Requires Free Membership to View
Most notable among the various compliance regulations in which organizations have invested significant time and money as of late have been the PCI DSS, HIPAA and SOX. All three regulations have a heavy focus on data protection and mandate that companies demonstrate a working identity management program, so it's not terribly surprising to hear about changes like the ones you are seeing.
The question is, what should you do? My advice is don't worry about what other companies are doing. Rather, talk with your executives about what their current and planned business priorities are, and alter your organization's security programs accordingly. That may mean working on data protection and IAM, but it could also mean working on Web application security or something completely different -- like security awareness training -- or implementing changes to policy and software development processes.
For more information:
- Get tips on protecting security budgets in a poor economy.
- Increase security with a decreasing budget with this expert advice.
This was first published in January 2009
Security Management Strategies for the CIO
Join the conversationComment
Share
Comments
Results
Contribute to the conversation