How to manage feedback in the compliance review process

We're revisiting our compliance policies, and want to get input from all business units and other stakeholders, but when we last did this, two to three years ago, the compliance review process became unruly. What's the best way to keep things in check? Solicit electronic feedback? Have a few meetings? Have an off-site? Who gets invited?

    Requires Free Membership to View

I'd encourage you to focus your efforts on the facts as much as possible. Generally speaking, compliance reviews are a fact-finding mission with several goals:

  1. Identify all activities in your organization that are subject to each compliance obligation.
  2. Identify the security controls in place surrounding those activities.
  3. Determine whether the security controls meet the requirements or whether you have compliance gaps.
  4. Design a remediation plan designed to fill any gaps, and bring your organization into compliance.

Ask the Expert

Got a vexing problem for Mike Chapple or any of our other experts? Ask your enterprise-specific questions today! (All questions are anonymous.)

You should avoid open-ended or philosophical questions that could lead to the type of unruly process you describe. I would suggest tackling each of the four goals above one at a time. Contact each business unit and provide them with the list of compliance-covered activities from your last assessment, and ask them to identify any changes that affect the list. Once you have a list of activities subject to various regulations, enumerate the controls surrounding those processes, identify any gaps and design remediation plans.

The format of your compliance review will depend upon its complexity and the culture of your organization. I prefer to hold annual face-to-face meetings with each stakeholder to review our organization's compliance plans, but that's the culture in my environment. If that would be unwieldy for you, due to your company's complexity or culture, consider conducting the review electronically instead. Whatever format you use, the key is to design the process in a manner that keeps participants focused on identifying facts, rather than rendering opinions.

This was first published in July 2012

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: