The Inner Circle

 View Only

Minutes of the Compliance Automation Revolution Stakeholder Meeting Thursday February 13th, 2025

  • 1.  Minutes of the Compliance Automation Revolution Stakeholder Meeting Thursday February 13th, 2025

    Posted Feb 20, 2025 12:47:00 PM
    Edited by Andy Ruth Feb 20, 2025 12:48:08 PM

    Attendees: 

     

    Name

    Organization

    Name

    Organization

    Andy Ruth

    CSA

    Daniele Catteddu

    CSA

    Eileen Sciarra

    CSA

    Hillary Baron

    CSA

    John DiMaria

    CSA

    John Yeoh

    CSA

    Illena Armstrong

    CSA

    Larry Hughes

    CSA

    Troy Leach

    CSA

    Abhay Kshirsagar

    Salesforce

    Anil Markose

    Oracle

    Antonio Tandoi

    Deloitte

    Ardiana Prekazi

    Deloitte

    Binita Prad

    BDO

    Eden Amitai

    Anecdotes

    Fabrizio Antonio Lo Bianco

    Deloitte

    J. Travis Howerton

    RegScale

    John Finizio

    Whistic

    Luca De Candia

    Deloitte

    Matteo Lucantonio

    Deloitte

    Melissa Yu

    Google

    Michaela Iorga

    NIST

    Michelle Reister

    Anecdotes

    Pamela Fusco

    Cyber Bear Group

    Phyllis Lee

    CIS

    Roberto Tanzi

    Deloitte

    Roi Amior

    Anecdotes

    Ruchi Khurana

    Google

    Stefan Walti

    Unknown

    Thomas Volpe

    RegScale

    Vikram Khare

    Google

    Agenda:

           Welcome new attendees

           Goals and timelines for H1 - 2025

           Working group establishment

           Webinar series update

           Miscellaneous

           Next steps and AOB (any other business)

    Summary:

    The meeting commenced with a welcome and an overview of the agenda, focusing on establishing timelines and goals for the next six months, launching initial working groups, and planning a marketing strategy. Participants introduced themselves, highlighting their roles in cloud security and compliance, including notable figures from various organizations. An initiative was informally launched at the CSA Digital Summit, with a formal announcement of the Compliance Automation Resolution (CAR) initiative planned for April 27th at the RSA event. The CAR participants agreed to draft a charter, issue a call for volunteers, and elect co-chairs, ensuring stakeholder representation. Discussions included ongoing webinars on compliance automation, the need for effective survey utilization, and planning for the RSA meeting, emphasizing the importance of support from founding members. The team aims to enhance engagement with regulatory agencies and secure financial support from new stakeholders. Next steps involve finalizing plans for the RSA conference, gathering input on the charter, and encouraging creative contributions towards compliance automation initiatives.

    Action Items:

    ·      Launch initial working groups and plan for a marketing strategy going forward.

    ·      Activate technical activities and launch the first three working groups, aiming to push out initial deliverables by July.

    ·      Finalize the charter and administrative work for the working groups, requiring contributions from all members to define objectives and deliverables.

    ·      Define the charter, call for volunteers, and elect co-chairs, with a focus on ensuring representation from all key stakeholder categories.

    ·      Brainstorm ideas on how to increase awareness and participation in the webinars, with input expected over email in the coming days.

    ·      Daniele Catteddu has sent an email to stakeholders seeking speakers for the webinars, with the aim for balanced representation and fairness in opportunities.

    ·      Daniele will circulate a 'save the date' for the CAR meeting at RSA to finalize the tentative date for the in-person meeting.

    ·      Eileen will send out an email with potential meeting dates before the end of the week, aiming for Tuesday as the preferred day to avoid scheduling conflicts as people get busier.

    ·      Daniele will circulate a template of the charter and request specific input from participants on goals, objectives, and priorities, encouraging everyone to review and comment on the deliverables for the working groups.

    ·      CAR participants will leverage connections with global regulators to enhance communication channels and ensure their participation in the regulatory decision-making process.

    ·      CAR participants will reach out to organizations that could potentially sign on as founding members to enhance financial support for their activities.

    ·      CAR participants agreed to finalize their plans for the RSA conference by next Friday, the 21st, to ensure clarity on their contributions.

    ·      Daniele Catteddu suggested that CAR participants should review the descriptions of previous webinars and the shared deliverables to better understand the context and contribute ideas for content promotion.

    ·      Daniele Catteddu requested that CAR participants think creatively about angles and perspectives to cover in relation to the goals of compliance automation and continuous assurance.


    Additional Detail:

    Meeting Agenda and Goals
    • The meeting agenda included timelines and goals for the next six months, specifically from February to July.
    • The discussion included launching initial working groups and planning for a marketing strategy going forward.

    Introduction of Participants
    • The meeting featured multiple introductions from participants, including Daniele Catteddu, Roberto Tanzi from Deloitte, Roi Amior and Michele Reister from Anecdotes, Luca De Candia, Antonio, Ardiana Prekazi, Abhay Kshirsagar and others, highlighting their roles in cloud security and compliance.

    Overview of Initiative Progress
    • The initiative was informally launched at the end of January during the CSA Digital Summit, with activities including a series of webinars planned.

    Launch of Compliance Automation Resolution Initiative
    • The official name of the initiative has changed to Compliance Automation Resolution Initiative, with a formal announcement planned for April 27th at the RSA event.
    • The CAR participants plan to support technical activities and launch the first three working groups, aiming to push out initial deliverables by July.
    • The CAR participants agreed on the initial approach for the next six months, including the launch of working groups and the marketing campaign.
    • The CAR participants need to finalize the charter and CSA staff complete administrative work for the working groups, requiring contributions from all members to define objectives and deliverables.

    Drafting and Approving the Charter
    • The team agreed to draft a charter, issue a call for volunteers, and proceed with the approval of the charter and election of co-chairs.
    • The co-chair structure will consist of three co-chairs for each of the three working groups, totalling nine co-chairs, representing three main stakeholder categories.
    • The next steps include defining the charter, calling for volunteers, and electing co-chairs, with a focus on ensuring representation from all key stakeholder categories.

    Webinar Series on Compliance Automation and Continuous Assurance
    • There is a concern regarding the sensitivity of potential speakers participating in a panel due to competition among them, which may hinder the organization of future webinars.
    • The webinars have seen a participation of approximately four hundred attendees, indicating a fair level of engagement.
    • The team is encouraged to brainstorm ideas on how to increase awareness and participation in the webinars, with input expected over email in the coming days.
    • Daniele Catteddu has sent an email to stakeholders seeking speakers for the webinars, aiming for a balanced representation and fairness in opportunities.

    Survey Utilization and RSA Meeting Planning
    • Daniele expressed concern about the need for support from founding members to enhance the marketing impact of the announcement at RSA, given the limited resources of CSA.
    • The CSA Summit at RSA is scheduled for Monday, and the proposed date for the in-person meeting is February 21st.
    • Daniele will circulate a 'save the date' for the CAR meeting at RSA to finalize the tentative date for the in-person meeting.
    • It was decided to aim for a couple of hours for an in-person meeting at RSA to discuss strategy and to plan for a more public reception event.

    Next Steps for Scheduling and Input Gathering
    • Eileen will send out an email with potential meeting dates before the end of the week, with Tuesday as the preferred day to avoid scheduling conflicts as people get busier.
    • Daniele will circulate a template of the charter and request specific input from participants on goals, objectives, and priorities, encouraging everyone to review and comment on the deliverables for the working groups.

    Regulatory Engagement and Compliance Automation
    • A solid draft of the charters is expected to be completed within the next two weeks, allowing for a call for volunteers and identification of candidates for the co-chair position in March.
    • There is a significant concern regarding the current compliance landscape, particularly in Europe, due to the impending regulations such as the UAE Act and DORA, which are creating a 'perfect storm' for compliance.
    • The CAR participants are requested to leverage connections with global regulators to enhance communication channels and ensure their participation in the regulatory decision-making process.

    Charter Drafting and Stakeholder Engagement
    • The CAR participants are tasked with reaching out to organizations that could potentially sign on as founding members to enhance financial support for their activities.

    RSA Conference Planning
    • The CAR participants agreed to finalize their plans for the RSA conference by next Friday, the 21st, to ensure clarity on their contributions.

    Webinar Series and Compliance Automation
    • John Finizio expressed a need for clearer guidelines on high-level messaging and the progression of initiatives, indicating that this would help in aligning efforts towards the launch.
    • Daniele Catteddu suggested that team members should review the descriptions of previous webinars and the shared deliverables to better understand the context and contribute ideas for content promotion.
    • Daniele Catteddu requested that team members think creatively about angles and perspectives to cover in relation to the goals of compliance automation and continuous assurance.

    ------------------------------
    Andy Ruth
    Cloud Security Alliance
    [email protected]

    ------------------------------