+ All Categories
Home > Technology > CAMM presentation for Cyber Security Gas and Oil june 2011

CAMM presentation for Cyber Security Gas and Oil june 2011

Date post: 31-Jan-2015
Category:
Upload: vladimir-jirasek
View: 954 times
Download: 1 times
Share this document with a friend
Description:
Let's talk about Cloud security, its challenges and how CAMM can help in managing supply chain assurance.
10
Managing risks in the supply chain Tuesday 7 June 2022 Common Assurance Maturity Model Common- Assurance.com 1 Vladimir Jirasek CAMM Steering Group Twitter @vjirasek
Transcript
Page 1: CAMM presentation for Cyber Security Gas and Oil june 2011

10 April 2023 Common Assurance Maturity Model Common-Assurance.com

1

Managing risks in the supply chain

Vladimir JirasekCAMM Steering Group

Twitter @vjirasek

Page 2: CAMM presentation for Cyber Security Gas and Oil june 2011

People say that they are concerned that their information is not secure in The Cloud

People do not fully trust The Cloud

Page 3: CAMM presentation for Cyber Security Gas and Oil june 2011

10 April 2023 Common Assurance Maturity Model Common-Assurance.com

3

Is the Cloud Secure?

• Can be as secure as any other IT system

• Depends on the model chosen

• Understand the responsibilities

• All eggs in one basket is the real question

• Implicit trust on provider• Exit and lock-in

Page 4: CAMM presentation for Cyber Security Gas and Oil june 2011

10 April 2023 Common Assurance Maturity Model Common-Assurance.com

4

Problem to be solved – trust in the supply chain

Your business

Your cloud provider

Suppliers for the cloud

provider

End to end assurance

Page 5: CAMM presentation for Cyber Security Gas and Oil june 2011

10 April 2023 Common Assurance Maturity Model Common-Assurance.com

5

What a CIO want

Domain Maturity

scoreGovernance 3

HR 3

Physical 4

IT 4

Business Continuity

3

Incident management

2

Domain Maturity

scoreGovernance 4

HR 4

Physical 4

IT 3

Business Continuity

3

Incident management

4

Provider A Provider B

Maturity levels feed into a supplier selection process

Page 6: CAMM presentation for Cyber Security Gas and Oil june 2011

10 April 2023 Common Assurance Maturity Model Common-Assurance.com

6

CAMM MISSIONProvide an objective framework to transparently rate and benchmark the capability of a selected solution to deliver information assurance maturity across the

supply chain

CAMM MISSIONProvide an objective framework to transparently rate and benchmark the capability of a selected solution to deliver information assurance maturity across the

supply chain

Page 7: CAMM presentation for Cyber Security Gas and Oil june 2011

10 April 2023 Common Assurance Maturity Model Common-Assurance.com

7

Overall structure of CAMM components

Controls framework

WorkBenchApp

Weightingframework

Scoring model

Auditors

Final maturity scores

Audited controls

Maturityscores

Non CAMM audit results

Mapping to other standardsTPAC

Free GRC app

Page 8: CAMM presentation for Cyber Security Gas and Oil june 2011

10 April 2023 Common Assurance Maturity Model Common-Assurance.com

8

Utilize your current investmentto an another standard e.g. ISO

• The Statement Of Applicability (SOA) of source standard is used as a baseline for translation

• CAMM Guidance documents will help auditors with ”yellow” area intepretations

e.g. ISO 2700x SOA CAMM

1=1 applicable, no need of intepretation

Auditor intepretation of applicability

Not implemented > to be CAMM audited

Translate

Souce standard Target standard

Page 9: CAMM presentation for Cyber Security Gas and Oil june 2011

Stakeholders1. Consumers – Can form trust relationship

based on understantable facts2. Companies – Can form trustworthy

supply chains to provide real trustworthiness to consumers & other customers

3. Governents – Can have more confidence in corporate governance to remove barriers from global single e-markets

4. Service Providers & Consultancies – Can build competences to achieve the target

5. Industry Associations – can excel in defining harmonized model implementations

CAM Commitee

GovernmentConsumer

Page 10: CAMM presentation for Cyber Security Gas and Oil june 2011

ProgressIt is anticipated for the initial set of COMMON controls and associated guidance to be completed by Q4 2011. The following details the key

milestones:

Major client, standards and service provider organisations engagedDevelopment of framework and appropriate weighting mechanism underway

Development of the framework Control framework created and reviewed Scoring model created

Development of the guidance Guidance material to be completed by end of October 2011

Pilot Pilot with major organisation planned for summer 2011 Development of Free GRC tool Major GRC vendor engaged to ad CAMM module

Dougie Rowlinson
It is ancipated that the initial set of COMMON controls and associated guidance will be completd by Q2 2010.

Recommended