Automating Policy Compliance and IT Governance

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Automating Policy Compliance and IT Governance - Presentation Transcript

    1. Jason Creech, Director of Strategic Alliances Automating Policy Compliance And IT Governance
    2. IT GRC
      • Information Technology – Governance, Risk, & Compliance
      • Became mainstream about two years ago
      • G, R, and C no longer considered separate silos
      • Focus on the commonalities between the disciplines
      • Aligns IT initiatives with business objectives
      • So what is GRC?
    3. Basic IT GRC Definitions
      • IT Governance
      • Defines how decisions will be made, by who, accountability, and measurement
      • IT Risk Management
      • Ensures strategic IT objectives take into account acceptable levels of risk in relation to stakeholders, industry mandates, and regulations
      • IT Compliance
      • Establishes and monitors IT Controls and ensures that decisions are made and prioritized in accordance with policy
      C O N F I D E N T I A L C O M P A N Y C O N F I D E N T I A L
    4. Why Do We Need IT GRC
      • To Meet regulatory requirements and industry mandates
      • To Address needs of stakeholders
      • To Prioritize IT tasks for elimination of critical IT risks
      • To Facilitate internal and external audit requirements
      • To Align IT process with business objectives
    5. Challenges?
      • Increasing Regulatory Requirements
      • Different Stakeholders With Different Needs
      • Manual Processes In Reporting Compliance
      • Communication Between Departments
    6. Regulatory Landscape
      • Increasing in number
      • No standardization
      • Constantly changing
      FDA 21 CFR Part 11 (Pharma) HIPAA Security Rule EU Data Protection Directive GLBA 1990s PIPEDA (Canada) FDCC/SCAP NIST SP 800-53 PCI Data Security Standard EC Data Privacy Directive BS 7799 / ISO 17799 / 27001 / 27002 FISMA 2002 Basel II Accord Sarbanes-Oxley NERC California SB 1386 Privacy 2000 and beyond FFIEC IT Exam Handbook ITIL v3
    7. Meet Compliance Stakeholder Needs
      • Consolidate security data
      • Proactively identify threats
      • Prioritize IT risks
      • Assign and verify remediation
      • Compliance and Security Summary Metrics
      • Reduce reporting costs
      • Identify areas of risk to the LOB
      • Reduce audit costs
      • Automate collection of audit data
      • Automate views into security data
      • Automate risk & regulatory reporting
      • Prioritize and track remediation
      • Utilize existing remediation tools
      • Closed-loop workflow
    8. Bridging Departmental Gaps Simple Compliance Framework Procedures and Guidelines Detail Knowledge and Expertise Framework Level Detailed Technical BU Managers/Audit Compliance Security Operations Policies, Standards, Business Requirements Controls (Manual/Auto) Procedures and Guidelines Enforcement Regulations Frameworks Standards SOX HIPAA GLBA CobIT COSO ISO17799 PCI NIST NERC “ Example: Vulnerable Processes must be eliminated..” CID 1130 The telnet daemon shall be disabled AIX 5.x Technology Telnet streams are transmitted in clear text, including usernames and passwords. The entire session is susceptible to interception by Threat Agents.
    9. QualysGuard Simplifies and Automates
      • An agent-less and scalable audit technology in a SaaS model
      • Automates the harvesting of IT data
      • Identifies violations of IT Policy
      • Improves relevance of IT data to regulatory concerns.
        • Sarbanes-Oxley
        • HIPAA
        • GLBA
        • FISMA
        • CobiT
        • ISO27002
        • FFIEC
        • ITIL
    10. Benefits
        • Immediate Deployment
        • Ease of Use / Automated
        • Accuracy
        • Scalability
        • Flexible Reporting
        • Security
        • Cost-Effective / Lowest TCO
    11. How does QualysGuard PC Work?
      • Leverages Same Infrastructure as QualysGuard VM…
    12. Summary
        • QualysGuard Policy Compliance Automates IT GRC process via:
          • SaaS model
          • Agent-less design
          • Seamless integration
          • Scheduled Collection of compliance data
          • Sharing of compliance data across the organization
      Security and Regulatory Compliance Convergence in one single application delivered as SaaS
    SlideShare Zeitgeist 2009

    + Sasha NunkeSasha Nunke Nominate

    custom

    435 views, 0 favs, 0 embeds more stats

    This presentation covers the foundations of a succe more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 435
      • 435 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 40
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories