SlideShare a Scribd company logo
1 of 21
1 
Balancing 
Compliance and 
Experimentation 
@jemolesky #LeanEnterprise
2 
Understanding 
Compliance
Laws, regulations and management 
Business 
Laws & 
Regulations 
Frameworks, 
Standards 
Mandated 
Compliance 
Guidance 
Influence 
Influence 
Influence 
Management 
Policies 
Process 
Controls
Avoid risk management theatre 
4 
• One process to rule them all 
• Success is following the process 
• Stops people from getting their work done 
• Pass the audit 
• Lack of responsibility
5 
Everyone owns this
6 
Finding the Balance - 
Apply Lean Principles to GRC
7 
Create a shared understanding
The way we work should determine controls 
Taliesen http://mrg.bz.ziSMzq 
8 
Rollingroscoe http://mrg.bz.vOsu5e 
Kconnors http://bz/PY1Jni
9 
Map the value stream 
• End to end value delivery 
• Identify times 
• Encourages collaboration 
• Measure improvement
Consider GRC from the beginning 
10 
• Type of Information 
• Take a risk based approach 
• Control access 
• Mastery and craftsmanship 
• GRC specialist are part of the team
Traditional security compliance 
UAT Test 
Backlog 
In dev 
Analysis 
Prod CI 
Code review 
Manual security 
testing 
Pen 
Test
Risk based security compliance 
Security 
stories, 
AC 
Inception 
Test 
In dev 
Analysis 
UAT 
Prod 
High Level – obligations, 
adversaries, assets, 
disaster scenarios 
Threat model & 
risk matrix 
Coding 
guidelines, 
pairing, code 
reviews 
CI 
Manual 
security testing 
Pen 
test 
Automated code 
analysis, security 
proxy, model 
verification 
Logs, 
Firewall, 
IDS, 
WAF,IPS
Seek controls that maintain flow 
13 
• Right level of granularity 
• Decisions by responsible people 
• Boundaries defined 
• Risk based controls 
• Contain the blast area 
• Use compensating controls
Create visibility and transparency 
14 
• Demand participation 
• Leave a trail of evidence 
• Visible means visible 
• Be disciplined, be consistent
15
16 
Experiment - start small and build out
17 
Gov.uk alpha design principles 
• Don’t slow down delivery 
• Decision when they are needed and at the 
right level 
• Do it with the right people 
• Go see for yourself 
• Only do it if it adds value 
• Trust and verify 
https://digitaltransformation.blog.gov.uk/2014/06/24/governance-principles/
18 
Seek Perfection 
PatriciaEGreen2 http://mrg.bz/7YvKW7
19 
Most significant challenges 
• Organizational structure not designed for 
fast pace of digital demands 
• Business process too inflexible to take 
advantage of new opportunities 
• Inability to adopt an experimental mind-set 
that is key for best practices 
http://www.mckinsey.com/insights/business_technology/The_digital_tippingbusiness_point_McKinsey_Global_Survey_results
20 
Conclusion 
Manage risks, not compliance 
 
Seek controls that match the way we 
work 
 
Create a shared understanding and cross 
collaboration 
 
Visualize and create flow
Thank you - Questions? 
http://bit.ly/leanentp 
@jemolesky | @barryoreilly 
#leanenterprise | @jezhumble

More Related Content

What's hot

Getting Executive Support for a Software Security Program
Getting Executive Support for a Software Security ProgramGetting Executive Support for a Software Security Program
Getting Executive Support for a Software Security ProgramCigital
 
Cyber Defence - Service portfolio
Cyber Defence - Service portfolioCyber Defence - Service portfolio
Cyber Defence - Service portfolioKaloyan Krastev
 
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...Iceberg Networks Corporation
 
Software Security Metrics
Software Security MetricsSoftware Security Metrics
Software Security MetricsCigital
 
Perforce on Tour 2015 - How are You Protecting Your Source Code?
Perforce on Tour 2015 - How are You Protecting Your Source Code?Perforce on Tour 2015 - How are You Protecting Your Source Code?
Perforce on Tour 2015 - How are You Protecting Your Source Code?Perforce
 
Anton's Log Management 'Worst Practices'
Anton's Log Management 'Worst Practices'Anton's Log Management 'Worst Practices'
Anton's Log Management 'Worst Practices'Anton Chuvakin
 
451 and Cylance - The Roadmap To Better Endpoint Security
451 and Cylance - The Roadmap To Better Endpoint Security451 and Cylance - The Roadmap To Better Endpoint Security
451 and Cylance - The Roadmap To Better Endpoint SecurityAdrian Sanabria
 
Introduction to yT
Introduction to yTIntroduction to yT
Introduction to yTbsechrist
 
7 Lessons Learned From BSIMM
7 Lessons Learned From BSIMM7 Lessons Learned From BSIMM
7 Lessons Learned From BSIMMCigital
 
Meta-Metrics: Building a Scorecard for the Evaluation of Security Management ...
Meta-Metrics: Building a Scorecard for the Evaluation of Security Management ...Meta-Metrics: Building a Scorecard for the Evaluation of Security Management ...
Meta-Metrics: Building a Scorecard for the Evaluation of Security Management ...Michael Smith
 

What's hot (10)

Getting Executive Support for a Software Security Program
Getting Executive Support for a Software Security ProgramGetting Executive Support for a Software Security Program
Getting Executive Support for a Software Security Program
 
Cyber Defence - Service portfolio
Cyber Defence - Service portfolioCyber Defence - Service portfolio
Cyber Defence - Service portfolio
 
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
 
Software Security Metrics
Software Security MetricsSoftware Security Metrics
Software Security Metrics
 
Perforce on Tour 2015 - How are You Protecting Your Source Code?
Perforce on Tour 2015 - How are You Protecting Your Source Code?Perforce on Tour 2015 - How are You Protecting Your Source Code?
Perforce on Tour 2015 - How are You Protecting Your Source Code?
 
Anton's Log Management 'Worst Practices'
Anton's Log Management 'Worst Practices'Anton's Log Management 'Worst Practices'
Anton's Log Management 'Worst Practices'
 
451 and Cylance - The Roadmap To Better Endpoint Security
451 and Cylance - The Roadmap To Better Endpoint Security451 and Cylance - The Roadmap To Better Endpoint Security
451 and Cylance - The Roadmap To Better Endpoint Security
 
Introduction to yT
Introduction to yTIntroduction to yT
Introduction to yT
 
7 Lessons Learned From BSIMM
7 Lessons Learned From BSIMM7 Lessons Learned From BSIMM
7 Lessons Learned From BSIMM
 
Meta-Metrics: Building a Scorecard for the Evaluation of Security Management ...
Meta-Metrics: Building a Scorecard for the Evaluation of Security Management ...Meta-Metrics: Building a Scorecard for the Evaluation of Security Management ...
Meta-Metrics: Building a Scorecard for the Evaluation of Security Management ...
 

Viewers also liked

Mobile Experiments: Easier Than You Think by Sheena Allen - The Lean Startup ...
Mobile Experiments: Easier Than You Think by Sheena Allen - The Lean Startup ...Mobile Experiments: Easier Than You Think by Sheena Allen - The Lean Startup ...
Mobile Experiments: Easier Than You Think by Sheena Allen - The Lean Startup ...Lean Startup Co.
 
Become a Better Listener, Build More Profitable Products by Jana Eggers - The...
Become a Better Listener, Build More Profitable Products by Jana Eggers - The...Become a Better Listener, Build More Profitable Products by Jana Eggers - The...
Become a Better Listener, Build More Profitable Products by Jana Eggers - The...Lean Startup Co.
 
MVPs You Can Learn From by Bill Gross - The Lean Startup Conference 12/10/14
MVPs You Can Learn From by Bill Gross - The Lean Startup Conference 12/10/14MVPs You Can Learn From by Bill Gross - The Lean Startup Conference 12/10/14
MVPs You Can Learn From by Bill Gross - The Lean Startup Conference 12/10/14Lean Startup Co.
 
Look Past Biases to Measure the Right Metrics by Ellynita Lamin - The Lean St...
Look Past Biases to Measure the Right Metrics by Ellynita Lamin - The Lean St...Look Past Biases to Measure the Right Metrics by Ellynita Lamin - The Lean St...
Look Past Biases to Measure the Right Metrics by Ellynita Lamin - The Lean St...Lean Startup Co.
 
An Experiment on Stage by Susana Jurado and Maria Olano - The Lean Startup Co...
An Experiment on Stage by Susana Jurado and Maria Olano - The Lean Startup Co...An Experiment on Stage by Susana Jurado and Maria Olano - The Lean Startup Co...
An Experiment on Stage by Susana Jurado and Maria Olano - The Lean Startup Co...Lean Startup Co.
 
Using Remote Tools for Customer Development by Holly DeWolf - The Lean Startu...
Using Remote Tools for Customer Development by Holly DeWolf - The Lean Startu...Using Remote Tools for Customer Development by Holly DeWolf - The Lean Startu...
Using Remote Tools for Customer Development by Holly DeWolf - The Lean Startu...Lean Startup Co.
 
Turn Lawyers into Allies by Sean Butler - The Lean Startup Conference 12/11/14
Turn Lawyers into Allies by Sean Butler - The Lean Startup Conference 12/11/14Turn Lawyers into Allies by Sean Butler - The Lean Startup Conference 12/11/14
Turn Lawyers into Allies by Sean Butler - The Lean Startup Conference 12/11/14Lean Startup Co.
 
How HP Shipped Faster--Much Faster by Kathryn Kuhn - The Lean Startup Confere...
How HP Shipped Faster--Much Faster by Kathryn Kuhn - The Lean Startup Confere...How HP Shipped Faster--Much Faster by Kathryn Kuhn - The Lean Startup Confere...
How HP Shipped Faster--Much Faster by Kathryn Kuhn - The Lean Startup Confere...Lean Startup Co.
 
Lean Impact–Lean Startup for Mission-driven Organizations by Leanne Pittsford...
Lean Impact–Lean Startup for Mission-driven Organizations by Leanne Pittsford...Lean Impact–Lean Startup for Mission-driven Organizations by Leanne Pittsford...
Lean Impact–Lean Startup for Mission-driven Organizations by Leanne Pittsford...Lean Startup Co.
 
Laura Busche - The Lean Startup Conference 12/9/14
Laura Busche - The Lean Startup Conference 12/9/14Laura Busche - The Lean Startup Conference 12/9/14
Laura Busche - The Lean Startup Conference 12/9/14Lean Startup Co.
 
Build a Technical Infrastructure that Supports Innovation by Florian Motlik -...
Build a Technical Infrastructure that Supports Innovation by Florian Motlik -...Build a Technical Infrastructure that Supports Innovation by Florian Motlik -...
Build a Technical Infrastructure that Supports Innovation by Florian Motlik -...Lean Startup Co.
 
Startup Metrics: The Data That Will Make or Break Your Business by Alistair C...
Startup Metrics: The Data That Will Make or Break Your Business by Alistair C...Startup Metrics: The Data That Will Make or Break Your Business by Alistair C...
Startup Metrics: The Data That Will Make or Break Your Business by Alistair C...Lean Startup Co.
 
Integrate Customer Feedback Into Your Product by Greg Nelson - The Lean Start...
Integrate Customer Feedback Into Your Product by Greg Nelson - The Lean Start...Integrate Customer Feedback Into Your Product by Greg Nelson - The Lean Start...
Integrate Customer Feedback Into Your Product by Greg Nelson - The Lean Start...Lean Startup Co.
 
Build a Culture that Outsmarts Perfectionism by Seppo Helava - The Lean Start...
Build a Culture that Outsmarts Perfectionism by Seppo Helava - The Lean Start...Build a Culture that Outsmarts Perfectionism by Seppo Helava - The Lean Start...
Build a Culture that Outsmarts Perfectionism by Seppo Helava - The Lean Start...Lean Startup Co.
 
Reinvent Decision Making at Established Institutions by Allison Dulin-Salisbu...
Reinvent Decision Making at Established Institutions by Allison Dulin-Salisbu...Reinvent Decision Making at Established Institutions by Allison Dulin-Salisbu...
Reinvent Decision Making at Established Institutions by Allison Dulin-Salisbu...Lean Startup Co.
 
Launch a New Product that Doesn't Hurt Your Existing Brand by Andrew Homeyer ...
Launch a New Product that Doesn't Hurt Your Existing Brand by Andrew Homeyer ...Launch a New Product that Doesn't Hurt Your Existing Brand by Andrew Homeyer ...
Launch a New Product that Doesn't Hurt Your Existing Brand by Andrew Homeyer ...Lean Startup Co.
 
Design Your Way to Product/Market Fit by Christina Wodtke - The Lean Startup ...
Design Your Way to Product/Market Fit by Christina Wodtke - The Lean Startup ...Design Your Way to Product/Market Fit by Christina Wodtke - The Lean Startup ...
Design Your Way to Product/Market Fit by Christina Wodtke - The Lean Startup ...Lean Startup Co.
 
Use Lean Startup Techniques on a Remote Team by William Donnell - The Lean St...
Use Lean Startup Techniques on a Remote Team by William Donnell - The Lean St...Use Lean Startup Techniques on a Remote Team by William Donnell - The Lean St...
Use Lean Startup Techniques on a Remote Team by William Donnell - The Lean St...Lean Startup Co.
 
How Staying Lean Made Us Big, Michael Perry, Shopify
How Staying Lean Made Us Big, Michael Perry, ShopifyHow Staying Lean Made Us Big, Michael Perry, Shopify
How Staying Lean Made Us Big, Michael Perry, ShopifyLean Startup Co.
 
Case Study: Lean Product Development in a Very Big Organization by Susana Jur...
Case Study: Lean Product Development in a Very Big Organization by Susana Jur...Case Study: Lean Product Development in a Very Big Organization by Susana Jur...
Case Study: Lean Product Development in a Very Big Organization by Susana Jur...Lean Startup Co.
 

Viewers also liked (20)

Mobile Experiments: Easier Than You Think by Sheena Allen - The Lean Startup ...
Mobile Experiments: Easier Than You Think by Sheena Allen - The Lean Startup ...Mobile Experiments: Easier Than You Think by Sheena Allen - The Lean Startup ...
Mobile Experiments: Easier Than You Think by Sheena Allen - The Lean Startup ...
 
Become a Better Listener, Build More Profitable Products by Jana Eggers - The...
Become a Better Listener, Build More Profitable Products by Jana Eggers - The...Become a Better Listener, Build More Profitable Products by Jana Eggers - The...
Become a Better Listener, Build More Profitable Products by Jana Eggers - The...
 
MVPs You Can Learn From by Bill Gross - The Lean Startup Conference 12/10/14
MVPs You Can Learn From by Bill Gross - The Lean Startup Conference 12/10/14MVPs You Can Learn From by Bill Gross - The Lean Startup Conference 12/10/14
MVPs You Can Learn From by Bill Gross - The Lean Startup Conference 12/10/14
 
Look Past Biases to Measure the Right Metrics by Ellynita Lamin - The Lean St...
Look Past Biases to Measure the Right Metrics by Ellynita Lamin - The Lean St...Look Past Biases to Measure the Right Metrics by Ellynita Lamin - The Lean St...
Look Past Biases to Measure the Right Metrics by Ellynita Lamin - The Lean St...
 
An Experiment on Stage by Susana Jurado and Maria Olano - The Lean Startup Co...
An Experiment on Stage by Susana Jurado and Maria Olano - The Lean Startup Co...An Experiment on Stage by Susana Jurado and Maria Olano - The Lean Startup Co...
An Experiment on Stage by Susana Jurado and Maria Olano - The Lean Startup Co...
 
Using Remote Tools for Customer Development by Holly DeWolf - The Lean Startu...
Using Remote Tools for Customer Development by Holly DeWolf - The Lean Startu...Using Remote Tools for Customer Development by Holly DeWolf - The Lean Startu...
Using Remote Tools for Customer Development by Holly DeWolf - The Lean Startu...
 
Turn Lawyers into Allies by Sean Butler - The Lean Startup Conference 12/11/14
Turn Lawyers into Allies by Sean Butler - The Lean Startup Conference 12/11/14Turn Lawyers into Allies by Sean Butler - The Lean Startup Conference 12/11/14
Turn Lawyers into Allies by Sean Butler - The Lean Startup Conference 12/11/14
 
How HP Shipped Faster--Much Faster by Kathryn Kuhn - The Lean Startup Confere...
How HP Shipped Faster--Much Faster by Kathryn Kuhn - The Lean Startup Confere...How HP Shipped Faster--Much Faster by Kathryn Kuhn - The Lean Startup Confere...
How HP Shipped Faster--Much Faster by Kathryn Kuhn - The Lean Startup Confere...
 
Lean Impact–Lean Startup for Mission-driven Organizations by Leanne Pittsford...
Lean Impact–Lean Startup for Mission-driven Organizations by Leanne Pittsford...Lean Impact–Lean Startup for Mission-driven Organizations by Leanne Pittsford...
Lean Impact–Lean Startup for Mission-driven Organizations by Leanne Pittsford...
 
Laura Busche - The Lean Startup Conference 12/9/14
Laura Busche - The Lean Startup Conference 12/9/14Laura Busche - The Lean Startup Conference 12/9/14
Laura Busche - The Lean Startup Conference 12/9/14
 
Build a Technical Infrastructure that Supports Innovation by Florian Motlik -...
Build a Technical Infrastructure that Supports Innovation by Florian Motlik -...Build a Technical Infrastructure that Supports Innovation by Florian Motlik -...
Build a Technical Infrastructure that Supports Innovation by Florian Motlik -...
 
Startup Metrics: The Data That Will Make or Break Your Business by Alistair C...
Startup Metrics: The Data That Will Make or Break Your Business by Alistair C...Startup Metrics: The Data That Will Make or Break Your Business by Alistair C...
Startup Metrics: The Data That Will Make or Break Your Business by Alistair C...
 
Integrate Customer Feedback Into Your Product by Greg Nelson - The Lean Start...
Integrate Customer Feedback Into Your Product by Greg Nelson - The Lean Start...Integrate Customer Feedback Into Your Product by Greg Nelson - The Lean Start...
Integrate Customer Feedback Into Your Product by Greg Nelson - The Lean Start...
 
Build a Culture that Outsmarts Perfectionism by Seppo Helava - The Lean Start...
Build a Culture that Outsmarts Perfectionism by Seppo Helava - The Lean Start...Build a Culture that Outsmarts Perfectionism by Seppo Helava - The Lean Start...
Build a Culture that Outsmarts Perfectionism by Seppo Helava - The Lean Start...
 
Reinvent Decision Making at Established Institutions by Allison Dulin-Salisbu...
Reinvent Decision Making at Established Institutions by Allison Dulin-Salisbu...Reinvent Decision Making at Established Institutions by Allison Dulin-Salisbu...
Reinvent Decision Making at Established Institutions by Allison Dulin-Salisbu...
 
Launch a New Product that Doesn't Hurt Your Existing Brand by Andrew Homeyer ...
Launch a New Product that Doesn't Hurt Your Existing Brand by Andrew Homeyer ...Launch a New Product that Doesn't Hurt Your Existing Brand by Andrew Homeyer ...
Launch a New Product that Doesn't Hurt Your Existing Brand by Andrew Homeyer ...
 
Design Your Way to Product/Market Fit by Christina Wodtke - The Lean Startup ...
Design Your Way to Product/Market Fit by Christina Wodtke - The Lean Startup ...Design Your Way to Product/Market Fit by Christina Wodtke - The Lean Startup ...
Design Your Way to Product/Market Fit by Christina Wodtke - The Lean Startup ...
 
Use Lean Startup Techniques on a Remote Team by William Donnell - The Lean St...
Use Lean Startup Techniques on a Remote Team by William Donnell - The Lean St...Use Lean Startup Techniques on a Remote Team by William Donnell - The Lean St...
Use Lean Startup Techniques on a Remote Team by William Donnell - The Lean St...
 
How Staying Lean Made Us Big, Michael Perry, Shopify
How Staying Lean Made Us Big, Michael Perry, ShopifyHow Staying Lean Made Us Big, Michael Perry, Shopify
How Staying Lean Made Us Big, Michael Perry, Shopify
 
Case Study: Lean Product Development in a Very Big Organization by Susana Jur...
Case Study: Lean Product Development in a Very Big Organization by Susana Jur...Case Study: Lean Product Development in a Very Big Organization by Susana Jur...
Case Study: Lean Product Development in a Very Big Organization by Susana Jur...
 

Similar to Balance Compliance and Experimentation by Joanne Molesky - The Lean Startup Conference 12/11/14

Caveon Webinar Series - Security Challenges in Creating Testing Programs - Se...
Caveon Webinar Series - Security Challenges in Creating Testing Programs - Se...Caveon Webinar Series - Security Challenges in Creating Testing Programs - Se...
Caveon Webinar Series - Security Challenges in Creating Testing Programs - Se...Caveon Test Security
 
Building an effective Information Security Roadmap
Building an effective Information Security RoadmapBuilding an effective Information Security Roadmap
Building an effective Information Security RoadmapElliott Franklin
 
Top Security Challenges Facing Credit Unions Today
Top Security Challenges Facing Credit Unions TodayTop Security Challenges Facing Credit Unions Today
Top Security Challenges Facing Credit Unions TodayChris Gates
 
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]Barun Kumar
 
GDPR | Cyber security process resilience
GDPR | Cyber security process resilienceGDPR | Cyber security process resilience
GDPR | Cyber security process resilienceRishi Kant
 
LEAN: Dream Maker Developments
LEAN: Dream Maker DevelopmentsLEAN: Dream Maker Developments
LEAN: Dream Maker DevelopmentsVadim Davydov
 
Вадим Давидов та Людмила Гребенюк “LEAN: Dream Maker Developments” Kharkiv Pr...
Вадим Давидов та Людмила Гребенюк “LEAN: Dream Maker Developments” Kharkiv Pr...Вадим Давидов та Людмила Гребенюк “LEAN: Dream Maker Developments” Kharkiv Pr...
Вадим Давидов та Людмила Гребенюк “LEAN: Dream Maker Developments” Kharkiv Pr...Lviv Startup Club
 
Anatomy Of A Breach: The Good, The Bad & The Ugly
Anatomy Of A Breach: The Good, The Bad & The UglyAnatomy Of A Breach: The Good, The Bad & The Ugly
Anatomy Of A Breach: The Good, The Bad & The UglyResilient Systems
 
Security Program Guidance and Establishing a Culture of Security
Security Program Guidance and Establishing a Culture of SecuritySecurity Program Guidance and Establishing a Culture of Security
Security Program Guidance and Establishing a Culture of SecurityDoug Copley
 
Building an Effective Data Privacy Program – 6 Steps from TRUSTe
Building an Effective Data Privacy Program – 6 Steps from TRUSTeBuilding an Effective Data Privacy Program – 6 Steps from TRUSTe
Building an Effective Data Privacy Program – 6 Steps from TRUSTeTrustArc
 
Cyber security series vulnerability assessments
Cyber security series   vulnerability assessmentsCyber security series   vulnerability assessments
Cyber security series vulnerability assessmentsJim Kaplan CIA CFE
 
Role of the virtual ciso
Role of the virtual cisoRole of the virtual ciso
Role of the virtual cisoMichael Ball
 
Just Trust Everyone and We Will Be Fine, Right?
Just Trust Everyone and We Will Be Fine, Right?Just Trust Everyone and We Will Be Fine, Right?
Just Trust Everyone and We Will Be Fine, Right?Scott Carlson
 
The State Of Information and Cyber Security in 2016
The State Of Information and Cyber Security in 2016The State Of Information and Cyber Security in 2016
The State Of Information and Cyber Security in 2016Shannon G., MBA
 
Agile Development Product Delivery For Successful Organizations
Agile Development Product Delivery For Successful OrganizationsAgile Development Product Delivery For Successful Organizations
Agile Development Product Delivery For Successful OrganizationsMarc Crudgington, MBA
 
How To Stop Target-Like Breaches In Their Tracks
How To Stop Target-Like Breaches In Their TracksHow To Stop Target-Like Breaches In Their Tracks
How To Stop Target-Like Breaches In Their TracksResilient Systems
 
Caveon Webinar Series - Creating Your Test Security Game Plan - March 2016
Caveon Webinar Series -  Creating Your Test Security Game Plan - March 2016Caveon Webinar Series -  Creating Your Test Security Game Plan - March 2016
Caveon Webinar Series - Creating Your Test Security Game Plan - March 2016Caveon Test Security
 
How to Centre your PCI Programme Around your Business Objective - SureCloud
How to Centre your PCI Programme Around your Business Objective - SureCloud How to Centre your PCI Programme Around your Business Objective - SureCloud
How to Centre your PCI Programme Around your Business Objective - SureCloud SureCloud
 
Decrease Cyber Risk at your Community Bank
Decrease Cyber Risk at your Community BankDecrease Cyber Risk at your Community Bank
Decrease Cyber Risk at your Community BankGreat Bay Software
 
Gain business insight with Continuous Controls Monitoring
Gain business insight with Continuous Controls MonitoringGain business insight with Continuous Controls Monitoring
Gain business insight with Continuous Controls MonitoringEmma Kelly
 

Similar to Balance Compliance and Experimentation by Joanne Molesky - The Lean Startup Conference 12/11/14 (20)

Caveon Webinar Series - Security Challenges in Creating Testing Programs - Se...
Caveon Webinar Series - Security Challenges in Creating Testing Programs - Se...Caveon Webinar Series - Security Challenges in Creating Testing Programs - Se...
Caveon Webinar Series - Security Challenges in Creating Testing Programs - Se...
 
Building an effective Information Security Roadmap
Building an effective Information Security RoadmapBuilding an effective Information Security Roadmap
Building an effective Information Security Roadmap
 
Top Security Challenges Facing Credit Unions Today
Top Security Challenges Facing Credit Unions TodayTop Security Challenges Facing Credit Unions Today
Top Security Challenges Facing Credit Unions Today
 
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
 
GDPR | Cyber security process resilience
GDPR | Cyber security process resilienceGDPR | Cyber security process resilience
GDPR | Cyber security process resilience
 
LEAN: Dream Maker Developments
LEAN: Dream Maker DevelopmentsLEAN: Dream Maker Developments
LEAN: Dream Maker Developments
 
Вадим Давидов та Людмила Гребенюк “LEAN: Dream Maker Developments” Kharkiv Pr...
Вадим Давидов та Людмила Гребенюк “LEAN: Dream Maker Developments” Kharkiv Pr...Вадим Давидов та Людмила Гребенюк “LEAN: Dream Maker Developments” Kharkiv Pr...
Вадим Давидов та Людмила Гребенюк “LEAN: Dream Maker Developments” Kharkiv Pr...
 
Anatomy Of A Breach: The Good, The Bad & The Ugly
Anatomy Of A Breach: The Good, The Bad & The UglyAnatomy Of A Breach: The Good, The Bad & The Ugly
Anatomy Of A Breach: The Good, The Bad & The Ugly
 
Security Program Guidance and Establishing a Culture of Security
Security Program Guidance and Establishing a Culture of SecuritySecurity Program Guidance and Establishing a Culture of Security
Security Program Guidance and Establishing a Culture of Security
 
Building an Effective Data Privacy Program – 6 Steps from TRUSTe
Building an Effective Data Privacy Program – 6 Steps from TRUSTeBuilding an Effective Data Privacy Program – 6 Steps from TRUSTe
Building an Effective Data Privacy Program – 6 Steps from TRUSTe
 
Cyber security series vulnerability assessments
Cyber security series   vulnerability assessmentsCyber security series   vulnerability assessments
Cyber security series vulnerability assessments
 
Role of the virtual ciso
Role of the virtual cisoRole of the virtual ciso
Role of the virtual ciso
 
Just Trust Everyone and We Will Be Fine, Right?
Just Trust Everyone and We Will Be Fine, Right?Just Trust Everyone and We Will Be Fine, Right?
Just Trust Everyone and We Will Be Fine, Right?
 
The State Of Information and Cyber Security in 2016
The State Of Information and Cyber Security in 2016The State Of Information and Cyber Security in 2016
The State Of Information and Cyber Security in 2016
 
Agile Development Product Delivery For Successful Organizations
Agile Development Product Delivery For Successful OrganizationsAgile Development Product Delivery For Successful Organizations
Agile Development Product Delivery For Successful Organizations
 
How To Stop Target-Like Breaches In Their Tracks
How To Stop Target-Like Breaches In Their TracksHow To Stop Target-Like Breaches In Their Tracks
How To Stop Target-Like Breaches In Their Tracks
 
Caveon Webinar Series - Creating Your Test Security Game Plan - March 2016
Caveon Webinar Series -  Creating Your Test Security Game Plan - March 2016Caveon Webinar Series -  Creating Your Test Security Game Plan - March 2016
Caveon Webinar Series - Creating Your Test Security Game Plan - March 2016
 
How to Centre your PCI Programme Around your Business Objective - SureCloud
How to Centre your PCI Programme Around your Business Objective - SureCloud How to Centre your PCI Programme Around your Business Objective - SureCloud
How to Centre your PCI Programme Around your Business Objective - SureCloud
 
Decrease Cyber Risk at your Community Bank
Decrease Cyber Risk at your Community BankDecrease Cyber Risk at your Community Bank
Decrease Cyber Risk at your Community Bank
 
Gain business insight with Continuous Controls Monitoring
Gain business insight with Continuous Controls MonitoringGain business insight with Continuous Controls Monitoring
Gain business insight with Continuous Controls Monitoring
 

More from Lean Startup Co.

A5: Designing Gamified Experiences to Gain Customer Insights, Richardo Chen &...
A5: Designing Gamified Experiences to Gain Customer Insights, Richardo Chen &...A5: Designing Gamified Experiences to Gain Customer Insights, Richardo Chen &...
A5: Designing Gamified Experiences to Gain Customer Insights, Richardo Chen &...Lean Startup Co.
 
Keynote: The Subscription Economy: How to Survive the End of Ownership, Tien ...
Keynote: The Subscription Economy: How to Survive the End of Ownership, Tien ...Keynote: The Subscription Economy: How to Survive the End of Ownership, Tien ...
Keynote: The Subscription Economy: How to Survive the End of Ownership, Tien ...Lean Startup Co.
 
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...Lean Startup Co.
 
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...Lean Startup Co.
 
Keynote: Innovation is a Habit, not a Mindset, Diana Kander
Keynote: Innovation is a Habit, not a Mindset, Diana KanderKeynote: Innovation is a Habit, not a Mindset, Diana Kander
Keynote: Innovation is a Habit, not a Mindset, Diana KanderLean Startup Co.
 
F3: Employee = Founder: Building a Startup inside a Fortune 500 Company, Max-...
F3: Employee = Founder: Building a Startup inside a Fortune 500 Company, Max-...F3: Employee = Founder: Building a Startup inside a Fortune 500 Company, Max-...
F3: Employee = Founder: Building a Startup inside a Fortune 500 Company, Max-...Lean Startup Co.
 
G3: Reflecting on My Failure to Build a Billion Dollar Company, Sahil Lavingia
G3: Reflecting on My Failure to Build a Billion Dollar Company, Sahil LavingiaG3: Reflecting on My Failure to Build a Billion Dollar Company, Sahil Lavingia
G3: Reflecting on My Failure to Build a Billion Dollar Company, Sahil LavingiaLean Startup Co.
 
C3: Optimize, Grow or Catapult: Where to Target Your Organization’s Innovatio...
C3: Optimize, Grow or Catapult: Where to Target Your Organization’s Innovatio...C3: Optimize, Grow or Catapult: Where to Target Your Organization’s Innovatio...
C3: Optimize, Grow or Catapult: Where to Target Your Organization’s Innovatio...Lean Startup Co.
 
G6: Getting Leaders On Board: Don’t Let Your Innovation Program be Pronounced...
G6: Getting Leaders On Board: Don’t Let Your Innovation Program be Pronounced...G6: Getting Leaders On Board: Don’t Let Your Innovation Program be Pronounced...
G6: Getting Leaders On Board: Don’t Let Your Innovation Program be Pronounced...Lean Startup Co.
 
E3: Amazon’s Approach to Culture Change, Wen Huang, Eric Tachibana
E3: Amazon’s Approach to Culture Change, Wen Huang, Eric TachibanaE3: Amazon’s Approach to Culture Change, Wen Huang, Eric Tachibana
E3: Amazon’s Approach to Culture Change, Wen Huang, Eric TachibanaLean Startup Co.
 
G1: Brackitz Toy Story: Learning From Mistakes and Mental Models for Success,...
G1: Brackitz Toy Story: Learning From Mistakes and Mental Models for Success,...G1: Brackitz Toy Story: Learning From Mistakes and Mental Models for Success,...
G1: Brackitz Toy Story: Learning From Mistakes and Mental Models for Success,...Lean Startup Co.
 
D5: Be the Solution: Use Lean to Solve Community Problems, Katrina Medoff
D5: Be the Solution: Use Lean to Solve Community Problems, Katrina MedoffD5: Be the Solution: Use Lean to Solve Community Problems, Katrina Medoff
D5: Be the Solution: Use Lean to Solve Community Problems, Katrina MedoffLean Startup Co.
 
F1: Mastering the Art of Telling Your Story, Jamie Lazzeri
F1: Mastering the Art of Telling Your Story, Jamie LazzeriF1: Mastering the Art of Telling Your Story, Jamie Lazzeri
F1: Mastering the Art of Telling Your Story, Jamie LazzeriLean Startup Co.
 
Keynote: Intelligent Growth in Startups: Building More Than a Product to Get ...
Keynote: Intelligent Growth in Startups: Building More Than a Product to Get ...Keynote: Intelligent Growth in Startups: Building More Than a Product to Get ...
Keynote: Intelligent Growth in Startups: Building More Than a Product to Get ...Lean Startup Co.
 
Keynote: From Founder to Investor: Stories From the Trenches of Entrepreneurs...
Keynote: From Founder to Investor: Stories From the Trenches of Entrepreneurs...Keynote: From Founder to Investor: Stories From the Trenches of Entrepreneurs...
Keynote: From Founder to Investor: Stories From the Trenches of Entrepreneurs...Lean Startup Co.
 
G5: Big Problems Require Big Solutions: the Story of Earn, Leigh Phillips
G5: Big Problems Require Big Solutions: the Story of Earn, Leigh PhillipsG5: Big Problems Require Big Solutions: the Story of Earn, Leigh Phillips
G5: Big Problems Require Big Solutions: the Story of Earn, Leigh PhillipsLean Startup Co.
 
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...Lean Startup Co.
 
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...Lean Startup Co.
 
B5: The 8 Deadly Maladies of Rapid Experimentation, Lukas Oberhuber
B5: The 8 Deadly Maladies of Rapid Experimentation, Lukas OberhuberB5: The 8 Deadly Maladies of Rapid Experimentation, Lukas Oberhuber
B5: The 8 Deadly Maladies of Rapid Experimentation, Lukas OberhuberLean Startup Co.
 
B4: The Road to Startup Success is Paved in Pivots, Kate Skavish
B4: The Road to Startup Success is Paved in Pivots, Kate Skavish B4: The Road to Startup Success is Paved in Pivots, Kate Skavish
B4: The Road to Startup Success is Paved in Pivots, Kate Skavish Lean Startup Co.
 

More from Lean Startup Co. (20)

A5: Designing Gamified Experiences to Gain Customer Insights, Richardo Chen &...
A5: Designing Gamified Experiences to Gain Customer Insights, Richardo Chen &...A5: Designing Gamified Experiences to Gain Customer Insights, Richardo Chen &...
A5: Designing Gamified Experiences to Gain Customer Insights, Richardo Chen &...
 
Keynote: The Subscription Economy: How to Survive the End of Ownership, Tien ...
Keynote: The Subscription Economy: How to Survive the End of Ownership, Tien ...Keynote: The Subscription Economy: How to Survive the End of Ownership, Tien ...
Keynote: The Subscription Economy: How to Survive the End of Ownership, Tien ...
 
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
 
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
A3: Lean For Social Impact: Innovating for Greater Impact and Scale, Steve Na...
 
Keynote: Innovation is a Habit, not a Mindset, Diana Kander
Keynote: Innovation is a Habit, not a Mindset, Diana KanderKeynote: Innovation is a Habit, not a Mindset, Diana Kander
Keynote: Innovation is a Habit, not a Mindset, Diana Kander
 
F3: Employee = Founder: Building a Startup inside a Fortune 500 Company, Max-...
F3: Employee = Founder: Building a Startup inside a Fortune 500 Company, Max-...F3: Employee = Founder: Building a Startup inside a Fortune 500 Company, Max-...
F3: Employee = Founder: Building a Startup inside a Fortune 500 Company, Max-...
 
G3: Reflecting on My Failure to Build a Billion Dollar Company, Sahil Lavingia
G3: Reflecting on My Failure to Build a Billion Dollar Company, Sahil LavingiaG3: Reflecting on My Failure to Build a Billion Dollar Company, Sahil Lavingia
G3: Reflecting on My Failure to Build a Billion Dollar Company, Sahil Lavingia
 
C3: Optimize, Grow or Catapult: Where to Target Your Organization’s Innovatio...
C3: Optimize, Grow or Catapult: Where to Target Your Organization’s Innovatio...C3: Optimize, Grow or Catapult: Where to Target Your Organization’s Innovatio...
C3: Optimize, Grow or Catapult: Where to Target Your Organization’s Innovatio...
 
G6: Getting Leaders On Board: Don’t Let Your Innovation Program be Pronounced...
G6: Getting Leaders On Board: Don’t Let Your Innovation Program be Pronounced...G6: Getting Leaders On Board: Don’t Let Your Innovation Program be Pronounced...
G6: Getting Leaders On Board: Don’t Let Your Innovation Program be Pronounced...
 
E3: Amazon’s Approach to Culture Change, Wen Huang, Eric Tachibana
E3: Amazon’s Approach to Culture Change, Wen Huang, Eric TachibanaE3: Amazon’s Approach to Culture Change, Wen Huang, Eric Tachibana
E3: Amazon’s Approach to Culture Change, Wen Huang, Eric Tachibana
 
G1: Brackitz Toy Story: Learning From Mistakes and Mental Models for Success,...
G1: Brackitz Toy Story: Learning From Mistakes and Mental Models for Success,...G1: Brackitz Toy Story: Learning From Mistakes and Mental Models for Success,...
G1: Brackitz Toy Story: Learning From Mistakes and Mental Models for Success,...
 
D5: Be the Solution: Use Lean to Solve Community Problems, Katrina Medoff
D5: Be the Solution: Use Lean to Solve Community Problems, Katrina MedoffD5: Be the Solution: Use Lean to Solve Community Problems, Katrina Medoff
D5: Be the Solution: Use Lean to Solve Community Problems, Katrina Medoff
 
F1: Mastering the Art of Telling Your Story, Jamie Lazzeri
F1: Mastering the Art of Telling Your Story, Jamie LazzeriF1: Mastering the Art of Telling Your Story, Jamie Lazzeri
F1: Mastering the Art of Telling Your Story, Jamie Lazzeri
 
Keynote: Intelligent Growth in Startups: Building More Than a Product to Get ...
Keynote: Intelligent Growth in Startups: Building More Than a Product to Get ...Keynote: Intelligent Growth in Startups: Building More Than a Product to Get ...
Keynote: Intelligent Growth in Startups: Building More Than a Product to Get ...
 
Keynote: From Founder to Investor: Stories From the Trenches of Entrepreneurs...
Keynote: From Founder to Investor: Stories From the Trenches of Entrepreneurs...Keynote: From Founder to Investor: Stories From the Trenches of Entrepreneurs...
Keynote: From Founder to Investor: Stories From the Trenches of Entrepreneurs...
 
G5: Big Problems Require Big Solutions: the Story of Earn, Leigh Phillips
G5: Big Problems Require Big Solutions: the Story of Earn, Leigh PhillipsG5: Big Problems Require Big Solutions: the Story of Earn, Leigh Phillips
G5: Big Problems Require Big Solutions: the Story of Earn, Leigh Phillips
 
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
 
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
B6: Leading Innovation and Building Better Lives: Intercorp Latin America, Ed...
 
B5: The 8 Deadly Maladies of Rapid Experimentation, Lukas Oberhuber
B5: The 8 Deadly Maladies of Rapid Experimentation, Lukas OberhuberB5: The 8 Deadly Maladies of Rapid Experimentation, Lukas Oberhuber
B5: The 8 Deadly Maladies of Rapid Experimentation, Lukas Oberhuber
 
B4: The Road to Startup Success is Paved in Pivots, Kate Skavish
B4: The Road to Startup Success is Paved in Pivots, Kate Skavish B4: The Road to Startup Success is Paved in Pivots, Kate Skavish
B4: The Road to Startup Success is Paved in Pivots, Kate Skavish
 

Recently uploaded

8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCRashishs7044
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...ssuserf63bd7
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCRashishs7044
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Servicecallgirls2057
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCRashishs7044
 
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / NcrCall Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncrdollysharma2066
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menzaictsugar
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCRashishs7044
 
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...ShrutiBose4
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607dollysharma2066
 

Recently uploaded (20)

8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
 
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
Call Us ➥9319373153▻Call Girls In North Goa
Call Us ➥9319373153▻Call Girls In North GoaCall Us ➥9319373153▻Call Girls In North Goa
Call Us ➥9319373153▻Call Girls In North Goa
 
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
 
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / NcrCall Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
 
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
 

Balance Compliance and Experimentation by Joanne Molesky - The Lean Startup Conference 12/11/14

  • 1. 1 Balancing Compliance and Experimentation @jemolesky #LeanEnterprise
  • 3. Laws, regulations and management Business Laws & Regulations Frameworks, Standards Mandated Compliance Guidance Influence Influence Influence Management Policies Process Controls
  • 4. Avoid risk management theatre 4 • One process to rule them all • Success is following the process • Stops people from getting their work done • Pass the audit • Lack of responsibility
  • 6. 6 Finding the Balance - Apply Lean Principles to GRC
  • 7. 7 Create a shared understanding
  • 8. The way we work should determine controls Taliesen http://mrg.bz.ziSMzq 8 Rollingroscoe http://mrg.bz.vOsu5e Kconnors http://bz/PY1Jni
  • 9. 9 Map the value stream • End to end value delivery • Identify times • Encourages collaboration • Measure improvement
  • 10. Consider GRC from the beginning 10 • Type of Information • Take a risk based approach • Control access • Mastery and craftsmanship • GRC specialist are part of the team
  • 11. Traditional security compliance UAT Test Backlog In dev Analysis Prod CI Code review Manual security testing Pen Test
  • 12. Risk based security compliance Security stories, AC Inception Test In dev Analysis UAT Prod High Level – obligations, adversaries, assets, disaster scenarios Threat model & risk matrix Coding guidelines, pairing, code reviews CI Manual security testing Pen test Automated code analysis, security proxy, model verification Logs, Firewall, IDS, WAF,IPS
  • 13. Seek controls that maintain flow 13 • Right level of granularity • Decisions by responsible people • Boundaries defined • Risk based controls • Contain the blast area • Use compensating controls
  • 14. Create visibility and transparency 14 • Demand participation • Leave a trail of evidence • Visible means visible • Be disciplined, be consistent
  • 15. 15
  • 16. 16 Experiment - start small and build out
  • 17. 17 Gov.uk alpha design principles • Don’t slow down delivery • Decision when they are needed and at the right level • Do it with the right people • Go see for yourself • Only do it if it adds value • Trust and verify https://digitaltransformation.blog.gov.uk/2014/06/24/governance-principles/
  • 18. 18 Seek Perfection PatriciaEGreen2 http://mrg.bz/7YvKW7
  • 19. 19 Most significant challenges • Organizational structure not designed for fast pace of digital demands • Business process too inflexible to take advantage of new opportunities • Inability to adopt an experimental mind-set that is key for best practices http://www.mckinsey.com/insights/business_technology/The_digital_tippingbusiness_point_McKinsey_Global_Survey_results
  • 20. 20 Conclusion Manage risks, not compliance  Seek controls that match the way we work  Create a shared understanding and cross collaboration  Visualize and create flow
  • 21. Thank you - Questions? http://bit.ly/leanentp @jemolesky | @barryoreilly #leanenterprise | @jezhumble

Editor's Notes

  1. http://www.mckinsey.com/insights/business_technology/the_digital_tipping_point_mckinsey_global_survey_results
  2. Laws and Regulations : Sox, Hippa, Privacy laws, security breach laws, Air transport, Government and Government agencies Frameworks, Standards – Guidance – ISO 270001, ITIL, CobiT, COSO, TOGAF Laws and Regulations – Sox, Privacy Laws, Security breach legislations Frameworks and Standards – CobiT, ISO 27000 series, ITIL, COSO, PCI DSS Policies and Processes – Information Security, Access, Change Management, Solution Delivery Life Cycle Controls – Approvals, reviews, limited access, boundaries
  3. Reduce risks with smaller decisions with more frequent review Goal is to pass the audit, not reduce the risks Approvals and reviews by busy people or those who don’t have a clue Throwing over the wall Those doing the work are not responsible One process to rule them all Success measured by following the process
  4. If we leave this to auditors and risk and compliance people to worry about this, we get what we deserve. Our responsibility to understand the obligations and work collaboratively to figure out the best way to achieve this, given our own knowledge and experience. Dirty little secret – Most IT auditors ads GRC people have never actually worked in IT. They don’t understand the process, tools or capabilities to leverage them. It is up to us who are doing the work to educate them. To do that intelligently, we need to understand their language and the intent of the control, not the specific way they think we should meet the controls meet the control.
  5. http://www.mckinsey.com/insights/business_technology/the_digital_tipping_point_mckinsey_global_survey_results
  6. Make decision around assumptions how information is presented Based on your ‘experience’ what is the decision? What is the colour represented value -- how much would you bet? Microsoft story -- 1/3 wrong, no impact, add value
  7. Dirty little secret – Most IT auditors and GRC people have never actually worked in IT. They don’t understand the process, tools or capabilities to leverage them. It is up to us who are doing the work to educate them. To do that intelligently, we need to understand their language and the intent of the control, not the specific way 0t meet the control. Story Suncorp Australian Insurance and Banking company Coming out of a growth strategy which involved acquisitions with multiple brands of insurance and legacy back end systems to support it. Realized growth had to come from another place. Goal move all brands onto one platform - Mainframe. Go from agile to continuous delivery, leverage fewer, stronger, more trusting partnerships with software development partners Story of controls required for ODCs
  8. End to end value to the customers Identify times, handovers, waiting times and queues Encourage collaboration between functional silos Build empathy, trust, partners and shared understanding In example above, Planning and setup takes 3 – 4 weeks elapsed time, Actual time to do the work – 3 – 4 days, Identify where to start experimenting Scientific based on measurement baseline to improve "In solving problems you get the best outcome by imagining the ideal solution and then working backward to where you are today" –Ackoff Stories Segregation of Duties
  9. Privacy by Design – consider type of information Access Control – Authentication, Authorization, Accountability Mastery – encryption, vulnerability prevention, design for detection and recovery Security, internal Risk and Compliance part of the team Applicable compliance issues Threat modeling Automated security and compliance testing
  10. Sony, MoM, UK Gov
  11. Sony, MoM, UK Gov
  12. Move decisions to lowest level of responsibility, based on relative risk and defined boundaries Story of PCI and Segregation of duties - Etsy
  13. Create visibility and transparency into who has done what and when. Leave a trail of evidence Auditor code: ‘If it isn't written, it doesn’t exist’ Demand participation –standups, showcases, pairing exercises, inceptions and iteration planning. Leave a trail of evidence Create visibility Monitors and screens Kanban boards, Lightweight documentation Be disciplined, be consistent
  14. Add notes regarding the situation
  15. Transparency - into process and progress - and what is happening Gov UK Digital transformation dashboard https://www.gov.uk/transformation
  16. http://www.mckinsey.com/insights/business_technology/the_digital_tipping_point_mckinsey_global_survey_results
  17. Companies with over a billion dollars in annual revenue
  18. What are the things that need to be considered beyond technology i.e. automation, software craftsmanship Set people up for success i.e. vision statement for you team, define what you believe to be your purpose and engage leadership to get their feedback Consider end to end flow for value i.e. create a value stream map with stakeholders involved to start the understanding and collaboration Get comfortable with uncertainty i.e. create safe-to-fail experiments