<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Psoenen&#039;s Blog</title>
	<atom:link href="http://psoenen.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://psoenen.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Fri, 01 Oct 2010 22:43:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='psoenen.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Psoenen&#039;s Blog</title>
		<link>http://psoenen.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://psoenen.wordpress.com/osd.xml" title="Psoenen&#039;s Blog" />
	<atom:link rel='hub' href='http://psoenen.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Cloud computing : Governance and security?</title>
		<link>http://psoenen.wordpress.com/2010/10/01/cloud-computing-governance-and-security/</link>
		<comments>http://psoenen.wordpress.com/2010/10/01/cloud-computing-governance-and-security/#comments</comments>
		<pubDate>Fri, 01 Oct 2010 22:36:34 +0000</pubDate>
		<dc:creator>psoenen</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Governance]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://psoenen.wordpress.com/?p=20</guid>
		<description><![CDATA[Do you consider moving into the cloud? Cloud customers need assurance that providers are following sound security practices. The importance of the governance and risk management issues related with the move of assets into the cloud computing should be clearly understood. The promise of the Cloud Cloud computing is a on-demand service model for IT [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=20&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div>Do you consider moving into the cloud? Cloud customers need assurance that providers are following sound security practices. The importance of the governance and risk management issues related with the move of assets into the cloud computing should be clearly understood.</div>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr>
<td>
<h2>The promise of the Cloud</h2>
<p>Cloud computing is a on-demand service model for IT provision, often based on virtualisation and distributed computing technologies.</p>
<h3>The attractiveness of Cloud Computing</h3>
<p>By moving IT services to the Cloud, enterprises can take advantage of using services in an on demand-model. The infrastructure costs are reduced and services are paid on an subscription or pay-per-use basis. The Cloud offers a way to extend IT&#8217;s existing capabilities on the fly without investing in new infrastructure, training new personnel, or licensing new software.</p>
<h3>The Cloud service delivery models</h3>
<p>Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.</p>
<div><img longdesc="Cloud models" src="http://www.qualified-audit-partners.be/user_images/Articles/Cloud_Models.jpg" border="0" alt="Cloud models" width="500" height="212" /></div>
<div><strong> </strong></div>
<div><strong>1. SaaS &#8211; Software as a Service</strong><strong></strong><strong> </p>
<p></strong></p>
<blockquote style="margin-right:0;">
<div>SaaS delivers provider&#8217;s applications through the browser to thousands of customers using a multitenant architecture, i.e. a single instance of the software runs on a server, serving multiple client organisations. The service providers maintain and govern the software, data, and underlying infrastructure. Examples include online word processing and spreadsheet tools, CRM services and web content delivery services.</div>
<div>Sample offerings are Salesforce CRM, Google Docs, etc.</div>
</blockquote>
<p><strong>2. PaaS &#8211; Platform as a Service</strong></p>
<blockquote style="margin-right:0;">
<div>PaaS offers the capability to deploy on the cloud infrastructure customer-created or acquired applications using tools supported by the provider. The service providers maintain and govern the application environments, server instances, as well as the underlying infrastructure.</div>
<div>Examples are Microsoft Azure, Force and Google App engine.</div>
</blockquote>
<p><strong>3. IaaS &#8211; Infrastructure as a Service</strong></p>
<blockquote style="margin-right:0;">
<div>IaaS offers the ability to deploy operating systems and applications on computing resources (processing, storage and networks) provided by a third party. The customers deploy and manage assets, including operating systems and applications, on leased or rented server instances, while the service providers own and govern the underlying infrastructure.</div>
<div>Examples include Amazon EC2 and S3, Terremark Enterprise Cloud, Windows Live Skydrive and Rackspace Cloud.</div>
</blockquote>
<h3>Cloud Computing Deployment Models</h3>
<p>There are three primary cloud deployment models and a hybrid model:</p>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr style="background-color:#000099;">
<td style="width:70px;height:19px;"><span style="color:#ffffff;"><strong>Deployment Model</strong></span></td>
<td><span style="color:#ffffff;"><strong>Description of the Cloud Infrastructure</strong></span></td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Private Cloud</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">An <em>internal</em> cloud emulates cloud computing on private networks:</div>
<div style="text-align:justify;margin-left:-15px;" dir="ltr">
<ul>
<li>Operated solely for an organisation;</li>
<li>May be managed by the organisation or a third party;</li>
<li>May exist on-premise or off-premise;</li>
<li>End-to-end control;</li>
<li>Dedicated resources.</li>
</ul>
</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Community Cloud</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">A <em>community</em> cloud may be established where several organisations have similar requirements and seek to share infrastructure so as to realise benefits of cloud computing:</div>
<div style="text-align:justify;margin-left:-15px;" dir="ltr">
<ul>
<li>Shared by several organisations;</li>
<li>Supports a specific community that has shared mission or interest;</li>
<li>May be managed by the organisations or a third party;</li>
<li>May reside on-premise or off-premise.</li>
</ul>
</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Public Cloud</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr"><em>External</em> or <em>multi-tenant</em> cloud describes the cloud computing in the traditional mainstream sense, whereby resources are dynamically provisioned over the Internet, via web services:</div>
<div style="text-align:justify;margin-left:-15px;" dir="ltr">
<ul>
<li>Made available to the general public or a large industry group;</li>
<li>Owned by an organisation selling cloud services;</li>
<li>Common policies;</li>
<li>Shared resources and multi-tenant .</li>
</ul>
</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Hybrid Cloud</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">A composition of two or more clouds (private, community or public) that remain unique entities but are bound together by standardised or proprietary technology that enables data and application portability.</div>
</td>
</tr>
</tbody>
</table>
<h3>Benefits</h3>
<p>Although financial savings may be attractive, the real opportunities are to streamline the business processes and to increase the innovation. Instead of managing and scaling infrastructures, the organisations can focus on their core business.</p>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr style="background-color:#000099;">
<td style="height:19px;"><strong>Key benefits</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Cost</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">The cloud offers enterprises the option of scalability without the serious financial commitments required for infrastructure purchase and maintenance. The upfront capital expenditure with cloud services is low. Services and storage are available on demand and are priced as a pay-as-you-go service.</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Immediacy</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">The provision and utilisation of services may be achieved in days compared to the weeks or months required for traditional IT projects.</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Availability</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">Cloud providers have the infrastructure and bandwidth to accommodate business requirements for high speed access, storage and applications.</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Scalability</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">Cloud services offer increased flexibility and scalability for evolving IT needs. Provisioning and implementation are done on demand, allowing for traffic spikes.</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Business focus</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">The reallocation of information management operational activities to the cloud offers businesses a unique opportunity to focus efforts on innovation and research and development.</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Resiliency</span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">Cloud providers have mirrored solutions that can be utilised in a disaster scenario as well as for load-balancing traffic.</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;height:20px;"><span style="color:black;">Mobility </span></td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:5px;margin-right:5px;" dir="ltr">Employees can access information wherever they are, rather than having to remain at their desks.</div>
</td>
</tr>
</tbody>
</table>
<h2>Governance and security</h2>
<h3>Security in the Cloud ?</h3>
<p>When switching to the cloud, the creation of a security plan should be a first consideration. Security breaches can be the direct cause of service interruptions and can contribute to lower service levels. Also, data theft resulting from a security breach could result in a real or perceived breach of customers’ trust in your organisation.</p>
<p>The customers should make buying their choices on the basis of the reputation for confidentiality, integrity and resilience, and the security services offered by a provider. This will drive the cloud providers to improve their security practices and also compete on security.</p>
<p>The following table gives an overview of the major control objectives and highlight some potential risks and issues related to the use of cloud solutions.</p>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr style="background-color:#000099;">
<td style="height:19px;"><strong>Criteria</strong></td>
<td><span style="color:#ffffff;"><strong>Objectives</strong></span></td>
<td><strong><strong>Risks and issues</strong></strong></td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Governance</span></td>
<td style="background-color:gainsboro;">Governance functions are established to ensure effective and sustainable management processes that result in transparency of business decisions, clear lines of responsibility, information security in alignment with regulatory and customer organisation standards and accountability.</td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:0;margin-right:0;" dir="ltr">How to govern the cloud: which management and monitoring processes should be implemented, which roles and responsibilities, which KPI’s?</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Risk management</span></td>
<td style="background-color:gainsboro;">Risk management procedures are implemented to evaluate inherent risks within the cloud computing model, identify appropriate control mechanisms, and ensure that residual risk is within acceptable levels.  The information risk management is integrated into the organisations Enterprise Risk Management (ERM) framework.</td>
<td style="background-color:gainsboro;">How to govern and manage enterprise risk: how can the user assess risks of a cloud provider?</td>
</tr>
<tr>
<td style="background-color:darkgray;" rowspan="5"><span style="color:black;">Compliance</span></td>
<td style="background-color:gainsboro;">Contractual obligations: Establish agreements and procedures to ensure contractual obligations are satisfied, and these obligations address the compliance requirements.  The use of cloud computing should not violate customer compliance agreements.</td>
<td style="background-color:gainsboro;">What is the legal, financial and information security in the contractual agreements?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">Legal issues relating to financial, jurisdictional and contractual requirements are addressed to protect both parties.</td>
<td style="background-color:gainsboro;">Regulatory and legislative compliance: how will the cloud affect your ability to comply with regulatory requirements such as SOX, GLBA, HPPA, PCI?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">The storage of personal data in the cloud should be compliant with the data privacy regulations.</td>
<td style="background-color:gainsboro;">Disclosure laws: Physical location dictates jurisdiction and legal obligation. Country laws governing personally identifiable information (PII) vary greatly.</td>
</tr>
<tr>
<td style="background-color:gainsboro;" rowspan="2">The right to audit is clearly defined and satisfies the assurance requirements of the customer’s board of directors, audit charter, external auditors and any regulators jurisdiction over the customer</td>
<td style="background-color:gainsboro;">Auditability: who can investigate data?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">If a legal investigation is required, namely because of illegal activity, can the provider support the customer to do the investigation?</td>
</tr>
<tr>
<td style="background-color:darkgray;" rowspan="2"><span style="color:black;">Application requirements </span></td>
<td style="background-color:gainsboro;" rowspan="2">For SaaS implementations, the applications should contain the appropriate functionality and processing controls required by the business.</td>
<td style="background-color:gainsboro;">Do the applications satisfy the functional, financial and operational requirements?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">Do the applications contain the processing controls required by the control policies?</td>
</tr>
<tr>
<td style="background-color:darkgray;" rowspan="2"><span style="color:black;">Asset management </span></td>
<td style="background-color:gainsboro;">Applications are developed with an understanding of the interdependencies inherent in cloud applications, based on risk analysis and design of configuration management and provisioning process that will withstand changing application architectures.</td>
<td style="background-color:gainsboro;">Difficulty to integrate multiple applications, namely with in-house IT</td>
</tr>
<tr>
<td style="background-color:gainsboro;">Planning for migration of data is required to reduce operational and financial risks at the end of contract.</td>
<td style="background-color:gainsboro;">
<div style="text-align:justify;margin-left:0;margin-right:0;" dir="ltr">Provider dependency: loss of control over systems and eventually data; how to ensure data portability and interoperability?</div>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Service management</span></td>
<td style="background-color:gainsboro;">Ensure that services provided by third parties meet business requirements through effective third-party management processes.</td>
<td style="background-color:gainsboro;">Does the service provider align its operations with the customer service requirements?</td>
</tr>
<tr>
<td style="background-color:darkgray;" rowspan="3"><span style="color:black;">Confidentiality</span></td>
<td style="background-color:gainsboro;">Data are securely transmitted and maintained to prevent unauthorised access and modification.</td>
<td style="background-color:gainsboro;">User access: how is data access ensured and controlled; who at the provider has access to data?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">Data are securely protected against unauthorised access, eventually through encryption, and separation of duties exists between key managers and the hosting organisation.</td>
<td style="background-color:gainsboro;">Data segregation: how to ensure that customers and competition don&#8217;t access data? How to ensure intrusion detection?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">The customers remains the only owner of his data.</td>
<td style="background-color:gainsboro;">Data ownership: who owns the data in the cloud?</td>
</tr>
<tr>
<td style="background-color:darkgray;" rowspan="2"><span style="color:black;">Integrity</span></td>
<td style="background-color:gainsboro;">Identity processes assure only authorised users and processes has access to the data and the resources, user activities can be audited and the customer has control over access management.</td>
<td style="background-color:gainsboro;">Data corruption: who can modify the data?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">Cross-contamination with other customer environments has to be avoided.</td>
<td style="background-color:gainsboro;">How to prevent against malware and security vulnerabilities?</td>
</tr>
<tr>
<td style="background-color:darkgray;" rowspan="3"><span style="color:black;">Availability</span></td>
<td style="background-color:gainsboro;" rowspan="3">An effective continuous service process minimises the probability and impact of a major IT service interruption on key business functions and processes.</td>
<td style="background-color:gainsboro;">Service reliability: What about the availability issues of Internet connectivity or system outages?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">Long term viability: And what in case the provider fails?</td>
</tr>
<tr>
<td style="background-color:gainsboro;">Recovery: Is data safeguarded?</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;">Incident management</span></td>
<td style="background-color:gainsboro;">Incident notifications, responses, remediation are documented, address the risk, are escalated as necessary and are formally closed.</td>
<td style="background-color:gainsboro;">Are incident detection, response, notification and remediation adequately managed?</td>
</tr>
</tbody>
</table>
<h3>Governance</h3>
<div>
<p>A port of the cost savings must be invested into increased scrutiny of the security capabilities of the provider, the application of security controls and ongoing detailed assessments and audits, to ensure requirements are continuously met.</p>
<p>Organisations should view cloud services and security as supply chain security issues. This means examining and assessing the provider’s supply chain (service provider relationships and dependencies), to the extent possible. </p>
<p>Information security governance should rely on cooperation between customers and providers to achieve agreed-upon goals which support the business mission and the information security requirements. The service model should adjust the defined roles and responsibilities in collaborative information security governance and risk management, while the deployment model should define the accountabilities and expectations.</p>
</div>
<div>User organisations should include review of specific information security governance structures and processes, as well as specific security controls, as part of their due diligence for prospective provider organisations. The provider’s security governance processes and capabilities should be assessed for sufficiency, maturity, and consistency with the user’s information security management processes. The assessment of the provider&#8217;s information security, risk management and compliance structures and processes should cover:</div>
<ul>
<li>Request clear documentation on how the facility and services are assessed for risk and audited for control weaknesses, the frequency of assessments, and how control weaknesses are mitigated in a timely manner.</li>
<li>Require definition of what the provider considers critical service and information security success factors, key performance indicators, and how these are measured relative to IT Service and Information Security Management.</li>
<li>Review the provider’s legal, regulatory, industry, and contractual requirements capture, assessment, and communication processes for comprehensiveness.</li>
<li>Perform full contract or terms-of-use due diligence to determine roles, responsibilities, and accountability. Ensure legal review, including an assessment of the enforceability of local contract provisions and laws in foreign or out-of-state jurisdictions.</li>
<li>Determine whether due diligence requirements encompass all material aspects of the cloud provider relationship, such as the provider’s financial condition, reputation (e.g., reference checks), controls, key personnel, disaster recovery plans and tests, insurance, communications capabilities, and use of subcontractors.</li>
</ul>
<p>The Service Level Agreement (SLA) is one of the most effective tools the organisation can use to ensure adequate protection of information entrusted to the cloud. The customers can specify which control frameworks will be utilised and describe the expectation of an external, third-party audit. Clear expectations regarding the handling, usage, storage and availability of information must be articulated in the SLA. Additionally, requirements for business continuity and disaster recovery should also be communicated in the agreement.</p>
<div>
<p>Metrics and standards for measuring performance and effectiveness of information security management should be established prior to moving into the cloud. Security metrics and standards, especially those relating to legal and compliance requirements, should be included in any Service Level Agreements and contracts.</p>
<p>The use of standards and frameworks will help businesses gain assurance around their cloud computing supplier’s internal controls and security. These standards and metrics should be documented, demonstrable and auditable.</p>
</div>
<div>
<p>Patrick Soenen | <a href="mailto:p.soenen@qap.eu" target="_blank">p.soenen[at]qap.eu</a> ♦ Jean-Pierre Palante | <a href="mailto:jp.palante@qap.eu" target="_blank">jp.palante[at]qap.eu</a></p>
</div>
</div>
<p> </td>
</tr>
</tbody>
</table>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/psoenen.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/psoenen.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/psoenen.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/psoenen.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/psoenen.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/psoenen.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/psoenen.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/psoenen.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/psoenen.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/psoenen.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/psoenen.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/psoenen.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/psoenen.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/psoenen.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=20&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://psoenen.wordpress.com/2010/10/01/cloud-computing-governance-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/01af6e578985a0862f33731a56d86afc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">psoenen</media:title>
		</media:content>

		<media:content url="http://www.qualified-audit-partners.be/user_images/Articles/Cloud_Models.jpg" medium="image">
			<media:title type="html">Cloud models</media:title>
		</media:content>
	</item>
		<item>
		<title>Protecting the privacy of personal information</title>
		<link>http://psoenen.wordpress.com/2010/10/01/protecting-the-privacy-of-personal-information/</link>
		<comments>http://psoenen.wordpress.com/2010/10/01/protecting-the-privacy-of-personal-information/#comments</comments>
		<pubDate>Fri, 01 Oct 2010 22:34:26 +0000</pubDate>
		<dc:creator>psoenen</dc:creator>
				<category><![CDATA[Data privacy]]></category>
		<category><![CDATA[Governance]]></category>

		<guid isPermaLink="false">http://psoenen.wordpress.com/?p=18</guid>
		<description><![CDATA[One of the many challenging risk management issues faced by organisations today is protecting the privacy of customers’ and employees’ personal information. When privacy is well managed, organisations earn the trust of their customers, employees, and other stakeholders. When it’s poorly managed, trust and confidence can quickly erode. And today, boards and audit committees want [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=18&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One of the many challenging risk management issues faced by organisations today is protecting the privacy of customers’ and employees’ personal information. When privacy is well managed, organisations earn the trust of their customers, employees, and other stakeholders. When it’s poorly managed, trust and confidence can quickly erode. And today, boards and audit committees want assurance around the organisation’s processes that protect private information.</p>
<p>Many countries have adopted nationwide privacy legislation governing the use of personal information, as well as the export of this information across borders. For businesses to operate effectively in this environment, they need to understand and comply with these privacy laws. Recent incidents of identity theft, mismanagement of personal information, and violation of privacy principles have increased regulatory and consumer pressure on organisations to develop appropriate controls in relation to privacy, data management, and information security.</p>
<div>
<h2>What is privacy</h2>
</div>
<p>The American Institute of Certified Public Accountants (AICPA) defines privacy as “<em>the rights and obligations of individuals and organisations with respect to the collection, use, disclosure, and retention of personal information</em>”.</p>
<p>The European Data Directive 95/46/EC requests that “Member States shall protect the fundamental rights and freedoms of natural persons, and in particular their right to privacy with respect to the processing of personal data.” .</p>
<p>In today’s business context, privacy often refers to the privacy of personal information about an individual and the individual’s ability to:</p>
<ul>
<li>Know how his or her personal information is handled;</li>
<li>Control the information collected;</li>
<li>Control what the information is used for;</li>
<li>Control who has access to the information;</li>
<li>Amend, change, and delete the information.</li>
</ul>
<div>
<h3>Personal information</h3>
</div>
<p>Personal information is data that can be linked to or used to identify an individual either directly or indirectly. Examples of personal information are:</p>
<ul>
<li>Person&#8217;s name;</li>
<li>Home address;</li>
<li>Pictures;</li>
<li>Telephone numbers (even a professional telephone number);</li>
<li>Identifiers such as Social Security, social insurance, passport, or account numbers;</li>
<li>Bank account numbers;</li>
<li>e-mail addresses;</li>
<li>Fingerprints;</li>
<li>Physical characteristics;</li>
<li>Credit records;</li>
<li>Consumer purchase history;</li>
<li>Employee files.</li>
</ul>
<div>
<h3>Sensitive information</h3>
</div>
<p>Sensitive personal information requires an extra level of protection and a higher duty of care:</p>
<ul>
<li>
<div>Medical records;</div>
</li>
<li>
<div>Financial information;</div>
</li>
<li>
<div>Racial or ethnic origin;</div>
</li>
<li>
<div>Political opinions;</div>
</li>
<li>
<div>Religious or philosophical beliefs;</div>
</li>
<li>
<div>Trade union membership;</div>
</li>
<li>
<div>Information related to offenses or criminal.</div>
</li>
</ul>
<div>
<h3>Non-personal information</h3>
</div>
<p>Anonymised information about people cannot be associated with specific individuals. This includes statistical or summarised personal information for which the identity of the individual is unknown or linkage to the individual has been removed.</p>
<div>
<h2>The benefits of good privacy management</h2>
</div>
<p>Good privacy governance involves identifying significant risks to the organisation, such as a potential misuse, leak, or loss of personal information. It also implies ensuring appropriate controls are in place to mitigate the privacy risks.</p>
<p>For businesses, the benefits of good privacy controls include:</p>
<ul>
<li>
<div>Protecting the organisation’s public image and brand;</div>
</li>
<li>
<div>Protecting valuable data on the organisation’s customers and employees;</div>
</li>
<li>
<div>Complying with applicable privacy laws and regulations;</div>
</li>
<li>
<div>Enhancing credibility and promoting confidence.</div>
</li>
</ul>
<p>For public-sector and non-profit organisations, the additional benefits of good privacy controls include:</p>
<ul>
<li>
<div>Maintaining trust with citizens and noncitizens;</div>
</li>
<li>
<div>Sustaining relationships with donors of non-profit organisations by respecting the privacy of their activities.</div>
</li>
</ul>
<h2>The Privacy Challenge</h2>
<p><img longdesc="QAP Data Privacy Management" src="http://www.qualified-audit-partners.be/user_images/Articles/QAP_DataPrivacy.jpg" border="0" alt="QAP Data Privacy" width="128" height="100" align="right" />Normally organisations recognise the need for implementing good privacy practices. However, the challenge is sustaining the privacy program. With the proliferation of data management technology, organisations have difficulty identifying where this data is stored, how it is protected, who has access to it, and how it is securely disposed. In addition, accountability and responsibility for maintaining the privacy practices is not always clearly assigned within the organisation.</p>
<h3>Privacy regulations</h3>
<p>Multiple regulations have been developed by various countries and organisations. </p>
<table border="2" cellspacing="2" cellpadding="2" rules="all">
<tbody>
<tr style="background-color:#000099;">
<td><span style="color:#ffffff;"><strong>Year</strong></span></td>
<td><span style="color:#ffffff;"><strong>Regulation</strong></span></td>
</tr>
<tr>
<td bgcolor="gainsboro">1980</td>
<td bgcolor="gainsboro">The OECD Council’s Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data was created to establish a common ground for free transborder data flow among the 24 OECD members</td>
</tr>
<tr>
<td bgcolor="gainsboro">1984/1998</td>
<td bgcolor="gainsboro">The UK Data Protection Acts</td>
</tr>
<tr>
<td bgcolor="gainsboro">1990</td>
<td bgcolor="gainsboro">The UN General Assembly issued its human rights based Guidelines Concerning Computerised Personal Data Files, which member states should take into account when implementing national data protection legislation</td>
</tr>
<tr>
<td bgcolor="gainsboro">1995</td>
<td bgcolor="gainsboro">The European Data Protection Directive 95/46/CE, on the Protection of Individuals with Regard to the Processing of Personal Data, has been translated in Belgian law</td>
</tr>
<tr>
<td bgcolor="gainsboro">1996</td>
<td bgcolor="gainsboro">The Canadian Standards Association Model Code for the Protection of Personal Information, now incorporated into national law (PIPEDA)</td>
</tr>
<tr>
<td bgcolor="gainsboro">1997</td>
<td bgcolor="gainsboro">The European Distance selling Directive 97/7/CE</td>
</tr>
<tr>
<td bgcolor="gainsboro">1997</td>
<td bgcolor="gainsboro">The Framework Data Protection Directive 97/66/CE, protecting privacy in telecommunications</td>
</tr>
<tr>
<td bgcolor="gainsboro">2000</td>
<td bgcolor="gainsboro">Standards Australia has developed AS 2805.9-2000: Electronic Funds Transfer – Privacy of Communications, which specifies methods of protecting from disclosure the information contained in electronic messages</td>
</tr>
<tr>
<td bgcolor="gainsboro">2002</td>
<td bgcolor="gainsboro">The European ePrivacy Directive 2002/58/CE, establishing rules for online marketing</td>
</tr>
<tr>
<td bgcolor="gainsboro">2004</td>
<td bgcolor="gainsboro">The APEC Privacy Framework (consistent with the core values of the OECD guidelines) was developed and intended to provide guidance and direction to businesses in APEC economies on common privacy issues and the impact these issues have on the way businesses are conducted</td>
</tr>
<tr>
<td bgcolor="gainsboro">2006</td>
<td bgcolor="gainsboro">The European Data Retention Directive 2006/24/CE, extending data privacy to Internet and e-Mail</td>
</tr>
</tbody>
</table>
<h3>The Commission for the Protection of Privacy (CPP)</h3>
<p>The Commission for the Protection of Privacy (CPP), known as Belgian Privacy Commission, is an independent authority ensuring the protection of privacy during the processing of personal data. The Commission recognises the information society&#8217;s need to collect and process personal data for societal and economic developments and compares societal and economic needs with this fundamental right in order to come to decisions and privacy safeguards reconciling both elements. The Commission realises that any personal data processing operation implies risks for privacy protection. It consequently stresses the importance of informing data subjects as well as processors about these risks, and of integrating safeguards, particularly relating to information security. Moreover, it focuses on the importance of the use of technologies in personal data processing for more well-being and welfare for citizens in our current society.</p>
<h2>Processing of privacy data</h2>
<h3>Personal data</h3>
<p>A data processing operation starts with the collection of data. Before the data is collected, however, the controller has to notify the processing to the Commission. The data has to be collected fairly and therefore transparently. The controller collecting personal data has to inform the person about the processing. The controller has to:</p>
<ul>
<li>
<div>clarify why he wishes to obtain your personal data;</div>
</li>
<li>
<div>transmit his contact details to you;</div>
</li>
<li>
<div>let you know who your data will be disclosed to;</div>
</li>
<li>
<div>inform you about your right to access and rectify your data;</div>
</li>
<li>
<div>mention that you may object free of charge to the use of your data for direct marketing, e.g. commercial actions.</div>
</li>
</ul>
<h3>Sensitive data</h3>
<p>Some data are so delicate that they may only be processed in specific cases. Sensitive data covers race, health, political opinions, philosophical beliefs (religious or atheist, etc.), sexual preferences or judicial past. The Privacy Law most strictly regulates registration and use of those data.</p>
<p>The controller may process sensitive data relating to you (except for judicial data) if:</p>
<ul>
<li>
<div>he has the person’s consent in writing;</div>
</li>
<li>
<div>if it is needed to provide the person with a necessary treatment;</div>
</li>
<li>it is compulsory under employment law.</li>
</ul>
<h3>Controller’s data commitments</h3>
<p>The controller has to ensure:</p>
<ul>
<li>
<div>the good quality of the data, in other words the data has to be precise;</div>
</li>
<li>
<div>the confidentiality of the data. He must ensure that not just anybody can access and disclose the data;</div>
</li>
<li>
<div>the security of the data. He must ensure that the data is not lost or stolen. The more sensitive the data, the higher the level of security has to be;</div>
</li>
<li>that he does not keep the data any longer than necessary to achieve his purpose. At the end of the processing operation, he therefore has to delete the data.</li>
</ul>
<h2>Privacy control framework</h2>
<p>Basic privacy control framework activities include setting objectives, establishing policies and procedures, and establishing monitoring and improvement mechanisms. Many organisations use control frameworks such as COSO (The Committee of Sponsoring Organisations of the Treadway Commission’s 1992 Internal Control — Integrated Framework) or its 2004 ERM (Enterprise Risk Management — Integrated Framework) enhancement.</p>
<p>Qualified Audit Partners’ governance risk management framework can be applied to privacy management and control:</p>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr style="background-color:#000099;">
<td><span style="color:#ffffff;"><strong>Principle</strong></span></td>
<td style="width:795px;height:29px;"><span style="color:#ffffff;"><strong>Description</strong></span></td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Context</strong></span></td>
<td style="background-color:gainsboro;">The privacy culture and tone of an organisation, closely linked with its customer and social responsibility, is critical for the internal privacy risk and control environment.The internal environment includes the privacy code, implicit and explicit privacy policies, and organisational privacy culture, as established and communicated by senior management, all of which have to be aligned with applicable laws and regulations.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Strategy</strong></span></td>
<td style="background-color:gainsboro;">Management needs to establish an organisational mission and vision from which privacy objectives and privacy policy can be derived, directly or indirectly.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Risk</strong></span></td>
<td style="background-color:gainsboro;">Identifying potential internal and external privacy threats is mainly part of periodic and ongoing operational and information technology risk assessment. Appropriate business processes, collection limitation, data security, contingency management, and data management measures mitigate privacy related risks.</td>
</tr>
<tr>
<td style="background-color:darkgray;width:107px;height:45px;"><span style="color:black;"><strong>Resources</strong></span></td>
<td style="background-color:gainsboro;">Adequate resources ensure that organisational policies, procedures, and structures, such as data security, access controls, integrity and contingency controls, privacy reviews, a privacy or security officer, are carried out.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Communication</strong></span></td>
<td style="background-color:gainsboro;">Stakeholders are made aware of the privacy issues and actins. Relevant information needs to be expedited timely to allow effective control.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Monitoring</strong></span></td>
<td style="background-color:gainsboro;">A data register is maintained, requests to access personal information records are evaluated, and privacy audits are conducted. Privacy metrics and reporting on issues and their mitigation are developed.</td>
</tr>
</tbody>
</table>
<h2>Data privacy implementation</h2>
<p>The implementation of a data privacy approach in the organisation is based on several steps:</p>
<ol>
<li>Data has to be inventoried and classified according its sensitivity;</li>
<li>The information security attributes should be applied;</li>
<li>Privacy practices have to be implemented within the organisation.</li>
</ol>
<h3>Data inventory and classification</h3>
<p>The organisation’s private data is one of the most vital corporate assets A corporate classification program for privacy-protected data will assist in prioritising the data. Assigning a sensitivity level, such as secret, confidential, proprietary or public, to data assists in evaluating the appropriateness of the controls over the technology and business processes that handle it.</p>
<h3>Information security</h3>
<p>The CPP commission requires information security to be checked against seven security attributes:</p>
<ul>
<li>
<div><strong>Confidentiality</strong>: only persons having authorisation can access the information;</div>
</li>
<li>
<div><strong>Integrity</strong>: the information cannot be altered intentionally or unintentionally;</div>
</li>
<li>
<div><strong>Availability</strong>: the information is accessible and usable whenever an authorised person has requested it;</div>
</li>
<li>
<div><strong>Accountability</strong>: there is always a trace of the author and of how the information was edited;</div>
</li>
<li>
<div><strong>Non-repudiation</strong>: proof that an operation or event actually took place, meaning that it cannot be denied now or at a later time;</div>
</li>
<li>
<div><strong>Authenticity</strong>: it is certain that a person really is who he claims to be;</div>
</li>
<li>
<div><strong>Reliability</strong>: the characteristic of achieving the expected result.</div>
</li>
</ul>
<h3>Implementation of privacy practices</h3>
<p>To implement and manage an effective privacy program, the organisation should clearly define its privacy policies, communicate those policies, and document the procedures and controls relating to the collection, use, retention, and disclosure of personal information to ensure compliance with laws, regulations, and the organisation’s policies. Specific criteria that are relevant, objective, complete, and measurable should be established for evaluating each of the effectiveness of these practices.</p>
<p>The Commission for the Protection of Privacy (CPP) proposed the introduction of 10 security measures:</p>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr style="background-color:#000099;">
<td><strong>Measure</strong></td>
<td style="width:638px;height:19px;"><strong>Description of the security measure</strong></td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Security Policy</strong></span></td>
<td style="background-color:gainsboro;">Any organisation processing personal data should draw up a security policy giving a precise description of security strategies and protection features selected for data security, consisting of:</p>
<ul>
<li>
<div>the risk management approach of personal data;</div>
</li>
<li>
<div>the priorities set and the mechanisms introduced, as a result of the risk assessment;</div>
</li>
<li>
<div>a planning for the policy&#8217;s taking effect;</div>
</li>
<li>
<div>a description of the various responsibilities and organisational rules;</div>
</li>
<li>
<div>a description of how to manage security incidents;</div>
</li>
<li>
<div>a description of the awareness-raising process within the organisation;</div>
</li>
<li>
<div>the measures to keep the security system up-to-date.</div>
</li>
</ul>
</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Security officer</strong></span></td>
<td style="background-color:gainsboro;">Within the organisation a security officer must be appointed, who is to be in charge of the implementation of the security policy.Reporting directly to the organisation&#8217;s management, he shall ensure that the various responsibilities with regard to security have been clearly defined and that the persons in charge of security can operate autonomously and independently.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Security <strong>organisation</strong></strong></span></td>
<td style="background-color:gainsboro;">The organisation must clearly define the responsibilities and the management processes regarding personal data security and properly integrate them in its general organisational structure and functioning.The organisation should ensure hat information classification procedures are elaborated, so that an inventory can be drawn up and all personal data being processed can be localised. The persons participating in the processing of personal information should to be sufficiently and constantly informed, as well as adequately trained, about their duties and responsibilities during processing operations.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Physical security</strong></span></td>
<td style="background-color:gainsboro;">The organisation should take the necessary measures to guarantee physical security of personal data.The organisation must also provide the necessary safeguards in order to avoid the loss or accidental modification of personal data, and ensure continuity of the business activities.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Network security</strong></span></td>
<td style="background-color:gainsboro;">The organisation must make sure that the confidentiality and integrity of personal data are guaranteed if the equipment is connected to networks while processing the data.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Access security</strong></span></td>
<td style="background-color:gainsboro;">The organisation must ensure that personal data, according to their classification, are only accessible to persons and application programmes explicitly having the necessary authorisations.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Audit trail</strong></span></td>
<td style="background-color:gainsboro;">The organisation should implement logging and audit trail mechanisms.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Monitoring and auditing</strong></span></td>
<td style="background-color:gainsboro;">The organisation must assure that the technical or organisational measures have been validated and that they are regularly checked.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Incident respons</strong></span></td>
<td style="background-color:gainsboro;">The organisation must have a security incident management plan.</td>
</tr>
<tr>
<td style="background-color:darkgray;"><span style="color:black;"><strong>Mobility</strong></span></td>
<td style="background-color:gainsboro;">The organisation should have complete centralised documentation relating to security, which is updated on a regular basis.</td>
</tr>
</tbody>
</table>
<h2>Cross-Border Transfers of Personal Data</h2>
<p>Personal data can move freely within the European Union, as long as the European Data Privacy Directive (95/46/EC) is observed. Indeed, all Member States apply the same level of protection when processing personal data.</p>
<p>Outside the European Union, only transfers to countries ensuring a level of protection equal to that which is offered on EU territory are authorised. The European Commission has recognised an adequate level of protection for the following countries: Switzerland, Canada, Argentina, the United States (if the recipient has accepted the &#8220;Safe Harbor Principles&#8221;), Guernesey and the Isle of Man.</p>
<p>If the country of final destination of the data is not included in the European Commission&#8217;s list, the controller may ensure adequate protection through a contract. This contract is binding for the individual transferring the data and for the one receiving it, and that contains sufficient safeguards with respect to data protection. In Belgium such a contract has to be authorised by Royal Decree, following the opinion of the Commission for the Protection of Privacy. To help the controller in this process, the European Commission has drawn up standard contractual clauses, which are automatically considered as sufficient safeguards for data protection.</p>
<div>A multinational may establish rules for the international transfer of data within its corporate group. All entities of the enterprise have to observe these rules. Binding Corporate Rules are considered as adequate safeguards for personal data protection after approval by the national data protection authorities.</div>
<p>Patrick Soenen | <a href="mailto:p.soenen@qap.eu" target="_blank">p.soenen[at]qap.eu</a> ♦ Jean-Pierre Palante | <a href="mailto:jp.palante@qap.eu" target="_blank">jp.palante[at]qap.eu</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/psoenen.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/psoenen.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/psoenen.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/psoenen.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/psoenen.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/psoenen.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/psoenen.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/psoenen.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/psoenen.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/psoenen.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/psoenen.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/psoenen.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/psoenen.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/psoenen.wordpress.com/18/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=18&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://psoenen.wordpress.com/2010/10/01/protecting-the-privacy-of-personal-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/01af6e578985a0862f33731a56d86afc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">psoenen</media:title>
		</media:content>

		<media:content url="http://www.qualified-audit-partners.be/user_images/Articles/QAP_DataPrivacy.jpg" medium="image">
			<media:title type="html">QAP Data Privacy</media:title>
		</media:content>
	</item>
		<item>
		<title>IT Governance, an integral part of Corporate Governance</title>
		<link>http://psoenen.wordpress.com/2010/03/22/it-governance-an-integral-part-of-corporate-governance/</link>
		<comments>http://psoenen.wordpress.com/2010/03/22/it-governance-an-integral-part-of-corporate-governance/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 00:31:33 +0000</pubDate>
		<dc:creator>psoenen</dc:creator>
				<category><![CDATA[Governance]]></category>

		<guid isPermaLink="false">http://psoenen.wordpress.com/?p=12</guid>
		<description><![CDATA[Article published in the Guberna Newsletter of September 2009 Carte Blanche / Leden aan het woord IT Governance, an integral part of Corporate Governance Organisations rely heavily on Information Technology (IT) for the daily running of their operational business processes and for meeting their strategic objectives. IT should sustain their business development and improve their [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=12&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Article published in the Guberna Newsletter of September 2009</p>
<p><strong><span style="font-size:x-small;">Carte Blanche / Leden aan het woord</span></strong></p>
<blockquote><p><strong><span style="font-family:Times New Roman, Times, serif;color:#999900;font-size:medium;">IT Governance, an integral part of Corporate Governance</span></strong></p>
<p>Organisations rely heavily on Information Technology (IT) for the daily running of their operational business processes and for meeting their strategic objectives. IT should sustain their business development and improve their competitiveness. They are faced with the challenge of adapting to dynamic business demands while handling complex technology-related risks and controls. Moreover, significant amounts of money and resources are invested in information systems.</p></blockquote>
<p> </p>
<table border="0" cellspacing="10" cellpadding="0" width="100%">
<tbody>
<tr>
<td width="50%" valign="top">
<h2>Why is IT governance so crucial?</h2>
<blockquote><p>Most organisations are currently facing 7 IT challenges:</p></blockquote>
<ul type="square">
<li>
<div><strong>Keeping IT running </strong>is the need to guarantee the continuity of IT services for business-critical services. The discontinuity of IT services may result in lost business, reduced profits, and serious damage to the organisation’s reputation. <br />
 </div>
</li>
<li>
<div><strong>Creating value </strong>by identifying the right IT projects and carrying them out within time and budget to deliver the expected value. In IT projects which exceed budgetary expectations or deadlines, business requirements are often poorly defined, project management is weak, and the effort required is underestimated.<br />
 </div>
</li>
<li>
<div><strong>Managing IT costs </strong>as carefully as the other significant business costs. Typically, costs associated with IT assets are not well understood, skilled resources are lacking and IT spending is not coordinated.<br />
 </div>
</li>
<li>
<div><strong>Mastering complexity </strong>by organising and managing the IT function, to ensure that applications are delivered and updated within the managed cost and deadlines. Typical issues are the management of technical infrastructures, the adaptation to changes and the management of external relationships.<br />
 </div>
</li>
<li>
<div><strong>Aligning </strong>with the business to ensure that IT works in partnership with the business to deliver value. The inability to set priorities and poor communication between business and IT creates a gap between what users expect and what IT provides.<br />
 </div>
</li>
<li>
<div><strong>Complying</strong> with the legal and contractual requirements of service providers and trading partners. Regulations that govern business operations impact IT systems. The IT function needs to be aware of legal and regulatory requirements that relate to financial reporting, privacy and security.<br />
 </div>
</li>
<li>
<div><strong>Ensuring information security</strong> in order to protect information adequately. Internet, external communications, the increasing misuse of information and the technical complexity all amplify the risk of information disclosure.</div>
</li>
</ul>
<p> </p>
<table border="2" cellspacing="0" cellpadding="10">
<tbody>
<tr>
<td>
<h2>What is IT Governance?</h2>
<p><strong><span style="color:#999900;">IT Governance consists of the organisational structures and processes that ensure that the organisation&#8217;s IT sustains and extends the organisation&#8217;s strategies and objectives. The goal is to ensure that organisation&#8217;s goals are achieved by generating added value, while balancing risk versus return over IT and its processes. IT Governance is the responsibility of the board and the management to implement the appropriate structures and processes for business involvement in IT decisions.</span></strong></td>
</tr>
</tbody>
</table>
<p> </td>
<td valign="top">
<h2>What IT Governance should deliver?</h2>
<blockquote>
<p dir="ltr">The 7 IT Governance principles to be considered:</p>
</blockquote>
<ul type="square">
<li>
<div>The <strong>governance context </strong>implies leadership and commitment. The management puts into place clear and precise organisational structures by establishing IT&#8217;s roles and responsibilities. The management ensures that standards, policies and procedures are created, and a code of conduct is implemented.<br />
 </div>
</li>
<li>
<div>The <strong>IT strategy </strong>defines the mission and the vision through which information systems contribute to the achievement of the enterprise strategy. Strategic alignment might imply reducing costs, supporting innovation, enhancing simplification, meeting service requirements, enabling expansion, improving business processes, etc.<br />
 </div>
</li>
<li>
<div>The <strong>value creation </strong>is accomplished by controlling IT investments and projects. Among the numerous investment proposals, the judicious choice is based on the return on investment (ROI) and strategic contribution. The focus is placed on the projects with the highest added value. IT and the business are jointly responsible for the achievements.<br />
 </div>
</li>
<li>
<div><strong>Risk management </strong>protects against threats through the identification, the analysis and the treatment of the IT risks. Security entails management and user awareness, regarding their responsibilities and the possible risks. Information security, data confidentiality and asset protection are ensured, while the continuity of the business activities is guaranteed in the case of a disaster.<br />
 </div>
</li>
<li>
<div><strong>Resource optimisation </strong>implies efficient and effective processes and optimal resource allocation such as people, systems, infrastructure and information. The efficient and effective use of resources will be balanced against achievements.<br />
 </div>
</li>
<li>
<div><strong>Communication </strong>methods are put into place to provide the stakeholders with correct information at the right moment. Communication is implemented through adequate relational mechanisms, e.g., IT steering committees.<br />
 </div>
</li>
<li>
<div>The <strong>monitoring </strong>evaluates the IT achievements through performance indicators and balanced scorecards. IT audits provide independent assessments of the IT governance implementation.</div>
</li>
</ul>
<p> </p>
<h2>        IT Governance: a major driver of business value</h2>
<blockquote><p>Governance requires a balance between the performance and conformance goals, directed and controlled by the board. Performance tends to enhance profitability, efficiency, effectiveness and to ensure business growth. Conformance involves the management of the adequate level of control for the IT risk taking approach<em>. </em>Implementing IT Governance is challenging, but the outcome is rewarding.</p></blockquote>
<p>Monique Garsoux &amp; Patrick Soenen, <em>Qualified Audit Partners</em></td>
</tr>
</tbody>
</table>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/psoenen.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/psoenen.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/psoenen.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/psoenen.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/psoenen.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/psoenen.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/psoenen.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/psoenen.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/psoenen.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/psoenen.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/psoenen.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/psoenen.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/psoenen.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/psoenen.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=12&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://psoenen.wordpress.com/2010/03/22/it-governance-an-integral-part-of-corporate-governance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/01af6e578985a0862f33731a56d86afc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">psoenen</media:title>
		</media:content>
	</item>
		<item>
		<title>A Global approach to Risk and Control (GRC)</title>
		<link>http://psoenen.wordpress.com/2010/03/22/a-global-approach-to-risk-and-control-grc/</link>
		<comments>http://psoenen.wordpress.com/2010/03/22/a-global-approach-to-risk-and-control-grc/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 00:19:35 +0000</pubDate>
		<dc:creator>psoenen</dc:creator>
				<category><![CDATA[Governance]]></category>

		<guid isPermaLink="false">http://psoenen.wordpress.com/?p=7</guid>
		<description><![CDATA[This article proposes a Global Risk and Control (GRC) model, which moves away from a silo approach toward a holistic view of risk and control across the organisation. Organisations able to effectively align risk management, control and compliance initiatives with their strategic objectives can reduce their risks and make more valuable decisions regarding their strategy. <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=7&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Article published in The Internal Auditor Compass of November 2009 (IIABEL)</p>
<blockquote><p><strong><span style="color:#6699ff;font-size:small;">A Global approach to Risk and Control (GRC)</span></strong></p>
<p><span style="color:#6699ff;font-size:small;">•   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   • </span></p>
<p>This article proposes a Global Risk and Control (GRC) model, which moves away from a silo approach toward a holistic view of risk and control across the organisation. Organisations able to effectively align risk management, control and compliance initiatives with their strategic objectives can reduce their risks and make more valuable decisions regarding their strategy.</p>
<p>Corporate boards, CEOs, CFOs and other members of the senior leadership team are facing unprecedented levels of business complexity, changing geopolitical threats, new legislation and regulations, and increasing shareholder demands. Achieving maximum performance and ensuring full conformance in today’s complex environment require organisations more than ever to combine risk, control and compliance management in a unique view. The present crisis illustrates that organisations did insufficiently integrate risk management and internal control into their business management. While oversight requirements have significantly grown over the years, boards and audit committees receive repeatedly different reporting with dissimilar views on risks from their stakeholders: executive management, risk and control functions, and audit.</p>
<p><span style="color:#999999;"><span style="color:#6699ff;font-size:small;">•   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   • </span></span></p></blockquote>
<p> </p>
<table border="0" cellspacing="10" cellpadding="0" width="100%">
<tbody>
<tr>
<td width="50%" valign="top">
<h2>The established defence lines</h2>
<p dir="ltr">A set of common control, risk and compliance activities are executed across business units and control functions, and are organised as defence lines.</p>
<p><img title="Defence lines" src="http://www.qualified-audit-partners.be/user_images/Communication/QAP-CerclesOfDefence.jpg" border="0" alt="Defence lines" hspace="0" width="199" height="199" align="middle" /></p>
<p>The primary goal is to organise these functions within the organisation to strengthen its defence.</p>
<p>Within the <strong>inner circle</strong>, the staff applies the policies and the procedures issued by the management, to ensure the regularity, the security and the validity of the operations. The internal control mechanisms are an essential component of the successful direction and control of the organisation. The senior executive management should focus on creating organisational transparency by defining the mechanisms an organisation uses to ensure that its constituents follow established processes and policies.</p>
<p>The <strong>second line</strong> of defence is composed of those functions responsible for an area of control expertise.</p>
<p><em>Internal control</em> is a process, performed to provide reasonable assurance regarding the achievement of objectives in the following areas:</p>
<ul>
<li>
<div>Effectiveness of operations and efficient use of the resources;</div>
</li>
<li>
<div>Reliability of financial and operational reporting;</div>
</li>
<li>
<div>Compliance with applicable laws, regulations and internal policies.</div>
</li>
</ul>
</td>
<td valign="top"><em>Risk management</em> brings a comprehensive, systematic approach for helping the organisation identify events and respond to the risks challenging its most critical objectives and related projects, initiatives, and day-to-day operating practices. Risk management deals with determining the organisation&#8217;s risk appetite, and then identifying and mitigating risks to appropriately balance the risk portfolio.<em>Compliance</em> is the set of practices that deals with adhering to mandated requirements such as laws, regulations, and voluntary requirements resulting from standards, policies, procedures and contractual arrangements. The legal and compliance departments play a major role to protect the organisation against the risk of non compliance.</p>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr>
<td> <br />
<span style="color:#6699ff;"><strong>&#8220;The chief audit executive should share information and coordinate activities with other internal and external providers of assurance and consulting services to ensure proper coverage and minimize duplication of efforts.&#8221;</strong></span><span style="color:#ffffff;"><strong>IIA Assurance Maps Practice Advisory 2050-2</strong></span></td>
</tr>
</tbody>
</table>
<p> </p>
<p><em>Resilience</em> ensures the ongoing business continuity, while <em>security</em> ensures the confidentiality, the integrity and the availability of the operations, the systems and the information.</p>
<p><em>Quality management</em> has the responsibility to establish a Quality Management System (QMS) based on an operational framework, composed of processes and procedures, compliant with the ISO standards.</p>
<p dir="ltr">The <strong>third line</strong> of defence consists of audit and assurance functions, which are performed by internal audit, the external audit and the regulators. Internal audit provides reasonable assurance that the required controls to mitigate risks are effectively designed and operated.  Internal audit should report to the highest level within the organisation to strengthen its objectivity and confirm its independence. A close and continuous link should be established with the Audit Committee.</p>
</td>
</tr>
</tbody>
</table>
<p> </p>
<p><span style="color:#6699ff;font-size:small;">•   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   • </span></p>
<table border="0" cellspacing="10" cellpadding="0" width="100%">
<tbody>
<tr>
<td width="50%" valign="top">
<h2><strong>Risk, Control and reporting fragmentation</strong></h2>
<p dir="ltr">The multiplication of the internal control actors increases complexity, creates a duplication of effort and may reduce the effectiveness of the internal control. At a given moment, the key players may be confident someone else takes care of a specific risk or control, without investing the required level of expertise to mitigate the risks. Consequently, the control, risk, and compliance activities should be coordinated.</p>
<p dir="ltr"><strong>Organisational fragmentation: </strong>As different policies, risks events, measurements are defined, the organisation ends up with different policies, duplication of effort, difficulty of predicting risk, and lack of transparency.</p>
<p dir="ltr"><strong>Information fragmentation</strong>: Local process implementation and optimisation of specific solutions further isolate information within systems, resulting in a lack of information integrity and a limited integrating view of enterprise risks.</p>
<p dir="ltr"><strong>Entity fragmentation:</strong> Policies and risks are generally defined and measured at the local level, without proper consideration of their impact on the global, multinational, national, or regional decision making levels. The interdependencies of the risks associated with the multitude of jurisdictions, countries, and markets are usually not considered.</p>
</td>
<td valign="top">
<p dir="ltr"><strong>Initiative fragmentation</strong>: The multiplication of the risk and control key players within the organisation increases the number of separate and non coordinated initiatives concerning financial reporting, security issues, information privacy, record retention, business regulations, environmental standards, occupational safety, etc.</p>
<p dir="ltr">Each player is developing analogous risk and control models customised to their specific needs and reporting axes. Organisations finally end up with several similar approaches which are delivering managing reports, providing diverse or even conflicting recommendations. Like in Babylon, management and board members get confused due to these different risk languages.</p>
<p dir="ltr"> </p>
<p dir="ltr"> </p>
<table border="0" cellspacing="2" cellpadding="10">
<tbody>
<tr>
<td><span style="color:#333333;">Integration does not mean unification. Integration means applying a common vocabulary, approach and infrastructure to the GRC processes. All the risk, control and assurance functions are updating a common information system, the GRC repository, while keeping their unique contribution. The GRC repository is key for a coordinated and holistic risk and control management and reporting.</span></td>
</tr>
</tbody>
</table>
<p> </td>
</tr>
</tbody>
</table>
<p> </p>
<p><span style="color:#6699ff;font-size:small;">•   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   • </span></p>
<table border="0" cellspacing="10" cellpadding="0" width="100%">
<tbody>
<tr>
<td width="50%" valign="top">
<h2><strong>The integrated GRC model as a solution</strong></h2>
<p dir="ltr">GRC is a system of people, processes and technology that enables an organisation to:</p>
<ul>
<li>
<div>Understand and prioritise stakeholder expectations;</div>
</li>
<li>
<div>Set business objectives congruent with the risks;</div>
</li>
<li>
<div>Operate within internal, social, ethical, legal and contractual boundaries;</div>
</li>
<li>
<div>Provide relevant, reliable, transparent and timely information to the stakeholders;</div>
</li>
<li>
<div>Enable the measurement of the performance and the conformance of the organisation.</div>
</li>
</ul>
<p>The GRC model consists of several interrelated components:</p>
<ul>
<li>
<div>The model starts with the identification and the description of the <strong>business universe</strong>. The organisation&#8217;s main products and services, customer groups and distribution channels are defined. The major business processes representing the core value-chain processes and the support processes are represented. And finally the strategic objectives are established.</div>
</li>
<li>
<div>The foundation of the GRC model is based on risk and controls categories also called assurance map. It lists universally accepted risks and controls which serve as the base for the establishment of the organisation&#8217;s risks and controls. Risks categories are those universally accepted risks which are critical to the organisation&#8217;s business objectives. For these risks, impact and likelihood are estimated. The universally accepted controls used to mitigate the risk categories are defined as controls categories.</div>
</li>
</ul>
</td>
<td valign="top">
<blockquote><p> </p></blockquote>
<ul>
<li>
<div>Risk management identifies, analyses, evaluates and mitigates risk by applying the risk categories to the business universe. Risk and control self-assessment may be performed at management level to identify the key risks. An event database keeps track of all risk events which have occurred within the organisation. The monitoring and the review of the risk management generate improvement action which is integrated into the action plan.</div>
</li>
<li>
<div>Internal control management applies the control categories to the specific business processes to manage the above identified process risks. Adequate control activities are designed and implemented. The assessment of the design and operational effectiveness of these implemented controls results in corrective and improvement action, which is also integrated into the global action plan.</div>
</li>
<li>
<div>The audit department uses the risk and control categories to build up the audit plan. The different audit assignments will independently assess the adequacy and the effectiveness of the implemented controls to mitigate the identified risks. An audit opinion will be rendered and recommendations are formulated. The accepted action is included in the global action plan.</div>
</li>
</ul>
<p>Subsequently, the GRC action plan contains the whole action set which corrects and enhances the global risk and control management within the organisation. Appropriate action selection, prioritisation and follow-up are required to ensure that the action contributing most to the improvement of the control and risk environment is executed first.</td>
</tr>
</tbody>
</table>
<p> </p>
<p><span style="color:#6699ff;font-size:small;"><img src="http://www.qualified-audit-partners.be/user_images/Communication/QAP-GRCplatform.jpg" border="0" alt="" width="398" height="166" /></span></p>
<p><span style="color:#6699ff;font-size:small;">•   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •<br />
</span></p>
<table border="0" cellspacing="10" cellpadding="0" width="100%">
<tbody>
<tr>
<td width="50%" valign="top">
<h2><strong>Implementing the GRC model</strong></h2>
<blockquote><p>A set of requirements condition the successful implementation of the GRC model:</p>
<ul>
<li>
<div>Support of the top management, which is directly interested by the benefits of a global risk and control approach;</div>
</li>
<li>
<div>Cooperation between the different management, control, risk and audit functions within the organisation;</div>
</li>
<li>
<div>A definition of the business universe consisting of the strategic objectives, the business products/services definition, and the description of the enterprise business model in terms of core and support processes;</div>
</li>
<li>
<div>A stepwise implementation ensuring a phased roll out of the model;</div>
</li>
<li>
<div>Adequate project management to attain the defined goals.</div>
</li>
</ul>
</blockquote>
</td>
<td valign="top"> </p>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr>
<td><strong>  </strong><strong><span style="color:#6699ff;"><strong>&#8220;The board will use multiple sources to gain reliable assurance. Assurance from management is fundamental and should be complemented by the provision of objective assurance from internal audit and other third parties&#8221;</strong></span></strong><span style="color:#6699ff;">IIA Assurance Maps Practice Advisory 2050-2</span></td>
</tr>
</tbody>
</table>
<p><strong> </strong></td>
</tr>
</tbody>
</table>
<div><span style="color:#999999;"> </span></div>
<div><span style="color:#999999;"><span style="color:#999999;"><span style="color:#6699ff;font-size:small;">•   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   • </span></span></span></div>
<div><span style="color:#999999;"> </span></div>
<div><span style="color:#999999;"> </span></div>
<p><span style="color:#999999;"> </p>
<p></span></p>
<table border="0" cellspacing="10" cellpadding="0" width="100%">
<tbody>
<tr>
<td width="50%" valign="top">
<h2><strong><strong>Key roles and accountabilities</strong></strong></h2>
<p dir="ltr">The board has the oversight of the GRC system and should</p>
<ul>
<li>
<div>Set business objectives and ensure they are congruent with values and risks;</div>
</li>
<li>
<div>Be knowledgeable about the design and the operation of the GRC model;</div>
</li>
<li>
<div>Obtain regular assurance the system is effective;</div>
</li>
</ul>
<p>The management must undertake the implementation and the follow-up of the GRC system.</p>
<ul>
<li>
<div>Design, implement and operate an efficient GRC system;</div>
</li>
<li>
<div>Communicate transparently with stakeholders about the GRC&#8217;s efficiency;</div>
</li>
<li>
<div>Evaluate and optimise the effectiveness and the efficiency of the GRC system.</div>
</li>
</ul>
</td>
<td valign="top">
<p dir="ltr"> </p>
<p>Audit should provide assurance to the board and the management that</p>
<ul>
<li>
<div>Risks are appropriately identified, evaluated, managed and monitored;</div>
</li>
<li>
<div>The GRC system is effectively designed to mitigate risks;</div>
</li>
<li>
<div>The GRC system is operating effectively.</div>
</li>
<li>
<div>The other risk and assurance providers are functioning effectively.</div>
</li>
</ul>
<p>As a best practice, a GRC steering committee is set up to manage the GRC global structure and to coordinate the different key players.</td>
</tr>
</tbody>
</table>
<div><span style="color:#999999;"> </span></div>
<div><span style="color:#999999;"><span style="color:#999999;"><span style="color:#6699ff;font-size:small;">•   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   • </span></span></span></div>
<div><span style="color:#999999;"> </span></div>
<div><span style="color:#999999;"> </span></div>
<p><span style="color:#999999;"> </p>
<p></span></p>
<table border="0" cellspacing="10" cellpadding="0" width="100%">
<tbody>
<tr>
<td width="50%" valign="top">
<h2><strong><strong>Impact of the GRC model</strong></strong></h2>
<p dir="ltr">The Global Risk and Control approach impacts the organisation and implies good coordination through:</p>
<ul>
<li>
<div>The integration of the GRC disciplines which act as a backbone for the management of enterprise risks and controls;</div>
</li>
<li>
<div>The integration of the GRC activities ensuring common action to achieve the strategic objectives;</div>
</li>
<li>
<div>The GRC integration with the business, by aligning the risk and control activities on common business processes;</div>
</li>
<li>
<div>The distribution of adequate GRC information to all levels of the organisation;</div>
</li>
<li>
<div>The adjustment of the mechanism to the exposed risks, the costs of the controls and the size of the organisation.</div>
</li>
</ul>
</td>
<td valign="top">   </p>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr>
<td> <br />
<span style="color:#6699ff;"><strong><span style="color:#6699ff;">&#8220;Organizations will benefit from a streamlined approach, which ensures the information is available to management about the risks they face and how the risks are being addressed. The mapping is done across the organization to understand where the overall risk and assurance roles and accountabilities reside. The aim is to ensure that there is a comprehensive risk and assurance process with no duplicated effort or potential gaps&#8221;.</span></strong></span><span style="color:#6699ff;"><span style="color:#6699ff;">IIA Assurance Maps Practice Advisory 2050-2</span>   </span></td>
</tr>
</tbody>
</table>
<p> </td>
</tr>
</tbody>
</table>
<div><span style="color:#999999;"> </span></div>
<div><span style="color:#999999;"><span style="color:#999999;"><span style="color:#6699ff;font-size:small;">•   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   •   • </span></span></span></div>
<div><span style="color:#999999;"> </span></div>
<div><span style="color:#999999;"> </span></div>
<p><span style="color:#999999;"> </p>
<p></span></p>
<table border="0" cellspacing="10" cellpadding="0" width="100%">
<tbody>
<tr>
<td width="50%" valign="top">
<h2><strong>Benefits of the GRC model </strong></h2>
<p dir="ltr">GRC brings multiple benefits to the organisation:</p>
<ul>
<li>
<div>Reducing costs as redundant activities are streamlined;</div>
</li>
<li>
<div>Reducing the impact of risk events due to the global risk and control approach;</div>
</li>
<li>
<div>More effective improvement action through an integrated and coordinated risk and control action plan;</div>
</li>
</ul>
</td>
<td valign="top">
<p dir="ltr"> </p>
<blockquote>
<li>
<div>Optimising competencies and scarce resources;</div>
</li>
<li>
<div>Increased quality of risk based information for strategic planning;</div>
</li>
<li>
<div>Enhanced board and management trust resulting from an integrated oversight and reporting on risks and controls, increasing stakeholder&#8217;s confidence.</div>
</li>
</blockquote>
<p dir="ltr">Monique Garsoux &amp; Patrick Soenen, <em>Qualified Audit Partners</em></p>
</td>
</tr>
</tbody>
</table>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/psoenen.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/psoenen.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/psoenen.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/psoenen.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/psoenen.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/psoenen.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/psoenen.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/psoenen.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/psoenen.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/psoenen.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/psoenen.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/psoenen.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/psoenen.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/psoenen.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=7&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://psoenen.wordpress.com/2010/03/22/a-global-approach-to-risk-and-control-grc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/01af6e578985a0862f33731a56d86afc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">psoenen</media:title>
		</media:content>

		<media:content url="http://www.qualified-audit-partners.be/user_images/Communication/QAP-CerclesOfDefence.jpg" medium="image">
			<media:title type="html">Defence lines</media:title>
		</media:content>

		<media:content url="http://www.qualified-audit-partners.be/user_images/Communication/QAP-GRCplatform.jpg" medium="image" />
	</item>
		<item>
		<title>The implementation of agile management in organisations</title>
		<link>http://psoenen.wordpress.com/2010/03/22/3/</link>
		<comments>http://psoenen.wordpress.com/2010/03/22/3/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 00:14:37 +0000</pubDate>
		<dc:creator>psoenen</dc:creator>
				<category><![CDATA[Governance]]></category>

		<guid isPermaLink="false">http://psoenen.wordpress.com/?p=3</guid>
		<description><![CDATA[The success of an agile organisation is its ability to develop methods and structures through which organisations can adapt quickly to changed environmental circumstances. Agile methods, developed at the point of departure in the IT sector, become widespread in the service sector, health and engineering.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=3&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em><span style="color:#333333;">The success of an agile organisation is its ability to develop methods and structures through which organisations can adapt quickly to changed environmental circumstances. Agile methods, developed at the point of departure in the IT sector, become widespread in the service sector, health and engineering.</span></em></p>
<hr />
<h2>The implementation of agile management in organisations</h2>
<table border="0" cellspacing="2" cellpadding="2">
<tbody>
<tr>
<td>We live in a world in constant change. New technologies, new client expectations, environmental changes are constantly disrupting the requirements on products and services. In traditional project management, a project is identified, evaluated, divided into tasks and precisely planned. Then it is realised by executing the tasks sequentially. But when results are available, the requirements may have changed considerably. How to manage projects effectively in such an environment?</p>
<p>Over the past decade, agile methods have completely changed the technical software development. But the project management methods, which remained very traditional, aren’t any more adapted to these very agile development techniques. Agile management both at executive and at project level provides innovative and new solutions. The agile principles were already applied in the famous Deming PDCA circle where at each iteration, action is planned and executed, the results are checked and the approach is adjusted.</p>
<h3>The benefits</h3>
<p>The success of an agile organisation lies in its ability to develop methods and structures through which the organisation can adapt quickly to changed environmental circumstances. Agility is different from agitation, the hustle, and requires a very strict methodology, far away from the chaotic image that is sometimes linked to the concept of agility.</p>
<p>The agile management methods were originally developed in the computer industry in parallel with agile programming methods. Today they tend to spread in the field of services and affect even areas traditionally hostile to this type of approach, such as engineering. This sector is indeed under pressure from its customers, who want to adapt their projects underway, with the changing economic and financial context. This impacts even the industrial and energy infrastructure, enforcing a cultural revolution to the engineering teams to adjust projects with dynamic boundaries.</p>
<p>Even the health sector is interested in the agile approach, as both financial and socio-economic conditions change very quickly. The numerous mergers of hospital institutions, the crisis of public finances, the aging population, the computerisation of patient records and the e-health developments are all events that have compelled the non-profit sector to adapt to rapidly evolving situations, requiring new management approaches.</p>
<h3>The principles of agile management</h3>
<p>Agile management structures the interactions between the main operational components of an organisation: human resources, processes and technology systems. An agile organisation is functionally operational when its components interact to capture and integrate change.</p>
<p>The agile organisation is based on 3 vectors:</p>
<ol>
<li>
<div>The<strong> rational motivation of human resources </strong>brings the collective intelligence that maximises the human potential. The proactive involvement of human resources promotes systematic improvement. Skills, attitude and mindset are the most important factors in agility.</div>
</li>
<li>
<div>The formalised <strong>control of continuous process improvement </strong>allows optimisation of resources used. Continuous process optimisation projects represent powerful means to obtain competitive advantages at the best price.</div>
</li>
<li>
<div>The <strong>optimal use of new technologies </strong>allows economical mass customisation of products and services and reduces time to market. An agile information system is characterised by its ability to provide optimum response to changes in the organisation.</div>
</li>
</ol>
<p><img src="http://www.qualified-audit-partners.be/user_images/Articles/Agile_management_EN.jpg" border="0" alt="" width="300" height="153" /></p>
<p>The agile management therefore incorporates the concept of &#8220;lean management&#8221; which seeks to maximise efficiency through the elimination of waste by removing processes that add no value. Agile management implies process control and a search for continuous process improvement (through Business Process Management &#8211; BPM). It also requires optimal use of new information and communication technologies (ICTs). However, only the combination of these three dimensions enables agility.</p>
<p>Today, a successful company is &#8220;service oriented&#8221;. And its tools are performance and quality of its processes. To be agile, the company must simultaneously master the dynamic evolution of human resources, business processes and information system.</p>
<h3>The characteristics of the agile management compared to traditional management</h3>
<p>In the traditional approach, the ultimate goal is translated early in a scope, a planning and (financial, human and technical) resources. In the agile management, the emphasis is on achieving goals, broken down into sub goals of affordable size per iteration. Over the iterations, the scope becomes dynamic.</p>
<p>The traditional planning involves initially considerable preparation with subsequent minor updates throughout the project. Agile planning is divided into multiple levels ranging from a high-level planning (macro-planning) up to detailed planning, established at the beginning of each iteration. The initial planning should be flexible to allow changes in customer demand throughout the project.</p>
<p>While the traditional approach breaks down the project by cascading a series of sequential tasks, the achievement in agile is iterative and incremental, making sure to deliver a tangible result to the client at each iteration.</p>
<p>The management role is in coaching teams to remove barriers to advancement. Decision making is decentralised to the teams. The roles and responsibilities aren&#8217;t based any more on titles and functions, but organised according to the expertise of the people.</p>
<p>Work organisation is decentralised and focused on results and on a watch of the constantly changing market environment. Confidence in the team, composed of individuals mastering the processes, improves the efficiency and effectiveness of the work performed.</p>
<p>Traditional risk management is descriptive, identifying the starting point of the potential risks along with mitigation actions. In the agile approach, risk management is based on experimentation. Learning takes place over the iterations. And within the iterations, the impact of failures is limited. </td>
<td width="1%"> </td>
<td width="50%" valign="top"> </p>
<h3>The agile methodology in project management</h3>
<p>The diagram below shows the methodology applied to agile project management.</p>
<p><img longdesc="Agile Methodology" src="http://www.qualified-audit-partners.be/user_images/Articles/Agile_methodology_EN.jpg" border="0" alt="Agile Methodology" width="349" height="288" align="center" /></p>
<p>The agile methodology is broken down into 5 steps</p>
<ol type="1">
<li>
<div>In the &#8220;<strong>Version Scope</strong>&#8221; phase, the requirements are identified. Even if the scope can evolve throughout the project, the scope is clearly defined at the start. The project terms of reference detail the project costs and benefits, taking into account the implications of identified risks. This first step is important for the specification of the requirements and for setting priorities.</div>
</li>
<li>
<div>Based on the initial plan and the achievements from the previous iterations, the <strong>cycle plan </strong>describes activities for the next iteration accurately and in detail. Each new iteration begins with a planning stage.</div>
</li>
<li>
<div>The <strong>Build cycle</strong> is realised in an iterative way, making sure that each iteration delivers a concrete and usable result for the user.</div>
</li>
<li>
<div>The <strong>Client</strong> <strong>checkpoint</strong> includes a quality review at the end of each iteration. The work done during the iteration is validated.</div>
</li>
<li>
<div>The <strong>Post-Version review </strong>generates feedback resulting into improvement plans. The effective realisation of initial expectations is evaluated.</div>
</li>
</ol>
<h3>The criteria</h3>
<p>Agile management is based on 7 criteria:</p>
<ul type="disc">
<li>
<div>sharing the goal by emphasising cooperation at all company levels;</div>
</li>
<li>
<div>a cooperative decision making process;</div>
</li>
<li>
<div>leadership, combined with a collaborative work team;</div>
</li>
<li>
<div>performance assessmen, ensuring control is replaced by result measurements and individual performance by group performance;</div>
</li>
<li>
<div>adaptive resources depending on the context and the environment;</div>
</li>
<li>
<div>value creation in order to innovate for greater customer satisfaction;</div>
</li>
<li>
<div>stimulation of horizontal and vertical cooperation between departments, individuals and disciplines.</div>
</li>
</ul>
<h3><strong>The implementation at the management level</strong></h3>
<p>The agile approach covers the main operational components of the company, i.e. human resources, process and technology. To avoid to destabilise the organisation, agility must be implemented in steps and in a iterative manner.</p>
<p><img longdesc="Governance components" src="http://www.qualified-audit-partners.be/user_images/Communication/QAP-GovernanceComponents.jpg" border="0" alt="Governance components" width="299" height="201" align="center" /></p>
<p>The first step is to readjust the organisation by establishing the roles and responsibilities across the organisation. Afterwards, human resources skills are adjusted in relation to this new organisational structure. During the next step, the processes are formalised and improved. Finally, the introduction of new technologies allows the process optimisation. And the changes made require a new realignment of the organisation, thus launching a new iteration.</p>
<h3><strong>An agile approach to dashboards</strong></h3>
<p><img longdesc="Balanced Scorecard" src="http://www.qualified-audit-partners.be/user_images/Articles/QAP_Governance_BSC_EN.jpg" border="0" alt="BSC" width="299" height="229" align="center" /></p>
<p>The agile approach is perfectly suited to scorecard methodologies (Balanced Scorecards), which like agile management methods put the focus on performance. To achieve the financial and collective performance and satisfy customers or users, organisations must optimise their resources and their internal processes. The learning and growth perspective incorporates the concept of the learning organisation and the collective intelligence.</p>
<p>Jean-Pierre Palante | <a href="mailto:jp.palante@qap.eu" target="_blank">jp.palante[at]qap.eu</a> ♦ Patrick Soenen | <a href="mailto:p.soenen@qap.eu" target="_blank">p.soenen[at]qap.eu</a></td>
</tr>
</tbody>
</table>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/psoenen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/psoenen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/psoenen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/psoenen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/psoenen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/psoenen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/psoenen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/psoenen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/psoenen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/psoenen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/psoenen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/psoenen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/psoenen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/psoenen.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=psoenen.wordpress.com&amp;blog=12736086&amp;post=3&amp;subd=psoenen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://psoenen.wordpress.com/2010/03/22/3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/01af6e578985a0862f33731a56d86afc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">psoenen</media:title>
		</media:content>

		<media:content url="http://www.qualified-audit-partners.be/user_images/Articles/Agile_management_EN.jpg" medium="image" />

		<media:content url="http://www.qualified-audit-partners.be/user_images/Articles/Agile_methodology_EN.jpg" medium="image">
			<media:title type="html">Agile Methodology</media:title>
		</media:content>

		<media:content url="http://www.qualified-audit-partners.be/user_images/Communication/QAP-GovernanceComponents.jpg" medium="image">
			<media:title type="html">Governance components</media:title>
		</media:content>

		<media:content url="http://www.qualified-audit-partners.be/user_images/Articles/QAP_Governance_BSC_EN.jpg" medium="image">
			<media:title type="html">BSC</media:title>
		</media:content>
	</item>
	</channel>
</rss>
