Loading…
Secure AI Summit 2024 (Powered by Cloud Native) has ended
Tuesday June 25, 2024 3:05pm - 3:15pm PDT
Today GRC team struggles to instill the culture of Continuous Control Monitoring. Typically, they utilize mechanisms such as security questionnaire, email or Sharepoint to gather evidence. These aids help them in assessing compliance, preparing for audits and managing vendor risk assessments. However, they encounter difficulties in collecting data and evidence due to lack of standardization, technical complexity, repetitiveness and insufficient time and resources. We can support our hard working GRC teams and equip them the necessary tools by employing LLM in the following way: - Creating a machine readable controls framework in YAML from the policy document. - Generating a dynamic graph of policies, controls and frameworks based on the YAML - Designing a dynamic evaluation questionnaire for users to assess the effectiveness of these policies - Deploying this questionnaire using well known tools like Google forms for continuous controls monitoring - Implementing CEL (Common Expression Language) to calculate the compliance score dynamically based on the evaluation responses. - Integrating the final results into reports and dashboards for the steering governance committee.
Speakers
avatar for Megha Shah

Megha Shah

Principal Solutions Architect, ComplianceCow
Kubernetes Security Engineer with CKAD, CKA and CKS. She is a proficient programmer in Golang and Python with 10+ years of software development experience and has specifically focused on Kubernetes, Cloud and SAAS security assurance for the last 5+ years.
Tuesday June 25, 2024 3:05pm - 3:15pm PDT
Room 447
Feedback form is now closed.

Attendees (8)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link