21
ITIL and Compliance , 13.30 – 14.15 Mikael May Yde, Senior Compliance Consultant, epista IT A/S

ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Embed Size (px)

Citation preview

Page 1: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

ITIL and Compliance , 13.30 – 14.15

Mikael May Yde, Senior Compliance Consultant, epista IT A/S

Page 2: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Speaker

Life Science since 2001, IT since 1987

epista IT A/S 2013 - present

• Inspection Readiness, IT Compliance Plan , IT QMS,

Validation of ERP, GxP IT

H. Lundbeck A/S 2001 - 2013

• Headed Global IT Compliance, 10+ years

– Corporate Validation of applications

– Global Qualification of IT infrastructure

– Global Service Management/ITIL processes

– Corporate Information Security

– Inspection coordinator for Corporate IT

– Lean in IT

Mikael May YdeSenior Compliance

Consultant

Page 3: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Objectives

• IT compliance requires control of:

– People

– Applications

– Data

– Infrastructure

– Procedures

– Ways of working

– Documented evidence

…among other things…

Page 4: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

ITIL Lifecycle

Page 5: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Objectives

• There and Back Again (Tolkien)

– Two worlds of understanding, two professions,

two languages…

– Meet people on their territory

• Aligning existing professions and methodologies

– Common understanding of processes

• Gaining compliance value of

existing investment

• Cultural change management(Culture eats Strategy for Breakfast)

Page 6: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Design & Preparation

Planning

Testing

End of life

System Lifecycle – Validation

Project Operations, support and maintenance

Implementation

Buy or Build

Page 7: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Requirements for an IT QMS

• Is the QMS

– Flexible?

– Scalable?

– Implementable?

– Recognizable?

– Value adding?

• Does the QMS

– Play well with others?

– Keep you in compliance?

– Lower your risk profile?

– Move your business forward?

Page 8: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Validation of Computerized Systems

The process of providing documented evidence that

a system does what it claims to do,

and that it will continue to do so in the future

Page 9: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

ITIL System Development Life Cycle

Page 10: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

GAMP Life cycle approachA life cycle approach entails defining and performing activities in a systematic way from conception, understanding the requirements, through development, release, and operational use, to system retirement.

(Figure from GAMP 5)

Page 11: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

ITIL Service Perspective

Page 12: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

GAMP Life cycle approach

The life cycle for any system consists of four major phases:

(Figure from GAMP 5)

Page 13: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

ITIL Service Lifecycle

Page 14: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Generic Case

• How to use ITIL® to map present operating

procedures and ways of working

Page 15: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

ITIL overview

Page 16: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

IT QMS - Compliance focus

Page 17: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

IT QMS – ITIL processes

Page 18: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

IT QMS - Other Procedures

Page 19: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

IT Compliance

Quality Security

Process

Page 20: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Objectives achieved

• IT compliance requires control of:

– People ☺

Applications

Data

Infrastructure

Procedures

Ways of working

– Documented evidence

Covered by

Page 21: ITIL and Compliance - Epista · ITIL and Compliance, 13.30 –14.15 ... – Lean in IT Mikael May Yde ... • How to use ITIL® to map present operating

Questions?

Mikael May YdeSenior Compliance Consultant

_____________

epista ITSlotsmarken 17

2970 Hørsholm

Denmark

M: +45 5369 4973E: [email protected]