Training Catalogue
WWISE
SPEAK TO A CONSULTANT

ICT Governance
& Compliance

What is ICT Governance?

ICT governance is a facet of enterprise corporate governance and it is aimed at ensuring that organisations manage their IT risks effectively and in line with the overall business objectives. ICT governance frameworks enable organisations to produce measurable results toward achieving their ICT strategies and goals.

Across the globe, organisations are subject to multiple legislative and regulatory requirements that govern the protection of confidential information, financial accountability, data retention, and disaster recovery, among other things. Organisations must also assure shareholders, stakeholders, and customers that they have an effective ICT environment. To ensure that organisations meet relevant internal and external requirements, organisations can implement a formal ICT governance programme that provides a framework of best practices and controls.

GDPR

What is GDPR?

The General Data Protection Regulation (GDPR)  is a pan-European data protection law.

The EU’s Data Protection Directive of 1995, and all other member state laws that have been based on it, including the UK’s DPA (Data Protection Act) of 1998. Regulations and Directives are the two major types of legislative acts that are enforced by states of the EU. Regulations apply directly to all EU member states and are binding. Directives, on the other hand, are goal agreements that member states must achieve with domestic legislation.

What does the GDPR do?

The GDPR allows European Union data subjects to have more control over their personal data and how it is processed. Organisations will also be required to comply with a range of rules and obligations regarding the processing of the personal data of their clients.

Who does the EU GDPR apply to?

The GDPR applies to all European Union (EU) organisations that gather, store, and process any personal data of citizens and people residing in the EU. 

The rules and obligations stipulated by the GDPR also applies to all organisations based outside the EU that perform services and offer products to any EU residents, which include monitoring or processing their behaviour or personal data. 

What are data controllers and processors?

A data controller is a person, public authority, agency, or body that determines the processes of personal data. A data processor processes data on behalf of a data controller. The requirements for compliance depend on whether you are a data controller or processor.  

What does GDPR require you to do?

  • Governance and accountability.
  • Perform data protection impact assessments when processing. Operations are considered as high-risk.
  • Ensure that personal data is kept safe and secure through the implementation of technical and organisational measures.
  • Steer a GDPR meeting which includes staff awareness training.
  • Appoint a data protection officer where necessary.

The benefits of GDPR compliance

There are great advantages to GDPR compliance. By approaching data protection correctly, your organisation can enjoy the enhancement of its reputation by building better customer relationships with existing and potential new customers.

Other benefits of complying to the GDPR include:

    • A risk reduction of data breaches.
    • An increase in information security.
    • Gaining a competitive advantage because of increased customer trust.

How Can WWISE help you with GDPR?

ISO 27701:2019 Security Techniques is extension to ISO/IEC 27001 and ISO/ IEC 27002 for Privacy Information Management (also Personal Information Management). WWISE can implement an Information Security Management System aligned to ISO 27001 and 27701 which will assist your organisation in complying to GDPR. Simply contact us today!

GDPR

King IV™

What is King IV™?

If King IV™ required a one-word synopsis, ‘transparency’ would be the best word to describe it. The predecessors of King IV™ created the foundation of complete corporate governance being a vital component of good corporate citizenship. The idea of good corporate governance stems from the recognition that organisations form an integral part of society, therefore, organisations are held accountable to any current or future stakeholders. King IV™ has introduced an ‘apply and explain’ regime which recommends the transparency of organisations throughout the application of their corporate governance practices.

King IV™ reiterates that good corporate governance goes beyond a quick tick box or compliance exercise, and should be considered as a universal, integrated collection of measures that require an extensive understanding and should be implemented in an integrated manner. King IV™ recommends that the King IV™ Code be applied in a sensible manner to ensure that an organisation’s practices are interpreted accordingly. This ensures that an organisation takes full advantage of the benefits offered by this facet of corporate governance.

Benefits of King IV™

King IV™ assists organisations to reap the benefits of complying with corporate governance. The King IV™ governance comprises 17 principles that encourage an organisation to move beyond merely complying and moving towards creating actions that relate to and integrate with an organisation’s context, which in turn will shift them towards accomplishing their goals.  Corporate governance exists to produce positive outcomes for organisations through implementation.

The list of key benefits includes:

  • Boosted reliability and improved reputation. A well-governed organisation is better suited to access financing at more desirable rates, ensuring the organisation is more appealing to investors and shareholders. These organisations tend to attract loyal customers and talented employees.
  • Good governance leads to more control, transparency, and a stronger resistance to fraud. White-collar crimes are currently one of the greatest risks for organisations as they are often underreported.
  • Good corporate governance enables organisations to mitigate risks more successfully to add to their disaster recovery capabilities, ensuring the organisation is more robust.
  • Corporate governance codes oblige governing bodies to create succession plans for high-profile leaders to avoid any interruptions in leadership, which can be detrimental to an organisation.

How Can WWISE Help you with King IV™?

King IV™ has principles related to ISO 9001:2018 Quality Management Systems and ISO 31000:2018 Risk Management Guidelines to assist in ensuring a framework of Good Governance. The ISO 37000 Guidance for the Governance of Organisations.  Key principles and relevant practices and a framework to guide the governance of organisations in how to meet their responsibilities so that they can fulfil their purpose. It is applicable to all organisations, regardless of type, size, location, structure or purpose.

WWISE can assist in implementing ISO 9001:2018 in conjunction with ISO 31000:2018 and ISO 37000:2016 to assist organisations with Governance best practices.

ITSM – ITIL

ITSM vs ITIL – Understanding the Difference

When it comes to managing IT services, two terms often come up: ITSM (IT Service Management) and ITIL (Information Technology Infrastructure Library). While they are closely related, they are not the same. Understanding the difference is essential for organisations looking to improve efficiency, align IT with business goals, and adopt international best practices.

What is ITSM- ITIL?

The Information Technology Infrastructure Library (ITIL) is a framework which aligns IT services with business needs. ITIL processes tasks, procedures, and checklists that are not company specific but can be part of an organisation’s strategy plan to maintain competency. The framework can be used to demonstrate compliance and measure improvement within a business.

ITSM (IT Service Management) refers to the practice of managing IT services end-to-end. It focuses on designing, delivering, managing, and continually improving the way IT supports the needs of the business.

Common ITSM processes include:

  • Incident Management
  • Problem Management
  • Change Management
  • Service Level Management
  • Asset and Configuration Management

ITSM is the “what” and “how” of IT service delivery. It is the discipline that ensures IT services provide value and meet agreed business requirements.

ITIL (Information Technology Infrastructure Library) is a framework of best practices that guides organisations in implementing ITSM effectively. It provides structured processes, roles, and metrics to help standardise IT service delivery.

Key ITIL practices include:

  • ITIL Service Strategy
  • ITIL Service Design
  • ITIL Service Transition
  • ITIL Service Operation
  • Continual Service Improvement (CSI)

ITIL is the “how-to” guide for ITSM. It provides the methodology and detailed steps for applying ITSM principles.

The benefits of ITIL

  • Aligns IT solutions with business requirements.
  • Consistency.
  • Effective service delivery.
  • Improved services and data processing.
  • Realistic Service Levels.
  • Improvement of the Return on investment (ROI).

How Can WWISE help you with ITIL?

At WWISE, we recognise the importance of ITC Governance. We offer consulting, and training services, as well as the development of ITIL systems against the ISO 20000-1:2018 IT Service Management System Requirements standard. We assist with Implementation to prepare an organisation for ISO 20000-1:2018 certification. With our 100% certification rate, you can rest assured your business will conform. 

Information Technology Infrastructure Library
CORBIT

COBIT 5 

What is COBIT 5?

COBIT stands for Control Objectives for Information and Related Technologies, quite a mouthful, is it not? COBIT is a framework created by the Information Systems Audit and Control Association (ISACA) for Information Technology Management and IT Governance. The framework highlights and defines the generic process of IT Management processes, relative objectives and outputs, key processes and Objectives. The framework measures performance and maturity using the Capability Maturity Model (CMM) which is a tool to study data collected from organisations contracted in the U.S Defence.

Benefits of COBIT 5

  • COBIT is an IT management framework with globally accepted principles, practices, tools, and models that increase trust.
  • The framework can be implemented within organisations of any size.
    Additionally, COBIT can be aligned to the ISO/IEC 27001:2022 Information Security Management System standard.

Compliance

WWISE cannot certify your organisation against COBIT 5. We can however introduce you to the ISO/IEC 27001:2022 Information Security Management System. This Information Security Management System (ISMS) will ensure you comply with the principles of COBIT 5. By implementing this ISMS, you will reap benefits through:

  • Time and cost savings.
  • Improved productivity and customer satisfaction.
  • Your organisation’s senior management has efficient ways to manage areas of responsibility as they are clearly defined.

Once certified, you will gain credibility in the industry and a competitive edge, especially when tendering for public work projects. Certification shows your customers that you follow standardised procedures of consistency. You also benefit from quality measures. Once the systems are in place, you can ensure on-time and high-quality service delivery, a decrease in returned products, less time spent handling complaints, and improved employee morale.

PRINCE2 

What is Prince2?

PRINCE2 is the abbreviation used for PRojects IN Controlled Environments. The tool is a structured project management and practitioner certification programme. PRINCE2 highlights the importance of breaking down projects into manageable and controlled stages. 

These principals are adopted across the globe, in the UK, Western European countries, and Australia. The principles are available in many languages.

Benefits of Prince2

PRINCE2 assists with methods for managing projects within a clearly defined framework. This framework does not guarantee seamless project management, as it is dependent on the complexities of projects. Benefits include:

  • Increased product quality.
  • Effective resource optimisation.
  • Boost in confidence amongst the project team.

Limitations and Certification of Prince2

Icon 1 PRINCE2 2017 Foundation: confirms the holder has sufficient knowledge and understanding of PRINCE2 and is able to work on projects using this framework.
Icon 2 PRINCE2 2017 Practitioner: confirms that the holder has achieved a good understanding of the application of PRINCE2 within a given scenario. A qualified PRINCE2 Practitioner who will go on to study the APMP qualification of the Association for Project Managers (APM).
Icon 3 PRINCE2 Agile Foundation: Confirms the holder has enough knowledge and understanding of PRINCE2 to utilise the framework in an agile way.
Icon 4 PRINCE2 Agile Practitioner: Confirms the holder can apply the project management principals of PRINCE2 and combine the principals with the agile concepts such as Scrum and Kanban.

 

Training and Certification

PRINCE2 certification is awarded by AXELOS, while training is provided by an Accredited Training Organisation (ATO), with a final examination to be granted accreditation.

While PRINCE2 is not a principal or framework facilitated by WWISE, we offer several Management System solutions that can assist your business to prepare and gain the expert advice to manage projects accordingly.

CORBIT

POPI 

What is the POPI Act?

Due to the globalisation of economies, the rapid expansion of technology and the internet’s ability to transfer communication swiftly from one country to another, the protection of personal information or data has become the object of global recognition. The purpose of the Protection of Personal Information Act (POPIA) is to ensure the protection of the constitutional right to privacy when organisations collect, process, store and share another individual’s or entity’s personal information. The Act holds institutions accountable when processing personal information and bestows certain rights of protection to the information owner. 

Why do you need it?

  1. Ignorance of the law is no excuse
    The POPI Act applies to any public or private institution which processes personal information. This includes processing the personal information of other entities. It is a code of conduct by which all businesses must comply. The penalties for non-compliance range from penalties of up to R10 million or imprisonment of up to 10 years. Therefore, achieving legal compliance brings with it a reduction in the risks of restrictions on fines and lawsuits.
  2. Alignment to global best practice
    Multiple jurisdictions around the world have already implemented data privacy legislations, such as the EU’s GDPR, the California Consumer Privacy Act, Australia’s Privacy Principles (APP), Canada’s Personal Information Protection and Electronic Data Act (PIPEDA) and Brazil’s Brazilian Internet Act amongst others. Therefore, compliance with the POPI Act assists organisations in aligning with global best practice in the field of Data Privacy.
  3. Transactions with global entities
    Non-compliance with globally aligned legislation like POPI can restrict a company’s ability to transact with other companies in the information economy.
  4. Transparency in processing information
    Compliance to the POPI Act assures stakeholders that an organisation will process information in a trustworthy manner. When consumers trust an organisation, they are more likely to share their private information with such an organisation. Therefore, POPI compliance becomes a marketable tool.
  5. Data Security Culture
    South Africa is reported to have the third highest rate of phishing attacks in the world. Furthermore, it is estimated that South Africa loses R1 billion a year due to cybercrime-related activities. Therefore, compliance to POPI assists in instilling an organisation-wide culture of data security.

What are the benefits?

The benefits of complying with the POPI Act include:

  • Aligning with International standards.
  • Aligning with ISO 27001.
  • Balance between the right to privacy and rights of access to information.
  • Implementing the constitutional right to privacy by safeguarding an entity’s personal information.

How can WWISE assist?

WWISE simplifies compliance to the POPI Act by assessing your businesses’ current compliance to the Act against the measures that need to be taken for full compliance. Compliance with the POPI Act is aligned to the ISO 27001:2013 standard.

COSO

Establish Effective Internal Controls with the COSO Framework

Organisations implement the Committee of Sponsoring Organizations (COSO) framework primarily to establish effective internal controls, enhance risk management, and ensure compliance with relevant laws and regulations. Adopting this widely recognised COSO framework helps organisations achieve their operational, reporting, and compliance objectives more efficiently and effectively.  

Key Reasons for Implementation

  • Strengthen Internal Controls 

The COSO internal control framework provides a structured, comprehensive model for designing, implementing, and evaluating internal control systems across all levels and functions of an organisation. This minimises opportunities for errors, mismanagement, and fraud. 

  • Enhance Risk Management 

The COSO enterprise risk management framework emphasises the importance of identifying, assessing, and mitigating internal and external risks that could hinder the achievement of business objectives. This proactive approach helps protect assets, build organisational resilience, and ensures management can respond to threats effectively. 

  • Ensure Regulatory Compliance 

The COSO internal control framework is the de facto standard used by public organisations to meet requirements under the Sarbanes-Oxley Act (SOX) and other regulations. Implementing the framework helps organisations stay audit-ready, avoid penalties, and demonstrate adherence to legal and ethical standards. 

  • Improve Financial Reporting Reliability 

By establishing effective controls over financial processes, the COSO framework helps ensure the accuracy, completeness, and reliability of both internal and external financial statements. This builds investor confidence and stakeholder trust. 

  • Boost Operational Efficiency 

The framework promotes standardised processes and clear lines of responsibility, which can help streamline operations, reduce duplication of effort, and make the organisation more efficient and profitable. 

  • Promote Effective Governance and Culture 

A key component of COSO is the ‘control environment’, which sets the tone with top management by emphasising integrity, ethical values, and accountability. This fosters a risk-aware culture and ensures strong oversight by the board of directors and senior management. It also aligns with the COSO IT framework, promoting ethical conduct and transparency through improved technological governance. 

  • Better Decision-Making 

By providing management with accurate, timely, and relevant information through effective communication channels, the COSO framework enables more informed and strategic decision-making.  

By implementing the COSO framework, organisations can build a more resilient, transparent, and well-governed organisation capable of navigating business complexities and achieving sustainable success.  

Why Choose WWISE?

WWISE has years of experience in successfully implementing Committee of Sponsoring Organizations (COSO) framework across clients worldwide. Our experts help design, evaluate, and maintain internal control systems aligned with the COSO enterprise risk management framework to support effective governance and lasting compliance. Contact the COSO experts at WWISE today. 

CORBIT

SOC 1 & SOC 2: What are the Differences?

SOC (System and Organisation Controls) 1 and SOC 2 are independent audit reports designed to help service organisations demonstrate their internal controls to clients and stakeholders, including SOC 2 Type I vs Type II. The key difference lies in their focus: SOC 1 focuses on financial reporting, while SOC 2 focuses on data security and privacy.

Both SOC 1 and SOC 2 reports come in two types:

  • Type I evaluates the design of controls at a single point in time.
  • Type II assesses the design and operational effectiveness of those controls over a period, typically 6-12 months, providing greater assurance, including SOC 2 Type II, for a SOC 2 report.

SOC 1

Purpose

To assure a service organisation’s Internal Controls Over Financial Reporting (ICFR).

Audience

Primarily the service organisation’s management, their clients (user entities), and the external auditors of those clients who need to assess risk to the clients’ financial statements.

Examples of organisations

Payroll processors, loan servicers, and medical claims processors, or any other business whose services could impact a client’s financial reports.

SOC 2

Purpose

To evaluate an organisation’s controls related to data security and operational compliance based on the AICPA’s Trust Services Criteria (TSC).

Audience

A broader range of stakeholders, including current and prospective customers, business partners, and regulators concerned with data protection. Reports are generally confidential and shared under a non-disclosure agreement (NDA).

Examples of organisations

SaaS companies, cloud storage providers, and data centres that store, process, or transmit customer data.

Custom Software Development | ISO-Aligned Solutions

WWISE services include preparing for SOC audits (SOC 1 Type I/II or SOC 2 Type I/II), which involves aligning processes, controls, and documentation to AICPA trust principles and supporting SOC audit readiness. Service providers typically offer the following services:

Readiness Assessment (Gap Analysis)

A structured review to determine current compliance maturity by evaluating existing policies, procedures, and controls. Identify gaps against SOC 1 (ICFR) or SOC 2 Trust Services Criteria (Security, Availability, etc.) by reviewing system descriptions and in-scope services. Provide a prioritised remediation roadmap and determine audit boundaries and control ownership.

Control Design & Documentation Support

Services that help clients build or refine necessary controls, including assistance with drafting or updating policies, procedures, and standard operating processes; risk assessments; business continuity & disaster recovery documentation; mapping existing controls to SOC criteria; and designing missing or weak controls.

Implementation of Technical & Security Controls

Hands-on support to implement required security or operational controls, such as identity & access management policies and tooling, change management workflows, logging and monitoring setup (SIEM, centralised log retention), vulnerability management processes, configuration hardening (servers, endpoints, cloud environments) and encryption and key management standards.

Evidence Collection & Audit Support Setup

Preparing the organisation for the audit process by identifying required evidence and establishing evidence owners; building evidence-collection calendars and documentation repositories; assisting with the creation of sample evidence (e.g., access review logs); and conducting mock walkthroughs ("pre-audit interviews") with control owners.

Internal Control Testing (Pre Assessment Testing)

We also assist with conducting sample tests of controls (e.g., user access reviews, change ticket sampling), identifying failing controls before the auditor finds them, and providing remediation guidance for test failures.

Risk Assessment & Governance Setup

Supporting required governance activities such as facilitating an enterprise or IT risk assessment, developing risk registers, establishing governance committees or reporting structures and guidance for complying with COSO (for SOC 1) or TSC frameworks (for SOC 2).

System Description (SoC Narrative) Development

SOC reports require a detailed narrative section (“system description”). WWISE helps draft service commitments and system components; describes infrastructure, software, processes, data flows, and sub-service providers; defines control objectives and maps them to Trust Services Criteria; and ensures the narrative aligns with auditor expectations.

Audit Liaison & Project Management

We provide end-to-end support before and during the audit, create project timelines and manage milestones, act as the primary contact for auditors, help answer auditor questions and interpret criteria, and manage remediation during the audit if issues surface.

Remediation Assistance

We address issues identified during readiness or testing, build corrective action plans, implement control updates, deploy technology to close gaps (logging, MFA, backups, etc.), and train control owners.

Security Awareness & Control Owner Training

To ensure audit readiness is maintained, WWISE conducts SOC framework overview workshops, control owner responsibilities and evidence preparation, and secure practices training (passwords, phishing, incident escalation).

CORBIT

NIST

Strengthen Your Cybersecurity Posture with Expert NIST Consulting Services

In today’s digital landscape, compliance with the NIST Cybersecurity Framework (CSF) and other National Institute of Standards and Technology (NIST) frameworks is more than a regulatory requirement; it is a strategic necessity for safeguarding sensitive data and maintaining trust with clients and partners. Our NIST consulting services are designed to help organisations of all sizes navigate complex compliance requirements, reduce cybersecurity risks, and achieve certification readiness with confidence. 

Why NIST Compliance Matters

NIST frameworks set the gold standard for cybersecurity best practices across industries. Whether you are a federal contractor, a private enterprise handling Controlled Unclassified Information (CUI), or an organisation seeking to enhance its security posture, aligning with NIST cybersecurity guidelines ensures effective protection against evolving threats and positions you as a trusted partner in the marketplace. 

WWISE NIST Consulting Services

WWISE provide end-to-end NIST cybersecurity and compliance consulting support for implementing and maintaining compliance with key NIST frameworks: 

NIST Cybersecurity Framework (CSF) Consulting 

  • Gap Analysis & Risk Assessment 

Identify vulnerabilities and assess your current security posture using the NIST Cybersecurity Framework (CSF). 

  • Implementation Roadmap 

Develop a tailored plan to align your cybersecurity programme with the five core CSF functions: Identify, Protect, Detect, Respond, and Recover. 

  • Policy Development & Training 

Create NIST-aligned policies and deliver awareness programmes to embed best practices across your organisation. 

  • Continuous Monitoring 

Establish ongoing processes to maintain compliance and adapt to emerging threats. 

 

NIST SP 800-171 Compliance 

  • Readiness Assessment 

Benchmark your systems and assess NIST compliance readiness against 110 security requirements for protecting CUI. 

  • System Security Plan (SSP) & POA&M Development 

Prepare auditor-ready documentation to demonstrate compliance. 

  • Control Implementation 

Deploy technical and procedural safeguards for access control, incident response, and system integrity. 

NIST SP 800-53 Compliance 

  • Control Selection & Tailoring 

Our NIST 800-53 consulting helps you implement security and privacy controls for federal information systems. 

  • Risk Management Framework (RMF) Support 

Guide you through categorisation, control implementation, assessment, and authorisation. 

  • Audit Preparation 

Provide evidence mapping and documentation for successful assessments. 

 

Specialised Services Offered by WWISE 

WWISE offers specialised NIST consulting and policy development services to strengthen compliance and governance: 

  • Policy & Procedure Development 

Build comprehensive documentation for compliance and governance. 

  • Training & Awareness Programmes 

Equip your team with the knowledge to maintain compliance and mitigate risks. 

  • Continuous Compliance Management 

Monitor control effectiveness and update documentation as threats evolve. 

Why Choose WWISE?

  • Expertise Across Frameworks 

NIST Cybersecurity Framework, SP 800-171, SP 800-53, and related standards. 

  • Tailored Solutions 

Customised strategies for your industry, size, and regulatory requirements. 

  • Audit-Ready Deliverables 

From gap analysis to evidence packs, we prepare you for successful assessments. 

  • Proven Track Record 

Decades of experience helping organisations achieve compliance and strengthen cybersecurity resilience with almost 800 clients in 36 countries. 

 

Ready to simplify your NIST compliance journey? 

Contact us today for a consultation and take the first step toward a secure, compliant future. 

Sarbanes-Oxley (SOX)

What are SOX Controls, and Why Implement Them?

Companies implement the Sarbanes-Oxley (SOX) Act controls primarily for legal compliance and to achieve significant business benefits, such as preventing fraud, enhancing transparency, and building investor confidence.  

Legal and Regulatory Compliance

  • The main driver for implementing SOX controls is adhering to U.S. federal law, which mandates specific requirements for all publicly traded companies and their consolidated subsidiaries. Legal reasons include:  

    • Executive Accountability 

    Sections 302 and 906 require the CEO and CFO to personally certify the accuracy of financial reports and the effectiveness of internal controls. Falsely certifying reports can lead to severe criminal penalties, including large fines and imprisonment. 

    • Mandatory Internal Controls 

    Section 404 outlines the SOX 404 requirements where management and external auditors must assess and report on the effectiveness of the company’s internal controls over financial reporting (ICFR). 

    • Auditor Independence 

    SOX established the Public Company Accounting Oversight Board (PCAOB) to oversee external auditors and ensure their independence, preventing conflicts of interest that contributed to past scandals. 

    • Record-Keeping and Whistleblower Protection 

    The Act requires companies to maintain financial records for specified periods and makes it illegal to destroy or alter them to obstruct a federal investigation. It also provides legal protection for whistleblowers who report misconduct. 

    • Consequences of Non-Compliance 

    Failure to comply can result in significant legal and financial penalties, regulatory scrutiny, delisting from stock exchanges, and severe reputational damage.  

Business and Operational Benefits

Beyond the legal mandates, implementing SOX controls offers substantial strategic and operational advantages:  

  • Increased Investor Confidence & Trust 

By ensuring the accuracy and reliability of financial statements, SOX builds a foundation of trust with investors, stakeholders, and the public. This enhanced credibility can attract more investment and potentially lower the cost of borrowing. 

  • Fraud Detection & Prevention 

The implementation of internal controls, such as segregation of duties and access management, helps prevent internal and external fraud and unethical practices. 

  • Improved Internal Processes & Efficiency 

The process of documenting and testing controls encourages companies to streamline accounting and IT procedures, identify redundancies, and improve overall operational efficiency. 

  • Better Risk Management 

SOX compliance requires organisations to conduct thorough risk assessments, allowing them to proactively identify, manage, and mitigate potential financial reporting risks before they become major issues. 

  • Stronger Corporate Governance 

The act institutionalises good governance by laying the groundwork for transparency, accountability, and ethical behaviour across all levels of the organisation. 

  • Enhanced Cybersecurity Posture 

Many of the IT general controls (ITGCs) required for SOX compliance, such as access controls and data backup procedures, also strengthen a company’s overall security against cyber threats and data breaches. 

  • Preparation for Future Events 

Private companies often voluntarily adopt SOX practices to strengthen internal controls and prepare for a potential initial public offering (IPO), acquisition, or other major financial events.  

Why Choose WWISE?

WWISE has assisted many international organisations with implementing and auditing the Sarbanes-Oxley Act. Our specialists apply global best practices to help you maintain accountability, reduce risk, and improve financial integrity. Contact WWISE today. 

CORBIT
CORBIT

CIS Controls

THE CIS CONTROLS EXPLAINED

The CIS Controls (Centre for Internet Security Controls) are a set of best practices designed to help organisations improve their cybersecurity posture. They provide a prioritised and actionable framework to defend against the most common cyber threats. As of the latest version (v8), the CIS Controls are organised into 18 categories, grouped into three implementation groups (IG1, IG2, IG3) based on organisational maturity and risk profile.

An Overview of the 18 CIS Controls (v8)

  1. Inventory and Control of Enterprise Assets

Track and manage all hardware devices connected to your network to ensure only authorised devices are given access.

  1. Inventory and Control of Software Assets

Maintain a list of authorised software and prevent unauthorised or unmanaged software from being installed or executed.

  1. Data Protection

Protect organisational data through encryption, access controls, and secure data handling practices.

  1. Secure Configuration of Enterprise Assets and Software

Establish and maintain secure configurations for hardware and software to reduce vulnerabilities.

  1. Account Management

Manage user accounts, including creation, use, and deletion, to minimise unauthorised access.

  1. Access Control Management

Ensure users only have access to the data and systems necessary for their roles.

  1. Continuous Vulnerability Management

Regularly scan for vulnerabilities and remediate them to reduce exposure to threats.

  1. Audit Log Management

Collect, manage, and analyse audit logs to detect and respond to security incidents.

  1. Email and Web Browser Protections

Secure email and web browsers to reduce exposure to phishing and malware.

  1. Malware Defenses

Deploy anti-malware tools and ensure they are updated and monitored.

  1. Data Recovery

Implement backup and recovery solutions to ensure data can be restored after an incident.

  1. Network Infrastructure Management

Secure and manage network devices to prevent unauthorised access and ensure network integrity.

  1. Network Monitoring and Defense

To detect, prevent, and correct network-based attacks through continuous monitoring of network activities and defensive measures.

 

  1. Security Awareness and Skills Training

Educate users on security practices and provide ongoing training to reduce human-related risks.

  1. Service Provider Management

Ensure third-party service providers follow security practices and contractual obligations.

  1. Application Software Security

Secure applications through secure coding practices, testing, and patching.

  1. Incident Response Management

Develop and maintain an incident response plan to detect, respond to, and recover from security incidents.

  1. Penetration Testing

Conduct regular penetration tests to identify and remediate vulnerabilities.

  1. Security Management Program

Establish and maintain a comprehensive security programme aligned with business objectives.

Implementation Groups (IGs)

  • IG1: Basic cyber hygiene for small to medium-sized organisations with limited resources.
  • IG2: For organisations with moderate resources and risk exposure.
  • IG3: For enterprises with high security requirements and complex environments.

IEC 62443 IACS

WHAT IS IEC 62443 IACS?

The standard was originally developed as ISA 99 in the early 2000s before evolving into the international IEC 62443 series. 

IEC 62443 is a series of international standards for cybersecurity in industrial automation and control systems (IACS). It provides a structured framework for securing industrial networks across their entire lifecycle, from design to decommissioning. The standard aims to mitigate risk by providing requirements for asset owners, system integrators, and component suppliers, and it defines security levels (SLs) to match security measures with the perceived threat. 

Key aspects of IEC 62443 IACS

  • Holistic approach: It addresses security by combining technical safeguards with necessary people and process requirements.
  • Structured lifecycle security: The standard covers cybersecurity throughout the entire product and system lifecycle, including specification, integration, operation, maintenance, and decommissioning.
  • Roles and responsibilities: It applies to all stakeholders in the industrial supply chain, including component suppliers, system integrators, and asset owners.
  • Zones and conduits: It uses a flexible approach to segmentation by grouping assets into “zones” with similar security needs and defining secure “conduits” for communication between them.
  • Security levels (SLs): The standard defines four security levels to help organisations match their security measures to the appropriate threat level:
    • SL 1: Protects against casual or unintentional violations.
    • SL 2: Protects against intentional attacks using simple means.
    • SL 3: Protects against sophisticated attacks by motivated adversaries.
    • SL 4: Protects against advanced, well-resourced attacks, such as those by nation-states.
  • Focus on health, safety, and environment: It recognises that cyberattacks on IACS can have serious implications for health, safety, and the environment, and integrates cybersecurity with existing risk management practices.

WWISE offers consultancy services for IEC 62443 compliance that encompass the entire lifecycle of industrial cybersecurity—from gap analysis to certification and ongoing support.

Readiness & Gap Analysis

  • Perform a baseline assessment to evaluate current OT/ICS systems and determine gaps against IEC 62443 requirements.
  • Deliver a roadmap for compliance, tailored to your operational needs and risk level.

Risk & Threat Assessment

  • Conduct OT cybersecurity risk assessments, identifying vulnerabilities, threats, and potential impact.
  • Provide vulnerability assessments and penetration testing, tailored to industrial environments.

Governance, Policies, & Procedures

  • Develop or enhance OT security governance frameworks, aligned to IEC 62443.
  • Craft essential documentation: patch/change management, incident response plans, access control policies, and role matrices.

Secure System & Component Implementation

  • Design zones and conduits and implement defence-in-depth network segmentation.
  • For product manufacturers: advise on secure-by-design development, including secure SDLC processes to meet IEC 62443‑4‑1/4‑2.

Verification, Testing, & Audit Support

  • Perform gap audits, vulnerability scans, and security testing for compliance evidence.
  • Support on-site audit readiness, preparing documentation and liaising with certifiers for 62443 certifications.

Training & Awareness

  • Provide tailored IEC 62443 training for asset owners, integrators, and OT staff to build capability and awareness.

Certification & Evaluation

  • Assist manufacturers in obtaining IEC 62443-4-1/4-2 product certification, often in conjunction with accredited labs.
  • Assist integrators and end users in achieving system-level certification under IEC 62443‑2‑4 / 3‑3.

Continuous Monitoring & Ongoing Advisory

  • Offer threat monitoring, vulnerability management, and periodic compliance reviews.
  • Provide incident response support, including ICS-specific playbooks and post-incident analysis.

Engineering & OT Implementation

  • Deliver real-world network design, engineering, and hardening services for SCADA, DCS, substations, and utility environments.

Contact WWISE specialist consultants to provide further information on how we can assist you with IEC 62443 implementation.

CORBIT

Contact Us at WWISE to assist your organisation in improving your ICT Governance with one of the following options:

  1. Gap Assessment or Maturity Assessment.
  2. Implementation Plan and Programme through a detailed Risk Management System.
  3. Training and Awareness.
  4. Change Management through custom videos on Policies, Processes, Procedures and Various Legal Requirements.
  5. Independent Assessment through a Certified Auditor.

We can assist with a full turnkey solution in improving your governance on any framework that maybe required for conformance and compliance status.