John Linn
Cloud FS Americas Metropolitan West, NYC – July 21, 2015
Aegon's Internal
Cloud Broker
Aegon at a glance
Countries
Employees
Revenue-generating
investments
and benefits in 2014
Paid out in claims
Underlying earnings
before tax in 2014
History
About Aegon
Rating
Focus
Life insurance, pensions
& asset management
Dating back
170 years
AA- financial
strength rating
Present in over 20 countries
across the world
Around 28,000
employees
As per March 31, 20153
Opportunities:
►
Next-gen technologies provide a competitive advantage
►Easy, low cost entry (rent versus own)
►
Scalable, flexible, and ubiquitous
►
Interest in integrating Cloud services with on premise
Constraints:
►
Cloudy Thinking – Money, Security, All or Nothing
►Efforts trapped in isolation
►
Downside danger of service provider termination or lock-in
►Regulatory compliance
Hurdles
Right to
Audit
Data
Protection
Directive
Data
Sovereignty
Risk
Assessment
Security
Standards
Taxes
Data Privacy
Contracts
Cloud Provider
Selection
Governing the
Ungovernable
Adopting Common
$ € £
Cloud
Hangover
You must be
THIS TALL
To Ride
This Ride
5
Emerging Needs
Workload consulting
Identification of total cost of ownership (TCO) and quantifying benefits
Cloud services register of approved Cloud services
Common third-party risk management process to identify blockers early
Operational support
Workload
Deployment
Definition
Identifying a
Cloud Use
Case
Selection
Vendor
Comparison
and Decision
Deployment
Development,
Integration, and
Portability
Management
Aggregation,
Portal & Billing
Customization,
and Runtime
Plans, Metrics, Risk Classification, and Governance
Third Party Risk Management Framework
Procurement Process
Due Diligence (including
resiliency and critical
fourth parties) & third
party selection
Contract negotiation
Roles and
responsibilities
for oversight and
relationship
management
Documentation
and reporting
Ongoing
monitoring
Termination,
including
contingency
plans
7
Clarification Through RASCI
Who is Responsible?
Who is Accountable?
Who is Supporting?
Who is Consulted?
Who is Informed?
The person who has to do it
The final decision maker
Resources allocated to responsible to help carry out the task
Persons requiring two way communication before a decision
The person kept up-to-date or told after a decision
R
A
S
C
Example: Ongoing Monitoring of Third Party
B u si n ess O w n er M an ag em en t C -L ev el P ro je ct Te am 3r d p ar ty R el ati o n sh ip M an ag er Su b je ct M ater E xp er ts D esi gn A u th o ri ty P ro cu re m en t Le ga l C o m p lia n ce In fo rm ati o n S ec u ri ty C h ie f R isk O ff ic er ( C R O ) O p er ati o n al R isk M an ag em en t M gr s Lo ca l O p er ati o n al R isk C o m m itt ee s G lo b al R isk C lo u d C o n su lti n g C lo u d D esi gn a n d B u ild C lo u d R u n G lo b al P ro cu re m en tDeliverable
Artifact /
Outcome
Third Party Outsourcing Monitoring
Ongoing Monitoring
Periodically monitor costs, performance, and ability to comply with contract, legal requirements, third party resiliency and financial health, and critical fourth parties
I A/R C C C C I R
Report on design & effectiveness of internal controls with third party I A/R I I I R
Report on risks with third party I A/R I I C/I R
Should arrangement be terminated? A R C C C I R
Invoke contingency plan / exit strategy C A/R R R S C I R
Terminate arrangement C A/R R R I I R
RASCI Assignments shown in Red are only applicable when the solution chosen is a cloud offering.
Risk 2nd Line Business Unit (BU) - 1st Line
RASCI
Outputs
Functional Roles Cloud Broker oi ng tori ng BeginMonitor costs, performance, contract compliance, legal requirements, third party resiliency and financial
Report on internal controls Report on risks with third party Terminate arrangement?
9
Cloud Broker Services
Central ‘go-to’ team for business units and other global
stakeholders for Cloud services
Provides assurance new Cloud capabilities adhere to policies and requirements
Ensures Cloud capabilities align with business and technical requirements by leveraging existing processes
Cloud Consulting
Cloud Design and
Construction
Cloud Operations
Cloud Brokering
Define reference architecture and service blueprints (for example, integration layers)
Engineer and implement automated platforms and solutions
Plan and manage projects
Provide configuration change, release and deployment management
Test, validate and evaluate services
Operate and monitor services and components
Provide capacity, availability and service level management
Perform incident and problem management
Provide request fulfilment
Maintain Cloud and Automation infrastructure
Oversee and manage
automated processes (patching, compliance, etc.)