Home > Security Tips > Compliance Counselor > Compliance Q&A: Myths, mistakes and management advice
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Compliance Q&A: Myths, mistakes and management advice


Jenny Wiseman, Associate Editor
04.18.2006
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Keeping organizations continuously compliant with multiple complex and ever-changing regulatory requirements remains a challenge for many infosec pros. But if they don't shape up now, it's only going to get worse. In this interview, Rebecca Herold, CISSP, CISA, CISM, FLMI, independent consultant, author and instructor with more than 16 years of experience in information security, privacy and compliance, shares her opinion on the future of compliance for infosec pros, where organizations are still lagging, why we're still seeing data breaches, and offers advice on how organizations can improve their efforts.

As the governance landscape continues to change and become more complex, where do you see compliance heading?

Herold: The landscape will certainly become more complex before it starts to simplify through the consolidation of some of the disperse regulations and requirements. More organizations are realizing they need full-time dedicated resources for compliance. In the past, (and even in most organizations currently) compliance was considered something an existing position could address in just a couple of hours a week. As reality sinks in, organizations are realizing this is a major initiative that requires full-time, dedicated resources.

What are some of the major compliance myths you've come across?

Herold: Considering all regulations and laws, some of the most dangerous myths for organizations to believe are:

  1. Technology alone can bring an organization into regulatory compliance. THIS IS NOT TRUE!
  2. It will take only an hour or less, and a couple of quickly thrown-together slides, to provide adequate compliance training to personnel. THIS IS NOT TRUE!
  3. It will not impact an organization if their business partner, to whom they have entrusted confidential information, experiences a security breach, or is found to be in noncompliance. THIS IS NOT TRUE!
  4. Chances are as long as a publicized incident does not occur, regulatory noncompliance for some of the major regulations such as HIPAA and GLBA will never be discovered. THIS IS NOT TRUE!
  5. Organizations do not need to worry about compliance as much for regulations that have no fines specified. THIS IS NOT TRUE!
What do you think the focus of new laws/regulations in the next few years will be?

Herold: You can tell by the trend in the last couple of years and the bills being considered that legislators are focusing on protecting personal information no matter what the industry. The laws are also becoming slightly broader in what information needs to be addressed and what data protection requirements should apply to all organizations. I think we'll see an evolution. I think the US federal laws will become more wide-sweeping than in the past and they'll start to parallel the types of laws currently in effect in Japan, Canada, Australia and Europe where there's more emphasis on the need for all organizations to protect personal information, and for organizations to formally establish data protection safeguards, training and responsibility.

More on compliance and data breaches

Read an excerpt from Rebecca Herold's book, The Practical Guide to Compliance and Security Risks

Learn how to comply with breach notification laws

Find out how you can prevent a breach in your organization

We're still hearing stories about data breaches in large companies. What are some of the mistakes organizations are making?

Herold:There are two critical things that involve most of the breaches. First, there doesn't appear to be enough employee information security and privacy education in those organizations, so people don't know how to take the appropriate precautions. For example, many people are leaving their laptops in cars, and thieves are either breaking in or simply opening unlocked doors, and stealing them. Your personnel should know they shouldn't leave their laptops exposed in such a manner, in addition to how to secure information. Proper employee education is cost-efficient and has a huge positive impact on organizations. There is a serious need for increased training and awareness in regards to privacy and security.

Second, many organizations are not properly safeguarding the confidential information they have on mobile computing devices. It's extremely important to encrypt all the confidential information on handhelds, PDAs and Blackberries, as well the data stored on back-up tapes and disks. If more organizations did this, these incidents would be non-incidents because no one would be able to decipher the encrypted private data.

Education and securing information, particularly with encryption, are two of the best actions organizations can take to protect their data, as part of a comprehensive information security program.

What about educating upper management and convincing them that it's worth the expense? What's the best approach?

Herold: This is critically important because it's where infosec pros often shoot themselves in the foot. They need to communicate the business impact information security noncompliance and incidents will have on the organization. Infosec pros typically start talking to business leaders about things that are technical in nature. However, upper management really want, and need, to hear about the impact on the business and the problems that will occur if they don't take action to address information security issues and compliance responsibilities. Infosec, privacy and compliance pros need to communicate what the different laws mean to their organization and what the implications are if their organization is found in noncompliance, and they need to show examples of what has happened to other organizations. Clear communication with business leaders, using the business leaders' perspectives, is key.

What are your thoughts on products that claim to help companies comply with regulations? Should companies be purchasing software or hardware for compliance?

Herold: Technology in the form of software and hardware can certainly support compliance and streamline many compliance activities. However, I am concerned when I read claims that such products will bring organizations into full compliance with regulations. The bulk of compliance activities involve the implementation of policies and procedures that are tailored to each organization's unique business environment, along with education to personnel and business partners about how to perform their job responsibilities to comply with these policies, procedures and regulatory requirements. Software and hardware alone will never be full compliance solutions, but they should be used where appropriate to support compliance activities.

It's now year two of SOX, how are companies shaping up and where should they focus next?

Herold: 2005 was a huge compliance activity year for companies with regard to SOX. Most got their independent reviews and audits completed. Now 2006 is the remediation year for these companies as they address the identified compliance deficiencies. Companies will need to carefully review their compliance gaps and realistically budget time, personnel and resources to closing those gaps. A key activity will be to document all this decision-making activity so the resulting actions can be justified if questioned during regulatory oversight activities.

For more on compliance and security risks, read an excerpt from The Practical Guide to Compliance and Security Risks.

About Rebecca Herold:
Rebecca Herold, CISSP, CISA, CISM, FLMI, is the community leader for Realtime-ITCompliance. Rebecca is an independent consultant, author and instructor with more than 16 years experience in information security, privacy and compliance. She has authored The Privacy Papers (Auerbach), The Privacy Management Toolkit (Information Shield), Managing an Information Security and Privacy Awareness and Training Program (Auerbach), The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach), The Practical Guide to Compliance and Security Risks (Realtime Publishers) and The Definitive Guide to Security Inside the Perimeter (Realtime Publishers). She was Chief Privacy Officer for two consulting organizations and was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Outstanding Security Program of the Year Award in 1997. Rebecca is also an adjunct professor for the Norwich University Master of Science in Information Assurance (MSIA) program. You can follow Rebecca's leading blog on information security, compliance and data protection at http://realtime-itcompliance.typepad.com.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Compliance Counselor,   Security Audit, Compliance and Standards,   Data Privacy and Protection,   Security Awareness Training and Internal Threats,   Information Security Management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance Counselor
The future of PCI DSS encryption requirements? Tokenization for PCI
Security compliance predictions for 2010: New regulations, new technology
Compliance strategy: How to become an internal IT auditor
GRC customers point to better efficiency, convergence and consistency
Benefits of ISO 27001 and ISO 27002 certification for your enterprise
Identity lifecycle management for security and compliance
Interpreting 'risk' in the Massachusetts data protection law
FTC Red Flags Rules: How to create an identity theft prevention plan
Creating a HIPAA employee training program
Data protection tips for corporate compliance leaders

Data Privacy and Protection
New data protection laws
MA 201 CMR 17 enforcement less likely with prompt reporting, cooperation
Information security book excerpts and reviews
Quiz: Compliance-driven role management
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Data Privacy and Protection Research

Security Awareness Training and Internal Threats
CISOs take measured steps to reduce social media risks
Information security book excerpts and reviews
Schneier-Ranum face-off, part 2: Social networking
Health Net breach failure of security policy, technology
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Secure your remote users in 2010
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
Creating a HIPAA employee training program

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cypherpunk  (SearchSecurity.com)
Data Encryption Standard  (SearchSecurity.com)
P3P  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts