IT Governance, Risk and Compliance (GRC) : A Strategic Priority. Joerg Asma



Similar documents
Governance, Risk, and Compliance (GRC) White Paper

Welcome to Modulo Risk Manager Next Generation. Solutions for GRC

How To Improve Your Business

Maintaining PCI-DSS compliance. Daniele Bertolotti Antonio Ricci

Top Ten Keys to Gaining Enterprise Configuration Visibility TM WHITEPAPER

Metrics that Matter Security Risk Analytics

Security & IT Governance: Strategies to Building a Sustainable Model for Your Organization

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes.

Feature. Log Management: A Pragmatic Approach to PCI DSS

igrc: Intelligent Governance, Risk, and Compliance White Paper

IT Security & Compliance Risk Assessment Capabilities

QRadar SIEM 6.3 Datasheet

White Paper Achieving PCI Data Security Standard Compliance through Security Information Management. White Paper / PCI

14 October 2015 ISACA Curaçao Conference By: Paul Helmich

Governance, Risk & Compliance for Public Sector

The Value of Vulnerability Management*

Hans Bos Microsoft Nederland.

XBRL & GRC Future opportunities?

Achieving Business Imperatives through IT Governance and Risk

How To Ensure Financial Compliance

White Paper Achieving GLBA Compliance through Security Information Management. White Paper / GLBA

Vendor Risk Management Financial Organizations

Defending the Database Techniques and best practices

Symantec Security Compliance Solution Symantec s automated approach to IT security compliance helps organizations minimize threats, improve security,

Enterprise Risk Management in Compliance 360

The Convergence of IT Security and Compliance with a Software as a Service (SaaS) approach

HP and netforensics Security Information Management solutions. Business blueprint

The Age of Audit: The Crucial Role of the 4 th A of Identity and Access Management in Provisioning and Compliance

Total Protection for Compliance: Unified IT Policy Auditing

Security Controls What Works. Southside Virginia Community College: Security Awareness

Practical IT Governance - Using MKS's Enterprise Software Change Management Solution for Greater Auditability and Control

1/8/2012. Gordon Shevlin, Allgress, Founder, CEO Kyle Starkey, CISO, Early Warning Services. Effectively Communicating IT Risk to Senior Management

An Overview of Information Security Frameworks. Presented to TIF September 25, 2013

GRC Program Best Practices & Lessons Learned

IT Risk Management Life Cycle and enabling it with GRC Technology

Moving beyond Virtualization as you make your Cloud journey. David Angradi

Making Compliance Work for You

Vulnerability. Management

Executive's Guide to

REALIZING MAXIMUM BENEFITS FROM GOVERNANCE, RISKS AND COMPLIANCE (GRC) TOOLS

PROTEUS Enterprise - IT Governance, Risk and Compliance Management Solution

STREAM Cyber Security

Clavister InSight TM. Protecting Values

8 Key Requirements of an IT Governance, Risk and Compliance Solution

Security Information Lifecycle

Sarbanes-Oxley Act. Solution Brief. Sarbanes-Oxley Act. Publication Date: March 17, EventTracker 8815 Centre Park Drive, Columbia MD 21045

Weighing in on the Benefits of a SAS 70 Audit for Third Party Data Centers

Governance, Risk and Compliance Update & Hot Topics Pittsburgh Chapter IIA December 3, 2012

Sarbanes-Oxley: Beyond. Using compliance requirements to boost business performance. An RIS White Paper Sponsored by:

Governance, Risk, Compliance and Beyond: The Emergence of Strategic IT Risk Management

Vulnerability Risk Management 2.0. Best Practices for Managing Risk in the New Digital War

Sarbanes-Oxley Compliance for Cloud Applications

Module 6 Essentials of Enterprise Architecture Tools

Delivering IT Security and Compliance as a Service

How To Manage It Asset Management On Peoplesoft.Com

The RSA Solution for. infrastructure security and compliance. A GRC foundation for VMware. Solution Brief

Understanding Vulnerability Management Life Cycle Functions

IT Security & Compliance. On Time. On Budget. On Demand.

The Firewall Audit Checklist Six Best Practices for Simplifying Firewall Compliance and Risk Mitigation

Self-Service SOX Auditing With S3 Control

LogInspect 5 Product Features Robust. Dynamic. Unparalleled.

Trusted Geolocation in The Cloud Technical Demonstration

Third Party Risk Management 12 April 2012

Data Governance. Unlocking Value and Controlling Risk. Data Governance.

Enterprise Security Solutions

Paisley Enterprise GRC Audit Profile. Linda Bergs

LogPoint 5.1 Product Features Robust. Dynamic. Unparalleled.

Whitepaper: 7 Steps to Developing a Cloud Security Plan

Symantec Control Compliance Suite. Overview

White Paper. An Overview of the Kalido Data Governance Director Operationalizing Data Governance Programs Through Data Policy Management

MarketScope for IT Governance, Risk and Compliance Management, 2008

Adopt a unified, holistic approach to a broad range of data security challenges with IBM Data Security Services.

VENDOR MANAGEMENT. General Overview

An Introduction to SIEM & RSA envision (Security Information and Event Management) January, 2011

Program Overview and 2015 Outlook

Enforcive / Enterprise Security

RSA Archer Training. Governance, Risk and Compliance. Managing enterprise-wide governance, risk and compliance through training and education

EMC CONSULTING SECURITY STANDARDS AND COMPLIANCE SERVICES

IT Governance: framework and case study. 22 September 2010

S24 - Governance, Risk, and Compliance (GRC) Automation Siamak Razmazma

IBM 2010 校 园 蓝 色 加 油 站 之. 商 业 流 程 分 析 与 优 化 - Business Process Management and Optimization. Please input BU name. Hua Cheng chenghua@cn.ibm.

Actionable Security Intelligence: Preparing for the Next Threat with a Proactive Strategy

Department of Technology Services

Agenda 3/7/ ERM Symposium March 14 16, Continuous Controls Monitoring. I. Changes In Corporate Environment

How To Manage A Privileged Account Management

Log Management Solution for IT Big Data

Moving Forward with IT Governance and COBIT

Transcription:

IT Governance, Risk and Compliance (GRC) : A Strategic Priority Joerg Asma

Agenda Introductions An Overview of IT Governance Risk & Compliance (IT-GRC) The Value Proposition Implementing an IT-GRC Program Market Landscape Open Discussion Closing Remarks All rights reserved. Printed in the U.S.A. 29548SFO 1

Introductions All rights reserved. Printed in the U.S.A. 29548SFO 2

An Overview of IT-Governance Risk & Compliance All rights reserved. Printed in the U.S.A. 29548SFO 3

Background to Governance, Risk and Compliance There have been many forms of GRC over the years: corporate governance, IT governance, financial risk, strategic risk, operational risk, IT risk, corporate compliance, Sarbanes-Oxley (SOX) compliance, employment/labor compliance, and privacy compliance. The introduction of Sarbanes Oxley Sec 404 (SOX 404) has driven an enterprise approach to establish more effective Corporate Governance. Insurance companies over the last several years have influenced the enterprise risk management (ERM) initiative which was also further supported by SOX 404. There has been an increase in the number of GRC related software solutions coming to the market that is converging a number of initiatives. All rights reserved. Printed in the U.S.A. 29548SFO 4

An Overview of IT-GRC Benefits Metrics and Reporting Best Practices Defines policies, standards and processes based on industry best practices and needs of your organization. Business Alignment IT is enabling business to meet their goals. Communicate track record of achievements to business users and ensure continuous improvement. Value Capture Successful IT GRC Program Regulatory Landscape Takes into account International, Federal, State, Local, etc. mandates that your organization must comply with. Provide a source of cost savings through realized synergies, such as consolidation and rationalization of applications, functions and assets. Resource Management Effective resource allocation and appropriate skill set alignment. Risk Management Defines Key Risk Indicators based on your unique environment, risk tolerance and key assets. Real time risk evaluation of non-compliance. Measurement of Controls Defines a common criteria for measuring controls across various groups within your organization to ensure uniform measurement during assessments. All rights reserved. Printed in the U.S.A. 29548SFO 5

The Value Proposition All rights reserved. Printed in the U.S.A. 29548SFO 6

Transparent Value Proposition Sustainable IT-GRC Efficient Consistent SUSTAINABLE Risk and Compliance Activities will not be going away. Compliance Officers need on-going visibility into the changing landscape. CONSISTENT in an era of increased accountability, firms cannot afford to NOT consistently understand, approach and measure risks and controls EFFICIENT Automation of risk and compliance processes resulting in reduction of Security and Compliance Management Costs TRANSPARENT need transparency into business operations and strategies to help navigate around threats and seize opportunities. Enterprise-Wide GRC Solutions assist in sustaining GRC Programs All rights reserved. Printed in the U.S.A. 29548SFO 7

Business Benefits of Compliance Market Trends: Top Business Benefits of Compliance Improved Operational Visibility 10% Supply Globilization Efforts 11% Other 1% Streamlining Business Processes 36% Enhanced Information Security 14% Improved Quality Survey Responses & Data Provided 28% Source of Survey - AMR Research All rights reserved. Printed in the U.S.A. 29548SFO 8

Implementing an IT-GRC Program All rights reserved. Printed in the U.S.A. 29548SFO 9

Architectural Overview Unified IT Risk & Compliance Management IT Risk Calculate Risk Management Prioritize Investments Compliance & Audit Reports E-Surveys Manual Surveys E-Data Gathering Connectors Scanners, SIM/SEM, Directory, CMDB IT Security Optimize Controls IT Operations Prioritize Mitigation Facilities Laptops Policy Management Control Testing & Gap Analysis Risk Analysis & Correlation Core Server Functions Policies & Mandates Frameworks Controls SOX PCI Custom GLBA FISMA ISO CobiT Custom Control Set Common Control Framework Processes Servers Databases Asset Info Reconciled Asset Information People Applications Customer Assets & Processes All rights reserved. Printed in the U.S.A. 29548SFO 10

Common Control Framework Question: What IT Governance frameworks/solutions do you use or are you considering using? Source: IT Governance Institute - Global Status Report 2008 All rights reserved. Printed in the U.S.A. 29548SFO 11

Approach to Developing an IT-GRC Program SOX GLBA PCI FISMA Custom ISO CobiT Custom Control Set Scope Assets Select Run Decide Act Intelligent Profiling People Processes IT Infrastructure Applications Buildings Partners Vendors Identify Threats & Vulnerabilities Common Control Framework Regulations and Mandates Corporate Policy Best Practices Standard Frameworks Controls and Subcontrols Key Risk Indicators Automated Processes Human Attestation Surveys Technical Control Checks Security Tool Integration Risk & Compliance Scoring Risk based Prioritization Risk Rationalized Tickets ROI Analysis vs. ALE / SLE Ticket Closure Workflow Consolidated View Risk & Compliance Process Management Role-Based Dashboards Trending Custom Reports Report Templates: All rights reserved. Printed in the U.S.A. 29548SFO 12

Market Landscape All rights reserved. Printed in the U.S.A. 29548SFO 13

Overview of the Market Moving from Concept to Practice Initially more divisional/group specific Limited enterprise-wide adoption GRC Related Spend in 2007 - $30B (according to AMR Research) SOX still accounts for 20% of all overall GRC Spend Adoption Rate in embryonic stage Market for vendors offering solutions growing The software is NOT the strategy; without a solid governance structure as a foundation no solution will bring about compliance. Existing risk, compliance, organizational structure and processes MUST be in place before implementing any solution. All rights reserved. Printed in the U.S.A. 29548SFO 14

Overview of the Market, continued Strong Positive Positive Promising Caution Source: Gartner MarketScope for IT Governance, Risk and Compliance Management 2008 2/11/08 All rights reserved. Printed in the U.S.A. 29548SFO 15

Open Discussion All rights reserved. Printed in the U.S.A. 29548SFO 16

Open Discussion Four Key Questions 1. Why should my organization implement IT-GRC? 2. What are the pre-requisites my organization needs in place to have the necessary foundation to make IT-GRC successful? 3. Who should own an IT-GRC Program? 4. What are the investment considerations to implement an IT-GRC Solution? All rights reserved. Printed in the U.S.A. 29548SFO 17

Valuable Reference Websites IT Governance Institute www.itgi.org The Institute of Internal Auditors (IIA) www.theiia.org European Corporate Governance Institute www.ecgi.org All rights reserved. Printed in the U.S.A. 29548SFO 18

Your contact ABCD Jörg Asma Partner Barbarossaplatz 1a 50674 Köln Germany Office: ++49 221 2073-6233 Mobile: ++49 172 762 0928 E-mail: jasma@kpmg.com All rights reserved. Printed in the U.S.A. 29548SFO 19