Managing risks in the supply chain<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />1<br ...
People do not fully trust  The Cloud<br />People say that they are concerned that their information is not secure in The C...
Is the Cloud Secure?<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />3<br />Can be as se...
Problem to be solved – trust in the supply chain<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance....
What a CIO want<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />5<br />Provider A<br />P...
19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />6<br />CAMM MISSIONProvide an objective frame...
Overall structure of CAMM components<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />7<b...
Utilize your current investmentto an another standard e.g. ISO<br />The Statement Of Applicability (SOA) of source standar...
Stakeholders<br />Consumers – Can form trust relationship based on understantable facts<br />Companies – Can form trustwor...
Progress<br />It is anticipated for the initial set of COMMON controls and associated guidance to be completed by Q4 2011....
Upcoming SlideShare
Loading in...5
×

CAMM presentation for Cyber Security Gas and Oil june 2011

702

Published on

Let's talk about Cloud security, its challenges and how CAMM can help in managing supply chain assurance.

Published in: Technology, Business
0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total Views
702
On Slideshare
0
From Embeds
0
Number of Embeds
1
Actions
Shares
0
Downloads
7
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide
  • Security very important issue to peopleBut look at other areas – vendor lock-inAt the same time business teams (marketing) go to cloud services with their credit cards – as IT is tooooo slow
  • Picture kindly taken from a Microsoft presentationProbably more secure than your local IT – but how to measure thatRisk cannot be outsourced to cloud – so how to measure what the riks with the cloud provider, type and delivery model isIf I use IaaS I still am responsibel for application mangement and potentially OS management
  • CAMM presentation for Cyber Security Gas and Oil june 2011

    1. 1. Managing risks in the supply chain<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />1<br />Vladimir Jirasek<br />CAMM Steering Group<br />Twitter @vjirasek<br />
    2. 2. People do not fully trust The Cloud<br />People say that they are concerned that their information is not secure in The Cloud<br />
    3. 3. Is the Cloud Secure?<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />3<br />Can be as secure as any other IT system<br /> Depends on the model chosen<br />Understand the responsibilities<br /> All eggs in one basket is the real question<br />Implicit trust on provider<br />Exit and lock-in<br />
    4. 4. Problem to be solved – trust in the supply chain<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />4<br />Suppliers for the cloud provider<br />Your business<br />Your cloud provider<br />End to end assurance<br />
    5. 5. What a CIO want<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />5<br />Provider A<br />Provider B<br />Maturity levels feed into a supplier selection process<br />
    6. 6. 19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />6<br />CAMM MISSIONProvide an objective framework to transparently rate and benchmark the capability of a selected solution to deliver information assurance maturity across the supply chain<br />
    7. 7. Overall structure of CAMM components<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />7<br />TPAC<br />Final maturity scores<br />Mapping to other standards<br />Free GRC app<br />Scoring model<br />Non CAMM audit results<br />Maturityscores<br />Weightingframework<br />WorkBench<br />App<br />Audited controls<br />Controls framework<br />Auditors<br />
    8. 8. Utilize your current investmentto an another standard e.g. ISO<br />The Statement Of Applicability (SOA) of source standard is used as a baseline for translation<br />CAMM Guidance documents will help auditors with ”yellow” area intepretations<br />19 June, 2011<br />Common Assurance Maturity Model Common-Assurance.com<br />8<br />Souce standard<br />Target standard<br />e.g. ISO 2700x SOA<br />CAMM<br />Translate<br />Not implemented > to be CAMM audited<br />Auditor intepretation of applicability<br />1=1 applicable, no need of intepretation<br />
    9. 9. Stakeholders<br />Consumers – Can form trust relationship based on understantable facts<br />Companies – Can form trustworthy supply chains to provide real trustworthiness to consumers & other customers<br />Governents – Canhavemore confidence in corporategovernance to remove barriers from global single e-markets<br />Service Providers & Consultancies – Can buildcompetences to achieve the target<br />Industry Associations – can excel in defining harmonized model implementations <br />Consumer<br />Government<br />CAM Commitee<br />
    10. 10. Progress<br />It is anticipated for the initial set of COMMON controls and associated guidance to be completed by Q4 2011. The following details the key milestones:<br />Major client, standards and service provider organisations engaged<br />Development of framework and appropriate weighting mechanism underway <br />Development of the framework <br />Control framework created and reviewed<br /> Scoring model created<br />Development of the guidance<br /> Guidance material to be completed by end of October 2011<br />Pilot<br /> Pilot with major organisation planned for summer 2011<br /> Development of Free GRC tool<br /> Major GRC vendor engaged to ad CAMM module<br />
    1. A particular slide catching your eye?

      Clipping is a handy way to collect important slides you want to go back to later.

    ×