White Papers

Practical advice for CIOs wrestling with compliance issues

Category: Security

Tags: endeca, cio, management

Overview This chapter from the upcoming book CIO Wisdom II delves into useful strategies for CIOs who don't have a dedicated department to take care of all their compliance concerns.

Most large companies have a compliance team and in-house lawyers to keep on top of the regulations. This team may also include someone from IT, so the CIO doesn't carry the entire burden of ensuring compliance. However, in smaller companies, compliance is often an extra responsibility given to representatives from different business units. In this setting, it is imperative that the CIO be involved with all compliance issues.In this sample chapter from CIO Wisdom II: More Best Practices, author John Supplee, in conjunction with the Enterprise Computing Institute, examines a number of key aspects of managing compliance. His recommendations include:

  • Structure the compliance staff in such a way that it will not inhibit the discovery and correction of issues.
  • Know each of the individuals involved in the compliance process.
  • Create a comprehensive risk assessment for the organization and each function.
  • Talk about the issues with upper management and the board and train employees so that you create a culture of compliance.
  • Talk to outside vendors and auditors when looking for solutions.
  • Try to use each new regulation as an opportunity to create business value.

Title: CIO Wisdom II: More Best Practices
ISBN: 0131855891
Published: November 2005; Prentice Hall Professional Technical Reference
Authors: Phil Laplante and Thomas Costello
Chapter: Compliance for the CIO (chapter author: John Supplee, in conjunction with the Enterprise Computing Institute.)

Join the

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
TechRepublic
File Format
PDF
Date Published
May 16, 2006
Format
White Papers
Topics
Best Practices, Security Management

Similiar White Papers

Web Application Security: Automated scanning versus manual penetration testing

Web Application Security: Automated scanning versus manual penetration testing

Research has shown that a vast number of Web sites are vulnerable to application attacks, most occurring over HTTP/S pro

Publisher: IBM  |  Tags: penetration testing

Demystifying the PCI Data Security Standard for Merchants

Demystifying the PCI Data Security Standard for Merchants

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security practices set forth by American Express,

Publisher: ComplyGuard Networks  |  Tags: data, data security, pci, pci dss

Top five strategies for combating modern threats: Is anti-virus dead?

Top five strategies for combating modern threats: Is anti-virus dead?

Today's fast, targeted, silent threats take advantage of the open network and new technologies that support an increasin

Publisher: Sophos  |  Tags: email, malware, network

Take a holistic approach to business-driven security

Take a holistic approach to business-driven security

Corporate leaders face multiple challenges including the need to address complience measures and protection against exte

Publisher: IBM

Gartner Report: Magic Quadrant for Secure Web Gateway, 2007

Gartner Report: Magic Quadrant for Secure Web Gateway, 2007

Interested in what analyst firm Gartner has to say about Blue Coat Secure Web Gateway solutions? Read its "Magic Quadra

Publisher: Blue Coat Systems  |  Tags: pcs

TechRepublic White Papers

Build your own consulting contract using this sample form

Build your own consulting contract using this sample form

Both independent consultants and their clients benefit when they're working with a solid contract. Download this sample

Publisher: TechRepublic  |  Tags: html

Say 'no thanks' the right way with this sample rejection letter

Say 'no thanks' the right way with this sample rejection letter

It's a good practice to let job candidates know when they haven't gotten the job. Use this sample thanks-but-no-thanks l

Publisher: TechRepublic  |  Tags: html

Step by step: Configure a Windows Server 2003 VPN?Server side

Step by step: Configure a Windows Server 2003 VPN?Server side

Set up a Windows Server 2003-based PPTP virtual private network (VPN) with this step-by-step installation and configurat

Publisher: TechRepublic  |  Tags: authentication, html, network, server, vpn, windows server

Download this sample IT due diligence report template

Download this sample IT due diligence report template

Performing a technology due diligence is a good way to understand your client's technology and assess the financial impl

Publisher: TechRepublic  |  Tags: due diligence

Define project expectations with this criteria acceptance form

Define project expectations with this criteria acceptance form

Establishing acceptance criteria at the beginning of a project helps ensure that the results are well received. This sam

Publisher: TechRepublic  |  Tags: html