Home > Compliance Management Tips > > Why it may not be ideal for your lawyer to be your compliance officer
Compliance Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Why it may not be ideal for your lawyer to be your compliance officer


Kevin Beaver, Contributor
05.19.2009
Rating: --- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Who's in charge of compliance in your organization? Is it your in-house legal counsel? If so, you're not alone. Many businesses, especially in larger enterprises, tend to have a lawyer heading up compliance.

In my opinion, that may not be the ideal person to have running the show. I understand we don't do business in an ideal world, and you're likely to never have the "perfect" person as a compliance officer. With that said, business leaders need to be smart about whom they put in charge of compliance. With the astronomical costs associated with compliance, they have to be.

More compliance resources
Five steps to get started with a GRC program

Economic downturn won't kill regulatory compliance projects
This leads me to my thoughts on lawyers and compliance. First, let me be clear: I have the utmost respect for lawyers, both in what it takes to become successful in the legal field as well as how their executive-level expertise is integral to running a business. I work with lawyers very closely as an expert witness and quite often in my consulting work. I also have friends who are excellent corporate attorneys. The problem I'm seeing in my work and in the industry in general is that lawyers are put in charge of end-to-end compliance when they're often not the best person for the job.

Compliance is a very complex business issue, with components that include IT operations, information security management, privacy management, external and internal audit, contractual and regulatory oversight and so on.

Many lawyers in compliance officer positions focus on the legal and regulatory components of compliance and nothing more. They want to know simply, "Are we compliant?" in order to relay that message onto management. In many situations they create data classification documentation, review security policies and ensure internal auditors keep IT controls in check -- but it ends there. Sometimes overlooked are information risk assessments, vulnerability management, incident response, disaster recovery, access controls and encrypting data in transit and at rest -- all of which are key components of legal and regulatory compliance. Gaps in compliance coverage are a main contributor to the data breach problem that grows every day.

Don't get me wrong: I don't think it's ideal to have a network administrator or information security manager as a compliance officer, either. Many people who fall into this category view compliance with their blinders on as well. They often see compliance merely as a technical issue: patching, conducting security scans, ensuring servers and applications are available and so on.

Nor is it ideal to have a general business manager or auditor who's not technically savvy in charge of compliance. Such people may understand policies and controls and are often good with user education, but there's that large technical component that can get overlooked.

The reality is many compliance managers -- lawyers, IT staff, you name it -- are missing the boat with compliance. I can't tell you how many times I've seen businesses with "compliance managers" who were completely out of the loop on state data breach notification, PCI DSS and even the very information security assessment work I may be performing for their businesses.

We have to strike a balance. It pays to have a
governance/
compliance committee with several key plays on board and making decisions.

The reality is that most lawyers are very good at what they do, but they're not necessarily information security and privacy experts. Likewise, information security experts are often very good at what they do, but they often don't understand the regulatory and legal side of the business. We have to strike a balance. It pays to have a governance/compliance committee with several key players on board and making decisions. There has to be an individual heading up compliance management, but this needs to be a person with the right tools and wisdom.

I believe the compliance officer should be someone with a technical background who understands the value of a solid control framework, strong security and privacy-related documentation; communicates well with management and users; and is eager to stay on top of the compliance landscape. It may seem too ideal to find in an employee, but I know these people exist. I have a good friend who fits this mold and I meet others like this as well, so I know they're out there. It's really a matter of understanding the overall compliance needs of your business and the skill sets required.

Business leaders of the world, think this one through. Focus on minimizing your investment in compliance while maximizing its effectiveness, rather than being just another business contributing to the compliance imbalance. Find the right person, regardless of what degree or professional license he possesses.

Kevin Beaver is an information security consultant, expert witness, as well as a seminar leader and keynote speaker at Atlanta-based Principle Logic LLC. Beaver can be reached at kbeaver@principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchCompliance.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Managing compliance teams
Applying the ISO 27005 risk management standard
The top regulatory compliance trends for IT operations in 2010
Top IT compliance management news stories of 2009
Priorities for your sound regulatory compliance management policy
HIPAA-covered entities' first step should be a quality assurance plan
Survey shows privacy policy success lies in collaboration with IT
HIPAA-covered entities, business associates confront HITECH rules
Steps toward making information security as important as data security
FAQ: What is the impact of e-discovery law on IT operations?
A compliance officer, secure network aren't enough for real compliance

Managing governance and compliance
Sorting through GRC framework questions
What MOF, ISO 2700x and PCI DSS can mean for your compliance strategy
Real-time compliance, social networking and the cloud highlight RSA
What's a risk management strategy worth to your S&P credit rating?
Find unexpected vulnerabilities to ensure cloud compliance
Congress hears testimony on location-based services and online privacy
Private Sector Preparedness Program provides business continuity options
Applying the ISO 27005 risk management standard
Schmidt: Apply risk management to the nation's cybersecurity threats
Business method patents ruling could spell relief from patent trolls

Risk management and compliance
Sorting through GRC framework questions
What MOF, ISO 2700x and PCI DSS can mean for your compliance strategy
Real-time compliance, social networking and the cloud highlight RSA
Contingent controls complement business continuity, DR
Social networking security poses risks to online privacy: RSA panel
What's a risk management strategy worth to your S&P credit rating?
201 CMR 17.00 compliance: Fast Guide to the Mass. data protection law
Will Private Sector Preparedness plan spur business continuity action?
Improving regulatory compliance management through log analysis, SIEM
Defending enterprise security in the post-Google Aurora era

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
IT controls  (SearchCompliance.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsBlogsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts