Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Norwich University Residency Week & Thoughts On the Court Ruling on Email Searches | Main | New Social Engineering Scheme Targets Military Families »

Laws, Standards, Mapping, and HIPAA

Today is the last day of Norwich University's Masters programs residency week; this afternoon is graduation.

It has been a great week...I have loved chatting with the students and faculty, and I've compiled a page full of topics I want to research and blog about!

One of the topics I discussed with some students was the challenge of trying to comply with multiple regulations, standards and laws. Folks are always looking for resources, which is not only understandable but a great idea, to help them see the commonalities of requirements between these multiple types of directives.

Some of the best resources I have found for mapping a large number of laws, regulations and standards to the common requirements are the Unified Compliance Project (UCP) tools
from the IT Compliance Institute.

For full disclosure, yes, I co-authored my last book, "Say What You Do" with one of the authors of the UCP tools, Dorian Cougias.

However, I have no direct connection to, or financial interest in, the UCP tools, and I do not make any type of revenue whatsoever from the UCP tools.

Yes, these tools do have a price. However, whenever you consider the amount of time they save you from doing the mapping yourself, and considering they are much more comprehensive and immediately useable than the other free mapping documents I've seen, I think they are a good investment for most organizations of any size.

As I was thinking about this topic and doing some scans of recent news stories related to it, I ran across an article in SC Magazine, "Shedding some light on PCI DSS."

The article itself contains some valid points and information, however, I cringed when I read the following paragraph at the beginning of the article:

"While the PCI DSS is much more detailed and specific in what organizations are required to do, versus other standards like Sarbanes-Oxley and HIPAA, much is left to individual interpretation as organizations attempt to achieve the compliance necessary to participate in online commerce."

The Sarbanes-Oxley Act (SoX) and HIPAA are *NOT* standards! They are laws.

In general laws cannot be detailed down to specifically required technologies or other detailed requirements such as those found within standards. The process of making laws and getting them put into effect does not make this feasible, and with the speed that technology, products and services evolve, it would not be good to include such details within laws anyway.

Data protection and privacy laws are generally similar to information security policies within organizations; they provide the targeted goal results for specific issues that covered entities must meet. They often include references to standards that can be used for meeting compliance.

Laws are not standards in the same way that organizational information security policies are not organizational information security standards.

Sometimes some of the requirements within laws evolve to become what are considered as "de jure" standards. We cover this in great detail in the Say What You Do book. I had great fun writing the bulk of the chapter on standards; you can find an excerpt about standards from the book here.

As another example, the U.S. Federal Trade Commission (FTC) has made multiple statements about how they consider the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule as a standard of best practices for all types of organizations, not just financials, to follow with regard to demonstrating a standard of due care.

Oh, and while I was at going through SC Magazine for the article I mentioned earlier, I ran across another article, "SSL: The handshake that requires scrutiny," that included within the text, "Health Insurance Portability and Accounting Act (HIPAA)."

AARRGGGHHH!!

It is the "Health Insurance Portability and Accountability Act"!

Making such an error with the name of a regulation can completely blow credibility for the author and the entire article.

I do not know who made this mistake, the author or the publisher's editor; I've had some editors change my writing that incorporated errors in the published version, and it really made me see red to have their mistake blow the effectiveness of something I wrote.

Writers, please be sure that when you are referencing a law or regulation that you have the correct title!

Publisher's editors, when you change writers' articles, please let them proofread your final version before publishing to ensure you do not introduce any errors into the article!

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/443

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.