AKIBIA'S PRACTICAL GUIDE TO ENTERPRISE TECHNOLOGY
Entries with Label: Mass Data Privacy Law
Compliance and Security Go Hand in Hand – How to Achieve Both
Friday, May 28, 2010
The buzzword “Compliance” has now overshadowed many of the previous popular terms in security discussions. Many equate “compliance” with “security,” but recent literature abounds with titles such as “Compliant Does Not Mean Secure” and “Information Assurance: The Difference between Secure and Compliant.” These articles make the case that it is possible to be compliant yet not secure. Most discussions focus on payment card industry (PCI) security, because of the high value of the data involved, the stringency of the compliance standards, and recent security breaches of major players. It is also useful for illustration purposes, since the typical PCI technical environment is usually confined, and the standards are very specific. However, it is important to expand the discussion beyond one security standard, especially since others are more comprehensive, although less specific.
Too Many Requirements; How One VP of IT Handles It
Thursday, September 30, 2010
In 1996 IT departments were only concerned with two mandates, but today there are over 200 and more than 2500 security controls associated with them. The cost, both in budget and time, associated with understanding, addressing and proving compliance with these ever expanding mandates is considerable. Because requirements expand and change on a regular basis, the project of managing compliance is never complete, leaving CIOs and their IT departments constantly at risk of non-compliance.
