Questions About Remote Learning? Click Here

IT Risk - Barry 1
Updated: 3/25/2020
IT Risk - Barry 1
This storyboard was created with

Storyboard Description

Unsanctioned app story 1

Storyboard Text

  • Hey Barry, have you seen our new customer quickpay app? It's a cloud app. It's so awesome!
  • A customer facing app? Where did this come from? Who agreed to this?
  • Hi Barry, we're just storing customer data for payments. It's a cool startup. Did you see the slick user interface. What's the big deal?Regards, "the Business"
  • Ugh! This could be bad. Now I have to rethink my entire workload for the week.
  • Barry finds out about a new unsanctioned cloud asset through a discovery process.
  • I really hate to be the bad guy!
  • Well, you are Barry! You ruined it. And to think I was going to invite you to our happy hour...
  • He realizes both the new asset and the vendor he hasn't worked with could pose significant risk to the organization. He will need to reprioritize his current workload to add a new manual assessment.
  • Barry wastes several hours hunting down the vendor details and contract to determine whether this vendor is on the approved list.
  • Another 1:1 tomorrow with my boss. I'm way behind and it looks like I don't get stuff done. I'll never get that raise!
  • (1) He discovers the Vendor is not approved. He alerts procurement and legal teams to investigate and tell the business to stop using the cloud service.
  • (2) He discovers the Vendor is approved and researches what contractual controls are in place vs. what controls must be managed internally. This takes him several days
  • Barry wishes this wasn't the only time this happened this quarter. He's backlogged on a bunch of assessments that are supposed to already be done.
Over 13 Million Storyboards Created
Storyboard That Family