it compliance and risk brian markham director, dit compliance and risk services may 1, 2014

24
IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

Upload: peter-boone

Post on 22-Dec-2015

219 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

Brian Markham

Director, DIT Compliance and Risk Services

May 1, 2014

Page 2: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

• UMD grad (BA and MBA)• Seven years in IT at UMD • Seven years in consulting (KPMG, PwC)• New-ish to GW (November ’13)

Introduction

Page 3: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

Three things:• The business of IT (an overview)• Compliance• Risk

Agenda

Page 4: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

The Business of IT

Page 5: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

Why do we have IT?

You

Page 6: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

Why do we have IT?

You IT Awesome!

Page 7: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

How do we succeed?

Customer Support OperationsApplication

DevelopmentStrategic PlanningSecurity

RiskCompliance

Governance

Page 8: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• Users/Customers• Understanding the business• Understanding requirements• Implementing technology that meets

requirements to enable the business• Perspective/vision of the future• Planning, strategy, execution• Fun!

IT Compliance and Risk

IT is about…

Page 9: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• IT is complicated• IT folks aren’t experts in all things• Different users have different needs• Business/requirements change• Technology changes (fast)

IT Compliance and Risk

But…

Page 10: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• Meet requirements (contracts, laws, policy)• Ensure that confidentiality data is protected• Ensure that data cannot be altered• Ensure that systems are available• Understand and manage risk• Ensure that services can be offered that

are secure and meet requirements• Services are “fit for use”

IT Compliance and Risk

Role of Compliance and Risk

Page 11: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

Compliance

Page 12: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• Federal Educational Rights and Privacy Act (FERPA)

• Federal Information Security Management Act (FISMA)

• Health Insurance Portability and Accountability Act (HIPAA)

• Payment Card Industry Data Security Standard (PCI DSS)

• University Policies• Contracts and Agreements

IT Compliance and Risk

GW and Compliance

Page 13: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• Understand the requirements• Identify stakeholders• Review controls and the “as-is” state• Reference control guidance and best practices• Assess controls

– Test of Design– Test of Operating Effectiveness

• Document gaps, identify corrective actions• Continuous monitoring

IT Compliance and Risk

How Do We Achieve Compliance?

Page 14: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

In other words…

Plan for Compliance

Implement Controls

Assess Controls

Corrective Actions

Deming Cycle – Plan, Do, Check, Act

Page 15: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• Understanding• Expensive• It’s hard• Compliance ≠ Security!

IT Compliance and Risk

Compliance Challenges

Page 16: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

Risk

Page 17: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.

Impact X Probability = Risk Priority

IT Compliance and Risk

What is Risk?

Page 18: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• It’s not easy• Data-driven “gut feel”• Use data where possible:

– Outages/Downtime– Revenue Lost– Performance vs. SLAs– Performance of KPIs– Historical Data

IT Compliance and Risk

Quantifying Risk

Page 19: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• Compliance Risk• Financial Risk• Human Resource Risk• Operations Risk (Availability)• Project Risk• Reputation Risk • Safety Risk • Security Risk • Vendor Risk

IT Compliance and Risk

Lots of Risk!

Page 20: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

• Governance!• Process and documentation• Outreach and buy-in• Identify, track and mitigate risks

– Prioritize

• Continuous improvement

IT Compliance and Risk

Where do we start?

Page 21: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

Risk Management Challenges

• You don’t know what you don’t know• Incentives to not report• Risks can be expensive• IT is complicated

Page 22: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

Risk Management Tools

• Governance Risk & Compliance (GRC) tool

• Risk Register• Assessment methodologies• Risk Assessments• Control catalogs• Configuration Management Database

(CMDB)

Page 23: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

Summary

• Compliance and risk management is a critical piece of IT management

• Understand the compliance landscape• Understand the risk landscape• We are all risk managers!

Page 24: IT Compliance and Risk Brian Markham Director, DIT Compliance and Risk Services May 1, 2014

IT Compliance and Risk

For More Information

Contact Brian Markham at 571-553-0189 or [email protected].