ITGRCWORKSHOP
ITGOVERNANCE,RISK&COMPLIANCE BRINGING ITALLTOGETHER
ITGOVERNANCE,RISK&COMPLIANCE BRINGING ITALLTOGETHER
PRESENTATIONOUTLINE 1
InformationProtectionManagementDiv.
2
WhatisGovernance,Risk&Compliance?
3
EnterpriseGovernance,Risk&Compliance
4
ITGovernance,Risk&Compliance
5
ITControlFrameworks
WHATISGOVERNANCE,RISK& COMPLIANCE? GENERALPERSPECTIVE
GOVERNANCE,RISK , ANDCOMPLIANCE Ø Governance v
Istheprocessbywhichpoliciesaresetanddecisionmakingisexecuted.
Ø RiskManagement v
Istheprocessofiden:fica:on,analysisandeitheracceptanceor mi:ga:onofuncertaintyindecision-making.
Ø Compliance v
Istheprocessofadherencetopoliciesanddecisions.
INTERRELATIONSHIP BETWEENGOVERNANCE ,RISK , ANDCOMPLIANCE
Governance
Governancemanagesthe strategicdirec7vesacompany wantstofollow.
GRC Riskmanagement assessestheareasof exposureandpoten7al impacts.
Risk
Compliance
Complianceisthetac7cal ac7ontomi7gaterisk.
WHY FOCUS ONGRCNOW? Ø
Riskshavebecomemorediverseandinterrelated.
Ø
Lawsandregula:onshavebecomemorecomplicated.
Ø
Boards,execu:vesandmanagementhavebecomemore accountable.
Thisputsorganiza:onsatgreaterriskandmakesitdifficult andcostlyforManagementtodotheirjobseffec:vely.
PROBLEMSF ACED BY ORGANIZATIONS Ø
ToomuchriskforthereturnwearegeJng
Ø
TooliKlevaluefrombusiness-ITinvestments
Ø
Slowdecisionmaking
Ø
Projectoverrunsanddelays
Ø
Lackofstability,availability,protec:onandrecoverability
GRCSPECIFICPROBLEMSF ACED BY ORGANIZATIONS Ø
GRCac:vi:esandcontrolsarefragmentedandmanagedinsilos
Ø
Organiza:onsusereac:ve,one-offapproachestoaddresscompliance issues
Ø
Riskandcomplianceconsidera:onsarenotintegratedintocorebusiness processesandmainstreamdecision-making
Ø
Leadersoenlackanenterpriseviewofrisks
Ø
ITassetsarenotwellalignedwithriskorcompliancemanagementneeds
Ø
Managementdoesnothavethehigh-qualityinforma:ontheyneed
IMPROVING EFFICIENCY AND EFFECTIVENESS REQUIRES IMPROVEMENT IN THREE ASPECTS OFGRC A?en7on Awareness&People
Improvementsaredependentonprogressinotherareas.
Efficiency
Effec7veness
Automa:on&Tools
Governance&Processes
ESSENTIALELEMENTS OF AGRCPROGRAM Governance • Centralized repository of policies and controls • Integrated database of major regulations, standards and best practices • Comprehensive policy management with awareness campaigns and attestation • Controls management and reporting
Risk • Risk management, including key risk indicators and risk dashboards
Compliance • Compliance assessment, monitoring and reporting
BENEFITS OFINTEGRATINGGRC Ø
Makerisk-informedstrategicdecisions.
Ø
Analyzeriskbasedonquan:ta:vedata.
Ø
Managecompliance.
Ø
Priori:zeremedia:onac:vi:es.
ENTERPRISEGOVERNANCE,RISK& COMPLIANCE TOUNDERSTANDITGRCY OUMUSTFIRST UNDERSTANDENTERPRISEGRC
ENTERPRISE GRC
Governance Strategy
RiskManagement Assessment
Planning
Mitigation
Compliance Assessment
Reporting
ANENTERPRISE GRCPLATFORM Auditors
Boards
AuditManagement RiskManagement
S E E L S S P E O C E O P R P
ComplianceManagement RemediationManagement PolicyManagement
Risk&ControlsMatrix
EnterpriseGRCPlatform
T M E M E G A N A M
ITGOVERNANCE,RISK&COMPLIANCE TO ESTABLISH MORE ACCOUNTABLE AND EFFECTIVE ITFUNCTIONS
ITGRCTIES TOGETHER THE PROGRAMS OF.. Ø ITGovernance v
AnITgovernanceprogramtoleveragethedevelopedrisk-basedop:onsin supportofanorganiza:on’sdecision-makingprocess.
Ø ITRiskmanagement v
AnITriskmanagementprogramperformsriskassessmenttodevelopand priori:zeop:onsforremedia:on
Ø ITCompliance v
AnITcomplianceprogramtomeasurethelevelofcompliancewithinanIT environment
IT-GRC
ITGRCMEANSM ANAGING… ITstrategy ITservices Systemsinfrastructure Informa:onmanagement Informa:onsecurity Resourceavailability(hardware,soware&data) Dataintegrity Technologyrisk Legalandregulatorycompliance
GRCM ATURITY MODEL CurrentIT-GRCMaturity.
NextPhase
REACTIVE,FRAGMENTEDIMPLEMENTATION PHASE Ø
GRCac:vi:esarelargelymanual,notstandardizedandnotwell integratedintocorebusinessprocesses
Ø
GRCac:vi:eshavenotreceivedasmuchaKen:oninthepast
Ø
Mostorganiza:onshavetreatedgovernance,riskandcomplianceas discreteac:vi:es,separatefrommainstreambusinessprocessesand decisionmaking
Ø
Exis:ngITinfrastructures,applica:onsandprocessesdonotprovide sufficientsupportforeffec:veriskmanagementandefficient compliance
ITGRCMUSTBEDRIVENFROM THETOP-DOWN Ø
CorporateGRCisanimportantinputfordefiningITGRC.
Ø
ITGRCrequiresseniorbusinesspar:cipa:on,especiallyatthe boardlevel.
ITCONTROLFRAMEWORKS COBIT CONTROLOBJECTIVES FORINFORMATION AND RELATEDTECHNOLOGY
COBIT ANDOTHERITM ANAGEMENTFRAMEWORKS
WHEREDOESCOBITFIT?
THECOBITFRAMEWORK WASDESIGNEDTO PROVIDE.. Acomprehensivecontrolframeworktocover Ø
ITorganiza:on
Ø
ITusers
Ø
ITprofessionals
Ø
ITgovernance
Ø
ITrisks
Ø
ITprocesses
SUMMARY Ø Ø
Ø
ITGRCisasubsetofCorporate Governance
Governance
ITGRCcomprisesof v
ITGovernance
v
ITRisk
v
ITCompliance
Withoutoneyoucannothavetheother.. v
Governance,RiskandComplianceare interrelated
GRC Risk
Compliance
DO YOU HAVE ANY QUESTIONS ?
Thankyou!