Home > Policies and regulatory compliance
Information Security magazine:
EMAIL THIS

Policies and regulatory compliance

08 Jun 2006 | Information Security magazine

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

By Harris Weisman

Prior to the Enron and MCI/WorldCom debacles, corporate management and boards of directors paid little attention to IT security policies. That's changed with the passage of SOX and the potential of fines and jail time for companies and their executives if there's a violation.

SOX is intended for publicly traded companies and focuses on the accuracy of financial reporting. Section 404 looks at information systems and the controls around them; failure to have an IT security policy and policy management are considered exceptions, causing problems for the company. There really aren't any must-have policies for SOX compliance -- auditors are looking for a strong overall information security program and policies, plus in-place monitoring of users and systems for compliance.

In addition to SOX, HIPAA and GLBA are other legislation that impact security policies. Both require keeping data private: HIPAA with regards to healthcare information, and GLBA with regards to financial data. Companies involved with either financial or healthcare information must develop, deploy, monitor and manage policies that govern how data is stored and transmitted. These policies can affect the entire IT infrastructure of an organization from firewall configuration to the data stored on workstations.

HIPAA and GLBA auditors will look for a solid data classification policy, or a policy that describes what types of data are used within the organization and how they are classified for privacy and security. Policies describing cryptography and cryptographic standards for the storage and transmission of sensitive data need to be outlined and deployed. Overall, auditors look for policies and procedures/guidelines that outline your data classification program and describe how that program will protect data within the organization.



BROWSE BY TAG
People & policy,   Policy enforcement,   Compliance,   Information Security Threats,   Identity Theft and Data Security Breaches,   Security Audit, Compliance and Standards,   Sarbanes-Oxley Act,   Gramm-Leach-Bliley Act (GLBA),   HIPAA,   Information Security Policies, Procedures and Guidelines,   Information Security Management,   Enterprise Data Protection,   Identity Theft and Data Security Breaches,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Policy enforcement
Security policies: Don't be an army of one
Defending the rock: Prudential's security culture and change control management
Separating fact from fiction: Security technologies for regulatory compliance

Identity Theft and Data Security Breaches
How to prevent and build protection against online identity theft
Heartland breach highlights PCI limitations
FBI investigates coordinated ATM scam
Encrypt now to meet new Mass. data protection law
Recovery plans essential for preventing data loss disasters
Internal auditors and CISOs mitigate similar risks
Cybersecurity expert sees PCI DSS problems ahead for retailers
PCI is about eliminating data, not securing it, former QSA says
Data breach discovery, disclosure outpaces 2007
PCI groups to focus on wireless, pre-authorization changes
Identity Theft and Data Security Breaches Research

Sarbanes-Oxley Act
Ex-SEC chief Pitt decries state of Sarbanes-Oxley, risk management
Information security book excerpts and reviews
Internal audits for Sarbanes Oxley and internal IT support
Internal auditors and CISOs mitigate similar risks
Implement security and compliance in a risk management context
Does password sharing in international branches violate SOX?
Consensus Controls project aims to set benchmarks for compliance
Security visualization helps make log files work
The Little Black Book of Computer Security, 2nd Edition
RSA attendees see data classification, rights management projects stumble
Sarbanes-Oxley Act Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
Find Security Channel Research for Resellers and Partners
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts