Home > Security Channel Project Guides > Regulatory Compliance Services > Technology to Support Regulatory Compliance > Security automation helps compliance, policy enforcement
Project Guides: Regulatory Compliance Services:
EMAIL THIS
 START   UNDERSTANDING TECHNOLOGY REGULATIONS   STANDARDS   TECHNOLOGY   CASE STUDIES   SELLING COMPLIANCE   
Technology to Support Regulatory Compliance

<< PREVIOUS | NEXT >>: Instant messaging security addresses risks,...

Security automation helps compliance, policy enforcement

By Colin Steele, features writer
08 Jun 2007 | SearchSecurityChannel.com

Channel News Update
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The government and industry regulations put in place early this decade to protect data and prevent corporate scandals left businesses scrambling to comply.

"They knew they had to do something, but they didn't know what to do," said Tom Eid, a research vice president for Gartner Research.

That has changed in recent years, as most businesses have at least put policies in place to address the Sarbanes-Oxley Act, the Health Insurance Portability and Accountability Act (HIPAA),
The cost is going up if you're doing it manually, and the time frame is way too long.
Joe Anthony
program director for identity management, IBM Tivoli Software
the Payment Card Industry Data Security Standard (PCI DSS) and other regulations. Now they're looking for more efficient ways to enforce those policies, often turning to their IT departments. And most see security automation as the best solution, experts and vendors said.

"Compliance management is driving the overall security industry right now," said Joe Anthony, program director for identity management at IBM's Tivoli Software.

Security automation provides sales and service opportunities for channel partners, said Khalid Kark, a senior analyst for Forrester Research. Some vendors focus on helping clients with the process of regulatory compliance, and others focus on the technology behind compliance, but "there isn't anybody who can effectively do both across the board," Kark said.

Eid agreed, saying, "There's not really a technology you can pick up and say, 'Now I'm doing IT (governance, risk management and compliance).'"

That's where the channel can step in and bring the two sides together to offer complete security automation. But Kark warns that those opportunities will dwindle as vendors begin to offer products and services that focus on both the process and the technology of compliance.

More than half of IBM's worldwide compliance sales go through channel partners, who can help clients determine the best policies to set and the appropriate entitlements to grant employees, Anthony said. IBM recommends that customers enlist the help of either IBM or a channel partner to deploy at least their first security automation system, because "a lot of (our partners) have very good implementation experience," Anthony said.

The company's security automation products include Tivoli Identity Manager, which allows the human resources and IT departments to set employees' access based on
More regulatory compliance resources for resellers
Sarbanes-Oxley Compliance Guide

HIPAA Compliance Guide

Visit our topic center for more regulatory compliance tips and strategies
their job descriptions, and Tivoli Security Compliance Manager, which keeps track of who is accessing what information to see if any policy violations have taken place.

The target customers for security automation are businesses that "are doing manual assessments or using their internal auditing systems" for compliance reasons, said Chris Pick, vice president of products and marketing for security and compliance vendor NetIQ. He and Anthony both highlighted the efficiencies that security automation can bring.

"The cost is going up if you're doing it manually, and the time frame is way too long," Anthony said.

Another benefit of security automation is the extra layer of protection it provides against abuses by users with privileged access. Products like Tivoli Security Compliance Manager and NetIQ's Security Manager 6.0 can audit the actions of employees who are supposed to be auditing everyone else.

"Policing those who have power is very much a critical factor," Pick said.

"The benefit of this is transparency," Eid said. "In the past, (the financial performance of an organization) could easily be manipulated. It is much harder now."

Let us know what you think about this story; email Colin Steele, features writer.



Tags: Technology to Support Regulatory ComplianceVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


<< PREVIOUS | NEXT >>: Instant messaging security addresses risks,...
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Regulatory Compliance
Red Flags Rules compliance: Are your customers informed?
PCI compliance guide: A resource for solution providers
PCI DSS pre-assessment services: Prelude to a QSA
The impact of PCI compliance on the channel
Compliance drives opportunities for security integrators
How to turn the HIPAA compliance changes into opportunities
Data protection services offer revenue for security solution providers
Agiliance and McAfee partner for better governance, risk and compliance services
SonicWall announces partnership with Western NRG
Building a framework-based compliance program

Technology to Support Regulatory Compliance
PCI compliance opportunities for security resellers
Global compliance services a competitive advantage for resellers
Instant messaging security addresses risks, compliance
IBM, Symantec join drive toward packaging compliance
Data theft creates a rich product, service market for security VARs
NAC's role in regulatory compliance
Identity-based security tools give customers control of users, not just ports
Selling unified threat management: Making the cost avoidance case

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts