Viewpoint: Let's add policy to GRC - Information Security Magazine - Page 1

Viewpoint: Let's add policy to GRC

How Do You Spell Data Governance? P-o-l-i-c-y
Regarding the Perspectives column by Julie Tower-Pierce ("Think Like a Lawyer,"

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

March 2008) there is a very crucial word missing: policy.

One of the most important aspects of any healthy e-discovery strategy is policy governing how data is handled, retained, destroyed and retrieved. Without standing policy (i.e., one you did not create after being served a subpoena) that spells out how your organization handles its data, you will find yourself on the very wrong end of a judge's orders requiring the (very expensive) production of records...and perhaps in need of refreshing your resume...or worse.

Stephen Yelick
Information technology security administrator, Macomb County, Mich.


Open Source Does the Job
I just finished reading "Encrypt Them All" (February 2008), and I have to admit that I am surprised that the open source solution, TrueCrypt, was never mentioned.

We have been using SecureDoc for many years and recently decided to give TrueCrypt a try as an alternative. I must admit, I was thoroughly surprised. Although not without problems, it turned out to be a very capable open source solution, and it is very possible that this will be our software of choice. So I must ask, why was it not given consideration for the article?

Art Beard
Manager of information technology, Community Financial


Editor's Note:
The product chart that accompanied the "Encrypt Them All" article was a representative sample of commercial products.

This was first published in May 2008