RSS Amplifier

The Risk Register by ComplianceXO · Jun 22, 2026

Good Operations is Good Business

0
Sign in to vote or save

The Risk Register by ComplianceXO · The Risk Register by ComplianceXO

“Always have a backup… person.” In IT risk management, we talk about backups all the time. Have good ones, make sure you test them, and so on. And we’ll get discuss data backups in a future issue of The Risk Register. But an often-overlooked risk is who are your backups to your team members? Large companies have teams with cross-training and the ability for one team member to fill in for another when needed. But small companies often have just one person who knows how it all works and where all the parts live.

Just as last week was a caution about having vendor lock-in, small companies can end up with “key-person” risk, where their IT operations, procedures, and even access and passwords are all kept by a single individual. Then, when that person wins the lottery, or just goes on a cruise-ship vacation, the entire company is put at risk if something comes up that only the one person can help with. There are many reasons why a single employee might not come into work, some good, some bad. But them not being there should never be a reason your company can’t continue to operate.

Key account passwords (such as break-glass accounts), contact information, and other information needed to use, fix, or maintain IT systems should be stored in a secure vault. It’s okay if that isn’t digital – if it’s physically secured and available only to key personnel. Digital vaults work if every authorized user has their own login and if the vault keeps a log of who has accessed the information it stores. That way you know if people are accessing information when there’s no business justification, but they do have access when its needed.

It’s good to have the backup personnel identified and trained. They should also be given opportunities to perform some of the tasks while the key person is in the office. Backup plans are important to test, no matter the type of plan. This one is no exception. By having a good employee backup plan, your business will be more resilient. And your employees should be happier too, knowing if they decide to go on a vacation, the company will still be there when they get back.

Bottom line: Make sure two (or three) people know how to perform key operations the business needs to run. Ensure they cross-train on how the systems work, where they might break, and how to access the information needed to maintain them.

The third pillar is simple. It’s doing the right job, the right way. In the introduction to the Four Pillars, it’s described as “verifiable, consistent, and efficient execution of processes.” Running all the IT (and OT) systems and ensuring they continue to run is the key part of the Operations pillar. It’s the world of process and procedure: both the documented and the ad hoc. Our Governance pillar likes to talk about the policies which define what matters to the company. Operations are where we move that down a level and build out actional and verifiable plans to get the job done.

Good operations are composed of well-defined, repeatable, efficient, and verifiable activities. When anything at a business needs to be done, there’s a preferred way to make it happen. Whether it is hiring employees, procuring inventory, finding customers, shipping products, or anything else, knowing how to do these things get done is critical. All of these activities are part of the business’s operations. Some of them are related to the IT/OT world, and fall under your IT risk, compliance, and security program.

Being well-defined is typically the first step in building your operations program. For most organizations, well-defined just means documented. You took the time to sit down with key operators and had them write out the steps they take to do a job function. Often, this happens when the person who has done it for a while needs to train someone new. It’s a great opportunity to make sure the process is documented in a way that someone else can follow. The documentation might be on paper, in an electronic document, or even in a task management system like ServiceNow. Wherever it lives, it’s well-defined because its documented.

Being repeatable and efficient are side-effects of the documentation process. Often, when we figure out how to do a task, we continue to do it in the same order we figured it out originally. When we slow down to write all the steps out, we discover that some steps may be redundant. Or if we have certain information earlier in the process, it can reduce the overall effort. The process of documenting a process often leads to more efficiency in operations. And, because the process is documented, its far more repeatable, because we’ve made sure others can do things the same way (and we do too, if we follow our own documentation).

When a third-party auditor says, “show me that you always follow the process,” it’s not enough to say, here’s the documented process, we promise we always do it this way.

Finally, and most critically to an IT governance program, we need our processes to be verifiable. When a third-party auditor says, “show me that you always follow the process,” it’s not enough to say, here’s the documented process, we promise we always do it this way. There needs to be a formal check-off method as well. A document you print and check the boxes as you complete the steps and then sign and date the bottom is a classic example. Digital workflows help automate the effort and track the routing and sign-off of work automatically. However you choose to log the activities, it’s important they be logged in a reliable ledger you can show to auditors later.

Over the next several weeks, we’ll continue to dive into the different aspects of the Operations pillar. This includes concepts like separation of duties, business continuity, service desks, and monitoring. It also covers how you manage vulnerabilities, patching, and third-party security testing. All of these activities are key parts to operating a modern IT/OT environment, so be sure to subscribe to get a full exploration of these topics and more.

Next week we’re wrapping up our Four Pillars introduction by covering Culture. You can read the high-level description in our first issue: Welcome to The Risk Register. Next week will be the last weekly issue for free subscriptions. Paid subscribers will continue to get weekly issues, and the free subscriptions will fall back to monthly updates.

Don’t start the week without making your IT risk, compliance, and security program a bit better! In the vein of improving operations, you should review your employee onboarding and off-boarding process. If you don’t have those documented already, then this week is a good time to talk to the people responsible for the process and help them document the steps.

Most companies have someone in HR manage the process, which formally begins once the offer letter is sent. Onboarding then typically goes through setting up payroll, benefits, and signing off on the employee agreement. On the IT side, HR should be requesting accounts be created and sharing what types of access the new employee should receive. All of these steps, from the initial offer letter to creating the IT accounts, should be logged into auditable systems. Email requests are not good enough if you have to prove it to third-party auditors later.

Offboarding is just as important, and the process should show that IT assets were returned, accounts were disabled, and all the other HR steps were followed. A signed checklist can be a good idea, as it helps make sure the same steps are taken every time. Or, when there are legitimate exceptions, that it’s noted and approved by the appropriate person.

Make this week’s mitigation task to figure out if your processes are documented, current, and followed!

Happy Mitigating!

No posts

Read the original on compliancexo.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.