<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>IT Compliance and Controls</title>
	<atom:link href="http://www.itcomplianceandcontrols.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.itcomplianceandcontrols.com</link>
	<description>Converging Business, Information, and Controls</description>
	<pubDate>Mon, 09 Nov 2009 15:16:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Lessons from Financial Crisis for CIO and Executive Technology Leadership, pulled from Senior Supervisors Group</title>
		<link>http://www.itcomplianceandcontrols.com/2009/11/09/lessons-from-financial-crisis-for-cio-and-executive-technology-leadership-pulled-from-senior-supervisors-group/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/11/09/lessons-from-financial-crisis-for-cio-and-executive-technology-leadership-pulled-from-senior-supervisors-group/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 15:16:38 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2009]]></category>

		<category><![CDATA[cio]]></category>

		<category><![CDATA[ciso]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[corporate integrity]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[Executive]]></category>

		<category><![CDATA[Financial Crisis]]></category>

		<category><![CDATA[governance]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[Peter Drucker]]></category>

		<category><![CDATA[Senior Supervisors Group]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=63</guid>
		<description><![CDATA[According to a recent examination by global professionals relating to the failure of risk management controls with respect to financial exposures many of the failures can be attributed to very specific technology failures.  This does not excuse the vast amount of other shortfalls, and apply blame as you see fit arguments.  It does highlight that [...]]]></description>
			<content:encoded><![CDATA[<p>According to a <a href="http://www.newyorkfed.org/newsevents/news/banking/2008/rp080306.html">recent examination</a> by global professionals relating to the failure of risk management controls with respect to financial exposures many of the failures can be attributed to very specific technology failures.  This does not excuse the vast amount of other shortfalls, and apply blame as you see fit arguments.  It does highlight that these did certainly not help the situation any, and in fact exasperated it to some degree.  A few cogent points highlighted in the 36 page report are eerily applicable to all organizations, and should be a flare to all audit, security, risk managers, and compliance personnel.  <a href="http://www.newyorkfed.org/newsevents/news/banking/2008/SSG_Risk_Mgt_doc_final.pdf">PDF Report can be downloaded here</a>.</p>
<p><em>Points that should be carefully considered:</em></p>
<blockquote><p>&#8220;One challenge to improving risk management systems has been poor integration resulting from multiple mergers and acquisitions&#8221;</p></blockquote>
<p>This is especially dangerous considering that many businesses choose to operate separately initially to insulate interruptions to the business at large.  Information systems are generally incompatible at the beginning of any integration.  This is due to the lack of pre-planning and enterprise M&amp;A integration methodologies within the acquiring firms.  Organizations should take immediate action if they have acquired entities without consolidating these technology systems, or at the very least routing ALL traffic, logs, compliance controls, and processes through the acquiriing entity.  This creates both friction and a need for efficiency - two very powerful forces that will result in immediate transformation of these information technology environments, in the right direction.</p>
<blockquote><p>&#8220;&#8230;acquisitions over the years have produced an environment in which static data are largely disaggregated&#8221;</p></blockquote>
<p>This effects the ability to ensure daily consistent delivery of data and information technology services.  In addition, historic activity is just as important in managing current data environments.  Lacking such clarity and statistics requires executives to manage blindly without any context and sensible barometer of delivery and achievable commitments.</p>
<blockquote><p>&#8220;&#8230;certain products and lines of business have not been included in data aggregation and analysis processes&#8221;</p></blockquote>
<p>Technology historically has been disconnected from the business delivery objectives, and actual exclusion of specific products and businesses only ensures budgets will be misplaced; service will be inappropriate; and risks will not be addressed properly (if at all)</p>
<blockquote><p>&#8220;&#8230;two systems for the same business results in duplication of processes&#8221;</p></blockquote>
<p>This finding simply highlights waste - waste in resources; talent; time; bandwidth; budget, and brainpower.  In an age of interconnected capabilities such requirements for dual systems should becoming sparse and rare.</p>
<p>An interesting message echoes throughout the report was risk managements lack of complete visibility into the firms&#8217; risks.  A point that is both similar in nature and impact to CIO and Technology executives alike.  How well do we professionals truly understand what is happening and has happened within the business information systems?  Is all the data that is pertinent provided and managed?  <a href="http://harvardbusiness.org/search/drucker/">Peter Drucker</a> would certainly ask - Are you fully aware of the system (not the one computer or the e-transactions, but the technology system as a whole)?  Are you making choices based on all the right information, or based on the information you have (right or wrong)?</p>
<p>The crossovers from professional risk management and technology leadership are clear, striking, and very relevant.  It is prudent that today&#8217;s leadership is aware and armed with the skills across many trades - risk management in particular - to truly leverage the centuries of experience that exist within arms reach.</p>
<p>Additional perspective - please leave a comment,</p>
<p>James DeLuccia IV</p>
<p>Check out my other thoughts here on <a href="http://pcidss.wordpress.com">IT Controls and PCI DSS</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/11/09/lessons-from-financial-crisis-for-cio-and-executive-technology-leadership-pulled-from-senior-supervisors-group/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Hard valuations and real world returns for IT GRC</title>
		<link>http://www.itcomplianceandcontrols.com/2009/11/05/hard-valuations-and-real-world-returns-for-it-grc/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/11/05/hard-valuations-and-real-world-returns-for-it-grc/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 14:26:14 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2009]]></category>

		<category><![CDATA[Aberdeen Group]]></category>

		<category><![CDATA[Analyst report]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[cost of impact]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[governance]]></category>

		<category><![CDATA[GRC]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[IT GRC]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=60</guid>
		<description><![CDATA[In the past five years of delivering work that has been focused on aligning and enhancing corporations against contractual agreements, operational requirements, and risks - today officially classified as Governance, Risk and Compliance (or GRC) through technology I have seen real returns for my clients.  While these improvements happen immediately, the real rewards are realized [...]]]></description>
			<content:encoded><![CDATA[<p>In the past five years of delivering work that has been focused on aligning and enhancing corporations against contractual agreements, operational requirements, and risks - today officially classified as Governance, Risk and Compliance (or GRC) through technology I have seen real returns for my clients.  While these improvements happen immediately, the real rewards are realized through embedding the efforts over the long haul.  I have been quite pleased with the results of my own GRC activities, and based the book on highlighting these core success criteria.</p>
<p>A recent survey, albeit funded by a GRC vendor, conducted by the Aberdeen Group reinforces the returns corporations receive through adopting GRC into their organizations.  I find these results to be in-line with my own personal experience.  The link to the press release is <a href="http://www.businesswire.com/portal/site/home/permalink/?ndmViewId=news_view&amp;newsId=20091021006549&amp;newsLang=en">here</a>.  A quick bit of the numbers they highlight include:</p>
<blockquote><p>Some of the main results pointed out by the research shows that        Best-in-Class companies:</p>
<p><strong>1.</strong> estimated that business-critical decisions are made 10%        faster, based on improved management visibility into current risks.</p>
<p><strong>2.</strong> eliminated redundant risk management activities and processes,        with a reduction of 8.5%.</p>
<p><strong>3.</strong> improved efficiency of their compliance tracking and reporting        processes by 12% and their ability to provide clear, timely        communication of risks and compliance status to shareholders and board        of directors.</p>
<p><strong>4.</strong> increased their flexibility to adjust to new or updated        regulatory requirements by 11.5%.</p></blockquote>
<p>I strongly encourage organizations to develop a culturally correct IT Governance process and create an ongoing GRC initiative.  Only when technology, business risk, and innovation are moved together can organizations truly capitalize on the benefits of their existing assets.</p>
<p>A separate report, <a href="http://www.preventia.co.uk/resources/white%20papers/lumension/NIT-GRC-Aberdeen-Lumension.pdf">Managing Risk, Improving Visibility, and Reducing Operating Costs</a> was released in May 2009 which is also quite good and highlights the IT GRC benefits.  As with any industry report, be aware of the samples, scope, sources, funding for report, and how your organization differs and is similar in nature.</p>
<p>Other considerations?</p>
<p>James DeLuccia IV</p>
<p><em>(Please note, I was unable to locate the actual report beyond the broken link in the press releases.  I will check periodically and see if I can locate it when it becomes available.  If you find it, please post a comment and I will update here)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/11/05/hard-valuations-and-real-world-returns-for-it-grc/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Beware Outsourcing Savings from oDesk and others&#8230;</title>
		<link>http://www.itcomplianceandcontrols.com/2009/08/13/beware-outsourcing-savings-from-odesk-and-others/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/08/13/beware-outsourcing-savings-from-odesk-and-others/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 20:33:12 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[audit]]></category>

		<category><![CDATA[cio]]></category>

		<category><![CDATA[ciso]]></category>

		<category><![CDATA[cloud computing]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[corporate integrity]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[Executive]]></category>

		<category><![CDATA[governance]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=57</guid>
		<description><![CDATA[An incredible trend is happening in the &#8220;for contract&#8221; market  - specifically the for hire programmers.  oDesk and eLance both show dramatic upticks in the amount of work being posted and delivered on the site (nice article here on the growth).  oDesk alone is tracking about 100,000 hours a week of work, or nearly $65 [...]]]></description>
			<content:encoded><![CDATA[<p>An incredible trend is happening in the &#8220;for contract&#8221; market  - specifically the <em>for hire</em> programmers.  <a href="http://www.odesk.com/community/oconomy">oDesk</a> and <a href="http://www.elance.com/skills_central">eLance</a> both show dramatic upticks in the amount of work being posted and delivered on the site (<a href="http://www.techcrunch.com/2009/08/13/in-a-tight-economy-outsourced-developers-on-odesk-work-100000-hours-a-week/">nice article here on the growth</a>).  oDesk alone is tracking about 100,000 hours a week of work, or nearly $65 million dollars worth.  This massive increase in outsourced projects to independents and for hire groups is an indicator of the need for businesses to find affordable development, but at what cost?<br />
The trend is perfect for highlighting how businesses can shift to deliver services required - in any economy.  The trend also equally shows that the practices and methods equally shift.  The challenge is making this shift securely and with the correct safeguards.  (This is highlighted nicely from a macro risk perspective by Mike Nolan here in <a href="http://kpmg.com/Global/IssuesAndInsights/ArticlesAndPublications/Pages/The-need-for-alignment.aspx">The Need for Alignment</a>.)  Leveraging contractors has always required specific validation techniques:</p>
<ul>
<li>Right to Audit clauses to ensure operations meet marketing materials</li>
<li>Background check summaries on contractors</li>
<li>AV and Malware running on contractor systems (<a href="http://www.cio.com/article/498629/P_P_Ban_Plan_for_Government_Gets_Mixed_Response">or in the U.S. government, no p2p</a>)</li>
<li>Vendor management procurement procedures</li>
</ul>
<p>Awareness is necessary for when these jobs begin to be sourced through open market places.  The fidelity of the business providing the services, protection of intellectual property, and the proper review of software against best practices is only the beginning of the new and expanded risks that must be considered.<br />
Businesses and leaders should certainly embrace these open markets that allow greater access and better price transparency, but it must be done in a manner that reflects the risk capability of the business to ensure a balanced operating environment.</p>
<p>Additional thoughts and ideas on best practices for vetting outsourcing vendors?</p>
<p>James DeLuccia IV</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/08/13/beware-outsourcing-savings-from-odesk-and-others/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Third Party Fraud - Breaking down Trust</title>
		<link>http://www.itcomplianceandcontrols.com/2009/08/04/third-party-fraud-breaking-down-trust/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/08/04/third-party-fraud-breaking-down-trust/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 21:29:35 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2009]]></category>

		<category><![CDATA[acfe]]></category>

		<category><![CDATA[audit]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[corporate integrity]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[forensic]]></category>

		<category><![CDATA[Fraud]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[kpmg]]></category>

		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=54</guid>
		<description><![CDATA[As the economies around the world remain challenged by the economic environment, the propensity for fraud is significantly higher.  One may speculate that fraud is consistent but only our sensitivity shifts between good and bad times.  Whichever school of thought you support is a matter of risk perspective, and quite irrelevant today.
Fraud is up on [...]]]></description>
			<content:encoded><![CDATA[<p>As the economies around the world remain challenged by the economic environment, the propensity for fraud is significantly higher.  One may speculate that fraud is consistent but only our sensitivity shifts between good and bad times.  Whichever school of thought you support is a matter of risk perspective, and quite irrelevant today.</p>
<p>Fraud is up on a worldwide basis.  The attacks and scams are increasing, and it is occurring across all sectors.  An excellent breakdown the &#8220;<a href="http://kpmg.co.uk/news/detail.cfm?pr=3334">KPMG Forensic Fraud Barometer</a>&#8221; states that <a href="http://www.cimaglobal.com/cps/rde/xchg/live/root.xsl/1630_11502.htm?itemid=19274631&amp;categoryname=Legislation">fraud</a> for the <a href="http://kpmg.co.uk/news/detail.cfm?pr=3541">UK and areas that over 1.1 billion Pounds of fraud have come to court in 2008.</a></p>
<p>The Association of Certified Fraud Examiners (ACFE) has a great amount of detailed <a href="http://www.acfe.com/about/statistics.asp">statistics here</a>, a <a href="http://www.acfe.com/documents/press-kit/acfe-small-business-fraud.pdf">nice simple guide for small businesses seeking to minimize/prevent fraud</a>, and a nice bit of information on the <a href="http://www.fraudconference.com/20th-recap.asp">past ACFE fraud conference</a> (highly recommended)</p>
<p>We are definitely seeing these frauds perpetrated in common channels - such as in Las Vegas at Conferences (below are several links to articles referring to two ATMs found during the DefCon 17 Conference - very interesting read):</p>
<ul>
<li><a href="http://hackaday.com/2009/08/04/malicious-atm-found-at-defcon-17/">Hack a Day Article</a></li>
<li><a href="http://www.engadget.com/2009/08/03/atm-scam-at-defcon-clearly-the-work-of-ironic-criminals/">Engadget Article</a></li>
<li><a href="http://it.slashdot.org/story/09/08/02/2151247/Scammer-Plants-a-Fake-ATM-At-Defcon-17?from=rss">Slashdot Article</a></li>
<li><a href="http://www.computerworld.com/s/article/9136179/Fake_ATM_doesn_t_last_long_at_hacker_meet">Computerworld Article</a></li>
<li><a href="http://www.wired.com/threatlevel/2009/08/malicious-atm-catches-hackers/">Wired Article</a></li>
</ul>
<p>In addition organized crime groups are also leveraging the technologies of today (Facebook, twitter, SMS) - and the attack vectors (i.e., phishing).</p>
<p><strong>Protection; Prevention; Detection:</strong></p>
<ol>
<li>Being aware of trends is vital to erecting current and appropriate (even if temporary) safeguards - such as required by the FTC Red Flag</li>
<li>Communicate with peers and collaborate - that may be accomplished by being a part of message boards; Twitter Groups, and attending Conferences.</li>
<li>Evaluate your fraud programs and determine the current success rate, and implement corrections.</li>
</ol>
<p>These are simply single high level areas to consider - review your fraud programs seriously and consider the resources available by the above referenced parties.</p>
<p>As mentioned by <a href="http://www.yhff.co.uk/Fraud%20Barometer%20-%20Feb%202009%20_2_.pdf">Vivien Osborne of KPMG UK in the KPMG Forensic Fraud Report</a>:</p>
<blockquote><p>&#8220;In these harsh economic times, internal fraud could become the tipping point between the survival and demise of an organisation.  Companies need to be rigorous about re-enforcing their anti-fraud measures.  By reviewing their high risk and key operations, having effective reporting channels and deploying detection mechanisms such as data analytics they may give themselves a better chance to fight fraud.&#8221;</p></blockquote>
<p>Additional Fraud Resources, please add below in comments.</p>
<p>Best,</p>
<p>James DeLuccia IV</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/08/04/third-party-fraud-breaking-down-trust/feed/</wfw:commentRss>
		</item>
		<item>
		<title>A bright spot in the innovation wave - a Venture Fund with strong focus on IT</title>
		<link>http://www.itcomplianceandcontrols.com/2009/07/08/a-bright-spot-in-the-innovation-wave-a-venture-fund-with-strong-focus-on-it/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/07/08/a-bright-spot-in-the-innovation-wave-a-venture-fund-with-strong-focus-on-it/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 20:41:24 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[data privacy]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[innovation]]></category>

		<category><![CDATA[pci dss]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[technology]]></category>

		<category><![CDATA[venture capital]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=52</guid>
		<description><![CDATA[As friends know, I have been launching businesses for the past few years with varied success and feelings about venture capitalists.  The summation is the common &#8220;chicken and egg problem&#8221;.  Meaning most investors that do not understand a new technology, or paradigm shifting solutions the investor(s) seek to see the solution working.  The inventor and [...]]]></description>
			<content:encoded><![CDATA[<p>As friends know, I have been launching businesses for the past few years with varied success and feelings about venture capitalists.  The summation is the common &#8220;chicken and egg problem&#8221;.  Meaning most investors that do not understand a new technology, or paradigm shifting solutions the investor(s) seek to see the solution working.  The inventor and technologist will likely feel that is the whole point of pitching for financing ;)  Hence chicken or egg.  I am extremely pleased to see <a href="http://blog.pmarca.com/2009/07/introducing-our-new-venture-capital-firm-andreessen-horowitz.html">Ben Horowitz and Marc Andreessen launching new fund</a> focused on placing money on the table to encourage solutions and innovation within IT Security, Compliance, and the tactical areas of the industry. One of their core principles:</p>
<blockquote><p>Technology and its advancement is absolutely central to human progress. Entrepreneurs who create new technologies and technology companies are improving the standard of living of people worldwide and unlocking amazing new levels of human potential.</p></blockquote>
<p>So a call to action to all my colleagues and friends that have been screaming and itching to make the world better through their own ingenuity and hardwork - APPLY; develop; and make a difference.</p>
<p>Or to consider the problem statement above:  Be a Rooster, because in the &#8220;Which came first the Chicken or the Egg&#8221; problem - the Egg is the answer, because Chickens don&#8217;t lay eggs - Roosters do.</p>
<p>Happy inventing and hacking,</p>
<p>James DeLuccia IV</p>
<p>For inspiration on problems to solve, <a href="http://pcidss.wordpress.com/">check out my other site here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/07/08/a-bright-spot-in-the-innovation-wave-a-venture-fund-with-strong-focus-on-it/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How understanding Human Behavior can improve your business</title>
		<link>http://www.itcomplianceandcontrols.com/2009/07/02/how-understanding-human-behavior-can-improve-your-business/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/07/02/how-understanding-human-behavior-can-improve-your-business/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 11:28:15 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[audit]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[cost]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[governance]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[regulations]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=50</guid>
		<description><![CDATA[There are many challenges to growing a business, sustaining a business, and definitely changing a business.  The latter, most would agree, is by far the hardest and largest challenge for organizations seeking to adopt controls throughout the business.  Now controls is a generic term being used now to include policies, procedures, technology safeguards, and routine [...]]]></description>
			<content:encoded><![CDATA[<p>There are many challenges to growing a business, sustaining a business, and definitely changing a business.  The latter, most would agree, is by far the hardest and largest challenge for organizations seeking to adopt controls throughout the business.  Now controls is a generic term being used now to include policies, procedures, technology safeguards, and routine human manual activities that seek to provide consistency of operations.<br />
As an advocate of trying to build control environments that reflect the business culture instead of forklifting a standard method (i.e., dropping COBIT 4 onto the business and walking away), it is encouraging to see how a study out of the University College of London support the potential of dense populations.<br />
The <a href="http://www.ucl.ac.uk/media/library/humanbehaviour">UCL study</a> found that &#8220;High population density leads to greater exchange of ideas and skills&#8230;&#8221;  This is profound when one considers how a business core team spends more time together then they do apart.  Even a common joke is that those who work together spend more time together then they do with their own spouses.<br />
The takeaway from this study is that businesses with core teams that work intensely together will excel where those alone cannot, and this is pointedly true with implementing a control environment.  It is true that bolting on a new standard or government set of mandates is inefficient, but what most fail to capture is how innovative businesses can be when working together to solve these problems together.<br />
Check out the interesting study here from the <a href="http://www.ucl.ac.uk/media/library/humanbehaviour">University College of London</a>.<br />
Moving forward - consider forming tight teams that are semi-permanent that are focused on finding innovation in the controls themselves to constantly uncover efficiencies and opportunities.</p>
<p>Best,</p>
<p>James DeLuccia IV</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/07/02/how-understanding-human-behavior-can-improve-your-business/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Compliance Week 2009:  Ineffective Controls due to Consolidation of Regulators</title>
		<link>http://www.itcomplianceandcontrols.com/2009/06/04/compliance-week-2009-ineffective-controls-due-to-consolidation-of-regulators/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/06/04/compliance-week-2009-ineffective-controls-due-to-consolidation-of-regulators/#comments</comments>
		<pubDate>Thu, 04 Jun 2009 16:24:12 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[audit]]></category>

		<category><![CDATA[compliance week]]></category>

		<category><![CDATA[corporate integrity]]></category>

		<category><![CDATA[Executive]]></category>

		<category><![CDATA[fcra]]></category>

		<category><![CDATA[GLBA]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[Practitioner]]></category>

		<category><![CDATA[sox]]></category>

		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=48</guid>
		<description><![CDATA[This week is Compliance Week and for most that implies vendor pitches and F.U.D., but there has been specific tidbits flow from the conference that indicate otherwise.  If you are not in attendance the consistent flow on Twitter (your window into conversations of interest) and upon blogs should give you a reasonable re-cap.  I strongly [...]]]></description>
			<content:encoded><![CDATA[<p>This week is <a href="http://www.complianceweek.com/page/525/annual-conference">Compliance Week</a> and for most that implies vendor pitches and F.U.D., but there has been specific tidbits flow from the conference that indicate otherwise.  If you are not in attendance the consistent flow on <a href="http://search.twitter.com/search?page=1&amp;q=%23cw2009">Twitter</a> (your window into conversations of interest) and upon blogs should give you a reasonable re-cap.  I strongly recommend if any sessions are of interest reaching out to the speakers directly and striking a conversation - <a href="http://www.complianceweek.com/page/528/annual-conference-speakers">the speaker&#8217;s list is here</a>.<br />
Michael Rasmussen has posted a <a href="http://corp-integrity.blogspot.com/2009/06/thoughts-from-compliance-week-09-day-1.html">nice update on his blog</a>.  He raises a point that is of particular interest to business executive and practitioners that I wanted to expand upon.  The concept of regulation, merging of regulating agencies, and the net effect on effectiveness and efficiencies.  There are plenty of arguments against regulation and for it, but that is not the point here - what is intriguing is what happens to the businesses themselves in these ebb and flow moments in our history?  I go into great detail on this fact <a href="http://www.amazon.com/gp/product/0470145013?ie=UTF8&amp;tag=itcomandcon-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0470145013">in my book</a>, but want to point out specific areas of focus.<br />
The concept of &#8220;consolidating&#8221; regulators and legislation to create a super structure to protect the citizens has the net effect of watering down guidance and regulation.  This is a common complaint for individuals adopting (fully) <a href="http://www.itil-officialsite.com/home/home.asp">ITIL v3</a> or <a href="http://www.isaca.org/cobit/">COBIT</a>.  These are too broad to properly fit any one organization, and unlikely to address the risks any one organization faces adequately.<br />
Given this observation, executives should consider:</p>
<ul>
<li>Embrace public; international; open governance / security frameworks and cut from here your own program</li>
<li>Cost to compliance should DECLINE and not increase over time - unless your business is expanding at which point the cost curve should be correlated to that of the expansion costs</li>
<li>The achievement of compliance is not sufficient to thwart the risks to the business - security, privacy, operational integrity, and satisfaction of contractual agreements require a cultural and organic approach</li>
</ul>
<p>Practitioners must take it upon themselves to educate and communicate when compliance F.U.D. and marketing take over a business&#8217; risk management programs.  Only through communication will everyone know what risks exist; what risks are addressed; which risks are immaterial; and how they fit together to form the information security program and governance processes.</p>
<p>Other insights and perspectives on the affect of consolidating and &#8220;watering down&#8221; effective controls and safeguards to the point where they do not address the original intent?</p>
<p>Kind regards,</p>
<p>James DeLuccia IV</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/06/04/compliance-week-2009-ineffective-controls-due-to-consolidation-of-regulators/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Cost of a Lost Laptop</title>
		<link>http://www.itcomplianceandcontrols.com/2009/05/04/cost-of-a-lost-laptop/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/05/04/cost-of-a-lost-laptop/#comments</comments>
		<pubDate>Mon, 04 May 2009 12:41:16 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[COI]]></category>

		<category><![CDATA[cost of impact]]></category>

		<category><![CDATA[data breaches]]></category>

		<category><![CDATA[data management]]></category>

		<category><![CDATA[fud]]></category>

		<category><![CDATA[intel]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[ponemon]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=45</guid>
		<description><![CDATA[There are numerous instances where laptops and portable devices are lost / stolen.  The classic CEO whose laptop disappeared at a conference to those thieves who coincidentally opened the one trunk of an auditor&#8217;s rental car and gained access to significant sensitive information sprinkle the news wires.
While imagination can speak to what the impacts may [...]]]></description>
			<content:encoded><![CDATA[<p>There are numerous instances where laptops and portable devices are lost / stolen.  The classic CEO whose laptop disappeared at a conference to those thieves who coincidentally opened the one trunk of an auditor&#8217;s rental car and gained access to significant sensitive information sprinkle the news wires.<br />
While imagination can speak to what the impacts may be - Intel sponsored a report by the Ponemon institute on this very topic.<br />
The net result is the majority of costs are derived from the substance of the data and not the actual laptop itself - meaning if there is Proprietary IP or protected sensitive data the costs are impactful.  Check out the <a href="http://communities.intel.com/docs/DOC-3076">Intel page here</a>, and the straight <a href="http://communities.intel.com/servlet/JiveServlet/download/3076-2-1994/Cost%20of%20a%20Lost%20Laptop%20White%20Paper%20Final%202.pdf">link to the paper here</a>.<br />
The report is centered explicitly on the costs and highlights the worst case scenarios without providing alternate avenues of thought and opportunity.  I would challenge readers of the report to consider how data is managed and utilized in the organization before safety cabling every laptop, deploying full-disk encryption (<a href="http://www.truecrypt.org/">not a bad idea</a>), or rolling out full dumb-terminal netbooks.<br />
In addition - consider the other devices that are transported with these laptops that can carry just as sensitive (or the same data) without any of the particular solutions or safeguards - your iphone / BB, a collection of USB tokens, CDs, ipod, <a href="http://www.rationalsurvivability.com/blog/?p=16">Kindle</a>, etc&#8230;</p>
<p>Consider all the data carriers before pushing out point solutions - data should be managed within an evolving program to satisfy each new channel and environment (Social networks, twitter, IM, torrent &#8230;)</p>
<p>Thoughts?</p>
<p>James DeLuccia IV</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/05/04/cost-of-a-lost-laptop/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Data Security and Privacy in a Downturn with 3rd Party Providers</title>
		<link>http://www.itcomplianceandcontrols.com/2009/02/27/data-security-and-privacy-in-a-downturn-with-3rd-party-providers/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/02/27/data-security-and-privacy-in-a-downturn-with-3rd-party-providers/#comments</comments>
		<pubDate>Fri, 27 Feb 2009 14:35:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[bpo]]></category>

		<category><![CDATA[cfo]]></category>

		<category><![CDATA[cio]]></category>

		<category><![CDATA[ciso]]></category>

		<category><![CDATA[cost]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[network world]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[regulations]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=43</guid>
		<description><![CDATA[Recently I contributed to a CIO Magazine and Network World piece on what is the impact to - Security and Privacy - in a downturn.  Specifically, what happens to all that sensitive data that was once locked behind doors and large security systems when the lights go out and the auction gavel hits the block?  [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I contributed to a <a href="http://www.cio.com/article/482187/When_A_Company_Folds_Who_Guards_Your_Data_s_Privacy_?page=1">CIO Magazine</a> and <a href="http://www.networkworld.com/news/2009/022409-when-a-company-folds-who.html">Network World piece</a> on what is the impact to - Security and Privacy - in a downturn.  Specifically, what happens to all that sensitive data that was once locked behind doors and large security systems when the lights go out and the auction gavel hits the block?  Please see the article <a href="http://www.networkworld.com/news/2009/022409-when-a-company-folds-who.html">here at Network World for a nice article,</a> and a timely post at LogBlog entitled &#8220;<a href="http://blog.loglogic.com/2009/02/is_your_data_protected_if_the_company_closes_its_doors.php">Is your data protected if the company closes its doors?</a>&#8220;.</p>
<p><em>Given those articles as the backdrop - there are two major concerns for executives and businesses that rely on third party firms (which is approximately 99% of the world).</em></p>
<p><strong>The first is the ability to deliver services without the incumbent service provider</strong></p>
<ul>
<li>When setting up third party service providers consideration must be placed on the exact details of how the data flows will occur.  This should be defined in the contract.</li>
<li>A common, and costly mistake by companies, is to not establish mechanisms to extract their business from a specific service provider.  This is caused by customizing your business to fit their processes, and thereby creating only one vendor that can service your firm.  Businesses must regularly review how these third party processors are integrated and establish a Back-Out Plan.  Similar in principle to a Disaster Recovery Plan (DRP), our BOP provides the organization with a full record of all business data and a workable repository that can be connected to a different vendor.  A consumer example - Ability to export your Google Contacts to your Exchange Server and vice versa, the easier it is the more likely you are to experiment and keep long term costs low.</li>
</ul>
<p><strong>The second is concern relating to the data and proprietary (patented?) processes and technology that may vanish when the business partner disappears.</strong></p>
<ul>
<li>The amount of information passed through a vendor varies, but inevitably sensitive information will be processed or transmitted.  The business owners should - in a contract, establish the ability to quarantine their data to specific systems, and may even consider &#8220;buying&#8221; these pieces of hardware to insure against losses in the future.</li>
<li>An alternate approach is to limit the data prudently to eliminate the possibility of company information being exposed.  This can be achieved by placing some processing in house and then passing along data to the vendor in a less sensitive manner.  A <a href="http://rationalsecurity.typepad.com/blog/2009/02/amazons-kindle-some-interesting-security-thoughts.html">consumer example is highlighted</a> on the <a href="http://www.amazon.com/gp/product/B00154JDAI?ie=UTF8&amp;tag=itcomandcon-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=B00154JDAI">Kindle2</a> and the 3rd party conversion process, and what if any data is being passed and processed.  (A single example of numerous services that slice through the daily business process that is seldom considered or understood, and only when problems (Breached / Hacked Organizations) make the news do we consider the full ramifications, let alone if the business itself vanishes.</li>
</ul>
<p>As is obvious, there are many approaches for businesses to leverage the BPO market while protecting the integrity of the business operations.</p>
<p>Best Regards,</p>
<p>James DeLuccia IV</p>
<p><a href="http://www.rsaconference.com/2009/us">**Speaking at RSA 2009 on the Payment Card Industry, April 22nd 2009**</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/02/27/data-security-and-privacy-in-a-downturn-with-3rd-party-providers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Positive Book Review</title>
		<link>http://www.itcomplianceandcontrols.com/2009/02/20/positive-book-review/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/02/20/positive-book-review/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 15:55:27 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=42</guid>
		<description><![CDATA[A new book review has been placed online by MSI.  A nice overview and elaboration of the book content. A nice highlight:
&#8220;DeLuccia lays a foundation by examining the importance of internal IT controls&#8230;explains why silo IT strategy wastes time and resources, offering a better solution in having an IT enterprise control environment&#8221;
Comments and challenges?
James DeLuccia
]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://stateofsecurity.com/?p=571">new book review has been placed online by MSI</a>.  A nice overview and elaboration of the book content. A nice highlight:</p>
<p><span>&#8220;DeLuccia lays a foundation by examining the importance of internal IT controls&#8230;explains why silo IT strategy wastes time and resources, offering a better solution in having an IT enterprise control environment&#8221;</span></p>
<p>Comments and challenges?</p>
<p>James DeLuccia</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/02/20/positive-book-review/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
