20140410 - Gestion des identités, traçabilité des accés - Analogie avec la qualité logicielle

IT Security Services
CONTROL FACTORY
|BEHIND THE SCENES|
Software Quality principles applied to
Security Controls
ITSecurityServices
BUSINESS ENVIRONMENT
CONTROL FACTORY |BEHIND THE SCENES|
ENERGY GIANT / BUSINESS LINE / BUSINESS UNIT
Integrated and dynamic management of
portfolio – purchasing contracts, assets and
sales contracts
Management & Trading of Energy
Client Business Environment
REGULATORY/CONTROLS CONSTRAINTS
Highly monitored and regularly audited
activities
Internal
controls
Compliance
Legal
External
audits
Group internal controls
Business line controls
Internal Compliance & Legal
Risk Operations
Internally driven Externally driven
Various
Auditors
ITSecurityServices
CONTROLS FRAMING
CONTROL FACTORY |BEHIND THE SCENES|
Security Controls governance
 Discipline/Part of Corporate Governance focused on
information technology (IT) oriented security controls
aligned with business constraints
Security Control book
 An important element of a framework ensuring that
the organization’s policies/requirements are
formalized, monitored and implemented as controls
over time
 A centralization of security controls carried out on the
organization
 A tool-based methodology implementing the security
control strategy
FRAMING CONTROLS BASED ON REQUIREMENTS
Controlsources
Requirement
Campaign
1
2
3
n
n
n
n
n
n
relationship | cardinality
Report/Gap analysis needs
Execution coverage
Requirement coverage
SECURITY CONTROLS | SOFTWARE QUALITY PRINCIPLES
Standards
Regulation
Internal
Framework
In-house best
practices
Sources of requirements
Risks
Requirement 1
Requirement 2
Requirement 3
Requirement 4
Requirement “n”
internal REG
REG
Internal
IN HOUSE
AUDIT
…
Sources of control
Control 1
Control 2
REQ 1 REQ 2
REQ 1 REQ 4
Sourcesofcampaign
Iteration 1
Campaign1
Control “n”
REQ n REQ n
Campaign “n”
CTL n
CTL 4
CTL n
Sourcesofiterations
Iteration 2
CAM 1
Iteration 1
Iteration 2
CAM 2
Requirement view
Control view
Campaign view
Execution view
Incidents
CONTROL ECOSYSTEM
CAM 1
CAM 2
Title
Description
Criticality
Category
(Security, Business…)
Owner
Group/source
(tag or ordering)
Covered risk
FRAMEWORK @ A GLANCE
Requirement template
Title Description
Nature
(administrative, technical, physical)
Function
(preventive, detective, corrective, recovery)
Type
(Security)
Frequency
Level
(1 to 3)
RACI matrix
FRAMEWORK @ A GLANCE
Control template
Title Description
Control suites
(STU 1, STU 2,…)
Assignee
Planning
Execution status
Basic stats
Control plan
(CTL1, CTL2,…)
FRAMEWORK @ A GLANCE
Campaign template
Controlsources
Requirement
Campaign
1
2
3
n
n
n
n
n
n
relationship | cardinality
Report/Gap analysis needs
Execution coverage
Requirement coverage



- Requirements covered by controls ?
- All controls associated to requirement ?
- Controls executed as expected ?
- Execution coverage of requirement ?


SECURITY CONTROLS | SOFTWARE QUALITY PRINCIPLES
ITSecurityServices
IAM SECURITY OPERATIONS
CONTROL FACTORY |BEHIND THE SCENES|
CONTROL FACTORY | DEFINE
refers to :
Control Factory (CF)
a structured collection of assets
that aids in producing controls through an assembly process
according to specific requirements1 3
2 4
The Control factory applies manufacturing
techniques and principles …
> Formalization > Automation
> Services Oriented > Industrialization
Right process  right result Reduce manual intervention
Activities divided in services Reusable components
CONTROL FACTORY | OBJECTIVES
… to mimic the benefits of traditional
manufacturing
>Consistency
build multiple instances of a control product line & set of
controls sharing similar “features and architecture”
>Quality
integrates reusable controls reducing the likelihood of control
design flaws
>Productivity
Controls activities can be streamlined and automated
Conception
Design and logic according to
requirements
Suppliers
relationship
Sourcing of data,
qualification, remediation
Production
Producing resources for
controls reports, dashboards
Delivery
Making resources for controls
available
Supervision
Governing controls campaign
and remediation
Internal
QA, maintenance,
improvements
CONTROL FACTORY | ACTIVITIES/SERVICES
Customers
CONTROL FACTORY | PRODUCTION SERVICES
Control Production
Production is divided in 6 distinct stages :
Supply Raw data from multiple collect sources
Compute Loading, ordering & storing data
Reconcile Identities vs. accounts
Control Production of control resources
SoD Advanced controls
Report Presenting results as expected
PRODUCTION SERVICES| SUPPLY
Supply
… loading raw data, reconciliation, mapping
and ordering for reuse
Controlsfactory
Advanced controls
Reports/views
Controls
Data Reconciliation
Compute
2
3
1
Attaching identities to respective
unitary organization
Reconciling identities with accounts,
perms…
Producing controls in the factory
Reporting results in expected views 4
…
PRODUCTION SERVICES| REPORT
Report … presenting control data as requested
(format & delivery)
• Timeslots
• Reports
• Data exports
Web portal
• Reports sent to
reviewers
Campaign
Data
Lifecycle
Data
Quality
Data
Volume
Business
Activity
CONTROLS GOVERNANCE | FOCUS ON PITFALLS
 Reduce treatment time
from import to
remediation
 Based on reliable data,
readable and
understandable
 Deeply analyzed and divided i.e.
volume that are “control ready”
and “supervision ready”
 Better integration of
stakeholders
processes
› Ergonomics and design
› Administration
› Dashboard & Reporting
› Automation
CAMPAIGN & CONTROLS | ANALYSIS
› Tickets directly created and assigned
› Follow-up using the factory
› Dynamic reports (web interfaces)
› Point and click review
› Enriched information
› Delegation mechanism enhanced
› Improved planning and review mechanism
Orientations and improvements
› Automated and real-time
› Web-based dashboard
ITSecurityServices
THANK U / QUESTIONS
CONTROL FACTORY |BEHIND THE SCENES|
1 of 22

Recommended

Ais Romney 2006 Slides 06 Control And Ais by
Ais Romney 2006 Slides 06 Control And AisAis Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And AisSharing Slides Training
1.9K views314 slides
Implementing an Integrated Quality Management System in SharePoint by
Implementing an Integrated Quality Management System in SharePointImplementing an Integrated Quality Management System in SharePoint
Implementing an Integrated Quality Management System in SharePointMontrium
8.2K views22 slides
Quality Control Insurance Systems by
Quality Control Insurance SystemsQuality Control Insurance Systems
Quality Control Insurance SystemsVictoria Condlln Smallridge
117 views8 slides
Promaint CMMS & EAM by
Promaint CMMS & EAMPromaint CMMS & EAM
Promaint CMMS & EAMPROCESS MASTER TECHNOLOGIES PVT. LTD.
2.5K views15 slides
15 Months to Certification: Using SharePoint as the Platform for an ISO 9001 ... by
15 Months to Certification: Using SharePoint as the Platform for an ISO 9001 ...15 Months to Certification: Using SharePoint as the Platform for an ISO 9001 ...
15 Months to Certification: Using SharePoint as the Platform for an ISO 9001 ...Barry Peters
5.3K views29 slides
BatchMaster for Specialty Chemicals by
BatchMaster for Specialty ChemicalsBatchMaster for Specialty Chemicals
BatchMaster for Specialty ChemicalsBatchMaster Software Pvt. Ltd.
488 views22 slides

More Related Content

What's hot

BSA 375 Final Assignment Team presentation by
BSA 375 Final Assignment Team presentationBSA 375 Final Assignment Team presentation
BSA 375 Final Assignment Team presentationMichael Jeter
2.9K views8 slides
Complete Purchasing Process For Small Business by
Complete Purchasing Process For Small BusinessComplete Purchasing Process For Small Business
Complete Purchasing Process For Small BusinessBill Kohnen
2.6K views21 slides
Documents system by
Documents systemDocuments system
Documents systemDeepak Amoli
255 views10 slides
Oracle Enterprise Manager by
Oracle Enterprise ManagerOracle Enterprise Manager
Oracle Enterprise Manageroracleonthebrain
495 views10 slides
Accounting system and control by
Accounting system and controlAccounting system and control
Accounting system and controlRaziya Hameed
2.4K views19 slides
008.itsecurity bcp v1 by
008.itsecurity bcp v1008.itsecurity bcp v1
008.itsecurity bcp v1Mohammad Ashfaqur Rahman
415 views21 slides

What's hot(20)

BSA 375 Final Assignment Team presentation by Michael Jeter
BSA 375 Final Assignment Team presentationBSA 375 Final Assignment Team presentation
BSA 375 Final Assignment Team presentation
Michael Jeter2.9K views
Complete Purchasing Process For Small Business by Bill Kohnen
Complete Purchasing Process For Small BusinessComplete Purchasing Process For Small Business
Complete Purchasing Process For Small Business
Bill Kohnen2.6K views
Accounting system and control by Raziya Hameed
Accounting system and controlAccounting system and control
Accounting system and control
Raziya Hameed2.4K views
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016 by StratesysUSA
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016
StratesysUSA384 views
Internal Control by Salih Islam
Internal ControlInternal Control
Internal Control
Salih Islam15.8K views
Enterprise resource planning trend since 1960s to 2000s and Major benefits a... by Orko Abir
Enterprise resource planning trend since 1960s to 2000s  and Major benefits a...Enterprise resource planning trend since 1960s to 2000s  and Major benefits a...
Enterprise resource planning trend since 1960s to 2000s and Major benefits a...
Orko Abir 204 views
The Revenue Cycle by Qamar Farooq
The Revenue Cycle The Revenue Cycle
The Revenue Cycle
Qamar Farooq113.8K views
Cg Risk Management Info Presentation by jlevenberg
Cg Risk Management Info PresentationCg Risk Management Info Presentation
Cg Risk Management Info Presentation
jlevenberg226 views
'Electronic Batch Process recording system by anusa
'Electronic Batch Process recording system'Electronic Batch Process recording system
'Electronic Batch Process recording system
anusa1.8K views
CONTROL AND AUDIT by Ros Dina
CONTROL AND AUDITCONTROL AND AUDIT
CONTROL AND AUDIT
Ros Dina3.1K views
Lecture 23 expenditure cycle part ii -fixed assets accounting information sy... by Habib Ullah Qamar
Lecture 23  expenditure cycle part ii -fixed assets accounting information sy...Lecture 23  expenditure cycle part ii -fixed assets accounting information sy...
Lecture 23 expenditure cycle part ii -fixed assets accounting information sy...
Habib Ullah Qamar3.5K views
Context of Organisations by prateek verma
Context of OrganisationsContext of Organisations
Context of Organisations
prateek verma507 views
ERP implementation at steel mill by Asher Jawad
ERP implementation at steel millERP implementation at steel mill
ERP implementation at steel mill
Asher Jawad303 views

Similar to 20140410 - Gestion des identités, traçabilité des accés - Analogie avec la qualité logicielle

Production cycle by
Production cycle Production cycle
Production cycle Poojith Jain
19.8K views28 slides
gray_audit_presentation.ppt by
gray_audit_presentation.pptgray_audit_presentation.ppt
gray_audit_presentation.pptKhalilIdhman
4 views18 slides
It Governance Methodology Cox by
It Governance Methodology CoxIt Governance Methodology Cox
It Governance Methodology CoxWilliam Cox MBA, QPM, CSM, PMP, CPHIMS
1.1K views28 slides
2016-06-08 FDA Inspection Readiness - Mikael Yde by
2016-06-08 FDA Inspection Readiness - Mikael Yde2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Ydemikaelyde
570 views28 slides
Measuring and Improving MP1.ppt by
Measuring and Improving MP1.pptMeasuring and Improving MP1.ppt
Measuring and Improving MP1.pptssuserf2880f
15 views47 slides
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems by
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT SystemsICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT SystemsMohammad Abdul Matin Emon
685 views12 slides

Similar to 20140410 - Gestion des identités, traçabilité des accés - Analogie avec la qualité logicielle(20)

Production cycle by Poojith Jain
Production cycle Production cycle
Production cycle
Poojith Jain19.8K views
gray_audit_presentation.ppt by KhalilIdhman
gray_audit_presentation.pptgray_audit_presentation.ppt
gray_audit_presentation.ppt
KhalilIdhman4 views
2016-06-08 FDA Inspection Readiness - Mikael Yde by mikaelyde
2016-06-08 FDA Inspection Readiness - Mikael Yde2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde
mikaelyde570 views
Measuring and Improving MP1.ppt by ssuserf2880f
Measuring and Improving MP1.pptMeasuring and Improving MP1.ppt
Measuring and Improving MP1.ppt
ssuserf2880f15 views
Continuous Compliance Monitoring by ControlCase
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance Monitoring
ControlCase487 views
How much does it cost to be Secure? by mbmobile
How much does it cost to be Secure?How much does it cost to be Secure?
How much does it cost to be Secure?
mbmobile499 views
Quality Assurance in Aviation by Seema Zaman
Quality Assurance in AviationQuality Assurance in Aviation
Quality Assurance in Aviation
Seema Zaman5.4K views
SafepaaS AuditPaaS by Jane Jones
SafepaaS AuditPaaSSafepaaS AuditPaaS
SafepaaS AuditPaaS
Jane Jones15 views
AuditPaaS SafePaaS by Emma Kelly
AuditPaaS SafePaaSAuditPaaS SafePaaS
AuditPaaS SafePaaS
Emma Kelly53 views
AuditPaas by SafePaaS by Jane Jones
AuditPaas by SafePaaSAuditPaas by SafePaaS
AuditPaas by SafePaaS
Jane Jones28 views
SafePaaS AuditPaaS by Jane Jones
SafePaaS AuditPaaS SafePaaS AuditPaaS
SafePaaS AuditPaaS
Jane Jones55 views
Erp introduction by Goa App
Erp introductionErp introduction
Erp introduction
Goa App1K views
eprocbayoverviewdemopresentation-130201034007-phpapp02 by Satwinder Singh
eprocbayoverviewdemopresentation-130201034007-phpapp02eprocbayoverviewdemopresentation-130201034007-phpapp02
eprocbayoverviewdemopresentation-130201034007-phpapp02
Satwinder Singh60 views
Value-added it auditing by Marc Vael
Value-added it auditingValue-added it auditing
Value-added it auditing
Marc Vael565 views
Implementing Automated Qms For Business Excellence by Khalizan Halid
Implementing Automated Qms For Business ExcellenceImplementing Automated Qms For Business Excellence
Implementing Automated Qms For Business Excellence
Khalizan Halid335 views

More from LeClubQualiteLogicielle

20171122 03 - Les tests de performance en environnement DevOps by
20171122 03 - Les tests de performance en environnement DevOps20171122 03 - Les tests de performance en environnement DevOps
20171122 03 - Les tests de performance en environnement DevOpsLeClubQualiteLogicielle
2.3K views30 slides
20171122 04 - Automatisation - formation et certifications by
20171122 04 - Automatisation - formation et certifications20171122 04 - Automatisation - formation et certifications
20171122 04 - Automatisation - formation et certificationsLeClubQualiteLogicielle
764 views37 slides
20171122 01 - REX : Intégration et déploiement continu chez Engie by
20171122 01 - REX : Intégration et déploiement continu chez Engie20171122 01 - REX : Intégration et déploiement continu chez Engie
20171122 01 - REX : Intégration et déploiement continu chez EngieLeClubQualiteLogicielle
1.1K views30 slides
20171122 02 - Engage developers to use better coding practices by
20171122 02 - Engage developers to use better coding practices20171122 02 - Engage developers to use better coding practices
20171122 02 - Engage developers to use better coding practicesLeClubQualiteLogicielle
269 views21 slides
20171122 - Accueil Club Qualité Logicielle by
20171122 - Accueil Club Qualité Logicielle 20171122 - Accueil Club Qualité Logicielle
20171122 - Accueil Club Qualité Logicielle LeClubQualiteLogicielle
415 views12 slides
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des... by
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...LeClubQualiteLogicielle
460 views23 slides

More from LeClubQualiteLogicielle(20)

20171122 03 - Les tests de performance en environnement DevOps by LeClubQualiteLogicielle
20171122 03 - Les tests de performance en environnement DevOps20171122 03 - Les tests de performance en environnement DevOps
20171122 03 - Les tests de performance en environnement DevOps
20171122 01 - REX : Intégration et déploiement continu chez Engie by LeClubQualiteLogicielle
20171122 01 - REX : Intégration et déploiement continu chez Engie20171122 01 - REX : Intégration et déploiement continu chez Engie
20171122 01 - REX : Intégration et déploiement continu chez Engie
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des... by LeClubQualiteLogicielle
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...
20140410 - Cartographie applicative multi-technologies et analyse d'impact by LeClubQualiteLogicielle
20140410 - Cartographie applicative multi-technologies et analyse d'impact20140410 - Cartographie applicative multi-technologies et analyse d'impact
20140410 - Cartographie applicative multi-technologies et analyse d'impact
20140410 - Implémentation de squash TM-TA - Architecture et méthodologie by LeClubQualiteLogicielle
20140410 - Implémentation de squash TM-TA - Architecture et méthodologie20140410 - Implémentation de squash TM-TA - Architecture et méthodologie
20140410 - Implémentation de squash TM-TA - Architecture et méthodologie
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a... by LeClubQualiteLogicielle
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e... by LeClubQualiteLogicielle
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...
20130113 04 - Tests d'integration et virtualisation - La vision IBM by LeClubQualiteLogicielle
20130113 04 - Tests d'integration et virtualisation - La vision IBM20130113 04 - Tests d'integration et virtualisation - La vision IBM
20130113 04 - Tests d'integration et virtualisation - La vision IBM
20130523 06 - The mathematics the way algorithms think / the mathematics the ... by LeClubQualiteLogicielle
20130523 06 - The mathematics the way algorithms think / the mathematics the ...20130523 06 - The mathematics the way algorithms think / the mathematics the ...
20130523 06 - The mathematics the way algorithms think / the mathematics the ...
20130523 04 - Grille d'évaluation - Gestion du patrimoine de test by LeClubQualiteLogicielle
20130523 04 - Grille d'évaluation - Gestion du patrimoine de test20130523 04 - Grille d'évaluation - Gestion du patrimoine de test
20130523 04 - Grille d'évaluation - Gestion du patrimoine de test

Recently uploaded

Keep by
KeepKeep
KeepGeniusee
77 views10 slides
.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra... by
.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra....NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra...
.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra...Marc Müller
40 views62 slides
Software evolution understanding: Automatic extraction of software identifier... by
Software evolution understanding: Automatic extraction of software identifier...Software evolution understanding: Automatic extraction of software identifier...
Software evolution understanding: Automatic extraction of software identifier...Ra'Fat Al-Msie'deen
9 views33 slides
Agile 101 by
Agile 101Agile 101
Agile 101John Valentino
9 views20 slides
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports by
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug ReportsBushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug ReportsRa'Fat Al-Msie'deen
8 views49 slides
ShortStory_qlora.pptx by
ShortStory_qlora.pptxShortStory_qlora.pptx
ShortStory_qlora.pptxpranathikrishna22
5 views10 slides

Recently uploaded(20)

.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra... by Marc Müller
.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra....NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra...
.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra...
Marc Müller40 views
Software evolution understanding: Automatic extraction of software identifier... by Ra'Fat Al-Msie'deen
Software evolution understanding: Automatic extraction of software identifier...Software evolution understanding: Automatic extraction of software identifier...
Software evolution understanding: Automatic extraction of software identifier...
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports by Ra'Fat Al-Msie'deen
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug ReportsBushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI... by Marc Müller
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...
Marc Müller41 views
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx by animuscrm
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx
animuscrm15 views
Ports-and-Adapters Architecture for Embedded HMI by Burkhard Stubert
Ports-and-Adapters Architecture for Embedded HMIPorts-and-Adapters Architecture for Embedded HMI
Ports-and-Adapters Architecture for Embedded HMI
Burkhard Stubert21 views
Airline Booking Software by SharmiMehta
Airline Booking SoftwareAirline Booking Software
Airline Booking Software
SharmiMehta6 views
Dapr Unleashed: Accelerating Microservice Development by Miroslav Janeski
Dapr Unleashed: Accelerating Microservice DevelopmentDapr Unleashed: Accelerating Microservice Development
Dapr Unleashed: Accelerating Microservice Development
Miroslav Janeski10 views
Bootstrapping vs Venture Capital.pptx by Zeljko Svedic
Bootstrapping vs Venture Capital.pptxBootstrapping vs Venture Capital.pptx
Bootstrapping vs Venture Capital.pptx
Zeljko Svedic12 views
FOSSLight Community Day 2023-11-30 by Shane Coughlan
FOSSLight Community Day 2023-11-30FOSSLight Community Day 2023-11-30
FOSSLight Community Day 2023-11-30
Shane Coughlan5 views
Advanced API Mocking Techniques by Dimpy Adhikary
Advanced API Mocking TechniquesAdvanced API Mocking Techniques
Advanced API Mocking Techniques
Dimpy Adhikary19 views
predicting-m3-devopsconMunich-2023.pptx by Tier1 app
predicting-m3-devopsconMunich-2023.pptxpredicting-m3-devopsconMunich-2023.pptx
predicting-m3-devopsconMunich-2023.pptx
Tier1 app7 views
Quality Engineer: A Day in the Life by John Valentino
Quality Engineer: A Day in the LifeQuality Engineer: A Day in the Life
Quality Engineer: A Day in the Life
John Valentino6 views
Generic or specific? Making sensible software design decisions by Bert Jan Schrijver
Generic or specific? Making sensible software design decisionsGeneric or specific? Making sensible software design decisions
Generic or specific? Making sensible software design decisions

20140410 - Gestion des identités, traçabilité des accés - Analogie avec la qualité logicielle

  • 1. IT Security Services CONTROL FACTORY |BEHIND THE SCENES| Software Quality principles applied to Security Controls
  • 3. ENERGY GIANT / BUSINESS LINE / BUSINESS UNIT Integrated and dynamic management of portfolio – purchasing contracts, assets and sales contracts Management & Trading of Energy Client Business Environment
  • 4. REGULATORY/CONTROLS CONSTRAINTS Highly monitored and regularly audited activities Internal controls Compliance Legal External audits Group internal controls Business line controls Internal Compliance & Legal Risk Operations Internally driven Externally driven Various Auditors
  • 6. Security Controls governance  Discipline/Part of Corporate Governance focused on information technology (IT) oriented security controls aligned with business constraints Security Control book  An important element of a framework ensuring that the organization’s policies/requirements are formalized, monitored and implemented as controls over time  A centralization of security controls carried out on the organization  A tool-based methodology implementing the security control strategy FRAMING CONTROLS BASED ON REQUIREMENTS
  • 7. Controlsources Requirement Campaign 1 2 3 n n n n n n relationship | cardinality Report/Gap analysis needs Execution coverage Requirement coverage SECURITY CONTROLS | SOFTWARE QUALITY PRINCIPLES
  • 8. Standards Regulation Internal Framework In-house best practices Sources of requirements Risks Requirement 1 Requirement 2 Requirement 3 Requirement 4 Requirement “n” internal REG REG Internal IN HOUSE AUDIT … Sources of control Control 1 Control 2 REQ 1 REQ 2 REQ 1 REQ 4 Sourcesofcampaign Iteration 1 Campaign1 Control “n” REQ n REQ n Campaign “n” CTL n CTL 4 CTL n Sourcesofiterations Iteration 2 CAM 1 Iteration 1 Iteration 2 CAM 2 Requirement view Control view Campaign view Execution view Incidents CONTROL ECOSYSTEM CAM 1 CAM 2
  • 9. Title Description Criticality Category (Security, Business…) Owner Group/source (tag or ordering) Covered risk FRAMEWORK @ A GLANCE Requirement template
  • 10. Title Description Nature (administrative, technical, physical) Function (preventive, detective, corrective, recovery) Type (Security) Frequency Level (1 to 3) RACI matrix FRAMEWORK @ A GLANCE Control template
  • 11. Title Description Control suites (STU 1, STU 2,…) Assignee Planning Execution status Basic stats Control plan (CTL1, CTL2,…) FRAMEWORK @ A GLANCE Campaign template
  • 12. Controlsources Requirement Campaign 1 2 3 n n n n n n relationship | cardinality Report/Gap analysis needs Execution coverage Requirement coverage    - Requirements covered by controls ? - All controls associated to requirement ? - Controls executed as expected ? - Execution coverage of requirement ?   SECURITY CONTROLS | SOFTWARE QUALITY PRINCIPLES
  • 14. CONTROL FACTORY | DEFINE refers to : Control Factory (CF) a structured collection of assets that aids in producing controls through an assembly process according to specific requirements1 3 2 4 The Control factory applies manufacturing techniques and principles … > Formalization > Automation > Services Oriented > Industrialization Right process  right result Reduce manual intervention Activities divided in services Reusable components
  • 15. CONTROL FACTORY | OBJECTIVES … to mimic the benefits of traditional manufacturing >Consistency build multiple instances of a control product line & set of controls sharing similar “features and architecture” >Quality integrates reusable controls reducing the likelihood of control design flaws >Productivity Controls activities can be streamlined and automated
  • 16. Conception Design and logic according to requirements Suppliers relationship Sourcing of data, qualification, remediation Production Producing resources for controls reports, dashboards Delivery Making resources for controls available Supervision Governing controls campaign and remediation Internal QA, maintenance, improvements CONTROL FACTORY | ACTIVITIES/SERVICES Customers
  • 17. CONTROL FACTORY | PRODUCTION SERVICES Control Production Production is divided in 6 distinct stages : Supply Raw data from multiple collect sources Compute Loading, ordering & storing data Reconcile Identities vs. accounts Control Production of control resources SoD Advanced controls Report Presenting results as expected
  • 18. PRODUCTION SERVICES| SUPPLY Supply … loading raw data, reconciliation, mapping and ordering for reuse Controlsfactory Advanced controls Reports/views Controls Data Reconciliation Compute 2 3 1 Attaching identities to respective unitary organization Reconciling identities with accounts, perms… Producing controls in the factory Reporting results in expected views 4 …
  • 19. PRODUCTION SERVICES| REPORT Report … presenting control data as requested (format & delivery) • Timeslots • Reports • Data exports Web portal • Reports sent to reviewers Campaign
  • 20. Data Lifecycle Data Quality Data Volume Business Activity CONTROLS GOVERNANCE | FOCUS ON PITFALLS  Reduce treatment time from import to remediation  Based on reliable data, readable and understandable  Deeply analyzed and divided i.e. volume that are “control ready” and “supervision ready”  Better integration of stakeholders processes
  • 21. › Ergonomics and design › Administration › Dashboard & Reporting › Automation CAMPAIGN & CONTROLS | ANALYSIS › Tickets directly created and assigned › Follow-up using the factory › Dynamic reports (web interfaces) › Point and click review › Enriched information › Delegation mechanism enhanced › Improved planning and review mechanism Orientations and improvements › Automated and real-time › Web-based dashboard
  • 22. ITSecurityServices THANK U / QUESTIONS CONTROL FACTORY |BEHIND THE SCENES|