SlideShare a Scribd company logo
Transforming	
  compliance	
  and	
  	
  
audit	
  management	
  with	
  ServiceNow	
  
DEMO	
  WEBINAR	
  •	
  July	
  24,	
  2018	
  
	
  
Delivering Risk Intelligence
David	
  Pearson	
  
CTO	
  &	
  SENIOR	
  GRC	
  CONSULTANT	
  
	
  
Travis	
  Giff	
  
SENIOR	
  GRC	
  ARCHITECT	
  	
  
&	
  DEVELOPER	
  
	
  
Today’s	
  presenters	
  
About	
  Iceberg	
  
ü  100%	
  focus	
  on	
  Governance,	
  	
  
Risk	
  Management	
  &	
  Compliance	
  (GRC)	
  
ü  Staff	
  includes	
  25+	
  full-­‐Xme	
  GRC	
  consultants	
  
&	
  cerXfied	
  developers	
  
ü  Customers	
  include	
  top	
  financials,	
  
insurance,	
  health	
  care,	
  manufacturers,	
  
retail,	
  government	
  in	
  North	
  America.	
  
Delivering Risk Intelligence
“Trusted,	
  aggregated	
  and	
  transparent	
  risk	
  data	
  enabling	
  organizations	
  
to	
  make	
  more	
  informed,	
  con:ident	
  and	
  effective	
  business	
  decisions.”	
  
Delivering	
  Risk	
  Intelligence	
  
Disconnected	
  risk	
  
&	
  business	
  data	
  
Aggregated	
  &	
  
integrated	
  for	
  context	
  
Analyzed	
  &	
  
interpreted	
  
Be_er	
  business	
  
decisions	
  &	
  acXons	
  
Delivering Risk Intelligence
A	
  full	
  lifecycle	
  of	
  GRC	
  services	
  
Management	
  
Workshops	
  
Visioning	
  &	
  Alignment	
  
CMO/FMO	
  
KRI/KxI	
  
Professional	
  
Services	
  
ImplementaXon	
  
&	
  IntegraXon	
  
SoluXon	
  Lifecycle	
  
Management	
  
Iceberg	
  
APS	
  
Post-­‐ProducXon	
  Support	
  
Mentoring,	
  Coaching	
  	
  
&	
  Skills	
  Development	
  
Sandboxes	
  
	
  
Risk	
  Intelligence	
  
Academy	
  
Case	
  Studies	
  
Best	
  PracXces	
  
Webinars	
  
	
  
GRC	
  
InnovaCon	
  
ReporXng	
  /	
  Dashboards	
  
Toolkits	
  &	
  Enhancements	
  
	
  
	
  
Delivering Risk Intelligence
Demo	
  Company	
  Pro-ile	
  
Ø  SaaS	
  for	
  markeXng/comms	
  
Ø  1,000	
  employees	
  
Ø  6	
  million	
  users	
  worldwide	
  
Ø  75	
  customers	
  in	
  the	
  the	
  Fortune	
  100	
  
Delivering Risk Intelligence
Challenges	
  
1	
  
ExisXng	
  internal	
  control	
  
structure	
  based	
  on	
  SOC2;	
  
need	
  to	
  leverage/adapt	
  to	
  
include	
  FedRAMP,	
  GDPR,	
  
and	
  other	
  regulaXons	
  
	
  
2	
  
Current	
  SOC2	
  a_estaXon	
  
process	
  done	
  with	
  
spreadsheets	
  /	
  email.	
  	
  	
  
Time	
  consuming	
  +	
  lack	
  of	
  
transparency	
  
	
  
3	
  
Poor	
  coordinaXon	
  of	
  
acXviXes	
  between	
  Control	
  
Owners	
  and	
  Auditors	
  for	
  
collecXon	
  of	
  evidence	
  and	
  
tracking	
  remediaXons.	
  
Delivering Risk Intelligence
Project	
  Goals	
  
1	
  
Demonstrate	
  that	
  
internal	
  controls	
  
conform	
  to	
  regulatory	
  
requirements	
  
	
  
2	
  
Simplify	
  the	
  
a_estaXon	
  process	
  
(make	
  it	
  easier	
  	
  
for	
  users)	
  
3	
  
Provide	
  greater	
  
visibility	
  into	
  the	
  
a_estaXon	
  process,	
  
and	
  track	
  the	
  state	
  of	
  
evidence	
  collecXon	
  
	
  
4	
  
Simplify	
  interacXon	
  
with	
  external	
  auditor	
  
for	
  collecXon	
  of	
  
evidence	
  
	
  
ServiceNow	
  Governance,	
  Risk,	
  and	
  Compliance	
  (GRC)	
  
Source:	
  Unified	
  Compliance	
  Framework	
  
Rs	
  
Research	
  Sites	
  
Ad	
  
Authority	
  
Docs	
  
Ct	
  
CitaXons	
  
Ac	
  
Acronyms	
  
Gl	
  
Glossary	
  
Cd	
  
cDocs	
  
Ro	
  
Roles	
  
Me	
  
Metrics	
  
Ce	
  
Controls	
  
As	
  
Assets	
  
Re	
  
Rec	
  
Examples	
  
Ci	
  
Config	
  
Items	
  
Cm	
  
Config	
  
Methods	
  
Ve	
  
Vendors	
  
Rc	
  
Record	
  
Category	
  
Ot	
  
Org	
  
Tasks	
  
Of	
  
Org	
  
FuncXons	
  
Au	
  
Audit	
  
Ev	
  
Events	
  
Content	
  Provider	
  (UCF)	
   ServiceNow	
  Reference	
  Content	
  Objects	
  
Authority	
  
Documents	
  
CitaXons	
  
Policy	
  
Statements	
  
Policies	
  
POLICY & COMPLIANCE
MANAGEMENT RISK MANAGEMENT AUDIT MANAGEMENT VENDOR RISK MANAGEMENT
Delivering Risk Intelligence
	
  
Key	
  AcCviCes	
  
•  Manage	
  Authority	
  Documents,	
  CitaXons,	
  
Policy	
  Statements	
  
•  Assign	
  Control	
  Owners	
  
•  Manage	
  Policy	
  ExcepXons	
  
•  Set	
  up	
  Indicators	
  for	
  ConXnuous	
  Monitoring	
  
	
   Compliance	
  Manager	
  	
  
	
  
“As	
  a	
  Compliance	
  Manager	
  of	
  XYZ	
  Company	
  I	
  need	
  to	
  manage	
  my	
  organizaBons	
  
internal	
  policies	
  and	
  ensure	
  my	
  organizaBon	
  is	
  compliant	
  with	
  the	
  various	
  
regulatory	
  frameworks.”	
  
	
  
Delivering Risk Intelligence
	
  
Key	
  AcCviCes	
  
•  Complete	
  Control	
  A_estaXons	
  
•  Respond	
  to	
  Ad	
  Hoc	
  Evidence	
  Requests	
  
•  Follow	
  up	
  with	
  any	
  Issues	
  and	
  RemediaXon	
  
Tasks	
  
	
  
Control	
  Owner	
  
	
  
	
  
“As	
  a	
  Control	
  Owner	
  of	
  XYZ	
  Company	
  I	
  need	
  to	
  ensure	
  the	
  proper	
  controls	
  are	
  in	
  
place	
  by	
  reviewing	
  the	
  control	
  guidance,	
  implemenBng	
  the	
  control	
  and	
  by	
  
providing	
  sufficient	
  evidence	
  of	
  the	
  control	
  being	
  in	
  place.”	
  
	
  
Delivering Risk Intelligence
	
  
Key	
  AcCviCes	
  
•  Manage	
  my	
  Audit	
  Engagements	
  
•  Manage	
  my	
  team	
  
•  Maximize	
  Control	
  TesXng	
  Efforts	
  
•  Follow	
  up	
  with	
  any	
  Issues	
  and	
  RemediaXon	
  Tasks	
  
	
  
Audit	
  Manager	
  
	
  
“As	
  a	
  Audit	
  Manager	
  I	
  need	
  to	
  manage	
  task	
  assignment	
  to	
  my	
  internal	
  and	
  
external	
  audit	
  staff,	
  ensure	
  all	
  controls	
  that	
  are	
  in	
  place	
  are	
  designed	
  and	
  
operaBng	
  effecBvely,	
  and	
  follow	
  up	
  with	
  issues	
  and	
  remediaBon	
  tasks	
  for	
  non-­‐
compliant	
  controls.	
  “	
  
Delivering Risk Intelligence
Demo	
  
Delivering Risk Intelligence
Driving	
  Outcomes	
  
1	
  
CONSOLIDATE	
  
MulXple	
  regulatory	
  
frameworks,	
  control	
  
structure	
  &	
  evidence	
  now	
  
in	
  one	
  central	
  repository	
  
2	
  
MANAGE	
  &	
  AUTOMATE	
  
Visibility	
  into	
  a_estaXon	
  
process,	
  lower	
  burden	
  on	
  
resources	
  
3	
  
COLLABORATE	
  	
  
Between	
  audit	
  and	
  control	
  
owners,	
  and	
  with	
  external	
  
audit	
  
	
  
Delivering Risk Intelligence
Implementation	
  details	
  
8-­‐week	
  implementaXon	
  
	
  
Most	
  effort	
  in	
  implementaCon	
  is	
  NOT	
  configuraCon	
  
it’s	
  understanding	
  the	
  structure	
  of	
  data,	
  roles	
  &	
  access,	
  reporXng	
  
requirements,	
  workflows	
  &	
  lifecycle	
  
Delivering Risk Intelligence
What’s	
  next?	
  
ü  Use	
  CI’s	
  created	
  for	
  this	
  project	
  as	
  a	
  foundaXon	
  for	
  a	
  more	
  
comprehensive	
  CMDB	
  
ü  Layer	
  on	
  risk	
  management,	
  including	
  risk	
  assessments	
  
ü  Incorporate	
  more	
  regulaXons	
  and	
  internal	
  policies	
  into	
  the	
  
exisXng	
  framework	
  
ü  Compliance	
  as	
  a	
  compeXXve	
  edge:	
  showcase	
  maturity	
  &	
  best	
  
pracXces	
  to	
  customers	
  
Delivering Risk Intelligence
A	
  foundation	
  for	
  Integrated	
  Risk	
  Management	
  (IRM)	
  
Delivering Risk Intelligence
Q&A	
  
David	
  Pearson	
  
CTO	
  &	
  SENIOR	
  GRC	
  CONSULTANT	
   Travis	
  Giff	
  
SENIOR	
  GRC	
  ARCHITECT	
  	
  
&	
  DEVELOPER	
  
	
  
Thank	
  you!	
  
Webinar	
  replay:	
  icebergnetworks.com	
  

More Related Content

What's hot

ITSM & JIRA Service Desk
ITSM & JIRA Service DeskITSM & JIRA Service Desk
ITSM & JIRA Service Desk
Ambientia
 
SYSPRO ERP for Manufacturing
SYSPRO ERP for Manufacturing SYSPRO ERP for Manufacturing
SYSPRO ERP for Manufacturing
SYSPRO
 
Azure DevOps
Azure DevOpsAzure DevOps
Azure DevOps
Juan Fabian
 
Uncover the mysteries of infrastructure as code (iac)!
Uncover the mysteries of infrastructure as code (iac)!Uncover the mysteries of infrastructure as code (iac)!
Uncover the mysteries of infrastructure as code (iac)!
Prashant Kalkar
 
Data Design for Microservices
Data Design for MicroservicesData Design for Microservices
Data Design for Microservices
Amazon Web Services
 
IT4IT Overview (A new standard for IT management)
IT4IT Overview (A new standard for IT management)IT4IT Overview (A new standard for IT management)
IT4IT Overview (A new standard for IT management)
Charles Betz
 
Itil v3 release and deployment management
Itil v3 release and deployment managementItil v3 release and deployment management
Itil v3 release and deployment management
kunaljoy11
 
ServiceNow Overview
ServiceNow OverviewServiceNow Overview
ServiceNow Overview
Jeremy Smith
 
Event Driven Architecture
Event Driven ArchitectureEvent Driven Architecture
Event Driven Architecture
Lourens Naudé
 
Gap Assessment for DevOps
Gap Assessment   for DevOpsGap Assessment   for DevOps
Gap Assessment for DevOps
Marc Hornbeek
 
The Bill for IT: IT Service Costing, Showback, & Chargebacks with PCMCS
The Bill for IT:  IT Service Costing, Showback, & Chargebacks with PCMCSThe Bill for IT:  IT Service Costing, Showback, & Chargebacks with PCMCS
The Bill for IT: IT Service Costing, Showback, & Chargebacks with PCMCS
Joseph Alaimo Jr
 
IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022
Rob Akershoek
 
Event Driven Architecture
Event Driven ArchitectureEvent Driven Architecture
Event Driven Architecture
Chris Patterson
 
Solution deck capgemini cloud assessment
Solution deck capgemini cloud assessmentSolution deck capgemini cloud assessment
Solution deck capgemini cloud assessment
Adobe
 
IT4IT - The Full Story for Digital Transformation - Part 2
IT4IT - The Full Story for Digital Transformation - Part 2IT4IT - The Full Story for Digital Transformation - Part 2
IT4IT - The Full Story for Digital Transformation - Part 2
Mohamed Zakarya Abdelgawad
 
Digital Operating Model & IT4IT
Digital Operating Model & IT4ITDigital Operating Model & IT4IT
Digital Operating Model & IT4IT
David Favelle
 
Product Roadmap - May 2018
Product Roadmap - May 2018Product Roadmap - May 2018
Product Roadmap - May 2018
eMoney Advisor LLC
 
ITIL4 and ServiceNow
ITIL4 and ServiceNowITIL4 and ServiceNow
ITIL4 and ServiceNow
ITSM Academy, Inc.
 
How to Execute a Successful API Strategy
How to Execute a Successful API StrategyHow to Execute a Successful API Strategy
How to Execute a Successful API Strategy
Matt McLarty
 
Observability
ObservabilityObservability

What's hot (20)

ITSM & JIRA Service Desk
ITSM & JIRA Service DeskITSM & JIRA Service Desk
ITSM & JIRA Service Desk
 
SYSPRO ERP for Manufacturing
SYSPRO ERP for Manufacturing SYSPRO ERP for Manufacturing
SYSPRO ERP for Manufacturing
 
Azure DevOps
Azure DevOpsAzure DevOps
Azure DevOps
 
Uncover the mysteries of infrastructure as code (iac)!
Uncover the mysteries of infrastructure as code (iac)!Uncover the mysteries of infrastructure as code (iac)!
Uncover the mysteries of infrastructure as code (iac)!
 
Data Design for Microservices
Data Design for MicroservicesData Design for Microservices
Data Design for Microservices
 
IT4IT Overview (A new standard for IT management)
IT4IT Overview (A new standard for IT management)IT4IT Overview (A new standard for IT management)
IT4IT Overview (A new standard for IT management)
 
Itil v3 release and deployment management
Itil v3 release and deployment managementItil v3 release and deployment management
Itil v3 release and deployment management
 
ServiceNow Overview
ServiceNow OverviewServiceNow Overview
ServiceNow Overview
 
Event Driven Architecture
Event Driven ArchitectureEvent Driven Architecture
Event Driven Architecture
 
Gap Assessment for DevOps
Gap Assessment   for DevOpsGap Assessment   for DevOps
Gap Assessment for DevOps
 
The Bill for IT: IT Service Costing, Showback, & Chargebacks with PCMCS
The Bill for IT:  IT Service Costing, Showback, & Chargebacks with PCMCSThe Bill for IT:  IT Service Costing, Showback, & Chargebacks with PCMCS
The Bill for IT: IT Service Costing, Showback, & Chargebacks with PCMCS
 
IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022
 
Event Driven Architecture
Event Driven ArchitectureEvent Driven Architecture
Event Driven Architecture
 
Solution deck capgemini cloud assessment
Solution deck capgemini cloud assessmentSolution deck capgemini cloud assessment
Solution deck capgemini cloud assessment
 
IT4IT - The Full Story for Digital Transformation - Part 2
IT4IT - The Full Story for Digital Transformation - Part 2IT4IT - The Full Story for Digital Transformation - Part 2
IT4IT - The Full Story for Digital Transformation - Part 2
 
Digital Operating Model & IT4IT
Digital Operating Model & IT4ITDigital Operating Model & IT4IT
Digital Operating Model & IT4IT
 
Product Roadmap - May 2018
Product Roadmap - May 2018Product Roadmap - May 2018
Product Roadmap - May 2018
 
ITIL4 and ServiceNow
ITIL4 and ServiceNowITIL4 and ServiceNow
ITIL4 and ServiceNow
 
How to Execute a Successful API Strategy
How to Execute a Successful API StrategyHow to Execute a Successful API Strategy
How to Execute a Successful API Strategy
 
Observability
ObservabilityObservability
Observability
 

Similar to Transforming compliance and audit management with ServiceNow

TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
Tuan Phan
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
Tri Phan
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard
Jim Robins
 
Fixnix GRC Suite A Glance
Fixnix GRC Suite A GlanceFixnix GRC Suite A Glance
Fixnix GRC Suite A Glance
FixNix Inc.,
 
Establishing the Core of an Effective Technology Risk Management Program
Establishing the Core of an Effective Technology Risk Management ProgramEstablishing the Core of an Effective Technology Risk Management Program
Establishing the Core of an Effective Technology Risk Management Program
Amna Awan
 
Regulatory Compliance Audit Management Solution
Regulatory Compliance Audit Management SolutionRegulatory Compliance Audit Management Solution
Regulatory Compliance Audit Management Solution
Lawrbit Lextech India Private Limited
 
Auto audit
Auto auditAuto audit
Auto audit
Mazen Baset
 
Infographic: Maturing Audit Plans and Processes
Infographic: Maturing Audit Plans and Processes Infographic: Maturing Audit Plans and Processes
Infographic: Maturing Audit Plans and Processes
EMC
 
LinkedInProfile_Deck09072016
LinkedInProfile_Deck09072016LinkedInProfile_Deck09072016
LinkedInProfile_Deck09072016
buckkulkarni
 
WEBINAR: Enhance your perspective of vendor risk with ServiceNow
WEBINAR: Enhance your perspective of vendor risk with ServiceNowWEBINAR: Enhance your perspective of vendor risk with ServiceNow
WEBINAR: Enhance your perspective of vendor risk with ServiceNow
Iceberg Networks Corporation
 
A Financial Planning Leader Streamlines Audit, Risk and Compliance
A Financial Planning Leader Streamlines Audit, Risk and Compliance A Financial Planning Leader Streamlines Audit, Risk and Compliance
A Financial Planning Leader Streamlines Audit, Risk and Compliance
MetricStream Inc
 
Internal Audit Solution - MetricStream
Internal Audit Solution - MetricStream Internal Audit Solution - MetricStream
Internal Audit Solution - MetricStream
MetricStream Inc
 
Presentation_20110802213554
Presentation_20110802213554Presentation_20110802213554
Presentation_20110802213554
P Karlin Panggalo.SE.MM.Ak.CA.CFA.CCM
 
Adaptive RiskPro
Adaptive RiskProAdaptive RiskPro
Adaptive RiskPro
LN Mishra CBAP
 
Enterprise Risk Management Solutions
Enterprise Risk Management SolutionsEnterprise Risk Management Solutions
Enterprise Risk Management Solutions
LexComply
 
Project Management Overview
Project Management OverviewProject Management Overview
Project Management Overview
Rockon0017i5
 
Quality Management Systems - Aviation Industry
Quality Management Systems - Aviation IndustryQuality Management Systems - Aviation Industry
Quality Management Systems - Aviation Industry
Ali Al-Zubaidi
 
4 Quality System Musts for Medtech Startups to Get Safer Products to Market F...
4 Quality System Musts for Medtech Startups to Get Safer Products to Market F...4 Quality System Musts for Medtech Startups to Get Safer Products to Market F...
4 Quality System Musts for Medtech Startups to Get Safer Products to Market F...
Greenlight Guru
 
Audits & Inspections_Katalyst HLS
Audits & Inspections_Katalyst HLSAudits & Inspections_Katalyst HLS
Audits & Inspections_Katalyst HLS
Katalyst HLS
 
Project Quality - Chapter 1.pptx
Project Quality - Chapter 1.pptxProject Quality - Chapter 1.pptx
Project Quality - Chapter 1.pptx
BscCS1
 

Similar to Transforming compliance and audit management with ServiceNow (20)

TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard
 
Fixnix GRC Suite A Glance
Fixnix GRC Suite A GlanceFixnix GRC Suite A Glance
Fixnix GRC Suite A Glance
 
Establishing the Core of an Effective Technology Risk Management Program
Establishing the Core of an Effective Technology Risk Management ProgramEstablishing the Core of an Effective Technology Risk Management Program
Establishing the Core of an Effective Technology Risk Management Program
 
Regulatory Compliance Audit Management Solution
Regulatory Compliance Audit Management SolutionRegulatory Compliance Audit Management Solution
Regulatory Compliance Audit Management Solution
 
Auto audit
Auto auditAuto audit
Auto audit
 
Infographic: Maturing Audit Plans and Processes
Infographic: Maturing Audit Plans and Processes Infographic: Maturing Audit Plans and Processes
Infographic: Maturing Audit Plans and Processes
 
LinkedInProfile_Deck09072016
LinkedInProfile_Deck09072016LinkedInProfile_Deck09072016
LinkedInProfile_Deck09072016
 
WEBINAR: Enhance your perspective of vendor risk with ServiceNow
WEBINAR: Enhance your perspective of vendor risk with ServiceNowWEBINAR: Enhance your perspective of vendor risk with ServiceNow
WEBINAR: Enhance your perspective of vendor risk with ServiceNow
 
A Financial Planning Leader Streamlines Audit, Risk and Compliance
A Financial Planning Leader Streamlines Audit, Risk and Compliance A Financial Planning Leader Streamlines Audit, Risk and Compliance
A Financial Planning Leader Streamlines Audit, Risk and Compliance
 
Internal Audit Solution - MetricStream
Internal Audit Solution - MetricStream Internal Audit Solution - MetricStream
Internal Audit Solution - MetricStream
 
Presentation_20110802213554
Presentation_20110802213554Presentation_20110802213554
Presentation_20110802213554
 
Adaptive RiskPro
Adaptive RiskProAdaptive RiskPro
Adaptive RiskPro
 
Enterprise Risk Management Solutions
Enterprise Risk Management SolutionsEnterprise Risk Management Solutions
Enterprise Risk Management Solutions
 
Project Management Overview
Project Management OverviewProject Management Overview
Project Management Overview
 
Quality Management Systems - Aviation Industry
Quality Management Systems - Aviation IndustryQuality Management Systems - Aviation Industry
Quality Management Systems - Aviation Industry
 
4 Quality System Musts for Medtech Startups to Get Safer Products to Market F...
4 Quality System Musts for Medtech Startups to Get Safer Products to Market F...4 Quality System Musts for Medtech Startups to Get Safer Products to Market F...
4 Quality System Musts for Medtech Startups to Get Safer Products to Market F...
 
Audits & Inspections_Katalyst HLS
Audits & Inspections_Katalyst HLSAudits & Inspections_Katalyst HLS
Audits & Inspections_Katalyst HLS
 
Project Quality - Chapter 1.pptx
Project Quality - Chapter 1.pptxProject Quality - Chapter 1.pptx
Project Quality - Chapter 1.pptx
 

More from Iceberg Networks Corporation

Yes, there is a better way to do vendor risk assessments!
Yes, there is a better way to do vendor risk assessments!Yes, there is a better way to do vendor risk assessments!
Yes, there is a better way to do vendor risk assessments!
Iceberg Networks Corporation
 
How Archer users are leveraging Iceberg APS for a stronger GRC program
How Archer users are leveraging Iceberg APS for a stronger GRC programHow Archer users are leveraging Iceberg APS for a stronger GRC program
How Archer users are leveraging Iceberg APS for a stronger GRC program
Iceberg Networks Corporation
 
Iceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Webinar: Adding relevant financial context to your BCM programIceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Networks Corporation
 
Webinar: Evolve Beyond the Third Line
Webinar: Evolve Beyond the Third LineWebinar: Evolve Beyond the Third Line
Webinar: Evolve Beyond the Third Line
Iceberg Networks Corporation
 
Webinar: Getting a grip on application risk
Webinar: Getting a grip on application riskWebinar: Getting a grip on application risk
Webinar: Getting a grip on application risk
Iceberg Networks Corporation
 
Case study: Getting a grip on application risk
Case study: Getting a grip on application riskCase study: Getting a grip on application risk
Case study: Getting a grip on application risk
Iceberg Networks Corporation
 
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Iceberg Networks Corporation
 
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPRSolution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
Iceberg Networks Corporation
 
RSA-Iceberg Seminar: Building an effective supplier risk management program
RSA-Iceberg Seminar: Building an effective supplier risk management programRSA-Iceberg Seminar: Building an effective supplier risk management program
RSA-Iceberg Seminar: Building an effective supplier risk management program
Iceberg Networks Corporation
 
Solving data publication challenges for even better rsa archer reporting
Solving data publication challenges for even better rsa archer reportingSolving data publication challenges for even better rsa archer reporting
Solving data publication challenges for even better rsa archer reporting
Iceberg Networks Corporation
 

More from Iceberg Networks Corporation (10)

Yes, there is a better way to do vendor risk assessments!
Yes, there is a better way to do vendor risk assessments!Yes, there is a better way to do vendor risk assessments!
Yes, there is a better way to do vendor risk assessments!
 
How Archer users are leveraging Iceberg APS for a stronger GRC program
How Archer users are leveraging Iceberg APS for a stronger GRC programHow Archer users are leveraging Iceberg APS for a stronger GRC program
How Archer users are leveraging Iceberg APS for a stronger GRC program
 
Iceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Webinar: Adding relevant financial context to your BCM programIceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Webinar: Adding relevant financial context to your BCM program
 
Webinar: Evolve Beyond the Third Line
Webinar: Evolve Beyond the Third LineWebinar: Evolve Beyond the Third Line
Webinar: Evolve Beyond the Third Line
 
Webinar: Getting a grip on application risk
Webinar: Getting a grip on application riskWebinar: Getting a grip on application risk
Webinar: Getting a grip on application risk
 
Case study: Getting a grip on application risk
Case study: Getting a grip on application riskCase study: Getting a grip on application risk
Case study: Getting a grip on application risk
 
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
 
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPRSolution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
 
RSA-Iceberg Seminar: Building an effective supplier risk management program
RSA-Iceberg Seminar: Building an effective supplier risk management programRSA-Iceberg Seminar: Building an effective supplier risk management program
RSA-Iceberg Seminar: Building an effective supplier risk management program
 
Solving data publication challenges for even better rsa archer reporting
Solving data publication challenges for even better rsa archer reportingSolving data publication challenges for even better rsa archer reporting
Solving data publication challenges for even better rsa archer reporting
 

Recently uploaded

Innovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & InnovationInnovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & Innovation
Operational Excellence Consulting
 
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
my Pandit
 
Digital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital ExcellenceDigital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital Excellence
Operational Excellence Consulting
 
Building Your Employer Brand with Social Media
Building Your Employer Brand with Social MediaBuilding Your Employer Brand with Social Media
Building Your Employer Brand with Social Media
LuanWise
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
ssuser567e2d
 
Income Tax exemption for Start up : Section 80 IAC
Income Tax  exemption for Start up : Section 80 IACIncome Tax  exemption for Start up : Section 80 IAC
Income Tax exemption for Start up : Section 80 IAC
CA Dr. Prithvi Ranjan Parhi
 
Part 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 SlowdownPart 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 Slowdown
jeffkluth1
 
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challengesEvent Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Holger Mueller
 
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
my Pandit
 
How to Implement a Real Estate CRM Software
How to Implement a Real Estate CRM SoftwareHow to Implement a Real Estate CRM Software
How to Implement a Real Estate CRM Software
SalesTown
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
Christian Dahlen
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
sssourabhsharma
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
my Pandit
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
SabaaSudozai
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
JeremyPeirce1
 
Business storytelling: key ingredients to a story
Business storytelling: key ingredients to a storyBusiness storytelling: key ingredients to a story
Business storytelling: key ingredients to a story
Alexandra Fulford
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
Adnet Communications
 
2022 Vintage Roman Numerals Men Rings
2022 Vintage Roman  Numerals  Men  Rings2022 Vintage Roman  Numerals  Men  Rings
2022 Vintage Roman Numerals Men Rings
aragme
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
3 Simple Steps To Buy Verified Payoneer Account In 2024
3 Simple Steps To Buy Verified Payoneer Account In 20243 Simple Steps To Buy Verified Payoneer Account In 2024
3 Simple Steps To Buy Verified Payoneer Account In 2024
SEOSMMEARTH
 

Recently uploaded (20)

Innovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & InnovationInnovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & Innovation
 
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
 
Digital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital ExcellenceDigital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital Excellence
 
Building Your Employer Brand with Social Media
Building Your Employer Brand with Social MediaBuilding Your Employer Brand with Social Media
Building Your Employer Brand with Social Media
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
 
Income Tax exemption for Start up : Section 80 IAC
Income Tax  exemption for Start up : Section 80 IACIncome Tax  exemption for Start up : Section 80 IAC
Income Tax exemption for Start up : Section 80 IAC
 
Part 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 SlowdownPart 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 Slowdown
 
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challengesEvent Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
 
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
 
How to Implement a Real Estate CRM Software
How to Implement a Real Estate CRM SoftwareHow to Implement a Real Estate CRM Software
How to Implement a Real Estate CRM Software
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
 
Business storytelling: key ingredients to a story
Business storytelling: key ingredients to a storyBusiness storytelling: key ingredients to a story
Business storytelling: key ingredients to a story
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
 
2022 Vintage Roman Numerals Men Rings
2022 Vintage Roman  Numerals  Men  Rings2022 Vintage Roman  Numerals  Men  Rings
2022 Vintage Roman Numerals Men Rings
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
 
3 Simple Steps To Buy Verified Payoneer Account In 2024
3 Simple Steps To Buy Verified Payoneer Account In 20243 Simple Steps To Buy Verified Payoneer Account In 2024
3 Simple Steps To Buy Verified Payoneer Account In 2024
 

Transforming compliance and audit management with ServiceNow

  • 1. Transforming  compliance  and     audit  management  with  ServiceNow   DEMO  WEBINAR  •  July  24,  2018    
  • 2. Delivering Risk Intelligence David  Pearson   CTO  &  SENIOR  GRC  CONSULTANT     Travis  Giff   SENIOR  GRC  ARCHITECT     &  DEVELOPER     Today’s  presenters   About  Iceberg   ü  100%  focus  on  Governance,     Risk  Management  &  Compliance  (GRC)   ü  Staff  includes  25+  full-­‐Xme  GRC  consultants   &  cerXfied  developers   ü  Customers  include  top  financials,   insurance,  health  care,  manufacturers,   retail,  government  in  North  America.  
  • 3. Delivering Risk Intelligence “Trusted,  aggregated  and  transparent  risk  data  enabling  organizations   to  make  more  informed,  con:ident  and  effective  business  decisions.”   Delivering  Risk  Intelligence   Disconnected  risk   &  business  data   Aggregated  &   integrated  for  context   Analyzed  &   interpreted   Be_er  business   decisions  &  acXons  
  • 4. Delivering Risk Intelligence A  full  lifecycle  of  GRC  services   Management   Workshops   Visioning  &  Alignment   CMO/FMO   KRI/KxI   Professional   Services   ImplementaXon   &  IntegraXon   SoluXon  Lifecycle   Management   Iceberg   APS   Post-­‐ProducXon  Support   Mentoring,  Coaching     &  Skills  Development   Sandboxes     Risk  Intelligence   Academy   Case  Studies   Best  PracXces   Webinars     GRC   InnovaCon   ReporXng  /  Dashboards   Toolkits  &  Enhancements      
  • 5. Delivering Risk Intelligence Demo  Company  Pro-ile   Ø  SaaS  for  markeXng/comms   Ø  1,000  employees   Ø  6  million  users  worldwide   Ø  75  customers  in  the  the  Fortune  100  
  • 6. Delivering Risk Intelligence Challenges   1   ExisXng  internal  control   structure  based  on  SOC2;   need  to  leverage/adapt  to   include  FedRAMP,  GDPR,   and  other  regulaXons     2   Current  SOC2  a_estaXon   process  done  with   spreadsheets  /  email.       Time  consuming  +  lack  of   transparency     3   Poor  coordinaXon  of   acXviXes  between  Control   Owners  and  Auditors  for   collecXon  of  evidence  and   tracking  remediaXons.  
  • 7. Delivering Risk Intelligence Project  Goals   1   Demonstrate  that   internal  controls   conform  to  regulatory   requirements     2   Simplify  the   a_estaXon  process   (make  it  easier     for  users)   3   Provide  greater   visibility  into  the   a_estaXon  process,   and  track  the  state  of   evidence  collecXon     4   Simplify  interacXon   with  external  auditor   for  collecXon  of   evidence    
  • 8. ServiceNow  Governance,  Risk,  and  Compliance  (GRC)   Source:  Unified  Compliance  Framework   Rs   Research  Sites   Ad   Authority   Docs   Ct   CitaXons   Ac   Acronyms   Gl   Glossary   Cd   cDocs   Ro   Roles   Me   Metrics   Ce   Controls   As   Assets   Re   Rec   Examples   Ci   Config   Items   Cm   Config   Methods   Ve   Vendors   Rc   Record   Category   Ot   Org   Tasks   Of   Org   FuncXons   Au   Audit   Ev   Events   Content  Provider  (UCF)   ServiceNow  Reference  Content  Objects   Authority   Documents   CitaXons   Policy   Statements   Policies   POLICY & COMPLIANCE MANAGEMENT RISK MANAGEMENT AUDIT MANAGEMENT VENDOR RISK MANAGEMENT
  • 9. Delivering Risk Intelligence   Key  AcCviCes   •  Manage  Authority  Documents,  CitaXons,   Policy  Statements   •  Assign  Control  Owners   •  Manage  Policy  ExcepXons   •  Set  up  Indicators  for  ConXnuous  Monitoring     Compliance  Manager       “As  a  Compliance  Manager  of  XYZ  Company  I  need  to  manage  my  organizaBons   internal  policies  and  ensure  my  organizaBon  is  compliant  with  the  various   regulatory  frameworks.”    
  • 10. Delivering Risk Intelligence   Key  AcCviCes   •  Complete  Control  A_estaXons   •  Respond  to  Ad  Hoc  Evidence  Requests   •  Follow  up  with  any  Issues  and  RemediaXon   Tasks     Control  Owner       “As  a  Control  Owner  of  XYZ  Company  I  need  to  ensure  the  proper  controls  are  in   place  by  reviewing  the  control  guidance,  implemenBng  the  control  and  by   providing  sufficient  evidence  of  the  control  being  in  place.”    
  • 11. Delivering Risk Intelligence   Key  AcCviCes   •  Manage  my  Audit  Engagements   •  Manage  my  team   •  Maximize  Control  TesXng  Efforts   •  Follow  up  with  any  Issues  and  RemediaXon  Tasks     Audit  Manager     “As  a  Audit  Manager  I  need  to  manage  task  assignment  to  my  internal  and   external  audit  staff,  ensure  all  controls  that  are  in  place  are  designed  and   operaBng  effecBvely,  and  follow  up  with  issues  and  remediaBon  tasks  for  non-­‐ compliant  controls.  “  
  • 13. Delivering Risk Intelligence Driving  Outcomes   1   CONSOLIDATE   MulXple  regulatory   frameworks,  control   structure  &  evidence  now   in  one  central  repository   2   MANAGE  &  AUTOMATE   Visibility  into  a_estaXon   process,  lower  burden  on   resources   3   COLLABORATE     Between  audit  and  control   owners,  and  with  external   audit    
  • 14. Delivering Risk Intelligence Implementation  details   8-­‐week  implementaXon     Most  effort  in  implementaCon  is  NOT  configuraCon   it’s  understanding  the  structure  of  data,  roles  &  access,  reporXng   requirements,  workflows  &  lifecycle  
  • 15. Delivering Risk Intelligence What’s  next?   ü  Use  CI’s  created  for  this  project  as  a  foundaXon  for  a  more   comprehensive  CMDB   ü  Layer  on  risk  management,  including  risk  assessments   ü  Incorporate  more  regulaXons  and  internal  policies  into  the   exisXng  framework   ü  Compliance  as  a  compeXXve  edge:  showcase  maturity  &  best   pracXces  to  customers  
  • 16. Delivering Risk Intelligence A  foundation  for  Integrated  Risk  Management  (IRM)  
  • 17. Delivering Risk Intelligence Q&A   David  Pearson   CTO  &  SENIOR  GRC  CONSULTANT   Travis  Giff   SENIOR  GRC  ARCHITECT     &  DEVELOPER    
  • 18. Thank  you!   Webinar  replay:  icebergnetworks.com