SlideShare ist ein Scribd-Unternehmen logo
1 von 24
Downloaden Sie, um offline zu lesen
© Copyright 2016 EMC Corporation.
#RSACharge © Copyright 2016 EMC Corporation.
Solving Data Publication Challenges
for Even Better Archer Reporting
Phil Aldrich, Dell
David Pearson, Iceberg
© Copyright 2016 EMC Corporation.
Agenda
• Reporting requirements
• Key Technical Challenges
• Datamart / ETL / BI solution
• EMC “Proof of Concept” (Archer/Tableau integration)
• Next Steps
© Copyright 2016 EMC Corporation.
Challenge
• Archer is a powerful tool for aggregating risk and compliance data
• More mature organizations often have reporting/dashboard
requirements that go beyond Archer out-of-box capabilities
• Example: Audit committee + board-level reporting requirements + risk
metrics
“How can we drive more meaningful / actionable /
valuable reports from Archer?”
© Copyright 2016 EMC Corporation.
Typical business requirements
Functionality
• Advanced visualizations
(heat maps, bowtie charts, cause-effect trees)
• Manipulate / customize dashboards
• More control over exports to Excel, PowerPoint, etc.
• Metric and Trend analysis
• Easier integration with other BI tools
© Copyright 2016 EMC Corporation.
Capability RSA Archer BI tool
• “On the fly” report creation/edits
• Ability to export reports into multiple formats
• Variety of report display options (bar, line, heat, pie, etc.)
• Ability to create reports with separate data sources
• Multi-dimensional reports (3 or more)
• Ability to implement analysis algorithms (monte carlo, etc.)
• Ability to add report description with export/display
• Metric Trending & Analysis
• Forecast projected results within report
Reporting Capabilities
© Copyright 2016 EMC Corporation.
Reporting Requirements
Source: COSO.org, Developing Key Risk Indicators to Strengthen Enterprise Risk Management
“Understand the Full Picture”
© Copyright 2016 EMC Corporation.
Reporting Requirements
Source: COSO.org, Risk Assessment in Practice
© Copyright 2016 EMC Corporation.
Reporting Requirements
Source: COSO.org, Risk Assessment in Practice
© Copyright 2016 EMC Corporation.
Current solution: Archer Data Publication
Service (DPS)
• Use Archer’s DPS (Data Publication Service), and import data
into a BI tool like Tableau
But DPS has its problems…
o Process is difficult to support/maintain
o How do we maintain Archer’s security/permissions in the BI
tool?
o DPS produces “unfriendly field names”
o How do we cross reference data from multiple Archer modules?
o Can we capture trending?
© Copyright 2016 EMC Corporation.
Risk Intelligence Data Mart
Datamart / ETL / BI solution
DPS
Meta Data
Archer
Application
Data
Xform Reporting
Datastore
SQL/API
Data Access
© Copyright 2016 EMC Corporation.
DPS Raw Data Model Risk Intelligence Data Mart
Meta Data
Xform Reporting
Datastore
Data Access
Archer
Application
Data
© Copyright 2016 EMC Corporation.
Additional Queries - Example Risk Intelligence Data Mart
Archer
Application
Data
Xform Reporting
Datastore
Data Access
Meta Data
© Copyright 2016 EMC Corporation.
Post Transformation Data Model Risk Intelligence Data Mart
Meta Data
Archer
Application
Data
Xform
Data Access
Reporting
Datastore
© Copyright 2016 EMC Corporation.
1. Datamart: all Archer data for an application is
available from a single view within a database
2. Maintains Archer’s security and access
controls: Includes row-level permissions,
automatically mirroring Archer’s security model
3. A simplified data model: Data is combined from
dozens or hundreds of tables, and includes
enumerated field “meanings”, for reporting ease and
performance
4. Reports/Dashboards: Easier configuration of
enriched executive reports and dashboards within a BI
tool.
© Copyright 2016 EMC Corporation.
© Copyright 2016 EMC Corporation.
© Copyright 2016 EMC Corporation.
EMC “Proof of Concept”
• Use a subset of information on proof of
concept (Risk Register)
• Build “solid” integration b/w Archer and
Tableau
• Showcase reporting capabilities not
available in Archer
• Maintain Archer access control permissions
• Ensure integration process is “easy” to
support
© Copyright 2016 EMC Corporation.
POC Phases LEADER
2016
July Aug Sept Oct Nov Dec
Requirements Gathering EMC
Technical Setup
EMC/Iceberg
/AHA
Report Creation Iceberg/AHA
ETL Redesign (6.1)
Iceberg/AHA
ETL Deploy/Test (6.1) EMC/Dell
Metrics Development Dell/AHA
EMC “Proof of Concept” timeline
© Copyright 2016 EMC Corporation.
• Ability to provide a full “snapshot” to executives with
supporting context
• Ability to add report data into PowerPoint presentations
or summary audit reports
• Provide “actionable” reporting files/interfaces to allow
real-time analysis (ie. Tableau)
© Copyright 2016 EMC Corporation.
Risk Action chart
• “Actionable” report for easy
executive consumption
• Provides another “axis” of
information
• Overlay of Risk Summary
Report
© Copyright 2016 EMC Corporation.
Challenges / Opportunities
• 5.5 version vs. 6.1 ETL – Required a redesign
– Commitment from RSA to inform on future changes
• Maintain Archer access control capability
– Key requirement to ensure data confidentiality
• Ensure “ease of use” for future “lights on” support
– Archer Support team can easily manage integration and updates
• Continue to build a “Risk Intelligence” story
– Add metrics, risk costs vs. impacts
#RSACharge © Copyright 2016 EMC Corporation.
Please Complete Session Evaluation
#RSACharge
© Copyright 2016 EMC Corporation.

Weitere ähnliche Inhalte

Was ist angesagt?

Native mobile application development with Flutter (Dart)
Native mobile application development with Flutter (Dart)Native mobile application development with Flutter (Dart)
Native mobile application development with Flutter (Dart)Randal Schwartz
 
Apache Karaf - Building OSGi applications on Apache Karaf - T Frank & A Grzesik
Apache Karaf - Building OSGi applications on Apache Karaf - T Frank & A GrzesikApache Karaf - Building OSGi applications on Apache Karaf - T Frank & A Grzesik
Apache Karaf - Building OSGi applications on Apache Karaf - T Frank & A Grzesikmfrancis
 
Deploying Viva Topics
Deploying Viva TopicsDeploying Viva Topics
Deploying Viva TopicsDrew Madelung
 
Modelo cascata apresentação
Modelo cascata apresentaçãoModelo cascata apresentação
Modelo cascata apresentaçãoerysonsi
 
Deploying Flink on Kubernetes - David Anderson
 Deploying Flink on Kubernetes - David Anderson Deploying Flink on Kubernetes - David Anderson
Deploying Flink on Kubernetes - David AndersonVerverica
 
Introducing the Apache Flink Kubernetes Operator
Introducing the Apache Flink Kubernetes OperatorIntroducing the Apache Flink Kubernetes Operator
Introducing the Apache Flink Kubernetes OperatorFlink Forward
 
BA and Beyond 20 - Elke Steegmans and David Vandenbroeck - Behaviour-driven d...
BA and Beyond 20 - Elke Steegmans and David Vandenbroeck - Behaviour-driven d...BA and Beyond 20 - Elke Steegmans and David Vandenbroeck - Behaviour-driven d...
BA and Beyond 20 - Elke Steegmans and David Vandenbroeck - Behaviour-driven d...BA and Beyond
 
Functional Smalltalk
Functional SmalltalkFunctional Smalltalk
Functional SmalltalkESUG
 
Android info session
Android info sessionAndroid info session
Android info sessionGDSC
 
Software development PROCESS
Software development PROCESSSoftware development PROCESS
Software development PROCESSIvano Malavolta
 
카카오톡의 서버사이드 코틀린
카카오톡의 서버사이드 코틀린카카오톡의 서버사이드 코틀린
카카오톡의 서버사이드 코틀린if kakao
 
Event driven architecture with Kafka
Event driven architecture with KafkaEvent driven architecture with Kafka
Event driven architecture with KafkaFlorence Next
 
Modern Automated Site Provisioning for SharePoint Online
Modern Automated Site Provisioning for SharePoint OnlineModern Automated Site Provisioning for SharePoint Online
Modern Automated Site Provisioning for SharePoint OnlineDocFluix, LLC
 
Overview about OracleVM and Oracle Linux
Overview about OracleVM and Oracle LinuxOverview about OracleVM and Oracle Linux
Overview about OracleVM and Oracle Linuxandreas kuncoro
 
Applications in Pharo
Applications in PharoApplications in Pharo
Applications in PharoESUG
 
Flutter vs. MAUI - what should you pick and why?
Flutter vs. MAUI - what should you pick and why?Flutter vs. MAUI - what should you pick and why?
Flutter vs. MAUI - what should you pick and why?Tobias Hoppenthaler
 

Was ist angesagt? (20)

Native mobile application development with Flutter (Dart)
Native mobile application development with Flutter (Dart)Native mobile application development with Flutter (Dart)
Native mobile application development with Flutter (Dart)
 
Apache Karaf - Building OSGi applications on Apache Karaf - T Frank & A Grzesik
Apache Karaf - Building OSGi applications on Apache Karaf - T Frank & A GrzesikApache Karaf - Building OSGi applications on Apache Karaf - T Frank & A Grzesik
Apache Karaf - Building OSGi applications on Apache Karaf - T Frank & A Grzesik
 
Deploying Viva Topics
Deploying Viva TopicsDeploying Viva Topics
Deploying Viva Topics
 
How to Send IDOC to SAP using MuleSoft
How to Send IDOC to SAP using MuleSoftHow to Send IDOC to SAP using MuleSoft
How to Send IDOC to SAP using MuleSoft
 
Modelo cascata apresentação
Modelo cascata apresentaçãoModelo cascata apresentação
Modelo cascata apresentação
 
Deploying Flink on Kubernetes - David Anderson
 Deploying Flink on Kubernetes - David Anderson Deploying Flink on Kubernetes - David Anderson
Deploying Flink on Kubernetes - David Anderson
 
Virtual Container - Docker
Virtual Container - Docker Virtual Container - Docker
Virtual Container - Docker
 
Introducing the Apache Flink Kubernetes Operator
Introducing the Apache Flink Kubernetes OperatorIntroducing the Apache Flink Kubernetes Operator
Introducing the Apache Flink Kubernetes Operator
 
BA and Beyond 20 - Elke Steegmans and David Vandenbroeck - Behaviour-driven d...
BA and Beyond 20 - Elke Steegmans and David Vandenbroeck - Behaviour-driven d...BA and Beyond 20 - Elke Steegmans and David Vandenbroeck - Behaviour-driven d...
BA and Beyond 20 - Elke Steegmans and David Vandenbroeck - Behaviour-driven d...
 
Functional Smalltalk
Functional SmalltalkFunctional Smalltalk
Functional Smalltalk
 
Android info session
Android info sessionAndroid info session
Android info session
 
Software development PROCESS
Software development PROCESSSoftware development PROCESS
Software development PROCESS
 
카카오톡의 서버사이드 코틀린
카카오톡의 서버사이드 코틀린카카오톡의 서버사이드 코틀린
카카오톡의 서버사이드 코틀린
 
Sap abap
Sap abapSap abap
Sap abap
 
Event driven architecture with Kafka
Event driven architecture with KafkaEvent driven architecture with Kafka
Event driven architecture with Kafka
 
Modern Automated Site Provisioning for SharePoint Online
Modern Automated Site Provisioning for SharePoint OnlineModern Automated Site Provisioning for SharePoint Online
Modern Automated Site Provisioning for SharePoint Online
 
Overview about OracleVM and Oracle Linux
Overview about OracleVM and Oracle LinuxOverview about OracleVM and Oracle Linux
Overview about OracleVM and Oracle Linux
 
Microsoft Teams Usage
Microsoft Teams UsageMicrosoft Teams Usage
Microsoft Teams Usage
 
Applications in Pharo
Applications in PharoApplications in Pharo
Applications in Pharo
 
Flutter vs. MAUI - what should you pick and why?
Flutter vs. MAUI - what should you pick and why?Flutter vs. MAUI - what should you pick and why?
Flutter vs. MAUI - what should you pick and why?
 

Andere mochten auch

Andere mochten auch (12)

Dissertation Final Draft
Dissertation Final DraftDissertation Final Draft
Dissertation Final Draft
 
Taller angela cuyamón
Taller angela cuyamónTaller angela cuyamón
Taller angela cuyamón
 
Relacion autores y teorias
Relacion autores y teoriasRelacion autores y teorias
Relacion autores y teorias
 
Tutorial 1.1 curso de car
Tutorial 1.1   curso de carTutorial 1.1   curso de car
Tutorial 1.1 curso de car
 
Sistemas de gestión de aprendizaje
Sistemas de gestión de aprendizajeSistemas de gestión de aprendizaje
Sistemas de gestión de aprendizaje
 
Project List
Project ListProject List
Project List
 
Normas apa
Normas apaNormas apa
Normas apa
 
Tutorial1 11/11
Tutorial1 11/11Tutorial1 11/11
Tutorial1 11/11
 
tacoma79dollarwebsitedesignpros_com
tacoma79dollarwebsitedesignpros_comtacoma79dollarwebsitedesignpros_com
tacoma79dollarwebsitedesignpros_com
 
Tutorial 2 curso de car
Tutorial 2   curso de carTutorial 2   curso de car
Tutorial 2 curso de car
 
Tv learning
Tv learningTv learning
Tv learning
 
Método científico
Método científicoMétodo científico
Método científico
 

Ähnlich wie Solving data publication challenges for even better rsa archer reporting

Catalyst 2016: EnergyCAP Report Designer: Intro and Overview.
Catalyst 2016: EnergyCAP Report Designer: Intro and Overview. Catalyst 2016: EnergyCAP Report Designer: Intro and Overview.
Catalyst 2016: EnergyCAP Report Designer: Intro and Overview. EnergyCAP, Inc.
 
Documentum Spring Data
Documentum Spring DataDocumentum Spring Data
Documentum Spring DataMichael Mohen
 
Oracle Application Express
Oracle Application ExpressOracle Application Express
Oracle Application ExpressHBoone
 
Peteris Arajs - Where is my data
Peteris Arajs - Where is my dataPeteris Arajs - Where is my data
Peteris Arajs - Where is my dataAndrejs Vorobjovs
 
Critical Preflight Checks for Your EPM Applications
Critical Preflight Checks for Your EPM ApplicationsCritical Preflight Checks for Your EPM Applications
Critical Preflight Checks for Your EPM ApplicationsDatavail
 
2017 OpenWorld Keynote for Data Integration
2017 OpenWorld Keynote for Data Integration2017 OpenWorld Keynote for Data Integration
2017 OpenWorld Keynote for Data IntegrationJeffrey T. Pollock
 
Modern infrastructure for business data lake
Modern infrastructure for business data lakeModern infrastructure for business data lake
Modern infrastructure for business data lakeEMC
 
APEX Boston Meetup - October 1st, 2019
APEX Boston Meetup - October 1st, 2019APEX Boston Meetup - October 1st, 2019
APEX Boston Meetup - October 1st, 2019msewtz
 
Data Governance - Atlas 7.12.2015
Data Governance - Atlas 7.12.2015Data Governance - Atlas 7.12.2015
Data Governance - Atlas 7.12.2015Hortonworks
 
EMC Big Data Solutions Overview
EMC Big Data Solutions OverviewEMC Big Data Solutions Overview
EMC Big Data Solutions Overviewwalshe1
 
BrightTalk session-The right SDS for your OpenStack Cloud
BrightTalk session-The right SDS for your OpenStack CloudBrightTalk session-The right SDS for your OpenStack Cloud
BrightTalk session-The right SDS for your OpenStack CloudEitan Segal
 
Advantages of the Cloud_Q2_2017.pptx
Advantages of the Cloud_Q2_2017.pptxAdvantages of the Cloud_Q2_2017.pptx
Advantages of the Cloud_Q2_2017.pptxSaboneSabone
 
Storm Demo Talk - Denver Apr 2015
Storm Demo Talk - Denver Apr 2015Storm Demo Talk - Denver Apr 2015
Storm Demo Talk - Denver Apr 2015Mac Moore
 
Scala dayssrinivas v3
Scala dayssrinivas v3Scala dayssrinivas v3
Scala dayssrinivas v3ragss
 
Exploitez le meilleur de SAP avec EMC
Exploitez le meilleur de SAP avec EMCExploitez le meilleur de SAP avec EMC
Exploitez le meilleur de SAP avec EMCRSD
 
Collaborate 19: Help!! EPRCS, Financial Reports, Smart View, Which Report Too...
Collaborate 19: Help!! EPRCS, Financial Reports, Smart View, Which Report Too...Collaborate 19: Help!! EPRCS, Financial Reports, Smart View, Which Report Too...
Collaborate 19: Help!! EPRCS, Financial Reports, Smart View, Which Report Too...Kelliann Hoelscher
 
Sap fundamentals overview_for_sap_minors
Sap fundamentals overview_for_sap_minorsSap fundamentals overview_for_sap_minors
Sap fundamentals overview_for_sap_minorsCenk Ersoy
 

Ähnlich wie Solving data publication challenges for even better rsa archer reporting (20)

Catalyst 2016: EnergyCAP Report Designer: Intro and Overview.
Catalyst 2016: EnergyCAP Report Designer: Intro and Overview. Catalyst 2016: EnergyCAP Report Designer: Intro and Overview.
Catalyst 2016: EnergyCAP Report Designer: Intro and Overview.
 
Why Use an Oracle Database?
Why Use an Oracle Database?Why Use an Oracle Database?
Why Use an Oracle Database?
 
Documentum Spring Data
Documentum Spring DataDocumentum Spring Data
Documentum Spring Data
 
Oracle Application Express
Oracle Application ExpressOracle Application Express
Oracle Application Express
 
Peteris Arajs - Where is my data
Peteris Arajs - Where is my dataPeteris Arajs - Where is my data
Peteris Arajs - Where is my data
 
Critical Preflight Checks for Your EPM Applications
Critical Preflight Checks for Your EPM ApplicationsCritical Preflight Checks for Your EPM Applications
Critical Preflight Checks for Your EPM Applications
 
2017 OpenWorld Keynote for Data Integration
2017 OpenWorld Keynote for Data Integration2017 OpenWorld Keynote for Data Integration
2017 OpenWorld Keynote for Data Integration
 
Modern infrastructure for business data lake
Modern infrastructure for business data lakeModern infrastructure for business data lake
Modern infrastructure for business data lake
 
APEX Boston Meetup - October 1st, 2019
APEX Boston Meetup - October 1st, 2019APEX Boston Meetup - October 1st, 2019
APEX Boston Meetup - October 1st, 2019
 
Data Governance - Atlas 7.12.2015
Data Governance - Atlas 7.12.2015Data Governance - Atlas 7.12.2015
Data Governance - Atlas 7.12.2015
 
EMC Big Data Solutions Overview
EMC Big Data Solutions OverviewEMC Big Data Solutions Overview
EMC Big Data Solutions Overview
 
BrightTalk session-The right SDS for your OpenStack Cloud
BrightTalk session-The right SDS for your OpenStack CloudBrightTalk session-The right SDS for your OpenStack Cloud
BrightTalk session-The right SDS for your OpenStack Cloud
 
Advantages of the Cloud_Q2_2017.pptx
Advantages of the Cloud_Q2_2017.pptxAdvantages of the Cloud_Q2_2017.pptx
Advantages of the Cloud_Q2_2017.pptx
 
Storm Demo Talk - Denver Apr 2015
Storm Demo Talk - Denver Apr 2015Storm Demo Talk - Denver Apr 2015
Storm Demo Talk - Denver Apr 2015
 
Scala dayssrinivas v3
Scala dayssrinivas v3Scala dayssrinivas v3
Scala dayssrinivas v3
 
Exploitez le meilleur de SAP avec EMC
Exploitez le meilleur de SAP avec EMCExploitez le meilleur de SAP avec EMC
Exploitez le meilleur de SAP avec EMC
 
Resume_Parthiban_Ranganathan
Resume_Parthiban_RanganathanResume_Parthiban_Ranganathan
Resume_Parthiban_Ranganathan
 
Collaborate 19: Help!! EPRCS, Financial Reports, Smart View, Which Report Too...
Collaborate 19: Help!! EPRCS, Financial Reports, Smart View, Which Report Too...Collaborate 19: Help!! EPRCS, Financial Reports, Smart View, Which Report Too...
Collaborate 19: Help!! EPRCS, Financial Reports, Smart View, Which Report Too...
 
SAP Business Objects Trianing
SAP Business Objects TrianingSAP Business Objects Trianing
SAP Business Objects Trianing
 
Sap fundamentals overview_for_sap_minors
Sap fundamentals overview_for_sap_minorsSap fundamentals overview_for_sap_minors
Sap fundamentals overview_for_sap_minors
 

Mehr von Iceberg Networks Corporation

Yes, there is a better way to do vendor risk assessments!
Yes, there is a better way to do vendor risk assessments!Yes, there is a better way to do vendor risk assessments!
Yes, there is a better way to do vendor risk assessments!Iceberg Networks Corporation
 
How Archer users are leveraging Iceberg APS for a stronger GRC program
How Archer users are leveraging Iceberg APS for a stronger GRC programHow Archer users are leveraging Iceberg APS for a stronger GRC program
How Archer users are leveraging Iceberg APS for a stronger GRC programIceberg Networks Corporation
 
Transforming compliance and audit management with ServiceNow
Transforming compliance and audit management with ServiceNowTransforming compliance and audit management with ServiceNow
Transforming compliance and audit management with ServiceNowIceberg Networks Corporation
 
WEBINAR: Enhance your perspective of vendor risk with ServiceNow
WEBINAR: Enhance your perspective of vendor risk with ServiceNowWEBINAR: Enhance your perspective of vendor risk with ServiceNow
WEBINAR: Enhance your perspective of vendor risk with ServiceNowIceberg Networks Corporation
 
Iceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Webinar: Adding relevant financial context to your BCM programIceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Webinar: Adding relevant financial context to your BCM program Iceberg Networks Corporation
 
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...Iceberg Networks Corporation
 
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPRSolution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPRIceberg Networks Corporation
 
RSA-Iceberg Seminar: Building an effective supplier risk management program
RSA-Iceberg Seminar: Building an effective supplier risk management programRSA-Iceberg Seminar: Building an effective supplier risk management program
RSA-Iceberg Seminar: Building an effective supplier risk management programIceberg Networks Corporation
 

Mehr von Iceberg Networks Corporation (11)

Yes, there is a better way to do vendor risk assessments!
Yes, there is a better way to do vendor risk assessments!Yes, there is a better way to do vendor risk assessments!
Yes, there is a better way to do vendor risk assessments!
 
How Archer users are leveraging Iceberg APS for a stronger GRC program
How Archer users are leveraging Iceberg APS for a stronger GRC programHow Archer users are leveraging Iceberg APS for a stronger GRC program
How Archer users are leveraging Iceberg APS for a stronger GRC program
 
Transforming compliance and audit management with ServiceNow
Transforming compliance and audit management with ServiceNowTransforming compliance and audit management with ServiceNow
Transforming compliance and audit management with ServiceNow
 
WEBINAR: Enhance your perspective of vendor risk with ServiceNow
WEBINAR: Enhance your perspective of vendor risk with ServiceNowWEBINAR: Enhance your perspective of vendor risk with ServiceNow
WEBINAR: Enhance your perspective of vendor risk with ServiceNow
 
Iceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Webinar: Adding relevant financial context to your BCM programIceberg Webinar: Adding relevant financial context to your BCM program
Iceberg Webinar: Adding relevant financial context to your BCM program
 
Webinar: Evolve Beyond the Third Line
Webinar: Evolve Beyond the Third LineWebinar: Evolve Beyond the Third Line
Webinar: Evolve Beyond the Third Line
 
Webinar: Getting a grip on application risk
Webinar: Getting a grip on application riskWebinar: Getting a grip on application risk
Webinar: Getting a grip on application risk
 
Case study: Getting a grip on application risk
Case study: Getting a grip on application riskCase study: Getting a grip on application risk
Case study: Getting a grip on application risk
 
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
Webinar: Vulnerability Management IT can fix it, but the business needs to ow...
 
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPRSolution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
 
RSA-Iceberg Seminar: Building an effective supplier risk management program
RSA-Iceberg Seminar: Building an effective supplier risk management programRSA-Iceberg Seminar: Building an effective supplier risk management program
RSA-Iceberg Seminar: Building an effective supplier risk management program
 

Kürzlich hochgeladen

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNavi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbuapidays
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusZilliz
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 

Kürzlich hochgeladen (20)

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNavi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 

Solving data publication challenges for even better rsa archer reporting

  • 1. © Copyright 2016 EMC Corporation.
  • 2. #RSACharge © Copyright 2016 EMC Corporation. Solving Data Publication Challenges for Even Better Archer Reporting Phil Aldrich, Dell David Pearson, Iceberg
  • 3. © Copyright 2016 EMC Corporation. Agenda • Reporting requirements • Key Technical Challenges • Datamart / ETL / BI solution • EMC “Proof of Concept” (Archer/Tableau integration) • Next Steps
  • 4. © Copyright 2016 EMC Corporation. Challenge • Archer is a powerful tool for aggregating risk and compliance data • More mature organizations often have reporting/dashboard requirements that go beyond Archer out-of-box capabilities • Example: Audit committee + board-level reporting requirements + risk metrics “How can we drive more meaningful / actionable / valuable reports from Archer?”
  • 5. © Copyright 2016 EMC Corporation. Typical business requirements Functionality • Advanced visualizations (heat maps, bowtie charts, cause-effect trees) • Manipulate / customize dashboards • More control over exports to Excel, PowerPoint, etc. • Metric and Trend analysis • Easier integration with other BI tools
  • 6. © Copyright 2016 EMC Corporation. Capability RSA Archer BI tool • “On the fly” report creation/edits • Ability to export reports into multiple formats • Variety of report display options (bar, line, heat, pie, etc.) • Ability to create reports with separate data sources • Multi-dimensional reports (3 or more) • Ability to implement analysis algorithms (monte carlo, etc.) • Ability to add report description with export/display • Metric Trending & Analysis • Forecast projected results within report Reporting Capabilities
  • 7. © Copyright 2016 EMC Corporation. Reporting Requirements Source: COSO.org, Developing Key Risk Indicators to Strengthen Enterprise Risk Management “Understand the Full Picture”
  • 8. © Copyright 2016 EMC Corporation. Reporting Requirements Source: COSO.org, Risk Assessment in Practice
  • 9. © Copyright 2016 EMC Corporation. Reporting Requirements Source: COSO.org, Risk Assessment in Practice
  • 10. © Copyright 2016 EMC Corporation. Current solution: Archer Data Publication Service (DPS) • Use Archer’s DPS (Data Publication Service), and import data into a BI tool like Tableau But DPS has its problems… o Process is difficult to support/maintain o How do we maintain Archer’s security/permissions in the BI tool? o DPS produces “unfriendly field names” o How do we cross reference data from multiple Archer modules? o Can we capture trending?
  • 11. © Copyright 2016 EMC Corporation. Risk Intelligence Data Mart Datamart / ETL / BI solution DPS Meta Data Archer Application Data Xform Reporting Datastore SQL/API Data Access
  • 12. © Copyright 2016 EMC Corporation. DPS Raw Data Model Risk Intelligence Data Mart Meta Data Xform Reporting Datastore Data Access Archer Application Data
  • 13. © Copyright 2016 EMC Corporation. Additional Queries - Example Risk Intelligence Data Mart Archer Application Data Xform Reporting Datastore Data Access Meta Data
  • 14. © Copyright 2016 EMC Corporation. Post Transformation Data Model Risk Intelligence Data Mart Meta Data Archer Application Data Xform Data Access Reporting Datastore
  • 15. © Copyright 2016 EMC Corporation. 1. Datamart: all Archer data for an application is available from a single view within a database 2. Maintains Archer’s security and access controls: Includes row-level permissions, automatically mirroring Archer’s security model 3. A simplified data model: Data is combined from dozens or hundreds of tables, and includes enumerated field “meanings”, for reporting ease and performance 4. Reports/Dashboards: Easier configuration of enriched executive reports and dashboards within a BI tool.
  • 16. © Copyright 2016 EMC Corporation.
  • 17. © Copyright 2016 EMC Corporation.
  • 18. © Copyright 2016 EMC Corporation. EMC “Proof of Concept” • Use a subset of information on proof of concept (Risk Register) • Build “solid” integration b/w Archer and Tableau • Showcase reporting capabilities not available in Archer • Maintain Archer access control permissions • Ensure integration process is “easy” to support
  • 19. © Copyright 2016 EMC Corporation. POC Phases LEADER 2016 July Aug Sept Oct Nov Dec Requirements Gathering EMC Technical Setup EMC/Iceberg /AHA Report Creation Iceberg/AHA ETL Redesign (6.1) Iceberg/AHA ETL Deploy/Test (6.1) EMC/Dell Metrics Development Dell/AHA EMC “Proof of Concept” timeline
  • 20. © Copyright 2016 EMC Corporation. • Ability to provide a full “snapshot” to executives with supporting context • Ability to add report data into PowerPoint presentations or summary audit reports • Provide “actionable” reporting files/interfaces to allow real-time analysis (ie. Tableau)
  • 21. © Copyright 2016 EMC Corporation. Risk Action chart • “Actionable” report for easy executive consumption • Provides another “axis” of information • Overlay of Risk Summary Report
  • 22. © Copyright 2016 EMC Corporation. Challenges / Opportunities • 5.5 version vs. 6.1 ETL – Required a redesign – Commitment from RSA to inform on future changes • Maintain Archer access control capability – Key requirement to ensure data confidentiality • Ensure “ease of use” for future “lights on” support – Archer Support team can easily manage integration and updates • Continue to build a “Risk Intelligence” story – Add metrics, risk costs vs. impacts
  • 23. #RSACharge © Copyright 2016 EMC Corporation. Please Complete Session Evaluation
  • 24. #RSACharge © Copyright 2016 EMC Corporation.