SlideShare a Scribd company logo
© 2019 ControlCase All Rights Reserved
Your IT Compliance Partner –
Go Beyond the Checklist
Vendor Response
Management
© 2019 ControlCase All Rights Reserved
Our Agenda 2
4
2
3
Your IT Compliance
Partner –
Go beyond the
checklist
ControlCase Introduction
About Vendor Risk Management
Common Challenges
Techniques To Increase Efficiencies
Why ControlCase5
1
© 2019 ControlCase All Rights Reserved
ControlCase Introduction1
© 2019 ControlCase All Rights Reserved
ControlCase Snapshot 4
Certification and ContinuousCompliance Services
Go beyond the auditor’s checklist to:
Dramatically cut the time, cost and burden from becoming certified and
maintaining IT compliance
• Demonstrate compliance more efficiently
and cost effectively (cost certainty)
• Improve efficiencies
• Do more with less resources and gain
compliance peace of mind
• Free up your internal resources to focus
on their priorities
• Offload much of the compliance burden
to a trusted compliance partner
1000+
Clients
300+
Security Experts
10,000+
IT Security Certifications
© 2019 ControlCase All Rights Reserved
Solution 5
Certification and Continuous Compliance Services
Automation
-DrivenSkyCAM
Partnership
Approach
IT Certification
Services
Continuous Compliance
Services
“I’ve worked on both sides of
auditing. I have not seen any
other firm deliver the same
product and service with the
same value. No other firm
provides that continuous
improvement and the level of
detail and responsiveness.”
Security and Compliance
Manager, Data Center
© 2019 ControlCase All Rights Reserved
Certification Services 6
OneAudit – Collect Once, Certify Many
PCI DSS ISO 27001 &
27002
SOC 1, SOC 2, SOC 3,
& SOC for Cybersecurity HITRUST CSF
HIPAA PCI P2PE GDPR NIST 800-53
PCI PIN PCI PA-DSS SCA PCI 3DS
“You have 27 seconds to make a
first impression. And after our
initial meeting, it became clear
that they were more interested
in helping our business and
building a relationship, not just
getting the business.”
Sr. Director, Information Risk &
Compliance, Large Merchant
Automation-
DrivenSkyCAM
Partnership
Approach
IT Certification
Services
Continuous Compliance
Services
© 2019 ControlCase All Rights Reserved
About Vendor Risk Management2
© 2019 ControlCase All Rights Reserved
Vendor Risk Management 8
 Vendor risk management is the process organizations use to understand
the risks that exist and the risks that they assume due to their business
relationships with third-party vendors.
 Vendor risk management is now a standard practice
 As a result, organizations are increasingly required to respond to their
customers requests
 59% of companies experienced a third-party breach in 2018 (Ponemon
Survey) – which costs millions of dollars and reputational damage to
large companies
© 2019 ControlCase All Rights Reserved
Common Process Used To Manage Vendors 9
Register/Inventory
vendors
Categorize vendors
Map controls to
categories
Create vendor risk
assessment
questionnaire
Create master control
checklist
Distribute
questionnaire to
vendors
Analyze responses
and attachments
Track exceptions to
closure
Provide a Data
Security Rating
© 2019 ControlCase All Rights Reserved
Common Challenges3
© 2019 ControlCase All Rights Reserved
Current Status 11
 Organizations receive multiple vendor risk questionnaires from their
customers
 Each customer uses their own templates, processes and requirements -
making it challenging to respond to all customers in a timely manner
 Vendor response management is being done manually.
Vendor Response Management is increasingly taking valuable time and
resources for already busy security/compliance experts.
© 2019 ControlCase All Rights Reserved
Common Challenges to Vendor Response Management 12
Time
• The process of responding to vendor risk management is time
consuming.
Resources
• Lack of resources to manage the process.
Cost
• Cost of hiring additional resources and complying to multiple
regulations.
Risk of Business Loss
• Risk of loosing business if you cannot comply with customer process
© 2019 ControlCase All Rights Reserved
Techniques To Increase Efficiencies5
© 2019 ControlCase All Rights Reserved
Multi-Threaded Approach 14
Continuous
Improvement
Identify
Common
Categories
Create
Repository
Integrate IT
Assessments
with Vendor
Response
Process
Have
“Standardized”
Verbiage
© 2019 ControlCase All Rights Reserved
Identify Common Categories 15
 Scoping
 Anti-Malware
 Application Security
 BCP/DR
 Change Management
 Configuration Management
 Data Encryption At Rest
 Data Encryption In Transit
 Governance And Compliance
 HR
 Incident Response
 Logging & Monitoring
 Logical Access
 Network
 Physical Security
 Policies & Procedures
 Privacy
 Processing Integrity
 Risk Assessment
 Security Testing
 Third Party Management
© 2019 ControlCase All Rights Reserved
Create
Repository for
“Single
Assessment
Data &
Responses”
16
16
© 2019 ControlCase All Rights Reserved
Integrate Vendor Response Management With Assessments 17
Consolidated
Repository for all
assessment data
• Consolidated Repository
• Using Technology and Integrated Checklist
HIPAA
Assessment
PCI DSS
Assessment
Deliverables
a. HIPAA Assessment Report
b. PCI DSS Report on
Compliance
c. Vendor Responses
Vendor
Responses
© 2019 ControlCase All Rights Reserved
Standardized Verbiage (Examples) 18
 “ControlCase tests its annual BCP/DR plan semi-annually. The last time it was
tested was July 15, 2019”
 “ControlCase protects all PII related to its credit card processing system
using AES-256 encryption”
 “ControlCase performs monthly vulnerability scanning. The last scan on July
5, 2019 found 2 medium and 1 low risk vulnerabilities. These were corrected
and retested on July 12, 2019. New scan results verified that the
vulnerabilities were addressed appropriately”
© 2019 ControlCase All Rights Reserved
Why ControlCase5
© 2019 ControlCase All Rights Reserved
Multi-Threaded Approach 20
Vendor
Responses
Skilled personnel to
document responses
Technology/Dataroom
for IT Responses
integrated with IT
Assessments
Process that includes
automation to collect
and maintain evidence
© 2019 ControlCase All Rights Reserved
ControlCase Vendor Response Management Solution 21
01 02
0304
STEP 2
Questionnaire completed
Small/Medium questionnaire (3 business days)
Medium/Large questionnaire (5 business days)
STEP 3
Document Quality Assurance
(2 business days)
REPEATABLE PROCESS
PHASE 4
Delivery within defined SLA
STEP 1
Assessment Received and Assigned
© 2019 ControlCase All Rights Reserved
ControlCase Certification Outcomes 22
“It’s a challenge keeping up with the
changing compliance landscape. Given
that we had GDPR and now the
California data privacy law, not to
mention HIPAA and others, there are a
lot of regulations and frameworks to
keep up with and a lot of time spent
preparing for audits. That puts a lot of
overhead and strain on me and my
team. We just don’t have the expertise
or time to keep up.
Before
ControlCase
“We cut audit prep time by 70% using
ConrolCase. It was their partner approach to us;
a combination of their expertise, their
responsiveness and automation. They brought us
great ideas on how to streamline our process,
and we were able to take advantage of
automated data collection. And, their IT
Compliance Portal gave us visibility throughout
the entire process.
Another thing - We don’t look at compliance as a
once a year event, and now, with ControlCase’s
Continuous Compliance services, we have the
visibility into what’s in compliance and what’s not
all year long. We can quickly remediate an issue
before it becomes a security threat.”
With ControlCase
Cut audit prep time by 70%
© 2019 ControlCase All Rights Reserved
Summary – Why ControlCase 23
“They provide excellent service, expertise and technology. And, the
visibility into my compliance throughout the year and during the audit
process provide a lot of value to us.”
Dir. of Compliance, SaaS company
Your IT Compliance Partner –
Go beyond the auditor’s checklist
Partnership
Approach
SkyCAM
IT
Compliance
Portal
Automation
driven Continuous Compliance
Services
© 2019 ControlCase All Rights Reserved
Email
contact@controlcase.com
Telephone
Americas +1.703-483-6383
India: +91.22.50323006
Social Media
Conection Suport
www.facebook.com/user
www.linkin.com/user
Visit our website
www.controlcase.com
THANK YOU FOR THE OPPORTUNITY TO
CONTRIBUTE TO YOUR
IT COMPLIANCE PROGRAM

More Related Content

PPTX
Continuous Compliance Monitoring
PPTX
Continuous Compliance Monitoring
PPTX
General Data Protection Regulation (GDPR)
PPTX
PCI DSS Business as Usual (BAU)
PPTX
Vendor Management for PCI DSS, HIPAA, and FFIEC
PPTX
Integrated Compliance – Collect Evidence Once, Certify to Many
PPTX
Performing One Audit Using Zero Trust Principles
PPTX
PCI DSS and PA DSS Compliance
Continuous Compliance Monitoring
Continuous Compliance Monitoring
General Data Protection Regulation (GDPR)
PCI DSS Business as Usual (BAU)
Vendor Management for PCI DSS, HIPAA, and FFIEC
Integrated Compliance – Collect Evidence Once, Certify to Many
Performing One Audit Using Zero Trust Principles
PCI DSS and PA DSS Compliance

What's hot (20)

PPTX
Log Monitoring and File Integrity Monitoring
PPTX
Docker container webinar final
PPTX
PCI DSS Business as Usual
PPTX
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
PPTX
PCI PIN Security & Key Management Compliance
PPTX
PCI DSS and Other Related Updates
PPTX
Integrated Compliance
PPTX
SOC 2 Compliance and Certification
PPTX
Continuous Compliance Monitoring
PDF
Introduction to Token Service Provider (TSP) Certification
PPTX
PCI DSS Compliance Checklist
PPTX
Healthcare Compliance: HIPAA and HITRUST
PPTX
OneAudit™ - Assess Once, Certify to Many
PPTX
Performing PCI DSS Assessments Using Zero Trust Principles
PDF
Agiliance Wp Key Steps
PPTX
PCI DSS Compliance in the Cloud
PPTX
Integrated Compliance
PPTX
FedRAMP Certification & FedRAMP Marketplace
PPTX
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
PDF
Soc 2 vs iso 27001 certification withh links converted-converted
Log Monitoring and File Integrity Monitoring
Docker container webinar final
PCI DSS Business as Usual
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
PCI PIN Security & Key Management Compliance
PCI DSS and Other Related Updates
Integrated Compliance
SOC 2 Compliance and Certification
Continuous Compliance Monitoring
Introduction to Token Service Provider (TSP) Certification
PCI DSS Compliance Checklist
Healthcare Compliance: HIPAA and HITRUST
OneAudit™ - Assess Once, Certify to Many
Performing PCI DSS Assessments Using Zero Trust Principles
Agiliance Wp Key Steps
PCI DSS Compliance in the Cloud
Integrated Compliance
FedRAMP Certification & FedRAMP Marketplace
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Soc 2 vs iso 27001 certification withh links converted-converted
Ad

Similar to Vendor risk management webinar 10022019 v1 (20)

PDF
Oracle OpenWorld 2014 GRC events and sessions
PDF
Logging and Automated Alerting Webinar.pdf
PPTX
Managing Multiple Assessments Using Zero Trust Principles
PPTX
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
PPTX
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
PPT
Vendor Management - Compliance Checklist Manifesto Series
PDF
Gain business insight with Continuous Controls Monitoring
PPTX
Supply Chain and Third-Party Risks During COVID-19
PPT
Improve Regulatory Compliance & Risk Management Using Best Practices
PPTX
Oow2014 nk 2
PPTX
HITRUST Overview and AI Assessments Webinar.pptx
PPTX
Integrated Compliance Webinar.pptx
PDF
Penetration Testing Basics Webinar ControlCase
PPTX
Webinar-MSP+ Cyber Insurance Fina.pptx
PDF
Healthcare Cybersecurity Survey 2018 - Sirius
PDF
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
PDF
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
PPTX
Privacy & Security Controls In Vendor Management Al Raymond
PDF
Risk & Compliance Outlook 2011
PDF
#OOW16 - Introducing Oracle Financial Reporting Compliance Cloud Service
Oracle OpenWorld 2014 GRC events and sessions
Logging and Automated Alerting Webinar.pdf
Managing Multiple Assessments Using Zero Trust Principles
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Vendor Management - Compliance Checklist Manifesto Series
Gain business insight with Continuous Controls Monitoring
Supply Chain and Third-Party Risks During COVID-19
Improve Regulatory Compliance & Risk Management Using Best Practices
Oow2014 nk 2
HITRUST Overview and AI Assessments Webinar.pptx
Integrated Compliance Webinar.pptx
Penetration Testing Basics Webinar ControlCase
Webinar-MSP+ Cyber Insurance Fina.pptx
Healthcare Cybersecurity Survey 2018 - Sirius
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
Privacy & Security Controls In Vendor Management Al Raymond
Risk & Compliance Outlook 2011
#OOW16 - Introducing Oracle Financial Reporting Compliance Cloud Service
Ad

More from ControlCase (16)

PDF
Navigating Compliance for MSPs From First Audit to Monetization
PDF
Principes de base des tests d’intrusion Webinar
PDF
PCI PIN Basics Webinar from the Controlcase Team
PDF
Maintaining Data Privacy with Ashish Kirtikar
PDF
PCI DSS v4 - ControlCase Update Webinar Final.pdf
PDF
ISO 27001 2002 Update Webinar.pdf
PDF
2022-Q2-Webinar-ISO_Spanish_Final.pdf
PDF
French PCI DSS v4.0 Webinaire.pdf
PDF
DFARS CMMC SPRS NIST 800-171 Explainer.pdf
PDF
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
PDF
Webinar-Spanish-PCI DSS-4.0.pdf
PDF
2022 Webinar - ISO 27001 Certification.pdf
PPTX
PCI DSS 4.0 Webinar Final.pptx
PPTX
Webinar - CMMC Certification.pptx
PPTX
HITRUST Certification
PPTX
CMMC Certification
Navigating Compliance for MSPs From First Audit to Monetization
Principes de base des tests d’intrusion Webinar
PCI PIN Basics Webinar from the Controlcase Team
Maintaining Data Privacy with Ashish Kirtikar
PCI DSS v4 - ControlCase Update Webinar Final.pdf
ISO 27001 2002 Update Webinar.pdf
2022-Q2-Webinar-ISO_Spanish_Final.pdf
French PCI DSS v4.0 Webinaire.pdf
DFARS CMMC SPRS NIST 800-171 Explainer.pdf
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
Webinar-Spanish-PCI DSS-4.0.pdf
2022 Webinar - ISO 27001 Certification.pdf
PCI DSS 4.0 Webinar Final.pptx
Webinar - CMMC Certification.pptx
HITRUST Certification
CMMC Certification

Recently uploaded (20)

PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Cloud computing and distributed systems.
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Electronic commerce courselecture one. Pdf
PPTX
A Presentation on Artificial Intelligence
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Machine learning based COVID-19 study performance prediction
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Approach and Philosophy of On baking technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Network Security Unit 5.pdf for BCA BBA.
Cloud computing and distributed systems.
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
The AUB Centre for AI in Media Proposal.docx
Electronic commerce courselecture one. Pdf
A Presentation on Artificial Intelligence
“AI and Expert System Decision Support & Business Intelligence Systems”
20250228 LYD VKU AI Blended-Learning.pptx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
Review of recent advances in non-invasive hemoglobin estimation
NewMind AI Weekly Chronicles - August'25 Week I
Machine learning based COVID-19 study performance prediction
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Spectral efficient network and resource selection model in 5G networks
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Approach and Philosophy of On baking technology

Vendor risk management webinar 10022019 v1

  • 1. © 2019 ControlCase All Rights Reserved Your IT Compliance Partner – Go Beyond the Checklist Vendor Response Management
  • 2. © 2019 ControlCase All Rights Reserved Our Agenda 2 4 2 3 Your IT Compliance Partner – Go beyond the checklist ControlCase Introduction About Vendor Risk Management Common Challenges Techniques To Increase Efficiencies Why ControlCase5 1
  • 3. © 2019 ControlCase All Rights Reserved ControlCase Introduction1
  • 4. © 2019 ControlCase All Rights Reserved ControlCase Snapshot 4 Certification and ContinuousCompliance Services Go beyond the auditor’s checklist to: Dramatically cut the time, cost and burden from becoming certified and maintaining IT compliance • Demonstrate compliance more efficiently and cost effectively (cost certainty) • Improve efficiencies • Do more with less resources and gain compliance peace of mind • Free up your internal resources to focus on their priorities • Offload much of the compliance burden to a trusted compliance partner 1000+ Clients 300+ Security Experts 10,000+ IT Security Certifications
  • 5. © 2019 ControlCase All Rights Reserved Solution 5 Certification and Continuous Compliance Services Automation -DrivenSkyCAM Partnership Approach IT Certification Services Continuous Compliance Services “I’ve worked on both sides of auditing. I have not seen any other firm deliver the same product and service with the same value. No other firm provides that continuous improvement and the level of detail and responsiveness.” Security and Compliance Manager, Data Center
  • 6. © 2019 ControlCase All Rights Reserved Certification Services 6 OneAudit – Collect Once, Certify Many PCI DSS ISO 27001 & 27002 SOC 1, SOC 2, SOC 3, & SOC for Cybersecurity HITRUST CSF HIPAA PCI P2PE GDPR NIST 800-53 PCI PIN PCI PA-DSS SCA PCI 3DS “You have 27 seconds to make a first impression. And after our initial meeting, it became clear that they were more interested in helping our business and building a relationship, not just getting the business.” Sr. Director, Information Risk & Compliance, Large Merchant Automation- DrivenSkyCAM Partnership Approach IT Certification Services Continuous Compliance Services
  • 7. © 2019 ControlCase All Rights Reserved About Vendor Risk Management2
  • 8. © 2019 ControlCase All Rights Reserved Vendor Risk Management 8  Vendor risk management is the process organizations use to understand the risks that exist and the risks that they assume due to their business relationships with third-party vendors.  Vendor risk management is now a standard practice  As a result, organizations are increasingly required to respond to their customers requests  59% of companies experienced a third-party breach in 2018 (Ponemon Survey) – which costs millions of dollars and reputational damage to large companies
  • 9. © 2019 ControlCase All Rights Reserved Common Process Used To Manage Vendors 9 Register/Inventory vendors Categorize vendors Map controls to categories Create vendor risk assessment questionnaire Create master control checklist Distribute questionnaire to vendors Analyze responses and attachments Track exceptions to closure Provide a Data Security Rating
  • 10. © 2019 ControlCase All Rights Reserved Common Challenges3
  • 11. © 2019 ControlCase All Rights Reserved Current Status 11  Organizations receive multiple vendor risk questionnaires from their customers  Each customer uses their own templates, processes and requirements - making it challenging to respond to all customers in a timely manner  Vendor response management is being done manually. Vendor Response Management is increasingly taking valuable time and resources for already busy security/compliance experts.
  • 12. © 2019 ControlCase All Rights Reserved Common Challenges to Vendor Response Management 12 Time • The process of responding to vendor risk management is time consuming. Resources • Lack of resources to manage the process. Cost • Cost of hiring additional resources and complying to multiple regulations. Risk of Business Loss • Risk of loosing business if you cannot comply with customer process
  • 13. © 2019 ControlCase All Rights Reserved Techniques To Increase Efficiencies5
  • 14. © 2019 ControlCase All Rights Reserved Multi-Threaded Approach 14 Continuous Improvement Identify Common Categories Create Repository Integrate IT Assessments with Vendor Response Process Have “Standardized” Verbiage
  • 15. © 2019 ControlCase All Rights Reserved Identify Common Categories 15  Scoping  Anti-Malware  Application Security  BCP/DR  Change Management  Configuration Management  Data Encryption At Rest  Data Encryption In Transit  Governance And Compliance  HR  Incident Response  Logging & Monitoring  Logical Access  Network  Physical Security  Policies & Procedures  Privacy  Processing Integrity  Risk Assessment  Security Testing  Third Party Management
  • 16. © 2019 ControlCase All Rights Reserved Create Repository for “Single Assessment Data & Responses” 16 16
  • 17. © 2019 ControlCase All Rights Reserved Integrate Vendor Response Management With Assessments 17 Consolidated Repository for all assessment data • Consolidated Repository • Using Technology and Integrated Checklist HIPAA Assessment PCI DSS Assessment Deliverables a. HIPAA Assessment Report b. PCI DSS Report on Compliance c. Vendor Responses Vendor Responses
  • 18. © 2019 ControlCase All Rights Reserved Standardized Verbiage (Examples) 18  “ControlCase tests its annual BCP/DR plan semi-annually. The last time it was tested was July 15, 2019”  “ControlCase protects all PII related to its credit card processing system using AES-256 encryption”  “ControlCase performs monthly vulnerability scanning. The last scan on July 5, 2019 found 2 medium and 1 low risk vulnerabilities. These were corrected and retested on July 12, 2019. New scan results verified that the vulnerabilities were addressed appropriately”
  • 19. © 2019 ControlCase All Rights Reserved Why ControlCase5
  • 20. © 2019 ControlCase All Rights Reserved Multi-Threaded Approach 20 Vendor Responses Skilled personnel to document responses Technology/Dataroom for IT Responses integrated with IT Assessments Process that includes automation to collect and maintain evidence
  • 21. © 2019 ControlCase All Rights Reserved ControlCase Vendor Response Management Solution 21 01 02 0304 STEP 2 Questionnaire completed Small/Medium questionnaire (3 business days) Medium/Large questionnaire (5 business days) STEP 3 Document Quality Assurance (2 business days) REPEATABLE PROCESS PHASE 4 Delivery within defined SLA STEP 1 Assessment Received and Assigned
  • 22. © 2019 ControlCase All Rights Reserved ControlCase Certification Outcomes 22 “It’s a challenge keeping up with the changing compliance landscape. Given that we had GDPR and now the California data privacy law, not to mention HIPAA and others, there are a lot of regulations and frameworks to keep up with and a lot of time spent preparing for audits. That puts a lot of overhead and strain on me and my team. We just don’t have the expertise or time to keep up. Before ControlCase “We cut audit prep time by 70% using ConrolCase. It was their partner approach to us; a combination of their expertise, their responsiveness and automation. They brought us great ideas on how to streamline our process, and we were able to take advantage of automated data collection. And, their IT Compliance Portal gave us visibility throughout the entire process. Another thing - We don’t look at compliance as a once a year event, and now, with ControlCase’s Continuous Compliance services, we have the visibility into what’s in compliance and what’s not all year long. We can quickly remediate an issue before it becomes a security threat.” With ControlCase Cut audit prep time by 70%
  • 23. © 2019 ControlCase All Rights Reserved Summary – Why ControlCase 23 “They provide excellent service, expertise and technology. And, the visibility into my compliance throughout the year and during the audit process provide a lot of value to us.” Dir. of Compliance, SaaS company Your IT Compliance Partner – Go beyond the auditor’s checklist Partnership Approach SkyCAM IT Compliance Portal Automation driven Continuous Compliance Services
  • 24. © 2019 ControlCase All Rights Reserved Email contact@controlcase.com Telephone Americas +1.703-483-6383 India: +91.22.50323006 Social Media Conection Suport www.facebook.com/user www.linkin.com/user Visit our website www.controlcase.com THANK YOU FOR THE OPPORTUNITY TO CONTRIBUTE TO YOUR IT COMPLIANCE PROGRAM

Editor's Notes

  • #5: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #9: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #10: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #12: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #15: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #16: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #17: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #18: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #19: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #21: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #22: Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.  
  • #23: Arm you with the data and reports that make sense to business executives and tie to business goals
  • #24: Partnership Approach – Proactive expertise, responsive support and new, innovative ideas to streamline and improve compliance Right mix of size and responsiveness - We’re big enough to provide comprehensive compliance services, but agile enough to deliver responsive client care and support Automation-Driven – Take advantage of automation to cut time and costs and improve efficiencies in becoming certified and maintaining compliance ControlCase IT Compliance Portal Automated evidence collection – on prem or in the cloud Real-time Certification Dashboard AI-powered Predictive Compliance Go beyond monitoring and alerting to predict, prioritize and remediate compliance risk before they become security threats GRC Platform integration Continuous Compliance – Use ControlCase’s continuous compliance services to maintain compliance continuously in between annual certification efforts, because point-in-time, snap-shot compliance doesn’t effectively keep your company compliant or secure Predict, prioritize and remediate compliance risks before they become security threats