
CTRLPhreaks (Clarissa Lucas & Bill Bensing)
Explore every episode of CTRLPhreaks
Pub. Date | Title | Duration | |
---|---|---|---|
07 Dec 2023 | How We Automated Governance with Robert Kelly | 00:49:13 | |
Clarrissa, Bill, and Robert Kelly discuss implementing automated governance systems in highly regulated organizations in this conversation. They explore the challenges of working with internal auditors and the importance of bringing auditors to the table early in the process. They emphasize the need for a culture shift and a change in mindset to ensure that automated governance solutions are integrated with internal audit processes. The conversation highlights the value of auditors in reducing risk and accelerating software delivery. Overall, the discussion provides insights into the implementation and benefits of automated governance systems. The conversation explores the integration of technologists and internal audits through automated governance. It discusses the challenges faced in bridging the gap between these two teams and the benefits of early collaboration. The concept of continuous compliance is examined, focusing on shifting towards real-time assurance. The conversation concludes with three key takeaways: the success of automated governance in various industries, the importance of bringing auditors in early, and the need to view compliance as an assurance process. Takeaways
Chapters
| |||
11 Jan 2024 | Mythbusting Agility: Agile, DevOps, and Lean Across Disciplines | 00:40:06 | |
In this episode, Clarissa & Bill promise to open up new avenues of thought! Agile, Lean, and DevOps – you've probably heard these terms thrown around in software development circles. But what if we told you these methodologies are not confined to the digital realm? Join us as we shatter this age-old myth with our guests, Robin Yeman and Suzette Johnson. Our daring duo takes us on a rollercoaster ride of their experiences, applying Agile, Lean, and DevOps in areas you'd least expect. They're not just sharing theories; they're bringing you real-life stories of implementing these dynamic practices in places ranging from auditing to operations. This episode is a treasure trove of tales and tips, perfect for anyone skeptical about mentioning 'Agile' outside the IT department. In this insightful conversation, Robin and Suzette delve into the application of engineering principles to cyber-physical systems and stress the importance of considering constraints in the design process. They talk about the need for multiple planning horizons – a strategy that ensures predictable delivery while allowing the flexibility to adjust scope and resources based on empirical data. Our guests share their journey in overcoming challenges and achieving success with new working methods. They highlight the importance of aligning on a common language and building internal support, which is essential to any transformation. Plus, they explore the concept of 'crossing the chasm', underscoring the necessity for continuous improvement in an ever-evolving digital landscape. This episode is not just about changing how you work; it's about a paradigm shift in approaching technology governance and innovation. Let's dive in!
Takeaways
Chapters
| |||
27 Jan 2024 | Harvesting Harmony: John Deere's IT & Audit Jamboree | 00:58:03 | |
In this episode, Lynn, Roberto, & Matt from John Deere discuss their digital transformation journey and its impact on IT and Internal Audit. They highlight the importance of agility in internal audit and how it helped prioritize work and enhance relationships with stakeholders. The team also shares the challenges they faced during the transformation and the strategies they used to overcome them. Additionally, they discuss the concept of defining deployable and its role in bridging the gap between technology and audit. The conversation explores the partnership between audit and other departments, the importance of metrics and measuring outcomes, applying software engineering principles to audit, and advice for implementing Agile in audit. Takeaways
| |||
26 Apr 2024 | Safety vs. Security: Why Words Matter with Sounil Yu | 00:45:17 | |
SummarySounil Yu, author of Cyber Defense Matrix, discusses the importance of terminology in cybersecurity and the distinction between safety and security. He explains how the Cyber Defense Matrix helps organize and identify gaps in security capabilities. He also introduces the concept of the D.I.E. Triad (distributed, immutable, ephemeral) and how it can reduce the impact of liabilities in cybersecurity. The conversation highlights the need to redefine the economic equation of cybersecurity from a cost to an investment. The talk explores the concepts of cyber safety and cybersecurity and how they relate to risk management and defense strategies. The guests discuss the importance of having necessary defenses in place, even for smaller businesses that may not be direct targets. They also delve into the three-line model and how it aligns with the cyber defense matrix. The matrix is a valuable tool for understanding the full scope of cybersecurity and making risk-based decisions. The conversation emphasizes the need for a common language and understanding between tech and audit professionals. Takeaways
Chapters00:00 Introduction and Background 06:18 The D.I.E. Triad 14:13 The Importance of Terminology 26:40 Risk Tolerance and Risk Appetite 35:07 The Role of Language and Common Understanding | |||
30 Nov 2023 | Developer Productivity Engineering (DPE), Audit, and GRC with Justin Reock | 00:46:10 | |
Clarissa Lucas and Bill Bensing interview Justin Reock about Developer Productivity Engineering (DPE) and its role in auditing and governance. They discuss the importance of measuring engineering productivity, observing the value stream, and identifying bottlenecks and impediments to productivity. They also explore the concept of proactive risk management and the need for partnership between developers and auditors. The conversation highlights the challenges of breaking silos and the potential for DPE to reduce developer toil and improve overall software quality. They conclude by reframing auditing as a way to fight cyber criminals and protect against exploitation. The conversation explores the intersection of auditing, governance, risk, and compliance (GRC) with the tech industry. It highlights the need for empathy, partnership, and bridging the gap between developers and auditors. The toxic mentality in the tech industry is also discussed. Follow Justin:
Takeaways
Chapters
| |||
15 Dec 2023 | Coffee Clatch For A Better Batch with Jeffrey Fredrick | 00:49:09 | |
In this conversation, Bill and Clarissa discuss the importance of effective conversations with “Agile Conversations” co-author Jeffrey Frederick. Overall, the episode emphasizes the power of conversations in reducing unnecessary pain and improving collaboration in various domains. They explore the concept of Taylorism and its impact on management philosophies, highlighting the need for a more human-centered approach. The conversation also touches on the biases present in traditional auditing processes and the importance of recognizing and overcoming them. In this episode, Jeffrey Fredrick discusses the importance of effective conversations in auditing and other professional contexts. He emphasizes the need for alignment and shared understanding in conversations, especially when auditors and clients have different perspectives. Jeffrey introduces the concept of the Four Rs (Record, Reflect, Revise, Role Play) as a tool for improving conversational skills. He explains each step of the Four Rs and highlights the importance of genuine curiosity and transparency in conversations. Jeffrey also discusses the ladder of inference and how it can help auditors and clients overcome challenges related to understanding each other's businesses. He concludes by emphasizing the need for practice and continuous improvement in conversational skills.
Takeaways
Chapters
| |||
20 Apr 2024 | Policy as Code: An Audit-Tech Peacekeeper with Mike Leuzinger and Andy Kolenko | 00:41:08 | |
SummaryIn this episode, Mike Leuzinger and Andy Kolenko discuss policy as code from a technology and audit perspective. Policy as code extends infrastructure as code, allowing organizations to automate and manage policies across multiple technology stacks. It can enable continuous compliance, self-service for auditors, and more robust controls through automation. However, challenges include dealing with heterogeneity and the complexity of new technologies. Bridging the gap between technologists and auditors is crucial for successful implementation. The conversation explores the challenges and benefits of implementing policy as code in an organization. Mike, Andy, Clariss, and Bill discuss the complexity of keeping up with proprietary schemas and controls and the importance of relying on vendors and industry standards. They also touch on the responsibility of setting and managing Policy as Code, highlighting the industry's lack of established processes and ownership. The conversation emphasizes the need for collaboration between auditors and technology partners and the importance of staying updated on compliance guidance and leveraging tools like Open Policy Agent and the AWS Well-Architected Framework. Takeaways
|