SlideShare a Scribd company logo
What is Continuous Controls Monitoring?
Continuous Controls Monitoring (CCM) is defined as applying technology to allow continuous (or at least high-frequency), automated monitoring of controls to validate the effectiveness
of controls designed to mitigate risk, including maintaining an active cyber defense posture and ensuring business continuity and regulatory compliance.
CCM has many use cases across industries. It exists in Financial Services as fraud monitoring and financial transaction monitoring. It’s utilized in Manufacturing for quality and process
control monitoring. Across industries, organizations are starting to deploy CCM over key control processes around network and data security.
There are a couple of different approaches to CCM implementation. It can be as simple as turning on certain settings in the source operating system and using its built-in dashboards and
reports.
To have a more comprehensive CCM system in place that monitors a wide range of controls across business domains, an organization needs a single repository that documents and
manages its controls and gathers evidence of their effectiveness. This type of system, commonly known as a compliance operations platform, is built to test and monitor controls at
scale. A compliance operations platform has connectors to common business applications across IT, Development, Security, HR, Sales, and Finance – and can pull relevant data about
many types of controls into its platform for streamlined controls assessment/validation.
All in all, CCM is a key aspect of Governance, Risk and Compliance that helps an enterprise improve its overall risk management.
Continuous Control Monitoring Radar
Benefits
Enhanced Accuracy: “Right the first time”— demonstrates the proportion of transactions that adhered to expected process and
tolerances…so you can focus on understanding and reducing anomalies.
Collaboration: You can increase trust and transparency across lines of defense through centralized dashboards and extractable
insight content.
Integration: CCM can help your organization connect and synthesize risk and control data from multiple platforms across the
enterprise
Reduce Costs: CCM can help your organization reduce costs, by reducing human capital effort on low-value testing, transferring risk
resolution to first line management, and highlighting process deviations for investigation
The Benefits of Implementing Continuous Controls Monitoring
• Organizations that deploy CCM enjoy numerous benefits, such as:
• Increased productivity of compliance/internal audit teams:
• These highly skilled employees are able to test more controls within a given timeframe so they’re more likely to catch issues before they develop into problems.
• These teams can do more impactful work and focus their time on strategic efforts such as including evaluating controls that require manual testing.
• Confidence that line managers and employees who operate the technologies that run key business processes are actively managing the risks that come with these
processes. Examples include:
• A senior engineer should always review new code before it gets deployed into the production environment.
• The admin for the company’s single sign-on system should remove any terminated employee from access within seven days of termination.
• A network security engineer needs to know that the application firewall is always on; if it isn’t, they need to fix it right away.
• A Chief Security Officer needs to know that the security team consistently patches “critical” vulnerabilities within seven days in accordance with its vulnerability
management program policy.
• Reduced remediation costs as control deficiencies are identified and fixed before they escalate.
• Increased visibility into the organization’s risk, security, and compliance posture for senior leaders.
• Improved ability to prioritize risk management decisions.
• Improved standing in the eyes of regulators, customers, and auditors with readily available evidence of risk mitigation, protection of valuable assets, and the
organization’s ability to meet its legal obligations.
Continuous Control Monitoring, when implemented effectively is an efficient way to handle that pressure.
Increased Visibility and Transparency of Operations: Real-time monitoring increases the visibility and transparency of activity, especially negatively impacting activities, and
mitigate the operational risk with a timely alert system that enables a good risk management and governance.
Analyzes and Traces Root Cause: A Continuous Control Monitoring tool can help analysts detect the correlation and root cause of certain critical anomalies. It enables the
corrections of root cause element anywhere within systems. This brings substantial performance achievement for the business.
Enables Rapid Response: Ultimately, the goal of Continuous Monitoring is to provide the organizations with fastest feedback, insight into business process controls and
interdependencies across the entire operations cycle. This helps drive operational, security and business performance.
Total visibility
Get a trusted, automated inventory
of all assets, accounts, apps and
cloud systems by combining data
from across your security and
business tools.
Complete control
With an automated inventory, you
can immediately uncover missing
assets and security control gaps. This
reduces the chance of a control
failure and builds confidence in
security reporting.
Faster remediation
Save time and rapidly reduce risk by
prioritising remediation campaigns
based on business context. Trusted,
reliable reporting improves
accountability by tracking fixes
against SLAs.
Presentation1.pptx

More Related Content

Similar to Presentation1.pptx

Running head AUDITING INFORMATION SYSTEMS PROCESS .docx
Running head AUDITING INFORMATION SYSTEMS PROCESS              .docxRunning head AUDITING INFORMATION SYSTEMS PROCESS              .docx
Running head AUDITING INFORMATION SYSTEMS PROCESS .docx
joellemurphey
 
RTCM.pptx
RTCM.pptxRTCM.pptx
RTCM.pptx
ScrumSystem
 
Fix nix, inc
Fix nix, incFix nix, inc
Fix nix, inc
FixNix Inc.,
 
Compliance Management Software | Corporate Compliance
Compliance Management Software | Corporate ComplianceCompliance Management Software | Corporate Compliance
Compliance Management Software | Corporate Compliance
Corporater
 
The Complete Guide to Building an Effective Enterprise Testing Strategy.pdf
The Complete Guide to Building an Effective Enterprise Testing Strategy.pdfThe Complete Guide to Building an Effective Enterprise Testing Strategy.pdf
The Complete Guide to Building an Effective Enterprise Testing Strategy.pdf
kalichargn70th171
 
Fixnix GRC Suite A Glance
Fixnix GRC Suite A GlanceFixnix GRC Suite A Glance
Fixnix GRC Suite A Glance
FixNix Inc.,
 
Effective quality management system
Effective quality management systemEffective quality management system
Effective quality management systemselinasimpson2601
 
Risk Assessment Framework
Risk Assessment FrameworkRisk Assessment Framework
Risk Assessment Framework
Jhurt7103
 
Test Management Montioring Control
Test Management Montioring ControlTest Management Montioring Control
Test Management Montioring Control
drishtipuro1234
 
Test Management Montioring Control
Test Management Montioring ControlTest Management Montioring Control
Test Management Montioring Control
sethnainaa
 
Audit software highlights
Audit software highlightsAudit software highlights
Audit software highlightssonisjs
 
Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais Part 1Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais Part 1
Sharing Slides Training
 
Ais Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And AisAis Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And Ais
sharing notes123
 
Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais Part 1Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais Part 1
sharing notes123
 
Ais Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And AisAis Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And Ais
Sharing Slides Training
 
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
gueste080564
 

Similar to Presentation1.pptx (20)

Running head AUDITING INFORMATION SYSTEMS PROCESS .docx
Running head AUDITING INFORMATION SYSTEMS PROCESS              .docxRunning head AUDITING INFORMATION SYSTEMS PROCESS              .docx
Running head AUDITING INFORMATION SYSTEMS PROCESS .docx
 
RTCM.pptx
RTCM.pptxRTCM.pptx
RTCM.pptx
 
Fix nix, inc
Fix nix, incFix nix, inc
Fix nix, inc
 
Compliance Management Software | Corporate Compliance
Compliance Management Software | Corporate ComplianceCompliance Management Software | Corporate Compliance
Compliance Management Software | Corporate Compliance
 
Auto audit
Auto auditAuto audit
Auto audit
 
The Complete Guide to Building an Effective Enterprise Testing Strategy.pdf
The Complete Guide to Building an Effective Enterprise Testing Strategy.pdfThe Complete Guide to Building an Effective Enterprise Testing Strategy.pdf
The Complete Guide to Building an Effective Enterprise Testing Strategy.pdf
 
Fixnix GRC Suite A Glance
Fixnix GRC Suite A GlanceFixnix GRC Suite A Glance
Fixnix GRC Suite A Glance
 
Effective quality management system
Effective quality management systemEffective quality management system
Effective quality management system
 
Risk Assessment Framework
Risk Assessment FrameworkRisk Assessment Framework
Risk Assessment Framework
 
Test Management Montioring Control
Test Management Montioring ControlTest Management Montioring Control
Test Management Montioring Control
 
Test Management Montioring Control
Test Management Montioring ControlTest Management Montioring Control
Test Management Montioring Control
 
It Governance Methodology Cox
It Governance Methodology CoxIt Governance Methodology Cox
It Governance Methodology Cox
 
Allgress_Brochure
Allgress_BrochureAllgress_Brochure
Allgress_Brochure
 
Audit software highlights
Audit software highlightsAudit software highlights
Audit software highlights
 
RAP GC 2016
RAP GC 2016RAP GC 2016
RAP GC 2016
 
Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais Part 1Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais Part 1
 
Ais Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And AisAis Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And Ais
 
Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais Part 1Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais Part 1
 
Ais Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And AisAis Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And Ais
 
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
 

Recently uploaded

Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Doctoral Symposium at the 17th IEEE International Conference on Software Test...Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Sebastiano Panichella
 
Supercharge your AI - SSP Industry Breakout Session 2024-v2_1.pdf
Supercharge your AI - SSP Industry Breakout Session 2024-v2_1.pdfSupercharge your AI - SSP Industry Breakout Session 2024-v2_1.pdf
Supercharge your AI - SSP Industry Breakout Session 2024-v2_1.pdf
Access Innovations, Inc.
 
0x01 - Newton's Third Law: Static vs. Dynamic Abusers
0x01 - Newton's Third Law:  Static vs. Dynamic Abusers0x01 - Newton's Third Law:  Static vs. Dynamic Abusers
0x01 - Newton's Third Law: Static vs. Dynamic Abusers
OWASP Beja
 
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
OECD Directorate for Financial and Enterprise Affairs
 
Getting started with Amazon Bedrock Studio and Control Tower
Getting started with Amazon Bedrock Studio and Control TowerGetting started with Amazon Bedrock Studio and Control Tower
Getting started with Amazon Bedrock Studio and Control Tower
Vladimir Samoylov
 
Bitcoin Lightning wallet and tic-tac-toe game XOXO
Bitcoin Lightning wallet and tic-tac-toe game XOXOBitcoin Lightning wallet and tic-tac-toe game XOXO
Bitcoin Lightning wallet and tic-tac-toe game XOXO
Matjaž Lipuš
 
Eureka, I found it! - Special Libraries Association 2021 Presentation
Eureka, I found it! - Special Libraries Association 2021 PresentationEureka, I found it! - Special Libraries Association 2021 Presentation
Eureka, I found it! - Special Libraries Association 2021 Presentation
Access Innovations, Inc.
 
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Orkestra
 
somanykidsbutsofewfathers-140705000023-phpapp02.pptx
somanykidsbutsofewfathers-140705000023-phpapp02.pptxsomanykidsbutsofewfathers-140705000023-phpapp02.pptx
somanykidsbutsofewfathers-140705000023-phpapp02.pptx
Howard Spence
 
Acorn Recovery: Restore IT infra within minutes
Acorn Recovery: Restore IT infra within minutesAcorn Recovery: Restore IT infra within minutes
Acorn Recovery: Restore IT infra within minutes
IP ServerOne
 
Gregory Harris' Civics Presentation.pptx
Gregory Harris' Civics Presentation.pptxGregory Harris' Civics Presentation.pptx
Gregory Harris' Civics Presentation.pptx
gharris9
 
International Workshop on Artificial Intelligence in Software Testing
International Workshop on Artificial Intelligence in Software TestingInternational Workshop on Artificial Intelligence in Software Testing
International Workshop on Artificial Intelligence in Software Testing
Sebastiano Panichella
 
Announcement of 18th IEEE International Conference on Software Testing, Verif...
Announcement of 18th IEEE International Conference on Software Testing, Verif...Announcement of 18th IEEE International Conference on Software Testing, Verif...
Announcement of 18th IEEE International Conference on Software Testing, Verif...
Sebastiano Panichella
 
Obesity causes and management and associated medical conditions
Obesity causes and management and associated medical conditionsObesity causes and management and associated medical conditions
Obesity causes and management and associated medical conditions
Faculty of Medicine And Health Sciences
 
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdfBonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
khadija278284
 
María Carolina Martínez - eCommerce Day Colombia 2024
María Carolina Martínez - eCommerce Day Colombia 2024María Carolina Martínez - eCommerce Day Colombia 2024
María Carolina Martínez - eCommerce Day Colombia 2024
eCommerce Institute
 
Media as a Mind Controlling Strategy In Old and Modern Era
Media as a Mind Controlling Strategy In Old and Modern EraMedia as a Mind Controlling Strategy In Old and Modern Era
Media as a Mind Controlling Strategy In Old and Modern Era
faizulhassanfaiz1670
 

Recently uploaded (17)

Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Doctoral Symposium at the 17th IEEE International Conference on Software Test...Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Doctoral Symposium at the 17th IEEE International Conference on Software Test...
 
Supercharge your AI - SSP Industry Breakout Session 2024-v2_1.pdf
Supercharge your AI - SSP Industry Breakout Session 2024-v2_1.pdfSupercharge your AI - SSP Industry Breakout Session 2024-v2_1.pdf
Supercharge your AI - SSP Industry Breakout Session 2024-v2_1.pdf
 
0x01 - Newton's Third Law: Static vs. Dynamic Abusers
0x01 - Newton's Third Law:  Static vs. Dynamic Abusers0x01 - Newton's Third Law:  Static vs. Dynamic Abusers
0x01 - Newton's Third Law: Static vs. Dynamic Abusers
 
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
 
Getting started with Amazon Bedrock Studio and Control Tower
Getting started with Amazon Bedrock Studio and Control TowerGetting started with Amazon Bedrock Studio and Control Tower
Getting started with Amazon Bedrock Studio and Control Tower
 
Bitcoin Lightning wallet and tic-tac-toe game XOXO
Bitcoin Lightning wallet and tic-tac-toe game XOXOBitcoin Lightning wallet and tic-tac-toe game XOXO
Bitcoin Lightning wallet and tic-tac-toe game XOXO
 
Eureka, I found it! - Special Libraries Association 2021 Presentation
Eureka, I found it! - Special Libraries Association 2021 PresentationEureka, I found it! - Special Libraries Association 2021 Presentation
Eureka, I found it! - Special Libraries Association 2021 Presentation
 
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
 
somanykidsbutsofewfathers-140705000023-phpapp02.pptx
somanykidsbutsofewfathers-140705000023-phpapp02.pptxsomanykidsbutsofewfathers-140705000023-phpapp02.pptx
somanykidsbutsofewfathers-140705000023-phpapp02.pptx
 
Acorn Recovery: Restore IT infra within minutes
Acorn Recovery: Restore IT infra within minutesAcorn Recovery: Restore IT infra within minutes
Acorn Recovery: Restore IT infra within minutes
 
Gregory Harris' Civics Presentation.pptx
Gregory Harris' Civics Presentation.pptxGregory Harris' Civics Presentation.pptx
Gregory Harris' Civics Presentation.pptx
 
International Workshop on Artificial Intelligence in Software Testing
International Workshop on Artificial Intelligence in Software TestingInternational Workshop on Artificial Intelligence in Software Testing
International Workshop on Artificial Intelligence in Software Testing
 
Announcement of 18th IEEE International Conference on Software Testing, Verif...
Announcement of 18th IEEE International Conference on Software Testing, Verif...Announcement of 18th IEEE International Conference on Software Testing, Verif...
Announcement of 18th IEEE International Conference on Software Testing, Verif...
 
Obesity causes and management and associated medical conditions
Obesity causes and management and associated medical conditionsObesity causes and management and associated medical conditions
Obesity causes and management and associated medical conditions
 
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdfBonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
 
María Carolina Martínez - eCommerce Day Colombia 2024
María Carolina Martínez - eCommerce Day Colombia 2024María Carolina Martínez - eCommerce Day Colombia 2024
María Carolina Martínez - eCommerce Day Colombia 2024
 
Media as a Mind Controlling Strategy In Old and Modern Era
Media as a Mind Controlling Strategy In Old and Modern EraMedia as a Mind Controlling Strategy In Old and Modern Era
Media as a Mind Controlling Strategy In Old and Modern Era
 

Presentation1.pptx

  • 1. What is Continuous Controls Monitoring? Continuous Controls Monitoring (CCM) is defined as applying technology to allow continuous (or at least high-frequency), automated monitoring of controls to validate the effectiveness of controls designed to mitigate risk, including maintaining an active cyber defense posture and ensuring business continuity and regulatory compliance. CCM has many use cases across industries. It exists in Financial Services as fraud monitoring and financial transaction monitoring. It’s utilized in Manufacturing for quality and process control monitoring. Across industries, organizations are starting to deploy CCM over key control processes around network and data security. There are a couple of different approaches to CCM implementation. It can be as simple as turning on certain settings in the source operating system and using its built-in dashboards and reports. To have a more comprehensive CCM system in place that monitors a wide range of controls across business domains, an organization needs a single repository that documents and manages its controls and gathers evidence of their effectiveness. This type of system, commonly known as a compliance operations platform, is built to test and monitor controls at scale. A compliance operations platform has connectors to common business applications across IT, Development, Security, HR, Sales, and Finance – and can pull relevant data about many types of controls into its platform for streamlined controls assessment/validation. All in all, CCM is a key aspect of Governance, Risk and Compliance that helps an enterprise improve its overall risk management. Continuous Control Monitoring Radar Benefits Enhanced Accuracy: “Right the first time”— demonstrates the proportion of transactions that adhered to expected process and tolerances…so you can focus on understanding and reducing anomalies. Collaboration: You can increase trust and transparency across lines of defense through centralized dashboards and extractable insight content. Integration: CCM can help your organization connect and synthesize risk and control data from multiple platforms across the enterprise Reduce Costs: CCM can help your organization reduce costs, by reducing human capital effort on low-value testing, transferring risk resolution to first line management, and highlighting process deviations for investigation
  • 2. The Benefits of Implementing Continuous Controls Monitoring • Organizations that deploy CCM enjoy numerous benefits, such as: • Increased productivity of compliance/internal audit teams: • These highly skilled employees are able to test more controls within a given timeframe so they’re more likely to catch issues before they develop into problems. • These teams can do more impactful work and focus their time on strategic efforts such as including evaluating controls that require manual testing. • Confidence that line managers and employees who operate the technologies that run key business processes are actively managing the risks that come with these processes. Examples include: • A senior engineer should always review new code before it gets deployed into the production environment. • The admin for the company’s single sign-on system should remove any terminated employee from access within seven days of termination. • A network security engineer needs to know that the application firewall is always on; if it isn’t, they need to fix it right away. • A Chief Security Officer needs to know that the security team consistently patches “critical” vulnerabilities within seven days in accordance with its vulnerability management program policy. • Reduced remediation costs as control deficiencies are identified and fixed before they escalate. • Increased visibility into the organization’s risk, security, and compliance posture for senior leaders. • Improved ability to prioritize risk management decisions. • Improved standing in the eyes of regulators, customers, and auditors with readily available evidence of risk mitigation, protection of valuable assets, and the organization’s ability to meet its legal obligations. Continuous Control Monitoring, when implemented effectively is an efficient way to handle that pressure. Increased Visibility and Transparency of Operations: Real-time monitoring increases the visibility and transparency of activity, especially negatively impacting activities, and mitigate the operational risk with a timely alert system that enables a good risk management and governance. Analyzes and Traces Root Cause: A Continuous Control Monitoring tool can help analysts detect the correlation and root cause of certain critical anomalies. It enables the corrections of root cause element anywhere within systems. This brings substantial performance achievement for the business. Enables Rapid Response: Ultimately, the goal of Continuous Monitoring is to provide the organizations with fastest feedback, insight into business process controls and interdependencies across the entire operations cycle. This helps drive operational, security and business performance.
  • 3. Total visibility Get a trusted, automated inventory of all assets, accounts, apps and cloud systems by combining data from across your security and business tools. Complete control With an automated inventory, you can immediately uncover missing assets and security control gaps. This reduces the chance of a control failure and builds confidence in security reporting. Faster remediation Save time and rapidly reduce risk by prioritising remediation campaigns based on business context. Trusted, reliable reporting improves accountability by tracking fixes against SLAs.