GRC Journal - (Page 63) Governance, risk & Compliance moderator lee dittmar deloitte consulting llp LEE DITTMAR is a Principal with Deloitte Consulting LLP where he leads the Enterprise Governance consulting practice and serves as Co-Leader of Deloitte’s GRC services. Lee is a highly sought after speaker on governance, risk management, IT strategy, and how companies can improve information quality and performance by aligning IT assets with GRC needs. Treasury and Risk Management magazine identified him as among the 100 most influential people in finance in 2005 and again in 2006. Consulting Magazine named him to its list of The Top 25 Consultants in 2006. Why is it so hard for companies to produce accurate and timely information? HR: Part of the issue that makes it so difficult is that governance over information as a topic can’t be addressed in isolation. We need to consider the context and framework established by balancing corporate governance, risk management and controls in compliance across the whole organization. Within that context, there are many earmarks of good information quality such as security, accessibility and also receiving the information that you need within the business context at the time that you need it within the business process. At the base, the problem comes down to fragmentation. Trying to establish a common framework around GRC and good information quality is difficult because a lot of companies are dealing with common problems of critical information being stored on someone’s individual laptop or a lack of integration between the systems that support the business processes that are critical to the organization. Holly really emphasizes the fragmentation and governance issues. Ed, does that resonate with you, and are there other factors that we should also consider? EG: This resonates very well with us. From our perspective, we’ve been a very fast-growing company. In 25 years, we’ve grown significantly through mergers and acquisitions which resulted in a number of legacy systems which are fragmented around the world. This makes it difficult for us to really put together good data architecture and there is no clear taxonomy. The culture of the organization makes it extremely difficult in trying to get people to understand that this is an enterprise-wide perspective that everybody needs to address. Senior management today still doesn’t understand what we need to do in this area – there aren’t enough resources, budgets, or skills out there, which makes it even more difficult. The challenge is mirrored in almost every customer environment that we see. We always have plenty of technology, but here it seems like we are talking about information challenges. From a Cisco perspective, you too have grown by mergers and acquisitions. How much does this add to the challenge of producing high-quality information? JM: It impacts the problem significantly – even just the need for more timely and accurate information across the enterprise. What we are seeing in practice, both internally and with our customers, is that IT organizations and C-level executives are trying to maximize the lifecycle of their application environments and systems, which have been used to produce data that was fine as long as it wasn’t integrated or correlated to meet the requirements of GRC. We see a lot of human middleware then being holly roland sap HOLLY ROLAND is the VP of Marketing for SAP’s GRC business unit. In this role, she manages the marketing campaigns for SAP’s GRC products as well as contributes to leading the development of the GRC roadmap and strategy. Holly’s responsibilities also include managing industry events and creating collateral materials for the sales force. In addition, she leads the executive advisory board composed of customers, partners and SAP executives, and facilitates collaboration in the development of GRC solutions to solve industry challenges. john morrell cisco JOHN MORRELL is a Senior Director with Cisco Systems Inc., responsible for the worldwide Advanced Services AT Product Management organization developing and supporting Cisco services for advanced technologies which enable Cisco’s Service Oriented Network Architecture (SONA). John is coleading the global SONA GRC go-to-market program for Cisco Customer Advocacy. He has been involved in the joint SAPCisco GRC development program. ed glover sun microsystems ED GLOVER is currently a Senior Director at Sun Microsystems Inc., responsible for the SunIT Compliance Program. Ed’s organization plays a critical role in the implementation of SunIT’s Sarbanes-Oxley initiative and other IT compliance programs. Prior to joining SunIT, Ed worked in Sun’s Professional Services and Internal Audit organizations. Before joining Sun, Ed spent over 15 years in various capacities in the security and IT audit fields. www.BTQuarterly.com Business Trends Quarterly 25 http://www.BTQuarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.