Compliance

Compliance-related resources to help firms comply with Sarbanes-Oxley (Sarbox), the Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley (GLB), and other government mandates.

Advice & Opinion

Avoiding IT Audit Nightmares

IT's problems can draw unwanted notice now that Sarbanes-Oxley requires them to appear in 10-K reports as 'material weaknesses.' Full Story »
How To

How IT Can Achieve Operational Resiliency

Today's complex IT environments make maintaining 'always on' availability more challenging than ever before, even as IT has become central to most business operations. IDC's David Tapper says organizations must adopt a plan for achieving operational resiliency.

News

Compliance vs. Risk in Enterprise Security

A CIO once quipped, "Security isn't hard, compliance is." And in fact many companies focus their security efforts on meeting compliance requirements. But if you are audit compliant, have you in fact addressed all of your risks, or are you just kidding yourself? Is it better to focus on the risks presuming that doing so will cover you off on the compliance side? Network World Editor in Chief put the question to two practitioners, both of whom come down on the side of risk.

Feature

Straight Talk on Security Gets Employees to Listen -- and Comply

From phishing your own employees to sharing your company's hack history, these techniques can help you get -- and keep -- users' attention about security.

Feature

How to Downgrade From Windows 8 (Hint: The First Step Is to Know Your Rights)

For a variety of reasons, some businesses are looking to downgrade from Windows 8 to Windows 7. The good news is that Microsoft's business licenses come with downgrade rights, but the catch is that the rules can be tricky and compliance could become an issue. Here are some clarifications on your rights when downgrading from Windows 8 or standardizing on noncurrent Microsoft software.

News

IT Security Managers Too Focused on Compliance, Experts Say

Companies with IT security strategies that focus mostly on complying with key standards are dangerously unprepared for emerging cyber threats, said security experts at the RSA Conference 2013 here this week.

Feature

Is Stolen IP Walking in the Door With New Employees?

More than half of employees who left or lost their jobs in the past 12 months took confidential corporate data with them and most plan to use it in their new jobs, creating the potential for IP contamination. How can you protect your IP?

News

PCI Council Releases Guidelines for Cloud Compliance

A new set of guidelines from the PCI Security Standards Council is intended to help merchants and cloud services providers comply with the PCI DSS when handling payment card data on the web.

News

Startup Service Targets Electronic Workplace Compliance, Training

Startup Convercent officially debuted today with a software-as-a-service (SaaS) offering that lets employers make available to employees in electronic form, via computer or mobile device, the workplace ethics and compliance terms the business supports.

News

EMC Offers Online File Sharing With On-Premise Storage Product

EMC is building on its acquisition of the Syncplicity file-sharing and collaboration service by combining it with its Isilon scale-out NAS to provide the enterprise what the storage giant claims provides the convenience of a cloud-based file-sharing service with the administrative and governance capabilities of an on-premise solution.

News

How IT Departments Can Prepare for a Software License Audit

As revenue for new software licenses is down, software vendors are focusing more on licensing audits to recover some of that lost income. Here's a look at some of the steps a corporate IT organization can take before the auditors arrive to maintain compliance and limit potential damage.

Feature

Employees Engage in Rogue Cloud Use Regardless of Security Policies

Studies show that employees are engaging in rogue use of the cloud, even when IT organizations say they have clear formal cloud policies and penalties for violation of the policies.

Feature

How IT Can Prepare for Mobile Forensic Investigations

If your IT security team must comply with regulations like PCI-DSS or HIPAA, you need to know who accesses your data and what they do with it, even if they're using a mobile device to do it. But performing forensic investigations on mobile devices is trickier than it is on PCs.

News

Dell Expands Private Cloud Offerings

Dell on Thursday said it will offer dedicated servers in its data centers and off-premises application and storage services for companies looking to establish private clouds.

Feature

How to Secure Data by Addressing the Human Element

Your sensitive data is only as secure as the weakest link in your organization, and in many cases the weak link is your employees. A properly established security awareness and training program can pay huge dividends.