Compliance Management: A Business Need Indeed

author-image
DQC News Bureau
New Update

With new regulations for managing IT security, enterprises need to have a
well-charted security and compliance framework. Solution providers should take
the gauntlet of educating their customers on how to go about framing this
structure

Advertisment

Increasing security incidents, audits and new regulations are creating a
paradigm shift in the way enterprises perceive security. From being seen as
primarily a technical problem, today security has emerged as a clear business
challenge

Undoubtedly, new regula­tions are an integral driver of this paradigm shift.
They take on business-level dimensions by forcing companies to adapt their
entire IT operations to demon­strate proof of security across complex IT
infrastructures. They also ensure that employees and partners understand and
abide by policies.

Therefore, there has emerged a clear need for the security and compliance
framework to build an efficient, consistent and auditable environment; which may
lead an organization to gain competitive advantage, meet customer and regulatory
demand, and preserve the confidentiality, integrity and availability of
information asset.

Advertisment

The first step in this direction that enterprises need to take is
implementation of security controls that help them demon­strate compliance while
impro­ving the protection of their information assets. Most enterprises,
especially the small and medium ones, might not have the in-house capability to
execute this, which presents the perfect opportunity to solution providers to
plug this gap.

By: Prosenjeet Banerjee

Because regulations do not provide specific implementation guidance,
organizations must translate following regulations into frameworks and standards
that can be mapped to specific controls and policies across the enterprise. Once
established, these controls must then be sustained on a continual basis to help
assure compliance and remediate deficiencies.

Therefore solution providers should help these organizations define
regulations, frameworks and standards that apply to their organization. They
should also implement standards to support policies and apply specific IT
technical controls to achieve compliance. But while doing so they ought to
demonstrate due care and sustain compliance by showing that IT controls are in
effect and are working properly.

Advertisment

How to address them?

To achieve compliance with multiple regulations in this complex environment,
and then to be able to verify compliance to the relevant parties, solution
providers must take some measures

Firstly, they should imple­ment a carefully devised technology and process
controls (eg, personnel controls, physical and logical access controls, and
legal and contractual controls). These controls should be automated, efficient,
clear-cut, easily duplicated, and immedi­ately transferred when a new user,
technology, or information is added.

The next step is to document and organize compliance efforts to demonstrate
compliance details to auditors. This includes implementing consistent,
repea­table systems for quanti­fying, tracking, analyzing, demonstrat­ing, and
reporting on comp­liance.

Advertisment

The system that is evolved should enable auditors and assessors to validate
documen­tation (audit servicing). This includes maintaining an audit data
repository and enabling validation.

Companies must be able to collect and compile assessment data in a format
that can be extracted easily, and shared efficiently and confidentially.
Validation may involve spot-auditing application usage, reviewing information
retention practices, examining user-authorization records, and ins­pecting
technical configurations.

Ideally, the preceding measures should be delivered via a flexible, low-cost
solution that maps to the unique technical and business requirements of each
internal organization, while allowing for the flexibility needed to address
future regulation and growth.

Advertisment

Typical enterprise comp­liance management solution need to be adequately
aligned with information security controls embedded in techno­logy,
applications, policies and possesses. Integration and automation of assessment,
monitoring and management is key success factor for any solution to meet
compliance management requirement.

Such real-time risk moni­toring not only helps organi­zation management to
keep track of possible risk factors which may worsen their business processes
and com­pliance need; It also helps them to adequately device mitigation
strategy and mobilizes resources as per the risk profile and business
requirement.

Implementation

An integrated approach to identify the most relevant compliance-management
solution must address the following:

Advertisment
  • Understand how compliance efforts and options overlap with regulations and
    standards
  • Develop concrete realistic and business-oriented action plans
  • Learn how to offset your compliance burden by reducing compliance cost
  • Address all possible risk areas by plugging compliance holes and bridging
    communication gaps
  • The solution must align itself to the business need by choosing an
    appropriate study path
  • Simplify compliance initia­tives by exploring leading compliance
    technology solutions

A typical approach to meet the above-mentioned require­ments should have
three components-a holistic view, a reporting structure and process management.
Creating a holistic view simply means having an integrated framework to meet
different regulatory needs. It should also allow management to walk the tree
from a regulation down to the detail controls and supporting evidence. Besides
this, business applications / processes should be mapped with regulatory
requirements.

The reporting structure should generate reports to satisfy various audiences
like executive management, stakeholders, technical team and auditors etc.
Finally the process management system should have capability to integrate with
process and help-desk management system. Exemption and deviation handling should
be mapped to business processes.

Advertisment

Today, compliance is not an option. It has become cost of doing business and
the best possible way of managing security risk. The challenge is to do so at
manageable cost, minimize manual tasks and most importantly without compromising
on security.

The author is Associate VP-Global Security Practice, HCLT ISD