Blog library

A collection of Protiviti blogs. 
ISSA 5000 | What this means for you

Blogs

March 19, 2025

IAASB’s ISSA 5000 Sets the Global Standard for Sustainability Assurance

The International Standard on Sustainability Assurance, or ISSA 5000, developed by the International Auditing and Assurance Standards Board (IAASB) in late 2024, is widely expected to be the global benchmark for sustainability assurance, influencing the future of sustainability audits. As regulatory mandates for sustainability reporting increase, organisations seeking...
Last Thursday, the Committee of Sponsoring Organisations of the Treadway Commission (COSO) released interpretive guidance on how to effectively apply the 2013 Internal Control — Integrated Framework (ICIF) — which is currently applied to financial reporting — to sustainability reporting. The guidance results from a project approved by the COSO board a year ago with…
Senior leaders focused on cybersecurity recognise there is considerable guidance, best practices, frameworks, regulations and varied opinions on how programmes should design defensive capabilities. In addition, depending on the day, the various pressures in the organisation’s macro-environment may be greater or lesser and invite different priorities for time, team and budget. Despite these various…
Some of the toughest conversations CIOs will have within their organisations are likely to be about the benefits of adopting every emerging technology that’s caught business leaders’ attention versus the potential investments to be made in transforming legacy systems. As companies across all industries look to accelerate efforts to achieve their business transformation goals, a considerable amount of focus – and…
Could any security organisation benefit from greater innovation? Or from responding more effectively to diverse internal customers? How about benefitting by retaining the talent its leaders have so carefully nurtured, by accessing more diverse capabilities, or by improving problem-solving capabilities within the team?
Learning difficulties at school left Victoria Sprott feeling confused about her abilities, but a sales job in Australia, helped launch a career in recruitment. Rhianne Williams from Protiviti’s iGROWW network hears a story about finding a calling, embracing the fear of change, and nurturing a healthy family life alongside a successful career.
Background On 16 February 2023, the Attorney-General’s Department released its Privacy Act Review Report (the Report) following a two-year review of the Privacy Act 1988 (Cth) (the Act). The Report contains 116 recommended amendments to the existing Act to strengthen the protection of personal information and the control individuals have over their information. If accepted and adopted, the recommendations will…
This blog post was authored by Chris Hanson - Director, Danielle Baumann - Senior Manager, Enterprise Application Solutions on The Technology Insights Blog. As more and more retailers build strategies to address supply chain challenges, customer experience and ease of doing business, many have come to the realisation that there may not be a single best solution for their various needs. This, coupled with…
I am often asked, with all the investments in data management and infrastructure over the last 50 years, why are we still not great with governing data? To put it simply and directly – it’s hard! Data governance programmes are easy to envision conceptually, difficult to implement, and without proper care, impossible to sustain. Often data governance investments have a long ‘time to value’ ROI, making…
This blog post was authored by Sheeraz Iqbal, Director, Enterprise Application Solutions on The Sap Insights Blog. Manufacturers often have heterogenous systems to accommodate different processes in a manufacturing cycle. From procurement and inventory management to calculating overhead, these systems carry critical financial data and information that are necessary to determine profitability, establish…
DevSecOps is an organisational software engineering culture and practice that aims at unifying software development (Dev), application security (Sec), and operations (Ops). The main characteristic of DevSecOps is to monitor and apply security at all phases of the software lifecycle: Planning, development, integration, delivery, deployment and production. Looking at DevSecOps through an IT professional’s lens, the…
Loading...