Your Guide to Good-Enough Compliance
- 17 May, 2007 11:55
- Comments
In November 2005, Jason Spaltro, executive director of information security at US-based Sony Pictures Entertainment, sat down in a conference room with an auditor who had just completed a review of his security practices. The auditor told Spaltro that Sony had several security weaknesses, including insufficiently strong access controls, which is a key Sarbanes-Oxley requirement.
Furthermore, the auditor told Spaltro, the passwords Sony employees were using did not meet best practice standards that called for combinations of random letters, numbers and symbols. Sony employees were using proper nouns. (Sox does not dictate how secure passwords need to be, but it does insist that public companies protect and monitor access to networks, which many auditors and consultants interpret as requiring complex password-naming conventions.)
Summing up, the auditor told Spaltro: "If you were a bank, you'd be out of business."
Frustrated, Spaltro responded, "If a bank was a Hollywood studio, it would be out of business."
Spaltro argued that if his people had to remember those non-intuitive passwords, they'd most likely write them down on sticky notes and post them on their monitors. And how secure would that be?
After some debate, the auditor agreed not to note "weak passwords" as a Sox failure.
Doing the Right Thing
Spaltro's experience illuminates a transaction that's rarely discussed outside corporate walls. Compliance with federal, state, and international privacy and security laws and regulations often is more an interpretive art than an empirical science — and it is frequently a matter for negotiation.
How to (or, for some CIOs, even whether to) follow regulations is neither a simple question with a simple answer nor a straightforward issue of following instructions. This makes it more an exercise in risk management than governance. Often, doing the right thing means doing what's right for the bottom line, not necessarily what's right in terms of the regulation or even what's right for the customer.
"There are decisions that have to be made," Spaltro explains. "We're trying to remain profitable for our shareholders, and we literally could go broke trying to cover for everything. So, you make risk-based decisions: What're the most important things that are absolutely required by law?" Spaltro does those, noting that "Sony is over-compliant in many areas", and he says that Sony takes "the protection of personal information very seriously and invests heavily in controls to protect it".
He adds that "legislative requirements are mandatory, but going the extra step is a business decision" based on what makes business sense. So you adjust, you decide, you weigh the issues. It's not black and white, yes or no.
When it comes to compliance, you can, in fact, be a little bit pregnant.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Cost Effective Security and Compliance with Oracle Database 11g Release 2
Information ranging from trade secrets to financial data to privacy related information has become the target of sophisticated attacks from both sides of the firewall. Built upon 30 years of security experience, the Oracle database provides defense-in-depth security controls that enable organizations to transparently protect data. By leveraging these controls, organizations can safeguard data, ensure regulatory compliance, and achieve business goals such as consolidation, globalization, right sourcing and cloud computing while still maintaining scalability, performance and availability. Read this whitepaper. -
Oracle x86 Rack Servers Optimized for Rapid Deployments and Operational Efficiency
Business-critical and mission-critical workloads demanding applications and databases require stable and secure environments. When these types of workloads are deployed on x86 servers, the need to ensure business continuity, maximum uptime, and consistent processing means that IT managers and business unit managers are looking at enterprise x86 servers in a new way: They realize that the business depends on these servers and that x86 server platforms for the enterprise are no longer expendable, as they might have been when servers were dedicated to a single application or when they were deployed as small Web servers that could be easily taken offline and replaced. -
10 Essential Steps to Web Security
This short guide outlines 10 simple steps to best practice in web security. Follow them all to step up your organisation’s information security and stay ahead of your competitors. But remember that the target never stands still. Focus on the principles behind the steps – policy, vigilance, simplification, automation and transparency – to keep your information security bang up to date.
-
Acrobat 6 and PDF Solutions (Includes CD-ROM)
-
3D Tools for Photographers and Illustrators +DVD
-
Photoshop CS2 Bible, Professional Edition
-
Deke Mcclellands's Look & Learn Dreamweaver, Version 4
-
Karel the Robot
-
The Garageband Book
-
Photoshop Elements 4
-
Beginning Access 2000 VBA
-
Macs for Dummies®, 10th Edition








Comments
Post new comment