Governance, Risk & Compliance - Management Commitment; Building a GRC Aware Culture.

Similar documents
NERC Staff Organization Chart Budget 2018

NERC Staff Organization Chart Budget 2019

NERC Staff Organization Chart Budget 2019

NERC Staff Organization Chart Budget 2017

NERC Staff Organization Chart Budget 2017

Oracle Buys Automated Applications Controls Leader LogicalApps

NERC Staff Organization Chart

BPS Suite and the OCEG Capability Model. Mapping the OCEG Capability Model to the BPS Suite s product capability.

Why GRC is important to you and your customers/prospects What do we mean by GRC? How does it relate to Oracle? Brian Gregory, ACA, EMEA GRC

IT Audit Process. Prof. Mike Romeu. January 30, IT Audit Process. Prof. Mike Romeu

"Charting the Course... Certified Information Systems Auditor (CISA) Course Summary

NERC Staff Organization Chart 2015 Budget

NERC Staff Organization Chart Budget

GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE TRENDS BY FCPAK ERIC KIMANI

ISACA. Certification Details for Certified in the Governance of Enterprise IT (CGEIT )

IT Audit Process Prof. Liang Yao Week Two IT Audit Function

354 & Index Board of Directors Responsibilities Audit Committee and Risk Committee Coordination, 244 Audit Committee Functions and Responsibilities, 2

Security and Privacy Governance Program Guidelines

Demystifying Governance, Risk, and Compliance (GRC) with 4 Simple Use Cases. Gen Fields Senior Solution Consultant, Federal Government ServiceNow

Copyright 2011 EMC Corporation. All rights reserved.

A Global Look at IT Audit Best Practices

<< Practice Test Demo - 2PassEasy >> Exam Questions CISM. Certified Information Security Manager.

Isaca EXAM - CISM. Certified Information Security Manager. Buy Full Product.

Table of Contents. Preface xvii PART ONE: FOUNDATIONS OF MODERN INTERNAL AUDITING

Exam4Tests. Latest exam questions & answers help you to pass IT exam test easily

IIA EXAM - IIA-CGAP. Certified Government Auditing Professional. Buy Full Product.

COURSE BROCHURE. COBIT5 FOUNDATION Training & Certification

Demystifying GRC. Abstract

Governance, Risk, and Compliance: A Practical Guide to Points of Entry

Improving Data Governance in Your Organization. Faire Co Regional Manger, Information Management Software, ASEAN

MNsure Privacy Program Strategic Plan FY

Exam Questions IIA-CGAP

TDWI Data Governance Fundamentals: Managing Data as an Asset

OVERVIEW BROCHURE GRC. When you have to be right

CISM Certified Information Security Manager

IT MANAGER PERMANENT SALARY SCALE: P07 (R ) Ref:AgriS042/2019 Information Technology Manager. Reporting to. Information Technology (IT)

COSO Enterprise Risk Management

ECCouncil EC-Council Certified CISO (CCISO) Download Full Version :

Uncovering the Risk of SAP Cyber Breaches

SAP security solutions Is your business protected?

Policies and Procedures Date: February 28, 2012

Implementation of a SAP GRC solution at a Swiss Mobile Network Operator. Andreas Eberhardt, Senior Consultant Barcelona,

Enterprise GRC Implementation

AT FIRST VIEW C U R R I C U L U M V I T A E. Diplom-Betriebswirt (FH) Peter Konrad. Executive Partner Senior Consultant

Aligning IT, Security and Risk Management Programs. Ahmed Qurram Baig, CISSP, CBCP, CRISC, CISM Information Security & GRC Expert

Risk: Security s New Compliance. Torsten George VP Worldwide Marketing and Products, Agiliance Professional Strategies - S23

INTELLIGENCE DRIVEN GRC FOR SECURITY

Improve your business performance

ROLE DESCRIPTION IT SPECIALIST

The CIA Challenge Exam. August 2018

Data Management and Security in the GDPR Era

ISSMP is in compliance with the stringent requirements of ANSI/ISO/IEC Standard

DIPLOMA COURSE IN INTERNAL AUDIT

Operationalizing Cybersecurity in Healthcare IT Security & Risk Management Study Quantitative and Qualitative Research Program Results

Ready, Willing & Able. Michael Cover, Manager, Blue Cross Blue Shield of Michigan

REPORT 2015/010 INTERNAL AUDIT DIVISION

MetricStream GRC Summit 2013: Case Study

Green Governance Growth

Turning Risk into Advantage

A New Cyber Defense Management Regulation. Ophir Zilbiger, CRISC, CISSP SECOZ CEO

The 10 Principles of Security in Modern Cloud Applications

High Performance Computing Environment for Research on Restricted Data. Dr. Erik Deumens Rob Adams Dr. Alin Dobra

OFFICE OF THE CIO MEMORIAL UNIVERSITY OF NEWFOUNDLAND A PRESENTATION FOR THE IM COMMUNITY

Information technology security and system integrity policy.

This document describes how to comply with your Hyperion license agreement.

Microsoft Security Management

Achieving effective risk management and continuous compliance with Deloitte and SAP

Governance, Risk and Controls (GRC) Internal audit driving quality organisations

Statement of Organization, Functions, and Delegations of Authority: Office of the

C32: GRC (Pro)(Con)Fusion Tools, Processes, and Pitfalls Jason Kobus, SVB Financial Group

GRC SURVEY RESULT Please indicate your profession

SAP: Speeding GRC Control Testing by 90% with SAP Solutions for GRC

Oracle Data Cloud ( ODC ) Inbound Security Policies

Bringing cyber to the Board of Directors & C-level and keeping it there. Dirk Lybaert, Proximus September 9 th 2016

POSITION DESCRIPTION

The Future of IT Internal Controls Automation: A Game Changer. January Risk Advisory

Cybersecurity: Considerations for Internal Audit. Gina Gondron Senior Manager Frazier & Deeter Geek Week August 10, 2016

Healthcare Security Success Story

ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION

Auditing and Monitoring in an Effective Institutional Compliance Program

Saving Time Amanda McPherson, CCBIA Vice President/Internal Audit Manager Colorado East Bank & Trust

Overview. Business value

KENYA SCHOOL OF GOVERNMENT EMPLOYMENT OPORTUNITY (EXTERNAL ADVERTISEMENT)

MEETING: DATE: TYPE OF ACTION: STAFF CONTACT: PHONE:

locuz.com SOC Services

SOLUTION BRIEF RSA ARCHER IT & SECURITY RISK MANAGEMENT

STRATEGIC PLAN

Managing Privacy Risk & Compliance in Financial Services. Brett Hamilton Advisory Solutions Consultant ServiceNow

Passguide CISM 631q. Number: CISM Passing Score: 800 Time Limit: 120 min File Version: Isaca CISM

Table of Contents. Preface xiii PART I: IT GOVERNANCE CONCEPTS. Chapter 1: Importance of IT Governance for All Enterprises 3

Heading Text. Manage your Organization s Governance, Risks, and Compliance Requirements and Transform your Business Potential with SAP GRC

Birmingham Community Healthcare NHS Foundation Trust. 2017/17 Data Security and Protection Requirements March 2018

The Deloitte-NASCIO Cybersecurity Study Insights from

Pave the way: Build a value driven SAP GRC roadmap March 2015

GOVERNANCE, RISK & COMPLIANCE CPD FOR MEMBERS IN COMMERCE & INDUSTRY AUGUST 2018

Securing Your Secured Data

1. Management Information Systems/ MIS211 (3 Crh.) pre. CS104+ BA Programming & Data Structures / MIS 213 (3 Cr.h.) pre CS104 (Computer Skills)

Access Governance in a Cloudy Environment. Nabeel Nizar VP Worldwide Solutions

Hong Kong Accountability Benchmarking Micro-Study. Nymity Accountability Workshop 10 June 2015, Office of the PCPD, Hong Kong

What is the Value of IT Certification?

Transcription:

Governance, Risk & Compliance - Management Commitment; Building a GRC Aware Culture. Natasak Rodjanapiches, Managing Director, Oracle Corporation (Thailand) 1

Governance, Risk, and Compliance (GRC) Natasak Rodjanapiches Regional Managing Director - ASEAN 2

3

The Finance Imperative VISIBILITY Deliver Better Business Information CONTROL Attain Sustainable Compliance EFFICIENCY Improve Business Processes at the Lowest Cost 4

กระบวนการของแนวค ด GRC Recommended Process Executed by 1. Governance (G) The board of director, corporate secretary and governance professionals including board management 2. Strategy Chief Executive Officer (CEO) or c-suite 3. Risk Management (R) Chief Risk Officer (CRO), business line and other executives 4. Audit Chief Audit Executives, internal audit, audit committee and external auditors 5. Legal The general counsel and legal staff 6. Compliance (C) The general conunsel, chief compliance and ethics officer, compliance professionals and other legal staff 7. Information Technology Chief Information Officer (CIO), privacy officer and /or security officer 8. Ethics & Corporate Social Responsibility Chief Ethics Officer and Chief Responsibility Officer 9. Quality Management Quality professionals throughout the organization 10. Human Capital & Culture Human resource professionals and organizational design and development professionals 5

Oracle Solutions for GRC Access Policy KPIs Documentation & Reporting Identity Mgmt SOD & Access GRC Reporting & Analytics GRC Infrastructure Controls Data Security Risk & Control KPIs GRC Process Management Management Assessments GRC Application Controls Application Configuration Systems Mgmt Certification KPIs Issues & Remediation Transaction Monitoring Records & Content Mgmt Digital Rights Purpose-built business solutions for key industries and GRC initiatives Best-in-class GRC core solutions to support all mandates and regulations Pre-integrated with Oracle applications and technology, supports heterogeneous environments Custom or Legacy Applications 6

Oracle Delivers Control Manage and Control Risk Deliver unified view of financial results, processes, risks, and underlying internal controls 7

Oracle Internal Controls Manager Attain Sustainable Compliance More Efficient Internal Control Testing Higher Certainty in Your Risk Assessment Lower External Audit Verification Costs 8

Oracle Internal Controls Manager Streamline Internal Control and Risk Management Define and Manage the Control Environment Associate processes to organizations Process documentation and approval Segregation of duties Plan and Control Audit Operations Risk assessment Audit projects Findings and remediations Streamline the Certification Process Business process certification Financial statement certification 9

Oracle s Governance, Risk and Compliance Solution Corporate Performance Management Planning & Budgeting Financial Consolidation Balanced Scorecard Profitability Manager Portal Operational Analytics Risk and Control Management GRC Manager PSFT ICE Reveleus Policy Management ilearning, isurvey Policies and Procedures Data Aggregation & Reporting BPEL Business Process Management BAM Identity & Role Administration ERP Application Identity Manager Tutor UPK Identity Management Identity Audit & Compliance Content and Records Mgmt Universal Content Management Access Manager Information Rights Mgmt Identity Federation Enterprise Manager Audit Vault PII Security Vault Data Protection Infrastructure Security Directory Security Database Vault Database Security Data Mining Web Service Security J2EE Security 10

11

Governance, Risk & Compliance - Management Commitment; Building a GRC Aware Culture. Natasak Rodjanapiches, Managing Director, Oracle Corporation (Thailand) 12