Home > Security News > Consensus Controls project aims to set benchmarks for compliance
Security News:
EMAIL THIS

Consensus Controls project aims to set benchmarks for compliance

By Marcia Savage, Features Editor, Information Security magazine
03 Oct 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A research firm is spearheading an effort to provide organizations with a way to see how the IT controls they implement for security and compliance compare with those of industry peers.

We're trying to provide a level of consensus building around what is appropriate based on your organization, your geography and risk exposures.
Brandon Dunlap,
managing director, Brightfly Inc.

The Consensus Controls project introduces the concept of peer review due care, said Brandon Dunlap, managing director of research at Houston-based Brightfly Inc. "The definition of due care is what a reasonable person in the same circumstances would do. A lot of people are introducing controls to achieve due care, but without context," he said.

It can be tricky for organizations to figure out appropriate controls to implement for complying with regulations such as HIPAA and SOX, he said. They often turn to frameworks like ISO 17799 or COBIT, but can wind up picking and choosing whatever controls "fit their risk appetite and they think can get them through an audit," Dunlap said. So finding the right balance can be a difficult and risky task.

"At the end of the day, organizations that spend more money on controls are way out there by themselves and taking money from shareholders because they're overdoing it," Dunlap said. "Conversely, if you're under doing it, you're probably going to get hit by a regulator or possibly a lawsuit."

The Consensus Controls project is designed to allow organizations to upload their spreadsheets of controls and compare them with their peers. For example, a health care company on the East Coast using a particular audit firm could compare its controls with other health care organizations in its area that use the same auditor. The information could arm a company with valuable data to work with auditors and executive boards, Dunlap said.

SearchSecurity radio:

"We're trying to provide a level of consensus building around what is appropriate based on your organization, your geography and risk exposures," he said. "We're trying to get people to tear down walls between their organizations and across industries to essentially decide what is reasonable when it comes to security and compliance considerations."

Dunlap said he's working with a variety of professional groups, including the Information Systems Audit and Control Association (ISACA) and the Center for Internet Security (CIS) to garner support for the project before formally launching it. Participants will be able to provide control data anonymously, if they prefer.

J.J. Thompson, president of the Information Systems Security Association (ISSA) Silicon Valley chapter, said ISSA members were "excited and intrigued" when Dunlap told them about the project at a meeting last month. Thompson, a partner at Rook Consulting, a San Jose-based IT risk management advisory services firm, was invited by Dunlap to help with the project.

"The lack of a mechanism for benchmarking controls with peers has led to the empowerment of auditors to drive the decision for what is 'reasonable.' Now the tables will be turned and industry will be able to support their own assessment of reasonability and the auditors will have to agree," Thompson said.

The project "will completely change the way we manage and audit compliance within the next two years," he added.

Thompson said the current state of the economy will mean IT executives will be pushed more than ever to reduce operating costs. Focusing on compliance inefficiencies is one way to reduce costs and Consensus Controls will enable organizations to "right-size" their control environment, he said.

Brightfly is providing the initial funding and stewardship for the project but the hope is that it will become self-sustaining with broad community involvement, Dunlap said.



Tags: HIPAASarbanes-Oxley ActEnterprise Risk Management: Metrics and AssessmentsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
HIPAA
Cost of security, IT management add up at healthcare facilities, study finds
Healthcare security spending remains sluggish, report shows
Creating a HIPAA employee training program
FTC extends breach notification to Web-based health repositories
Are there guidelines to create a HIPAA-compliant data center?
HHS HIPAA guidance on encryption requirements and data destruction
Writing a patient identifier policy to prevent common HIPAA violations
HIPAA compliance: New regulations change the game
HIPAA compliance manual: Training, audit and requirement checklist
Key elements of a HIPAA compliance checklist
HIPAA Research

Sarbanes-Oxley Act
SOX compliance burdens midmarket security teams
Ex-SEC chief Pitt decries state of Sarbanes-Oxley, risk management
Information security book excerpts and reviews
Internal audits for Sarbanes Oxley and internal IT support
Internal auditors and CISOs mitigate similar risks
Implement security and compliance in a risk management context
Does password sharing in international branches violate SOX?
Security visualization helps make log files work
The Little Black Book of Computer Security, 2nd Edition
RSA attendees see data classification, rights management projects stumble
Sarbanes-Oxley Act Research

Enterprise Risk Management: Metrics and Assessments
How to justify information security spending on cloud computing
Layoffs prompt insider threat fears, cybersecurity survey finds
How to avoid Internet liability lawsuits
Bruce Jones: Report Security and Risk Metrics in a Business-Friendly Way
Bernie Rominski: Communicate Effectively with Management about Risk
Best Policy and Risk Management Products
Monitoring program data and internal controls for risk management
Risk management strategy for an information technology solution provider
Align your data protection efforts with GRC
The basics of enterprise GRC project management
Enterprise Risk Management: Metrics and Assessments Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts