IT Compliance and Controls

Converging Business, Information, and Controls

IT Compliance and Controls header image 4

Entries from January 2008

Settled Identity Theft Complaints with the FTC

January 31st, 2008 · No Comments

A constant challenge for organizations is measuring the potential impact and consequences of mandated regulations. The weighting of compliance initiatives based on such consequences is not best practice, but is common. The need to demonstrate a true cost benefit analysis is dependent upon, in part, to the actual follow through and enforcement of requirements by […]

[Read more →]

Tags: FTC · GLBA · Identity Theft · Risk Awareness · Technology Intelligence · Technology Strategy Orchestration

Implementing Effective Ethics Programs

January 27th, 2008 · No Comments

The need for organizations to define and communicate effective policies and procedures resonates around the globe, and is strongly supported by such governance organizations to include the WTO, The World Bank, OCEG, and the OECD, to name but a few. A first, but essential, step to ensuring appropriate controls and operational efficiency is the defining […]

[Read more →]

Tags: Monitoring and Performance Reviews · Policy and Procedures · Risk Awareness · Tone at the Top

Sensitive Information includes Internet Addresses, EU Data Privacy Group

January 25th, 2008 · No Comments

Personally Identifiable Information is defined differently by each industry, country, and region. Companies must have information intelligence practices in place that account for these types of information, and means of classifying and protecting. Such information in the U.S. varies by jurisdiction, but can include medical records, financial information, and now perhaps in the EU your […]

[Read more →]

Tags: Human Resources · Monitoring and Performance Reviews · Policy and Procedures · Risk Awareness · Technology Intelligence

CIA: Energy Infrastructure Attacked

January 24th, 2008 · No Comments

In my book, IT Compliance and Controls, I highlight the importance of the energy infrastructure, and the risks that these systems face given their newly interconnectedness. To highlight the relevant points from the book – the energy infrastructures of the world support the medical, HVAC, security, and financial systems of our economies. The loss of […]

[Read more →]

Tags: Access and Authorization · Application Controls · Incident Response Capability · Logical Access · Monitoring and Performance Reviews · Physical Access · Sustain Operations · Technology Intelligence · Trusted Computing Platform Systems

Best E-Discovery Tools, Providers, and Trends

January 17th, 2008 · No Comments

The annual 2007 Socha-Gelbmann Electronic Discovery Survey has been released and is a great resource for vetting your current internal approach to managing data, and providing a quick guide for establishing a relationship based on industry opinion. Interesting facts include – market share, expertise in legal aspects of e-discovery, tools, and more.  A prime component […]

[Read more →]

Tags: Incident Response Capability · Monitoring and Performance Reviews · Security and Assurance · Technology Intelligence

News Beat: Technology Integration on the radar

January 14th, 2008 · No Comments

A quick news bite on a topic I similarly covered at the PCI DSS focused site was posted at Bank Systems and Technology.  Highlights the importance and challenge faced by organizations when they conduct M&A deals.  This article specifically covers the recent purchase by BofA for Countrywide. Check out the Article Here. Warning, they have […]

[Read more →]

Tags: Direcitonal Alignment · Risk Awareness · Technology Intelligence · Technology Strategy Orchestration