SlideShare a Scribd company logo
1 of 21
Trends in GRC ManagementJeff Kushner, Director of Marketingjeff.kushner@modulo.com
Modulo Leadership 25+ years experience in IT security and GRC management 300% US growth (09-10) Over 400 employees world-wide Global Leader- Automated GRC Management Solutions   Nine-year of development, a mature product Active member of evolving GRC standards  ISO 27001, ISO 31000, PCI SVA & Shared Assessments/Bits Initiative 1st company in the world to obtain ISO 27001 certification ISO 9001 certified since 1998
Complexity and Risk Continue to  Increase Source: An Executive View of IT Governance, IT Governance Institute
Constant Change Regulations Polices People Processes Technology Technology Technology Technology Policy Policy Process Process Process People People
Fragmented Approach to GRC Management People People People Technology Technology Technology Process Process Process Facility Facility Facility ,[object Object]
Lack of automation
Little Consistency
Limited visibility,[object Object]
Automation, Practice and Policy in Information Security for Better Outcomes, IT Policy Compliance Group
Global survey into the integration of governance,risk and compliance, KPMG
Global survey into the integration of governance,risk and compliance, KPMG
IT Balancing Enterprise Risk and Reward, Aberdeen Group
IT Balancing Enterprise Risk and Reward, Aberdeen Group
Beyond Demonstrating Compliance, Aberdeen Group
Beyond Demonstrating Compliance, Aberdeen Group
Value of a CommonArchitecture for GRC Platforms, Michael Rasmussen The goal: An enterprise view of risk and compliance on a common architecture The Value: A common architecture relieves the GRC burden on the business Disconnected risk and compliance processes introduce greater exposure Manual processes drive inefficiency and raise GRC costs GRC, done right, delivers efficiency and value to the organization
Value of a CommonArchitecture for GRC Platforms, Michael Rasmussen Foundations of a GRC Technology Architecture A common user interface (screen design) for all applications A common workflow engine throughout the applications A common security model to protect applications and data A common programming language used to build the applications A common database used to run the applications A common enterprise architecture (a method for describing the departments and divisions within the organization)
References http://www.itgi.org/ http://www.itpolicycompliance.com/ http://www.kpmg.com/Global/en/IssuesAndInsights/ArticlesPublications/Pages/The-convergence-challenge-Global-survey.aspx http://www.modulo.com/research/ (Aberdeen Reports) http://www.corp-integrity.com/
Modulo The Company
Example of Modulo Clients South Carolina Department  of  Health and Human Services
Modulo GRC Metaframework

More Related Content

Similar to Jeff kushner trends in grc management

Ecom Nets Technologies
Ecom Nets TechnologiesEcom Nets Technologies
Ecom Nets Technologies
nveeravalli
 
IO Journey All Up
IO Journey All UpIO Journey All Up
IO Journey All Up
baselsss
 
Nassers Pitchbook 03032010
Nassers Pitchbook 03032010Nassers Pitchbook 03032010
Nassers Pitchbook 03032010
Nasser J Khan
 
Nassers Pitchbook 03032010
Nassers Pitchbook 03032010Nassers Pitchbook 03032010
Nassers Pitchbook 03032010
Nasser J Khan
 
NachiketaSharmaResume - Executive
NachiketaSharmaResume - ExecutiveNachiketaSharmaResume - Executive
NachiketaSharmaResume - Executive
Nachiketa Sharma
 
Thomas R Graham bio
Thomas R Graham bioThomas R Graham bio
Thomas R Graham bio
Tom Graham
 
Security architecture rajagiri talk march 2011
Security architecture  rajagiri talk march 2011Security architecture  rajagiri talk march 2011
Security architecture rajagiri talk march 2011
subramanian K
 
IBM - Understanding the value of ECM
IBM - Understanding the value of ECMIBM - Understanding the value of ECM
IBM - Understanding the value of ECM
rashmin_cby
 

Similar to Jeff kushner trends in grc management (20)

Ecom Nets Technologies
Ecom Nets TechnologiesEcom Nets Technologies
Ecom Nets Technologies
 
S Rod Simpson Resume
S Rod Simpson ResumeS Rod Simpson Resume
S Rod Simpson Resume
 
IO Journey All Up
IO Journey All UpIO Journey All Up
IO Journey All Up
 
Nassers Pitchbook 03032010
Nassers Pitchbook 03032010Nassers Pitchbook 03032010
Nassers Pitchbook 03032010
 
Nassers Pitchbook 03032010
Nassers Pitchbook 03032010Nassers Pitchbook 03032010
Nassers Pitchbook 03032010
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
Real World Governance Risk and Compliance | European Collaboration Summit 2023
Real World Governance Risk and Compliance | European Collaboration Summit 2023Real World Governance Risk and Compliance | European Collaboration Summit 2023
Real World Governance Risk and Compliance | European Collaboration Summit 2023
 
MullaneyChrisER
MullaneyChrisERMullaneyChrisER
MullaneyChrisER
 
NachiketaSharmaResume - Executive
NachiketaSharmaResume - ExecutiveNachiketaSharmaResume - Executive
NachiketaSharmaResume - Executive
 
FulcrumWay GRC Solutions
FulcrumWay GRC SolutionsFulcrumWay GRC Solutions
FulcrumWay GRC Solutions
 
Enterprise Architecture: An enabler of organizational agility
Enterprise Architecture: An enabler of organizational agility Enterprise Architecture: An enabler of organizational agility
Enterprise Architecture: An enabler of organizational agility
 
The Challenges Of, And Advantages In, Establishing A Consistent Architectural...
The Challenges Of, And Advantages In, Establishing A Consistent Architectural...The Challenges Of, And Advantages In, Establishing A Consistent Architectural...
The Challenges Of, And Advantages In, Establishing A Consistent Architectural...
 
Thomas R Graham bio
Thomas R Graham bioThomas R Graham bio
Thomas R Graham bio
 
Sept 2008 Presentation Quality & Project Management
Sept 2008 Presentation Quality & Project ManagementSept 2008 Presentation Quality & Project Management
Sept 2008 Presentation Quality & Project Management
 
Erpppt
ErppptErpppt
Erpppt
 
Adaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyAdaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_study
 
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
 
Security architecture rajagiri talk march 2011
Security architecture  rajagiri talk march 2011Security architecture  rajagiri talk march 2011
Security architecture rajagiri talk march 2011
 
IBM - Understanding the value of ECM
IBM - Understanding the value of ECMIBM - Understanding the value of ECM
IBM - Understanding the value of ECM
 
CMMi & IT Governance
CMMi & IT GovernanceCMMi & IT Governance
CMMi & IT Governance
 

Recently uploaded

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Recently uploaded (20)

Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 

Jeff kushner trends in grc management

  • 1. Trends in GRC ManagementJeff Kushner, Director of Marketingjeff.kushner@modulo.com
  • 2. Modulo Leadership 25+ years experience in IT security and GRC management 300% US growth (09-10) Over 400 employees world-wide Global Leader- Automated GRC Management Solutions Nine-year of development, a mature product Active member of evolving GRC standards ISO 27001, ISO 31000, PCI SVA & Shared Assessments/Bits Initiative 1st company in the world to obtain ISO 27001 certification ISO 9001 certified since 1998
  • 3. Complexity and Risk Continue to Increase Source: An Executive View of IT Governance, IT Governance Institute
  • 4. Constant Change Regulations Polices People Processes Technology Technology Technology Technology Policy Policy Process Process Process People People
  • 5.
  • 8.
  • 9. Automation, Practice and Policy in Information Security for Better Outcomes, IT Policy Compliance Group
  • 10. Global survey into the integration of governance,risk and compliance, KPMG
  • 11. Global survey into the integration of governance,risk and compliance, KPMG
  • 12. IT Balancing Enterprise Risk and Reward, Aberdeen Group
  • 13. IT Balancing Enterprise Risk and Reward, Aberdeen Group
  • 16. Value of a CommonArchitecture for GRC Platforms, Michael Rasmussen The goal: An enterprise view of risk and compliance on a common architecture The Value: A common architecture relieves the GRC burden on the business Disconnected risk and compliance processes introduce greater exposure Manual processes drive inefficiency and raise GRC costs GRC, done right, delivers efficiency and value to the organization
  • 17. Value of a CommonArchitecture for GRC Platforms, Michael Rasmussen Foundations of a GRC Technology Architecture A common user interface (screen design) for all applications A common workflow engine throughout the applications A common security model to protect applications and data A common programming language used to build the applications A common database used to run the applications A common enterprise architecture (a method for describing the departments and divisions within the organization)
  • 18. References http://www.itgi.org/ http://www.itpolicycompliance.com/ http://www.kpmg.com/Global/en/IssuesAndInsights/ArticlesPublications/Pages/The-convergence-challenge-Global-survey.aspx http://www.modulo.com/research/ (Aberdeen Reports) http://www.corp-integrity.com/
  • 20. Example of Modulo Clients South Carolina Department of Health and Human Services
  • 22. The Modulo Advantage Automate the manual fragmented approach to GRC management Comply with multiple regulations Lower IT and enterprise risk Reduce cost of people resources and IT infrastructure overhead Know where you stand quicker = ROI

Editor's Notes

  1. Modulo is the industry’s leading global provider of automated Governance, Risk and Compliance (GRC) management solutions.  Our Award-winning Risk Manager™ Software delivers a consistent out-of-the-box solution that simplifies the management of the GRC life-cycle which significantly reduces management costs and corporate risk.   Unlike other non-integrated GRC solutions, Modulo provides quick visibility into the corporate risk and compliance posture for executives, management and technical staff . To effectively and effectively measure, manage and proactively sustain risk mitigation, compliance obligations and governance objectives.
  2. THE MODULO ADVANTAGE Automate the manual fragmented approach to GRC management -Distributed database driven platform with common policy, asset, reporting and incident repository Comply with multiple regulations- Effectively manage the policy lifecycle and map multiple policies to common controls Lower IT and enterprise risk- Consistently measure and communicate risk posture across enterprise Reduce cost of people resources and IT infrastructure overhead- Automate common tasks and leverage technology in place without adding the complexity of agents Know where you stand quicker = ROI- Get value in hours not days or weeks from 25 years of experience in IT security and GRC management expertise