best Practices and ROI for Risk-based Vulnerability Management
PDF
Taking a Data-Driven Approach to Business Continuity
PDF
Terrorism in a Corporate Setting
PDF
Reporting to the Board on Corporate Compliance
PDF
An Intro to Resolver's Compliance Application
PDF
Information Security Best Practices: Keeping Your Company's Data Safe
PDF
Security Trends: From "Silos" to Integrated Risk Management
PDF
Modelling your Business Processes with Resolver Core
PDF
Scammed: Defend Against Social Engineering
PDF
A Peek at adidas Group's Integrated Risk & Security Management Strategy
PDF
An Intro to Resolver's Resilience Application
PDF
Data Driven Risk Assessment
PDF
How to Achieve a Fully Integrated Approach to Business Resilience
PDF
An Intro to Resolver's Risk Application
PDF
Keeping Your Data Clean
PDF
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
PDF
An Intro to Resolver's InfoSec Application (RiskVision)
PDF
Leveraging Change Leadership to Find Success in your IRM Program
How to Prove the Value of Security Investments
ERM Benchmarking Survey Results
Best Practices and ROI for Risk-based Vulnerability Management
Taking a Data-Driven Approach to Business Continuity
Terrorism in a Corporate Setting
Reporting to the Board on Corporate Compliance
An Intro to Resolver's Compliance Application
Information Security Best Practices: Keeping Your Company's Data Safe
Security Trends: From "Silos" to Integrated Risk Management
Modelling your Business Processes with Resolver Core
Scammed: Defend Against Social Engineering
A Peek at adidas Group's Integrated Risk & Security Management Strategy
An Intro to Resolver's Resilience Application
Data Driven Risk Assessment
How to Achieve a Fully Integrated Approach to Business Resilience
An Intro to Resolver's Risk Application
Keeping Your Data Clean
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
An Intro to Resolver's InfoSec Application (RiskVision)
Leveraging Change Leadership to Find Success in your IRM Program
Ad

Recently uploaded (20)

PPTX
Online Work Permit System for Fast Permit Processing
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PPTX
ai tools demonstartion for schools and inter college
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PPTX
L1 - Introduction to python Backend.pptx
PPTX
Transform Your Business with a Software ERP System
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
 
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
System and Network Administraation Chapter 3
PPTX
ManageIQ - Sprint 268 Review - Slide Deck
PDF
Digital Strategies for Manufacturing Companies
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PPTX
ISO 45001 Occupational Health and Safety Management System
Online Work Permit System for Fast Permit Processing
Internet Downloader Manager (IDM) Crack 6.42 Build 41
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
ai tools demonstartion for schools and inter college
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
L1 - Introduction to python Backend.pptx
Transform Your Business with a Software ERP System
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
 
Which alternative to Crystal Reports is best for small or large businesses.pdf
Design an Analysis of Algorithms I-SECS-1021-03
System and Network Administraation Chapter 3
ManageIQ - Sprint 268 Review - Slide Deck
Digital Strategies for Manufacturing Companies
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
ISO 45001 Occupational Health and Safety Management System

How Resolver Uses Resolver