10
Muni Chatarpal, CISM, CISSP, CEH Security and Risk Management Enbridge Energy Par tners June 15, 2010 Considerations for Implementing IT GRC

Muni chatarpal considerations for grc

  • Upload
    jpkush

  • View
    314

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Muni chatarpal   considerations for grc

Muni Chatarpal, CISM, CISSP, CEHSecurity and Risk ManagementEnbridge Energy PartnersJune 15, 2010

Considerations for Implementing IT GRC

Page 2: Muni chatarpal   considerations for grc

Meeting Agenda

Problem Statement Our Solution Our Roadmap Key Discoveries Immediate Benefits Path Forward

2

Page 4: Muni chatarpal   considerations for grc

Our Solution

People, Process ,Technology Stakeholder Analysis – Create RACI, Identify

Ambassadors Develop process and implement phased approach Easy <10% effort

Establish and adopted a common framework Map controls to assets Request evidence for critical assets

Scope Challenge – ‘don’t boil the ocean’ IT Asset Repository

4

ITRM Compliance

Process

Inventory

Plan and scope

Analyze and Report

Treat or Accept

Page 5: Muni chatarpal   considerations for grc

Our Solution

Communication Awareness Compliance Specialists, Control Owners, ASs

Align Methodologies RM strategies with audit methodologies Develop evidence collection guidelines to build

synergies with existing collection methods

Start with basic assessment functionalities and Automate where possible

Utilized web-based questionnaires instead of manual assessment techniques to automate self assessment process

Provide capability to capture evidence

5

Page 6: Muni chatarpal   considerations for grc

Q1: 2009 ITRM policy

adopted

Q3 2009: Compliance process developed

Q4 2009:

ITRM Solution implemented

Ris

k M

anag

emen

t C

apab

ilit

y

Q1 2010: Assessment completed

Jan 2011:

121 IT assets

checked for

ITRM compliance

Full reports

produced

Q1-Q4 2010:

Assessments in

progress. Quarterly

reports.

2011: Phase IIEnhanced reporting &

Risk Assessments

6

Our 2010 Roadmap

Page 7: Muni chatarpal   considerations for grc

Key Discoveries

Don’t overwhelm Control Owners Enable Control Owners by using automation Quality Control the first assessment Audit is an enabler Asset repository can be challenging Incremental approach Train and engage

7

Page 8: Muni chatarpal   considerations for grc

Immediate Benefits

Improved quality of assessments Increased efficiency though utilization of

consistent processes Control Owners engagement Compliance reporting

8

Page 9: Muni chatarpal   considerations for grc

Path Forward

Integration with other areas and compliance mandates (SOX, PCI, NERC/FERC, TSA PSG, API 1164, PIPEDA, etc)

Integration of TRA (Threat Risk Assessments) Remediation Tracking and exception management Leverage integration with 3rd party tools (VA,

Ticketing) Improved Reporting

9

Page 10: Muni chatarpal   considerations for grc

Questions

10