Using technology to manage risk and compliance

The importance of technology in GRC

Decorative banner

Thank you for agreeing to participate in this research. Bloor Research is looking to gain a deeper understanding of how technology is helping organisations to better manage risk and compliance. Every year there are new regulations you have to consider or new threats you have to address. We are looking to ascertain the level of preparation organisations of different sizes and in different regions and industries are at in achieving risk management and compliance objectives in order to better understand where the roadblocks are. 
 
This survey should take no more than 10 minutes of your time. We are not asking for any of your personal information unless you choose to provide your email address to receive an advance copy of the research report or for entry into the prize draw. Email addresses will not be used for any other purpose. Our privacy policy can be accessed here.  
 
As a thank you, we offer you the following in appreciation of your response:
1. An advance free copy of the resulting research report.
2. Entry into a prize draw with more than $500 in prizes, paid in the currency of your choice. 
3. We will make a donation to charity on your behalf.
 
If you would like to leave the survey at any time, click on the "Exit this survey" link and all answers input will be saved. 

Thank you very much for your time. 
1.In what functional area do you work?
2.What size is your organisation?
3.In what region is your organisation based?
4.In which industry do you work?
5.What does GRC mean for your business? (Select all that apply)
6.Who is responsible for managing risk and compliance in your organisation?
7.What are the main threats that your organisations faces? (Select all that apply)
8.Have you experienced any of the following? (Select all that apply)
9.Which of the following compliance issues are most important to your organisation?
Very important
Somewhat important
Not important
Doesn't apply to us
Don't know
PCI
GDPR
ISO 27000 and similar
SOX
HIPAA
BCBS 239
MiFID II
COSO
COBIT
Internal and external audit requirements
10.How prepared are you for GDPR compliance?
Fully prepared
Somewhat prepared
Unprepared
We have established effective data ownership
We have allocated a specific budget
We have visibility over all personal data
We have controls in place to manage how data is accessed and used
We have adequate controls for protecting data from loss, damage and destruction
We have licensed appropriate tools for anonymising personal data
We have reporting processes in place regarding data use
We are prepared to deal with data access requests
All staff are aware of data protection requirements
11.For managing compliance, which statements apply to your organisation? (Select all that apply)
12.What do you need to do to achieve GRC? (Select all that apply)
13.What are the benefits of GRC? (Select all that apply)
14.What is stopping your GRC efforts? (Select all that apply)
15.How do you assess the risk associated with the following types of data?
Very risky
Quite risky
Not risky
SQL databases
Access databases
NoSQL databases
Spreadsheets
CSV files
Document systems
Emails
Other end-using computing file types
16.What tools do you use for governance? (Select all that apply)
17.How are governance policies created and implemented? (Select all that apply)
18.What technologies do you use for risk and compliance management? (Select all that apply)
19.What technologies do you deploy for managing information security? (Select all that apply)
20.Which areas are of most importance when selecting infrastructure partners (including cloud and MSPs)? 
Very important
Somewhat important
Not important
Service levels
Disaster recovery
Eco credentials
Security
Interaction with major cloud environments such as AWS and Azure
Cost
Built in PaaS features like data storage, analytics and others
21.Which of the following attributes are most important when selecting technology? 
Very important
Somewhat important
Not important
Product functionality
Reputation of vendor (how it benefits your organisation)
Ease of use
Ease of renewal
Ease of management
Robust management capabilities
Self service
Cost
Support
22.What are your preferred channels for procurement of technology?
Very important
Somewhat important
Not important
Online
From channel reseller
As a managed service
From cloud service provider
Direct from vendor
Direct from vendor's self-service portal or website
Other
23.What are your most important sources of information for technology purchasing decisions?
Very important
Somewhat important
Not important
Online reviews
Vendor website
Vendor sales representative
Technology content site
Peer recommendation
White papers
Webcasts/webinars
Trade shows or conferences
User groups or forums
Analyst firms
Blogs
24.Would you like to receive any of the following? 
25.Please enter an email address to receive your selected materials. All email addresses will be deleted once the incentive process is complete and will not be used for any other purpose. 
26.Which is your preferred currency?
Current Progress,
0 of 26 answered