Solutions

Chief Information Officer, Chief Information Security Officer Compliance

As your company's Chief Information Officer or Chief Information Security Officer, you are most concerned that governance requirements are not being well defined. There is ambiguity; there are redundancies; there are areas that are not being covered by current procedures. When this happens, risks and exposures are more likely to occur, threatening the integrity of your company's compliance efforts. Add to this the fact that you wish your IT organization could deliver information faster to executives allowing them to better evaluate company performance.

Your task is not an easy one because you are straddling two worlds – the IT world and the business world. On one hand, you are responsible for the IT infrastructure in the organization – the automated reporting, the IT staff manual activities, educating the end users on good security practices. On the other hand, you are now being increasingly expected to enforce a business application – governance -- across the entire enterprise. Since governance activities are pervasive throughout the organization, IT is now being seen as the backbone or conduit for reporting on all of these departmental compliance activities. Your role is evolving into one that includes not only technology but also business aspects. As such, you have to understand the business framework and the business rules in your organization. You also have to figure out how to enforce governance at the IT infrastructure level. The IT function is expected to provide all business information regarding governance -- not just the IT compliance information -- for all operations and all departments.

Add to this new responsibility, the daunting complexity and costs of compliance. Point solutions for governance have sprung up throughout the corporation, as each functional area – finance, HR, sales & marketing, service, and procurement have implemented their own version to address compliance. In other cases, point solutions have been organized around specific regulations, such as Sarbanes Oxley, or around regulatory bodies, such as the FDA. Policies and procedures and expenses overlap. The costs for compliance are skyrocketing – even as your budget remains flat -- or more likely is being cut.

Because each of these point solutions operates independently, having their own people and processes, it is time consuming and very inefficient to get information in and out of the point solutions. In fact, it takes days or weeks just to collect data, and more time on top of that to generate reports. You attempt to construct an overview from the piecemeal information coming in from all the sources, in order to determine if the organization is in compliance. Once that view is established, and if changes need to be made, it takes as much time to feed the changes back down the chain. Of course, other incidents and exposures may have already occurred during this process, creating a situation whereby an organization falls farther and farther behind the governance curve.

According to InformationWeek's Global Security Survey, July 2006, "Regulations are forcing companies to re-evaluate their security initiatives. In the U.S., Sarbanes-Oxley, 41%, the U.S. Homeland Security Act, 25%, and the U.S. Patriot Act, 23%, have forced companies to change their security practices." Later in the article, it states that the real problem, in the case of the stolen Veterans Administration laptop that contained the names and social security numbers of millions of current and former military personnel, was that there was no policy in place to protect the personal information. Not that there was a violation of a policy. "That's the real negligence – that there were no policies," said representative Bob Filner, California.

Your job would be considerably easier if you could gather data from hundreds of difference sources and get one real-time, integrated view of governance.

Take for example, the difficulty of addressing PCI compliance. PCI dictates requirements for access control, network security, data protection, monitoring and policy development, so it affects a wide range of policies and activities within your organization. As CIO or CISO, you will be responsible for evaluating the standard and updating your policies to address the requirements. Then you are charged with implementing the new policies and procedures, communicating, educating, testing hundreds or thousands of employees on their understanding of the policy, and reporting on the enforcement. Finally, the IT systems must be monitored and audited for compliance. If changes to the PCI Standard occur, they have to be fed back into the process and the cycle starts all over again. Compound that process with a similar response to any of the other hundreds of regulations that you are subject to and you can easily see the need for an enterprise-wide solution to manage the situation.

Polivec's Enterprise Governance Solution -- integrates and controls all aspects of governance. The cornerstone of the solution is the unique Policy Center – it allows officers to create and store policies that fulfill regulations. All required procedures and tasks, needed to fulfill those policies, across all corporate organizations, people, processes and systems, are housed in one place. The Center determines who has access to the information, and who has reviewed and approved the policies.

Other parts of the Polivec Solution, inform appropriate employees, collect real-time data from all compliance activities, organize both automated and manual tasks, link the practices back to their specific policies and regulations, ensure that policies meet regulatory requirements, monitor the enforcement of all of the policies, highlight gaps in compliance, and signal management when any lapses occur so that they can be addressed immediately.

The Polivec Solution integrates all the compliance data from end-to-end in one seamless software platform. The Polivec Solution incorporates state-of-the-art development techniques, such as, Service Oriented Architecture (SOA), J2EE programming language, and utilizing industry standard relational databases. Investments in current point solutions are also protected. If a firm has existing compliance software, this can be immediately integrated into the Polivec Solution. The Solution is designed to accommodate implementations, in specific functional areas along with specific regulations, and then grow to encompass all functional areas, over time, as new regulations and policies are phased in.

These are the questions you need to ask yourself about your current governance solutions:

  1. Do you have an established program to establish the right "tone at the top"?
  2. Do you have policies in place that address the regulations your company needs to abide by?
  3. Can you measure your employees understanding of the policies?
  4. Do your employees understand protection and privacy of data?
  5. Can you prove that the rules are being properly followed?
  6. Can you prove this to external auditors?

Then you need to think seriously about Polivec's Enterprise Governance Solution. The Solution gives you an integrated, enterprise view of all governance activities and allows you to manage risk, reduce cost, minimize complexity and protect your current investments in compliance.