Home > Compliance Management Tips > Compliance Tips > Legal Expert: MDM can advance compliance goals
Compliance Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE TIPS

Legal Expert: MDM can advance compliance goals


Jeffrey Ritter
08.06.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


IT executives truly dislike getting lawyers involved in any substantial IT-driven project. They see delays, undue scrutiny and concerns about risk avoidance that could change or stall their effort. The lawyer, meanwhile, appears to take forever, often because of the technology learning curve and a lack of time to devote to the project.

A master data management (MDM) project, or any data governance effort, definitely triggers these lawyer-avoidance reactions. Intensive, detail-oriented work on data consolidation, deduplication and synchronization of programs and applications consistently proves to be more difficult when lawyers are on hand.

However, an MDM system can significantly reduce your company's exposure to legal risk and lower the cost of legal and compliance services if designed and implemented correctly. How? Put a lawyer on the project team, use compliance to build your business case, then ensure that your new single version of the truth delivered via MDM meets compliance objectives, and you'll have a winning project all around.

Embed compliance into the MDM architecture

Of course, we aren't there yet. As MDM practices mature, companies are learning that project teams often overlook the need to align MDM data to existing compliance controls during the system assessment and design process. Remediating this omission downstream adds costs and runs the risk of a late-stage veto by the legal department.

By contrast, emphasizing compliance and resulting cost savings as a business driver for the MDM program ensures alignment from the beginning. The key is to ask: "How can MDM reduce the cost of compliance?"

To do this, the CIO needs to look at the compliance costs of working with status quo data that is inaccurate or in conflict


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Data retention and compliance software
Voices from RSA: CA's Dave Hansen on compliance strategy
Biometric security data adds layer of privacy compliance risk
Hacked dental school server compromises 300,000
Data center virtualization: Four steps to compliance
Google amends log retention rules, privacy advocates respond
Clearwell makes its electronic discovery search more transparent
PCI groups to focus on wireless, pre-authorization changes
Digitized data creates storage management and compliance challenges
E-records management moves up the state CIO agenda
HP targets compliance officers with refreshed database archiving software

Risk management and compliance
Critical infrastructure at risk to cyberattacks: What you can do
Strategic risk management includes risk-based approach to compliance
Scale aside, cloud computing compliance still worries IT managers
Comparing how-to guides for business continuity standards
Twitter security risks, popularity spark regulatory concerns
Business model risk is a key part of your risk management strategy
SEC commish, FINRA head: Reform financial services regulations
Ex-SEC chief Pitt decries state of Sarbanes-Oxley and risk management
Anatomy of a hyperproductive compliance management team
Chapter excerpt: The Three Core Disciplines of IT Risk Management

Compliance Tips
A compliance officer, secure network aren't enough for real compliance
Electronic discovery critical to health of company, IT organization
Critical infrastructure at risk to cyberattacks: What you can do
Comparing how-to guides for business continuity standards
Nevada toughens data protection law with crypto, PCI requirements
How to mitigate operational, compliance risk of outsourcing services
Applying risk assessment to your disaster recovery plan
HIPAA becoming a standard for data protection regulations
What's in the White House Cyberspace Policy Review you need to know?
Anatomy of a hyperproductive compliance management team

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


with other internal records as well as the costs of audits, inspections or legal actions associated with finding the right data. Another part of the justification is avoiding any potential legal penalities stemming from an inability to find data in a timely fashion. One midsized investment management firm, for example, recently confided it cost nearly $5 million to respond to a routine Securities and Exchange Commission "sweep" review.

Next, to embed compliance into MDM initiatives, the CIO needs to conduct a thorough risk analysis of how the MDM services affect the existing configuration of the organization's compliance framework and controls. This risk assessment has several steps:

Implementing these steps takes work. IT executives familiar with International Standards Organization-based information security controls can often manage the compliance dimension of MDM systems using the same process-based control orientation used to deploy security controls. Create a map of the compliance risks, the control objectives to be achieved and the specific controls to be employed. Here is a CastleQuest sample map with some ideas on how to integrate compliance into your MDM project.

Provide clear, measurable criteria against which to declare victory and move forward, making continual improvement of your company's compliance profile an important new benefit that MDM can achieve.

Not only will you build a stronger case for your system, but you'll also keep your legal team happy -- and perhaps more responsive for your next project.

Jeffrey Ritter, Esq., is CEO of Waters Edge Consulting LLC in Reston, Va. Waters Edge offers strategic consulting services to develop improved information governance. Write to him at editor@searchcio-midmarket.com or Jeffrey@wec-llc.com.

Rate this Tip
To rate tips, you must be a member of SearchCompliance.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsBlogsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts