Top Banner
How Atlassian Manages Risk and Compliance GEORGE TOTEV | HEAD OF RISK & COMPLIANCE | ATLASSIAN
29

How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Jan 21, 2018

Download

Software

Atlassian
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

How Atlassian Manages Risk and Compliance

GEORGE TOTEV | HEAD OF RISK & COMPLIANCE | ATLASSIAN

Page 2: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

RISK & COMPLIANCE TEAM

"We are here to help you build trust with our customers fast"

We manage • Compliance program • Business Continuity/Disaster Recovery (BC/DR) program • Risk management program

Page 3: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Agenda

Agile and Compliance relationship - “It’s Complicated”

It all begins with a TEAM

Integrated Compliance

Governance, Risk & Compliance (GRC) dilemma

Taking it up a notch - Trust Management System

Page 4: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

We Love Agile!

• Delivers value quickly • Focuses on the stakeholder • Autonomous team execution • Highly adaptable • Continuous improvement • Predictable cost and delivery

Source: Informal survey of Atlassian development managers

• Reduces Time to Market • Improves quality • Improves productivity • Increases employee satisfaction • Reduces cost

Source: HBR Analytic Services (PwC Internal Benchmark)

Page 5: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Individuals and interactions over processes and tools

Working software over comprehensive documentation

Customer collaboration over contract negotiation

Responding to change over following a plan

Source: “Agile Manifesto” - http://agilemanifesto.org

Page 6: How Atlassian Manages Risk and Compliance with Jira Software and Confluence
Page 7: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

We Hate Agile!

Highly Dynamic

Unstructured/Unpredictable

Limited Documentation

Scaling Fast

Traditional Compliance “Nightmare”!

Page 8: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

There Is A Way! We Hate

Agile!We Love

Agile!

Page 9: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Automate

Leverage Existing Processes

Optimize

Manage Risk

Highly Dynamic

Unstructured/Unpredictable

Limited Documentation

Scaling Fast

CHALLENGES APPROACH

Page 10: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Agenda

Agile and Compliance relationship - “It’s Complicated”

It all begins with a TEAM

Integrated Compliance

Governance, Risk & Compliance (GRC) dilemma

Taking it up a notch - Trust Management System

Page 11: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Closely aligned with business

Wide range of skills

Deep domain knowledge

Risk & Compliance

TEAM

We have intimate knowledge of the business TEAMS

Page 12: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Agenda

Agile and Compliance relationship - “It’s Complicated”

It all begins with a TEAM

Integrated Compliance

Governance, Risk & Compliance (GRC) dilemma

Taking it up a notch - Trust Management System

Page 13: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

File Ticket

Review Board

Schedule Change

Deploy

TRADITIONAL CHANGE MANAGEMENT

“AGILE” CHANGE MANAGEMENT

Green build =

Deployment =

Optimize and automate existing process

How do you audit this? Peer review =

Page 14: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

MORE ABOUT OUR CONTROLS…

Go to https://www.atlassian.com/trust/compliance

• Request our ISO27001 certificate • Request our SOC2 Type I reports

Bitbucket Cloud Jira Cloud* Confluence Cloud*

*Jira and Confluence to be available later

Page 15: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Sarbanes - Oxley

FedRAMP

G-Cloud

GDPR

Page 16: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Atlassian Controls

Framework

Optimize Controls Portfolio

Reduce Business Involvement

Lower Audit Cost

Expand and Scale

Inspiration: Unified Compliance Framework (UCF) https://www.unifiedcompliance.com

Page 17: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Agenda

Agile and Compliance relationship - “It’s Complicated”

It all begins with a TEAM

Integrated Compliance

Governance, Risk & Compliance (GRC) dilemma

Taking it up a notch - Trust Management System

Page 18: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

GRC

Efficient

Scalable

Low Cost

Integrated

Easy to Use

Spreadsheets & Documents Really?!

Specialized Tools Unwieldy, $$$

What else is out there? Hmmm….

Page 19: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

GRC Recipe

Ingredients • One Vanilla JIRA • One Vanilla Confluence • Several GRC Experts • Lots of Coffee & Pizza • (Optional: Spice up with JIRA Service Desk)

• Mix and stir for about a week • Taste and improve

Page 20: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Issues…

Compliance Objects

• Standard • Control Objective • Control Activity • Control Test • Finding • Remediation • ….

Page 21: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

… Go through lifecycles …

Page 22: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

… and link to other issues and pages…

Page 23: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

… and are used in reports

Page 24: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Other Examples

Policies Policy in Confluence

Policy Lifecycle in Jira Policy Exceptions in JIRA Service Desk

Audit Subtasks in Control Test

Linked PBCs Findings in Jira

Linked Remediations

Risk Risk Issue Type

Risk Driver Issue Type Links with Controls

“Crowdsourcing” risks

Attestations Issues in Jira

Reports attached Lifecycle is Workflow

Templates in Confluence

Page 25: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Easy Low Cost

Integrated Expandable

Scalable

Page 26: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Agenda

Agile and Compliance relationship - “It’s Complicated”

It all begins with a TEAM

Integrated Compliance

Governance, Risk & Compliance (GRC) dilemma

Taking it up a notch - Trust Management System

Page 27: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Atlassian Trust

Management System (ATMS)

Standards, generally, require/prescribe:

• Governance Structures • Policy Management • Controls Management • Audit & Assurance

Goal Abstracted Risk Management

Page 28: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

Summary

Optimize Control Framework Reduce cost and burden on TEAMs

Trust Management System Abstract Risk Management and leverage components

There is a Way! Combining TEAM with Atlassian tools could allow Agile Compliance Management

GRC JIRA and Confluence are easy, effective, scalable way to manage GRC

Atlassian Compliance Community at https://community.atlassian.com/t5/Compliance/ct-p/compliance

Page 29: How Atlassian Manages Risk and Compliance with Jira Software and Confluence

How Atlassian Manages Risk and Compliance

GEORGE TOTEV | HEAD OF RISK & COMPLIANCE | ATLASSIAN