l loyd dawson 2010 it grc at psc

17
Lloyd Dawson, Director, IT Compliance June 2010 IT Governance, Risk, and Compliance (GRC) at PSC

Upload: jpkush

Post on 03-Nov-2014

395 views

Category:

Business


7 download

DESCRIPTION

 

TRANSCRIPT

Page 1: L loyd dawson   2010 it grc at psc

Lloyd Dawson, Director, IT ComplianceJune 2010

IT Governance, Risk, and Compliance (GRC) at PSC

Page 2: L loyd dawson   2010 it grc at psc

Agenda

• PSC, LLC

• IT Organizational Chart

• Why IT GRC at PSC

• IT GRC Strategies, Operations, and Tactics

• IT GRC Results

• Question and Answer

Page 3: L loyd dawson   2010 it grc at psc

PSC, LLC

Page 4: L loyd dawson   2010 it grc at psc

PSC North America Locations

Page 5: L loyd dawson   2010 it grc at psc

IT Organizational Chart

• Vice President of IT – Pamela Rucker – Professional staff and outsourced services– Support 4 Lines of Business

Page 6: L loyd dawson   2010 it grc at psc

IT Compliance Responsibilities

Page 7: L loyd dawson   2010 it grc at psc

Why IT GRC at PSC

Page 8: L loyd dawson   2010 it grc at psc

Strategies, Operations, and Tactics

Page 9: L loyd dawson   2010 it grc at psc

IT Risk Management

ISO 27005:2008based process

Risk Management Internal Audit

Page 10: L loyd dawson   2010 it grc at psc

IT Security – Account Administration

ISO 27002:2005based policy

Page 11: L loyd dawson   2010 it grc at psc

IT Compliance

• 2008 – Baseline controls• 2009 – Expanded coverage controls• 2010 – Complete coverage controls• PSC received nomination for ISE Security Executive of the Year

(http://www.iseprograms.com/central_project_nominees.asp)

Page 12: L loyd dawson   2010 it grc at psc

IT DRP

• Close coordination between HR and IT• Annual/as required updates and tests• Special DRP ‘kits’ for key plan participants• Conferences and seminars

IT HR

DRP = Disaster Recovery Plan BCP = Business Continuity Plan

Page 13: L loyd dawson   2010 it grc at psc

IT Change Management

ITIL-basedProcess

CAB = Change Advisory Board

Page 14: L loyd dawson   2010 it grc at psc

IT Vendor Management

RelationshipManagement

Control Visibility

Page 15: L loyd dawson   2010 it grc at psc

IT GRC Summary

• Controls• Regulations • Ownership• Accountability• Measurements• Sustained• Coordination• Cost Control

Page 16: L loyd dawson   2010 it grc at psc

Results

Page 17: L loyd dawson   2010 it grc at psc

Question & Answer