Friday, April 08, 2005

Compliance Hindsight: What Organizations Have Learned from Early Compliance Approaches

The escalating number of regulations with a clear information security impact has finally put enterprises on notice: information security is part of business risk and can no longer be left on the sidelines. Previously, few companies paid much attention to regulatory compliance, their "control infrastructure," or even information security.

Now, however, organizations large and small are racing to assess, test, and document their internal controls for Sarbanes-Oxley, their security and privacy practices for HIPAA, or their basic security safeguards for GLBA, Basel II, Homeland Security, and dozens of other mandates.

See full Article.