SlideShare a Scribd company logo
1 of 10
Considerations for Implementing IT GRC Muni Chatarpal, CISM, CISSP, CEHSecurity and Risk ManagementEnbridge Energy PartnersJune 15, 2010
Meeting Agenda ,[object Object]
Our Solution
Our Roadmap
Key Discoveries
Immediate Benefits
Path Forward2
Problem Statement ,[object Object]
Inefficient Process
Poor Quality

More Related Content

Similar to Muni chatarpal considerations for grc

White paper: "Human performance improvement"
White paper: "Human performance improvement"White paper: "Human performance improvement"
White paper: "Human performance improvement"APARNA SANAKA
 
6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectivenessRavi Tirumalai
 
Implementing Anti-Money Laundering and Know Your Customer Managed Services So...
Implementing Anti-Money Laundering and Know Your Customer Managed Services So...Implementing Anti-Money Laundering and Know Your Customer Managed Services So...
Implementing Anti-Money Laundering and Know Your Customer Managed Services So...accenture
 
Performance Measurement for Local Governments
Performance Measurement for Local GovernmentsPerformance Measurement for Local Governments
Performance Measurement for Local GovernmentsRavikant Joshi
 
2008 Pioneering The Employment Services Audit In The Ontario College Sector
2008 Pioneering The Employment Services Audit In The Ontario College Sector2008 Pioneering The Employment Services Audit In The Ontario College Sector
2008 Pioneering The Employment Services Audit In The Ontario College SectorNikhat Rasheed
 
Action Plan Workshop Apr 23 2009
Action Plan Workshop Apr 23 2009Action Plan Workshop Apr 23 2009
Action Plan Workshop Apr 23 2009Szymra
 
Sustain it Sample of Project References
Sustain it Sample of Project ReferencesSustain it Sample of Project References
Sustain it Sample of Project ReferencesLaurent Janssens
 
CMMI & Six Sigma Integration
CMMI & Six Sigma IntegrationCMMI & Six Sigma Integration
CMMI & Six Sigma IntegrationAnand Subramaniam
 
Flash Report for Capgemini Consulting - Digitally transforming a retail bank
Flash Report for Capgemini Consulting - Digitally transforming a retail bankFlash Report for Capgemini Consulting - Digitally transforming a retail bank
Flash Report for Capgemini Consulting - Digitally transforming a retail bankPrashanth Ramachandran
 
Managing The Business Risk Of Fraud
Managing The Business Risk Of FraudManaging The Business Risk Of Fraud
Managing The Business Risk Of FraudEZ-R Stats, LLC
 
Performance Management to Program Evaluation: Creating a Complementary Connec...
Performance Management to Program Evaluation: Creating a Complementary Connec...Performance Management to Program Evaluation: Creating a Complementary Connec...
Performance Management to Program Evaluation: Creating a Complementary Connec...nicholes21
 
Data analytics 2 analytics in the audit slides
Data analytics 2 analytics in the audit slides Data analytics 2 analytics in the audit slides
Data analytics 2 analytics in the audit slides Jim Kaplan CIA CFE
 
Measurement Strategy for Software Companies
Measurement Strategy for Software CompaniesMeasurement Strategy for Software Companies
Measurement Strategy for Software Companiesnazlitemu
 
Risk Assessments Best Practice and Practical Approaches Webinar
Risk Assessments Best Practice and Practical Approaches WebinarRisk Assessments Best Practice and Practical Approaches Webinar
Risk Assessments Best Practice and Practical Approaches WebinarAviva Spectrum™
 
Use the Windshield, Not the Mirror Predictive Metrics that Drive Successful ...
 Use the Windshield, Not the Mirror Predictive Metrics that Drive Successful ... Use the Windshield, Not the Mirror Predictive Metrics that Drive Successful ...
Use the Windshield, Not the Mirror Predictive Metrics that Drive Successful ...Seapine Software
 
Jisc learning analytics mar2017
Jisc learning analytics mar2017Jisc learning analytics mar2017
Jisc learning analytics mar2017Paul Bailey
 

Similar to Muni chatarpal considerations for grc (20)

White paper: "Human performance improvement"
White paper: "Human performance improvement"White paper: "Human performance improvement"
White paper: "Human performance improvement"
 
6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness
 
Implementing Anti-Money Laundering and Know Your Customer Managed Services So...
Implementing Anti-Money Laundering and Know Your Customer Managed Services So...Implementing Anti-Money Laundering and Know Your Customer Managed Services So...
Implementing Anti-Money Laundering and Know Your Customer Managed Services So...
 
Performance Measurement for Local Governments
Performance Measurement for Local GovernmentsPerformance Measurement for Local Governments
Performance Measurement for Local Governments
 
2008 Pioneering The Employment Services Audit In The Ontario College Sector
2008 Pioneering The Employment Services Audit In The Ontario College Sector2008 Pioneering The Employment Services Audit In The Ontario College Sector
2008 Pioneering The Employment Services Audit In The Ontario College Sector
 
Action Plan Workshop Apr 23 2009
Action Plan Workshop Apr 23 2009Action Plan Workshop Apr 23 2009
Action Plan Workshop Apr 23 2009
 
Sustain it Sample of Project References
Sustain it Sample of Project ReferencesSustain it Sample of Project References
Sustain it Sample of Project References
 
CMMI & Six Sigma Integration
CMMI & Six Sigma IntegrationCMMI & Six Sigma Integration
CMMI & Six Sigma Integration
 
Flash Report for Capgemini Consulting - Digitally transforming a retail bank
Flash Report for Capgemini Consulting - Digitally transforming a retail bankFlash Report for Capgemini Consulting - Digitally transforming a retail bank
Flash Report for Capgemini Consulting - Digitally transforming a retail bank
 
Managing The Business Risk Of Fraud
Managing The Business Risk Of FraudManaging The Business Risk Of Fraud
Managing The Business Risk Of Fraud
 
Performance Management to Program Evaluation: Creating a Complementary Connec...
Performance Management to Program Evaluation: Creating a Complementary Connec...Performance Management to Program Evaluation: Creating a Complementary Connec...
Performance Management to Program Evaluation: Creating a Complementary Connec...
 
Data analytics 2 analytics in the audit slides
Data analytics 2 analytics in the audit slides Data analytics 2 analytics in the audit slides
Data analytics 2 analytics in the audit slides
 
Samsung electronics case study
Samsung electronics case studySamsung electronics case study
Samsung electronics case study
 
Get your data analytics strategy right!
Get your data analytics strategy right!Get your data analytics strategy right!
Get your data analytics strategy right!
 
Measurement Strategy for Software Companies
Measurement Strategy for Software CompaniesMeasurement Strategy for Software Companies
Measurement Strategy for Software Companies
 
Risk Assessments Best Practice and Practical Approaches Webinar
Risk Assessments Best Practice and Practical Approaches WebinarRisk Assessments Best Practice and Practical Approaches Webinar
Risk Assessments Best Practice and Practical Approaches Webinar
 
Use the Windshield, Not the Mirror Predictive Metrics that Drive Successful ...
 Use the Windshield, Not the Mirror Predictive Metrics that Drive Successful ... Use the Windshield, Not the Mirror Predictive Metrics that Drive Successful ...
Use the Windshield, Not the Mirror Predictive Metrics that Drive Successful ...
 
Project Metrics & Measures
Project Metrics & MeasuresProject Metrics & Measures
Project Metrics & Measures
 
Jisc learning analytics mar2017
Jisc learning analytics mar2017Jisc learning analytics mar2017
Jisc learning analytics mar2017
 
[StepTalks2013] - How did we achieve CMMI? - Lara Osório
[StepTalks2013] - How did we achieve CMMI? - Lara Osório[StepTalks2013] - How did we achieve CMMI? - Lara Osório
[StepTalks2013] - How did we achieve CMMI? - Lara Osório
 

Recently uploaded

Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 

Recently uploaded (20)

Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 

Muni chatarpal considerations for grc

Editor's Notes

  1. Complex Process - The current process is very complex to track and manage, as they are mostly done manually, and are prone to errors. The current workflow is also inconsistent between business units, creating a challenge in harmonizing IT risk management activities at an enterprise level. Timely and accurate reporting (which is required to support informed decisions), especially for audit purposes is more challenging and inaccurate; Inefficient Process - As current processes are mostly manual, makes it difficult to Gather, Analyze, and Report against Risk and Control activities. This increases the time required to complete IT risk management and compliance activities, especially when an external party (assessment) is involved. With many overlaps between different regulations and standards, it is important to cross reference the compliance areas, minimizing redundancy and maximizing efficiency;Poor Quality - The existing process lacks the capability to prioritize risk across mandates, which is important in applying controls where it really matters the most. Since the current process, is mostly done manually, consolidation of IT risk and compliance management activities is also a challenge, which creates complexity in comparing and reporting activities between business unitsHigh Cost – duplication of efforts and inconsistencies in processes. Manual method takes more time to complete assessments and prone to errors. Consolidation of information challenging! Manual efforts for ITRM compliance activities (interviews, IA, documentation, TRA, Remediation, VA, VA Remediation can add up! FRAGMENTED APPROACH is EXPENSIVE. Relying on what people tell you. Inability to get evidence. Some were doing IA against assets and some were not. Lack of Visibility – Timely Reporting or trending capabilities non-existent or challenging. No idea where you stand at a given point in time.
  2. People, Process, TechnologyCreate Roles and ResponsibilitiesImplement in PHASES. Phase 1 (Plan and Purchase, Assets Selection ,Self Assessment), Phase II (Assessment validation, TRA, Exception tracking, Reporting) Phase III ( Leverage with other compliance mandates, expand functionality, etc).Established and adopted a common framework – What framework must be adopted for compliance management??? We adopted our ISO based ITRM policy. We started out asking for evidence for only critical assets.Scope – Break project into reasonable chunks. Start with basic functionality (automation of questionnaires, reporting, etc). Asset data is contained in a variety of repositories across a wide set of network, system and security management products.
  3. Communication Awareness – Early communication and awareness of critical stakeholders in the process (Compliance Specialists, control Owners, and Audit Services.). We utilized Lunch and Learns, desk drops, Training, etc.Align Methodologies - We aligned our RM strategies with auditing methodology.  Get on AS ‘s Audit Plan. Its impossible to assess each component.  NOW we are looking at controls AND risk. Audit Services role is to provide ASSURANCE on all significant aspects of GRC.We provide guidelines on what evidence to provide.Start with basic self assessment functionalities – Use Web based questionnaires to Automate assessment. Capture pertinent evidence. Basic reporting. We utilized IT control self-assessment survey functions to help measure its compliance with our established policies.
  4. Overwhelming Control Owners – Provide sufficient training and advanced awareness otherwise COs can be overwhelmed. We have just added more work to their already busy schedule.Enable CO by using automation where possible to help them conduct their jobs more efficiently.Quality Control of first assessment – Human Judgment Reqd. AQ will be required to determine if adequate evidence was submitted and ensure the CO answered all the questions correctly. Garbage IN = Garbage Out. Compliance Specialist needs to be familiar with types of risks.Audit is an enabler– work with them to build RM/Compliance QA work into their workplan. Bring to the table ‘Monitoring and Auditing” controls + Improvement opportunitiesAsset Repository– Most companies don’t have a list of their assets. We started with what WE KNOW. Start with Critical assets and try to cover all in a year.
  5. Improved quality – consistent process less prone to errors since questionnaires are automated, Capturing evidence possible.Increased Efficiency – cost savings associated with All CO and Compliance Specialists using consistent process common tools=less errors, less duplication, more meaningful reporting = Single Source of Truth = SINGLE PLATFORM ENTERPRISE WIDEAdoption by Control Owners – ask questions, complete questionnaires, and provide valuable feedback for improvement.Compliance Reporting – immediate visual representation of compliance status helps satisfy effective decision making
  6. Integration with other areas – AS, Physical Security, IC, Operational Security Best practises - – Break SilosIntegration with other IT compliance mandates (SOX, TSA PSG, API 1164, etc) – Transportation Security Adm – Pipelines Security Guidelines, Pipeline SCADA Security. OFTEN an overlap of Assets, People, CONSIDER using a GRC solution for everything…Familiar with ONE platform to satisfy multiple mandatesRemediation and exception management - Tracks the life cycle of identified gaps and authorized policy exceptionsLeverage Integration with 3rd party tools (VA Tools – Qualys, Remedy, EFS, etc). UTILIZE workflow capabilities with other integrated solutions.Improved Reporting – Customized for our ITRM policy.