Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO...

25
Increasing scope and speeding up delivery while staying secure. IT Risk in an Agile transformation. Information Security Risk Management – ABN AMRO Christian de Groot & Sander Oerlemans

Transcript of Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO...

Page 1: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

Increasing scope and speeding up delivery while staying secure.

IT Risk in an Agile transformation.

Information Security Risk Management – ABN AMROChristian de Groot & Sander Oerlemans

Page 2: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

2 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

What you will learn

Lessons Learned for ABN AMRO in this transformation

3

Learn About Key IT Risk Challenges in Agile Context

of ABN AMRO

Learn About Agile IT Risk Transformationof ABN AMRO

21

Page 3: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

3 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Agenda

Introduction

Challenges of the old IT Risk process in an Agile context

Objectives new IT Risk process and current solution

Lessons learned

Next steps

Q&A

Page 4: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

4 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ABN AMRO

• Retail, Private & Corporate Clients

• Full range of products, majority of products available via internet

• Operating income 8588 million

• 21664 employees

• Amsterdam, 1720

Page 5: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

5 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Page 6: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

6 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ABN AMRO and scope IT Risk

IT Risk assessments performed on a periodic basis and in case of major changes.

USA

Brazil

UKThe Netherlands

Singapore

Hongkong

France

GermanyBelgiumGuernsey

Assessments on IT processes

Generic IT processes

Assessments on IT assets

• +/- 3000 applications• IT infrastructure

• Internal hosted datacentre

• Cloud• Vendors• etc

Page 7: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

7 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

IT

IT ownership IT assets

Chief Operations Office

Business ownership IT assets

Project Managers

Business lines

Business ideas for improvement

ABN AMRO organizational structure prior to Agile transition

Full Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Page 8: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

8 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ABN AMRO transforms to Agile organizational structureFull Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

IT

Centralized ownership IT assets

Business lines

Business ideas for improvement

Page 9: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

9 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Business lines

ABN AMRO transforms to Agile organizational structure

Ideas for improvement

Grid Grid

BlockBlock BlockBlock

BlockProduct Owner

BM BM

BMBM

SM

Ideas for improvement

Ideas for improvement

Ideas for improvement

Distinction between Business and IT ownership

Full Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Product Owners are always responsible for their (IT) products

Lack of IT Risk

ownership awareness

Page 10: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

10 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ABN AMRO’s old IT Risk process not fit for AgileFull Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Start project

End project

Old IT Risk Assessment process

RiskAssessmentTiming IT

Risk assessment

unclear

Page 11: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

11 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ABN AMRO increasing digitalFull Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Scope assessed assets and assessed

controls too low

Page 12: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

12 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ABN AMRO’s outdated tooling and manual processesFull Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

OUTDATED TOOLING

MANUAL PROCESSES

Assessed controls not

100% accurate

Manual processes

and outdated

tooling

Page 13: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

13 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ABN AMRO’s IT Risk process not compliant in Agile context

Full Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Frequency too low

Quality too low

Awareness ownership too low

IT Risk process not compliant in

Agile context

Page 14: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

14 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Goals for new IT Risk processFull Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

OBJECTIVES new processCHALLENGES Old process1. All assets should be in scope

2. All controls should be in scope

3. Assessed controls should be 100% accurate

4. Presence of full awareness of Product Owner of IT Risk ownership

5. Future proof tooling (maximum automation and integration)

6. Prove compliance of IT Risk process in the new Agile context

Lack of IT Risk

ownership awareness

Timing of IT Risk process

unclear

Scope assessed

assets and assessed

controls too low

Assessed controls not 100% accurate

Manual processes

and outdated

tooling

IT Risk process not compliant in

Agile context

Page 15: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

15 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ServiceNow proven golden source for all IT assets, buildings and vendors.

Our ServiceNow GRC solution – scope and accuracy

Assessed assets

Controls InternetBanking

HR Jira Adm

Full Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Increased accuracy of assessed controls by using automatic profiling.

Public

Confidential

Transactional

Cloud

Baseline

Page 16: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

16 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ServiceNow proven golden source for all IT assets, buildings and vendors.

Our ServiceNow GRC solution – scope and accuracy

Assessed assets

Controls InternetBanking

HR Jira Adm

Baseline

Full Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Increased accuracy of assessed controls by using automatic profiling.

Public

Confidential

Transactional

Cloud

Baseline

Page 17: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

17 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

ServiceNow GRC

Control

Issue

Issue Task

Our ServiceNow GRC solution – Full Awareness

JIRA

Backlog

Full Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

MANUAL PROCESSES

Assessed controls not

100% accurate

Manual processes

and outdated

tooling

Page 18: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

18 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Our GRC solution – Future proof tooling and automationFull Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

ITSM & Asset management

Page 19: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

19 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Compliance IT Risk Process

Our ServiceNow GRC solution – Prove Compliance

ü Risk Assessment Frequency Sufficient

ü Risk Assessment Frequency sufficient

ü Risk Assessment Quality is sufficient

ü Increased number of people who are carrying out assessments.

Full Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Proof compliance through Dashboardü Product Owners

ü (Senior) Management

ü Direct Access 2nd Line

ü Internal Audit

Page 20: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

20 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Value outcomes

400Product Owners

3000+Applications and

other assets

An increase of

All assets in scope Security Check done by 400 Product Owners

instead of 40 Risk Assessors

CISO Operational IT Risk Assessment

From 3-6 months to 2-4 weeks

7XFASTER

Page 21: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

21 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Knowledge sharing with other companies (e.g. ServiceNow Summits & Knowledge)4

Lessons learned

Change People, Process and culture instead of ServiceNow; use out of the box functionality3

Communication is key2

Commitment from management of all effected business lines1

Regular feedback sessions with ServiceNow experts 5

Page 22: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

22 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Training

• Training new process and tool for whole organization

Integration

• Integration with cloud management

• Integration with vendor management

Control

• Control test automation by integrating with other applications

Check list

• Implementation of Risk Management part of GRC.

Our next stepsFull Agile Enterprise

Currently here (October 2018)

Traditional Enterprise with Agile teams (2016)

Start Agile Transformation (2015)

Waterfall

Page 24: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

24 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Speaker introduction

Name: Christian de GrootTitle: Information Security Risk Manager

Function: CISO / IT Risk ManagementCompany: ABN AMRO

Experience/Expertise: 5 years experience in BI & datawarehousing and KPI reporting. 4 years experience of improving Markets systems. 3 years experience in business process improvement (lean six sigma), 1,5 years ABN AMRO CISO process and product development within IT risk management (current). MscBusiness Information Systems. Expertise: Achievements: Roll out of Financial Management Datamarts for MeesPierson, Implementation of Intellimatch/Intellitracs for Markets back office and Launcher platform for Markets front office, Roll-out ServiceNow GRC module to CISO organization and increased internal work collaboration by automating IT risk assessment process within ABN AMRO.

Current Projects: Roll-out ServiceNow GRC module to the rest of the organization - including Product owners into the IT risk assessment process.

Page 25: Increasing scope and speeding up delivery while staying ... … · Company: ABN AMRO Experience/Expertise: 5 years experience in BI & datawarehousingand KPI reporting. 4 years experience

25 © 2018 ServiceNow, Inc. All Rights Reserved. Confidential.

Speaker introduction

Name: Sander OerlemansTitle: Information Security Risk Manager

Function: CISO / IT Risk ManagementCompany: ABN AMRO

Experience/Expertise: 1,5 years IT risk management for ABN AMRO business line Retail, 1,5 years ABN AMRO CISO process and product development within IT risk management (current), BA Philosophy and MSc Information studies: Business Information studies.

Expertise: Achievements: Roll-out ServiceNow GRC module to CISO organization and increased internal work collaboration by automating IT risk assessment process within ABN AMRO.

Current Projects: Roll-out ServiceNow GRC module to the rest of the organization - including Product owners into the IT risk assessment process.