GRC A holistic Road Map for Information Security



















- Slides: 19
GRC, A holistic Road Map for Information Security Transformation Eng. Mohamed Saad Mousa Head of information Security IKEA Saudi and Bahrain 00966562539903
Digital Transformation Era 2 Robotics • Future Driven Technologies Very Cheap Labour Block chain Virtual Reality create internet of money Reality As you imagine Clouded computing ICT department in no where Big Data Analysis Artificial Intelligence Determine business mean stream take a decision instead of human Internet of things IOT will be Sensing every thing Agile Software development of software is not a big deal Cyber Security Program
Cyber resilience statistics (EY 20 th Global Information Security Survey 2017 -18 )
2019 Will Be The Year Of Cyber War ?
CISO Challenges 5 business reliability on ICT Culture change resistance business relay more on ICT day after day. We live in digital business era with increasing expectation of Confidentiality, Integrity , availability and privacy Changing culture for more security environment is always a challnge New emerging technology Resources And all of these new technologies introduce new risks to business environment Still we have a very limited number of resources in information security field Budget constrains Most of business environments is struggling to reduce their expenses
Governance , Risk and Compliance • GRC is a system of people, processes and technology that enables an organization to understand prioritize stakeholder expectations; set business objectives congruent with values and risks; achieve objectives while optimizing risk profile and protecting value; operate within legal, contractual, internal, social and ethical boundaries; provide relevant, reliable and timely information to appropriate stakeholders; and enable the measurement of the performance and effectiveness of the system.
GRC is a vision of Principled Performance
Learn Your Business Context for Principled Performance
GRC Road Map (Strategic insight)
GRC 5 integration points, IT and Information Security
5 Success Driving Gears Standards and frameworks Never relay on the standard or framework reputation. There is no best standard and every business has its own character. Chose suitable Framework that present your business 01 02 objective control library Chose the control library that achieve your business objective not that has much more controls again there is no best standard The program can not be measured can not managed. : e-GRC platform will help you to have a complete vision of GRC program with holistic program KPIs. Chose the right risk management methodology. After that Link the risk management with other Information security department activity such incident handling , vulnerability 03 management , compliance …etc 04 Measuring principle performance Risk Management Culture change Culture resistance is most Show stopper of GRC programme. Awareness programme is most effective tool to culture 05 change
GRC : Measure people security to manage information security • The GRC program is about business enablement for principal performance. The program can not be measured can not managed. üPeople performance üProcesses maturity üTechnology benchmarking o CISO should design clear KPIs that related to Program Effectiveness, Responsive , compliance , …etc. o Use standards to design your own measuring tool such as COBIT 5 PAM tool, OCEG (Burgundy Book), ISF benchmarking tool , …. .
Questions
Thank you