60 likes | 221 Views
GRC Ninja controls governance and compliance the same way an accounting package controls finances…. Sector: financial services Focus: financial governance & compliance, data privacy – human resources. Allen O’Neill – Isolate Technologies www.grcninja.com.
E N D
GRCNinjacontrols governance and compliance the same way an accounting package controls finances… Sector: financial services Focus: financial governance & compliance, data privacy – human resources Allen O’Neill – Isolate Technologies www.grcninja.com Compliance in the cloud – lessons learned
Eating our own dog food… Issues: Data protection Security Territorial concerns “we sell compliance, so we’d better be compliant ….”
segment / risk / value Data types (sensitivity, value) Relevant regulation Customer Trust / acceptance Actual risk vs perceived Impact of breach on: Our business <-> Clients business Decision: Architect for catastrophe
Decisions taken Platform = Virtual Machine Cluster Portability (Cloud & LAN) Host in clients territory and reduce remote legal reach Scalable due to business model Balance cost & security 1 DB/File location per client Mitigates damage WHEN breach occurs Multi-factor authentication Data segmentation User/Pass & SSL strong Client certificates stronger YubiKey device strongest What to tell him?
www.grcninja.com @IsolateTech allen.oneill@isolate.ie Allen O’Neill – Isolate Technologies