Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Weighing the cost of compliance

Certain to spend too much adhering to regulations this year, IT may be putting the enterprise at risk


From Sarbanes-Oxley to HIPAA to PCI/DSS, chances are your company is subject to myriad compliance requirements. And although the goals of such regulations are noble, the chunk taken out of your security budget to uphold them is considerable, in some cases precluding stronger, more tangible computer security protections. In other words, by spending heavily on the letter of the law, you may, in fact, be putting your organization at risk.

Download PDF

Stephen Northcutt, director of the SANS Institute, agrees that IT’s ongoing emphasis on compliance may be worth reconsidering. “It’s an audit mentality, not a security mentality,” Northcutt says. “It’s, ‘Let’s do everything we can to meet a checklist of audit requirements that in the end do not guarantee or measure real security.’ The audit requirements and regulations are generally too broad, with gaps and overlaps. And when the first audit is over, the team switches into another, entirely different mode to satisfy the next audit, which requires different objectives.”

Most companies fall under multiple regulatory laws with overly broad descriptions of what is secure. Whether you pass or fail a particular audit requirement is up to the discretion of external auditors. Not surprisingly, pleasing auditors often has little to do with sound security practice.

“The first auditor said we had to use passwords with a minimum of six characters. Another said passwords had to be eight characters and complex,” a bank IT director says. “One cared about account lockout mechanisms. The other didn’t. Neither asked about all the other factors that impact overall password security. … And if you read the actual regulations, they don’t specify a particular number of password characters. They just say passwords need to be secure. That’s it.”

Robert W. Hodges, information security officer at Bon Secours Health Systems, says, “When we get two conflicting or overlapping regulations, we play it safe and take the most conservative, secure approach. That way it satisfies both requirements.”

But always taking the most conservative approach means higher spending — in many cases, more than is necessary from an overall security perspective. Regulatory clarification would help. Discretionary guidelines are often given specific answers in court. But with regulations showing more bark than bite despite the fact that most organizations are not fully compliant, you have to wonder where to draw the line when financing compliance efforts. After all, continually redirecting vast amounts of IT dollars and attention away from other practical security projects in order to remain compliant could prove considerably more costly down the line.

Your only solution, however, may be to hold your nose as you overspend. As Hodges puts it, “Who wants to risk their company being the defendant when the government decides to make a test-case example?”

Roger A. Grimes is contributing editor of the InfoWorld Test Center.

Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





What Every Enterprise Needs to Know About VDI
Today's enterprise IT environment is already complex, and replete with heterogeneous technologies. Attend this informative webcast to understand the key components for deploying and managing virtual desktop infrastructure in your environment. Sponsor: VDIworks

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 09/04/2008

Sony recalls 73,000 laptops, Google to rework Chrome license after users...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist