Home > Compliance Management News > Economic downturn won't kill regulatory compliance projects
Compliance Management News:
EMAIL THIS

Economic downturn won't kill regulatory compliance projects

By Mark Schlack, Vice President, Editorial
05 Feb 2009 | SearchCompliance.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

High-level IT managers report that while budgets are down for many this year, most will go easy when it comes to trimming regulatory compliance budgets. That's according to a recent survey of 275 members of SearchCIO.com and SearchCIO-Midmarket.com.

While 38% of respondents reported that their overall IT budgets were down from 2008, only 16% were cutting compliance budgets, and 39% were increasing budgets (with 44% holding the line). Compliance is a mandate, it would seem -- or more properly, a series of different mandates. No single factor was cited by respondents as driving their efforts. Industry-specific legislation was the most popular driver for 27% of respondents, with the Health Insurance Portability and Accountability Act, litigation discovery and the Sarbanes-Oxley Act all fairly close behind.

As to what the money will be spent on, compliance budgets will purchase backup/recovery equipment or services at half of IT shops. Also high on the shopping list are data protection tools (44%), archiving software or services (38%), log management (35%), content management (30%) and governance/risk management software (26%).

IT departments will also upgrade existing systems to support regulatory compliance. Most commonly, security systems will get upgrades (63%), as well as backup tools (52%), archive systems (46%) and WANs (46%).

One wild card in compliance planning has been the impact of virtualization, particularly at the server level. Despite issues related to having solid audit trails of virtual machines as they move from one physical server to another, most respondents were not concerned. "No impact," said 43%, and 17% said virtualization would make compliance easier, compared with only 4% who thought it would make their compliance jobs harder.

Compliance seems to fit into a more general pattern of how IT is dealing with the economic downturn: make sure the business has the software it needs, consolidate with virtualization to keep costs in line, and make sure external mandates like disaster recovery planning and regulatory compliance are met. That was the overall picture presented by this survey, both in the midmarket and large enterprises.

One more interesting finding of the survey: 45% of top IT managers are involved with or aware of the compliance budget. That's compared with 60% to 80% involvement with the traditional IT stovepipes, such as networking, servers or applications. So compliance is becoming more a part of IT, but not as much as more venerable activities.

Let us know what you think about the story; email: Mark Schlack, Vice President, Editorial



Tags: Managing governance and complianceManaging compliance teamsPCI complianceSOX and other public company compliance requirementsHIPAA and other healthcare compliance requirementsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Managing governance and compliance
A business continuity management standard would offer consistency
Business Model for Information Security: Security right the first time
Facing uncertainty, IT turns to governance, risk and compliance, ERM
Google adds Dashboard: Does transparency mean more online privacy?
NERC CSO warns of cybersecurity threats, risk to electric grid
Priorities for your sound regulatory compliance management policy
Threat management for information systems relies on categorization
HITECH FAQ: What is the impact of the HITECH Act on IT operations?
Survey shows privacy policy success lies in collaboration with IT
Record locator service a step to health information exchange

Managing compliance teams
Priorities for your sound regulatory compliance management policy
HIPAA-covered entities' first step should be a quality assurance plan
Survey shows privacy policy success lies in collaboration with IT
HIPAA-covered entities, business associates confront HITECH rules
Steps toward making information security as important as data security
FAQ: What is the impact of e-discovery law on IT operations?
A compliance officer, secure network aren't enough for real compliance
Chapter excerpt: Decision-making processes and IT governance
Is all the PCI DSS compliance whining and complaining justified?
Anatomy of a hyperproductive compliance management team

PCI compliance
IT compliance: FAQs about IT operations, regulations and standards
Compliance news quiz: Test your knowledge of FTC, SB 20, PCI and more
Priorities for your sound regulatory compliance management policy
Data breach notification law SB 20 strikes right balance: Simitian
D.C. CTO sees compliance, cost savings benefits to cloud computing
Does using ISO 27000 to comply with PCI DSS make for better security?
Security and compliance can go together, when done in the right order
Nonprofits are working to maintain donor trust with PCI compliance
PCI DSS compliance fails to raise the bar on financial fraud
PCI DSS compliance requires better management of vendor risk

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
IT controls  (SearchCompliance.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

HomeNewsTopicsITKnowledge ExchangeTipsBlogsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts