Home > Compliance Management Tips > Compliance Tips > A compliance officer, secure network aren't enough for real compliance
Compliance Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE TIPS

A compliance officer, secure network aren't enough for real compliance


Kevin Beaver, Contributor
07.06.2009
Rating: --- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Compliance is a joke. Seriously. Its definition has gotten so skewed that compliance can mean just about anything to anyone, depending on the circumstances that happen to be in their favor. Even with all the evidence of the complexities involved with compliance today, I still hear people say things like, "We have a secure network, so we're compliant." Or, "Our auditor checked things over and we're compliant." Or, in the case of many physicians' practices, one of my favorites: "We give a notice of privacy practices to all patients who come see us, so we're compliant." Compliant? Compliant with what? Their own made-up concept of what reasonable privacy and security should be?

More compliance resources
Top regulatory compliance trends that will affect IT in 2009

Strategic risk management includes risk-based approach to compliance
I have friends, colleagues and clients who are of the mind-set that some basic documentation, strong passwords and a firewall make them compliant with whatever law or regulation you ask them about. Interestingly, in my work performing security assessments -- which are almost always driven by regulatory compliance -- I see a different story. By and large, there are a lot of compliance officers, security managers and sometimes -- in the case of small and medium-sized businesses -- network administrators who focus most, if not all, of their efforts on the operational "soft" side of security and privacy, completely overlooking the technical issues at hand. They say they're compliant, but the devil's in the details.

Here are some things to keep in mind about compliance:

A compliance officer is not enough. As with a chief information officer, chief technology officer or CEO, just because the person's in the compliance officer position doesn't mean he or she is fit for the job. Compliance requires both business and technical expertise, with a whole lot of people savvy sprinkled in between.

A policy manual is not enough. It's easy to download policy templates off the Internet, fill in the blanks and assume that's enough to please the auditors and regulators. The reality is talk is cheap. It's one thing to say you're doing something but quite another to actually have a set of controls and processes that make things work the way they're supposed to.

Trusting what IT or development says is not enough. A colleague of mine earns his living performing compliance assessments, and not a single one of them involves technical vulnerability assessments. Sometimes, he'll run a high-level auditing tool that does minimal operating system version checking and port scanning, but most of the time, he tells me, he just relies on the security scans that a network admin or developer has run against the network or Web application. They're often outdated and of minimal depth. Talk about the fox guarding the henhouse. Third-party validation (be it in-house or through a consultant or security firm) really needs to be done.

Security scans are not enough. There's no doubt that running a quality vulnerability scanner such as QualysGuard against your operating systems or Acunetix Web Vulnerability Scanner against your Web applications is vital. As good as tools like these are, you still have to take your security vulnerability scanning results with a grain of salt. A monkey could be taught to run most scans. It's what you do with the results (i.e., filter the false positives and focus on what matters in the context of your business) that's going to make the difference. Furthermore, scans don't tell the whole story. Manual analysis using ethical hacking techniques easily makes up 40% to 50% of your overall security testing. Doing both scans and manual analysis is the only way you're going to find all the things that matter.

A secure network architecture is not enough. You can have the most well-designed network with fancy firewalls separating the LAN segments, a demilitarized zone for your Internet-facing systems, virtual LANs scattered about and so on, but bad things can still happen. Internal users still, almost always, have unfettered access to your network and sensitive information they shouldn't be getting into. They also have unprotected laptops and smartphones that are likely exposing sensitive "regulated" information this very minute. Take a look at the publicized data breaches. It's your internal users you've got to worry about -- something a strong network is not going to do much for.

[The definition of compliance] has gotten so skewed that compliance can mean just
about anything to anyone, depending
on the circumstances that happen to be in their favor.

Passwords aren't enough. There are a lot of assumptions about passwords that get people into trouble. The general consensus I've seen is that as long as passwords are required, then the sensitive information behind the login mechanism is safe. This is a dangerous mind-set that can create a false sense of security with your operating systems, Web applications and especially the security of your laptop computers and mobile devices. Not good for compliance.

Certificates and products are not enough. I see a lot of organizations claim that their data center is SAS 70 Type II compliant, therefore they're secure. Likewise with all these compliance management products. The assumption is compliance can be bought. It really can't. Compliance does not come in a box, nor does it come in an annual report. It comes from the top in the form of leadership, culture and support for doing what's right.

Past processes aren't enough. Sure, patches may have been applied recently, backups have probably been kicked off, and security scans were run not too long ago, but what are you doing on a periodic and consistent basis that's going to keep sensitive information protected today, tomorrow and beyond? Compliance is not a one-time deal.

Doing an assessment or a higher-level gap analysis against any of the current laws and regulations may not uncover much, and things may look quite rosy now. But you probably haven't looked hard enough. You have to dig deeper into your operations and systems to truly find out where you stand.

I'm not trying to be a pessimist. Nor am I trying to spread fear, uncertainty and doubt to create work. I'm just calling it like it is. I don't like government and industry intrusion into how we do business any more than the other guy. But it's here and something we've got to deal with in the right way.

Bottom line: Be careful claiming compliance when you haven't looked at the whole picture. Don't fall for the compliance by checklist or the compliant-now-equals-compliant-always misconceptions. They'll surely come back to bite you. The reality of it all may be quite different than how you see it from your perspective. It may not matter for now, and it may not matter for a while. But the truth will come out when someone such as a customer, business partner or concerned employee questions your compliance status, or worse: once a breach occurs.

Kevin Beaver is an information security consultant and expert witness, as well as a seminar leader and keynote speaker at Atlanta-based Principle Logic LLC. He can be reached at www.principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchCompliance.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Regulatory compliance audits
Effective compliance document management in five days
FAQ: What is the impact of a compliance audit on IT operations?
ISO 27001 certification not enough for verifying SaaS, cloud security
HIPAA-covered entities' first step should be a quality assurance plan
Healthcare, cybersecurity policy and privacy on legislative agenda
FTC pursuing HIPAA violations as a matter of consumer protection
New HIPAA data breach notification rules put health industry on notice
PCI DSS compliance fails to raise the bar on financial fraud
HIPAA-covered entities, business associates confront HITECH rules
PCI DSS FAQ: The Payment Card Industry Data Security Standard and IT

Vulnerability assessment for compliance
New evaluation criteria for Web application security scanners
GPS devices, geolocation data create privacy, security risks
Security and compliance can go together, when done in the right order
Steps toward making information security as important as data security
Run encryption the right way to ensure wireless network security
Security concerns may mean peer-to-peer file sharing days are over
How CISOs can leverage the internal audit process
How to build a mature information security program: A crisis helps
How to mitigate operational, compliance risk of outsourcing services
Applying risk assessment to your disaster recovery plan

Managing compliance teams
Priorities for your sound regulatory compliance management policy
HIPAA-covered entities' first step should be a quality assurance plan
Survey shows privacy policy success lies in collaboration with IT
HIPAA-covered entities, business associates confront HITECH rules
Steps toward making information security as important as data security
FAQ: What is the impact of e-discovery law on IT operations?
Chapter excerpt: Decision-making processes and IT governance
Is all the PCI DSS compliance whining and complaining justified?
Anatomy of a hyperproductive compliance management team
Chapter excerpt: The Three Core Disciplines of IT Risk Management

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
compliance audit  (SearchCompliance.com)
compliance validation  (SearchCompliance.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsBlogsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts