Standards-Based Approach Can Simplify IT Compliance
By:
Biztech2 Staff
| May 07,2008
RSA, the security division of EMC, has announced the findings of a new research paper that details the benefits organisations may gain – including reduced costs and improved security – by implementing a standards-based framework of security controls. The paper also details the ability of comprehensive security frameworks to help companies more easily comply with a variety of security requirements handed down by regulatory bodies, industry groups, partners, customers and internal policies.
In addition, RSA announced new reports within the RSA enVision security information and event management solution that are designed to enable organisations to more easily report on key aspects of the ISO 27002 standard – a global code of practice for information security management, which is useful in defining an effective set of best practice security controls as part of a compliance framework.
In March 2008, RSA commissioned Michael Rasmussen, industry analyst and president of corporate integrity, to undertake a research paper based on what it means to develop a “sustainable and cost-effective IT compliance program.” The key findings of this project are that the typical approach to compliance – responding on a regulation-by-regulation basis without an integrated IT compliance management program – escalates costs, reduces visibility of the control environment overall, wastes resources, and leads to unnecessary complexity, inflexibility, vulnerability and exposure.
“A proactive approach to IT compliance allows organisations to look confidently to the future while also mitigating risk in the course of business,” says Rasmussen. “An effective IT compliance program should be centred on a comprehensive framework, based on industry-wide standards – such as ISO 27002.”
Security frameworks-based programs to simplify IT compliance
As organisations worldwide struggle to both comply with a plethora of compliance requirements and improve enterprise-wide security, a framework-based approach founded upon best practices and controls helps customers to build a proactive security program that may effectively break down the walls that often isolate organisational compliance silos. By driving compliance holistically, rather than on a requirement-by-requirement basis, companies may reduce costs by both avoiding redundant technology controls and easing the process of managing compliance. In addition, leveraging international standards such ISO 27002 as the foundation of an IT security and compliance program helps organisations align efforts to comply with key portions of many global regulations, including: the Payment Card Industry (PCI), Data Security Standard (DSS), HIPPA, Sarbanes-Oxley, the European Union’s Data Protection requirements and regional data privacy laws.
“Our forward-thinking customers are using framework-based security and compliance programs to cost-effectively satisfy multiple requirements and manage information risk,” says Steven Preston, senior director, solutions marketing at RSA. “This goal can be achieved through the application of a consistent, holistic set of repeatable, scalable, enterprise-wide controls, which are centred upon recognised IT security best practices.”
RSA Solutions to establish security frameworks for simplified compliance
RSA’s portfolio of technology solutions offers key security controls that can help organisations establish frameworks based upon global best practices and standards and comprises authentication, data loss prevention, encryption key management and logging, monitoring and reporting solutions.
In addition, RSA announced new reports within the RSA enVision security information and event management solution that are designed to enable organisations to more easily report on key aspects of the ISO 27002 standard – a global code of practice for information security management, which is useful in defining an effective set of best practice security controls as part of a compliance framework.
In March 2008, RSA commissioned Michael Rasmussen, industry analyst and president of corporate integrity, to undertake a research paper based on what it means to develop a “sustainable and cost-effective IT compliance program.” The key findings of this project are that the typical approach to compliance – responding on a regulation-by-regulation basis without an integrated IT compliance management program – escalates costs, reduces visibility of the control environment overall, wastes resources, and leads to unnecessary complexity, inflexibility, vulnerability and exposure.
“A proactive approach to IT compliance allows organisations to look confidently to the future while also mitigating risk in the course of business,” says Rasmussen. “An effective IT compliance program should be centred on a comprehensive framework, based on industry-wide standards – such as ISO 27002.”
Security frameworks-based programs to simplify IT compliance
As organisations worldwide struggle to both comply with a plethora of compliance requirements and improve enterprise-wide security, a framework-based approach founded upon best practices and controls helps customers to build a proactive security program that may effectively break down the walls that often isolate organisational compliance silos. By driving compliance holistically, rather than on a requirement-by-requirement basis, companies may reduce costs by both avoiding redundant technology controls and easing the process of managing compliance. In addition, leveraging international standards such ISO 27002 as the foundation of an IT security and compliance program helps organisations align efforts to comply with key portions of many global regulations, including: the Payment Card Industry (PCI), Data Security Standard (DSS), HIPPA, Sarbanes-Oxley, the European Union’s Data Protection requirements and regional data privacy laws.
“Our forward-thinking customers are using framework-based security and compliance programs to cost-effectively satisfy multiple requirements and manage information risk,” says Steven Preston, senior director, solutions marketing at RSA. “This goal can be achieved through the application of a consistent, holistic set of repeatable, scalable, enterprise-wide controls, which are centred upon recognised IT security best practices.”
RSA Solutions to establish security frameworks for simplified compliance
RSA’s portfolio of technology solutions offers key security controls that can help organisations establish frameworks based upon global best practices and standards and comprises authentication, data loss prevention, encryption key management and logging, monitoring and reporting solutions.
| Ads by Google | ||
Post a Comment on “Standards-Based Approach Can Simplify IT Compliance”
LATEST NEWS
- Siemens PLM Software, Satyam Sign Alliance To Enhance PLM Industry
- Experian Launches Business Credit Monitoring System
- Wind River, Intel To Drive Open Source Platform For Auto Industry
- IBM Unveils AnyPlace Kiosk Model For Small Retailers
- Capgemini To Offer Enhanced Insurance Data Conversion Solutions
- Aricent Announces Worldwide Launch Of Celltop For All Providers
- D-Link To Provide Wireless Access Points For Tata Comm
- GSM Based Radio Sol For North Central Railways
- Standard Chartered Selects Arcot For Secure Online Payment
- Guided Selling And Product Configurator By Cincom
| Ads by Google | ||
RELATED
- Siemens PLM Software, Satyam Sign Alliance To Enhance PLM Industry
- Experian Launches Business Credit Monitoring System
- Wind River, Intel To Drive Open Source Platform For Auto Industry
- IBM Unveils AnyPlace Kiosk Model For Small Retailers
- Capgemini To Offer Enhanced Insurance Data Conversion Solutions
| Ads by Google | ||
Hot Searches & Keywords :
AMD
APAC
Acquisition
Asia Pacific
Asian Paints
BFSI
BI
BSNL
Bharti Airtel
Blackberry
Broadband
Business
Business Objects
Business intelligence
CA
CIO
CIOs
CRM
Cisco
Cisco Systems
Compliance
Data
Data Centre
Datacentre
Dell
EMC
ERP
Frost & Sullivan
Gartner
Google
Growth
HP
IBM
IDC
IT
India
Infrastructure
Intel
Internet
Linux
Manish Choksi
McAfee
Microsoft
Mobile
Mobile Banking
Nasscom
NetApp
Network
Networking
Novell
Open Source
Oracle
PLM
Red Hat
Retail
SAP
SMB
SMBs
SME
SMEs
SOA
SaaS
Satyam
Security
Software
Storage
Sun Microsystems
Symantec
TCS
Teradata
VMware
Virtualisation
VoIP
Web
Web 2.0
Websense
WiMax
Wipro
e-governance
healthcare
investment
outsourcing
partnership
telecom
|
|
||
| Ads by Google |
Sections
Applications |
Audits&surveys |
Bfsi |
Bookreviews |
Businessintelligence |
Businessprocesses |
Ciscosmenews |
Ciscowhitepapers |
Computing |
Contactcenters |
Contributedvideos |
Crm |
Ctoprofiles |
Datasecurity |
Databases |
Datacenters |
Education |
Energy |
Erp |
Focusspecials |
Government |
Guruspeak |
Hardwaresecurity |
Indialogue |
Innovation&leadership |
Innovators |
Intrusiondetection |
Intrusionprevention |
Ites |
Knowledgeprocess |
Lenovo |
Linux |
Managedservices |
Manufacturing |
Media |
Mobile |
Mobility |
Movement |
Networking |
Oncuewithitleaders |
Peoplemanagement |
Pharma |
Platforms |
Policies&compliance |
Recruitment |
Retail |
Saas |
Scm |
Securitymanagement |
Servers |
Services |
Softwaresecurity |
Softwareservices |
Specialreports |
Storage |
Storagesolution(apps) |
Techaction |
Telecom |
Telecommunications |
Theinsider |
Trendwatch |
Web |
Webisodescisco |
Weeklywrapup |
About Us | Copyright © 2006, Biztech2.com India - A Network18 Venture

