尊敬的 微信汇率:1円 ≈ 0.046089 元 支付宝汇率:1円 ≈ 0.04618元 [退出登录]
SlideShare a Scribd company logo
GRCaaS
Governance Risk Compliance as a Service
GRC Automation Simplified
Agenda
• How was GRC developed?
• What exactly is GRC?
• The role of GRC in ISMS
• Impact of GRC
• Types of GRC
• The role IT-GRC in IT-RMC
• IT-GRC Foundation
• Why to deploy IT-GRC Management System?
How was GRC developed?
GRC framework was developed as a consequence of well-known
public events such as Enron scandal in October 2001, eventually
lead the bankruptcy of the Enron Corp.
Followed by the dissolution of Arthur Andersen, one of the
largest audit and accounting partnerships in the world
In addition to begin the largest bankruptcy reorganization in
American history at the time, Enron attributed as the biggest
audit failure
How was GRC developed?
Because of the scandal, new regulations and legislation enacted
to expand the accuracy of financial reporting for public
companies
One piece of legislation, Sarbanes-Oxley Act, increased penalties
for destroying, altering, or fabricating records in federal
investigations or for attempting to defraud shareholders
The act also increased the accountability of auditing firms to
remain unbiased and independent of their clients
What is GRC
GRC Definition
Governance Risk Compliance is an integrated approach used by
corporations to act in accordance with the guidelines set for
each category
GRC is not a single activity, but rather a firm-wide approach to
achieving high standards in all three overlapping categories
What is GRC
IT-GRC specifics key capabilities
• Controls and policy library
• Policy distribution and response
• IT Controls self-assessment and measurement
• IT Asset repository
• Remediation and exception management
• Vendors Management
• Reporting
• Advanced IT risk evaluation and compliance dashboards
The role of GRC
The business impact
• 70% to 80% of market value comes from hard-to-assess
intangible assets such as brand equity, intellectual capital and
goodwill
• Organizations are especially vulnerable to incidents that may
damage their reputations, oftentimes with unforeseen
consequences
The role of GRC
From Ernst & Young survey of 137 Global
Institutional Investors:
• 82% will pay a premium for companies that demonstrate
successful risk management
• 61% will not invest where there is evidence of poor risk
management
• 41% would withdraw investment where there is a
perceived lack of appropriate risk management
IT-GRC in ISMS
Information Security Management Systems
Internal effectiveness
Customer
confidence
External security risks
Compliance
&
regulations
ISMS
ISMS overall management system based on a Risk approach to:
Establish, Implement, Operate, Monitor, Review and Improve Information Security
Impact of GRC
• Emergence of new regulatory compliances
• Alteration of corporate governance landscape
• Organizations are held accountable for accuracy and
integrity in their business operations
• Effective and reliable governance and compliance
procedures is the need of the hour
Types of GRC
eGRC IT-GRC
Focus Enterprise Only IT
Content supplied by Customer Prepopulated
Deployment type Lengthy - large number of variables Short - Well defined framework
Controls Financial Control & Labor
Standards
• Regulatory Compliance
• Business Processes
• Import and Export Laws
• Health and Safety
• Security
• Infrastructure
• and much more
IT security systems and applications
• Vulnerability
• Configuration management
• Change management
• IT-Risk management
• IT-Regulatory Compliance
• and more
Success rate Low - Due to complexity and lack
of buying from key stakeholders
Very high – Due to it focus and defined
SOW, stakeholders support and
measurable KPI and KRI
Resetting IT-GRC definition at Gartner
IT-GRC is essentially enterprise GRC functions focused on IT
specific needs
For the last two years, IT-GRC has started to bifurcate into:
• IT-related GRC functions
• Security operations functions
IT-GRC at Gartner
The role of IT-GRC in IT-RMC
IT-GRC specifics key capabilities
 Controls and policy library
 Policy distribution and response
 IT Controls self-assessment and measurement
 IT Asset repository
 Remediation and exception management
 Vendors Management
 Reporting, Scorecards, Dashboard
 Advanced IT risk evaluation and compliance dashboards
Why GRC
Step One - Define
Policies and Compliance
o Map Policies & Regulation to controls
o Identify Assets and Vendors
o Identify Risk Profile
Step Two - Measure
Test Controls
o Create customized Assessments
o Measure inherent Risk & Compliance
o Measure Policy training effectiveness
o Test Vendor Risk
Step Three - Manage
Manage Risk & Compliance
o Create interactive real time GRC
Dashboards for mobile devices
o Demonstrate Compliance
o Manage Incidents, Threats and
Vulnerabilities
GRC is a centralized and cohesive system which, incorporates:
• Internal Audits
• External Regulatory Compliance
• Risk Management
Why to deploy IT-GRC Management
System?
• Better management of workflow as compared to the hassle of
using spreadsheets or auditors provided software
• Because different groups in the organization are looking for
audit and risk compliance management solutions
• Effective management of compliances to avoid chaos,
difficulties and confusion
• Improves reporting and dashboarding
• Holistic view of risk management and compliance activities
• Supports rationalization of compliance and risk management
activities across the platform
CMLgroup GRCaaS
Contact us today to discuss your
IT-GRC requirements
+ 1 646 827-2291
www.cmlgroup.com
Info@cmlgroup.com

More Related Content

What's hot

GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance Executive
Max Neira Schliemann
 
Operational security | How to design your information security GRC (governanc...
Operational security | How to design your information security GRC (governanc...Operational security | How to design your information security GRC (governanc...
Operational security | How to design your information security GRC (governanc...
Maxime CARPENTIER
 
GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014
Paul Simidi
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
Risk Management Institution of Australasia
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
Rishabh Software
 
Ten Slides in Ten Minutes - Company Realities - GRC
Ten Slides in Ten Minutes - Company Realities - GRCTen Slides in Ten Minutes - Company Realities - GRC
Ten Slides in Ten Minutes - Company Realities - GRC
Bill Graham CP.APMP
 
it grc
it grc it grc
it grc
9535814851
 
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
Egyptian Engineers Association
 
Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)
Alex Todd
 
Integrated GRC
Integrated GRCIntegrated GRC
Integrated GRC
Transcendent Group
 
Risk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and ImplementationRisk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and Implementation
Risk Management Institution of Australasia
 
Governance Risk and Compliance - in Higher Education - Australia
Governance Risk and Compliance - in Higher Education - AustraliaGovernance Risk and Compliance - in Higher Education - Australia
Governance Risk and Compliance - in Higher Education - Australia
Marissa McCauley
 
5 steps for better risk assessment
5 steps for better risk assessment5 steps for better risk assessment
5 steps for better risk assessment
DrMohammedFarid
 
Fix nix, inc
Fix nix, incFix nix, inc
Fix nix, inc
FixNix Inc.,
 
GRC 101 ISACA Bengaluru on 28th Dec 2013
GRC 101 ISACA Bengaluru on 28th Dec 2013GRC 101 ISACA Bengaluru on 28th Dec 2013
GRC 101 ISACA Bengaluru on 28th Dec 2013
FixNix Inc.,
 
Cloud Securiy: A Vendor Risk Management Perspective
Cloud Securiy: A Vendor Risk Management PerspectiveCloud Securiy: A Vendor Risk Management Perspective
Cloud Securiy: A Vendor Risk Management Perspective
Argyle Executive Forum
 
Third Party Risk Management
Third Party Risk ManagementThird Party Risk Management
Third Party Risk Management
EC-Council
 
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment QuestionnairesThird-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Corporater
 
GRC Fundamentals
GRC FundamentalsGRC Fundamentals
GRC Fundamentals
3Sixty Insights
 
6 implications of internal audit
6 implications of internal audit6 implications of internal audit
6 implications of internal audit
SALIH AHMED ISLAM
 

What's hot (20)

GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance Executive
 
Operational security | How to design your information security GRC (governanc...
Operational security | How to design your information security GRC (governanc...Operational security | How to design your information security GRC (governanc...
Operational security | How to design your information security GRC (governanc...
 
GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
Ten Slides in Ten Minutes - Company Realities - GRC
Ten Slides in Ten Minutes - Company Realities - GRCTen Slides in Ten Minutes - Company Realities - GRC
Ten Slides in Ten Minutes - Company Realities - GRC
 
it grc
it grc it grc
it grc
 
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
 
Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)
 
Integrated GRC
Integrated GRCIntegrated GRC
Integrated GRC
 
Risk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and ImplementationRisk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and Implementation
 
Governance Risk and Compliance - in Higher Education - Australia
Governance Risk and Compliance - in Higher Education - AustraliaGovernance Risk and Compliance - in Higher Education - Australia
Governance Risk and Compliance - in Higher Education - Australia
 
5 steps for better risk assessment
5 steps for better risk assessment5 steps for better risk assessment
5 steps for better risk assessment
 
Fix nix, inc
Fix nix, incFix nix, inc
Fix nix, inc
 
GRC 101 ISACA Bengaluru on 28th Dec 2013
GRC 101 ISACA Bengaluru on 28th Dec 2013GRC 101 ISACA Bengaluru on 28th Dec 2013
GRC 101 ISACA Bengaluru on 28th Dec 2013
 
Cloud Securiy: A Vendor Risk Management Perspective
Cloud Securiy: A Vendor Risk Management PerspectiveCloud Securiy: A Vendor Risk Management Perspective
Cloud Securiy: A Vendor Risk Management Perspective
 
Third Party Risk Management
Third Party Risk ManagementThird Party Risk Management
Third Party Risk Management
 
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment QuestionnairesThird-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
 
GRC Fundamentals
GRC FundamentalsGRC Fundamentals
GRC Fundamentals
 
6 implications of internal audit
6 implications of internal audit6 implications of internal audit
6 implications of internal audit
 

Viewers also liked

NTXISSACSC3 - Why Enterprise Information Management is the Key to GRC by Mika...
NTXISSACSC3 - Why Enterprise Information Management is the Key to GRC by Mika...NTXISSACSC3 - Why Enterprise Information Management is the Key to GRC by Mika...
NTXISSACSC3 - Why Enterprise Information Management is the Key to GRC by Mika...
North Texas Chapter of the ISSA
 
Expertool GRC Accelerator
Expertool GRC AcceleratorExpertool GRC Accelerator
Expertool GRC Accelerator
slideshareneilj
 
FulcrumWay - Ed. Webinar - Identify and Eliminate False Positives from your S...
FulcrumWay - Ed. Webinar - Identify and Eliminate False Positives from your S...FulcrumWay - Ed. Webinar - Identify and Eliminate False Positives from your S...
FulcrumWay - Ed. Webinar - Identify and Eliminate False Positives from your S...
FulcrumWay
 
Enterprise under attack dealing with security threats and compliance
Enterprise under attack dealing with security threats and complianceEnterprise under attack dealing with security threats and compliance
Enterprise under attack dealing with security threats and compliance
SPAN Infotech (India) Pvt Ltd
 
jComply grc_platform_v1.0
jComply grc_platform_v1.0jComply grc_platform_v1.0
jComply grc_platform_v1.0
jComply
 
DFlabs corporate profile 01-2013
DFlabs corporate profile 01-2013DFlabs corporate profile 01-2013
DFlabs corporate profile 01-2013
DFLABS SRL
 
Reciprocity_GRC Software Buyers Guide v5
Reciprocity_GRC Software Buyers Guide v5Reciprocity_GRC Software Buyers Guide v5
Reciprocity_GRC Software Buyers Guide v5
justinklooster
 
Software Evaluation Checklist
Software Evaluation ChecklistSoftware Evaluation Checklist
Software Evaluation Checklist
Salina Saharudin
 
The Evaluation Checklist
The Evaluation ChecklistThe Evaluation Checklist
The Evaluation Checklist
wmartz
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
Ceyeap
 
Corporate compliance powerpoint
Corporate compliance powerpointCorporate compliance powerpoint
Corporate compliance powerpoint
smcmanus3
 

Viewers also liked (11)

NTXISSACSC3 - Why Enterprise Information Management is the Key to GRC by Mika...
NTXISSACSC3 - Why Enterprise Information Management is the Key to GRC by Mika...NTXISSACSC3 - Why Enterprise Information Management is the Key to GRC by Mika...
NTXISSACSC3 - Why Enterprise Information Management is the Key to GRC by Mika...
 
Expertool GRC Accelerator
Expertool GRC AcceleratorExpertool GRC Accelerator
Expertool GRC Accelerator
 
FulcrumWay - Ed. Webinar - Identify and Eliminate False Positives from your S...
FulcrumWay - Ed. Webinar - Identify and Eliminate False Positives from your S...FulcrumWay - Ed. Webinar - Identify and Eliminate False Positives from your S...
FulcrumWay - Ed. Webinar - Identify and Eliminate False Positives from your S...
 
Enterprise under attack dealing with security threats and compliance
Enterprise under attack dealing with security threats and complianceEnterprise under attack dealing with security threats and compliance
Enterprise under attack dealing with security threats and compliance
 
jComply grc_platform_v1.0
jComply grc_platform_v1.0jComply grc_platform_v1.0
jComply grc_platform_v1.0
 
DFlabs corporate profile 01-2013
DFlabs corporate profile 01-2013DFlabs corporate profile 01-2013
DFlabs corporate profile 01-2013
 
Reciprocity_GRC Software Buyers Guide v5
Reciprocity_GRC Software Buyers Guide v5Reciprocity_GRC Software Buyers Guide v5
Reciprocity_GRC Software Buyers Guide v5
 
Software Evaluation Checklist
Software Evaluation ChecklistSoftware Evaluation Checklist
Software Evaluation Checklist
 
The Evaluation Checklist
The Evaluation ChecklistThe Evaluation Checklist
The Evaluation Checklist
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
 
Corporate compliance powerpoint
Corporate compliance powerpointCorporate compliance powerpoint
Corporate compliance powerpoint
 

Similar to CMLGroup - What is GRC?

Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear LLC
 
task 1
task 1task 1
Governance Risk Compliance Framework.pptx
Governance Risk Compliance Framework.pptxGovernance Risk Compliance Framework.pptx
Governance Risk Compliance Framework.pptx
Isorobot
 
Grc and is audit
Grc and is auditGrc and is audit
Grc and is audit
BIBEKCHAUDHARYBScHon
 
GRC Africa The Paradigm Shift (Technology and GRC)
GRC Africa   The Paradigm Shift (Technology and GRC)GRC Africa   The Paradigm Shift (Technology and GRC)
GRC Africa The Paradigm Shift (Technology and GRC)
Maganathin Veeraragaloo
 
Automated Regulatory Compliance Management
Automated Regulatory Compliance ManagementAutomated Regulatory Compliance Management
Automated Regulatory Compliance Management
Adeel159
 
Government and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP SystemsGovernment and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP Systems
Dan Aldridge, ERP Software Evangelist, LION
 
A systematic approach to pci compliance using rsa archer
A systematic approach to pci compliance using rsa archerA systematic approach to pci compliance using rsa archer
A systematic approach to pci compliance using rsa archer
Subhajit Bhuiya
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
Tuan Phan
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
Tri Phan
 
GRC
GRCGRC
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
Oracle
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...
Oracle
 
SLVA - Developing an IT GRC Strategy
SLVA - Developing an IT GRC StrategySLVA - Developing an IT GRC Strategy
SLVA - Developing an IT GRC Strategy
SLVA Information Security
 
Concept of Governance - Management of Operational Risk for IT Officers/Execut...
Concept of Governance - Management of Operational Risk for IT Officers/Execut...Concept of Governance - Management of Operational Risk for IT Officers/Execut...
Concept of Governance - Management of Operational Risk for IT Officers/Execut...
Amity University | FMS - DU | IMT | Stratford University | KKMI International Institute | AIMA | DTU
 
Internal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC StrategyInternal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC Strategy
David Fernandes
 
Advantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environmentAdvantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environment
IBM Analytics
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC Strategy
Cognizant
 
Paradigm 2020
Paradigm 2020Paradigm 2020
Paradigm 2020
Sanjeev K Sancheti
 
GRC Tools.pptx
GRC Tools.pptxGRC Tools.pptx
GRC Tools.pptx
RahulTripathi330262
 

Similar to CMLGroup - What is GRC? (20)

Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
task 1
task 1task 1
task 1
 
Governance Risk Compliance Framework.pptx
Governance Risk Compliance Framework.pptxGovernance Risk Compliance Framework.pptx
Governance Risk Compliance Framework.pptx
 
Grc and is audit
Grc and is auditGrc and is audit
Grc and is audit
 
GRC Africa The Paradigm Shift (Technology and GRC)
GRC Africa   The Paradigm Shift (Technology and GRC)GRC Africa   The Paradigm Shift (Technology and GRC)
GRC Africa The Paradigm Shift (Technology and GRC)
 
Automated Regulatory Compliance Management
Automated Regulatory Compliance ManagementAutomated Regulatory Compliance Management
Automated Regulatory Compliance Management
 
Government and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP SystemsGovernment and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP Systems
 
A systematic approach to pci compliance using rsa archer
A systematic approach to pci compliance using rsa archerA systematic approach to pci compliance using rsa archer
A systematic approach to pci compliance using rsa archer
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
GRC
GRCGRC
GRC
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...
 
SLVA - Developing an IT GRC Strategy
SLVA - Developing an IT GRC StrategySLVA - Developing an IT GRC Strategy
SLVA - Developing an IT GRC Strategy
 
Concept of Governance - Management of Operational Risk for IT Officers/Execut...
Concept of Governance - Management of Operational Risk for IT Officers/Execut...Concept of Governance - Management of Operational Risk for IT Officers/Execut...
Concept of Governance - Management of Operational Risk for IT Officers/Execut...
 
Internal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC StrategyInternal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC Strategy
 
Advantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environmentAdvantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environment
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC Strategy
 
Paradigm 2020
Paradigm 2020Paradigm 2020
Paradigm 2020
 
GRC Tools.pptx
GRC Tools.pptxGRC Tools.pptx
GRC Tools.pptx
 

Recently uploaded

Satta matka guessing Kalyan fxxjodi panna
Satta matka guessing Kalyan fxxjodi pannaSatta matka guessing Kalyan fxxjodi panna
Satta matka guessing Kalyan fxxjodi panna
➑➌➋➑➒➎➑➑➊➍
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
DefenceTech Meetup #1 - Lisbon, Portugal
DefenceTech Meetup #1 - Lisbon, PortugalDefenceTech Meetup #1 - Lisbon, Portugal
DefenceTech Meetup #1 - Lisbon, Portugal
Andre Marquet
 
一比一原版(毕业证)一桥大学毕业证如何办理
一比一原版(毕业证)一桥大学毕业证如何办理一比一原版(毕业证)一桥大学毕业证如何办理
一比一原版(毕业证)一桥大学毕业证如何办理
taqyea
 
TriStar Gold Corporate Presentation (Revised) - June 2024
TriStar Gold Corporate Presentation (Revised) - June 2024TriStar Gold Corporate Presentation (Revised) - June 2024
TriStar Gold Corporate Presentation (Revised) - June 2024
Adnet Communications
 
Intelligent Small Boat Security Solution - June 2024
Intelligent Small Boat Security Solution - June 2024Intelligent Small Boat Security Solution - June 2024
Intelligent Small Boat Security Solution - June 2024
Hector Del Castillo, CPM, CPMM
 
❣Call Girl Near Chennai 💯Call Us 🔝 7737669865 🔝💃Independent Chennai Escorts S...
❣Call Girl Near Chennai 💯Call Us 🔝 7737669865 🔝💃Independent Chennai Escorts S...❣Call Girl Near Chennai 💯Call Us 🔝 7737669865 🔝💃Independent Chennai Escorts S...
❣Call Girl Near Chennai 💯Call Us 🔝 7737669865 🔝💃Independent Chennai Escorts S...
kumarilali919
 
Satta matka DP boss matka Kalyan result India matka
Satta matka DP boss matka Kalyan result India matkaSatta matka DP boss matka Kalyan result India matka
Satta matka DP boss matka Kalyan result India matka
➑➌➋➑➒➎➑➑➊➍
 
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
➒➌➎➏➑➐➋➑➐➐ Satta Matta Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Satta Matta Matka Dpboss Matka Guessing Kalyan panel Chart➒➌➎➏➑➐➋➑➐➐ Satta Matta Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Satta Matta Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Satta Matka Kalyan Matka Satta Matka Guessing
Satta Matka Kalyan Matka Satta Matka GuessingSatta Matka Kalyan Matka Satta Matka Guessing
Satta Matka Kalyan Matka Satta Matka Guessing
DP Boss Satta Matka Kalyan Matka
 
Matka Result Kalyan chart Fix Matka 420
Matka Result  Kalyan chart Fix Matka 420Matka Result  Kalyan chart Fix Matka 420
Matka Result Kalyan chart Fix Matka 420
Matka Guessing ❼ʘ❷ʘ❻❻➃➆➆➀ Matka Result
 
Kanban Coaching Exchange with Dave White - Sample SDR Report
Kanban Coaching Exchange with Dave White - Sample SDR ReportKanban Coaching Exchange with Dave White - Sample SDR Report
Kanban Coaching Exchange with Dave White - Sample SDR Report
Helen Meek
 
➒➌➎➏➑➐➋➑➐➐ Satta Matka Dpboss Matka Guessing Indian Matka
➒➌➎➏➑➐➋➑➐➐ Satta Matka Dpboss Matka Guessing Indian Matka➒➌➎➏➑➐➋➑➐➐ Satta Matka Dpboss Matka Guessing Indian Matka
➒➌➎➏➑➐➋➑➐➐ Satta Matka Dpboss Matka Guessing Indian Matka
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
一比一原版(UCSC毕业证)加州大学圣克鲁兹分校毕业证如何办理
一比一原版(UCSC毕业证)加州大学圣克鲁兹分校毕业证如何办理一比一原版(UCSC毕业证)加州大学圣克鲁兹分校毕业证如何办理
一比一原版(UCSC毕业证)加州大学圣克鲁兹分校毕业证如何办理
taqyea
 
Askxx.com Complete Pitch Deck Course Online
Askxx.com Complete Pitch Deck Course OnlineAskxx.com Complete Pitch Deck Course Online
Askxx.com Complete Pitch Deck Course Online
AskXX.com
 
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Matka Live Time Bazar Panel Chart Milan.
Matka Live Time Bazar Panel Chart Milan.Matka Live Time Bazar Panel Chart Milan.
Matka Live Time Bazar Panel Chart Milan.
Matka Guessing ❼ʘ❷ʘ❻❻➃➆➆➀ Matka Result
 
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
The Key Summaries of Forum Gas 2024.pptx
The Key Summaries of Forum Gas 2024.pptxThe Key Summaries of Forum Gas 2024.pptx
The Key Summaries of Forum Gas 2024.pptx
Sampe Purba
 

Recently uploaded (20)

Satta matka guessing Kalyan fxxjodi panna
Satta matka guessing Kalyan fxxjodi pannaSatta matka guessing Kalyan fxxjodi panna
Satta matka guessing Kalyan fxxjodi panna
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
 
DefenceTech Meetup #1 - Lisbon, Portugal
DefenceTech Meetup #1 - Lisbon, PortugalDefenceTech Meetup #1 - Lisbon, Portugal
DefenceTech Meetup #1 - Lisbon, Portugal
 
一比一原版(毕业证)一桥大学毕业证如何办理
一比一原版(毕业证)一桥大学毕业证如何办理一比一原版(毕业证)一桥大学毕业证如何办理
一比一原版(毕业证)一桥大学毕业证如何办理
 
TriStar Gold Corporate Presentation (Revised) - June 2024
TriStar Gold Corporate Presentation (Revised) - June 2024TriStar Gold Corporate Presentation (Revised) - June 2024
TriStar Gold Corporate Presentation (Revised) - June 2024
 
Intelligent Small Boat Security Solution - June 2024
Intelligent Small Boat Security Solution - June 2024Intelligent Small Boat Security Solution - June 2024
Intelligent Small Boat Security Solution - June 2024
 
❣Call Girl Near Chennai 💯Call Us 🔝 7737669865 🔝💃Independent Chennai Escorts S...
❣Call Girl Near Chennai 💯Call Us 🔝 7737669865 🔝💃Independent Chennai Escorts S...❣Call Girl Near Chennai 💯Call Us 🔝 7737669865 🔝💃Independent Chennai Escorts S...
❣Call Girl Near Chennai 💯Call Us 🔝 7737669865 🔝💃Independent Chennai Escorts S...
 
Satta matka DP boss matka Kalyan result India matka
Satta matka DP boss matka Kalyan result India matkaSatta matka DP boss matka Kalyan result India matka
Satta matka DP boss matka Kalyan result India matka
 
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
 
➒➌➎➏➑➐➋➑➐➐ Satta Matta Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Satta Matta Matka Dpboss Matka Guessing Kalyan panel Chart➒➌➎➏➑➐➋➑➐➐ Satta Matta Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Satta Matta Matka Dpboss Matka Guessing Kalyan panel Chart
 
Satta Matka Kalyan Matka Satta Matka Guessing
Satta Matka Kalyan Matka Satta Matka GuessingSatta Matka Kalyan Matka Satta Matka Guessing
Satta Matka Kalyan Matka Satta Matka Guessing
 
Matka Result Kalyan chart Fix Matka 420
Matka Result  Kalyan chart Fix Matka 420Matka Result  Kalyan chart Fix Matka 420
Matka Result Kalyan chart Fix Matka 420
 
Kanban Coaching Exchange with Dave White - Sample SDR Report
Kanban Coaching Exchange with Dave White - Sample SDR ReportKanban Coaching Exchange with Dave White - Sample SDR Report
Kanban Coaching Exchange with Dave White - Sample SDR Report
 
➒➌➎➏➑➐➋➑➐➐ Satta Matka Dpboss Matka Guessing Indian Matka
➒➌➎➏➑➐➋➑➐➐ Satta Matka Dpboss Matka Guessing Indian Matka➒➌➎➏➑➐➋➑➐➐ Satta Matka Dpboss Matka Guessing Indian Matka
➒➌➎➏➑➐➋➑➐➐ Satta Matka Dpboss Matka Guessing Indian Matka
 
一比一原版(UCSC毕业证)加州大学圣克鲁兹分校毕业证如何办理
一比一原版(UCSC毕业证)加州大学圣克鲁兹分校毕业证如何办理一比一原版(UCSC毕业证)加州大学圣克鲁兹分校毕业证如何办理
一比一原版(UCSC毕业证)加州大学圣克鲁兹分校毕业证如何办理
 
Askxx.com Complete Pitch Deck Course Online
Askxx.com Complete Pitch Deck Course OnlineAskxx.com Complete Pitch Deck Course Online
Askxx.com Complete Pitch Deck Course Online
 
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
 
Matka Live Time Bazar Panel Chart Milan.
Matka Live Time Bazar Panel Chart Milan.Matka Live Time Bazar Panel Chart Milan.
Matka Live Time Bazar Panel Chart Milan.
 
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐ Indian Matka Dpboss Matka Guessing Kalyan panel Chart
 
The Key Summaries of Forum Gas 2024.pptx
The Key Summaries of Forum Gas 2024.pptxThe Key Summaries of Forum Gas 2024.pptx
The Key Summaries of Forum Gas 2024.pptx
 

CMLGroup - What is GRC?

  • 1. GRCaaS Governance Risk Compliance as a Service GRC Automation Simplified
  • 2. Agenda • How was GRC developed? • What exactly is GRC? • The role of GRC in ISMS • Impact of GRC • Types of GRC • The role IT-GRC in IT-RMC • IT-GRC Foundation • Why to deploy IT-GRC Management System?
  • 3. How was GRC developed? GRC framework was developed as a consequence of well-known public events such as Enron scandal in October 2001, eventually lead the bankruptcy of the Enron Corp. Followed by the dissolution of Arthur Andersen, one of the largest audit and accounting partnerships in the world In addition to begin the largest bankruptcy reorganization in American history at the time, Enron attributed as the biggest audit failure
  • 4. How was GRC developed? Because of the scandal, new regulations and legislation enacted to expand the accuracy of financial reporting for public companies One piece of legislation, Sarbanes-Oxley Act, increased penalties for destroying, altering, or fabricating records in federal investigations or for attempting to defraud shareholders The act also increased the accountability of auditing firms to remain unbiased and independent of their clients
  • 5. What is GRC GRC Definition Governance Risk Compliance is an integrated approach used by corporations to act in accordance with the guidelines set for each category GRC is not a single activity, but rather a firm-wide approach to achieving high standards in all three overlapping categories
  • 6. What is GRC IT-GRC specifics key capabilities • Controls and policy library • Policy distribution and response • IT Controls self-assessment and measurement • IT Asset repository • Remediation and exception management • Vendors Management • Reporting • Advanced IT risk evaluation and compliance dashboards
  • 7. The role of GRC The business impact • 70% to 80% of market value comes from hard-to-assess intangible assets such as brand equity, intellectual capital and goodwill • Organizations are especially vulnerable to incidents that may damage their reputations, oftentimes with unforeseen consequences
  • 8. The role of GRC From Ernst & Young survey of 137 Global Institutional Investors: • 82% will pay a premium for companies that demonstrate successful risk management • 61% will not invest where there is evidence of poor risk management • 41% would withdraw investment where there is a perceived lack of appropriate risk management
  • 9. IT-GRC in ISMS Information Security Management Systems Internal effectiveness Customer confidence External security risks Compliance & regulations ISMS ISMS overall management system based on a Risk approach to: Establish, Implement, Operate, Monitor, Review and Improve Information Security
  • 10. Impact of GRC • Emergence of new regulatory compliances • Alteration of corporate governance landscape • Organizations are held accountable for accuracy and integrity in their business operations • Effective and reliable governance and compliance procedures is the need of the hour
  • 11. Types of GRC eGRC IT-GRC Focus Enterprise Only IT Content supplied by Customer Prepopulated Deployment type Lengthy - large number of variables Short - Well defined framework Controls Financial Control & Labor Standards • Regulatory Compliance • Business Processes • Import and Export Laws • Health and Safety • Security • Infrastructure • and much more IT security systems and applications • Vulnerability • Configuration management • Change management • IT-Risk management • IT-Regulatory Compliance • and more Success rate Low - Due to complexity and lack of buying from key stakeholders Very high – Due to it focus and defined SOW, stakeholders support and measurable KPI and KRI
  • 12. Resetting IT-GRC definition at Gartner IT-GRC is essentially enterprise GRC functions focused on IT specific needs For the last two years, IT-GRC has started to bifurcate into: • IT-related GRC functions • Security operations functions
  • 14. The role of IT-GRC in IT-RMC IT-GRC specifics key capabilities  Controls and policy library  Policy distribution and response  IT Controls self-assessment and measurement  IT Asset repository  Remediation and exception management  Vendors Management  Reporting, Scorecards, Dashboard  Advanced IT risk evaluation and compliance dashboards
  • 15. Why GRC Step One - Define Policies and Compliance o Map Policies & Regulation to controls o Identify Assets and Vendors o Identify Risk Profile Step Two - Measure Test Controls o Create customized Assessments o Measure inherent Risk & Compliance o Measure Policy training effectiveness o Test Vendor Risk Step Three - Manage Manage Risk & Compliance o Create interactive real time GRC Dashboards for mobile devices o Demonstrate Compliance o Manage Incidents, Threats and Vulnerabilities GRC is a centralized and cohesive system which, incorporates: • Internal Audits • External Regulatory Compliance • Risk Management
  • 16. Why to deploy IT-GRC Management System? • Better management of workflow as compared to the hassle of using spreadsheets or auditors provided software • Because different groups in the organization are looking for audit and risk compliance management solutions • Effective management of compliances to avoid chaos, difficulties and confusion • Improves reporting and dashboarding • Holistic view of risk management and compliance activities • Supports rationalization of compliance and risk management activities across the platform
  • 17. CMLgroup GRCaaS Contact us today to discuss your IT-GRC requirements + 1 646 827-2291 www.cmlgroup.com Info@cmlgroup.com
  翻译: