Asset Management in the Cloud How to identify and manage Cloud based assets and services. September 19, 2014



Similar documents
Information Life Cycle Management (ILM)

Auto insurance telematics The three-minute guide

Extending Security Analytics to support Operational Efficiency. John A. Greco Deloitte & Touche LLP Cyber Risk Services

Does Providing Tax Services Impair Auditor Independence? Evidence from Assessing Tax Accrual Quality

ERP Administrative Challenges Brian Jensen

Service Organization Control (SOC) Reports

Designing a Data Solution with Microsoft SQL Server 2014

Risk Considerations for Internal Audit

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard

Implementing Microsoft Azure Infrastructure Solutions

Ensuring Contract Compliance through integration of Ariba Contracts and SAP ECC Michael Chavez and Sean Rhoades, Deloitte Consulting LLP

Mary E. Galligan Director Deloitte & Touche LLP August 4, 2015

Revenue Cycle in Post- Acute Care Deloitte & Touche LLP Victor Shutack, Senior Manager June 2015

IPT 2015 Sales & Use Tax Symposium Indian Wells, CA. Tax Accrual Data Analytics Dashboards to Minimize Risk

Three Ways Enterprises are Protecting SQL Server in the Cloud

Mobility Trends. Deloitte Tax Management Consulting. December Todd Dannenfelser. Niketu Bhatt. Deloitte Tax LLP

Putting it all together Using technology to drive tax business processes

Analytics for Shared Services The three-minute guide

Medicaid Enterprise Data Governance Approach. MESConference August 21, 2012 Rashmi Menon, Deloitte Consulting LLP

People change management framework for High maturity Stakeholder management Training

Autodesk PLM 360 Security Whitepaper

Big data The three-minute guide

Pricing Analytics The three-minute guide

Software Asset Management High Risk, High Reward

Cloud & Datacenter Monitoring with System Center Operations Manager

Who is my SAP HANA DBA? What can I expect from her/him? HANA DBA Role & Responsibility. Rajesh Gupta, Deloitte. Consulting September 24, 2015

The Changing IT Risk Landscape Understanding and managing existing and emerging risks

Configuring and Deploying a Private Cloud

MS 20465C: Designing a Data Solution with Microsoft SQL Server

CA ARCserve Replication and High Availability Deployment Options for Hyper-V

BladeLogic Software-as-a- Service (SaaS) Solution. Help reduce operating cost, improve security compliance, strengthen cybersecurity posture

Business Intelligence Competency Partners

Third Party Security: Are your vendors compromising the security of your Agency?

Data Center Consolidation in the Federal Government Looking beyond the technology

1. Understanding Big Data

Deployment Options for Microsoft Hyper-V Server

Evergreen Solutions Lowering the cost of EHR ownership

Microsoft Exchange Load Balancing. Unique Applied Patent Technology By XRoads Networks

Legal billing and predictive coding A fresh way to assess your legal spend

This three-day instructor-led course provides existing SQL Server database professionals with the knowledge

Configuring and Deploying a Private Cloud 20247C; 5 days

Building disaster-recovery solution using Azure Site Recovery (ASR) for Hyper-V (Part 1)

Frequently Asked Questions

This course is intended for database professionals who need who plan, implement, and manage database solutions. Primary responsibilities include:

Documentation, coding, charging, and billing for medications Identifying risks and internal audit focus areas

NCOE whitepaper Master Data Deployment and Management in a Global ERP Implementation

Infrastructure solution Options for

Brand Ambassadors From pre-foundation to advanced recruitment process through Social Media

Course 20465: Designing a Data Solution with Microsoft SQL Server

Designing a Data Solution with Microsoft SQL Server

Identity & Access Management The Cloud Perspective. Andrea Themistou 08 October 2015

Realizing the Benefits of Hybrid Cloud. Anand MS Cloud Solutions Architect Microsoft Asia Pacific

Cloud Computing What Auditors need to know

Configuring and Deploying a Private Cloud. Day(s): 5. Overview

ISO27032 Guidelines for Cyber Security

Designing a Data Solution with Microsoft SQL Server

Designing a Data Solution with Microsoft SQL Server 2014

Sustainability Analytics The three-minute guide

CLOUD SERVICES FOR EMS

Unlock your digital marketing potential

U.S. CFO Program The Four Faces of the CFO Deloitte Touche Tohmatsu

Course 20465C: Designing a Data Solution with Microsoft SQL Server

Deloitte 2010 lease administration benchmarking survey

Datacenter Management and Virtualization. Microsoft Corporation

Course Syllabus. Maintaining a Microsoft SQL Server 2005 Database. At Course Completion

Robotic Process Automation Overview and RPA Case Study. November 2015

Cloud Computing. Chapter 1 Introducing Cloud Computing

Course Syllabus. 2553A: Administering Microsoft SharePoint Portal Server Key Data. Audience. At Course Completion.

The Changing SAS 70 Landscape Dan Hirstein Director Rebecca Goodpasture Senior Manager Deloitte & Touche LLP January 13, 2011

Journey to Cloud 10 Questions

Interplant Costing using Oracle Sourcing Rules with Oracle Supply Chain Cost Rollup in Oracle R12. OAUG Cost Management SIG February 17, 2015

State Tax Implications of an IRS Audit. Steve Spaletto, Deloitte Tax LLP

Deloitte and IBM Smarter teaming for clients

Cloud Operations Excellence & Reliability

Deloitte and Salesforce.com Bringing cloud computing to the banking industry. Cover head Cover head insightful

Current issues and trends in the Aerospace supply chain

Using Hedge Accounting to Better Reflect Risk Mitigation Strategies. Jeff Craft Jason Weaver Deloitte & Touche LLP

20465: Designing a Data Solution with Microsoft SQL Server

Contact Centers in the Cloud: A Better Way to Source

Configuring and Deploying a Private Cloud

RSA enables rapid transformation of Identity and Access Governance processes

HL7 EHR System Functional Model and Standard (ISO/HL ), Release 2

September 9, 2013 Don Hoag Deloitte Consulting, LLP

Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks.

Transcription:

Asset Management in the Cloud How to identify and manage Cloud based assets and services September 19, 2014

Contents Overview 4 Standard asset management process 6 Asset identification 9 Asset management and planning 15 Wrap-up/questions 22 2

Overview Presentation objectives Provide a high level understanding of asset management Understand how assets are identified and managed in the cloud Identify ways that you can bring asset management to the cloud services being utilized in your organization 3

Overview What is an asset? ISO 55000 Coordinated activity of an organization to realize value from assets IT asset management (ISO 19770) For Example, Software Licensing What are assets in a cloud environment? For Example, Virtual Hard Drive (VHD), Servers, Network Devices, Data, Box Storage ISO 19770-4 (Possible future standard) Why use asset management? 4

Standard asset management process 5

Standard asset management process Foundation of asset management process Defining what assets are being managed Identifying the assets currently within the environment Implementing systems for tracking assets in place Developing policies and procedures around asset handling and management Asset Lifecycle 6

Standard asset management process Goal of asset management in the cloud Identifying the assets currently within the environment Determining who owns these assets Standardizing asset management to maintain compliance in dynamic environment Associated risk Risk of not knowing what assets are being used and how they are utilized can cost organizations in large expenses, possible outages, or environments not aligned with security policies 7

Additional considerations: What are some risks that your company has faced or that you have seen related to Asset Management? Who in your organization can help assist in the IT Asset Management process? 8

Asset identification 9

Asset identification Techniques that can be used to identify cloud based assets Network Monitoring Purchase Card/Expense Monitoring Third-party Tools Audit Evaluations/Interviews 10

Asset identification Network monitoring Some key drivers: IT Department/Networking Group What to look for: Network traffic known cloud service providers Large data uploads/downloads that align with new system acquisitions/creation Recurring network traffic that is not being managed by known batch processing systems or access specific restrictions (Server Build-out) 11

Asset identification P-Card / Expense monitoring Key drivers: Finance Department/Accounts Payable What to look for: Reoccurring expenses to known cloud service providers Expenses related to cloud management tools or new IT software For Example, Telnet software, SQL Server cloud licenses ABC Web Services Conferencing 12

Asset identification Third-party tools Key drivers: IT Department/Management How to leverage: Working with the IT department to identify the applicable tools and approaches for using a third party for identifying assets Tools: Asset Tracking Tools Cloud Service Provider vs. External Provider Asset Management Tools 13

Asset identification Audit evaluations / Interviews Key drivers: Internal Audit/External Auditors How to leverage: Have Internal Audit perform a directed assessment of the use of cloud services Provide Internal/External auditors questions to ask directed at the identification of cloud assets Simple vs Complex Questions 14

Asset identification Audience discussion Additional considerations: Outside of the four methods presented: Network Monitoring, Purchase Card/ Expense Monitoring, Third-party Tools, and Audit Evaluations/Interviews, what other methods could be used to identify assets? Who should be performing or managing an Asset Identification Project? 15

Asset management & planning 16

Asset management & planning - Identifying and tracking assets Many Cloud Service Providers offer built-in tools for tracking assets deployed in their respective environments: AWS Management Console Microsoft Azure Management Portal Third-Party Tools (Bolt-ons) can also be used This presentation should not be construed as an endorsement on the part of Deloitte for AWS Management Console, Microsoft Azure Management Portal, or other Third- Party Tools 17

Asset management & planning - Identifying and tracking assets AWS Management Console: 18

Asset management & planning - Identifying and tracking assets AWS Billing Console: 19

Asset management & planning - Identifying and tracking assets Microsoft Azure Portal: 20

Asset management & planning Policies and taxonomy Policy development Current policies should be modified New policies and procedures developed Tagging/Naming convention Driven from standardized procedures in policy documents Used to easily identify and track assets Tagging in AWS: 21

Asset management & planning Server deployment Server deployments Driven from policy Establish a deployment approach Flatten & Repave Have specified zones for deployment Record how long assets will be deployed for 22

Asset management & planning Disaster recovery / Capacity planning Disaster recovery Simple approach - Standard Business Continuity/Disaster Recovery processes Failover Testing Complex approach - Data Storage and Recovery What needs to be backed up? For how long? Replication & Redundancy 23

Asset management & planning Disaster recovery / Capacity planning Capacity planning Understanding what assets are available Determine budget for cloud services Track that capacity is meeting demand Track that usage does not exceed budget 24

Closing remarks / Questions 25

Closing remarks Asset management in the cloud: Can be complex Take time to understand your environment Utilize information and services provided by the cloud service providers 26

Contact Information Aaron Brown Partner Deloitte & Touche LLP aaronbrown@deloitte.com Tel 1-206-716-7457 Todd Mack Manager Deloitte & Touche LLP tmack@deloitte.com Tel 1-206-716-6528 David Fantham Consultant Deloitte & Touche LLP dfantham@deloitte.com Tel 1-206-716-7077

This presentation contains general information only and Deloitte is not, by means of this presentation, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This presentation is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this presentation. Product names mentioned in this presentation are the trademarks or registered trademarks of their respective owners and are mentioned for identification purposes only. Deloitte is not endorsing any specific company, product or service by means of this presentation. About Deloitte Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee ( DTTL ), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as Deloitte Global ) does not provide services to clients. Please see www.deloitte.com/about for a detailed description of DTTL and its member firms. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting. Member of Deloitte Touche Tohmatsu Limited 28