Network World
Friday, January 9, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

Compliance Issues

You can see why Bear's Stearns dropped quickly. Checklist's are not the problem with compliance. Implementors of compliance use checklists as a tool. The issue is due diligence, and ensuring as a manager that you are validating requirements using multiple methods. If all they relied on was a checklist - you're toast. Interviewing personel, process review, policy review, Automated scans of systems, individual system reports are how you verify the checklist. Typically, this is time consuming but if mid management and stakeholders don't follow due diligence and just check the box - it results in a greater risk to the business. Overreaching that risk cause situations like Bear Stearns.

Click to read the article this is in response to.

Agreed

0

I would have to agree. Checklists should only be used as a guide to ensure all areas are being looked at. Companies are being forced to react to compliance rather than being given solid guidance on how to best secure their environments. This rush to compliance forces companies to cut corners, hire inexperienced staff, and ignore the true risks.
Companies must address their environment using a risk based approach that takes into account business and security requirements and take the time to architect solutions the right way the first time rather than focusing on the compliance flavor of the month.

Business processes failed due to dependance on IT

0

Basic Accounting principles are being forgotten as business managers depend on IT to do all the checks and balances. The CISO is worried about IT security, but doesn't dive deep enough into the business processes. Checklists are fine, if the right questions are on the lists. Did B-S fail due to lax accounting? Or lack of integrity? I'd say yes to both.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: