Surviving SOX with Scrum. Integrating Scrum in IT Governance at Allianz



Similar documents
AN OVERVIEW OF INFORMATION SECURITY STANDARDS

How can I be agile and still satisfy the auditors?

Water-Scrum-Fall Agile Reality for Large Organisations. By Manav Mehan Principal Agile consultant

When is Agile the Best Project Management Method? Lana Tylka

Enhancing IT Governance, Risk and Compliance Management (IT GRC)

Contracts Management Software as a Tool for SOX Compliance

Certified Scrum Master Workshop

Agile Metrics. It s Not All That Complicated

White Paper. Ensuring Network Compliance with NetMRI. An Opportunity to Optimize the Network. Netcordia

The Advantages of ISO 9001 Certification

Certified Software Quality Assurance Professional VS-1085

Certified ScrumMaster Workshop

Mapping COBIT 5 with IT Governance, Risk and Compliance at Ecopetrol S.A. By Alberto León Lozano, CISA, CGEIT, CIA, CRMA

COSO 2013 Internal Control Framework

MM Agile: SCRUM + Automotive SPICE. Electronics Infotainment & Telematics

The Upside of Risk: Enterprise Risk Management and Public Real Estate Companies

Sustainable Software Development in Agile and CMMI: Apply Lessons Learned today

How To Get A Tech Startup To Comply With Regulations

Agile SW Siemens

Building Software in an Agile Manner

Agile Project Forecasting Techniques. "Who Says You Can't Plan Agile Projects?" Matt Davis, PMP, MCITP October 21, 2013

A FRAMEWORK FOR INTEGRATING SARBANES-OXLEY COMPLIANCE INTO THE SOFTWARE DEVELOPMENT PROCESS

Agile Training and Certification Options. David Hicks

Sarbanes-Oxley Compliance: Section 404-Past, Present, and Future

How To Get A Whistleblower Pass On A Corporation

Models of Software Development

There are 3 main activities during each Scrum sprint: A planning meeting where: the Product Owner prioritizes user stories in the product backlog

Agile Team Roles Product Owner & ScrumMaster. Brian Adkins Rick Smith

What Should IS Majors Know About Regulatory Compliance?

UC4 Software: HELPING IT ACHEIVE SARBANES-OXLEY COMPLIANCE

Agile SW Siemens

How to optimize offshore software development with Agile methodologies

Scrum In 10 Slides. Inspect & Adapt

"IT Governance and Compliance in an Agile World"

Introduction Auditing Internal Controls in an IT Environment SOx and the COSO Internal Controls Framework Roles and Responsibilities of IT Auditors

Information overload: How to make data analytics work for the internal audit function

Executive's Guide to

Introduction to Agile Software Development Process. Software Development Life Cycles

How SUSE Manager Can Help You Achieve Regulatory Compliance

Using COSO Small Business Guidance for Assessing Internal Financial Controls

6 Oct Agile: Creating a Culture of Quality, Value and Feedback. Agile. Creating a Culture of Quality, Value and Feedback.

Making Compliance Work for You

Agile Development Overview

Course Title: Managing the Agile Product Development Life Cycle

Data Archiving for Littelfuse Paved the Way for One Day SAP ERP ECC 6.0 Upgrade

Internal Control over Financial Reporting Guidance for Smaller Public Companies

Scrum Guidelines. v W W W. S C R U M D E S K. C O M

Trends in Information Technology (IT) Auditing

IT Governance Dr. Michael Shaw Term Project

PMP vs. Scrum Master

Course Title: Planning and Managing Agile Projects

Practical and ethical considerations on the use of cloud computing in accounting

Leveraging Sarbanes-Oxley (SOX) to Build Better Practices

Practical IT Governance - Using MKS's Enterprise Software Change Management Solution for Greater Auditability and Control

GLOBAL STANDARD FOR INFORMATION MANAGEMENT

CHAPTER 3 : AGILE METHODOLOGIES. 3.3 Various Agile Software development methodologies. 3.4 Advantage and Disadvantage of Agile Methodology

Certified ScrumMaster (CSM) Content Outline and Learning Objectives January 2012

Sometimes: 16 % Often: 13 % Always: 7 %

Curriculum Vitae: Hans Jonker

The 2015 State of Scrum Report. How the world is successfully applying the most popular Agile approach to projects

Call for Tender for Application Development and Maintenance Services

2015 Defense Health Information Technology Symposium Implementation of Agile SCRUM Software Development Methodology

Certified ScrumMaster (CSM) Content Outline and Learning Objectives January 2012

Incorporate CMMI with Corporate Governance Using Enterprise Software Change Management Solutions

Self-Service SOX Auditing With S3 Control

Governance, Risk, and Compliance (GRC) White Paper

Sarbanes-Oxley Control Transformation Through Automation

ITIL Foundation Certification Course

Preparation Guide. EXIN Agile Scrum Foundation

Using Story Points to Estimate Software Development Projects in the Commercial Phase

COBIT 5 Implementation Certification Course

Agile Practitioner: PMI-ACP and ScrumMaster Aligned

Requirements Management Practice Description

Best Practices in Identity and Access Management (I&AM) for Regulatory Compliance. RSA Security and Accenture February 26, :00 AM

0. INTRODUCTION 1. SCRUM OVERVIEW

The Agile Manifesto is based on 12 principles:

Achieving Governance, Risk and Compliance Requirements with HISP Certification Course

IT Governance Implementation Workshop

Using QUalysgUard to Meet sox CoMplianCe & it Control objectives

Leveraging Agile and CMMI for better Business Benefits Presented at HYDSPIN Mid-year Conference Jun-2014

Effektiver Tool-Einsatz

IT Governance, Risk and Compliance (GRC) : A Strategic Priority. Joerg Asma

ScrumMaster Certification Workshop: Preparatory Reading

Transcription:

Surviving SOX with Scrum Integrating Scrum in IT Governance at Allianz 1

Who are we? Simon Roberts MBA and Dr. Christoph Mathis Independent Scrum coaches and trainers; Scrum since 2002, XP since late 1990s Both have a strong software engineering background Track record of successful Scrum projects for small, medium and large enterprises in Germany and the UK Together we provide the thought leadership for the Allianz Germany Agile Methods Competence Center http://scrumcenter.org 2

Enterprise Scrum @ Allianz A Holistic Approach We have been engaged in an enterprise Scrum transition at Allianz Germany for the last 2 years For us, enterprise Scrum includes at least: How to transition to Scrum and sustain its use through change management How to integrate with IT governance How to help teams, Product Owners and Scrum Masters to realize their potential Today we want to talk mainly about integrating Scrum with IT governance but first lets take a look at our enterprise Scrum approach in a little more detail... 3

4

CMMI SOX The Enterprise Scrum Governance Landscape COBIT ITIL ISO 9001 5

What is SOX? Sarbanes-Oxley Act Technically a U.S. law from 2002 which is intended to ensure the reliability of financial statements of public companies in the wake of the scandals around Enron, WorldCom and others New: the leaders of an organization are personally responsible for compliance and for the correctness of the financial statement SOX 404 (the part most important for IT): Public companies must introduce strict internal controls They must document these controls and guarantee that they are followed 6

The History of Compliance in the USA 1933: SEC (Securities and Exchange Commission) and GAAP (Generally Accepted Accounting Principles) introduced after the depression of 1929 1985: Treadway Commission after a series of financial scandals, the Treadway Commission (named after James Treadway, former chairman of the SEC) brought together leading accounting organizations: FEI (Financial Executives International) AAA (American Accounting Association) AIPCA (American Institute of Certified Public Accountants) IIA (Institute of Internal Auditors) IMA (Institute of Management Accountants) this became known as COSO (Committee of Sponsoring Organizations of the Treadway Commission) 7

Why might SOX be relevant for your Organization? If you have a US listing If you need access to the capital markets SOX is becoming a de facto standard outside the US Analysts increasingly include IT governance in their rating of an organization, which can have an effect on stock price The EU Commission is going in a similar direction with their focus on the COBIT framework The financial crisis will likely result in stricter controls 8

Cost of SOX In the USA companies spend 6 billion US $ annually for SOX-compliance activities 9

Profitable, agile Enterprise Potential conflicts with SOX 10

comply and die: static business model Profitable, agile Enterprise Potential conflicts with SOX 10

comply and die: static business model non-compliance penalties Profitable, agile Enterprise Potential conflicts with SOX 10

comply and die: static business model non-compliance penalties inefficient Profitable, processesagile Enterprise Potential conflicts with SOX 10

comply and die: static business model non-compliance penalties inefficient Profitable, processesagile high Enterprise compliance costs Potential conflicts with SOX 10

SOX Requirements and Scrum Goal Realization Notes Defined development process Scrum as a defined process Need to standardize practices Defined release process Integrate release decision making into Sprint review Dual-key deployment Prevention of manipulation Performance management Access rights for key data and additional user stories for some applications Resource allocation at the technical level Need to guarantee that financial information is produced in a timely manner 11

SOX Requirements and Scrum Goal Realization Notes Testing Automated testing, test definitions and reports securely archived Possible to leverage continuous build and test system Documentation for Users Archiving Additional acceptance criteria for user stories or additional user stories Has an impact on the configuration management systems that we use and introduces additional requirements on applications that we can represent as user stories The documentation that SOX requires becomes part of the definition of done Need to archive balance relevant data for at least 10 years 12

Defined Development Process Daily Scrum Burn Down Chart Product Backlog Sprint Backlog Sprint Product Increment Release Planning Sprint Planning Sprint Review/ Retrospective 13

Defined Development Process Standardized Practices: User Stories Story Points Planning Poker Automated Unit Testing Automated Acceptance Testing Continuous Integration Daily Scrum Burn Down Chart Product Backlog Sprint Backlog Sprint Product Increment Release Planning Sprint Planning Sprint Review/ Retrospective 13

User Stories for SOX Relevant Projects (1) 14

User Stories for SOX Relevant Projects (1) 14

User Stories for SOX Relevant Projects (2) 15

User Stories for SOX Relevant Projects (2) 15

User Stories for SOX Relevant Projects (3) 16

User Stories for SOX Relevant Projects (3) 16

User Stories for SOX Relevant Projects (4) 17

User Stories for SOX Relevant Projects (4) 17

User Stories for SOX Relevant Projects (5) 18

User Stories for SOX Relevant Projects (5) 18

Continuous Integration with Automated Acceptance Testing Continuum, Maven and Selenium 19

Summary You might need to be SOX compliant even if your company does not have a US listing SOX and Scrum can coexist Some of the agile practices such as automated testing and user stories can help to make SOX compliance less painful For larger organizations, strict IT governance is unavoidable. Agile methods can help 20

just one more thing 21

The key challenge is Compliance whilst Activating Innovation 22