SlideShare a Scribd company logo
1 of 31
Technology and GRC
Agenda
• Organisational Overview
• GRC and Security Challenges
• SAP GRC vs. SAS GRC
• How to choose a GRC Platform?
• How to implement GRC Platform?
• Summary
Agenda
• Organisational Overview
• GRC and Security Challenges
• SAP GRC vs. SAS GRC
• How to choose a GRC Platform?
• How to implement GRC Platform?
• Summary
Organisational Overview
• Eskom is a South African electricity public utility,
established in 1923 as the Electricity Supply
Commission (ESC) by the government of the Union of
South Africa in terms of the Electricity Act (1922).
• Eskom operates a number of notable power stations,
ranging from Coal, Gas, Renewable and a Nuclear
power plant.
• The company is divided into Generation, Transmission
and Distribution divisions and together Eskom
generates approximately 95% of electricity used in
South Africa.
Organisational Overview
Source: http://www.eskom.co.za/OurCompany/CompanyInformation/Pages/Company_Information_1.aspx
Technological Overview
6
• SAP PM
• GPSS
• THEMSE
• CSS
• COLLOPS
• MDMS
• FLIP
• SCADA
• MAXIMO/ TERTIARY WIRES
• GTX
• CS-ONLINE
• AVAYA
• VAT – MOBILITY
• SMALLWORLD
• FMS
• ENS
• PRIMAVERA
• SPF
• PRISM
• SMALLWORLD & ENS
• ACNAC
• SMARTPLANT
• ENGINEERING SYSTEMS
• CIBOODLE
• MV90
• ROUTEMASTER
• AMI
• ALFS
• KSACS MDMS
• CNL
• CS-ONLINE
INTEGRATION
INTEGRATION
INTEGRATION
INTEGRATION
Agenda
• Organisational Overview
• GRC and Security Challenges
• SAP GRC vs. SAS GRC
• How to choose a GRC Platform?
• How to implement GRC Platform?
• Summary
GRC and Security Challenges
Challenges
Regulation
Legislation
Technology
Models
Business
Models
E.g. NERSA,
SABA, HPSA,
NCR
E.g. Industry 4.0
E.g. FICA, PoPIE.g. IoT, Cloud
Services
Agenda
• Organisational Overview
• GRC and Security Challenges
• SAP GRC vs. SAS GRC
• How to choose a GRC Platform?
• How to implement GRC Platform?
• Summary
SAP GRC vs. SAS GRC
SAP GRC Overview
SAP GRC vs. SAS GRC
SAP GRC Overview
SAP GRC vs. SAS GRC
SAS GRC Overview
SAP GRC vs. SAS GRC
• SAS Enterprise GRC Features
– Conduct audits
– Manage policies
– Conduct risk and control assessments
– Test controls
– Investigate incidents
– Create and track issues and develop action plans
– Scenario analysis
SAP GRC vs. SAS GRC
SAP Strengths SAS Strengths
1. Integration of Risk and Performance
Management
1. Clear understanding of C-Suite
needs
2. Integration other SAP Modules 2. Great Reporting
3. Advanced Data Analytics 3. Financial and Utility Capabilities
SAP Cautions SAS Cautions
1. Pricing Model 1. Challenging Configuration
2. Customer Experience Satisfaction 2. Minimal Expectations
3. Extensive Configurations 3. Long Implementation Times
Agenda
• Organisational Overview
• GRC and Security Challenges
• SAP GRC vs. SAS GRC
• How to choose a GRC Platform?
• How to implement GRC Platform?
• Summary
How to choose a GRC Platform
• The governance, risk and compliance (GRC) software
market has evolved and segmented.
• Risk management solutions and related processes
are typically focused on individual functions across
an organization, which inhibits collaboration and
understanding of risk at an enterprise level.
• Many organizations employ a "technology-first"
mindset when trying to solve their most pressing risk
management challenges.
How to choose a GRC Platform
• Organizations require features and functions for their GRC
platform to support multiple risk management and
compliance, specifically in the following functional categories:
– Architecture
– Reporting
– Administration
– Risk management
– Incident management
– Compliance and policy management
– Regulatory intelligence and change management
– Audit management
– Etc.
How to choose a GRC Platform
Basel II/III Foreign Corrupt Practices Act
Business continuity management Internal audit
Corporate compliance management and
oversight
IT risk management
Environmental, health and safety (EH&S)
and sustainability
Privacy compliance
Enterprise risk management Project risk management
Ethics compliance Security risk and compliance oversight
Cyber Risk Management Third-party risk management
Example of High Level Use Cases
How to choose a GRC Platform
Gartner Integrated Risk Management Solutions
Corporate Compliance
and Oversight
Enterprise Legal
Management
Audit Management
IT Risk Management
Business Continuity
Management Planning
IT Vendor Risk
Management
Operational Risk
Management
How to choose a GRC Platform
Risk Management Solution
Integrated Risk Management Solution
Business
Continuity
Management
Planning
Critical
Capabilities for
Operational
Risk
Management
IT Vendor Risk
Management
IT Risk
Management
Audit
Management
Corporate
Compliance
and Oversight
Enterprise
Legal
Management
Chief Information
Security Officer
Chief Operating
Officer
Chief Risk Officer Chief Compliance
Officer
Chief Audit
Executive
Chief Legal Officer /
General Counsel
Chief Information
Officer
Chief Procurement
Officer
Chief Financial Officer
Gartner IRMS Research and Related Key Stakeholder Roles
How to choose a GRC Platform
The Global Risks Report 2017 - 12th Edition (The Risks-Trends Interconnections Map)
How to choose a GRC Platform
Business
Relevance
Filter
Technology
Filter
Economic
Filter
POV Filter
Agenda
• Organisational Overview
• GRC and Security Challenges
• SAP GRC vs. SAS GRC
• How to choose a GRC Platform?
• How to implement GRC Platform?
• Summary
How to implement GRC Platform
• The key to the success of a GRC solution deployment
continues to be the existence of clear requirements
from management and well-defined processes.
• The most successful GRC Platform deployments are
characterized as automating and improving existing,
or well-defined, practices versus deployments that
seek to define GRC Platform around a tool.
How to implement GRC Platform
• Planning, and not technical issues, is at the root cause of most
deployment failures. Deployment failures are most often the result of
poorly defined requirements or unrealistic timelines and not because of
technical problems with tools.
• GRC solution selections are often heavily influenced by features that are
never fully utilized. Solutions in this space often present long lists of
features, but the resources requirements to implement and operationalize
these features often fall outside the enterprise appetite.
• Enterprises often underestimate the initial and ongoing resource requirements for
utilizing policy management to map policy, controls and compliance requirements.
Enterprises should ensure that they have a durable business case that justifies the
necessary investment.
• In order for GRC processes and their results to be relied upon by executives,
auditors and examiners, they must inspire confidence.
How to implement GRC Platform
Time
Skills
Value
1. Identify the requirements
and processes
2. Select and Prioritize Use
Cases
3. Test the identified IRMS
Module
4. Stabilise Infrastructure
to Access and Analyse
5. Deploy the Selected
Module(s)
6. Enable the Enterprise
IRMS
Awareness
Mapping the Solution Path to the Typical Stages and Milestones of IRMS
Agenda
• Organisational Overview
• GRC and Security Challenges
• SAP GRC vs. SAS GRC
• How to choose a GRC Platform?
• How to implement GRC Platform?
• Summary
Summary
• Failure to deliver Business Value
• Improper Use Case Selection
• Organisational InertiaStrategy
• Identifying the wrong risks
• Using unreliable data
• Misunderstanding the nuances of Risk ModelsRisks
• Lack of Skills
• Inability to address adjacent technologies
Skills
Top Reasons for GRC Platform Failures
Summary
Frame
Problem
Design
Analysis
Gather
Data
Execute &
Interpret
Implement
Measure
Gain
Experience
Architectural Approach for IRMS
Summary
• Enterprises should invest time and energy in clearly defining the goals,
objectives, measurements of success, and practices for IT GRC prior to
pursuing the selection and deployment of these solutions. Once a goal
state is clearly defined, enterprises can choose from a number of available
solutions.
• Ensure that the business case has been made not just for purchasing a
solution, but also for the investments that are required to utilize and
maintain it: GRC solutions are frequently purchased as a part of a push to
address particular audit, compliance or regulatory concerns, and then
they languish, underutilized, or become shelf ware. Secure a commitment
not just to acquire capabilities, but also to implement and maintain the
solution. Careful consideration must also be given to how ongoing
maintenance will be staffed.
• GRC itself is a set of processes and practices that aims to manage the risks
of business use of IT and IT itself. Enterprises can purchase solutions to
automate or improve IT GRC, but the actual work of governing, managing
risk and addressing compliance requirements necessitates the enterprise
to establish policies, procedures, practices, organizational structures and
management expectations.
GRC Africa   The Paradigm Shift (Technology and GRC)

More Related Content

What's hot

Reduce Operational Costs in Healthcare by Adopting Lean Application Support ...
 Reduce Operational Costs in Healthcare by Adopting Lean Application Support ... Reduce Operational Costs in Healthcare by Adopting Lean Application Support ...
Reduce Operational Costs in Healthcare by Adopting Lean Application Support ...HCL Technologies
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCognizant
 
System Center Service Manager (Av Torgeir Bergsvik)
System Center Service Manager (Av Torgeir Bergsvik)System Center Service Manager (Av Torgeir Bergsvik)
System Center Service Manager (Av Torgeir Bergsvik)Microsoft Norge AS
 
Application Crisis avoidance six things you can do
Application Crisis avoidance  six things you can doApplication Crisis avoidance  six things you can do
Application Crisis avoidance six things you can doApalytics
 
CloudPilot Application Migration Tools Datasheet - CloudOrigin®
CloudPilot Application Migration Tools Datasheet - CloudOrigin®CloudPilot Application Migration Tools Datasheet - CloudOrigin®
CloudPilot Application Migration Tools Datasheet - CloudOrigin®UnifyCloud
 
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...Amazon Web Services
 
Maximo integration to other systems by Bashar Mahasen
 Maximo integration to other systems by Bashar Mahasen Maximo integration to other systems by Bashar Mahasen
Maximo integration to other systems by Bashar MahasenBashar Mahasen
 
Whitepaper factors to consider commercial infrastructure management vendors
Whitepaper  factors to consider commercial infrastructure management vendorsWhitepaper  factors to consider commercial infrastructure management vendors
Whitepaper factors to consider commercial infrastructure management vendorsapprize360
 
4 project management information system
4 project management information system4 project management information system
4 project management information systemDr.R. SELVAM
 
How to-migrate-and-manage-security-policies-in-a-segmented-data-center---webi...
How to-migrate-and-manage-security-policies-in-a-segmented-data-center---webi...How to-migrate-and-manage-security-policies-in-a-segmented-data-center---webi...
How to-migrate-and-manage-security-policies-in-a-segmented-data-center---webi...Adi Gazit Blecher
 
Whitepaper factors to consider when selecting an open source infrastructure ...
Whitepaper  factors to consider when selecting an open source infrastructure ...Whitepaper  factors to consider when selecting an open source infrastructure ...
Whitepaper factors to consider when selecting an open source infrastructure ...apprize360
 
Benefits of a Multi Regional API Management Solution for a Global Enterprise
Benefits of a Multi Regional API Management Solution for a Global EnterpriseBenefits of a Multi Regional API Management Solution for a Global Enterprise
Benefits of a Multi Regional API Management Solution for a Global EnterpriseWSO2
 
Presilient Worldwide at a Glance
Presilient Worldwide at a GlancePresilient Worldwide at a Glance
Presilient Worldwide at a GlanceKrystanne
 
ITIL Overview
ITIL OverviewITIL Overview
ITIL Overviewwdpowel
 
L Holution Srochure B V1
L Holution Srochure B V1L Holution Srochure B V1
L Holution Srochure B V1James McDermott
 

What's hot (20)

Cloud is a Process, Not a Tech Revolution
Cloud is a Process, Not a Tech RevolutionCloud is a Process, Not a Tech Revolution
Cloud is a Process, Not a Tech Revolution
 
Integration architecture framework
Integration architecture frameworkIntegration architecture framework
Integration architecture framework
 
Reduce Operational Costs in Healthcare by Adopting Lean Application Support ...
 Reduce Operational Costs in Healthcare by Adopting Lean Application Support ... Reduce Operational Costs in Healthcare by Adopting Lean Application Support ...
Reduce Operational Costs in Healthcare by Adopting Lean Application Support ...
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC Strategy
 
System Center Service Manager (Av Torgeir Bergsvik)
System Center Service Manager (Av Torgeir Bergsvik)System Center Service Manager (Av Torgeir Bergsvik)
System Center Service Manager (Av Torgeir Bergsvik)
 
Arcadia overview nr2
Arcadia overview nr2Arcadia overview nr2
Arcadia overview nr2
 
Application Crisis avoidance six things you can do
Application Crisis avoidance  six things you can doApplication Crisis avoidance  six things you can do
Application Crisis avoidance six things you can do
 
CloudPilot Application Migration Tools Datasheet - CloudOrigin®
CloudPilot Application Migration Tools Datasheet - CloudOrigin®CloudPilot Application Migration Tools Datasheet - CloudOrigin®
CloudPilot Application Migration Tools Datasheet - CloudOrigin®
 
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
AWS Summit 2013 | Singapore - Service Orchestration – Managing the Cloud Disr...
 
Maximo integration to other systems by Bashar Mahasen
 Maximo integration to other systems by Bashar Mahasen Maximo integration to other systems by Bashar Mahasen
Maximo integration to other systems by Bashar Mahasen
 
Whitepaper factors to consider commercial infrastructure management vendors
Whitepaper  factors to consider commercial infrastructure management vendorsWhitepaper  factors to consider commercial infrastructure management vendors
Whitepaper factors to consider commercial infrastructure management vendors
 
4 project management information system
4 project management information system4 project management information system
4 project management information system
 
Types of rule engine
Types of rule engineTypes of rule engine
Types of rule engine
 
How to-migrate-and-manage-security-policies-in-a-segmented-data-center---webi...
How to-migrate-and-manage-security-policies-in-a-segmented-data-center---webi...How to-migrate-and-manage-security-policies-in-a-segmented-data-center---webi...
How to-migrate-and-manage-security-policies-in-a-segmented-data-center---webi...
 
Afl rim capabilities
Afl rim capabilitiesAfl rim capabilities
Afl rim capabilities
 
Whitepaper factors to consider when selecting an open source infrastructure ...
Whitepaper  factors to consider when selecting an open source infrastructure ...Whitepaper  factors to consider when selecting an open source infrastructure ...
Whitepaper factors to consider when selecting an open source infrastructure ...
 
Benefits of a Multi Regional API Management Solution for a Global Enterprise
Benefits of a Multi Regional API Management Solution for a Global EnterpriseBenefits of a Multi Regional API Management Solution for a Global Enterprise
Benefits of a Multi Regional API Management Solution for a Global Enterprise
 
Presilient Worldwide at a Glance
Presilient Worldwide at a GlancePresilient Worldwide at a Glance
Presilient Worldwide at a Glance
 
ITIL Overview
ITIL OverviewITIL Overview
ITIL Overview
 
L Holution Srochure B V1
L Holution Srochure B V1L Holution Srochure B V1
L Holution Srochure B V1
 

Similar to GRC Africa The Paradigm Shift (Technology and GRC)

The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field Resolver Inc.
 
Asset Information Management (AIM) Presentation @ ARC's 2011 Industry Forum
Asset Information Management (AIM) Presentation @ ARC's 2011 Industry ForumAsset Information Management (AIM) Presentation @ ARC's 2011 Industry Forum
Asset Information Management (AIM) Presentation @ ARC's 2011 Industry ForumARC Advisory Group
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and TrendsMaclear LLC
 
How Nationwide Insurance Transformed and Accelerated its Small_1.3.1
How Nationwide Insurance Transformed and Accelerated its Small_1.3.1How Nationwide Insurance Transformed and Accelerated its Small_1.3.1
How Nationwide Insurance Transformed and Accelerated its Small_1.3.1ptulachan
 
Webinar | GE & Stork | APM Best Practices - Mechanical Integrity
Webinar | GE & Stork | APM Best Practices - Mechanical IntegrityWebinar | GE & Stork | APM Best Practices - Mechanical Integrity
Webinar | GE & Stork | APM Best Practices - Mechanical IntegrityStork
 
Gain business insight with Continuous Controls Monitoring
Gain business insight with Continuous Controls MonitoringGain business insight with Continuous Controls Monitoring
Gain business insight with Continuous Controls MonitoringEmma Kelly
 
ARC's Greg Gorbach CPM & Operations Mgmt Presentation @ ARC Industry Forum 2010
ARC's Greg Gorbach CPM & Operations Mgmt Presentation @ ARC Industry Forum 2010ARC's Greg Gorbach CPM & Operations Mgmt Presentation @ ARC Industry Forum 2010
ARC's Greg Gorbach CPM & Operations Mgmt Presentation @ ARC Industry Forum 2010ARC Advisory Group
 
Sabrion_Consulting_Overview CPG Retail Apparel.pdf
Sabrion_Consulting_Overview CPG Retail Apparel.pdfSabrion_Consulting_Overview CPG Retail Apparel.pdf
Sabrion_Consulting_Overview CPG Retail Apparel.pdfBrion Carroll (II)
 
Modernizing legacy systems
Modernizing legacy systemsModernizing legacy systems
Modernizing legacy systemsBhagvanK1
 
Dont let governance risk and compliance be a roll of the device | Modern Wor...
 Dont let governance risk and compliance be a roll of the device | Modern Wor... Dont let governance risk and compliance be a roll of the device | Modern Wor...
Dont let governance risk and compliance be a roll of the device | Modern Wor...Nikki Chapple
 
GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014Paul Simidi
 
SAP ERP IMPLEMENTATION AND Sap migration
SAP ERP IMPLEMENTATION AND Sap migrationSAP ERP IMPLEMENTATION AND Sap migration
SAP ERP IMPLEMENTATION AND Sap migrationArig
 
Reliability Engineering in Biomanufacturing - Presentation by Michael Andrews
Reliability Engineering in Biomanufacturing - Presentation by Michael AndrewsReliability Engineering in Biomanufacturing - Presentation by Michael Andrews
Reliability Engineering in Biomanufacturing - Presentation by Michael AndrewsWPICPE
 
Maximo KPI Maintenance & Asset Reliability Support Workshop IMC 2013 presenta...
Maximo KPI Maintenance & Asset Reliability Support Workshop IMC 2013 presenta...Maximo KPI Maintenance & Asset Reliability Support Workshop IMC 2013 presenta...
Maximo KPI Maintenance & Asset Reliability Support Workshop IMC 2013 presenta...Julie Rampello
 
Adaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyAdaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyRob Johnston, MBA
 
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...D. Scott Clark
 

Similar to GRC Africa The Paradigm Shift (Technology and GRC) (20)

GRC– The Way Forward
GRC– The Way ForwardGRC– The Way Forward
GRC– The Way Forward
 
The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field
 
Asset Information Management (AIM) Presentation @ ARC's 2011 Industry Forum
Asset Information Management (AIM) Presentation @ ARC's 2011 Industry ForumAsset Information Management (AIM) Presentation @ ARC's 2011 Industry Forum
Asset Information Management (AIM) Presentation @ ARC's 2011 Industry Forum
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
GRC
GRCGRC
GRC
 
How Nationwide Insurance Transformed and Accelerated its Small_1.3.1
How Nationwide Insurance Transformed and Accelerated its Small_1.3.1How Nationwide Insurance Transformed and Accelerated its Small_1.3.1
How Nationwide Insurance Transformed and Accelerated its Small_1.3.1
 
Webinar | GE & Stork | APM Best Practices - Mechanical Integrity
Webinar | GE & Stork | APM Best Practices - Mechanical IntegrityWebinar | GE & Stork | APM Best Practices - Mechanical Integrity
Webinar | GE & Stork | APM Best Practices - Mechanical Integrity
 
Gain business insight with Continuous Controls Monitoring
Gain business insight with Continuous Controls MonitoringGain business insight with Continuous Controls Monitoring
Gain business insight with Continuous Controls Monitoring
 
ARC's Greg Gorbach CPM & Operations Mgmt Presentation @ ARC Industry Forum 2010
ARC's Greg Gorbach CPM & Operations Mgmt Presentation @ ARC Industry Forum 2010ARC's Greg Gorbach CPM & Operations Mgmt Presentation @ ARC Industry Forum 2010
ARC's Greg Gorbach CPM & Operations Mgmt Presentation @ ARC Industry Forum 2010
 
Sabrion_Consulting_Overview CPG Retail Apparel.pdf
Sabrion_Consulting_Overview CPG Retail Apparel.pdfSabrion_Consulting_Overview CPG Retail Apparel.pdf
Sabrion_Consulting_Overview CPG Retail Apparel.pdf
 
Modernizing legacy systems
Modernizing legacy systemsModernizing legacy systems
Modernizing legacy systems
 
SAP License Services by Crayon Software Experts
SAP License Services by Crayon Software ExpertsSAP License Services by Crayon Software Experts
SAP License Services by Crayon Software Experts
 
Migration Planning
Migration PlanningMigration Planning
Migration Planning
 
Dont let governance risk and compliance be a roll of the device | Modern Wor...
 Dont let governance risk and compliance be a roll of the device | Modern Wor... Dont let governance risk and compliance be a roll of the device | Modern Wor...
Dont let governance risk and compliance be a roll of the device | Modern Wor...
 
GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014
 
SAP ERP IMPLEMENTATION AND Sap migration
SAP ERP IMPLEMENTATION AND Sap migrationSAP ERP IMPLEMENTATION AND Sap migration
SAP ERP IMPLEMENTATION AND Sap migration
 
Reliability Engineering in Biomanufacturing - Presentation by Michael Andrews
Reliability Engineering in Biomanufacturing - Presentation by Michael AndrewsReliability Engineering in Biomanufacturing - Presentation by Michael Andrews
Reliability Engineering in Biomanufacturing - Presentation by Michael Andrews
 
Maximo KPI Maintenance & Asset Reliability Support Workshop IMC 2013 presenta...
Maximo KPI Maintenance & Asset Reliability Support Workshop IMC 2013 presenta...Maximo KPI Maintenance & Asset Reliability Support Workshop IMC 2013 presenta...
Maximo KPI Maintenance & Asset Reliability Support Workshop IMC 2013 presenta...
 
Adaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyAdaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_study
 
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
 

More from Maganathin Veeraragaloo

Cybersecurity Capability Maturity Model (C2M2)
Cybersecurity Capability Maturity Model (C2M2)Cybersecurity Capability Maturity Model (C2M2)
Cybersecurity Capability Maturity Model (C2M2)Maganathin Veeraragaloo
 
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORKZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORKMaganathin Veeraragaloo
 
CYBERSECURITY MESH - DIGITAL TRUST FRAMEWORK
CYBERSECURITY MESH - DIGITAL TRUST FRAMEWORKCYBERSECURITY MESH - DIGITAL TRUST FRAMEWORK
CYBERSECURITY MESH - DIGITAL TRUST FRAMEWORKMaganathin Veeraragaloo
 
Enterprise security architecture approach
Enterprise security architecture approachEnterprise security architecture approach
Enterprise security architecture approachMaganathin Veeraragaloo
 
Domain 5 - Identity and Access Management
Domain 5 - Identity and Access Management Domain 5 - Identity and Access Management
Domain 5 - Identity and Access Management Maganathin Veeraragaloo
 

More from Maganathin Veeraragaloo (20)

MULTI-CLOUD ARCHITECTURE
MULTI-CLOUD ARCHITECTUREMULTI-CLOUD ARCHITECTURE
MULTI-CLOUD ARCHITECTURE
 
Cloud security (domain11 14)
Cloud security (domain11 14)Cloud security (domain11 14)
Cloud security (domain11 14)
 
Cloud security (domain6 10)
Cloud security (domain6 10)Cloud security (domain6 10)
Cloud security (domain6 10)
 
Cloud Security (Domain1- 5)
Cloud Security (Domain1- 5)Cloud Security (Domain1- 5)
Cloud Security (Domain1- 5)
 
BTABOK / ITABOK
BTABOK / ITABOKBTABOK / ITABOK
BTABOK / ITABOK
 
Observability
ObservabilityObservability
Observability
 
Foresight 4 Cybersecurity
Foresight 4 CybersecurityForesight 4 Cybersecurity
Foresight 4 Cybersecurity
 
Cybersecurity Capability Maturity Model (C2M2)
Cybersecurity Capability Maturity Model (C2M2)Cybersecurity Capability Maturity Model (C2M2)
Cybersecurity Capability Maturity Model (C2M2)
 
CLOUD NATIVE SECURITY
CLOUD NATIVE SECURITYCLOUD NATIVE SECURITY
CLOUD NATIVE SECURITY
 
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORKZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
 
ISO 27005 - Digital Trust Framework
ISO 27005 - Digital Trust FrameworkISO 27005 - Digital Trust Framework
ISO 27005 - Digital Trust Framework
 
CYBERSECURITY MESH - DIGITAL TRUST FRAMEWORK
CYBERSECURITY MESH - DIGITAL TRUST FRAMEWORKCYBERSECURITY MESH - DIGITAL TRUST FRAMEWORK
CYBERSECURITY MESH - DIGITAL TRUST FRAMEWORK
 
COBIT 2019 - DIGITAL TRUST FRAMEWORK
COBIT 2019 - DIGITAL TRUST FRAMEWORKCOBIT 2019 - DIGITAL TRUST FRAMEWORK
COBIT 2019 - DIGITAL TRUST FRAMEWORK
 
Open Digital Framework from TMFORUM
Open Digital Framework from TMFORUMOpen Digital Framework from TMFORUM
Open Digital Framework from TMFORUM
 
Enterprise security architecture approach
Enterprise security architecture approachEnterprise security architecture approach
Enterprise security architecture approach
 
Cloud and Data Privacy
Cloud and Data PrivacyCloud and Data Privacy
Cloud and Data Privacy
 
XaaS Overview
XaaS OverviewXaaS Overview
XaaS Overview
 
Multi cloud security architecture
Multi cloud security architecture Multi cloud security architecture
Multi cloud security architecture
 
Multi Cloud Architecture Approach
Multi Cloud Architecture ApproachMulti Cloud Architecture Approach
Multi Cloud Architecture Approach
 
Domain 5 - Identity and Access Management
Domain 5 - Identity and Access Management Domain 5 - Identity and Access Management
Domain 5 - Identity and Access Management
 

Recently uploaded

(SHINA) Call Girls Khed ( 7001035870 ) HI-Fi Pune Escorts Service
(SHINA) Call Girls Khed ( 7001035870 ) HI-Fi Pune Escorts Service(SHINA) Call Girls Khed ( 7001035870 ) HI-Fi Pune Escorts Service
(SHINA) Call Girls Khed ( 7001035870 ) HI-Fi Pune Escorts Serviceranjana rawat
 
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore EscortsVIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escortsaditipandeya
 
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Serviceranjana rawat
 
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceCunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceHigh Profile Call Girls
 
DNV publication: China Energy Transition Outlook 2024
DNV publication: China Energy Transition Outlook 2024DNV publication: China Energy Transition Outlook 2024
DNV publication: China Energy Transition Outlook 2024Energy for One World
 
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up NumberMs Riya
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escortsranjana rawat
 
Night 7k to 12k Call Girls Service In Navi Mumbai 👉 BOOK NOW 9833363713 👈 ♀️...
Night 7k to 12k  Call Girls Service In Navi Mumbai 👉 BOOK NOW 9833363713 👈 ♀️...Night 7k to 12k  Call Girls Service In Navi Mumbai 👉 BOOK NOW 9833363713 👈 ♀️...
Night 7k to 12k Call Girls Service In Navi Mumbai 👉 BOOK NOW 9833363713 👈 ♀️...aartirawatdelhi
 
PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)ahcitycouncil
 
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxIncident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxPeter Miles
 
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Serviceranjana rawat
 
How the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersHow the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersCongressional Budget Office
 
Human-AI Collaboration for Virtual Capacity in Emergency Operation Centers (E...
Human-AI Collaborationfor Virtual Capacity in Emergency Operation Centers (E...Human-AI Collaborationfor Virtual Capacity in Emergency Operation Centers (E...
Human-AI Collaboration for Virtual Capacity in Emergency Operation Centers (E...Hemant Purohit
 
WIPO magazine issue -1 - 2024 World Intellectual Property organization.
WIPO magazine issue -1 - 2024 World Intellectual Property organization.WIPO magazine issue -1 - 2024 World Intellectual Property organization.
WIPO magazine issue -1 - 2024 World Intellectual Property organization.Christina Parmionova
 
Item # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfItem # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfahcitycouncil
 
2024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 292024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 29JSchaus & Associates
 

Recently uploaded (20)

(SHINA) Call Girls Khed ( 7001035870 ) HI-Fi Pune Escorts Service
(SHINA) Call Girls Khed ( 7001035870 ) HI-Fi Pune Escorts Service(SHINA) Call Girls Khed ( 7001035870 ) HI-Fi Pune Escorts Service
(SHINA) Call Girls Khed ( 7001035870 ) HI-Fi Pune Escorts Service
 
The Federal Budget and Health Care Policy
The Federal Budget and Health Care PolicyThe Federal Budget and Health Care Policy
The Federal Budget and Health Care Policy
 
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore EscortsVIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escorts
 
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
 
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceCunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
 
DNV publication: China Energy Transition Outlook 2024
DNV publication: China Energy Transition Outlook 2024DNV publication: China Energy Transition Outlook 2024
DNV publication: China Energy Transition Outlook 2024
 
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
 
Night 7k to 12k Call Girls Service In Navi Mumbai 👉 BOOK NOW 9833363713 👈 ♀️...
Night 7k to 12k  Call Girls Service In Navi Mumbai 👉 BOOK NOW 9833363713 👈 ♀️...Night 7k to 12k  Call Girls Service In Navi Mumbai 👉 BOOK NOW 9833363713 👈 ♀️...
Night 7k to 12k Call Girls Service In Navi Mumbai 👉 BOOK NOW 9833363713 👈 ♀️...
 
Call Girls In Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In  Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCeCall Girls In  Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
 
PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)
 
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxIncident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
 
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
 
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance VVIP 🍎 SER...
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SER...Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SER...
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance VVIP 🍎 SER...
 
How the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersHow the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists Lawmakers
 
Human-AI Collaboration for Virtual Capacity in Emergency Operation Centers (E...
Human-AI Collaborationfor Virtual Capacity in Emergency Operation Centers (E...Human-AI Collaborationfor Virtual Capacity in Emergency Operation Centers (E...
Human-AI Collaboration for Virtual Capacity in Emergency Operation Centers (E...
 
WIPO magazine issue -1 - 2024 World Intellectual Property organization.
WIPO magazine issue -1 - 2024 World Intellectual Property organization.WIPO magazine issue -1 - 2024 World Intellectual Property organization.
WIPO magazine issue -1 - 2024 World Intellectual Property organization.
 
Item # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfItem # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdf
 
2024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 292024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 29
 

GRC Africa The Paradigm Shift (Technology and GRC)

  • 2. Agenda • Organisational Overview • GRC and Security Challenges • SAP GRC vs. SAS GRC • How to choose a GRC Platform? • How to implement GRC Platform? • Summary
  • 3. Agenda • Organisational Overview • GRC and Security Challenges • SAP GRC vs. SAS GRC • How to choose a GRC Platform? • How to implement GRC Platform? • Summary
  • 4. Organisational Overview • Eskom is a South African electricity public utility, established in 1923 as the Electricity Supply Commission (ESC) by the government of the Union of South Africa in terms of the Electricity Act (1922). • Eskom operates a number of notable power stations, ranging from Coal, Gas, Renewable and a Nuclear power plant. • The company is divided into Generation, Transmission and Distribution divisions and together Eskom generates approximately 95% of electricity used in South Africa.
  • 6. Technological Overview 6 • SAP PM • GPSS • THEMSE • CSS • COLLOPS • MDMS • FLIP • SCADA • MAXIMO/ TERTIARY WIRES • GTX • CS-ONLINE • AVAYA • VAT – MOBILITY • SMALLWORLD • FMS • ENS • PRIMAVERA • SPF • PRISM • SMALLWORLD & ENS • ACNAC • SMARTPLANT • ENGINEERING SYSTEMS • CIBOODLE • MV90 • ROUTEMASTER • AMI • ALFS • KSACS MDMS • CNL • CS-ONLINE INTEGRATION INTEGRATION INTEGRATION INTEGRATION
  • 7. Agenda • Organisational Overview • GRC and Security Challenges • SAP GRC vs. SAS GRC • How to choose a GRC Platform? • How to implement GRC Platform? • Summary
  • 8. GRC and Security Challenges Challenges Regulation Legislation Technology Models Business Models E.g. NERSA, SABA, HPSA, NCR E.g. Industry 4.0 E.g. FICA, PoPIE.g. IoT, Cloud Services
  • 9. Agenda • Organisational Overview • GRC and Security Challenges • SAP GRC vs. SAS GRC • How to choose a GRC Platform? • How to implement GRC Platform? • Summary
  • 10. SAP GRC vs. SAS GRC SAP GRC Overview
  • 11. SAP GRC vs. SAS GRC SAP GRC Overview
  • 12. SAP GRC vs. SAS GRC SAS GRC Overview
  • 13. SAP GRC vs. SAS GRC • SAS Enterprise GRC Features – Conduct audits – Manage policies – Conduct risk and control assessments – Test controls – Investigate incidents – Create and track issues and develop action plans – Scenario analysis
  • 14. SAP GRC vs. SAS GRC SAP Strengths SAS Strengths 1. Integration of Risk and Performance Management 1. Clear understanding of C-Suite needs 2. Integration other SAP Modules 2. Great Reporting 3. Advanced Data Analytics 3. Financial and Utility Capabilities SAP Cautions SAS Cautions 1. Pricing Model 1. Challenging Configuration 2. Customer Experience Satisfaction 2. Minimal Expectations 3. Extensive Configurations 3. Long Implementation Times
  • 15. Agenda • Organisational Overview • GRC and Security Challenges • SAP GRC vs. SAS GRC • How to choose a GRC Platform? • How to implement GRC Platform? • Summary
  • 16. How to choose a GRC Platform • The governance, risk and compliance (GRC) software market has evolved and segmented. • Risk management solutions and related processes are typically focused on individual functions across an organization, which inhibits collaboration and understanding of risk at an enterprise level. • Many organizations employ a "technology-first" mindset when trying to solve their most pressing risk management challenges.
  • 17. How to choose a GRC Platform • Organizations require features and functions for their GRC platform to support multiple risk management and compliance, specifically in the following functional categories: – Architecture – Reporting – Administration – Risk management – Incident management – Compliance and policy management – Regulatory intelligence and change management – Audit management – Etc.
  • 18. How to choose a GRC Platform Basel II/III Foreign Corrupt Practices Act Business continuity management Internal audit Corporate compliance management and oversight IT risk management Environmental, health and safety (EH&S) and sustainability Privacy compliance Enterprise risk management Project risk management Ethics compliance Security risk and compliance oversight Cyber Risk Management Third-party risk management Example of High Level Use Cases
  • 19. How to choose a GRC Platform Gartner Integrated Risk Management Solutions Corporate Compliance and Oversight Enterprise Legal Management Audit Management IT Risk Management Business Continuity Management Planning IT Vendor Risk Management Operational Risk Management
  • 20. How to choose a GRC Platform Risk Management Solution Integrated Risk Management Solution Business Continuity Management Planning Critical Capabilities for Operational Risk Management IT Vendor Risk Management IT Risk Management Audit Management Corporate Compliance and Oversight Enterprise Legal Management Chief Information Security Officer Chief Operating Officer Chief Risk Officer Chief Compliance Officer Chief Audit Executive Chief Legal Officer / General Counsel Chief Information Officer Chief Procurement Officer Chief Financial Officer Gartner IRMS Research and Related Key Stakeholder Roles
  • 21. How to choose a GRC Platform The Global Risks Report 2017 - 12th Edition (The Risks-Trends Interconnections Map)
  • 22. How to choose a GRC Platform Business Relevance Filter Technology Filter Economic Filter POV Filter
  • 23. Agenda • Organisational Overview • GRC and Security Challenges • SAP GRC vs. SAS GRC • How to choose a GRC Platform? • How to implement GRC Platform? • Summary
  • 24. How to implement GRC Platform • The key to the success of a GRC solution deployment continues to be the existence of clear requirements from management and well-defined processes. • The most successful GRC Platform deployments are characterized as automating and improving existing, or well-defined, practices versus deployments that seek to define GRC Platform around a tool.
  • 25. How to implement GRC Platform • Planning, and not technical issues, is at the root cause of most deployment failures. Deployment failures are most often the result of poorly defined requirements or unrealistic timelines and not because of technical problems with tools. • GRC solution selections are often heavily influenced by features that are never fully utilized. Solutions in this space often present long lists of features, but the resources requirements to implement and operationalize these features often fall outside the enterprise appetite. • Enterprises often underestimate the initial and ongoing resource requirements for utilizing policy management to map policy, controls and compliance requirements. Enterprises should ensure that they have a durable business case that justifies the necessary investment. • In order for GRC processes and their results to be relied upon by executives, auditors and examiners, they must inspire confidence.
  • 26. How to implement GRC Platform Time Skills Value 1. Identify the requirements and processes 2. Select and Prioritize Use Cases 3. Test the identified IRMS Module 4. Stabilise Infrastructure to Access and Analyse 5. Deploy the Selected Module(s) 6. Enable the Enterprise IRMS Awareness Mapping the Solution Path to the Typical Stages and Milestones of IRMS
  • 27. Agenda • Organisational Overview • GRC and Security Challenges • SAP GRC vs. SAS GRC • How to choose a GRC Platform? • How to implement GRC Platform? • Summary
  • 28. Summary • Failure to deliver Business Value • Improper Use Case Selection • Organisational InertiaStrategy • Identifying the wrong risks • Using unreliable data • Misunderstanding the nuances of Risk ModelsRisks • Lack of Skills • Inability to address adjacent technologies Skills Top Reasons for GRC Platform Failures
  • 30. Summary • Enterprises should invest time and energy in clearly defining the goals, objectives, measurements of success, and practices for IT GRC prior to pursuing the selection and deployment of these solutions. Once a goal state is clearly defined, enterprises can choose from a number of available solutions. • Ensure that the business case has been made not just for purchasing a solution, but also for the investments that are required to utilize and maintain it: GRC solutions are frequently purchased as a part of a push to address particular audit, compliance or regulatory concerns, and then they languish, underutilized, or become shelf ware. Secure a commitment not just to acquire capabilities, but also to implement and maintain the solution. Careful consideration must also be given to how ongoing maintenance will be staffed. • GRC itself is a set of processes and practices that aims to manage the risks of business use of IT and IT itself. Enterprises can purchase solutions to automate or improve IT GRC, but the actual work of governing, managing risk and addressing compliance requirements necessitates the enterprise to establish policies, procedures, practices, organizational structures and management expectations.