Home > Security Tips > Compliance Counselor > Learning the language of global compliance
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Learning the language of global compliance


Mike Rothman, Contributor
10.14.2008
Rating: -3.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


To be clear, compliance is not something to do. It's not something to buy. It's not something that is finished -- ever.
Break out the passport; the corporation's going global. With ubiquitous networks, low-cost telecoms and an increasingly tech-savvy workforce, it won't be long before international operations are thriving in many U.S. companies that don't have them today. Yet, when thinking about doing business around the world and protecting assets, the question inevitably crops up: What about compliance?

Doing business in the U.S., you know all about the alphabet soup that is today's compliance mess: PCI DSS, HIPAA, GLBA, SOX, etc. But what about global regulations? Are there other things to worry about, maybe more compliance laws?

The answer is yes and no. If the company takes credit cards for payment, then PCI DSS is in play wherever those transactions are captured. Enforcement outside of the U.S. is in its infancy, but it will grow. There are quite a few QSAs (Qualified Security Assessors) that can conduct global assessments, so if the organization is international, then it's important to have consistent processes and control sets in place to protect the credit card data. If the company is compliant with PCI DSS in the U.S., then it's likely compliant in all the countries in which it operates.

What about having solid financial controls? Is it necessary to pay the Sarbanes-Oxley tax outside of the U.S.? This only happens if the company is in Japan where their Financial Instruments and Exchange Law (know as J-SOX, because it's so closely modeled after SOX) is in place. That means it's important to take a risk-based approach to making sure that financial controls are in place and separation of duties is enforced. Also, do some logging to verify what's actually been done.

It's worth noting that five years ago differences in the international regulatory frameworks were apparent when considering privacy, but not anymore. To its credit, Europe has really led the way in terms of delineating what is acceptable to share and defining a set of specific requirements about protecting customer information. Nowadays, regardless of geography, the standards are mostly equivalent for both security and privacy.

Many of these requirements are laid out in the European Commission's 1995 Directive on Data Protection (Directive 95/46/EC). This directive was adopted in 1995 and has been enforced since 1998 for all countries in the European Union. It lays out eight principles of good practice, of which number seven is "secure."

That's right: Private companies (and governments for that matter) need to keep private data secure. But what does that mean? It's generally the same as every other regulation that requires data protection. Organizations must make the case to local regulators that excessive private data is not being stored and that any data that is stored is done securely. It's not unlike other privacy-oriented regulations such as HIPAA and GLBA in the U.S.: First protect the data, and then document the controls used. If the company proves it can successfully protect its data, it will -- in all likelihood -- be compliant.

For more information
Learn how to combine compliance efforts to manage PCI DSS.

Find out more about building a risk-based compliance program in this Security School lesson.
The fine folks in Canada used the EU privacy directive to build their PIPEDA (Personal Information Protection and Electronic Documents Act) regulations, which went into effect in 2001. Similar to other privacy regulations, PIPEDA requires organizations to notify customers when they collect private data, specify what it will be used for and obtain the proper consent.

A quick assessment of these global privacy regulations always brings me back to my general philosophy on compliance. Many organizations look at compliance as a set of check boxes that must be addressed. But compliance is not the goal; it's a result of securing data in a dynamic and dangerous world.

To be clear, compliance is not something to do. It's not something to buy. It's not something that is finished -- ever. As long as attackers are coming up with new ways to steal information, there will always be new defenses that are required and new reports that need to be generated for new regulators.

So regardless of where an organization does business, there are a few basic principles: Don't collect more data than needed. Protect customers' private data. Document the controls that are in place.

And get a nice case for that compliance passport that will house all the stamps from around the world.

About the author:
Mike Rothman is president and principal analyst of Security Incite, an industry analyst firm in Atlanta, and the author of The Pragmatic CSO: 12 Steps to Being a Security Master. Rothman is also SearchSecurity.com's expert-in-residence on information security management. Get more information about the Pragmatic CSO, read his blog, or reach him via e-mail.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Compliance Counselor,   Security Audit, Compliance and Standards,   Data Privacy and Protection,   Information Security Management,   Information Security Policies, Procedures and Guidelines,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance Counselor
Identity lifecycle management for security and compliance
Interpreting 'risk' in the Massachusetts data protection law
FTC Red Flags Rules: How to create an identity theft prevention plan
Creating a HIPAA employee training program
Data protection tips for corporate compliance leaders
PCI DSS compliance requirements: Ensuring data integrity
Understanding PCI DSS compliance requirements for log management
Are 'strong authentication' methods strong enough for compliance?
Strategies for using technology to enable automated compliance
Common PCI questions: Web application firewalls or source code review?

Data Privacy and Protection
Quiz: Compliance-driven role management
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Researchers predict SSNs, crack algorithm putting identities at risk
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Data Privacy and Protection Research

Information Security Policies, Procedures and Guidelines
Health Net breach failure of security policy, technology
How to protect distributed information flows
Essential guide: Pandemic planning for H1N1
Whitelists, SaaS modify traditional security, tackle flaws
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Reuters: Obama ready to select cyber security czar
How a corporate Twitter policy can combat social network threats
Should enterprises be concerned with Twitter in the workplace?
Information security management hype: Debunking best practices
Data breach avoidance begins with security basics, panel says

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cypherpunk  (SearchSecurity.com)
Data Encryption Standard  (SearchSecurity.com)
P3P  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts