SlideShare ist ein Scribd-Unternehmen logo
1 von 43
Downloaden Sie, um offline zu lesen
Governance
Strategies for
Office 365
The Compliance
Playbook Series
June 18, 2019
2
3
Today’s Agenda
LIVE WEBINAR
• About Montrium
• Overview of IT Governance for GxP Systems
• Office 365 Governance
• Governance Risk Mitigation
• Office 365 Compliance Resources for Subscribers
House Keeping
4
5
House
Keeping
L I V E W E B I N A R
• This webinar is being recorded and
will be made available after this
session
• Feel free to use the chatbox to
submit your questions at anytime
• Q&A will take place at the end of the
webinar
• We will send these slides to your
email at the end of the webinar
6
Meet Your
Speakers
Chrysa Plagiannos
Senior Validation and
Compliance Analyst,
Montrium
Geetartha
Uppaladadium
Validation and Compliance
Analyst,
Montrium
• Founded in 2005
• Working Exclusively in the Life Sciences
• Headquartered in Montreal, Canada
• EU headquarters in Brussels
• Clients in North America, Europe & Asia
• Leading Content Management Platform
• Over 8000 Users in 20+ Countries
• Experienced Professional Services Group
7
About
Montrium
Connecting People,
Processes & Technology
A B O U T T H E C O M P A N Y
What is IT Governance?
8
According to the IT Governance Institute, IT Governance “consists
of the leadership and organizational structures and processes that
ensure that the organization's IT sustains and extends the
organization's strategies and objectives”.
Owes its prevalence to corporate fraud scandals in the 1990’s and
2000’s that brought about increased regulation of corporate
practices and resulted in a move towards formalizing these
practices.
IT Governance
9
• IT Governance involves the
implementation of frameworks,
standards and policies to align an
organization’s IT strategy with the
corporate strategy.
• IT Governance is often associated to
Governance, Risk and Controls (GRC)
which focuses on:
• Implementing controls (both
technical and procedural)
• Risk assessment and mitigation
• Measuring the effectiveness of
controls implemented
Overview of
IT Governance
10
Do you have an IT Governance
Strategy in place?
a) In the process of putting one in place.
b) Yes. But, trying to improve.
c) We have a robust strategy in place.
11
POLL
IT Governance and
GxP-Regulated Activities
12
In the life sciences, computerized
systems are considered to consist
of:
• Hardware, software and network
components
• Associated documentation
• People
GxP
Computerized
Systems
Supporting documentation can include:
• Procedural controls (SOPs, work
instructions)
• User manuals
• Contractual documents (SLA, quality
agreements)
GxP
Computerized
Systems
14
Additional considerations:
• Regulatory compliance
• Relationship with vendors/
suppliers
• Use for GxP and non-GxP
activities
Office 365 Governance
15
Principle of Shared Responsibility
Customer Management of Risk
Data Classification and Accountability
Shared Management of Risk
Identity & Access Management
Provider Management of Risk
Physical | Networking
Cloud Provider Cloud Customer On-Prem IaaS PaaS SaaS
Data classification and
accountability
Client & endpoint protection
Identity access management
Application level controls
Network controls
Host infrastructure
Physical security of datacenters
Regulated users
are ultimately
responsible for
demonstrating
compliance
17
Key Compliance Considerations
Microsoft Responsibilities
• Establish security controls to ensure confidentiality, integrity & availability of customer data.
• Follow industry best practices for infrastructure control, software development and service delivery.
• Implement robust risk and quality management processes to ensure quality of delivered products and
services.
Regulated User Responsibilities
• Establish governance controls and operational processes covering administration and proper use of the
application.
• Conduct end-user training on proper system use.
• Perform system validation to demonstrate fitness for intended use and regulatory compliance.
• Implement a controlled process for managing changes to the system over time.
Do you follow a version of the shared
responsibility model for the governance of
cloud based systems?
a) Yes. We have clearly defined responsibilities.
b) Yes. But, we would like to better implement
the division of responsibilities.
c) No. We don't work with cloud based systems.
18
POLL
Governance processes are outlined in procedural
controls that cover activities related to:
• Implementation
• Operational use
• Administration
Required controls are tied to the intended use of
the system, including GxP relevance of the
business process.
A risk-based approach to governance involves
evaluating risks to Patient Safety, Product
Quality, and Data Integrity.
Key Compliance
Considerations
19
Areas Subject to Governance
20
Implementation Operational use Administrative use
• Vendor Selection
• Validation
• End User Training
• System Documentation
• Contingency Planning
• Change Management
• Incident Management
• Maintenance
• Back-Up and Recovery
• Physical Security
• Logical Security
• Access management
Application Governance Roles
IT Personnel
Business Process
Owner
End Users
Quality Assurance
• Establish data governance policies
• Provision environment
• Maintain configuration
• Manage user access requests
• Perform periodic review of assigned permissions
• Define business process requirements
• Train users on business process
• Perform day-to-day activities in system
• Perform initial and on-going training
• Stakeholder in achieving and maintaining state of
compliance
• Oversee vendor selection/ assessment process
Special
Considerations for
Cloud Services
As a cloud service provider, Microsoft makes
available documentation describing its
products, services and technical commitments
to customers.
Documents published by Microsoft, like the
Online Service Terms and Service Level
Agreement, can serve as inputs to the
governance process.
Due to the responsibilities shared by the
regulated user and Microsoft, the user’s
governance processes must account for
activities for which Microsoft is responsible.
Microsoft’s responsibilities are assessed via the
Vendor Assessment process.
22
Goal
To provide adequate oversight to protect data
Implications for
• System Design: How to segregate GxP and non-
GxP data
• Access Management: Preserve data integrity and
confidentiality
• Procedural controls: Clearly define roles and
responsibilities
Use for
GxP and
Non-GxP
Processes
23
Office 365: Managing GxP Content
Functional Area Business need
Quality SOP Management / Training Management
Data Management Collaboration site for internal and external
users
Regulatory Affairs / Clinical Regulatory submission management and
archive
Records Management Record review and archive of various GxP
records
Governance Risk
Mitigation
25
Adding or
modifying or
deleting a
feature
26
Staying Compliant
Risk
• Unplanned impact on existing functionality.
• Impact on business process.
• Impact on System Documentation.
Impact on Governance
• A Change Control process would provide a framework to address this scenario in a controlled
fashion.
Microsoft Tools
• Release Roadmap
• Change Notifications
Incident with
technological
Impact
27
Staying Compliant
Risk
• Incident resolution needs input from Microsoft.
Impact on Governance
• An Incident Management process would define escalation procedure within the organization and to
Microsoft.
MicrosoftTools
• Service Level Agreements
• Online Service Terms
Data Corruption
&
Availability
Issues
28
Staying Compliant
Risk
• Unavailability or distortion of content impacting business process.
• Not able to apply retention policies.
• Inability to sort data.
• Confidentiality breach.
Impact on Governance
• A backup and restore procedure would minimize the impact of data corruption and unavailability on
business.
• A procedure for classifying data and defining retention policies would address the issues caused by
disorganized data.
• Procedures defining the levels of access to data given to users would prevent unauthorized access.
MicrosoftTools
• O365 Functionalities
• Enforcing retention policies
• Data Classification
• Audit Functionality
• Access Controls
Assessing
Cloud Services
from Microsoft
29
Staying Compliant
Risk
• Not meeting business needs.
• Not having the ability to have controls in place.
Impact on Governance
• A vendor assessment procedure helps to address business and regulatory concerns specific to cloud
service providers.
• A vendor assessment procedure would provide a provision to plan and schedule for periodically re-
evaluating the cloud service provider for continued compliance assurance.
MicrosoftTools
• Microsoft Trust Portal
• Third Party Audit Reports (SOC, ISO).
• Tools to plan and track compliance activities.
Do you have measures to assess and
monitor your company's level of
compliance to general controls?
a) Yes
b) No
30
POLL
Office 365 Compliance
Resources for Subscribers
31
For Office 365, assessments for the
following standards are currently available
in the Compliance Manager:
• CSA CCM301
• FFIEC
• FedRAMP Moderate
• GDPR
• HIPAA
• ISO 27001:2013
• ISO 27018: 2014
• NIST 800-171
• NIST 800-53
• NIST CSF
32
Compliance
Manager
• A dashboard view of progress in
implementing controls (by both
Microsoft and your organization)
• Provides an overview of status of
compliance activities
• Controls are assigned a risk-based
compliance score
• Outlines suggested activities for
customers to demonstrate compliance
linked to technical/ procedural
controls
• Allows for filtering of information
• Ability to generate reports
33
Compliance
Manager
MAIN FEATURES
34
35
Microsoft Secure Score provides visibility
on the security controls in place for Office
365. It can also assist your organization in
planning and tracking actions that can
improve security in Office 365.
• Overview of currently implemented
controls and other available controls
• Score reflects points allocated for the
security controls implemented for Office
365
• Ability to benchmark with other
organizations and to track your
company’s progress over time
• Provides a list of actions that can be
implemented to improve your score.
• Can tailor controls to business needs
and expectations
36
Microsoft
Secure
Score
MAIN FEATURES
37
38
Governance controls provide the framework for implementing and
maintaining a computerized system in a controlled manner.
Office 365 governance must take into account the type of data
being managed and the individuals who will be using this data.
Questions to ask:
• What controls can my organization implement to achieve and
maintain compliance?
• What resources and services does Microsoft offer to assist in
maintaining control over the system?
39
Conclusion
40
The Compliance Toolkits for Office 365
A C C E L E R A T E Y O U R T R A N S I T I O N T O T H E C L O U D
Microsoft Vendor
Assessment Toolkit
SharePoint Online
Validation Toolkit
SharePoint Online
Governance Toolkit
SharePoint Online
Deployment Toolkit
SharePoint Online
Migration Toolkit
Would you like to receive more
information on Montrium’s Compliance
Toolkits for Office 365?
a) Yes, could be useful
b) No, thank you
41
POLL
INFO@MONTRIUM.COM
Thank You!
QUESTIONS?
43

Weitere ähnliche Inhalte

Was ist angesagt?

Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDrew Madelung
 
Design, Build and Run an Effective IT (Service) Strategy to Business Needs
Design, Build and Run an Effective IT (Service) Strategy to Business NeedsDesign, Build and Run an Effective IT (Service) Strategy to Business Needs
Design, Build and Run an Effective IT (Service) Strategy to Business NeedsFlevy.com Best Practices
 
Migrating and modernizing your data estate to Azure with Data Migration Services
Migrating and modernizing your data estate to Azure with Data Migration ServicesMigrating and modernizing your data estate to Azure with Data Migration Services
Migrating and modernizing your data estate to Azure with Data Migration ServicesMicrosoft Tech Community
 
Choosing Between Microsoft Fabric, Azure Synapse Analytics and Azure Data Fac...
Choosing Between Microsoft Fabric, Azure Synapse Analytics and Azure Data Fac...Choosing Between Microsoft Fabric, Azure Synapse Analytics and Azure Data Fac...
Choosing Between Microsoft Fabric, Azure Synapse Analytics and Azure Data Fac...Cathrine Wilhelmsen
 
Cloud-Native Observability
Cloud-Native ObservabilityCloud-Native Observability
Cloud-Native ObservabilityTyler Treat
 
Monitoring & Observability
Monitoring & ObservabilityMonitoring & Observability
Monitoring & ObservabilityLumban Sopian
 
Proactive Governance & Adoption In Microsoft 365 - M365Ottawa
Proactive Governance & Adoption In Microsoft 365 - M365OttawaProactive Governance & Adoption In Microsoft 365 - M365Ottawa
Proactive Governance & Adoption In Microsoft 365 - M365OttawaRichard Harbridge
 
Microsoft Azure Security Overview
Microsoft Azure Security OverviewMicrosoft Azure Security Overview
Microsoft Azure Security OverviewAlert Logic
 
Data Integration, Access, Flow, Exchange, Transfer, Load And Extract Architec...
Data Integration, Access, Flow, Exchange, Transfer, Load And Extract Architec...Data Integration, Access, Flow, Exchange, Transfer, Load And Extract Architec...
Data Integration, Access, Flow, Exchange, Transfer, Load And Extract Architec...Alan McSweeney
 
Getting started with Site Reliability Engineering (SRE)
Getting started with Site Reliability Engineering (SRE)Getting started with Site Reliability Engineering (SRE)
Getting started with Site Reliability Engineering (SRE)Abeer R
 
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...Christopher Bradley
 
Overcoming the Challenges of your Master Data Management Journey
Overcoming the Challenges of your Master Data Management JourneyOvercoming the Challenges of your Master Data Management Journey
Overcoming the Challenges of your Master Data Management JourneyJean-Michel Franco
 
Observability for Modern Applications (CON306-R1) - AWS re:Invent 2018
Observability for Modern Applications (CON306-R1) - AWS re:Invent 2018Observability for Modern Applications (CON306-R1) - AWS re:Invent 2018
Observability for Modern Applications (CON306-R1) - AWS re:Invent 2018Amazon Web Services
 
CollabDays NL 2023 - Protect and govern your sensitive data with Microsoft Pu...
CollabDays NL 2023 - Protect and govern your sensitive data with Microsoft Pu...CollabDays NL 2023 - Protect and govern your sensitive data with Microsoft Pu...
CollabDays NL 2023 - Protect and govern your sensitive data with Microsoft Pu...Jasper Oosterveld
 
Creating an Effective MDM Strategy for Salesforce
Creating an Effective MDM Strategy for SalesforceCreating an Effective MDM Strategy for Salesforce
Creating an Effective MDM Strategy for SalesforcePerficient, Inc.
 
Microservices, DevOps & SRE
Microservices, DevOps & SREMicroservices, DevOps & SRE
Microservices, DevOps & SREAraf Karsh Hamid
 

Was ist angesagt? (20)

Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss Prevention
 
Design, Build and Run an Effective IT (Service) Strategy to Business Needs
Design, Build and Run an Effective IT (Service) Strategy to Business NeedsDesign, Build and Run an Effective IT (Service) Strategy to Business Needs
Design, Build and Run an Effective IT (Service) Strategy to Business Needs
 
Migrating and modernizing your data estate to Azure with Data Migration Services
Migrating and modernizing your data estate to Azure with Data Migration ServicesMigrating and modernizing your data estate to Azure with Data Migration Services
Migrating and modernizing your data estate to Azure with Data Migration Services
 
Choosing Between Microsoft Fabric, Azure Synapse Analytics and Azure Data Fac...
Choosing Between Microsoft Fabric, Azure Synapse Analytics and Azure Data Fac...Choosing Between Microsoft Fabric, Azure Synapse Analytics and Azure Data Fac...
Choosing Between Microsoft Fabric, Azure Synapse Analytics and Azure Data Fac...
 
Cloud-Native Observability
Cloud-Native ObservabilityCloud-Native Observability
Cloud-Native Observability
 
Observability
Observability Observability
Observability
 
TOGAF
TOGAFTOGAF
TOGAF
 
Monitoring & Observability
Monitoring & ObservabilityMonitoring & Observability
Monitoring & Observability
 
Proactive Governance & Adoption In Microsoft 365 - M365Ottawa
Proactive Governance & Adoption In Microsoft 365 - M365OttawaProactive Governance & Adoption In Microsoft 365 - M365Ottawa
Proactive Governance & Adoption In Microsoft 365 - M365Ottawa
 
Microsoft Purview
Microsoft PurviewMicrosoft Purview
Microsoft Purview
 
Microsoft Azure Security Overview
Microsoft Azure Security OverviewMicrosoft Azure Security Overview
Microsoft Azure Security Overview
 
Data Integration, Access, Flow, Exchange, Transfer, Load And Extract Architec...
Data Integration, Access, Flow, Exchange, Transfer, Load And Extract Architec...Data Integration, Access, Flow, Exchange, Transfer, Load And Extract Architec...
Data Integration, Access, Flow, Exchange, Transfer, Load And Extract Architec...
 
Getting started with Site Reliability Engineering (SRE)
Getting started with Site Reliability Engineering (SRE)Getting started with Site Reliability Engineering (SRE)
Getting started with Site Reliability Engineering (SRE)
 
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
 
Overcoming the Challenges of your Master Data Management Journey
Overcoming the Challenges of your Master Data Management JourneyOvercoming the Challenges of your Master Data Management Journey
Overcoming the Challenges of your Master Data Management Journey
 
Observability for Modern Applications (CON306-R1) - AWS re:Invent 2018
Observability for Modern Applications (CON306-R1) - AWS re:Invent 2018Observability for Modern Applications (CON306-R1) - AWS re:Invent 2018
Observability for Modern Applications (CON306-R1) - AWS re:Invent 2018
 
Elastic-Engineering
Elastic-EngineeringElastic-Engineering
Elastic-Engineering
 
CollabDays NL 2023 - Protect and govern your sensitive data with Microsoft Pu...
CollabDays NL 2023 - Protect and govern your sensitive data with Microsoft Pu...CollabDays NL 2023 - Protect and govern your sensitive data with Microsoft Pu...
CollabDays NL 2023 - Protect and govern your sensitive data with Microsoft Pu...
 
Creating an Effective MDM Strategy for Salesforce
Creating an Effective MDM Strategy for SalesforceCreating an Effective MDM Strategy for Salesforce
Creating an Effective MDM Strategy for Salesforce
 
Microservices, DevOps & SRE
Microservices, DevOps & SREMicroservices, DevOps & SRE
Microservices, DevOps & SRE
 

Ähnlich wie Governance Strategies for Office 365

Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...
Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...
Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...Montrium
 
Tools for Accelerating Validation of Office 365
Tools for Accelerating Validation of Office 365Tools for Accelerating Validation of Office 365
Tools for Accelerating Validation of Office 365Montrium
 
Continuous validation of office 365
Continuous validation of office 365Continuous validation of office 365
Continuous validation of office 365Montrium
 
Best Practices for Implementing Robust Governance Processes in Office 365
Best Practices for Implementing Robust Governance Processes in Office 365Best Practices for Implementing Robust Governance Processes in Office 365
Best Practices for Implementing Robust Governance Processes in Office 365Montrium
 
Structured NERC CIP Process Improvement Using Six Sigma
Structured NERC CIP Process Improvement Using Six SigmaStructured NERC CIP Process Improvement Using Six Sigma
Structured NERC CIP Process Improvement Using Six SigmaEnergySec
 
How to build a change workflow process
How to build a change workflow processHow to build a change workflow process
How to build a change workflow processTufin
 
How to Get Started with GxP Processes in Office 365 - The Discovery Phase
How to Get Started with GxP Processes in Office 365 - The Discovery PhaseHow to Get Started with GxP Processes in Office 365 - The Discovery Phase
How to Get Started with GxP Processes in Office 365 - The Discovery PhaseMontrium
 
How to Migrate Drug Safety and Pharmacovigilance Data Cost-Effectively and wi...
How to Migrate Drug Safety and Pharmacovigilance Data Cost-Effectively and wi...How to Migrate Drug Safety and Pharmacovigilance Data Cost-Effectively and wi...
How to Migrate Drug Safety and Pharmacovigilance Data Cost-Effectively and wi...Perficient
 
O365Con18 - Compliance Manager - Tomislav Lulic
O365Con18 - Compliance Manager - Tomislav LulicO365Con18 - Compliance Manager - Tomislav Lulic
O365Con18 - Compliance Manager - Tomislav LulicNCCOMMS
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Meghna Verma
 
Beyond Automation: Extracting Actionable Intelligence from Clinical Trials
Beyond Automation: Extracting Actionable Intelligence from Clinical TrialsBeyond Automation: Extracting Actionable Intelligence from Clinical Trials
Beyond Automation: Extracting Actionable Intelligence from Clinical TrialsMontrium
 
romi-pm-08-quality-april2013.pptx
romi-pm-08-quality-april2013.pptxromi-pm-08-quality-april2013.pptx
romi-pm-08-quality-april2013.pptxfauzi chayo
 
Adaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyAdaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyRob Johnston, MBA
 
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...D. Scott Clark
 
GRCPerfect - Enterprise Project Governance, Risk and Compliance Management Sy...
GRCPerfect - Enterprise Project Governance, Risk and Compliance Management Sy...GRCPerfect - Enterprise Project Governance, Risk and Compliance Management Sy...
GRCPerfect - Enterprise Project Governance, Risk and Compliance Management Sy...LN Mishra CBAP
 
Ken Bolt Resume 2011 01 14
Ken Bolt Resume 2011 01 14Ken Bolt Resume 2011 01 14
Ken Bolt Resume 2011 01 14kengb6
 
Why Are Life Science Companies Moving to Office 365?
Why Are Life Science Companies Moving to Office 365?Why Are Life Science Companies Moving to Office 365?
Why Are Life Science Companies Moving to Office 365?Montrium
 
Drive Smarter Decisions with Big Data Using Complex Event Processing
Drive Smarter Decisions with Big Data Using Complex Event ProcessingDrive Smarter Decisions with Big Data Using Complex Event Processing
Drive Smarter Decisions with Big Data Using Complex Event ProcessingPerficient, Inc.
 
SharePoint for Pharma - Computer System Life Cycle Management
SharePoint for Pharma - Computer System Life Cycle ManagementSharePoint for Pharma - Computer System Life Cycle Management
SharePoint for Pharma - Computer System Life Cycle ManagementMontrium
 

Ähnlich wie Governance Strategies for Office 365 (20)

Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...
Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...
Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...
 
Tools for Accelerating Validation of Office 365
Tools for Accelerating Validation of Office 365Tools for Accelerating Validation of Office 365
Tools for Accelerating Validation of Office 365
 
Continuous validation of office 365
Continuous validation of office 365Continuous validation of office 365
Continuous validation of office 365
 
Best Practices for Implementing Robust Governance Processes in Office 365
Best Practices for Implementing Robust Governance Processes in Office 365Best Practices for Implementing Robust Governance Processes in Office 365
Best Practices for Implementing Robust Governance Processes in Office 365
 
Structured NERC CIP Process Improvement Using Six Sigma
Structured NERC CIP Process Improvement Using Six SigmaStructured NERC CIP Process Improvement Using Six Sigma
Structured NERC CIP Process Improvement Using Six Sigma
 
How to build a change workflow process
How to build a change workflow processHow to build a change workflow process
How to build a change workflow process
 
How to Get Started with GxP Processes in Office 365 - The Discovery Phase
How to Get Started with GxP Processes in Office 365 - The Discovery PhaseHow to Get Started with GxP Processes in Office 365 - The Discovery Phase
How to Get Started with GxP Processes in Office 365 - The Discovery Phase
 
How to Migrate Drug Safety and Pharmacovigilance Data Cost-Effectively and wi...
How to Migrate Drug Safety and Pharmacovigilance Data Cost-Effectively and wi...How to Migrate Drug Safety and Pharmacovigilance Data Cost-Effectively and wi...
How to Migrate Drug Safety and Pharmacovigilance Data Cost-Effectively and wi...
 
O365Con18 - Compliance Manager - Tomislav Lulic
O365Con18 - Compliance Manager - Tomislav LulicO365Con18 - Compliance Manager - Tomislav Lulic
O365Con18 - Compliance Manager - Tomislav Lulic
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799
 
Beyond Automation: Extracting Actionable Intelligence from Clinical Trials
Beyond Automation: Extracting Actionable Intelligence from Clinical TrialsBeyond Automation: Extracting Actionable Intelligence from Clinical Trials
Beyond Automation: Extracting Actionable Intelligence from Clinical Trials
 
romi-pm-08-quality-april2013.pptx
romi-pm-08-quality-april2013.pptxromi-pm-08-quality-april2013.pptx
romi-pm-08-quality-april2013.pptx
 
Adaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyAdaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_study
 
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
 
GRCPerfect - Enterprise Project Governance, Risk and Compliance Management Sy...
GRCPerfect - Enterprise Project Governance, Risk and Compliance Management Sy...GRCPerfect - Enterprise Project Governance, Risk and Compliance Management Sy...
GRCPerfect - Enterprise Project Governance, Risk and Compliance Management Sy...
 
Ken Bolt Resume 2011 01 14
Ken Bolt Resume 2011 01 14Ken Bolt Resume 2011 01 14
Ken Bolt Resume 2011 01 14
 
Why Are Life Science Companies Moving to Office 365?
Why Are Life Science Companies Moving to Office 365?Why Are Life Science Companies Moving to Office 365?
Why Are Life Science Companies Moving to Office 365?
 
Drive Smarter Decisions with Big Data Using Complex Event Processing
Drive Smarter Decisions with Big Data Using Complex Event ProcessingDrive Smarter Decisions with Big Data Using Complex Event Processing
Drive Smarter Decisions with Big Data Using Complex Event Processing
 
GRC– The Way Forward
GRC– The Way ForwardGRC– The Way Forward
GRC– The Way Forward
 
SharePoint for Pharma - Computer System Life Cycle Management
SharePoint for Pharma - Computer System Life Cycle ManagementSharePoint for Pharma - Computer System Life Cycle Management
SharePoint for Pharma - Computer System Life Cycle Management
 

Mehr von Montrium

Monitoring Beyond COVID-19: Setting Yourself Up for the New-Normal
Monitoring Beyond COVID-19: Setting Yourself Up for the New-NormalMonitoring Beyond COVID-19: Setting Yourself Up for the New-Normal
Monitoring Beyond COVID-19: Setting Yourself Up for the New-NormalMontrium
 
Strategies to Facilitate GxP Processes Deployment in Office 365
Strategies to Facilitate GxP Processes Deployment in Office 365Strategies to Facilitate GxP Processes Deployment in Office 365
Strategies to Facilitate GxP Processes Deployment in Office 365Montrium
 
How to prepare for an audit and maintain oversight within your e qms
How to prepare for an audit and maintain oversight within your e qmsHow to prepare for an audit and maintain oversight within your e qms
How to prepare for an audit and maintain oversight within your e qmsMontrium
 
Transforming eTMF Management: Moving to a Data-Driven Approach
Transforming eTMF Management: Moving to a Data-Driven ApproachTransforming eTMF Management: Moving to a Data-Driven Approach
Transforming eTMF Management: Moving to a Data-Driven ApproachMontrium
 
Best practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsBest practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsMontrium
 
Best practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsBest practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsMontrium
 
Implementing Metrics & Completeness Reporting in TMF Management​
Implementing Metrics & Completeness Reporting in TMF Management​Implementing Metrics & Completeness Reporting in TMF Management​
Implementing Metrics & Completeness Reporting in TMF Management​Montrium
 
Empowering Active TMF Management With an eTMF System
Empowering Active TMF Management With an eTMF SystemEmpowering Active TMF Management With an eTMF System
Empowering Active TMF Management With an eTMF SystemMontrium
 
Empowering active tmf management
Empowering active tmf managementEmpowering active tmf management
Empowering active tmf managementMontrium
 
Automation of document management paul fenton webinar
Automation of document management paul fenton webinarAutomation of document management paul fenton webinar
Automation of document management paul fenton webinarMontrium
 
Practical Steps to Selecting and Implementing an eTMF
Practical Steps to Selecting and Implementing an eTMFPractical Steps to Selecting and Implementing an eTMF
Practical Steps to Selecting and Implementing an eTMFMontrium
 
Implementing the TMF Reference Model
Implementing the TMF Reference ModelImplementing the TMF Reference Model
Implementing the TMF Reference ModelMontrium
 
Tmf Fundamentals - webinar
Tmf Fundamentals - webinarTmf Fundamentals - webinar
Tmf Fundamentals - webinarMontrium
 
TMF Fundamentals - An Introduction to Better Trial Master File Management - M...
TMF Fundamentals - An Introduction to Better Trial Master File Management - M...TMF Fundamentals - An Introduction to Better Trial Master File Management - M...
TMF Fundamentals - An Introduction to Better Trial Master File Management - M...Montrium
 
Automating the Regulatory Submission Process - Reducing Time and Increasing Q...
Automating the Regulatory Submission Process - Reducing Time and Increasing Q...Automating the Regulatory Submission Process - Reducing Time and Increasing Q...
Automating the Regulatory Submission Process - Reducing Time and Increasing Q...Montrium
 
Future of eTMF Webinar - Montrium
Future of eTMF Webinar - MontriumFuture of eTMF Webinar - Montrium
Future of eTMF Webinar - MontriumMontrium
 
How to Build a Business Case for an eTMF
How to Build a Business Case for an eTMFHow to Build a Business Case for an eTMF
How to Build a Business Case for an eTMFMontrium
 
Outsourcing TMF Management
Outsourcing TMF ManagementOutsourcing TMF Management
Outsourcing TMF ManagementMontrium
 
Top Clinical Conferences 2019
Top Clinical Conferences 2019Top Clinical Conferences 2019
Top Clinical Conferences 2019Montrium
 
Best practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsBest practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsMontrium
 

Mehr von Montrium (20)

Monitoring Beyond COVID-19: Setting Yourself Up for the New-Normal
Monitoring Beyond COVID-19: Setting Yourself Up for the New-NormalMonitoring Beyond COVID-19: Setting Yourself Up for the New-Normal
Monitoring Beyond COVID-19: Setting Yourself Up for the New-Normal
 
Strategies to Facilitate GxP Processes Deployment in Office 365
Strategies to Facilitate GxP Processes Deployment in Office 365Strategies to Facilitate GxP Processes Deployment in Office 365
Strategies to Facilitate GxP Processes Deployment in Office 365
 
How to prepare for an audit and maintain oversight within your e qms
How to prepare for an audit and maintain oversight within your e qmsHow to prepare for an audit and maintain oversight within your e qms
How to prepare for an audit and maintain oversight within your e qms
 
Transforming eTMF Management: Moving to a Data-Driven Approach
Transforming eTMF Management: Moving to a Data-Driven ApproachTransforming eTMF Management: Moving to a Data-Driven Approach
Transforming eTMF Management: Moving to a Data-Driven Approach
 
Best practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsBest practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspections
 
Best practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsBest practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspections
 
Implementing Metrics & Completeness Reporting in TMF Management​
Implementing Metrics & Completeness Reporting in TMF Management​Implementing Metrics & Completeness Reporting in TMF Management​
Implementing Metrics & Completeness Reporting in TMF Management​
 
Empowering Active TMF Management With an eTMF System
Empowering Active TMF Management With an eTMF SystemEmpowering Active TMF Management With an eTMF System
Empowering Active TMF Management With an eTMF System
 
Empowering active tmf management
Empowering active tmf managementEmpowering active tmf management
Empowering active tmf management
 
Automation of document management paul fenton webinar
Automation of document management paul fenton webinarAutomation of document management paul fenton webinar
Automation of document management paul fenton webinar
 
Practical Steps to Selecting and Implementing an eTMF
Practical Steps to Selecting and Implementing an eTMFPractical Steps to Selecting and Implementing an eTMF
Practical Steps to Selecting and Implementing an eTMF
 
Implementing the TMF Reference Model
Implementing the TMF Reference ModelImplementing the TMF Reference Model
Implementing the TMF Reference Model
 
Tmf Fundamentals - webinar
Tmf Fundamentals - webinarTmf Fundamentals - webinar
Tmf Fundamentals - webinar
 
TMF Fundamentals - An Introduction to Better Trial Master File Management - M...
TMF Fundamentals - An Introduction to Better Trial Master File Management - M...TMF Fundamentals - An Introduction to Better Trial Master File Management - M...
TMF Fundamentals - An Introduction to Better Trial Master File Management - M...
 
Automating the Regulatory Submission Process - Reducing Time and Increasing Q...
Automating the Regulatory Submission Process - Reducing Time and Increasing Q...Automating the Regulatory Submission Process - Reducing Time and Increasing Q...
Automating the Regulatory Submission Process - Reducing Time and Increasing Q...
 
Future of eTMF Webinar - Montrium
Future of eTMF Webinar - MontriumFuture of eTMF Webinar - Montrium
Future of eTMF Webinar - Montrium
 
How to Build a Business Case for an eTMF
How to Build a Business Case for an eTMFHow to Build a Business Case for an eTMF
How to Build a Business Case for an eTMF
 
Outsourcing TMF Management
Outsourcing TMF ManagementOutsourcing TMF Management
Outsourcing TMF Management
 
Top Clinical Conferences 2019
Top Clinical Conferences 2019Top Clinical Conferences 2019
Top Clinical Conferences 2019
 
Best practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspectionsBest practices for preparing for and surviving inspections
Best practices for preparing for and surviving inspections
 

Kürzlich hochgeladen

Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 

Kürzlich hochgeladen (20)

Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 

Governance Strategies for Office 365

  • 1.
  • 2. Governance Strategies for Office 365 The Compliance Playbook Series June 18, 2019 2
  • 3. 3 Today’s Agenda LIVE WEBINAR • About Montrium • Overview of IT Governance for GxP Systems • Office 365 Governance • Governance Risk Mitigation • Office 365 Compliance Resources for Subscribers
  • 5. 5 House Keeping L I V E W E B I N A R • This webinar is being recorded and will be made available after this session • Feel free to use the chatbox to submit your questions at anytime • Q&A will take place at the end of the webinar • We will send these slides to your email at the end of the webinar
  • 6. 6 Meet Your Speakers Chrysa Plagiannos Senior Validation and Compliance Analyst, Montrium Geetartha Uppaladadium Validation and Compliance Analyst, Montrium
  • 7. • Founded in 2005 • Working Exclusively in the Life Sciences • Headquartered in Montreal, Canada • EU headquarters in Brussels • Clients in North America, Europe & Asia • Leading Content Management Platform • Over 8000 Users in 20+ Countries • Experienced Professional Services Group 7 About Montrium Connecting People, Processes & Technology A B O U T T H E C O M P A N Y
  • 8. What is IT Governance? 8
  • 9. According to the IT Governance Institute, IT Governance “consists of the leadership and organizational structures and processes that ensure that the organization's IT sustains and extends the organization's strategies and objectives”. Owes its prevalence to corporate fraud scandals in the 1990’s and 2000’s that brought about increased regulation of corporate practices and resulted in a move towards formalizing these practices. IT Governance 9
  • 10. • IT Governance involves the implementation of frameworks, standards and policies to align an organization’s IT strategy with the corporate strategy. • IT Governance is often associated to Governance, Risk and Controls (GRC) which focuses on: • Implementing controls (both technical and procedural) • Risk assessment and mitigation • Measuring the effectiveness of controls implemented Overview of IT Governance 10
  • 11. Do you have an IT Governance Strategy in place? a) In the process of putting one in place. b) Yes. But, trying to improve. c) We have a robust strategy in place. 11 POLL
  • 13. In the life sciences, computerized systems are considered to consist of: • Hardware, software and network components • Associated documentation • People GxP Computerized Systems
  • 14. Supporting documentation can include: • Procedural controls (SOPs, work instructions) • User manuals • Contractual documents (SLA, quality agreements) GxP Computerized Systems 14 Additional considerations: • Regulatory compliance • Relationship with vendors/ suppliers • Use for GxP and non-GxP activities
  • 16. Principle of Shared Responsibility Customer Management of Risk Data Classification and Accountability Shared Management of Risk Identity & Access Management Provider Management of Risk Physical | Networking Cloud Provider Cloud Customer On-Prem IaaS PaaS SaaS Data classification and accountability Client & endpoint protection Identity access management Application level controls Network controls Host infrastructure Physical security of datacenters
  • 17. Regulated users are ultimately responsible for demonstrating compliance 17 Key Compliance Considerations Microsoft Responsibilities • Establish security controls to ensure confidentiality, integrity & availability of customer data. • Follow industry best practices for infrastructure control, software development and service delivery. • Implement robust risk and quality management processes to ensure quality of delivered products and services. Regulated User Responsibilities • Establish governance controls and operational processes covering administration and proper use of the application. • Conduct end-user training on proper system use. • Perform system validation to demonstrate fitness for intended use and regulatory compliance. • Implement a controlled process for managing changes to the system over time.
  • 18. Do you follow a version of the shared responsibility model for the governance of cloud based systems? a) Yes. We have clearly defined responsibilities. b) Yes. But, we would like to better implement the division of responsibilities. c) No. We don't work with cloud based systems. 18 POLL
  • 19. Governance processes are outlined in procedural controls that cover activities related to: • Implementation • Operational use • Administration Required controls are tied to the intended use of the system, including GxP relevance of the business process. A risk-based approach to governance involves evaluating risks to Patient Safety, Product Quality, and Data Integrity. Key Compliance Considerations 19
  • 20. Areas Subject to Governance 20 Implementation Operational use Administrative use • Vendor Selection • Validation • End User Training • System Documentation • Contingency Planning • Change Management • Incident Management • Maintenance • Back-Up and Recovery • Physical Security • Logical Security • Access management
  • 21. Application Governance Roles IT Personnel Business Process Owner End Users Quality Assurance • Establish data governance policies • Provision environment • Maintain configuration • Manage user access requests • Perform periodic review of assigned permissions • Define business process requirements • Train users on business process • Perform day-to-day activities in system • Perform initial and on-going training • Stakeholder in achieving and maintaining state of compliance • Oversee vendor selection/ assessment process
  • 22. Special Considerations for Cloud Services As a cloud service provider, Microsoft makes available documentation describing its products, services and technical commitments to customers. Documents published by Microsoft, like the Online Service Terms and Service Level Agreement, can serve as inputs to the governance process. Due to the responsibilities shared by the regulated user and Microsoft, the user’s governance processes must account for activities for which Microsoft is responsible. Microsoft’s responsibilities are assessed via the Vendor Assessment process. 22
  • 23. Goal To provide adequate oversight to protect data Implications for • System Design: How to segregate GxP and non- GxP data • Access Management: Preserve data integrity and confidentiality • Procedural controls: Clearly define roles and responsibilities Use for GxP and Non-GxP Processes 23
  • 24. Office 365: Managing GxP Content Functional Area Business need Quality SOP Management / Training Management Data Management Collaboration site for internal and external users Regulatory Affairs / Clinical Regulatory submission management and archive Records Management Record review and archive of various GxP records
  • 26. Adding or modifying or deleting a feature 26 Staying Compliant Risk • Unplanned impact on existing functionality. • Impact on business process. • Impact on System Documentation. Impact on Governance • A Change Control process would provide a framework to address this scenario in a controlled fashion. Microsoft Tools • Release Roadmap • Change Notifications
  • 27. Incident with technological Impact 27 Staying Compliant Risk • Incident resolution needs input from Microsoft. Impact on Governance • An Incident Management process would define escalation procedure within the organization and to Microsoft. MicrosoftTools • Service Level Agreements • Online Service Terms
  • 28. Data Corruption & Availability Issues 28 Staying Compliant Risk • Unavailability or distortion of content impacting business process. • Not able to apply retention policies. • Inability to sort data. • Confidentiality breach. Impact on Governance • A backup and restore procedure would minimize the impact of data corruption and unavailability on business. • A procedure for classifying data and defining retention policies would address the issues caused by disorganized data. • Procedures defining the levels of access to data given to users would prevent unauthorized access. MicrosoftTools • O365 Functionalities • Enforcing retention policies • Data Classification • Audit Functionality • Access Controls
  • 29. Assessing Cloud Services from Microsoft 29 Staying Compliant Risk • Not meeting business needs. • Not having the ability to have controls in place. Impact on Governance • A vendor assessment procedure helps to address business and regulatory concerns specific to cloud service providers. • A vendor assessment procedure would provide a provision to plan and schedule for periodically re- evaluating the cloud service provider for continued compliance assurance. MicrosoftTools • Microsoft Trust Portal • Third Party Audit Reports (SOC, ISO). • Tools to plan and track compliance activities.
  • 30. Do you have measures to assess and monitor your company's level of compliance to general controls? a) Yes b) No 30 POLL
  • 31. Office 365 Compliance Resources for Subscribers 31
  • 32. For Office 365, assessments for the following standards are currently available in the Compliance Manager: • CSA CCM301 • FFIEC • FedRAMP Moderate • GDPR • HIPAA • ISO 27001:2013 • ISO 27018: 2014 • NIST 800-171 • NIST 800-53 • NIST CSF 32 Compliance Manager
  • 33. • A dashboard view of progress in implementing controls (by both Microsoft and your organization) • Provides an overview of status of compliance activities • Controls are assigned a risk-based compliance score • Outlines suggested activities for customers to demonstrate compliance linked to technical/ procedural controls • Allows for filtering of information • Ability to generate reports 33 Compliance Manager MAIN FEATURES
  • 34. 34
  • 35. 35
  • 36. Microsoft Secure Score provides visibility on the security controls in place for Office 365. It can also assist your organization in planning and tracking actions that can improve security in Office 365. • Overview of currently implemented controls and other available controls • Score reflects points allocated for the security controls implemented for Office 365 • Ability to benchmark with other organizations and to track your company’s progress over time • Provides a list of actions that can be implemented to improve your score. • Can tailor controls to business needs and expectations 36 Microsoft Secure Score MAIN FEATURES
  • 37. 37
  • 38. 38
  • 39. Governance controls provide the framework for implementing and maintaining a computerized system in a controlled manner. Office 365 governance must take into account the type of data being managed and the individuals who will be using this data. Questions to ask: • What controls can my organization implement to achieve and maintain compliance? • What resources and services does Microsoft offer to assist in maintaining control over the system? 39 Conclusion
  • 40. 40 The Compliance Toolkits for Office 365 A C C E L E R A T E Y O U R T R A N S I T I O N T O T H E C L O U D Microsoft Vendor Assessment Toolkit SharePoint Online Validation Toolkit SharePoint Online Governance Toolkit SharePoint Online Deployment Toolkit SharePoint Online Migration Toolkit
  • 41. Would you like to receive more information on Montrium’s Compliance Toolkits for Office 365? a) Yes, could be useful b) No, thank you 41 POLL