SlideShare une entreprise Scribd logo
1  sur  36
Télécharger pour lire hors ligne
RESPONSIVE GOVERNANCE FOR
EVOLUTIONARY TECHNOLOGY PLATFORMS
Heiko Gerin
Things to cover
● Evolutionary technology platforms & governance
● Things to govern & common friction points
● Governance principles: what we’ve seen working
● Common limitations & exciting stuff
Evolutionary Technology Platforms
● Support incremental, constant change
● Are built in a way that is appropriately coupled
● Optimise for high delivery velocity & quality
● Promote end-to-end ownership and accountabilities
● Deliver through cross-functional teams aligned to
business outcomes
Evolutionary Technology Platforms
● Include people, process and technology
● Change rapidly and constantly
● Appropriate governance changes with the
requirements and the environment
● Needs to be responsive to evolve
Definitions: GRC
IT Governance provides a structure for aligning IT strategy with business
strategy;
Ensures Risk is identified and addressed and
Ensures Compliance to laws and regulations
Definition Paraphrased from
Wikipedia
Ensure we understand
potential risks and
mitigate them
Ensure that we do the right
things (aligned to business
goals)
Ensure that we do things
the right way (within laws
and regulations)
http://jonnyschneider.com/
Why the friction?
1. Governance tends to come in extremes
2. Governance implemented can’t
support constant change
1. Governance tends to come in extremes
Big Corporate
Governance Extremes: How governance “happens”
Startup
Super Scale-Up
Global Scale
Medium Scale-Up
Single Market
Small Scale-Up
Single Segment
Large Scale-Up
Multi Market
Sudden influx of
cash
Entered regulated
industry
High profile Outage
/Privacy Breach
IPO, acquisition
A few words on Governance Frameworks
● Service Management ITIL, SIAM, ISO/IEC20000
● Security ISO 27001
● Risk COSO
● Architecture TOGAF
● Process improvement CMMI
● Governing governance COBIT
“The collective memory of all things that have ever
gone wrong in this and every other organisation”
Governance areas
Program / Project Governance
Prioritisation, Portfolio Management
Architectural Governance
Data, APIs, Service Design, Review Boards
Change & Release
Quality, Versioning, Change advisory boards,
Config Management Databases
Risk & Security
Reviews boards, Code scanning, Pen testing,
Enterprise Security Services
Business Continuity / DR
Disaster Recovery Exercises
& Requirements
Audit & Compliance
Government regulations, Internal & external
audit activities
Funding Model
Project based or capacity based
2. Implementation can’t support constant change
● Some frameworks are products of their time
● Implementations tend to reinforce silos
(Tragedy of the commons)
● “Governance events” cause big bang rollouts
● Implementations of controls and policies
○ designed for a more traditional delivery
and op model
○ Non-responsive (static or changeable
only by committee)
Governance Extremes: Examples
Complete lack of repeatability and
documentation
Overly bureaucratic and wasteful processes
No accountability for Information Security,
Change Management or Operations
Siloed functions that don't work effectively
together
No traceability of changes or decisions made Long wait times for rubber-stamp approvals
that are largely theater
Uncontrollable technology and tool sprawl Policies dictated by people that don't feel the
impact of their decisions
VS
VS
VS
VS
Governance Principles
Automate compliance
but enable assurance
Focus on vision,
principles & constraints
From gatekeepers to
facilitators & partners
Provide paved roads:
the pit of success
Evolve the operating
model
Automate compliance and enable assurance
● Embed governance & compliance requirements
in operational runtime monitoring of the platform
● Evaluate as part of the delivery pipeline (blocking)
● Enable & promote independent
verification & audit (non-blocking)
● Take a risk based approach to
prevent bottom-up audit
Preventing Bottom Up Audit
Audit Lifecycle:
- Business objectives
- Identified Risks
- Control objectives
- Mitigating procedures
- Verify & Adapt
Corporate Folklore
Focus on vision, principles & constraints
● Move away from specifying tools, processes and solutions
● Frame needs as visions, principles and constraints
● Degree of autonomy to make implementation choices
(“Docker” is not a principle)
● Target outcomes over specific implementations
● Guardrails
The Leviathan
Internal Technology Radar
● Catalyst for architectural conversations
● Visibility across teams
● Discipline around moving between
assess, trial, adopt and hold
● Apply WIP limits
Tech radar used for lightweight governance
From gatekeepers to facilitators
Avoid using sparse skill-sets as enforcement
agencies: Operations, Compliance, Risk, Security, ...
Amplify them to increase their effectiveness:
● Expert advisors for teams, facilitating, coaching
and advising
● Articulate principles and constraints - but also
help implement them
Years & years of penetration
tests
Change Control
● Peer review is the most effective form of change control
● Pre-approved (ITIL) standard changes
● De-risk changes using Continuous Delivery
● Automate compliance
● Distributed, electronic CABs & subgroups
The perfect CMDB & CABs all
the way down
Provide paved roads & the pit of success
● Centralised supporting platforms as a product
● Teams focus on delivering business value while
complying with overall guardrails
● The pit of success - make it easy
to do the right thing
● Customer centricity
● Non-mandatory
If all you have is a hammer
Introducing “Goldilocks” governance:
Evolve the operating model
● Define activities and do a RACI - before & after
● Adapt accountabilities & responsibilities
● Start small, experiment
● Exemplar teams
● New acceptance criteria, definitions of done
Big bang rollout
Evolve the operating model: RACIs
Evolve the operating model
Governance Principles
Automate compliance
but enable assurance
Focus on vision,
principles & constraints
From gatekeepers to
facilitators & partners
Provide paved roads:
the pit of success
Evolve the operating
model
Common limitations (they’re mostly technical)
● Compliance as code is not really there yet
● No real standards ways of governing cloud infrastructure
● Bespoke, hand crafted implementations & formats
Exciting things happening!
● Using the cloud to govern the cloud (prowler, AWS config rules, etc.)
● Kubernetes as a basic “cloud agnostic” infra building block
● Grafeas/Kritis for compliance as code
● Binary authorization as a first class cloud service (like GKE on Google Cloud)
Grafeas/Binary Auth
Thank you!
Heiko Gerin
hgerin@thoughtworks.com
Q&A
Audit Alpaca found on reddit
"Tripod Candlestand" is licensed
under CC BY 3.0
"Warm and fluffy" by ILYA Denisenko is
licensed under CC BY-NC 4.0
"Negative - Walla Walla, New South Wales,
1932" is licensed under CC PDM 1.0
"Gatekeepers" by Suzanne Brandt is licensed
under CC BY-NC-ND 4.0
"change" is licensed under CC0 1.0
"Pavement Loop" by Alex Varanese is
licensed under CC BY-NC 4.0
"Smoking Kaiju robot is licensed under CC
BY-NC 3.0
SANS secure DevOps Toolchain Poster
Cumulative controls
Sensitivity
Criticality
SoR
AnalyticsWebapp
Infra
LowHigh
HighLow
Architectural Principles
http://engineering-principles.jl-engineering.net
● Not hard and fast rules but guidelines
● Could also be used in a 'discovery phase'
to select new products or tools
● Probably no more than 10
● Govern them via fitness functions
Cloud Native
Build systems that are native to cloud
environments.
Rationale, Implications (prefer
open tooling, etc …), Examples
Evolve the operating model
Evolve the operating model

Contenu connexe

Tendances

PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Bankingsenakafdo
 
Tech Trends 2018 - Deloitte
Tech Trends 2018 - DeloitteTech Trends 2018 - Deloitte
Tech Trends 2018 - DeloitteTaylor Murphy
 
ArabNet Beirut - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
ArabNet Beirut  - Keynote: Open Banking - To be or not to be? by Open Bank Pr...ArabNet Beirut  - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
ArabNet Beirut - Keynote: Open Banking - To be or not to be? by Open Bank Pr...ArabNet ME
 
Technology and Innovation in Financial Services Scenarios
Technology and Innovation in Financial Services ScenariosTechnology and Innovation in Financial Services Scenarios
Technology and Innovation in Financial Services ScenariosWorldEconomicForumDavos
 
Le white paper de l'Ilnas sur la blockchain et les DLT
Le white paper de l'Ilnas sur la blockchain et les DLTLe white paper de l'Ilnas sur la blockchain et les DLT
Le white paper de l'Ilnas sur la blockchain et les DLTPaperjam_redaction
 
2019 outlook : 3 key trends that will impact digital-first banking
2019 outlook : 3 key trends that will impact digital-first banking2019 outlook : 3 key trends that will impact digital-first banking
2019 outlook : 3 key trends that will impact digital-first bankingBackbase
 
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...CA Technologies
 
IT funding made to measure
IT funding made to measureIT funding made to measure
IT funding made to measureAike Hurkens
 
Retail banker intl
Retail banker intl Retail banker intl
Retail banker intl Backbase
 
[Webinar] - Intelligent Automation: Enabling Bots with Brain
[Webinar] - Intelligent Automation: Enabling Bots with Brain[Webinar] - Intelligent Automation: Enabling Bots with Brain
[Webinar] - Intelligent Automation: Enabling Bots with BrainJK Tech
 
[AI Webinar Series P1] - How Advanced Text Analytics Can Increase the Operati...
[AI Webinar Series P1] - How Advanced Text Analytics Can Increase the Operati...[AI Webinar Series P1] - How Advanced Text Analytics Can Increase the Operati...
[AI Webinar Series P1] - How Advanced Text Analytics Can Increase the Operati...JK Tech
 
Realising Digital’s Full Potential in the Value Chain
Realising Digital’s Full Potential in the Value ChainRealising Digital’s Full Potential in the Value Chain
Realising Digital’s Full Potential in the Value ChainCognizant
 
Webinar (UK/Europe) - Demystifying SAP S/4HANA
Webinar (UK/Europe) - Demystifying SAP S/4HANAWebinar (UK/Europe) - Demystifying SAP S/4HANA
Webinar (UK/Europe) - Demystifying SAP S/4HANAJK Tech
 
The New Role of the Architect - Central to growing your business in today’s d...
The New Role of the Architect - Central to growing your business in today’s d...The New Role of the Architect - Central to growing your business in today’s d...
The New Role of the Architect - Central to growing your business in today’s d...Capgemini
 
Company Profile – Sankalp Tech (MLM Software)
Company Profile – Sankalp Tech (MLM Software)Company Profile – Sankalp Tech (MLM Software)
Company Profile – Sankalp Tech (MLM Software)Sankalp
 
Global CIO Banking Summit - Workshop Cultural Changes to Survive Digital Disr...
Global CIO Banking Summit - Workshop Cultural Changes to Survive Digital Disr...Global CIO Banking Summit - Workshop Cultural Changes to Survive Digital Disr...
Global CIO Banking Summit - Workshop Cultural Changes to Survive Digital Disr...Jeremy Brown
 
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIsAPIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIsJeremy Brown
 
3.FINTECH Course NMIMS -UNDERSTANDING TECH in Fintech
3.FINTECH Course NMIMS -UNDERSTANDING TECH in Fintech3.FINTECH Course NMIMS -UNDERSTANDING TECH in Fintech
3.FINTECH Course NMIMS -UNDERSTANDING TECH in FintechNiraj Vaidya
 

Tendances (20)

PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Banking
 
Tech Trends 2018 - Deloitte
Tech Trends 2018 - DeloitteTech Trends 2018 - Deloitte
Tech Trends 2018 - Deloitte
 
ArabNet Beirut - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
ArabNet Beirut  - Keynote: Open Banking - To be or not to be? by Open Bank Pr...ArabNet Beirut  - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
ArabNet Beirut - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
 
Technology and Innovation in Financial Services Scenarios
Technology and Innovation in Financial Services ScenariosTechnology and Innovation in Financial Services Scenarios
Technology and Innovation in Financial Services Scenarios
 
Le white paper de l'Ilnas sur la blockchain et les DLT
Le white paper de l'Ilnas sur la blockchain et les DLTLe white paper de l'Ilnas sur la blockchain et les DLT
Le white paper de l'Ilnas sur la blockchain et les DLT
 
2019 outlook : 3 key trends that will impact digital-first banking
2019 outlook : 3 key trends that will impact digital-first banking2019 outlook : 3 key trends that will impact digital-first banking
2019 outlook : 3 key trends that will impact digital-first banking
 
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
 
IT funding made to measure
IT funding made to measureIT funding made to measure
IT funding made to measure
 
Retail banker intl
Retail banker intl Retail banker intl
Retail banker intl
 
[Webinar] - Intelligent Automation: Enabling Bots with Brain
[Webinar] - Intelligent Automation: Enabling Bots with Brain[Webinar] - Intelligent Automation: Enabling Bots with Brain
[Webinar] - Intelligent Automation: Enabling Bots with Brain
 
[AI Webinar Series P1] - How Advanced Text Analytics Can Increase the Operati...
[AI Webinar Series P1] - How Advanced Text Analytics Can Increase the Operati...[AI Webinar Series P1] - How Advanced Text Analytics Can Increase the Operati...
[AI Webinar Series P1] - How Advanced Text Analytics Can Increase the Operati...
 
Realising Digital’s Full Potential in the Value Chain
Realising Digital’s Full Potential in the Value ChainRealising Digital’s Full Potential in the Value Chain
Realising Digital’s Full Potential in the Value Chain
 
BaaS - Banking as a Service
BaaS - Banking as a ServiceBaaS - Banking as a Service
BaaS - Banking as a Service
 
Webinar (UK/Europe) - Demystifying SAP S/4HANA
Webinar (UK/Europe) - Demystifying SAP S/4HANAWebinar (UK/Europe) - Demystifying SAP S/4HANA
Webinar (UK/Europe) - Demystifying SAP S/4HANA
 
The New Role of the Architect - Central to growing your business in today’s d...
The New Role of the Architect - Central to growing your business in today’s d...The New Role of the Architect - Central to growing your business in today’s d...
The New Role of the Architect - Central to growing your business in today’s d...
 
Company Profile – Sankalp Tech (MLM Software)
Company Profile – Sankalp Tech (MLM Software)Company Profile – Sankalp Tech (MLM Software)
Company Profile – Sankalp Tech (MLM Software)
 
Global CIO Banking Summit - Workshop Cultural Changes to Survive Digital Disr...
Global CIO Banking Summit - Workshop Cultural Changes to Survive Digital Disr...Global CIO Banking Summit - Workshop Cultural Changes to Survive Digital Disr...
Global CIO Banking Summit - Workshop Cultural Changes to Survive Digital Disr...
 
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIsAPIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
 
3.FINTECH Course NMIMS -UNDERSTANDING TECH in Fintech
3.FINTECH Course NMIMS -UNDERSTANDING TECH in Fintech3.FINTECH Course NMIMS -UNDERSTANDING TECH in Fintech
3.FINTECH Course NMIMS -UNDERSTANDING TECH in Fintech
 
Intellect's Global Transaction Banking
Intellect's Global Transaction BankingIntellect's Global Transaction Banking
Intellect's Global Transaction Banking
 

Similaire à RESPONSIVE GOVERNANCE FOR EVOLUTIONARY TECHNOLOGY PLATFORMS

Synergy6.5 Change4.7 Ecp
Synergy6.5 Change4.7 EcpSynergy6.5 Change4.7 Ecp
Synergy6.5 Change4.7 EcpBill Duncan
 
CMAD Group Workbook 7 Governance
CMAD Group Workbook 7 GovernanceCMAD Group Workbook 7 Governance
CMAD Group Workbook 7 GovernanceAlexander Doré
 
Enterprise Architecture Governance: A Framework for Successful Business
Enterprise Architecture Governance: A Framework for Successful BusinessEnterprise Architecture Governance: A Framework for Successful Business
Enterprise Architecture Governance: A Framework for Successful BusinessNathaniel Palmer
 
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
20200429 PMI NYC Meetup Agile Governance Ariel Partners for DistributionCraeg Strong
 
[WSO2Con USA 2018] Winning Strategy For Enterprise Integration to Empower Dig...
[WSO2Con USA 2018] Winning Strategy For Enterprise Integration to Empower Dig...[WSO2Con USA 2018] Winning Strategy For Enterprise Integration to Empower Dig...
[WSO2Con USA 2018] Winning Strategy For Enterprise Integration to Empower Dig...WSO2
 
Creating an Operating Model to enable a high frequency organization
Creating an Operating Model to enable a high frequency organizationCreating an Operating Model to enable a high frequency organization
Creating an Operating Model to enable a high frequency organizationTom Laszewski
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsOracle
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Oracle
 
Self Service Cloud Operations: Safely Delegate the Management of your Cloud ...
Self Service Cloud Operations:  Safely Delegate the Management of your Cloud ...Self Service Cloud Operations:  Safely Delegate the Management of your Cloud ...
Self Service Cloud Operations: Safely Delegate the Management of your Cloud ...Rundeck
 
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & ImplementationsThousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & ImplementationsOracle
 
Best practices for fusion hcm cloud implementation
Best practices for fusion hcm cloud implementationBest practices for fusion hcm cloud implementation
Best practices for fusion hcm cloud implementationmohamed refaei
 
Who needs EA… when we have DevOps?
Who needs EA… when we have DevOps?Who needs EA… when we have DevOps?
Who needs EA… when we have DevOps?Jeff Jakubiak
 
End to-End Monitoring for ITSM and DevOps
End to-End Monitoring for ITSM and DevOpsEnd to-End Monitoring for ITSM and DevOps
End to-End Monitoring for ITSM and DevOpseG Innovations
 
Agile Mumbai 2023 | DevOps By Design @ Rite - Ritesh Pareksh
Agile Mumbai 2023 | DevOps By Design @ Rite - Ritesh ParekshAgile Mumbai 2023 | DevOps By Design @ Rite - Ritesh Pareksh
Agile Mumbai 2023 | DevOps By Design @ Rite - Ritesh ParekshAgileNetwork
 
"Digital transformation and innovations implementation. Architectural points ...
"Digital transformation and innovations implementation. Architectural points ..."Digital transformation and innovations implementation. Architectural points ...
"Digital transformation and innovations implementation. Architectural points ...Fwdays
 
DevOps Primer : Presented by Uday Kumar
DevOps Primer : Presented by Uday KumarDevOps Primer : Presented by Uday Kumar
DevOps Primer : Presented by Uday KumaroGuild .
 

Similaire à RESPONSIVE GOVERNANCE FOR EVOLUTIONARY TECHNOLOGY PLATFORMS (20)

Synergy6.5 Change4.7 Ecp
Synergy6.5 Change4.7 EcpSynergy6.5 Change4.7 Ecp
Synergy6.5 Change4.7 Ecp
 
CMAD Group Workbook 7 Governance
CMAD Group Workbook 7 GovernanceCMAD Group Workbook 7 Governance
CMAD Group Workbook 7 Governance
 
Enterprise Architecture Governance: A Framework for Successful Business
Enterprise Architecture Governance: A Framework for Successful BusinessEnterprise Architecture Governance: A Framework for Successful Business
Enterprise Architecture Governance: A Framework for Successful Business
 
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
 
[WSO2Con USA 2018] Winning Strategy For Enterprise Integration to Empower Dig...
[WSO2Con USA 2018] Winning Strategy For Enterprise Integration to Empower Dig...[WSO2Con USA 2018] Winning Strategy For Enterprise Integration to Empower Dig...
[WSO2Con USA 2018] Winning Strategy For Enterprise Integration to Empower Dig...
 
Creating an Operating Model to enable a high frequency organization
Creating an Operating Model to enable a high frequency organizationCreating an Operating Model to enable a high frequency organization
Creating an Operating Model to enable a high frequency organization
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...
 
Self Service Cloud Operations: Safely Delegate the Management of your Cloud ...
Self Service Cloud Operations:  Safely Delegate the Management of your Cloud ...Self Service Cloud Operations:  Safely Delegate the Management of your Cloud ...
Self Service Cloud Operations: Safely Delegate the Management of your Cloud ...
 
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & ImplementationsThousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
 
Demystifying Devops - Uday kumar
Demystifying Devops - Uday kumarDemystifying Devops - Uday kumar
Demystifying Devops - Uday kumar
 
Best practices for fusion hcm cloud implementation
Best practices for fusion hcm cloud implementationBest practices for fusion hcm cloud implementation
Best practices for fusion hcm cloud implementation
 
Who needs EA… when we have DevOps?
Who needs EA… when we have DevOps?Who needs EA… when we have DevOps?
Who needs EA… when we have DevOps?
 
End to-End Monitoring for ITSM and DevOps
End to-End Monitoring for ITSM and DevOpsEnd to-End Monitoring for ITSM and DevOps
End to-End Monitoring for ITSM and DevOps
 
Quality & Risk Management Challenges When Acquiring Enterprise Systems
Quality & Risk Management Challenges When Acquiring Enterprise SystemsQuality & Risk Management Challenges When Acquiring Enterprise Systems
Quality & Risk Management Challenges When Acquiring Enterprise Systems
 
Agile Mumbai 2023 | DevOps By Design @ Rite - Ritesh Pareksh
Agile Mumbai 2023 | DevOps By Design @ Rite - Ritesh ParekshAgile Mumbai 2023 | DevOps By Design @ Rite - Ritesh Pareksh
Agile Mumbai 2023 | DevOps By Design @ Rite - Ritesh Pareksh
 
"Digital transformation and innovations implementation. Architectural points ...
"Digital transformation and innovations implementation. Architectural points ..."Digital transformation and innovations implementation. Architectural points ...
"Digital transformation and innovations implementation. Architectural points ...
 
DevOps Primer : Presented by Uday Kumar
DevOps Primer : Presented by Uday KumarDevOps Primer : Presented by Uday Kumar
DevOps Primer : Presented by Uday Kumar
 
M:s Checkmate Global Technologies DevOps Services.pptx
M:s Checkmate Global Technologies DevOps Services.pptxM:s Checkmate Global Technologies DevOps Services.pptx
M:s Checkmate Global Technologies DevOps Services.pptx
 
Noor-Res
Noor-ResNoor-Res
Noor-Res
 

Plus de Thoughtworks

Design System as a Product
Design System as a ProductDesign System as a Product
Design System as a ProductThoughtworks
 
Designers, Developers & Dogs
Designers, Developers & DogsDesigners, Developers & Dogs
Designers, Developers & DogsThoughtworks
 
Cloud-first for fast innovation
Cloud-first for fast innovationCloud-first for fast innovation
Cloud-first for fast innovationThoughtworks
 
More impact with flexible teams
More impact with flexible teamsMore impact with flexible teams
More impact with flexible teamsThoughtworks
 
Culture of Innovation
Culture of InnovationCulture of Innovation
Culture of InnovationThoughtworks
 
Developer Experience
Developer ExperienceDeveloper Experience
Developer ExperienceThoughtworks
 
When we design together
When we design togetherWhen we design together
When we design togetherThoughtworks
 
Hardware is hard(er)
Hardware is hard(er)Hardware is hard(er)
Hardware is hard(er)Thoughtworks
 
Customer-centric innovation enabled by cloud
 Customer-centric innovation enabled by cloud Customer-centric innovation enabled by cloud
Customer-centric innovation enabled by cloudThoughtworks
 
Amazon's Culture of Innovation
Amazon's Culture of InnovationAmazon's Culture of Innovation
Amazon's Culture of InnovationThoughtworks
 
When in doubt, go live
When in doubt, go liveWhen in doubt, go live
When in doubt, go liveThoughtworks
 
Don't cross the Rubicon
Don't cross the RubiconDon't cross the Rubicon
Don't cross the RubiconThoughtworks
 
Your test coverage is a lie!
Your test coverage is a lie!Your test coverage is a lie!
Your test coverage is a lie!Thoughtworks
 
Docker container security
Docker container securityDocker container security
Docker container securityThoughtworks
 
Redefining the unit
Redefining the unitRedefining the unit
Redefining the unitThoughtworks
 
Technology Radar Webinar UK - Vol. 22
Technology Radar Webinar UK - Vol. 22Technology Radar Webinar UK - Vol. 22
Technology Radar Webinar UK - Vol. 22Thoughtworks
 
A Tribute to Turing
A Tribute to TuringA Tribute to Turing
A Tribute to TuringThoughtworks
 
Rsa maths worked out
Rsa maths worked outRsa maths worked out
Rsa maths worked outThoughtworks
 

Plus de Thoughtworks (20)

Design System as a Product
Design System as a ProductDesign System as a Product
Design System as a Product
 
Designers, Developers & Dogs
Designers, Developers & DogsDesigners, Developers & Dogs
Designers, Developers & Dogs
 
Cloud-first for fast innovation
Cloud-first for fast innovationCloud-first for fast innovation
Cloud-first for fast innovation
 
More impact with flexible teams
More impact with flexible teamsMore impact with flexible teams
More impact with flexible teams
 
Culture of Innovation
Culture of InnovationCulture of Innovation
Culture of Innovation
 
Dual-Track Agile
Dual-Track AgileDual-Track Agile
Dual-Track Agile
 
Developer Experience
Developer ExperienceDeveloper Experience
Developer Experience
 
When we design together
When we design togetherWhen we design together
When we design together
 
Hardware is hard(er)
Hardware is hard(er)Hardware is hard(er)
Hardware is hard(er)
 
Customer-centric innovation enabled by cloud
 Customer-centric innovation enabled by cloud Customer-centric innovation enabled by cloud
Customer-centric innovation enabled by cloud
 
Amazon's Culture of Innovation
Amazon's Culture of InnovationAmazon's Culture of Innovation
Amazon's Culture of Innovation
 
When in doubt, go live
When in doubt, go liveWhen in doubt, go live
When in doubt, go live
 
Don't cross the Rubicon
Don't cross the RubiconDon't cross the Rubicon
Don't cross the Rubicon
 
Error handling
Error handlingError handling
Error handling
 
Your test coverage is a lie!
Your test coverage is a lie!Your test coverage is a lie!
Your test coverage is a lie!
 
Docker container security
Docker container securityDocker container security
Docker container security
 
Redefining the unit
Redefining the unitRedefining the unit
Redefining the unit
 
Technology Radar Webinar UK - Vol. 22
Technology Radar Webinar UK - Vol. 22Technology Radar Webinar UK - Vol. 22
Technology Radar Webinar UK - Vol. 22
 
A Tribute to Turing
A Tribute to TuringA Tribute to Turing
A Tribute to Turing
 
Rsa maths worked out
Rsa maths worked outRsa maths worked out
Rsa maths worked out
 

Dernier

08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 

Dernier (20)

08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 

RESPONSIVE GOVERNANCE FOR EVOLUTIONARY TECHNOLOGY PLATFORMS

  • 1. RESPONSIVE GOVERNANCE FOR EVOLUTIONARY TECHNOLOGY PLATFORMS Heiko Gerin
  • 2. Things to cover ● Evolutionary technology platforms & governance ● Things to govern & common friction points ● Governance principles: what we’ve seen working ● Common limitations & exciting stuff
  • 3. Evolutionary Technology Platforms ● Support incremental, constant change ● Are built in a way that is appropriately coupled ● Optimise for high delivery velocity & quality ● Promote end-to-end ownership and accountabilities ● Deliver through cross-functional teams aligned to business outcomes
  • 4. Evolutionary Technology Platforms ● Include people, process and technology ● Change rapidly and constantly ● Appropriate governance changes with the requirements and the environment ● Needs to be responsive to evolve
  • 5. Definitions: GRC IT Governance provides a structure for aligning IT strategy with business strategy; Ensures Risk is identified and addressed and Ensures Compliance to laws and regulations Definition Paraphrased from Wikipedia
  • 6. Ensure we understand potential risks and mitigate them Ensure that we do the right things (aligned to business goals) Ensure that we do things the right way (within laws and regulations) http://jonnyschneider.com/
  • 7. Why the friction? 1. Governance tends to come in extremes 2. Governance implemented can’t support constant change
  • 8. 1. Governance tends to come in extremes
  • 9. Big Corporate Governance Extremes: How governance “happens” Startup Super Scale-Up Global Scale Medium Scale-Up Single Market Small Scale-Up Single Segment Large Scale-Up Multi Market Sudden influx of cash Entered regulated industry High profile Outage /Privacy Breach IPO, acquisition
  • 10. A few words on Governance Frameworks ● Service Management ITIL, SIAM, ISO/IEC20000 ● Security ISO 27001 ● Risk COSO ● Architecture TOGAF ● Process improvement CMMI ● Governing governance COBIT “The collective memory of all things that have ever gone wrong in this and every other organisation”
  • 11. Governance areas Program / Project Governance Prioritisation, Portfolio Management Architectural Governance Data, APIs, Service Design, Review Boards Change & Release Quality, Versioning, Change advisory boards, Config Management Databases Risk & Security Reviews boards, Code scanning, Pen testing, Enterprise Security Services Business Continuity / DR Disaster Recovery Exercises & Requirements Audit & Compliance Government regulations, Internal & external audit activities Funding Model Project based or capacity based
  • 12. 2. Implementation can’t support constant change ● Some frameworks are products of their time ● Implementations tend to reinforce silos (Tragedy of the commons) ● “Governance events” cause big bang rollouts ● Implementations of controls and policies ○ designed for a more traditional delivery and op model ○ Non-responsive (static or changeable only by committee)
  • 13. Governance Extremes: Examples Complete lack of repeatability and documentation Overly bureaucratic and wasteful processes No accountability for Information Security, Change Management or Operations Siloed functions that don't work effectively together No traceability of changes or decisions made Long wait times for rubber-stamp approvals that are largely theater Uncontrollable technology and tool sprawl Policies dictated by people that don't feel the impact of their decisions VS VS VS VS
  • 14. Governance Principles Automate compliance but enable assurance Focus on vision, principles & constraints From gatekeepers to facilitators & partners Provide paved roads: the pit of success Evolve the operating model
  • 15. Automate compliance and enable assurance ● Embed governance & compliance requirements in operational runtime monitoring of the platform ● Evaluate as part of the delivery pipeline (blocking) ● Enable & promote independent verification & audit (non-blocking) ● Take a risk based approach to prevent bottom-up audit
  • 16. Preventing Bottom Up Audit Audit Lifecycle: - Business objectives - Identified Risks - Control objectives - Mitigating procedures - Verify & Adapt Corporate Folklore
  • 17. Focus on vision, principles & constraints ● Move away from specifying tools, processes and solutions ● Frame needs as visions, principles and constraints ● Degree of autonomy to make implementation choices (“Docker” is not a principle) ● Target outcomes over specific implementations ● Guardrails The Leviathan
  • 18. Internal Technology Radar ● Catalyst for architectural conversations ● Visibility across teams ● Discipline around moving between assess, trial, adopt and hold ● Apply WIP limits Tech radar used for lightweight governance
  • 19. From gatekeepers to facilitators Avoid using sparse skill-sets as enforcement agencies: Operations, Compliance, Risk, Security, ... Amplify them to increase their effectiveness: ● Expert advisors for teams, facilitating, coaching and advising ● Articulate principles and constraints - but also help implement them Years & years of penetration tests
  • 20. Change Control ● Peer review is the most effective form of change control ● Pre-approved (ITIL) standard changes ● De-risk changes using Continuous Delivery ● Automate compliance ● Distributed, electronic CABs & subgroups The perfect CMDB & CABs all the way down
  • 21. Provide paved roads & the pit of success ● Centralised supporting platforms as a product ● Teams focus on delivering business value while complying with overall guardrails ● The pit of success - make it easy to do the right thing ● Customer centricity ● Non-mandatory If all you have is a hammer
  • 22. Introducing “Goldilocks” governance: Evolve the operating model ● Define activities and do a RACI - before & after ● Adapt accountabilities & responsibilities ● Start small, experiment ● Exemplar teams ● New acceptance criteria, definitions of done Big bang rollout
  • 23. Evolve the operating model: RACIs
  • 25. Governance Principles Automate compliance but enable assurance Focus on vision, principles & constraints From gatekeepers to facilitators & partners Provide paved roads: the pit of success Evolve the operating model
  • 26. Common limitations (they’re mostly technical) ● Compliance as code is not really there yet ● No real standards ways of governing cloud infrastructure ● Bespoke, hand crafted implementations & formats
  • 27. Exciting things happening! ● Using the cloud to govern the cloud (prowler, AWS config rules, etc.) ● Kubernetes as a basic “cloud agnostic” infra building block ● Grafeas/Kritis for compliance as code ● Binary authorization as a first class cloud service (like GKE on Google Cloud)
  • 30. Q&A
  • 31. Audit Alpaca found on reddit "Tripod Candlestand" is licensed under CC BY 3.0 "Warm and fluffy" by ILYA Denisenko is licensed under CC BY-NC 4.0 "Negative - Walla Walla, New South Wales, 1932" is licensed under CC PDM 1.0 "Gatekeepers" by Suzanne Brandt is licensed under CC BY-NC-ND 4.0 "change" is licensed under CC0 1.0 "Pavement Loop" by Alex Varanese is licensed under CC BY-NC 4.0 "Smoking Kaiju robot is licensed under CC BY-NC 3.0
  • 32. SANS secure DevOps Toolchain Poster
  • 34. Architectural Principles http://engineering-principles.jl-engineering.net ● Not hard and fast rules but guidelines ● Could also be used in a 'discovery phase' to select new products or tools ● Probably no more than 10 ● Govern them via fitness functions Cloud Native Build systems that are native to cloud environments. Rationale, Implications (prefer open tooling, etc …), Examples