What it takes to become compliant with any regulation!
- IT TOPICS:Government & Regulation, Security
Are you looking for a magic bullet to solve your compliance project(s)? Are you wondering where that simple fix is that will forever ensure that the government stays out of management's business so management will get off of your back? Well look no longer!
Here's the answer to all your questions!
Just scroll down a bit more!
What's the answer??
IT DOESN"T EXIST!!!
In today's world of all the different compliancy regulations (both public and private), it is no wonder that so many companies want a quick fix to make all the pain go away. But people, it does not exist. You cannot put in a few products and have PCI compliancy. You cannot install some new technology and have all your HIPAA headaches go away. But that is still what people are looking for. And I see no end to it.
I had a great conversation with a fellow employee of mine today. We were discussing the problem of so many people in the security industry just drawing a paycheck and not being motivated to actually secure their network. And those security professionals who do give a crap are often hamstrung by their management when they try to make meaningful changes. We discussed how so many companies freak out when they see how much a security assessment or compliance GAP analysis costs. Then they either scale the project back so far that it is meaningless, or they go with Bob's security company where the consultants just finished Hacking For Dummies last week.
If you have the job of making your company compliant, remember this: compliance is NOT a technology project. It involves so much more. It takes diligence and hard work. Don't get into the checkbox mentality. There is no quick fix. Don't believe the companies that give quick paths to becoming compliant. They don't work. And don't assume that you don't need help. This is not an easy task, even for smaller companies.
Short and sweet, do it right the first time.



