Kamis, 10 Mei 2012

Compliance With ISO27001 - Is It Really Necessary?


In today's high technology environment, organizations are becoming increasingly dependent upon their information systems. Information is widely regarded as the life blood of the modern enterprise. And, consequently, the security controls surrounding these systems are becoming the differentiating factor in customer choice. With data being held on many of the most sensitive aspects of the business, including key third party stakeholders, information security integrity has become a focal point of all business initiative. The protection of information assets - information security - is therefore overtaking physical asset protection as a fundamental corporate governance responsibility.
Organizations are facing a flood of threats to their information, with new challenges emerging almost daily. Any breach to security can have a severe effect on the operational running, reputation, or legal compliance of the organization. Damage to any one of these areas can be measured by its impact on the bottom line, in both the short and long term. It is self-evident that organizations should, therefore, take appropriate steps to secure and protect their information assets. This is now particularly relevant with the web of legislation and regulation to conform too, making firms criminally liable, and in some instances making directors personally accountable for implementing and maintaining appropriate risk control and information security measures. No longer is it enough to find and fix vulnerabilities on an ad-hoc basis. Only a comprehensive, systematic approach will deliver the level of security that any organization really needs.
Today, security processes need to be well documented and substantiated. So it's no longer good enough to be secure; organizations have to be able to prove they are secure. If done correctly, this additional layer of regulatory scrutiny and reporting can help enterprises combine their security and compliance programs better to streamline efforts, control costs and keep networks secure and compliant.
With the key corporate governance objective being to ensure that the organization has an appropriate balance of risk and reward in its business operations, information security requirements should be identified by a methodical assessment of security risks, with expenditure on risk controls needing to be balanced against the business harm likely to result from security failures.
The most practical and effective way for policy makers to handle their information security risks and obligations, is to adopt and implement an information security policy and information security management system (ISMS) that is capable of being independently certified as complying with ISO/IEC 27001:2005. The standard provides the only independently developed framework for the management of information security. While compliance with the standard does not of itself confer immunity from legal obligations, it does point clearly to management's implementation of best practice, of effective IT governance. Security risks managed in this systematic and comprehensive manner help to garner competitive advantage in the organization through the adherence to an international best practice standard. Certification to ISO27001 can also aid in forming part of any potential legal defense required after a security breach.
ISO27001 compliance ensures a company will meet the regulatory guidelines and standards such as the following:
o Sarbanes Oxley (SOX) requires companies to disclose information regarding finances and accounting. SOX helps prevent financial malpractice and accounting disclosures. All US-listed companies must adhere to SOX regulations.
o Gramm-Leach Bliley Act (GLBA) requires financial institutions to protect customer data and provide privacy notices. Banks and financial institutions must follow GLBA.
o Health Insurance Portability and Accountability Act (HIPAA) requires health care organizations to ensure the privacy of personal health information. Hospitals, medical centers and any business dealing with patient medical records must comply with HIPAA.
o Payment Card Industry (PCI) specifies how to secure information systems and media containing cardholder account information to prevent access by or disclosure to any unauthorized party. PCI also covers effective deletion of unnecessary data. Companies that store, process or transmit credit card holder data must follow PCI.
o COBIT is an IT governance framework and supporting toolset that allows managers to bridge the gap between control requirements, technical issues and business risks. COBIT enables clear policy development and good practice for IT control throughout organizations. COBIT emphasizes regulatory compliance, helps organizations to increase the value attained from IT, enables alignment and simplifies implementation of the COBIT framework.
ISO27001 provides a single coherent and over-arching framework for compliance with all the regulations and standards laid out above, while also actually providing a risk assessment-based approach to information security. Nonetheless, in order to achieve a risk assessment that is completed methodically, systematically and comprehensively an appropriate software tool is a must. It is practically impossible to carry out and maintain a useful risk assessment for an organization that has more than about four workstations without using such a tool that contains fit-for-purpose databases of risk threats and vulnerabilities. This is because the risk assessment is a complex and data-rich process. And for an organization of any size, the only practical way to effectively undertake the project is to create a database that contains details of all assets within the scope of the ISMS, and then to link, to each asset, the details of its (multiple) threats and (multiple) vulnerabilities, and their likelihood and resulting impacts, together with details of the asset ownership and its confidentiality classification.
The risk assessment process is made enormously simpler if ready-made databases of threats and vulnerabilities are used. The database should also contain details of the control decisions made as a result of the risk assessment, so at a glance, it easy to see what controls are in place for each asset within the ISMS. To one extent or another, the software tool chosen to perform the ISMS should automate the risk assessment process and generate a Statement of Applicability. It should also encourage the user to perform a thorough and comprehensive security audit on the organization's information system, while not generating too much paperwork. The chosen software should produce risk assessment results that are easily comparable and reproducible.
One such tool on the market developed to help organizations quickly and easily carry out an ISO27001-compliant risk assessment is the ISMS tool vsRisk(TM)- the Definitive ISO27001: 2005-Compliant Information Security Risk Assessment Tool. Equipped with a wizard-based approach to simplify and accelerate the process for undertaking risk assessments; asset by asset identification of threats and vulnerabilities; the tool easily imports additional controls to deal with risks, and an integrated threats and vulnerability databases, which are continually updated to ensure that they are the most up-to-date available. vsRisk(TM), in terms of functionality, ease of use and value for money, and alignment with the requirements of ISO27001 is the most complete ISMS software tool on the market.
Effective risk management is a continuous Plan-Do-Check-Act-Cycle which means that the risk assessment must be regularly revisited at planned intervals and take into account changes in the business environment, regulatory bodies, and a review of the residual risks. However, following the initial resource intensive phase of the ISMS implementation the organization should find subsequent reviews of the ISMS are much less labour intensive and relatively easily maintained with the aid of the right software tool.
* vsRisk(TM) can also be found as part the No 3 Comprehensive ISO 27001 ISMS Toolkit, a necessity for organizations looking to accelerate their ISO27001 project and develop an ISO27001-compliant Information Security Management System (ISMS).
Chris Hanwell is the Product and Services Executive of 27001.com (itgovernance.co.uk), the one-stop-shop for information security books, tools, training and consultancy


Article Source: http://EzineArticles.com/1099155





By 

Meeting Regulatory Standards for Compliance: Seven Tips to Help Insurers Guarantee Effective Enterprise-wide Data Searches

As an insurer, you probably recognize the value of digital storage and workflow automation for business. Not only does it accelerate processing speeds and improve service; it makes the burden of regulatory compliance significantly easier. In order to meet regulatory standards, efficient data collection across the enterprise is critical. You need to be able to use that data when and where it is needed. 

From HIPAA and Sarbanes Oxley to market conduct examinations, regulatory issues such as Solvency II, and more, mounting regulations continue to dictate the way we store information and conduct everyday business. Establishing clear policies that respond promptly to regulatory changes and implementing them effectively helps you to protect your leaders and your company. Still, you need immediate, thorough, and accurate audit trails to demonstrate your commitment to the policies you create. 

The time-consuming measures you have to put in place to respond to increasing regulations can be frustrating, but they aren’t avoidable. The regulations are not going to disappear; in the wake of numerous recent financial scandals and the ensuing economic crisis, they are expected to proliferate. The sooner you get a handle on your information, the better equipped you will be to survive public and private scrutiny from government, compliance officers, and auditors. 

Here are a few tips to help you stay afloat in the turbulent sea of changing regulations: 

1) Create a central repository for all of your information. Although digital capture and storage improves data quality and makes data access easier, faster, and more secure, ‘going digital’ alone is not enough. Electronic files should be stored in a single, central electronic document management (EDM) repository, or that repository should point to the location of files that are stored in multiple systems. This enables centralized queries and searches, rather than probing through multiple digital data silos when you need information quickly. It gives you and your auditors instant, detailed insight into your business transaction details. 

2) Configure your document management system to restrict access to information in accordance with regulations and your internal policies. Make sure your system has the flexibility to let you define and limit access by business unit, department, a person’s role or position, and individual. Make sure it can also prohibit access to specific pages within routine documents that contain sensitive information. 

3) Take into consideration the enterprise-wide needs for the data within your documents that you weren’t originally planning to catalog as you create a file indexing plan. The data may be vital to another department’s or individual’s process. Understand how people with diverse job functions search for information so you can make it quick and easy for them to find it when it’s needed. 

The regulations are not going to disappear; they are expected to proliferate. The sooner you get a handle on your information, the better equipped you will be to survive public and private scrutiny from government, compliance officers, and auditors. Make sure any data they need to find from the files is included in your indexing plan. Making changes in the indexing scheme later in order to correct current oversights is very costly. 

4) Take care that your enterprise search application fully integrates with your electronic storage repository. This helps you to guarantee a complete return of requested files and data. Otherwise, you may encounter errors and omissions as a result of poor interoperability between your document management repository and the search tools you use. 

5) Choose an enterprise search application that lets you access data in structured forms and files as well as unstructured data stored in your repository, such as data stored in handwritten correspondence or emails. Comprehensive search will save you and your staff considerable time, and you will rest easier knowing that your queries aren’t overlooking anything. 

6) Make sure your system provides clear, structured data in an auditable format that will meet the needs of auditors and compliance officers. Electronic queries should provide details of all file access and business transactions involving digital media. This makes it easier to prove compliance with the information governance policies you establish and communicate. 

7) Don’t forget to include email archival and indexing in your document management system. Some sources suggest that businesses store as much as 90% of their critical data in email communications. The ability to search email messages and attachments that have been archived and indexed ensures thorough and fast access to important information, saving you time and money. When you need to search email to show proof of compliance or to support other documentation, you’ll be glad not to have to resort to slow manual searches. 

Compliance Scenario: Before and After EDM 

Let’s imagine someone in your company—for whatever reason—obtains and shares private information about a person whom the company recently insured, who has health problems. The insured person learns through a conversation related to a job application that her potential employer is aware of her health issues, but she knows that she has never mentioned them. She suspects that someone on the insurer’s staff saw information on the health insurance application and leaked it to the potential employer, and she files a lawsuit against the company. The court issues a subpoena for her application and any records pertaining to who accessed it, when, and for what reason. 

In a paper-based system, your compliance routine might look like this: 

• Management talks with the appropriate person about the files that need to be pulled. 

• The records manager discovers that the health insurance application is missing. Only pre-specified employees who are legally allowed to access the files – those who rely on the information to do their jobs and service the client – are permitted access. 

• Management approaches every person in the office who was permitted to access the insured’s files, but no one claims to have pulled the document since the day it was approved and sent to the records manager for appropriate storage. Don’t forget to include email archival and indexing in your document management system. The ability to search email messages and attachments that have been archived and indexed ensures thorough and fast access to important information, saving you time and money. 

• Management assumes staff is innocent, but asks the appropriate staff members to search their offices for the application, which is not found. 

• The records manager is instructed to search through the files of others whose applications were logged as being pulled from the files on the same day. 

• Fortunately, the file is found, stuck to another applicant’s file that was checked out the same day. 

• Since there was no record of authorization to pull the applicant’s file from storage, and yet it was missing, the company can not prove its staff is innocent of foul play. The lawsuit moves forward, requiring additional records relating to a staff member who is accused and suspected. An inordinate amount of time is wasted on searching for and pulling documents. In addition, the company pays considerable fines because it can not prove compliance without a doubt. 

In a mixed media system with partly digital records and partly paper, the same routine might look like this: 

• The records manager searches the paper files for the application in question. 

• The human resources manager searches through sensitive digital records that are under her domain as well as supporting paper documentation. 

• Files are compiled and presented for analysis. 

• There is some data inconsistency about the employee, most likely resulting from errors in the manual data entry of information. 

• Both the records manager and HR manager lose valuable time conducting an exhaustive search. Since not all files are digital, nor are they in one place, considerable time is wasted, and the audit trail is not complete. 

Imagine the same scenario, with everything stored in a single, centralized EDM system: 

• The court subpoenas the applicant’s form and the HR records that are specific to the employee who is suspected of foul play. 

• Queries are built to retrieve the application as well as the suspected employee’s files. 

• The compliance officer and auditor are granted access to query the electronic files. They examine the file interactions remotely from their laptops, giving them direct access to the information they need and allowing the company’s staff to remain focused on other mission-critical work. 

• Clear audit trails show that the suspected person (the applicant’s agent) accessed the file and inappropriately forwarded its contents to a friend who works at the company where the insured had applied. 

• Company policy and corporate communications show the insurer regularly and clearly 

• Digital records show that the agent accessed those communications and was not oblivious of the rules. The insurer was also able to locate and produce a form signed by the employee in question that affirmed that he was aware of corporate policy. 

Result: The insurer is able to demonstrate corporate compliance with the policies the company set in place. 

Today’s electronic document management and reporting tools give management, compliance officers, and auditors unquestionable proof of the access, movement, interaction with, and use of files and data. 24/7 remote desktop access provided by web-based document management systems make auditing a breeze, giving those who audit your files easy access while removing the burden of search from your shoulders. Effective enterprise search not only lets you deliver information and improve service to your customers; it provides information to others who need it while making sure you aren’t distracted from focusing on the business at hand. 

Summary 

Meeting regulatory standards for compliance is only going to become more complicated as regulations increase. By digitizing your information, storing it in one place, and establishing effective search across your enterprise, you gain control over your information and how it is used. How you use the extra time you gain through the increased efficiency is up to you. 

Optical Image Technology offers an integrated suite of imaging, document management, and workflow software. The DocFinity suite includes document archiving, lifecycle management, electronic forms, and email management products that support compliance. To learn more about our products and services, visit our website athttp://www.docfinity.com, or call us at 800-678-3241. 

©2009 Optical Image Technology, Inc. All rights reserved. DocFinity, IntraVIEWER, and XML FormFLOW are trademarks or registered trademarks of Optical Image Technology, Inc. 

 by: Laurel Sanders - http://www.docfinity.com 

IT Governance - The Basics


What Is IT Governance?
At the macro level, successful IT governance is accomplished by basing IT practices on high-quality, well-defined, repeatable processes. At the micro level, IT governance focuses on developing precise policies, clearly defined procedures, and scrupulously detailed documentation. In addition to zeroing in on these areas, IT governance also constitutes a forward-looking plan for continual improvement.
Types of Governance Models
There are two main public models for IT governance. The IT Infrastructure Library (ITIL) is a widely accepted approach. Specifically developed for IT service management and operations, ITIL is a framework of best practices that are documented in an abstract fashion to be applicable to any IT organization. ITIL's main focus is to provide service objectives, key activities, and key performance indicators for applications management, IT service delivery and support, infrastructure management, and business perspectives. This method is divided into 48 modules/processes.
Elsewhere, the Control Objectives for Information and related Technology (COBIT) is used as a control framework for corporate IT processes. Organizations use COBIT to manage accountability of IT resources, focus resources on business goals, and to build a framework for risk assessment. It divides information technology into 34 modules/processes that are further organized into four domains: planning, acquiring and implementing, delivery and support, and monitoring.
Action Plan
1.Get executives on board. IT governance is a control management system that enables you to translate a strategic vision into practical and measurable actions. If the top executives don't understand and support a strategic framework for IT governance, then the outcome won't have value. Also, governance is embedded in organizational culture and politics, not just processes. Backing from the C-level team is therefore critical.
2.Know what you're working towards. Reviews of successful IT governance models have revealed that there are characteristics common to all models. Derived from industry standards, the following outcomes are indicative, but not exhaustive, of well-executed governance deployments:
  • Complete, flexible IT structure geared toward the delivery of business applications. 
  • Centrally managed IT infrastructure, as well as centralized IT staff. 
  • Estimated project costs based on a five-year lifecycle cost. 
  • Project portfolio management in place. 
  • Clearly defined reporting relationships and strict adherence to standards.

3.Use modules from the standards bodies. An IT shop in a mid-sized company won't be able to implement ITIL or COBIT in whole - they are simply too big and all-encompassing. You can, however, use parts of them that speak directly to your particular needs. For example, if the help desk is your worry, then use the help desk module from ITIL like the government of Ontario did. When using this module-by-module approach, keep the following tips in mind:
  • Be sure to first benchmark the trouble area before moving ahead with the module. This way, you will be able to better measure performance over time. 
  • Continue to stay focused on this one area of change, as training, implementation, and change management will pose major ongoing challenges. 
  • Use such projects as a learning experience. Document everything and use this information when moving on to the next area that could use governance.

4.Tie in governance with compensation. Management must lead the charge when implementing IT governance. Bonus programs for employees will have to change to reflect a focus on positive metrics and key performance indicator improvements.
In Summary
IT governance plays an important role in making companies more successful via streamlined and standardized processes. Get started now to realize long-term benefits.
Visit [http://hcsfit.com] to learn more.


Article Source: http://EzineArticles.com/4084526

By Rick Spair