LawAn Automated, Risk-based Approach to IT Compliance Learn how enterprises can automate key IT compliance processes to reduce the risk to their information assets and reduce the costs of managing compliance. Here Comes the CNCI and the Era of Proactive IT Security Government agencies must step up and be more proactive about security. The best strategy is to stay on top of the latest security threats and attack trends. Making Critical Connections for Better Security The federal government's National Cyber Security Initiative can serve as the catalyst for improving cybersecurity. Private and public enterprise executives are concerned about growing risks, data breaches and lack of education. Unifying Governance, Risk and Compliance Large organizations are facing increasing pressure to develop comprehensive GRC strategies to help coordinate IT systems, business processes and employees. Minimizing PII Exposure and Loss The shift to e-government -- and all that comes with it, including high-speed networks, mobile computing and better information sharing -- has introduced new risks to PII. Upping the Ante for Public Sector CIOs The appointment of California's first statewide CIO to a cabinet-level position marks a turning point for federal, state and local IT managers. Effective Online Fraud Management The Secure Internet Banking Alliance is working to define the industry paradigm that protects online bank users from identity theft. New E-Discovery and Archiving Rules Revisions to the Federal Rules of Civil Procedure (FRCP) late last year make e-discovery and archiving an issue organizations can no longer ignore. Changing IT Awareness in State Governments State CIOs must raise awareness and implement training to help avoid data breaches and internal security threats. Outsourcing and the Foreign Worker Direct management of an overseas staff is the vendor's responsibility, but the risks that come with inadequate performance remain with the company outsourcing the work. Key Considerations for Classifying and Intelligently Archiving Email While some email is an asset, and other email is a liability, organizations need to determine the amount of time both types of messages are retained. Facing Up to the E-Discovery Challenge New federal rules dictating guidelines for electronic discovery underscore the need for financial institutions to protect and manage business-related data. Getting Privacy Right This Time CIOs can help their organizations protect privacy the right way, which can bring an enterprise into compliance with laws, as well as appease consumers. The Cost of Regulatory Compliance Mid-sized enterprises may not be publicly-traded, but IT managers still need to cope with some of the same compliance obligations as larger organizations. Changes to federal rules now require businesses of all sizes to be prepared to turn over electronic records in court, but IT leaders need know how to comply. On the Horizon: More Compliance Regulations IT departments need to act now because the volume of paperwork to comply with new laws is expected to double for enterprises in the next few years. Decision-Making: No More "Us vs. Them" When it comes to compliance and other enterprise-wide issues, CIOs need to mend fences and encourage a collegial work environment to make projects successful. Limit Your Exposure with Email Archiving Failure to archive email can end up costing government agencies a great deal in terms of money, reputation, and citizen confidence. The advent of a number of regulations -- including Sarbanes Oxley and HIPAA -- means organizations need to consider how to clean disks before disposing of old PCs. Consumers and companies alike need to take steps to protect personal information before it becomes the basis for fraud and theft. The challenge is not only using IT to achieve compliance, but also in sustaining it when faced with overstretched staffs and budgets. The State of Privacy Regulation Recent laws have become more specific about companies' data liability. It's up to the CIO to know the details. Laws such as the SPY ACT and SPY BLOCK ACT help to protect organizations, but there is still more work to be done. Getting Tough on the Growing Spam Problem States are stepping up with laws against unsolicited email. Rising to the Compliance Challenge Government guidelines alone aren't enough for a secure, available and compliant IT. Financial institutions that embrace this new framework will reduce risk. What's in Store for FISMA in 2005 Government agencies are working toward compliance, but face competing concerns. Spyware is annoying and invasive, that much is clear. But as the threat comes in many forms, security professionals need to agree on a definition before finding a solution. |
ADVERTISEMENT Related Content |