IT Governance Risk and Compliance GRC

Download as pdf or txt
Download as pdf or txt
You are on page 1of 30

IT

GRC WORKSHOP

IT GOVERNANCE, RISK & COMPLIANCE


BRINGING IT ALL TOGETHER

PRESENTATION OUTLINE


1 2 3 4 5 Information Protection Management Div. What is Governance, Risk & Compliance? Enterprise Governance, Risk & Compliance IT Governance, Risk & Compliance IT Control Frameworks

WHAT IS GOVERNANCE, RISK & COMPLIANCE?


GENERAL PERSPECTIVE

GOVERNANCE, RISK, AND COMPLIANCE


Governance
vIs the process by which policies are set and decision making is executed.

Risk Management
vIs the process of iden:ca:on, analysis and either acceptance or mi:ga:on of uncertainty in decision-making.

Compliance
vIs the process of adherence to policies and decisions.

INTERRELATIONSHIP BETWEEN GOVERNANCE, RISK, AND COMPLIANCE


Governance manages the strategic direc7ves a company wants to follow.

Governance

GRC
Risk management assesses the areas of exposure and poten7al impacts.

Risk

Compliance

Compliance is the tac7cal ac7on to mi7gate risk.

WHY FOCUS ON GRC NOW?


Risks have become more diverse and interrelated. Laws and regula:ons have become more complicated. Boards, execu:ves and management have become more accountable.

This puts organiza:ons at greater risk and makes it dicult and costly for Management to do their jobs eec:vely.

PROBLEMS FACED BY ORGANIZATIONS


Too much risk for the return we are geJng Too liKle value from business-IT investments Slow decision making Project overruns and delays Lack of stability, availability, protec:on and recoverability

GRC SPECIFIC PROBLEMS FACED BY ORGANIZATIONS


GRC ac:vi:es and controls are fragmented and managed in silos Organiza:ons use reac:ve, one-o approaches to address compliance issues Risk and compliance considera:ons are not integrated into core business processes and mainstream decision-making Leaders oOen lack an enterprise view of risks IT assets are not well aligned with risk or compliance management needs Management does not have the high-quality informa:on they need

IMPROVING EFFICIENCY AND EFFECTIVENESS REQUIRES IMPROVEMENT IN THREE ASPECTS OF GRC


A?en7on
Awareness & People

Improvements are dependent on progress in other areas. Eciency


Automa:on & Tools

Eec7veness
Governance & Processes

ESSENTIAL ELEMENTS OF A GRC PROGRAM


Governance
Centralized repository of policies and controls Integrated database of major regulations, standards and best practices Comprehensive policy management with awareness campaigns and attestation Controls management and reporting

Risk
Risk management, including key risk indicators and risk dashboards

Compliance
Compliance assessment, monitoring and reporting

BENEFITS OF INTEGRATING GRC


Make risk-informed strategic decisions. Analyze risk based on quan:ta:ve data. Manage compliance. Priori:ze remedia:on ac:vi:es.

ENTERPRISE GOVERNANCE, RISK & COMPLIANCE


TO UNDERSTAND IT GRC YOU MUST FIRST UNDERSTAND ENTERPRISE GRC

ENTERPRISE GRC

Governance
Strategy

Risk Management
Assessment

Compliance
Assessment Reporting

Planning

Mitigation

AN ENTERPRISE GRC PLATFORM


Auditors Boards

Audit Management Risk Management

Compliance Management Remediation Management Policy Management

Risk & Controls Matrix

Enterprise GRC Platform

MANAGEMEMT

PROCESSES

PEOPLE

IT GOVERNANCE, RISK & COMPLIANCE


TO ESTABLISH MORE ACCOUNTABLE AND EFFECTIVE IT FUNCTIONS

IT GRC TIES TOGETHER THE PROGRAMS OF..


IT Governance
v An IT governance program to leverage the developed risk-based op:ons in support of an organiza:ons decision-making process.

IT Risk management
v An IT risk management program performs risk assessment to develop and priori:ze op:ons for remedia:on

IT Compliance
v An IT compliance program to measure the level of compliance within an IT environment

IT-GRC

IT GRC MEANS MANAGING


IT strategy IT services Systems infrastructure Informa:on management Informa:on security Resource availability (hardware, soOware & data) Data integrity Technology risk Legal and regulatory compliance

GRC MATURITY MODEL


Current IT-GRC Maturity. Next Phase

REACTIVE, FRAGMENTED IMPLEMENTATION PHASE


GRC ac:vi:es are largely manual, not standardized and not well integrated into core business processes GRC ac:vi:es have not received as much aKen:on in the past Most organiza:ons have treated governance, risk and compliance as discrete ac:vi:es, separate from mainstream business processes and decision making Exis:ng IT infrastructures, applica:ons and processes do not provide sucient support for eec:ve risk management and ecient compliance

IT GRC MUST BE DRIVEN FROM THE TOP-DOWN


Corporate GRC is an important input for dening IT GRC. IT GRC requires senior business par:cipa:on, especially at the board level.

IT CONTROL FRAMEWORKS
COBIT CONTROL OBJECTIVES FOR INFORMATION AND RELATED TECHNOLOGY

COBIT AND OTHER IT MANAGEMENT FRAMEWORKS

WHERE DOES COBIT FIT?

THE COBIT FRAMEWORK WAS DESIGNED TO PROVIDE..


A comprehensive control framework to cover: IT organiza:on IT users IT professionals IT governance IT risks IT processes

SUMMARY
IT GRC is a subset of Corporate Governance IT GRC comprises of:
vIT Governance vIT Risk vIT Compliance

Governance

GRC
Risk Compliance

Without one you cannot have the other..


vGovernance, Risk and Compliance are interrelated

DO YOU HAVE ANY QUESTIONS?

Thank you !

BREAK

You might also like