您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。 [Octopus Deploy]:合规与持续交付:金融服务业及受监管组织如何在不妥协的前提下平衡合规与创新 - 发现报告

合规与持续交付:金融服务业及受监管组织如何在不妥协的前提下平衡合规与创新

金融 2025-01-01 Octopus Deploy 七个橙子一朵发🍊
报告封面

BYSTEVEFENTON Howthefinancialserviceindustryandotherregulatedorganizationscanmanagecompliance Compliance through Continuous How thefinancial service industry and otherregulated organizations can manage compliance Copyright © 2025 by Octopus Deploy Pty. Ltd. All rights reserved. Except for brief quotations in critical articles or reviews, no part of this book may be reproduced in any mannerwithout prior written permission from the publisher, Octopus Deploy. Level 4, 199 Grey Street, South Brisbane, This publication contains opinions and ideas of the author. It is intended to provide helpful and informativematerial on the subjects addressed in the publication. The author and publisher make no warranty, express or Octopus, Octopus Deploy, and the Octopus logo, are registered trade marks of Octopus Deploy Pty Ltd. Ed.1.2025.2 IntroductionThe impact of new regulationsPenaltiesImpact on product and featuredevelopment Organizations in thefinancial services industry feel the perceived trade-offbetween throughput and stability more keenly than those in unregulated sectors.There seems to be an unresolvable tension between slowing down the rate of Traditionally, organizations have implemented a slow-by-default deploymentpipeline dominated by manual checks and approvals, with an exceptionalprocess to expedite changes when there's an urgent need. The problem with this In Continuous Delivery (Addison-Wesley, 2010), Dave Farley and Jez Humbleshare that the best solution to this tension is to create a streamlined deploymentpipeline for all changes that uses automation to reduce manual handling. When A modern deployment pipeline doesn't skip past the checks the business needs.Instead, it reduces friction with automation and strong tooling so thatorganizations can have a fast and reliable path to production. This is now This report looks at the relationship between different approaches todeployment pipelines in the context of regulated organizations. We offer a deep This report is based on data explicitly collected from organizations in thefinancial industry. The survey was conducted early in 2025 and had 50 The impact of new regulations While theDigital Operational Resilience Actis an EU initiative, it provides anopportunity to assess the impact of new regulations on technology teams. Thelegislation was enacted in 2023 with a compliance deadline of January 17, 2025. With the steady rise in cyberattacks, the act was developed to protect thefinancial sector. It applies to institutions offeringfinancial services in the EU andtheir third-party suppliers of information and communication technology (ICT). It Incident management, classification, and reportingOperational resilience testingData sharing arrangementsManaging third-party risks Penalties for non-compliance Like similar regulations, non-compliance penalties include significant monetary In 2024, worldwide regulatoryfines increased to a record-breaking$19.3 billion.In the US, regulators issued$4.3 billioninfinancial penalties. In addition tofinancial and reputational damage, there is an increasingwillingness to pursue criminal prosecution, which can mean jail time for Impact on product delivery and The % of time software teams spend on compliance with new regulations. We asked organizations to assess the impact of compliance with the newregulations in terms of the loss of focus on other software development work.Most organizations lose up to 20% of their roadmap to compliance activities, Many organizations with low compliance overheads operate solely in domesticmarkets outside of the EU. They have assessed the regulations and concluded Compliance with existing standards was also cited as a reason for organizationshaving a low overhead of adopting the Digital Operational Resilience Act. These Where the Digital Operational Resilience Act was the organization's driver foradopting these practices, the investment required has been far higher. To attain A small number of organizations were not aware of the legislation, and oursurvey has prompted them to investigate further, which suggests awareness is Specific focus areas Organizations are managing the impact of the legislation through increased Strengthened disaster recovery and business continuity planningEnhanced monitoring and alerting systemsImproved incident management and classification processesMore rigorous security testing and vulnerability management A particular difficulty is the need to improve the practice of third-party suppliers Increased compliance overhead Multiple respondents note the administrative burden, including: More frequent security patching requires additional deployment cyclesEnhanced documentation and audit trail requirementsIncreased internal audits and risk-related tasksMore detailed incident reporting and classification Organizations without automated deployment pipelines struggle to meet thedemand for increased deployment frequency. Some organizations have