NAVEX > 实例探究 > Major Medical Device Manufacturer Automates IT Risk and Compliance Processes

Major Medical Device Manufacturer Automates IT Risk and Compliance Processes

NAVEX Logo
产品
  • NAVEX IRM
技术栈
  • GRC platform
实施规模
  • Enterprise-wide Deployment
影响指标
  • Cost Savings
  • Productivity Improvements
技术
  • 分析与建模 - 实时分析
  • 应用基础设施与中间件 - 数据交换与集成
适用行业
  • 医疗保健和医院
适用功能
  • 离散制造
  • 质量保证
用例
  • 预测性维护
  • 过程控制与优化
服务
  • 数据科学服务
  • 系统集成
关于客户
The customer is a major medical device manufacturer. They are focused on building world-class surgical devices for hospitals. However, less attention is given to IT risk, information security and audit compliance - but failures on these fronts can lead to fines, litigation and reputation loss. The company’s IT security team was not equipped to manage risks and comply with audits. Essential information was difficult to track down, often stored in emails or individual spreadsheets. The company managed web application assessments, penetration tests and vulnerabilities as separate efforts.
挑战
The medical device manufacturer was struggling with a lack of insight into IT risks, siloed information, and inefficient audit preparation. The company’s IT security team was not equipped to manage risks and comply with audits. Essential information was difficult to track down, often stored in emails or individual spreadsheets. The company managed web application assessments, penetration tests and vulnerabilities as separate efforts. Reporting was manual and cumbersome, so risks were rarely visible to leadership. Audits were labor-intensive tasks that required collecting data from different departments and it took weeks of preparation before external auditors arrived. The medical device manufacturer needed a unified way to collect information, report on potential risks and streamline the audit process.
解决方案
The medical device manufacturer selected NAVEX’s GRC platform, NAVEX IRM, to address the company’s challenge with IT risk, audits and information security. Over the course of eight months, the company used NAVEX IRM to manage control activities and mapped policies to regulatory requirements from a centralized location, use automation to manage vulnerabilities, map IT risks to business risks for an enterprise-wide view, combine web application and penetration test results for the past two years, creating a historical, searchable system of record, and organize and speed up external audits using a single dashboard to display audit progress with real-time tracking and insights. The company managed to centralize all risk data and documentation and respond to audit requests in days instead of months.
运营影响
  • Switching from manual processes to automation with NAVEX IRM saved time and money.
  • The company managed to centralize all risk data and documentation and respond to audit requests in days instead of months.
  • By using NAVEX IRM to become more efficient at critical tasks, IT, audit and compliance staff had more time to focus on other initiatives to lower costs and remediate risks.
数量效益
  • Automated parts of the vulnerability management process in 2 months
  • Reduced audit preparation time by 80%: from 5 weeks to 1 week
  • Created a dashboard to display near real-time risk posture
  • Automated alerts and notifications for managers and auditors during the audit process

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

相关案例.

联系我们

欢迎与我们交流!
* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

感谢您的信息!
我们会很快与你取得联系。