Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« New Benchmark Research Report Released Today from IT Policy Compliance (ITPC): "Taking Action to Protect Sensitive Data" | Main | "Protecting Personal Information: A Guide for Business": Free from the FTC »

How Access Management Compliance Supports Good Business

Many business leaders I speak with now have great concern for data protection law and regulation compliance, which is certainly prudent. However, often when digging into the details of their compliance plans and activities, I find most of the effort and budget is going towards initiatives for firewall and perimeter protection, with increasing implementations for encryption.

These are definitely important! But when I ask about any plans they have for improving their authentication methods, a large number, with perhaps the exception of the online banks, say something similar to, "Oh, we are comfortable with our current authentication solution; our passwords must be strong, and must change every 90 days. And we have not experienced any problems with our access control systems. So, we should already be in compliance with these types of legal requirements." But will single-factor re-usable passwords continue to be an acceptable practice for authenticating enterprise users as incidents continue to occur on an ever more frequent basis?

Similarly, when I ask about plans for improving access control methods, many business leaders have a response similar to, “Our access controls are based upon departmental responsibility and manager oversight. We have used this method for several years. It seems to work fine, and we have trust in our managers’ capabilities.” Will the old way of establishing and managing access controls still be acceptable as the insider threat continues to negatively impact businesses and their customers? Will these practices pass muster with regulatory oversight agencies that check for compliance?

I just posted a paper exploring these issues, "How Access Management Compliance Supports Good Business"

Agree? Disagree? Let me know what you think!

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/341

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.