CONTINUOUS COMPLIANCE
MONITORING
YOUR IT COMPLIANCE PARTNER –
GO BEYOND THE CHECKLIST
ControlCase Introduction
Recurrence Frequency & Calendar
About the Regulations
Common Challenges
AGENDA
© 2020 ControlCase. All Rights Reserved. 2
1
2
3
4
5
Continuous Compliance Components
ControlCase Solution6
1 CONTROLCASE INTRODUCTION
© 2020 ControlCase. All Rights Reserved. 3
ControlCase Snapshot
© 2020 ControlCase. All Rights Reserved. 4
CERTIFICATION AND CONTINUOUS COMPLIANCE SERVICES
Go beyond the auditor’s checklist to:
Dramatically cut the time, cost and burden from becoming certified and maintaining IT compliance.
• Demonstrate compliance more efficiently
and cost effectively (cost certainty)
• Improve efficiencies
⁃ Do more with less resources and gain
compliance peace of mind
• Free up your internal resources to focus
on their priorities
• Offload much of the compliance burden to
a trusted compliance partner
1,000+ 275+10,000+
CLIENTS IT SECURITY
CERTIFICATIONS
SECURITY
EXPERTS
Solution
© 2020 ControlCase. All Rights Reserved. 5
“I’ve worked on both sides of
auditing. I have not seen any other
firm deliver the same product and
service with the same value. No
other firm provides that continuous
improvement and the level of detail
and responsiveness.
— Security and Compliance Manager,
Data Center
Certification and Continuous Compliance Services
Certification Services
© 2020 ControlCase. All Rights Reserved. 6
“You have 27 seconds to make a first
impression. And after our initial
meeting, it became clear that they
were more interested in helping
our business and building a
relationship, not just getting the
business.
— Sr. Director, Information Risk & Compliance,
Large Merchant
ISO 27001
& 27002
SOC 1,2,3 & SOC
for Cybersecurity
HITRUST CSF
PCI P2PE GDPR NIST 800-53
PCI PIN PCI PA-DSS FedRAMP PCI 3DS
PCI DSS
HIPAA
ABOUT THE REGULATIONS2
© 2020 ControlCase. All Rights Reserved. 7
What do the Regulations Mean?
© 2020 ControlCase. All Rights Reserved. 8
Payment Card Industry Data Security Standard (PCI DSS)
Established by leading payment card issuers - Guidelines for securely
processing, storing, or transmitting payment card account data.
Health Insurance Portability and Accountability Act (HIPAA)
Passed by Congress in 1996 Mandates industry-wide standards for health care
information on electronic billing and other processes and requires the protection
and confidential handling of protected health information.
ISO 27001/ISO 27002 - ISO 27001
The management framework for implementing information security
within an organization. ISO 27002 are the detailed controls from an
implementation perspective.
FISMA
The Federal Information Security Management Act, which the United States
Congress passed in 2002 requires federal agencies to implement information
security plans to protect sensitive data. Any private sector company that has a
contractual relationship with the government, whether to provide services,
support a federal program, or receive grant money, must comply with FISMA
.
PCI SSF
Ensures payment applications support PCI DSS compliance.
NERC
The North American Electric Reliability Corporation (NERC) is a not-for-profit
international regulatory authority whose mission is to ensure the reliability of the
bulk power system in North America.
SOC 2
Created by the American Institute of Certified Public Accountants (AICPA) to fill the
gap for organizations that were being requested to have a SAS 70 (now SSAE 18).
The purpose of a SOC 2 report is to evaluate an organization’s information systems
relevant to Security, Availability, Processing Integrity, Confidentiality or Privacy.
REGION INDUSTRY REGULATION
APAC Business Process Organizations (BPOs) PCI DSS, SOC2, ISO 27001, HITRUST, HIPAA
APAC Payments PCI DSS, PCI SSF, SOC2, ISO 27001, PCI 3DS
APAC Financial Services PCI DSS, PCI SSF, PCI PIN, PCI 3DS, PCI CP
AMERICAS Payments PCI DSS, PCI SSF, SOC2, ISO 27001, PCI 3DS
AMERICAS Cloud Service Providers PCI DSS, PCI SSF, SOC2, ISO 27001, HITRUST
AMERICAS Retail PCI DSS, PCI P2PE, SOC2, ISO 27001, HIPAA
AMERICAS Technology PCI DSS, PCI SSF, SOC2, ISO 27001, HIPAA
LATIN AMERICA Cloud Services Providers PCI DSS, PCI SSF, SOC2, ISO 27001, HIPAA
EUROPE Cloud Services Providers PCI DSS, PCI SSF, SOC2, ISO 27001
Common Regulations by Region/Industry
© 2020 ControlCase. All Rights Reserved. 9
CONTINUOUS COMPLIANCE
COMPONENTS
3
© 2020 ControlCase. All Rights Reserved. 10
Continuous Compliance Domains
© 2020 ControlCase. All Rights Reserved. 11
Asset and Vulnerability Management
Change Management
Data Management
Business Continuity Management
Physical Security
Policy Management
Log Management
Incident and Problem Management
Risk Management
HR Management
Vendor / Third Party Management
Continuous Monitoring
© 2020 ControlCase. All Rights Reserved. 12
Test once, comply to multiple regulations
Mapping of controls
Automated data collection
Self assessment data collection
Executive dashboards
Policy Management
© 2020 ControlCase. All Rights Reserved. 13
REG/STANDARD COVERAGE AREA
ISO 27001 A.5
PCI 12
HIPAA 164.308a1i
FISMA AC-1
FERC/NERC CIP-003-6
Appropriate update of policies and procedures
Link/Mapping to controls and standards
Communication, training and attestation
Monitoring of compliance to corporate policies
Vendor / Third Party Management
© 2020 ControlCase. All Rights Reserved. 14
REG/STANDARD COVERAGE AREA
ISO 27001 A.6, A.10
PCI 12
HIPAA 164.308b1
FISMA PS-3
FERC/NERC Multiple Requirements
Management of third parties/vendors
Self attestation by third parties/vendors
Remediation tracking
Asset / Vulnerability Management
© 2020 ControlCase. All Rights Reserved. 15
REG/STANDARD COVERAGE AREA
ISO 27001 A.7, A.12
PCI 6, 11
HIPAA 164.308a8
FISMA RA-5
FERC/NERC CIP-010
Asset list
Management of vulnerabilities and dispositions
Training to development and support staff
Management reporting if unmitigated vulnerability
Linkage to non-compliance
Logging & Monitoring
© 2020 ControlCase. All Rights Reserved. 16
REG/STANDARD COVERAGE AREA
ISO 27001 A.7, A.12
PCI 6, 11
HIPAA 164.308a1iiD
FISMA SI-4
Logging
File Integrity Monitoring
24X7 Monitoring
Managing volumes of data
Logging & Monitoring
(SIEM/FIM, etc.)
Change Management
ticketing System
Correlation of logs /
alerts to change
requests
Response / Resolution
process for expected
logs / alerts
Escalation to incident for
unexpected logs / alerts
1 2 3 4 5
Change Management
© 2020 ControlCase. All Rights Reserved. 17
REG/STANDARD COVERAGE AREA
ISO 27001 A.10
PCI 1, 6, 10
FISMA SA-3
Incident / Problem Management
© 2020 ControlCase. All Rights Reserved. 18
REG/STANDARD COVERAGE AREA
ISO 27001 A.13
PCI 12
HIPAA 164.308a6i
FISMA IR Series
FERC/NERC CIP-008
Lost Laptop
Upgrades to
Applications
Changes to
Firewall Rulesets
Intrusion
Alerting
Monitoring
Detection
Reporting
Responding
Approving
Data Management
© 2020 ControlCase. All Rights Reserved. 19
REG/STANDARD COVERAGE AREA
ISO 27001 A.7
PCI 3, 4
HIPAA 164.310d2iv
FERC / NERC CIP-011
Identification of data
Classification of data
Protection of data
Monitoring of data
Risk Management
© 2020 ControlCase. All Rights Reserved. 20
REG/STANDARD COVERAGE AREA
ISO 27001 A.6
PCI 12
HIPAA 164.308a1iiB
FISMA RA-3
Input of key criterion
Numeric algorithms to compute risk
Output of risk dashboards
Business Continuity Management
© 2020 ControlCase. All Rights Reserved. 21
REG/STANDARD COVERAGE AREA
ISO 27001 A.14
PCI Not Applicable
HIPAA 164.308a7i
FISMA CP Series
FERC / NERC CIP-009
Business Continuity Planning
Disaster Recovery
BCP / DR Testing
Remote Site / Hot Site
HR Management
© 2020 ControlCase. All Rights Reserved. 22
REG/STANDARD COVERAGE AREA
ISO 27001 A.8
PCI 12
HIPAA 164.308a3i
FISMA AT-2
FERC / NERC CIP-004
Training
Background Screening
Reference Checks
REG/STANDARD COVERAGE AREA
ISO 27001 A.11
PCI 9
HIPAA 164.310
FISMA PE Series
FERC / NERC CIP-006
Badges
Visitor Access
CCTV
Biometric
Physical Security
© 2020 ControlCase. All Rights Reserved. 23
RECURRENCE FREQUENCY
& CALENDAR
4
© 2020 ControlCase. All Rights Reserved. 24
Daily Monitoring Domains
© 2020 ControlCase. All Rights Reserved. 25
ASSET & VULNERABILITY
MANAGEMENT
• New Assets
• New Vulnerabilities
LOG
MANAGEMENT
• Response time window
CHANGE
MANAGEMENT
• Impact in case of an error
• Unknown and insecure
applications
INCIDENT & PROBLEM
MANAGEMENT
• Root cause of systemic
problems
• Response to operational and
security incidents
Monthly / Quarterly Monitoring Domains
© 2020 ControlCase. All Rights Reserved. 26
VENDOR / THIRD PARTY
MANAGEMENT
• New Assets
• New Vulnerabilities
DATA
MANAGEMENT
• Identification of unknown
data
HR
MANAGEMENT
• Time taken for training
• Time taken for background
checks
PHYSICAL SECURITY
MANAGEMENT
• Time take to install new
physical security
components
Annual Monitoring Domains
© 2020 ControlCase. All Rights Reserved. 27
POLICY
MANAGEMENT
• Annual policy reviews
RISK
MANAGEMENT
• Enterprise-wide nature of risk
assessment
BCP / DR
MANAGEMENT
• Time taken to conduct BCP / DR tests
5 COMMON CHALLENGES
© 2020 ControlCase. All Rights Reserved. 28
Common Challenges
© 2020 ControlCase. All Rights Reserved. 29
Redundant Efforts
Lack of Dashboard
Change in Environment
Increased Regulations
Cost Inefficiencies
Fixing of Dispositions
Reliance on Third Parties
Reducing Budgets (Do more with less)
6 CONTROLCASE SOLUTION
© 2020 ControlCase. All Rights Reserved. 30
Continuous Compliance Services
© 2020 ControlCase. All Rights Reserved. 31
WHAT IS
CONTINUOUS COMPLIANCE
BENEFITS OF
CONTINUOUS COMPLIANCE
DELIVERABLE OF
CONTINUOUS COMPLIANCE
• Eliminates the need for potential
major last minute audit findings.
• Reduces effort for final audit by
approximately 25%.
• Reduces the risk of technical
shortcomings such as,
⎼ Quarterly scans missed certain
assets.
⎼ Logs from all assets not reporting.
• Quarterly review of 20-25 high
impact/high risk questions.
• Technical review of vulnerability
scans, log management, asset list
and other available automated
systems.
Predictive Continuous Compliance Services
© 2020 ControlCase. All Rights Reserved. 32
• Go beyond monitoring and alerting to predict, prioritize and
remediate compliance risks before they become security threats
• Address common non-compliant situations that leave you
vulnerable all year long, including:
⎼ In-scope assets not reporting logs
⎼ In-scope assets missed from vulnerability scans
⎼ Critical, overlooked vulnerabilities due to volume
⎼ Risky firewall rule sets go undetected
⎼ Non-compliant user access scenarios not flagged
The continuous compliance
monitoring is a big value add to
their audit and certification
services, which is good for
organizations that don’t have the
team in-house. It’s a big
differentiator for them.”
— VP of IT,
Call Center/BPO Company
“70% Of company’s assets are non-
compliant at some point in the year.
Summary – Why ControlCase
© 2020 ControlCase. All Rights Reserved. 33
They provide excellent service,
expertise and technology. And,
the visibility into my compliance
throughout the year and during
the audit process provide a lot
of value to us.
— Dir. of Compliance,
SaaS company
“
7 QUESTIONS & ANSWERS
© 2020 ControlCase. All Rights Reserved. 34
THANK YOU FOR THE
OPPORTUNITY TO CONTRIBUTE TO
YOUR IT COMPLIANCE PROGRAM.
www.controlcase.com
(US) + 1 703.483.6383 (INDIA) + 91.22.62210800
contact@controlcase.com

Continuous Compliance Monitoring

  • 1.
    CONTINUOUS COMPLIANCE MONITORING YOUR ITCOMPLIANCE PARTNER – GO BEYOND THE CHECKLIST
  • 2.
    ControlCase Introduction Recurrence Frequency& Calendar About the Regulations Common Challenges AGENDA © 2020 ControlCase. All Rights Reserved. 2 1 2 3 4 5 Continuous Compliance Components ControlCase Solution6
  • 3.
    1 CONTROLCASE INTRODUCTION ©2020 ControlCase. All Rights Reserved. 3
  • 4.
    ControlCase Snapshot © 2020ControlCase. All Rights Reserved. 4 CERTIFICATION AND CONTINUOUS COMPLIANCE SERVICES Go beyond the auditor’s checklist to: Dramatically cut the time, cost and burden from becoming certified and maintaining IT compliance. • Demonstrate compliance more efficiently and cost effectively (cost certainty) • Improve efficiencies ⁃ Do more with less resources and gain compliance peace of mind • Free up your internal resources to focus on their priorities • Offload much of the compliance burden to a trusted compliance partner 1,000+ 275+10,000+ CLIENTS IT SECURITY CERTIFICATIONS SECURITY EXPERTS
  • 5.
    Solution © 2020 ControlCase.All Rights Reserved. 5 “I’ve worked on both sides of auditing. I have not seen any other firm deliver the same product and service with the same value. No other firm provides that continuous improvement and the level of detail and responsiveness. — Security and Compliance Manager, Data Center Certification and Continuous Compliance Services
  • 6.
    Certification Services © 2020ControlCase. All Rights Reserved. 6 “You have 27 seconds to make a first impression. And after our initial meeting, it became clear that they were more interested in helping our business and building a relationship, not just getting the business. — Sr. Director, Information Risk & Compliance, Large Merchant ISO 27001 & 27002 SOC 1,2,3 & SOC for Cybersecurity HITRUST CSF PCI P2PE GDPR NIST 800-53 PCI PIN PCI PA-DSS FedRAMP PCI 3DS PCI DSS HIPAA
  • 7.
    ABOUT THE REGULATIONS2 ©2020 ControlCase. All Rights Reserved. 7
  • 8.
    What do theRegulations Mean? © 2020 ControlCase. All Rights Reserved. 8 Payment Card Industry Data Security Standard (PCI DSS) Established by leading payment card issuers - Guidelines for securely processing, storing, or transmitting payment card account data. Health Insurance Portability and Accountability Act (HIPAA) Passed by Congress in 1996 Mandates industry-wide standards for health care information on electronic billing and other processes and requires the protection and confidential handling of protected health information. ISO 27001/ISO 27002 - ISO 27001 The management framework for implementing information security within an organization. ISO 27002 are the detailed controls from an implementation perspective. FISMA The Federal Information Security Management Act, which the United States Congress passed in 2002 requires federal agencies to implement information security plans to protect sensitive data. Any private sector company that has a contractual relationship with the government, whether to provide services, support a federal program, or receive grant money, must comply with FISMA . PCI SSF Ensures payment applications support PCI DSS compliance. NERC The North American Electric Reliability Corporation (NERC) is a not-for-profit international regulatory authority whose mission is to ensure the reliability of the bulk power system in North America. SOC 2 Created by the American Institute of Certified Public Accountants (AICPA) to fill the gap for organizations that were being requested to have a SAS 70 (now SSAE 18). The purpose of a SOC 2 report is to evaluate an organization’s information systems relevant to Security, Availability, Processing Integrity, Confidentiality or Privacy.
  • 9.
    REGION INDUSTRY REGULATION APACBusiness Process Organizations (BPOs) PCI DSS, SOC2, ISO 27001, HITRUST, HIPAA APAC Payments PCI DSS, PCI SSF, SOC2, ISO 27001, PCI 3DS APAC Financial Services PCI DSS, PCI SSF, PCI PIN, PCI 3DS, PCI CP AMERICAS Payments PCI DSS, PCI SSF, SOC2, ISO 27001, PCI 3DS AMERICAS Cloud Service Providers PCI DSS, PCI SSF, SOC2, ISO 27001, HITRUST AMERICAS Retail PCI DSS, PCI P2PE, SOC2, ISO 27001, HIPAA AMERICAS Technology PCI DSS, PCI SSF, SOC2, ISO 27001, HIPAA LATIN AMERICA Cloud Services Providers PCI DSS, PCI SSF, SOC2, ISO 27001, HIPAA EUROPE Cloud Services Providers PCI DSS, PCI SSF, SOC2, ISO 27001 Common Regulations by Region/Industry © 2020 ControlCase. All Rights Reserved. 9
  • 10.
    CONTINUOUS COMPLIANCE COMPONENTS 3 © 2020ControlCase. All Rights Reserved. 10
  • 11.
    Continuous Compliance Domains ©2020 ControlCase. All Rights Reserved. 11 Asset and Vulnerability Management Change Management Data Management Business Continuity Management Physical Security Policy Management Log Management Incident and Problem Management Risk Management HR Management Vendor / Third Party Management
  • 12.
    Continuous Monitoring © 2020ControlCase. All Rights Reserved. 12 Test once, comply to multiple regulations Mapping of controls Automated data collection Self assessment data collection Executive dashboards
  • 13.
    Policy Management © 2020ControlCase. All Rights Reserved. 13 REG/STANDARD COVERAGE AREA ISO 27001 A.5 PCI 12 HIPAA 164.308a1i FISMA AC-1 FERC/NERC CIP-003-6 Appropriate update of policies and procedures Link/Mapping to controls and standards Communication, training and attestation Monitoring of compliance to corporate policies
  • 14.
    Vendor / ThirdParty Management © 2020 ControlCase. All Rights Reserved. 14 REG/STANDARD COVERAGE AREA ISO 27001 A.6, A.10 PCI 12 HIPAA 164.308b1 FISMA PS-3 FERC/NERC Multiple Requirements Management of third parties/vendors Self attestation by third parties/vendors Remediation tracking
  • 15.
    Asset / VulnerabilityManagement © 2020 ControlCase. All Rights Reserved. 15 REG/STANDARD COVERAGE AREA ISO 27001 A.7, A.12 PCI 6, 11 HIPAA 164.308a8 FISMA RA-5 FERC/NERC CIP-010 Asset list Management of vulnerabilities and dispositions Training to development and support staff Management reporting if unmitigated vulnerability Linkage to non-compliance
  • 16.
    Logging & Monitoring ©2020 ControlCase. All Rights Reserved. 16 REG/STANDARD COVERAGE AREA ISO 27001 A.7, A.12 PCI 6, 11 HIPAA 164.308a1iiD FISMA SI-4 Logging File Integrity Monitoring 24X7 Monitoring Managing volumes of data
  • 17.
    Logging & Monitoring (SIEM/FIM,etc.) Change Management ticketing System Correlation of logs / alerts to change requests Response / Resolution process for expected logs / alerts Escalation to incident for unexpected logs / alerts 1 2 3 4 5 Change Management © 2020 ControlCase. All Rights Reserved. 17 REG/STANDARD COVERAGE AREA ISO 27001 A.10 PCI 1, 6, 10 FISMA SA-3
  • 18.
    Incident / ProblemManagement © 2020 ControlCase. All Rights Reserved. 18 REG/STANDARD COVERAGE AREA ISO 27001 A.13 PCI 12 HIPAA 164.308a6i FISMA IR Series FERC/NERC CIP-008 Lost Laptop Upgrades to Applications Changes to Firewall Rulesets Intrusion Alerting Monitoring Detection Reporting Responding Approving
  • 19.
    Data Management © 2020ControlCase. All Rights Reserved. 19 REG/STANDARD COVERAGE AREA ISO 27001 A.7 PCI 3, 4 HIPAA 164.310d2iv FERC / NERC CIP-011 Identification of data Classification of data Protection of data Monitoring of data
  • 20.
    Risk Management © 2020ControlCase. All Rights Reserved. 20 REG/STANDARD COVERAGE AREA ISO 27001 A.6 PCI 12 HIPAA 164.308a1iiB FISMA RA-3 Input of key criterion Numeric algorithms to compute risk Output of risk dashboards
  • 21.
    Business Continuity Management ©2020 ControlCase. All Rights Reserved. 21 REG/STANDARD COVERAGE AREA ISO 27001 A.14 PCI Not Applicable HIPAA 164.308a7i FISMA CP Series FERC / NERC CIP-009 Business Continuity Planning Disaster Recovery BCP / DR Testing Remote Site / Hot Site
  • 22.
    HR Management © 2020ControlCase. All Rights Reserved. 22 REG/STANDARD COVERAGE AREA ISO 27001 A.8 PCI 12 HIPAA 164.308a3i FISMA AT-2 FERC / NERC CIP-004 Training Background Screening Reference Checks
  • 23.
    REG/STANDARD COVERAGE AREA ISO27001 A.11 PCI 9 HIPAA 164.310 FISMA PE Series FERC / NERC CIP-006 Badges Visitor Access CCTV Biometric Physical Security © 2020 ControlCase. All Rights Reserved. 23
  • 24.
    RECURRENCE FREQUENCY & CALENDAR 4 ©2020 ControlCase. All Rights Reserved. 24
  • 25.
    Daily Monitoring Domains ©2020 ControlCase. All Rights Reserved. 25 ASSET & VULNERABILITY MANAGEMENT • New Assets • New Vulnerabilities LOG MANAGEMENT • Response time window CHANGE MANAGEMENT • Impact in case of an error • Unknown and insecure applications INCIDENT & PROBLEM MANAGEMENT • Root cause of systemic problems • Response to operational and security incidents
  • 26.
    Monthly / QuarterlyMonitoring Domains © 2020 ControlCase. All Rights Reserved. 26 VENDOR / THIRD PARTY MANAGEMENT • New Assets • New Vulnerabilities DATA MANAGEMENT • Identification of unknown data HR MANAGEMENT • Time taken for training • Time taken for background checks PHYSICAL SECURITY MANAGEMENT • Time take to install new physical security components
  • 27.
    Annual Monitoring Domains ©2020 ControlCase. All Rights Reserved. 27 POLICY MANAGEMENT • Annual policy reviews RISK MANAGEMENT • Enterprise-wide nature of risk assessment BCP / DR MANAGEMENT • Time taken to conduct BCP / DR tests
  • 28.
    5 COMMON CHALLENGES ©2020 ControlCase. All Rights Reserved. 28
  • 29.
    Common Challenges © 2020ControlCase. All Rights Reserved. 29 Redundant Efforts Lack of Dashboard Change in Environment Increased Regulations Cost Inefficiencies Fixing of Dispositions Reliance on Third Parties Reducing Budgets (Do more with less)
  • 30.
    6 CONTROLCASE SOLUTION ©2020 ControlCase. All Rights Reserved. 30
  • 31.
    Continuous Compliance Services ©2020 ControlCase. All Rights Reserved. 31 WHAT IS CONTINUOUS COMPLIANCE BENEFITS OF CONTINUOUS COMPLIANCE DELIVERABLE OF CONTINUOUS COMPLIANCE • Eliminates the need for potential major last minute audit findings. • Reduces effort for final audit by approximately 25%. • Reduces the risk of technical shortcomings such as, ⎼ Quarterly scans missed certain assets. ⎼ Logs from all assets not reporting. • Quarterly review of 20-25 high impact/high risk questions. • Technical review of vulnerability scans, log management, asset list and other available automated systems.
  • 32.
    Predictive Continuous ComplianceServices © 2020 ControlCase. All Rights Reserved. 32 • Go beyond monitoring and alerting to predict, prioritize and remediate compliance risks before they become security threats • Address common non-compliant situations that leave you vulnerable all year long, including: ⎼ In-scope assets not reporting logs ⎼ In-scope assets missed from vulnerability scans ⎼ Critical, overlooked vulnerabilities due to volume ⎼ Risky firewall rule sets go undetected ⎼ Non-compliant user access scenarios not flagged The continuous compliance monitoring is a big value add to their audit and certification services, which is good for organizations that don’t have the team in-house. It’s a big differentiator for them.” — VP of IT, Call Center/BPO Company “70% Of company’s assets are non- compliant at some point in the year.
  • 33.
    Summary – WhyControlCase © 2020 ControlCase. All Rights Reserved. 33 They provide excellent service, expertise and technology. And, the visibility into my compliance throughout the year and during the audit process provide a lot of value to us. — Dir. of Compliance, SaaS company “
  • 34.
    7 QUESTIONS &ANSWERS © 2020 ControlCase. All Rights Reserved. 34
  • 35.
    THANK YOU FORTHE OPPORTUNITY TO CONTRIBUTE TO YOUR IT COMPLIANCE PROGRAM. www.controlcase.com (US) + 1 703.483.6383 (INDIA) + 91.22.62210800 contact@controlcase.com

Editor's Notes

  • #5 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #6 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #7 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #12 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #13 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #14 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #15 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #16 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #17 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #18 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #19 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #20 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #21 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #22 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #23 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #24 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #26 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #27 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #28 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #30 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #32 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #33 Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  • #34 Partnership Approach – Proactive expertise, responsive support and new, innovative ideas to streamline and improve compliance Right mix of size and responsiveness - We’re big enough to provide comprehensive compliance services, but agile enough to deliver responsive client care and support Automation-Driven – Take advantage of automation to cut time and costs and improve efficiencies in becoming certified and maintaining compliance ControlCase IT Compliance Portal Automated evidence collection – on prem or in the cloud Real-time Certification Dashboard AI-powered Predictive Compliance Go beyond monitoring and alerting to predict, prioritize and remediate compliance risk before they become security threats GRC Platform integration Continuous Compliance – Use ControlCase’s continuous compliance services to maintain compliance continuously in between annual certification efforts, because point-in-time, snap-shot compliance doesn’t effectively keep your company compliant or secure Predict, prioritize and remediate compliance risks before they become security threats