"On this page you will find a set of useful agile factsheets which can be useful in many situations. You can download any one of them by clicking on a chosen image. If you can’t find what you need then you could visit our Frequent Agile Questions."
agile  guidelines  dopost 
5 days ago by niksilver
Enable or Disable IDN Punycode in Firefox Address Bar in Windows | Tutorials
"This tutorial will show you how enable or disable showing IDN punycode in the address bar of Firefox for your account in Windows 7, Windows 8, and Windows 10."
firefox  security  unicode  punycode  tip  dopost 
12 days ago by niksilver
Together we can thwart the big-tech data grab. Here’s how | John Harris | Opinion | The Guardian
"...perhaps something truly radical is required: a reconceptualisation of what the internet is, and what happens to the data that determines who controls it."
data  google  artificial_intelligence  internet  tim_berners_lee  future  dopost 
13 days ago by niksilver
How Apps on Android Share Data with Facebook - Report | Privacy International
"We also found that some apps routinely send Facebook data that is incredibly detailed and sometimes sensitive. Again, this concerns data of people who are either logged out of Facebook or who do not have a Facebook account. A prime example is the travel search and price comparison app "KAYAK"..."
apps  facebook  privacy  security  dopost  report 
19 days ago by niksilver
The Verge 2018 tech report card: Facebook - The Verge
"Whether you’re evaluating the company by its financial performance, its public perception, or its ability to contain and avoid scandals, the company will end the year in worse shape than it began."
facebook  analysis  dopost 
22 days ago by niksilver
Iranian phishers bypass 2fa protections offered by Yahoo Mail and Gmail | Ars Technica
"A recent phishing campaign targeting US government officials, activists, and journalists is notable for using a technique that allowed the attackers to bypass two-factor authentication protections offered by services such as Gmail and Yahoo Mail, researchers said Thursday."
security  phishng  2fa  dopost  iran 
4 weeks ago by niksilver
Transformation Troubles - 7 Things To Avoid When You Move To Agile - Matt Hosking - Agile Cymru 2018 - YouTube
Matt Hosking on agile transformation. Includes "Organisational culture is defined by the lowest standard of behaviour the organisation is willing to put up with."
culture  transformation  agile  video  technical_debt  dopost 
5 weeks ago by niksilver
Music Software & Bad Interface Design: Avid’s Sibelius - YouTube
"Sibelius is the embodiment of what not to do as a user experience designer and this video covers a range of examples of inappropriate design patterns and bad user interface choices. Then I go insane."
video  sibelius  criticism  user_interfaces  design  dopost 
5 weeks ago by niksilver
Frequent Password Changes Is a Bad Security Idea - Schneier on Security
"I've been saying for years that it's bad security advice, that it encourages poor passwords. Lorrie Cranor, now the FTC's chief technologist, agrees..."
security  passwords  advice  dopost 
6 weeks ago by niksilver
On-stage mistake means OnePlus won't have the first Snapdragon 855 phone
What defines maturity? "Even with that being the case, the very public nature of the error also calls into question OnePlus's overall maturity as a company."
oneplus  mistake  dopost 
6 weeks ago by niksilver
Blind - About Us
"Blind is an anonymous social networking platform for professionals. Work email-verified professionals can connect with coworkers and other company/industry professionals by holding meaningful conversations on a variety of different topics."
app  community  privacy  dopost 
6 weeks ago by niksilver
The Best Way to Type ¯_(ツ)_/¯ - The Atlantic
"All hail ¯\_(ツ)_/¯. In its 11 strokes, the symbol encapsulates what it’s like to be an individual on the Internet. With raised arms and a half-turned smile, it exudes the melancholia, the malaise, the acceptance, and (finally) the embrace of knowing that something’s wrong on the Internet and you can’t do anything about it."
characters  communication  emoticons  unicode  dopost 
6 weeks ago by niksilver
The Software Defined Delivery Manifesto
"We recognize that delivering useful software shapes our world. We recognize that code is the best way to specify precise action. We recognize that code is only useful when we deliver it."
manifesto  delivery  software  continuous_deployment  dopost 
6 weeks ago by niksilver
Coding the curriculum: new computer science GCSE fails to make the grade | The Independent
"Experts predicted the computer science GCSE would not work as a replacement for the ICT which was scrapped in 2015 as they are very different subjects. Among course content issues raised was the focus placed on coding and programming [... My own ongoing research interviewing pupils in year nine about the changes in the way computing and ICT are being taught, testifies to this."
schools  education  computer_science  teaching  dopost 
7 weeks ago by niksilver
Manager Energy Drain | Lara Hogan
"Ha. Sorry to break this to you, but the best gift you can give your direct reports is a messy, unscoped project with a bit of a safety net. This kind of project creates the biggest opportunity for someone to grow as a leader..."
management  leadership  dopost  advice 
8 weeks ago by niksilver
Sorry Mark Zuckerberg, Facebook isn’t a “positive force” | Ars Technica
"One defense of Facebook is that the company is just giving users what they want. And that's true—but only in the sense that casinos give heavy gamblers what they want."
facebook  criticism  mental_health  politics  analysis  dopost 
8 weeks ago by niksilver
Think BIG, build small – MrMattWright – Medium
"Running a software project is hard, but not impossible. Here are some tips to help you out in that process, and how to manage a company to get your project off the ground."
project_management  advice  web_development  dopost 
8 weeks ago by niksilver
More companies are chipping their workers like pets
"Sorry, I'm just a little cynical right now. The report explained the purpose of corporate bosses chipping their workers like a beloved Pekinese is to set restrictions on areas they can access within the companies."
security  privacy  future  dopost 
9 weeks ago by niksilver
Facebook’s latest scandal has Washington’s full attention - The Verge
"Facebook’s day was consumed with the fallout from Wednesday’s New York Times story about its slow response to Russian interference, which generated a furor greater than anything the company has seen since the Cambridge Analytica data privacy scandal."
facebook  media  public_relations  dopost 
9 weeks ago by niksilver
System error: Japan cyber security minister admits he has never used a computer | World news | The Guardian
"A Japanese minister in charge of cyber security has provoked astonishment by admitting he has never used a computer in his professional life, and appearing confused by the concept of a USB drive."
dopost  security  weird  japan  politics  failure 
9 weeks ago by niksilver
Zero-Based Budgeting – a warning - Beyond Budgeting Institute
"Despite the hype, ZBB does not at all address most of the problems associated with traditional budgeting..."
beyond_budgeting  finance  dopost 
10 weeks ago by niksilver
Blockchain-based elections would be a disaster for democracy | Ars Technica
"Online voting would be a huge threat to the integrity of our elections—and to public faith in election outcomes."
blockchain  voting  dopost 
10 weeks ago by niksilver
RealWorld - "The mother of all demo apps"
"See how the exact same clone (called Conduit) is built using any of our supported frontends and backends. Yes, you can mix and match them, because they all adhere to the same API spec 😮😎"
demo  languages  frameworks  dopost 
11 weeks ago by niksilver
Talking about risk and opportunity | Norman Marks on Governance, Risk Management, and Audit
"...the tools and techniques traditionally used to ‘manage’ potential harms (risks, in normal language) can and probably should be used to manage the potential for gain (opportunities)."
risk  risk_management  dopost 
12 weeks ago by niksilver
Return of the Obra Dinn review - The Verge
"The latest game from Papers, Please creator Lucas Pope tasks you with solving the mystery of the titular Obra Dinn, a ship that washed up on shore in 1807, five years after it was believed to be lost at sea. What happened to all 60 of its crewmembers? [...] The most important part of the experience is a magical watch that can temporarily transport you to the exact moment a person died."
game  dopost 
october 2018 by niksilver
Go: the Good, the Bad and the Ugly
"This is an additional post in the “Go is not good” series. Go does have some nice features, hence the “The Good” part in this post, but overall I find it cumbersome and painful to use when we go beyond API or network servers (which is what it was designed for) and use it for business domain logic. But even for network programming, it has a lot of gotchas both in its design and implementation that make it dangerous under an apparent simplicity."
golang  analysis  dopost 
october 2018 by niksilver
Samsung has figured out EUV, the holy grail of chipmaking
"[Samsung is] getting set to commercialize chips that have a 40 percent smaller surface area compared to the company's previous 10-nanometer tech, while reducing power consumption by 50 percent or boosting performance by 20 percent."
hardware  samsung  manufacturing  dopost  innovation 
october 2018 by niksilver
Palm is back (sort of), and it built a tiny smartphone sidekick
"A startup out of California now uses the Palm name, and it's serious about breathing new life into the brand. [...] its first smartphone — known simply as the Palm — is a minuscule device you're meant to carry around when you don't want to bring your main iPhone or Galaxy along."
palm  hardware  phone  dopost 
october 2018 by niksilver
Hackers access 50 million Facebook profiles | Revue
"The attack relied on a confluence of three separate bugs. Lorenzo Franceschi-Bicchierai and Jason Koebler at Motherboard have a good, succinct explanation of how the attack worked..."
facebook  security  hacking  dopost 
october 2018 by niksilver
Kanye West Has Literally the Worst iPhone Passcode You Could Ever Have - Motherboard
"In a clip of Kanye West meeting with President Donald Trump broadcast and then shared on social media Thursday, the superstar is seen unlocking his iPhone before getting access. The apparent passcode? Well it’s just hammering the bottom key as much as possible really: 000000."
security  kanye_west  failure  dopost 
october 2018 by niksilver
A military expert explains why social media is the new battlefield - The Verge
"LikeWar: The Weaponization of Social Media is a look at the role social media plays in modern conflict."
social_media  interview  book  facebook  twitter  war  russia  dopost 
october 2018 by niksilver
Planning fallacy - Wikipedia
"The planning fallacy, first proposed by Daniel Kahneman and Amos Tversky in 1979,[1][2] is a phenomenon in which predictions about how much time will be needed to complete a future task display an optimism bias and underestimate the time needed."
planning  cognitive_bias  psychology  dopost 
october 2018 by niksilver
A basic principle most people don’t understand about risk | Norman Marks on Governance, Risk Management, and Audit
"Almost everybody makes a fundamental error when it comes to assessing a risk [...] They show the level of risk as a point: the likelihood of a potential impact or consequence. But 99% of the time this is wrong. 99% of the time, there is a range of potential consequences, each with its own likelihood."
risk_management  security  report  dopost  uncertainty 
october 2018 by niksilver
Project Strobe: Protecting your data, improving our third-party APIs, and sunsetting consumer Google+
Security is hard. Google takes the nuclear option... "Finding 1: There are significant challenges in creating and maintaining a successful Google+ product that meets consumers’ expectations. Action 1: We are shutting down Google+ for consumers."
google_plus  security  social_network  dopost  google 
october 2018 by niksilver
String of own goals by Russian spies exposes a strange sloppiness | World news | The Guardian
Beware your data trail: "...researchers from Bellingcat and the Insider also recognised that the men were issued sequentially numbered passports by a special division..."
data  social_media  spying  russia  failure  dopost 
october 2018 by niksilver
Conspectus Risk Assessment & Management Strategies
"GRASP is technically a soft-systems methodology that uses multi-stakeholder perspectives to make it easier for any management team to determine what should be done to ensure its projects go forward successfully, its strategic planning is sustainable and its critical decisions more likely to gain widespread support. The methodology makes it easier to identify less obvious but nonetheless important opportunities, search for underlying causes of risk to the project and better define the inevitable uncertainties and assumptions present in all projects."
risk_management  book  dopost 
september 2018 by niksilver
Practitioners in a box | Norman Marks on Governance, Risk Management, and Audit
"Successful leaders are constantly challenging themselves and fixing things even if they are not broken – yet."
management  change  leadership  dopost 
september 2018 by niksilver
I am Bruce Schneier, cybersecurity expert, author, and #PublicInterestTech AMA : IAmA
"Q: Do you see any way in which the market would reward security and longevity for technology? [...] A: Yes, the market will reward it if it is forced to. Think of laws and regulation as establishing the playing field for the market to operate in. Once society demands -- through the levels of policy -- security and longevity, the market will figure out how to provide it cheaply and efficiently and effectively. Markets are good at that. What they're terrible at is societal direction."
security  society  regulation  market_forces  economics  dopost  interview 
september 2018 by niksilver
Welcome | RAML
"RESTful API Modeling Language (RAML) makes it easy to manage the whole API lifecycle from design to sharing. It's concise - you only write what you need to define - and reusable. It is machine readable API design that is actually human friendly."
apis  design  modelling  dopost  rest 
september 2018 by niksilver
Lessons from being a parent that apply to your start-up and vice versa.
"Nothing is easy, the Instagram moment is the result of many sunk hours of perspiration and preparation."
startups  advice  children  dopost 
september 2018 by niksilver
What we're buying: A potent audio sampler that fits in your pocket
"See, the KO is a pretty full featured sampler that fits in your pocket. And since I got the rubberized case too, I can actually put it in my pocket and not worry too much about it getting damaged. Now instead of scrolling through Instagram or endlessly checking email while I'm waiting at the optometrist or on the bus, I can sit and bang out a little tune."
music  musical_instrument  hardware  dopost  pocket_operator 
september 2018 by niksilver
Revenge of the PMO | Silicon Valley Product Group
"From all that I have read and heard, I would not want to work in a company using a process like this. I can’t imagine any of the strong tech product companies I know choosing to move to SAFe, and if for some reason they did, I’m pretty certain their top talent would leave."
safe  agile  product_management  dopost 
august 2018 by niksilver
Measuring quality across different teams – Compare The Market – Medium
"Agreeing on the right set of metrics for a single team is on its own very difficult, but the truth is that you can’t let it stop you. Here at CompareTheMarket, we have in place what we call the Immune System."
testing  quality  quality_assurance  measurement  dopost  metrics  case_study 
august 2018 by niksilver
I Just Hacked a State Election. I’m 17. And I’m Not Even a Very Good Hacker. - POLITICO Magazine
"It took me around 10 minutes to crash the upcoming midterm elections. Once I accessed the shockingly simple and vulnerable set of tables that make up the state election board’s database, I was able to shut down the website that would tally the votes, bringing the election to a screeching halt."
voting  hacking  elections  dopost 
august 2018 by niksilver
Being a start-up CTO (or ‘how I fired myself enough times to finally become CTO’)
"It’s one challenge to be CTO in a ‘normal’ startup, it’s quite a separate challenge to also be at the forefront of a new category. I’ll post separately about the category challenges, but first, here’s my functional CTO story..."
jobs  scalability  startups  product_management  dopost  learning 
august 2018 by niksilver
Testing Strategies in a Microservice Architecture
"Here, we plan to discuss a number of approaches for managing the additional testing complexity of multiple independently deployable components as well as how to have tests and the application remain correct despite having multiple teams each acting as guardians for different services."
microservices  testing  architecture  dopost 
august 2018 by niksilver
ReMarkable tablet review: The high price of getting that paper feeling | Ars Technica
"But the company reMarkable is trying to expand E Ink's use with the reMarkable paper tablet, a slab with a 10.3-inch E Ink display and an included stylus. Not only is it meant to be a reading device, but the reMarkable is designed to replace pretty much any papers you have to bring with you anywhere—books, documents, notes, sketches, and the like."
review  tablets  productivity  dopost  hardware 
august 2018 by niksilver
Georgia defends voting system despite 243-percent turnout in one precinct | Ars Technica
"Georgia is one of four states in the US that continues to use voting machines with no ability to provide voters a paper record so that they can verify the machine counted their vote correctly."
voting  security  failure  dopost 
august 2018 by niksilver -> The Zen of Erlang
"If you've ever looked at Erlang before, you've heard about that "Let it crash" motto. My first encounter with it had me wondering what the hell this was about. Erlang was supposed to be great for concurrency and fault tolerance, and here I was being told to let things crash..."
presentation  erlang  programming  distributed_computing  dopost 
july 2018 by niksilver
Goodbye Microservices: From 100s of problem children to 1 superstar · Segment Blog
"It seemed as if we were falling from the microservices tree, hitting every branch on the way down. Instead of enabling us to move faster, the small team found themselves mired in exploding complexity. Essential benefits of this architecture became burdens. As our velocity plummeted, our defect rate exploded."
microservices  failure  architecture  dopost 
july 2018 by niksilver
Axiologik | Turning The Tides – 8 Key Areas Of Exploration For Leadership Grappling With Struggling Programmes
"...a fair chunk of our work is helping clients understand where transformation programmes are struggling and then working closely with them to establish and execute recovery plans. Typically, the challenges we find clients facing boil down into 8 key areas and we thought it may be of use to list those out..."
transformation  failure  dopost 
july 2018 by niksilver
Why the fuss about serverless? – Hacker Noon
"If it helps, serverless is roughly where Infrastructure as a Service (e.g. cloud) was in late 2007. [...] If you currently have regrets about not moving fast enough back then, just know you’re about to make the same mistake again."
business_strategy  serverless  cloud_computing  dopost  devops 
july 2018 by niksilver
How Adobe productivity increased after an executive leaked HR plans to press - Business Insider Deutschland
"Rather than rely on the human resources team to conduct sessions or base compensation off of feedback from those sessions, the new system asked leaders throughout the company take charge of the process and compensate employees based on things like performance."
adobe  remuneration  performance  human_resources  management  dopost 
july 2018 by niksilver
New information about cyber risk is alarming | Norman Marks on Governance, Risk Management, and Audit
"Six in ten (56%) report that their organisation has suffered a ransomware attack in the last 12 months, compared to under half (48%) who said the same in 2016. Of those whose organisation has suffered a ransomware attack in the last 12 months, they have had to defend against five ransomware attacks during this period, on average."
risk_management  ransomware  dopost  security 
july 2018 by niksilver
The Shocking Secret About Static Types – JavaScript Scene – Medium
"When it comes to bug reduction, I think it’s fair to say: Static types are overrated. But when it comes to other features, static types are still cool, and may still be worth using. Bottom line: You want to reduce bugs? Use TDD. You want useful code intelligence tools? Use static types."
software  bugs  testing  test_driven_development  dopost  javascript  typescript 
july 2018 by niksilver
Why hypothetical thinking is only a pale imitation of real life | Oliver Burkeman | Life and style | The Guardian
"Hypothetical thinking, in short, can only ever be a pale imitation of real life. On balance, that’s good news: a reason to worry less about the future, and trust that, if the situation you’re fretting about occurs, you might surprise yourself by knowing precisely what to do."
decision_making  psychology  dopost 
june 2018 by niksilver
The man who was fired by a machine - BBC News
"The story of Mr Diallo's sacking by machine began when his entry pass to the Los Angeles skyscraper where his office was based failed to work, forcing him to rely on the security guard to allow him entry."
artificial_intelligence  jobs  failure  weird  dopost 
june 2018 by niksilver
The crooked timber of humanity | 1843
"The world’s first national data network was constructed in France during the 1790s. It was a mechanical telegraph system, consisting of chains of towers, each of which had a system of movable wooden arms on top."
history  crime  security  hacking  dopost  networks 
june 2018 by niksilver
Slack’s Stewart Butterfield on coping with rapid growth | Financial Times
"Trust is like “gravity”, he says, “it falls off very quickly”."
trust  slack  interview  leadership  dopost 
june 2018 by niksilver
Why automated continuous integration is a must for microservices success
"Microservice architectures put a tremendous amount of pressure on the testing infrastructure. You need to have a good CI strategy and automated testing harness to make sure that you can test all the edge cases and all the different integration points between the services."
microservices  continuous_deployment  testing  automation  dopost  advice 
june 2018 by niksilver
"...with microservices there are serious consequences for operations[...]. Consequently if you don't have certain baseline competencies, you shouldn't consider using the microservice style."
advice  micropayments  dopost 
june 2018 by niksilver
Should we “tear up the risk appetite” statement? | Norman Marks on Governance, Risk Management, and Audit
"[Lauren Gow says] A risk appetite document is a vertical silo tool. And it is being used during a period when most businesses are pushing for more horizontal, integrated ways of working."
risk_management  dopost 
may 2018 by niksilver
Elon Musk wants to crowdsource truth, but that’s not how the internet works - The Verge
"[Elon Musk's] Pravda is not just a bad idea; it’s a dangerous one for the internet, truth, and democracy. Let me explain why."
truth  crowdsourcing  propaganda  analysis  dopost 
may 2018 by niksilver
Carillion - Business, Energy and Industrial Strategy and Work and Pensions Committees - House of Commons
"Carillion’s rise and spectacular fall was a story of recklessness, hubris and greed. Its business model was a relentless dash for cash, driven by acquisitions, rising debt, expansion into new markets and exploitation of suppliers."
carrillion  report  dopost  risk_management  failure 
may 2018 by niksilver
Let’s play the blame game! Never In The Office
"Dammit, I’m the boss. I’m in charge and I’m in control! If I say we don’t have a blame culture, we don’t have one. If you don’t agree, then you’re the problem. In other words it’s your fault!"
blame  working_practices  dopost 
may 2018 by niksilver
In the lab with Xbox’s new Adaptive Controller, which may change gaming forever | Ars Technica
"When it came to designing a more accessible controller, though, members of the design team had to get into a mindset outside of the standard controller use cases they were familiar with. Thus, again and again, a mantra was repeated during the preview event: by leaving any gamers in the cold, the standard controller just wasn't good enough."
xbox  accessibility  hardware  inclusivity  dopost 
may 2018 by niksilver
The journey to an agile organization at Zalando | McKinsey & Company
"We evolved a simple prioritization model to focus on the customer, on company priorities, and on local priorities; this was an incredible unlocking mechanism, allowing people to make decisions without needing to align. Simultaneously through that, we managed to significantly reduce work in progress."
agile  case_study  clothing  dopost 
may 2018 by niksilver
Digging deep for organizational innovation | McKinsey & Company
"Hilcorp began embracing agile practices long before they were buzzwords, has put in place an innovative compensation system emphasizing fairness and shared rewards, and is comfortable that only half of the goals emerging from its planning process will be met."
agile  beyond_budgeting  oil_industry  dopost  case_study 
may 2018 by niksilver
a16z Podcast: Feedback Loops — Company Culture, Change, and DevOps – Andreessen Horowitz
"But what is DevOps, really? And beyond the definitions and history, where does DevOps fit into the broader history and landscape of other tech movements (such as lean manufacturing, agile development, lean startups, microservices)? Finally, what kinds of companies are truly receptive to change, beyond so-called organizational “maturity” scores? And for pete’s sake, can we figure out how to measure software productivity already?? All this and more in this episode!"
devops  productivity  podcast  interview  dopost 
may 2018 by niksilver
Babe Ruth and Feature Lists – GV Library
"I asked the group to pretend they each had one hundred dollars of Google’s money to spend. How would they stack formatting bugs against these other improvements? [...] One woman said: “I spend one hundred dollars on formatting, then I take another hundred of my own money out of my own damn wallet and spend that on fixing formatting.”"
features  product_development  product_management  google_docs  dopost  prioritisation 
april 2018 by niksilver
Ray Ozzie’s plan for unlocking encrypted phones gets a chilly reception | Ars Technica
"Almost as soon as the Wired article was published, security experts and privacy advocates took to social media to criticize Clear. Little of their critiques was new."
cryptography  patent  mobiles  crime  dopost 
april 2018 by niksilver
PCI-DSS and continuous deployment at Etsy - Continuous Delivery
"At DevOpsDays Mountain View I was lucky enough to get some time with Michael Rembetsy, Director of Operations Engineering at Etsy, which manages to be PCI-DSS compliant while practicing continuous deployment. In this short interview, he describes how they do it."
pci_compliance  compliance  devops  continuous_deployment  dopost 
april 2018 by niksilver
Exclusive: Chat is Google’s next big fix for Android’s messaging mess - The Verge
"Given how fractious the history has been here, I’m sort of impressed that Google got everybody to call this feature “Chat” instead of “AT&T super premium advanced messaging plus” or whatever. As of this writing, 55 carriers, 11 OEMs, and two operating system providers have all pledged to either adopt or switch over to the system."
google  messaging  telecoms  android  chat  dopost 
april 2018 by niksilver
"An Immutable Server is [...] a server that once deployed, is never modified, merely replaced with a new updated instance.2
devops  automation  dopost 
april 2018 by niksilver
High performing teams know more about trust
"Delivering something on-time is key to building trust. But customers can distrust people who want to limit scope in order to achieve early deliverables. Previous disappointments (they never got the functionality they wanted) mean they assume the first release will be the only one. So they include everything in a gold plated wish-list through lack of trust."
trust  delivery  teams  dopost 
april 2018 by niksilver
Causal Capital: Self-Healing Risk Solutions
"Perhaps one of the learning takeaways we should acknowledge with Self-Healing Risk Solutions is that the concept reverses the function of reliability to scale, in that the larger and more complex the scale, the more effective, efficient and reliable you become."
risk_management  power_distribution  scalability  self_healing_systems  dopost 
april 2018 by niksilver
Cyber security and information risk guidance for Audit Committees - National Audit Office (NAO)
"Audit committees should be scrutinising cyber security arrangements. To aid them, this guidance complements government advice by setting out high-level questions and issues for audit committees to consider."
auditing  risk_management  cyber_security  security  dopost 
march 2018 by niksilver
Four ways to keep the daily scrum from being about status |
"The heart of the daily scrum is to use it as a micro planning and coordination session for the next 24 hours, not so everyone can share their status. Status can be gleaned from a simple task board, a burndown, a burnup, or other information radiators."
scrum  advice  dopost 
march 2018 by niksilver
Risk Management – The 3 Lines of Defense for Good Risk Management
"Today, a new governance model is gaining popularity. The “three lines of defense” (3LoD) model mobilizes three separate groups—business managers, central risk and compliance management teams, and internal auditors—to work together at different stages to provide increased protection against an ever-widening array of risks."
risk_management  management  auditing  dopost 
march 2018 by niksilver
The limits of our language… – Risk Reflections
"And after more than 10 years in audit, risk management and compliance, I think it is the risk functions who have to adapt their language and thinking more to business and management. It is not (primarily) management who needs to be educated more about (downside) risks and formal, heuristic risk “management tools”, periodic review of risk registers and dots on heat maps."
risk_management  language  dopost 
march 2018 by niksilver
