Home > Security News > Sound compliance policies, practices reduce legal costs
Security News:
EMAIL THIS

Sound compliance policies, practices reduce legal costs

By Neil Roiter, Senior Technology Editor, Information Security magazine
08 Sep 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The larger your organization, the more legal suits and regulatory investigations you can expect to have to deal with. And while the amended Federal Rules of Civil Procedure (FRCP) help clarify requirements for electronic discovery, the cost of holding, preserving and producing information for legal cases can run into millions of dollars.

The differences in performance outcomes in terms of spend were not related to size of company or industry grouping.
Jim Hurley,
managing director, IT Policy Compliance Group

But how much you spend on legal costs does not depend so much on the size of your organization, but, rather, on the policies, processes and practices you have in place, according to results of a survey of 235 U.S. firms released today by the IT Policy Compliance Group (IT PCG).

In fact, by following best practices, a company with $25 billion annual revenue can expect to spend only about $500,000 a year more than a $500 million company demonstrating the worst practices. Even more striking, best practices yield enormous reductions in the total annual cost of legal fees and settlements.

"The differences in performance outcomes in terms of spend were not related to size of company or industry grouping," said Jim Hurley, IT PCG managing director, "but what we did find was differences in outcome by spend were very related to practices."

Regardless of size, companies following best practices spent a small fraction on legal fees than those following the worst. Firms following what IT PCG describes as "normative" practices still spent just roughly a third of their less diligent counterparts.

The numbers are eye-popping. For example, best-practice companies with $500 million annual revenue spent an average of $174,000 on legal fees and settlements, compared to almost $3 million by those with worst practices. For $25 billion firms, the numbers were $3.6 million and $68 million.

Best practices yield similar annual savings in IT spending to find, produce, protect and preserve information. For $500 million companies, the best-worst number were $89,000 and $1,125,000; for $25 billion firms, about $1.6 million and $22 million.

SearchSecurity radio:

The legal custody of information affects organizations across the enterprise: legal, IT, finance, HR and senior management and employees.

IT PCG has some 3,000 members, more than half in the U.S. There are 20 advisory members taking the lead in guiding research and setting the editorial calendar, and several supporting members, including The IIA The Institute of Internal Auditors, the Information Systems Audit and Control Association, the IT Governance Institute, Protiviti and Symantec, which provides funding for ITpolicycompliance.com.

The report cited a number of strategic actions and practices by the best-performing companies:

  • Notifying affected employees of legal holds on data within one hour
  • Responding to legal requests within one day
  • Maintaining evidence of the handling of data
  • Delivering training to employees
  • Improving the quality of legal counsel
  • Tracking results to make subsequent improvements

    These firms also showed sound information lifecycle management for legal information, including converting as much as possible to electronic formats (not surprisingly, costs are highest for paper records and archived tapes); inventorying and indexing information for fast search, and updating police for record retention and destruction.

    In the U.S., FRCP is the prime driver for adopting sound processes for handling legal information, Hurley said. But while the survey was limited to the U.S., he believes many European companies are shoring up their practices for privacy compliance.

    "It's interesting to see that some of the firms in Europe I spoke with are implementing the same kind of practices even though external pressures are different," he said.



    Tags: Information Security Incident ResponseInformation Security Policies, Procedures and GuidelinesSecurity Awareness Training and Internal ThreatsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Information Security Incident Response
    Tying log management and identity management shortens incident response
    Tabletop exercises sharpen security and business continuity
    Security book chapter: Applied Security Visualization
    The challenges of incident response plans and procedures
    CISOs, human resources cooperation vital to security
    After a data breach, are there legal implications of sharing details?
    Boosting morale of the information security staff after a data breach
    Recovering stolen laptops one step at a time
    IT security pros face challenge during economic crisis
    Spotlight article: Domain 9, Physical Security
    Information Security Incident Response Research

    Information Security Policies, Procedures and Guidelines
    Twitter risks, Facebook threats trouble security pros
    Cybersecurity czar candidate questions clout of new position
    Incident response planning
    The basics of enterprise GRC project management
    RSA council addresses growing security risks in the cloud
    How to write a risk methodology that blends business, security needs
    Risk management must include physical-logical security convergence
    DHS fills National Cybersecurity Center post
    New partnerships, creative thinking help security bust recession
    Experts optimistic of Obama cybersecurity plan

    Security Awareness Training and Internal Threats
    Twitter risks, Facebook threats trouble security pros
    Social engineering training could disrupt botnet growth
    How to write a risk methodology that blends business, security needs
    Risk management must include physical-logical security convergence
    Tabletop exercises sharpen security and business continuity
    Security policies need simplifying, expert says
    Microsoft IE 8 security only benefits educated users
    Security book chapter: The Truth About Identity Theft
    How to integrate the security of both physical and virtual machines
    Laid off workers likely to steal company data, survey warns

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    incident response  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    Focused on Channel Security?
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts