Swiss regulation, governance and GRC work
The second line of defence is where risk and compliance sit: between the business that owns the risk and the audit that checks it. This is written from there. What Swiss information security regulation actually requires, and what the work itself is actually like.