Home > Policies and regulatory compliance
Information Security magazine:
EMAIL THIS

Policies and regulatory compliance

08 Jun 2006 | Information Security magazine

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

By Harris Weisman

Prior to the Enron and MCI/WorldCom debacles, corporate management and boards of directors paid little attention to IT security policies. That's changed with the passage of SOX and the potential of fines and jail time for companies and their executives if there's a violation.

SOX is intended for publicly traded companies and focuses on the accuracy of financial reporting. Section 404 looks at information systems and the controls around them; failure to have an IT security policy and policy management are considered exceptions, causing problems for the company. There really aren't any must-have policies for SOX compliance -- auditors are looking for a strong overall information security program and policies, plus in-place monitoring of users and systems for compliance.

In addition to SOX, HIPAA and GLBA are other legislation that impact security policies. Both require keeping data private: HIPAA with regards to healthcare information, and GLBA with regards to financial data. Companies involved with either financial or healthcare information must develop, deploy, monitor and manage policies that govern how data is stored and transmitted. These policies can affect the entire IT infrastructure of an organization from firewall configuration to the data stored on workstations.

HIPAA and GLBA auditors will look for a solid data classification policy, or a policy that describes what types of data are used within the organization and how they are classified for privacy and security. Policies describing cryptography and cryptographic standards for the storage and transmission of sensitive data need to be outlined and deployed. Overall, auditors look for policies and procedures/guidelines that outline your data classification program and describe how that program will protect data within the organization.



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Compliance Regulations
The power of the ICO: Liabilities for a data security breach
Privacy, data protection must be built into system design, says ICO
Using ISO 27000 to comply with Data Protection Act principles
Latest U.K. data security laws get tough on fines, PETs and policies
Will the Data Handling Review improve government security practices?
The 'appropriate' way to comply with Data Protection Act 1998
Best practices: Handling compliance during a corporate merger
Information Commissioner turns up the heat on data breach culprits
Email confusion could look bad in court
Firms aim to achieve PCI compliance deadline, despite the cost

Security Policies and Awareness
Security is a people business, don't forget it
Appliance provides network access protection on school campus
How to prevent clickjacking attacks with security policy, not technology
Privacy, data protection must be built into system design, says ICO
Can policy thwart disgruntled employee data leaks?
Setting up a remote access security policy
Security policies often ignored, non-existent, survey finds
Information Commissioner turns up the heat on data breach culprits
DLP useless when companies fail to classify data
Finance sector poor at achieving outsourcing success

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Basel II  (SearchSecurityUK.com)
EU Data Protection Directive  (SearchSecurityUK.com)
Financial Services Authority  (SearchSecurityUK.com)
UK Identity Cards Act  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts