Home > Information Security Tips > Compliance and regulations > Consider a compliance-driven security framework
Security UK Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE AND REGULATIONS

Consider a compliance-driven security framework


Ravila Helen White, Contributor
08.12.2009
Rating: --- (out of 5)


Security UK Tips and Expert Advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


HIPAA, PCI DSS and Sarbanes-Oxley (SOX) are well known in information security and business. Despite the fact that the business is aware of these regulations and is willing to support them to avoid sanctions, there still exists a gap when information security professionals and the business must collaborate to ensure compliance. The result is mismatched expectations and frustration.

In part, some of the frustration is justified from the business as many information security professionals will use guidelines from the IT Governance Institute, the National Institute for Standards in Technology (NIST) and ISACA's COBIT as a basis for developing information security frameworks. This results in the business being presented with a framework that is heavily security centric and laden with technology and complex countermeasures as the 'fix' toward compliance. This is of concern for midmarket companies since they are typically focused on improving their long-term competitive stature. In today's market, part of that strategy is the outsourcing of functions which carry a level of risk as the data associated with these functions is sensitive and or confidential in nature. Stringent guidelines, costly technology and complex countermeasures will adversely impact the businesses overall goal of market competitiveness.

Rather than relying solely on the traditional information security guides to build a security framework, consider using one or more of the compliance regulations as a framework. Why? If an organization is already aware that they must meet both SOX and PCI requirements there is already a level of awareness among the stakeholders who must support these requirements. By using a compliance-driven framework, you may be better able to demonstrate how the countermeasures and controls you've been pushing will help the organization support compliance. Let's use PCI as our example.

PCI has 12 requirements that must be met by organizations that process credit card information. These requirements can be fully mapped to the recommendations of a security program as put forth by the IT Governance Institute. The difference between the two is that the PCI requirements are more granular and mention specific actions, technology types and in some cases explicit technology use to reach compliance. The simple presentation of the requirements will be more digestible in a framework that the business must buy into as compared to the broad categories typically seen in information security centric guides.

A pitfall though of the granular presentation of PCI requirements is seen when you realize that some of the traditionally supporting elements of a security program are not present. For instance, requirements 7, 8, 9 and 12 can be easily implemented but poorly supported if an organizations user community is not aware of why these requirements are necessary. PCI does not prescribe security awareness training as a method for supporting the education around the requirements. A similar gap is evident with requirements 1-6 and the lack of an iterative security assessment process to identify any lapses in security posture as a result of configuration changes in technology. Not to be forgotten is the lack of incident management in the PCI standard. Most security practitioners understand that it's not "if" a breach will occur but "when" it occurs you must be prepared to respond. So how may one go about developing and presenting a compliance-based framework without critical gaps?

You can gain efficiency in the creation of your compliance-based framework if you take your existing information security centric framework and overlay it on the compliance-based framework. Keep the information security centric requirements that you have identified as gaps in the compliance-based framework. Finally using a people, processes and technology (PPT) methodology you can merge the two frameworks into one. The result is a framework that is driven by compliance and supported by traditional information security program pieces.

Whether you are creating a program from scratch or adapting an existing program you must be patient as it typically takes at least 2.5 years to see the results of program efforts. Be prepared to fight some of the same battles and introduce new ones.

Ravila Helen White is senior IT security analyst for the Bill & Melinda Gates Foundation.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.co.UK.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Compliance and regulations
Encryption basics: How asymmetric and symmetric encryption works
SIEM systems streamline compliance processes, offer security benefits
Tips to achieve PCI compliance
How to choose an external compliance auditor
Using a privacy impact assessment template for DPA compliance
PCI DSS checklist: Mistakes and problem areas to avoid
The elements of a compliance-oriented architecture
Wireless network guidelines for PCI DSS compliance
PCI DSS requirement: Implement strong access control procedures
How to choose full disk encryption for laptop security, compliance

Compliance Regulation and Standard Requirements
PCI DSS requirements still baffling as compliance deadline approaches
Make PCI DSS compliance easier by reducing scope, outsourcing data
Cloud computing compliance: Exploring data security in the cloud
Encryption basics: How asymmetric and symmetric encryption works
SIEM systems streamline compliance processes, offer security benefits
No major PCI DSS revision expected in 2010
PCI QSAs, certifications to get new scrutiny
Tips to achieve PCI compliance
PCI DSS requirements: Get ready for stricter enforcement, fines
Data Protection Act breach could cost companies 500,000 pounds

IT Security Frameworks and Standards
How to develop a culture of security in the enterprise
ICO issues draft guidelines for personal information online
Using a privacy impact assessment template for DPA compliance
Benefits of ISO 27001 and ISO 27002 certification for your enterprise
How to write an information security policy
The elements of a compliance-oriented architecture
New products aim to streamline compliance efforts
A helpful BSI data protection standard for DPA compliance
How project management maturity models can reveal security strength
CSA, Jericho Forum unite on cloud computing security message

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Basel II  (SearchSecurityUK.com)
Code of Connection (CoCo)  (SearchSecurityUK.com)
EU Data Protection Directive  (SearchSecurityUK.com)
Financial Services Authority  (SearchSecurityUK.com)
IFRS (International Financial Reporting Standards)  (SearchSecurityUK.com)
UK Identity Cards Act  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



UK Data Security Solutions: Data Privacy, Identity Theft, Data Loss
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts