SlideShare ist ein Scribd-Unternehmen logo
1 von 22
Downloaden Sie, um offline zu lesen
IT Security Services
CONTROL FACTORY
|BEHIND THE SCENES|
Software Quality principles applied to
Security Controls
ITSecurityServices
BUSINESS ENVIRONMENT
CONTROL FACTORY |BEHIND THE SCENES|
ENERGY GIANT / BUSINESS LINE / BUSINESS UNIT
Integrated and dynamic management of
portfolio – purchasing contracts, assets and
sales contracts
Management & Trading of Energy
Client Business Environment
REGULATORY/CONTROLS CONSTRAINTS
Highly monitored and regularly audited
activities
Internal
controls
Compliance
Legal
External
audits
Group internal controls
Business line controls
Internal Compliance & Legal
Risk Operations
Internally driven Externally driven
Various
Auditors
ITSecurityServices
CONTROLS FRAMING
CONTROL FACTORY |BEHIND THE SCENES|
Security Controls governance
 Discipline/Part of Corporate Governance focused on
information technology (IT) oriented security controls
aligned with business constraints
Security Control book
 An important element of a framework ensuring that
the organization’s policies/requirements are
formalized, monitored and implemented as controls
over time
 A centralization of security controls carried out on the
organization
 A tool-based methodology implementing the security
control strategy
FRAMING CONTROLS BASED ON REQUIREMENTS
Controlsources
Requirement
Campaign
1
2
3
n
n
n
n
n
n
relationship | cardinality
Report/Gap analysis needs
Execution coverage
Requirement coverage
SECURITY CONTROLS | SOFTWARE QUALITY PRINCIPLES
Standards
Regulation
Internal
Framework
In-house best
practices
Sources of requirements
Risks
Requirement 1
Requirement 2
Requirement 3
Requirement 4
Requirement “n”
internal REG
REG
Internal
IN HOUSE
AUDIT
…
Sources of control
Control 1
Control 2
REQ 1 REQ 2
REQ 1 REQ 4
Sourcesofcampaign
Iteration 1
Campaign1
Control “n”
REQ n REQ n
Campaign “n”
CTL n
CTL 4
CTL n
Sourcesofiterations
Iteration 2
CAM 1
Iteration 1
Iteration 2
CAM 2
Requirement view
Control view
Campaign view
Execution view
Incidents
CONTROL ECOSYSTEM
CAM 1
CAM 2
Title
Description
Criticality
Category
(Security, Business…)
Owner
Group/source
(tag or ordering)
Covered risk
FRAMEWORK @ A GLANCE
Requirement template
Title Description
Nature
(administrative, technical, physical)
Function
(preventive, detective, corrective, recovery)
Type
(Security)
Frequency
Level
(1 to 3)
RACI matrix
FRAMEWORK @ A GLANCE
Control template
Title Description
Control suites
(STU 1, STU 2,…)
Assignee
Planning
Execution status
Basic stats
Control plan
(CTL1, CTL2,…)
FRAMEWORK @ A GLANCE
Campaign template
Controlsources
Requirement
Campaign
1
2
3
n
n
n
n
n
n
relationship | cardinality
Report/Gap analysis needs
Execution coverage
Requirement coverage



- Requirements covered by controls ?
- All controls associated to requirement ?
- Controls executed as expected ?
- Execution coverage of requirement ?


SECURITY CONTROLS | SOFTWARE QUALITY PRINCIPLES
ITSecurityServices
IAM SECURITY OPERATIONS
CONTROL FACTORY |BEHIND THE SCENES|
CONTROL FACTORY | DEFINE
refers to :
Control Factory (CF)
a structured collection of assets
that aids in producing controls through an assembly process
according to specific requirements1 3
2 4
The Control factory applies manufacturing
techniques and principles …
> Formalization > Automation
> Services Oriented > Industrialization
Right process  right result Reduce manual intervention
Activities divided in services Reusable components
CONTROL FACTORY | OBJECTIVES
… to mimic the benefits of traditional
manufacturing
>Consistency
build multiple instances of a control product line & set of
controls sharing similar “features and architecture”
>Quality
integrates reusable controls reducing the likelihood of control
design flaws
>Productivity
Controls activities can be streamlined and automated
Conception
Design and logic according to
requirements
Suppliers
relationship
Sourcing of data,
qualification, remediation
Production
Producing resources for
controls reports, dashboards
Delivery
Making resources for controls
available
Supervision
Governing controls campaign
and remediation
Internal
QA, maintenance,
improvements
CONTROL FACTORY | ACTIVITIES/SERVICES
Customers
CONTROL FACTORY | PRODUCTION SERVICES
Control Production
Production is divided in 6 distinct stages :
Supply Raw data from multiple collect sources
Compute Loading, ordering & storing data
Reconcile Identities vs. accounts
Control Production of control resources
SoD Advanced controls
Report Presenting results as expected
PRODUCTION SERVICES| SUPPLY
Supply
… loading raw data, reconciliation, mapping
and ordering for reuse
Controlsfactory
Advanced controls
Reports/views
Controls
Data Reconciliation
Compute
2
3
1
Attaching identities to respective
unitary organization
Reconciling identities with accounts,
perms…
Producing controls in the factory
Reporting results in expected views 4
…
PRODUCTION SERVICES| REPORT
Report … presenting control data as requested
(format & delivery)
• Timeslots
• Reports
• Data exports
Web portal
• Reports sent to
reviewers
Campaign
Data
Lifecycle
Data
Quality
Data
Volume
Business
Activity
CONTROLS GOVERNANCE | FOCUS ON PITFALLS
 Reduce treatment time
from import to
remediation
 Based on reliable data,
readable and
understandable
 Deeply analyzed and divided i.e.
volume that are “control ready”
and “supervision ready”
 Better integration of
stakeholders
processes
› Ergonomics and design
› Administration
› Dashboard & Reporting
› Automation
CAMPAIGN & CONTROLS | ANALYSIS
› Tickets directly created and assigned
› Follow-up using the factory
› Dynamic reports (web interfaces)
› Point and click review
› Enriched information
› Delegation mechanism enhanced
› Improved planning and review mechanism
Orientations and improvements
› Automated and real-time
› Web-based dashboard
ITSecurityServices
THANK U / QUESTIONS
CONTROL FACTORY |BEHIND THE SCENES|

Weitere ähnliche Inhalte

Was ist angesagt?

BSA 375 Final Assignment Team presentation
BSA 375 Final Assignment Team presentationBSA 375 Final Assignment Team presentation
BSA 375 Final Assignment Team presentationMichael Jeter
 
Complete Purchasing Process For Small Business
Complete Purchasing Process For Small BusinessComplete Purchasing Process For Small Business
Complete Purchasing Process For Small BusinessBill Kohnen
 
Accounting system and control
Accounting system and controlAccounting system and control
Accounting system and controlRaziya Hameed
 
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016StratesysUSA
 
Document Integrity - Maximize Your Benefits Through Production Management
Document Integrity - Maximize Your Benefits Through Production Management Document Integrity - Maximize Your Benefits Through Production Management
Document Integrity - Maximize Your Benefits Through Production Management Crawford Technologies, Inc.
 
Internal Control
Internal ControlInternal Control
Internal ControlSalih Islam
 
The Revenue Cycle
The Revenue Cycle The Revenue Cycle
The Revenue Cycle Qamar Farooq
 
KITARON ERP&MES system Advantages
KITARON ERP&MES system AdvantagesKITARON ERP&MES system Advantages
KITARON ERP&MES system AdvantagesGeosoft Systems
 
Cg Risk Management Info Presentation
Cg Risk Management Info PresentationCg Risk Management Info Presentation
Cg Risk Management Info Presentationjlevenberg
 
'Electronic Batch Process recording system
'Electronic Batch Process recording system'Electronic Batch Process recording system
'Electronic Batch Process recording systemanusa
 
CONTROL AND AUDIT
CONTROL AND AUDITCONTROL AND AUDIT
CONTROL AND AUDITRos Dina
 
Lecture 23 expenditure cycle part ii -fixed assets accounting information sy...
Lecture 23  expenditure cycle part ii -fixed assets accounting information sy...Lecture 23  expenditure cycle part ii -fixed assets accounting information sy...
Lecture 23 expenditure cycle part ii -fixed assets accounting information sy...Habib Ullah Qamar
 
Context of Organisations
Context of OrganisationsContext of Organisations
Context of Organisationsprateek verma
 
ERP implementation at steel mill
ERP implementation at steel millERP implementation at steel mill
ERP implementation at steel millAsher Jawad
 

Was ist angesagt? (19)

BSA 375 Final Assignment Team presentation
BSA 375 Final Assignment Team presentationBSA 375 Final Assignment Team presentation
BSA 375 Final Assignment Team presentation
 
Complete Purchasing Process For Small Business
Complete Purchasing Process For Small BusinessComplete Purchasing Process For Small Business
Complete Purchasing Process For Small Business
 
Documents system
Documents systemDocuments system
Documents system
 
Oracle Enterprise Manager
Oracle Enterprise ManagerOracle Enterprise Manager
Oracle Enterprise Manager
 
Accounting system and control
Accounting system and controlAccounting system and control
Accounting system and control
 
008.itsecurity bcp v1
008.itsecurity bcp v1008.itsecurity bcp v1
008.itsecurity bcp v1
 
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016
Stratesys - eDMS Solution OpenText - Flyer+Ebers (USA) - JUNIO2016
 
ATPL ERP
ATPL ERPATPL ERP
ATPL ERP
 
Oow2014 nk 2
Oow2014 nk 2Oow2014 nk 2
Oow2014 nk 2
 
Document Integrity - Maximize Your Benefits Through Production Management
Document Integrity - Maximize Your Benefits Through Production Management Document Integrity - Maximize Your Benefits Through Production Management
Document Integrity - Maximize Your Benefits Through Production Management
 
Internal Control
Internal ControlInternal Control
Internal Control
 
The Revenue Cycle
The Revenue Cycle The Revenue Cycle
The Revenue Cycle
 
KITARON ERP&MES system Advantages
KITARON ERP&MES system AdvantagesKITARON ERP&MES system Advantages
KITARON ERP&MES system Advantages
 
Cg Risk Management Info Presentation
Cg Risk Management Info PresentationCg Risk Management Info Presentation
Cg Risk Management Info Presentation
 
'Electronic Batch Process recording system
'Electronic Batch Process recording system'Electronic Batch Process recording system
'Electronic Batch Process recording system
 
CONTROL AND AUDIT
CONTROL AND AUDITCONTROL AND AUDIT
CONTROL AND AUDIT
 
Lecture 23 expenditure cycle part ii -fixed assets accounting information sy...
Lecture 23  expenditure cycle part ii -fixed assets accounting information sy...Lecture 23  expenditure cycle part ii -fixed assets accounting information sy...
Lecture 23 expenditure cycle part ii -fixed assets accounting information sy...
 
Context of Organisations
Context of OrganisationsContext of Organisations
Context of Organisations
 
ERP implementation at steel mill
ERP implementation at steel millERP implementation at steel mill
ERP implementation at steel mill
 

Ähnlich wie IT Security Controls Software Factory Optimizes Governance

gray_audit_presentation.ppt
gray_audit_presentation.pptgray_audit_presentation.ppt
gray_audit_presentation.pptKhalilIdhman
 
2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Ydemikaelyde
 
Measuring and Improving MP1.ppt
Measuring and Improving MP1.pptMeasuring and Improving MP1.ppt
Measuring and Improving MP1.pptssuserf2880f
 
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT SystemsICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT SystemsMohammad Abdul Matin Emon
 
Continuous Compliance Monitoring
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance MonitoringControlCase
 
How much does it cost to be Secure?
How much does it cost to be Secure?How much does it cost to be Secure?
How much does it cost to be Secure?mbmobile
 
Quality Assurance in Aviation
Quality Assurance in AviationQuality Assurance in Aviation
Quality Assurance in AviationSeema Zaman
 
SafepaaS AuditPaaS
SafepaaS AuditPaaSSafepaaS AuditPaaS
SafepaaS AuditPaaSJane Jones
 
SafePaaS AuditPaaS
SafePaaS AuditPaaS SafePaaS AuditPaaS
SafePaaS AuditPaaS Jane Jones
 
AuditPaas by SafePaaS
AuditPaas by SafePaaSAuditPaas by SafePaaS
AuditPaas by SafePaaSJane Jones
 
AuditPaaS SafePaaS
AuditPaaS SafePaaSAuditPaaS SafePaaS
AuditPaaS SafePaaSEmma Kelly
 
Erp introduction
Erp introductionErp introduction
Erp introductionGoa App
 
eprocbayoverviewdemopresentation-130201034007-phpapp02
eprocbayoverviewdemopresentation-130201034007-phpapp02eprocbayoverviewdemopresentation-130201034007-phpapp02
eprocbayoverviewdemopresentation-130201034007-phpapp02Satwinder Singh
 
Value-added it auditing
Value-added it auditingValue-added it auditing
Value-added it auditingMarc Vael
 
Implementing Automated Qms For Business Excellence
Implementing Automated Qms For Business ExcellenceImplementing Automated Qms For Business Excellence
Implementing Automated Qms For Business ExcellenceKhalizan Halid
 

Ähnlich wie IT Security Controls Software Factory Optimizes Governance (20)

Production cycle
Production cycle Production cycle
Production cycle
 
gray_audit_presentation.ppt
gray_audit_presentation.pptgray_audit_presentation.ppt
gray_audit_presentation.ppt
 
It Governance Methodology Cox
It Governance Methodology CoxIt Governance Methodology Cox
It Governance Methodology Cox
 
2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde
 
Measuring and Improving MP1.ppt
Measuring and Improving MP1.pptMeasuring and Improving MP1.ppt
Measuring and Improving MP1.ppt
 
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT SystemsICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
 
Continuous Compliance Monitoring
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance Monitoring
 
How much does it cost to be Secure?
How much does it cost to be Secure?How much does it cost to be Secure?
How much does it cost to be Secure?
 
Regulatory Compliance Audit Management Solution
Regulatory Compliance Audit Management SolutionRegulatory Compliance Audit Management Solution
Regulatory Compliance Audit Management Solution
 
Quality Assurance in Aviation
Quality Assurance in AviationQuality Assurance in Aviation
Quality Assurance in Aviation
 
Government and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP SystemsGovernment and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP Systems
 
SafepaaS AuditPaaS
SafepaaS AuditPaaSSafepaaS AuditPaaS
SafepaaS AuditPaaS
 
SafePaaS AuditPaaS
SafePaaS AuditPaaS SafePaaS AuditPaaS
SafePaaS AuditPaaS
 
AuditPaas by SafePaaS
AuditPaas by SafePaaSAuditPaas by SafePaaS
AuditPaas by SafePaaS
 
AuditPaaS SafePaaS
AuditPaaS SafePaaSAuditPaaS SafePaaS
AuditPaaS SafePaaS
 
Erp introduction
Erp introductionErp introduction
Erp introduction
 
eprocbayoverviewdemopresentation-130201034007-phpapp02
eprocbayoverviewdemopresentation-130201034007-phpapp02eprocbayoverviewdemopresentation-130201034007-phpapp02
eprocbayoverviewdemopresentation-130201034007-phpapp02
 
Value-added it auditing
Value-added it auditingValue-added it auditing
Value-added it auditing
 
Implementing Automated Qms For Business Excellence
Implementing Automated Qms For Business ExcellenceImplementing Automated Qms For Business Excellence
Implementing Automated Qms For Business Excellence
 
3b 2 Energy Audit
3b  2   Energy Audit3b  2   Energy Audit
3b 2 Energy Audit
 

Mehr von LeClubQualiteLogicielle

20171122 03 - Les tests de performance en environnement DevOps
20171122 03 - Les tests de performance en environnement DevOps20171122 03 - Les tests de performance en environnement DevOps
20171122 03 - Les tests de performance en environnement DevOpsLeClubQualiteLogicielle
 
20171122 04 - Automatisation - formation et certifications
20171122 04 - Automatisation - formation et certifications20171122 04 - Automatisation - formation et certifications
20171122 04 - Automatisation - formation et certificationsLeClubQualiteLogicielle
 
20171122 01 - REX : Intégration et déploiement continu chez Engie
20171122 01 - REX : Intégration et déploiement continu chez Engie20171122 01 - REX : Intégration et déploiement continu chez Engie
20171122 01 - REX : Intégration et déploiement continu chez EngieLeClubQualiteLogicielle
 
20171122 02 - Engage developers to use better coding practices
20171122 02 - Engage developers to use better coding practices20171122 02 - Engage developers to use better coding practices
20171122 02 - Engage developers to use better coding practicesLeClubQualiteLogicielle
 
20171122 - Accueil Club Qualité Logicielle
20171122 - Accueil Club Qualité Logicielle 20171122 - Accueil Club Qualité Logicielle
20171122 - Accueil Club Qualité Logicielle LeClubQualiteLogicielle
 
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...LeClubQualiteLogicielle
 
20151013 - Agirc arrco : Behavior driven development
20151013 - Agirc arrco : Behavior driven development20151013 - Agirc arrco : Behavior driven development
20151013 - Agirc arrco : Behavior driven developmentLeClubQualiteLogicielle
 
20151013 - Réduire les coûts des tests de performance ?
20151013 - Réduire les coûts des tests de performance ?20151013 - Réduire les coûts des tests de performance ?
20151013 - Réduire les coûts des tests de performance ?LeClubQualiteLogicielle
 
20151013 - Accueil Club Qualité Logicielle
20151013 - Accueil Club Qualité Logicielle 20151013 - Accueil Club Qualité Logicielle
20151013 - Accueil Club Qualité Logicielle LeClubQualiteLogicielle
 
20151013 - DevOps et qualification continue
20151013 - DevOps et qualification continue20151013 - DevOps et qualification continue
20151013 - DevOps et qualification continueLeClubQualiteLogicielle
 
20140410 - Cartographie applicative multi-technologies et analyse d'impact
20140410 - Cartographie applicative multi-technologies et analyse d'impact20140410 - Cartographie applicative multi-technologies et analyse d'impact
20140410 - Cartographie applicative multi-technologies et analyse d'impactLeClubQualiteLogicielle
 
20140410 - Implémentation de squash TM-TA - Architecture et méthodologie
20140410 - Implémentation de squash TM-TA - Architecture et méthodologie20140410 - Implémentation de squash TM-TA - Architecture et méthodologie
20140410 - Implémentation de squash TM-TA - Architecture et méthodologieLeClubQualiteLogicielle
 
20140410 - Choisir et implanter un outil de test
20140410 - Choisir et implanter un outil de test20140410 - Choisir et implanter un outil de test
20140410 - Choisir et implanter un outil de testLeClubQualiteLogicielle
 
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...LeClubQualiteLogicielle
 
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...LeClubQualiteLogicielle
 
20130113 05 - Inspection continue et roadmap 2013
20130113 05 - Inspection continue et roadmap 201320130113 05 - Inspection continue et roadmap 2013
20130113 05 - Inspection continue et roadmap 2013LeClubQualiteLogicielle
 
20130113 04 - Tests d'integration et virtualisation - La vision IBM
20130113 04 - Tests d'integration et virtualisation - La vision IBM20130113 04 - Tests d'integration et virtualisation - La vision IBM
20130113 04 - Tests d'integration et virtualisation - La vision IBMLeClubQualiteLogicielle
 
20130523 06 - The mathematics the way algorithms think / the mathematics the ...
20130523 06 - The mathematics the way algorithms think / the mathematics the ...20130523 06 - The mathematics the way algorithms think / the mathematics the ...
20130523 06 - The mathematics the way algorithms think / the mathematics the ...LeClubQualiteLogicielle
 
20130523 04 - Grille d'évaluation - Gestion du patrimoine de test
20130523 04 - Grille d'évaluation - Gestion du patrimoine de test20130523 04 - Grille d'évaluation - Gestion du patrimoine de test
20130523 04 - Grille d'évaluation - Gestion du patrimoine de testLeClubQualiteLogicielle
 

Mehr von LeClubQualiteLogicielle (20)

20171122 03 - Les tests de performance en environnement DevOps
20171122 03 - Les tests de performance en environnement DevOps20171122 03 - Les tests de performance en environnement DevOps
20171122 03 - Les tests de performance en environnement DevOps
 
20171122 04 - Automatisation - formation et certifications
20171122 04 - Automatisation - formation et certifications20171122 04 - Automatisation - formation et certifications
20171122 04 - Automatisation - formation et certifications
 
20171122 01 - REX : Intégration et déploiement continu chez Engie
20171122 01 - REX : Intégration et déploiement continu chez Engie20171122 01 - REX : Intégration et déploiement continu chez Engie
20171122 01 - REX : Intégration et déploiement continu chez Engie
 
20171122 02 - Engage developers to use better coding practices
20171122 02 - Engage developers to use better coding practices20171122 02 - Engage developers to use better coding practices
20171122 02 - Engage developers to use better coding practices
 
20171122 - Accueil Club Qualité Logicielle
20171122 - Accueil Club Qualité Logicielle 20171122 - Accueil Club Qualité Logicielle
20171122 - Accueil Club Qualité Logicielle
 
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...
20151013 - Crédit Mutuel ARKEA : mise en place d'une traçabilité outillée des...
 
20151013 - Agirc arrco : Behavior driven development
20151013 - Agirc arrco : Behavior driven development20151013 - Agirc arrco : Behavior driven development
20151013 - Agirc arrco : Behavior driven development
 
20151013 - Réduire les coûts des tests de performance ?
20151013 - Réduire les coûts des tests de performance ?20151013 - Réduire les coûts des tests de performance ?
20151013 - Réduire les coûts des tests de performance ?
 
20151013 - Accueil Club Qualité Logicielle
20151013 - Accueil Club Qualité Logicielle 20151013 - Accueil Club Qualité Logicielle
20151013 - Accueil Club Qualité Logicielle
 
20151013 - DevOps et qualification continue
20151013 - DevOps et qualification continue20151013 - DevOps et qualification continue
20151013 - DevOps et qualification continue
 
20140410 - Cartographie applicative multi-technologies et analyse d'impact
20140410 - Cartographie applicative multi-technologies et analyse d'impact20140410 - Cartographie applicative multi-technologies et analyse d'impact
20140410 - Cartographie applicative multi-technologies et analyse d'impact
 
20140410 - Implémentation de squash TM-TA - Architecture et méthodologie
20140410 - Implémentation de squash TM-TA - Architecture et méthodologie20140410 - Implémentation de squash TM-TA - Architecture et méthodologie
20140410 - Implémentation de squash TM-TA - Architecture et méthodologie
 
20140410 - Choisir et implanter un outil de test
20140410 - Choisir et implanter un outil de test20140410 - Choisir et implanter un outil de test
20140410 - Choisir et implanter un outil de test
 
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...
20130113 02 - TMMI, un modèle pour rentabiliser une organisation de test et a...
 
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...
20130113 06 - Travaux de recherche sur la corrélation entre qualité du code e...
 
20130113 05 - Inspection continue et roadmap 2013
20130113 05 - Inspection continue et roadmap 201320130113 05 - Inspection continue et roadmap 2013
20130113 05 - Inspection continue et roadmap 2013
 
20130113 04 - Tests d'integration et virtualisation - La vision IBM
20130113 04 - Tests d'integration et virtualisation - La vision IBM20130113 04 - Tests d'integration et virtualisation - La vision IBM
20130113 04 - Tests d'integration et virtualisation - La vision IBM
 
20130523 06 - The mathematics the way algorithms think / the mathematics the ...
20130523 06 - The mathematics the way algorithms think / the mathematics the ...20130523 06 - The mathematics the way algorithms think / the mathematics the ...
20130523 06 - The mathematics the way algorithms think / the mathematics the ...
 
20130523 05 - Cyclomatic complexity
20130523 05 - Cyclomatic complexity20130523 05 - Cyclomatic complexity
20130523 05 - Cyclomatic complexity
 
20130523 04 - Grille d'évaluation - Gestion du patrimoine de test
20130523 04 - Grille d'évaluation - Gestion du patrimoine de test20130523 04 - Grille d'évaluation - Gestion du patrimoine de test
20130523 04 - Grille d'évaluation - Gestion du patrimoine de test
 

Kürzlich hochgeladen

Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...harshavardhanraghave
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionSolGuruz
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVshikhaohhpro
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfkalichargn70th171
 
Clustering techniques data mining book ....
Clustering techniques data mining book ....Clustering techniques data mining book ....
Clustering techniques data mining book ....ShaimaaMohamedGalal
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...kellynguyen01
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsArshad QA
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...ICS
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Modelsaagamshah0812
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsAlberto González Trastoy
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantAxelRicardoTrocheRiq
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...OnePlan Solutions
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️anilsa9823
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsAndolasoft Inc
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...OnePlan Solutions
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerThousandEyes
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsJhone kinadey
 

Kürzlich hochgeladen (20)

Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with Precision
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTV
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
 
Clustering techniques data mining book ....
Clustering techniques data mining book ....Clustering techniques data mining book ....
Clustering techniques data mining book ....
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview Questions
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Models
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service Consultant
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.js
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial Goals
 
Exploring iOS App Development: Simplifying the Process
Exploring iOS App Development: Simplifying the ProcessExploring iOS App Development: Simplifying the Process
Exploring iOS App Development: Simplifying the Process
 

IT Security Controls Software Factory Optimizes Governance

  • 1. IT Security Services CONTROL FACTORY |BEHIND THE SCENES| Software Quality principles applied to Security Controls
  • 3. ENERGY GIANT / BUSINESS LINE / BUSINESS UNIT Integrated and dynamic management of portfolio – purchasing contracts, assets and sales contracts Management & Trading of Energy Client Business Environment
  • 4. REGULATORY/CONTROLS CONSTRAINTS Highly monitored and regularly audited activities Internal controls Compliance Legal External audits Group internal controls Business line controls Internal Compliance & Legal Risk Operations Internally driven Externally driven Various Auditors
  • 6. Security Controls governance  Discipline/Part of Corporate Governance focused on information technology (IT) oriented security controls aligned with business constraints Security Control book  An important element of a framework ensuring that the organization’s policies/requirements are formalized, monitored and implemented as controls over time  A centralization of security controls carried out on the organization  A tool-based methodology implementing the security control strategy FRAMING CONTROLS BASED ON REQUIREMENTS
  • 7. Controlsources Requirement Campaign 1 2 3 n n n n n n relationship | cardinality Report/Gap analysis needs Execution coverage Requirement coverage SECURITY CONTROLS | SOFTWARE QUALITY PRINCIPLES
  • 8. Standards Regulation Internal Framework In-house best practices Sources of requirements Risks Requirement 1 Requirement 2 Requirement 3 Requirement 4 Requirement “n” internal REG REG Internal IN HOUSE AUDIT … Sources of control Control 1 Control 2 REQ 1 REQ 2 REQ 1 REQ 4 Sourcesofcampaign Iteration 1 Campaign1 Control “n” REQ n REQ n Campaign “n” CTL n CTL 4 CTL n Sourcesofiterations Iteration 2 CAM 1 Iteration 1 Iteration 2 CAM 2 Requirement view Control view Campaign view Execution view Incidents CONTROL ECOSYSTEM CAM 1 CAM 2
  • 9. Title Description Criticality Category (Security, Business…) Owner Group/source (tag or ordering) Covered risk FRAMEWORK @ A GLANCE Requirement template
  • 10. Title Description Nature (administrative, technical, physical) Function (preventive, detective, corrective, recovery) Type (Security) Frequency Level (1 to 3) RACI matrix FRAMEWORK @ A GLANCE Control template
  • 11. Title Description Control suites (STU 1, STU 2,…) Assignee Planning Execution status Basic stats Control plan (CTL1, CTL2,…) FRAMEWORK @ A GLANCE Campaign template
  • 12. Controlsources Requirement Campaign 1 2 3 n n n n n n relationship | cardinality Report/Gap analysis needs Execution coverage Requirement coverage    - Requirements covered by controls ? - All controls associated to requirement ? - Controls executed as expected ? - Execution coverage of requirement ?   SECURITY CONTROLS | SOFTWARE QUALITY PRINCIPLES
  • 14. CONTROL FACTORY | DEFINE refers to : Control Factory (CF) a structured collection of assets that aids in producing controls through an assembly process according to specific requirements1 3 2 4 The Control factory applies manufacturing techniques and principles … > Formalization > Automation > Services Oriented > Industrialization Right process  right result Reduce manual intervention Activities divided in services Reusable components
  • 15. CONTROL FACTORY | OBJECTIVES … to mimic the benefits of traditional manufacturing >Consistency build multiple instances of a control product line & set of controls sharing similar “features and architecture” >Quality integrates reusable controls reducing the likelihood of control design flaws >Productivity Controls activities can be streamlined and automated
  • 16. Conception Design and logic according to requirements Suppliers relationship Sourcing of data, qualification, remediation Production Producing resources for controls reports, dashboards Delivery Making resources for controls available Supervision Governing controls campaign and remediation Internal QA, maintenance, improvements CONTROL FACTORY | ACTIVITIES/SERVICES Customers
  • 17. CONTROL FACTORY | PRODUCTION SERVICES Control Production Production is divided in 6 distinct stages : Supply Raw data from multiple collect sources Compute Loading, ordering & storing data Reconcile Identities vs. accounts Control Production of control resources SoD Advanced controls Report Presenting results as expected
  • 18. PRODUCTION SERVICES| SUPPLY Supply … loading raw data, reconciliation, mapping and ordering for reuse Controlsfactory Advanced controls Reports/views Controls Data Reconciliation Compute 2 3 1 Attaching identities to respective unitary organization Reconciling identities with accounts, perms… Producing controls in the factory Reporting results in expected views 4 …
  • 19. PRODUCTION SERVICES| REPORT Report … presenting control data as requested (format & delivery) • Timeslots • Reports • Data exports Web portal • Reports sent to reviewers Campaign
  • 20. Data Lifecycle Data Quality Data Volume Business Activity CONTROLS GOVERNANCE | FOCUS ON PITFALLS  Reduce treatment time from import to remediation  Based on reliable data, readable and understandable  Deeply analyzed and divided i.e. volume that are “control ready” and “supervision ready”  Better integration of stakeholders processes
  • 21. › Ergonomics and design › Administration › Dashboard & Reporting › Automation CAMPAIGN & CONTROLS | ANALYSIS › Tickets directly created and assigned › Follow-up using the factory › Dynamic reports (web interfaces) › Point and click review › Enriched information › Delegation mechanism enhanced › Improved planning and review mechanism Orientations and improvements › Automated and real-time › Web-based dashboard
  • 22. ITSecurityServices THANK U / QUESTIONS CONTROL FACTORY |BEHIND THE SCENES|