We did it based on percent of projects funded for purely business functions vs IT
However I found some items subjective. Is the upgrade to Exchange Cloud an IT project or for the business? An SAP upgrade for version support and IT project? SAP upgrade for new business functionality definitely a Business Project. There can be a lot of subjective decisions that move the percentage around…..
As part of our NYSE IPO prep, we’re debating how to communicate our system hardening efforts in regulatory disclosures (e.g., SEC Form 20-F, SFC).
Would you recommend sharing % compliance (e.g., “85% CIS Tier 2”) or sticking to qualitative descriptions of how we identify and mitigate risks? Also, do SFC/ISO 27001 expectations require full ISMS integration, or is a % model acceptable?
We did it based on percent of projects funded for purely business functions vs IT
However I found some items subjective. Is the upgrade to Exchange Cloud an IT project or for the business? An SAP upgrade for version support and IT project? SAP upgrade for new business functionality definitely a Business Project. There can be a lot of subjective decisions that move the percentage around…..