<?xml version="1.0" encoding="utf-8"?><rss version="2.0">
<channel><title><![CDATA[Compliance Focus - Comments for blog: IT-GRC Emerges as a New Market Segment]]></title><link>http://www.compliancefocus.com</link><description /><language>en-us</language><copyright><![CDATA[http://www.compliancefocus.com]]></copyright><generator>N/A</generator><webMaster>jim@compliancefocus.com</webMaster><lastBuildDate>Sat, 04 Sep 2010 17:59:26 EDT</lastBuildDate><ttl>20</ttl><item><title><![CDATA[Comment #1]]></title><link>http://www.compliancefocus.com/blogs/14/IT-GRC-Emerges-as-a-New-Market-Segment.html#Comment1</link><description><![CDATA[Funny, because I see almost no "R" there, as well!<br/><br/>
(Comment posted by Alex at 8:28 am, Sat 5th Apr 2008)]]></description><author>no@spam.com (Alex)</author><pubDate><![CDATA[Sat, 05 Apr 2008 08:28:23 EDT]]></pubDate><guid isPermaLink="true">http://www.compliancefocus.com/blogs/14/IT-GRC-Emerges-as-a-New-Market-Segment.html#Comment1</guid></item><item><title><![CDATA[Comment #2 (Reply to Comment #1)]]></title><link>http://www.compliancefocus.com/blogs/14/IT-GRC-Emerges-as-a-New-Market-Segment.html#Comment2</link><description><![CDATA[For true risk analysis, I would agree, and I have another blog post coming on the lack of risk management, threat modeling, etc. in these tools. Many of the IT-GRC tools do however provide some overarching risk management capabilities- managing workflow of remediation items to closure for example. And despite most of the tools lacking a rigorous way to *analyze* risk, there is still a lot of value in helping organizations manage closure of the big gaps.<br/><br/>
(Comment posted by Jim at 11:17 am, Sat 5th Apr 2008)]]></description><author>no@spam.com (Jim)</author><pubDate><![CDATA[Sat, 05 Apr 2008 11:17:05 EDT]]></pubDate><guid isPermaLink="true">http://www.compliancefocus.com/blogs/14/IT-GRC-Emerges-as-a-New-Market-Segment.html#Comment2</guid></item></channel></rss>