<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>eIQviews &#187; Compliance</title>
	<atom:link href="http://blog.eiqnetworks.com/tag/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.eiqnetworks.com</link>
	<description>Perspectives on Security and Compliance Management from eIQnetworks</description>
	<lastBuildDate>Mon, 14 Dec 2009 13:04:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.eiqnetworks.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/9a3baa02baa3289d9a8c9a6a0eb652a5?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>eIQviews &#187; Compliance</title>
		<link>http://blog.eiqnetworks.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.eiqnetworks.com/osd.xml" title="eIQviews" />
	<atom:link rel='hub' href='http://blog.eiqnetworks.com/?pushpress=hub'/>
		<item>
		<title>Press Release: ComplianceVue Packages for PCI, NERC and HIPAA</title>
		<link>http://blog.eiqnetworks.com/2009/09/09/press-release-compliancevue-packages-for-pci-nerc-and-hipaa/</link>
		<comments>http://blog.eiqnetworks.com/2009/09/09/press-release-compliancevue-packages-for-pci-nerc-and-hipaa/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 18:13:29 +0000</pubDate>
		<dc:creator>eiqbeth</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Product]]></category>
		<category><![CDATA[ComplianceVue]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[NERC CIP]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Press Releases]]></category>
		<category><![CDATA[SecureVue]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=259</guid>
		<description><![CDATA[Today eIQ announced new ComplianceVue Packages, a turnkey offering to address compliance reporting requirements based on its SecureVue® security and compliance management platform. The ComplianceVueTM packages (PCIVueTM, NERCVueTM, and HIPAAVueTM) provide detailed compliance reporting across more than just log data, greatly surpassing the capabilities of competitive products. ComplianceVue packages are available immediately to address PCI-DSS, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=259&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Today eIQ announced new ComplianceVue Packages, a turnkey offering to address compliance reporting requirements based on its SecureVue® security and compliance management platform. The ComplianceVue<sup>TM</sup> packages (PCIVue<sup>TM</sup>, NERCVue<sup>TM</sup>, and HIPAAVue<sup>TM</sup>) provide detailed compliance reporting across more than just log data, greatly surpassing the capabilities of competitive products. ComplianceVue packages are available immediately to address PCI-DSS, NERC CIP and HIPAA regulatory requirements.</p>
<p>“eIQnetworks already correlates data from more data sources than any other solution on the market, and for that reason SecureVue is uniquely positioned to identify sophisticated in-progress attacks or vulnerabilities that log-only solutions will miss,” said Vijay Basani, eIQnetworks’ CEO. “With the ComplianceVue packages, eIQ now offers a turnkey solution for comprehensive compliance reporting across a broad range of security data including events, configuration data, vulnerabilities, and network flows, proving again that ‘log data is not enough’ to properly prove adherence to regulatory rules.”</p>
<p>The new ComplianceVue packages include a SecureVue Central Server, and the associated compliance reporting modules and dashboards required to provide necessary documentation for regulatory-driven audits. Reporting is effortless, and section-specific compliance reports are directly linked to appropriate rules and requirements of each supported regulation, best practice, or standard. Interactive dashboards provide real-time views into key compliance metrics, and provide drill-down into underlying data to support comprehensive internal and external auditing needs.</p>
<p>For more details and benefits on the new ComplianceVue package, check out the full press release on the eIQ site: “<a href="http://www.eiqnetworks.com/news/eIQ_ComplianceVue_Final.shtml">eIQnetworks Introduces ComplianceVue Packages for PCI, NERC and HIPAA to Streamline Regulatory Compliance Reporting</a>”</p>
<br />Posted in Announcements, Compliance, Product Tagged: Compliance, ComplianceVue, HIPAA, NERC CIP, PCI, Press Releases, SecureVue <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/259/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=259&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/09/09/press-release-compliancevue-packages-for-pci-nerc-and-hipaa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">eiqbeth</media:title>
		</media:content>
	</item>
		<item>
		<title>eIQcast Episode 17: Exposed Smart Metering and Energy Security Compliance</title>
		<link>http://blog.eiqnetworks.com/2009/07/06/eiqcast-episode-17-exposed-smart-metering-and-energy-security-compliance/</link>
		<comments>http://blog.eiqnetworks.com/2009/07/06/eiqcast-episode-17-exposed-smart-metering-and-energy-security-compliance/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 14:05:45 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[eIQcast]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[smart meter]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=220</guid>
		<description><![CDATA[According to published reports, one of the anticipated sessions at the upcoming Black Hat conference will show vulnerabilities within smart metering technologies that certain utilities are deploying to make the electricity grid more intelligent&#8211; from energy production through consumption. The big question is whether the vulnerabilities would put utilities out of compliance with energy industry [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=220&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:Calibri,Verdana,Helvetica,Arial;"><span style="font-size:11pt;"><a href="http://www.flickr.com/photos/juverna/3681292330/"><a href="http://www.flickr.com/photos/juverna/3681292330/"><a href="http://www.flickr.com/photos/juverna/3681292330/"><a href="http://www.flickr.com/photos/juverna/3681292330/"><img class="alignright size-full wp-image-221" title="&quot;2009-06-29 Smart Meter 2&quot; originally uploaded by juverna" src="http://eiqviews.files.wordpress.com/2009/07/smart-meter.jpg?w=240&#038;h=180" alt="&quot;2009-06-29 Smart Meter 2&quot; originally uploaded by juverna" width="240" height="180" /></a></a></a></a>According to published reports, one of the anticipated sessions at the upcoming Black Hat conference will show vulnerabilities within smart metering technologies that certain utilities are deploying to make the electricity grid more intelligent&#8211; from energy production through consumption.</p>
<p>The big question is whether the vulnerabilities would put utilities out of compliance with energy industry regulations regarding security.</p>
<p>In the latest episode of eIQcast, Ross Levanto asks eIQnetworks Product Evangelist John Linkous for a review of what we know about the vulnerabilities and the current state of security compliance within the energy industry.</span></span></p>
<p><span style="font-family:Calibri,Verdana,Helvetica,Arial;"><span style="font-size:11pt;">Running time: 10:27<br />
</span></span></p>
<div><a href="http://eiqcast.podOmatic.com" target="eiqcast"><br />
<img src="http://www.podomatic.com/images/share/player_logo.jpg" border="0" alt="" /></a></div>
<p>Direct Link: <a href="http://eiqcast.podOmatic.com/entry/2009-07-06T06_58_21-07_00" target="_blank"><span style="color:#0000ff;"><span style="font-family:Calibri,Verdana,Helvetica,Arial;"><span style="font-size:11pt;"><span style="text-decoration:underline;">http://eiqcast.podOmatic.com/entry/2009-07-06T06_58_21-07_00</span></span></span></span></a><span style="font-family:Calibri,Verdana,Helvetica,Arial;"><span style="font-size:11pt;"> </span></span> <!--EndFragment--></p>
<p><em>Don’t be like Dick and check out eIQ’s video at <a href="http://www.logdataisnotenough.com/" target="_blank">logdataisnotenough.com</a></em></p>
<br />Posted in eIQcast Tagged: Compliance, NERC, smart meter <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/220/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/220/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/220/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/220/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/220/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=220&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/07/06/eiqcast-episode-17-exposed-smart-metering-and-energy-security-compliance/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://eiqviews.files.wordpress.com/2009/07/smart-meter.jpg" medium="image">
			<media:title type="html">&#34;2009-06-29 Smart Meter 2&#34; originally uploaded by juverna</media:title>
		</media:content>

		<media:content url="http://www.podomatic.com/images/share/player_logo.jpg" medium="image" />
	</item>
		<item>
		<title>Going Beyond Traditional SIEM</title>
		<link>http://blog.eiqnetworks.com/2009/03/18/going-beyond-traditional-siem/</link>
		<comments>http://blog.eiqnetworks.com/2009/03/18/going-beyond-traditional-siem/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 18:17:08 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Mark Nicolett]]></category>
		<category><![CDATA[SIEM]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=128</guid>
		<description><![CDATA[We recently recorded an audio program with Gartner&#8217;s Marc Nicolett to discuss issues related to security and compliance based on what he is seeing out there in the market. To listen, you&#8217;ll need to register on the eIQ website. Here is the description: Join this exclusive eIQnetworks podcast to hear Gartner’s VP and Distinguished Analyst [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=128&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="margin:10px;" src="http://www.gartnerinfo.com/images/GartnerLogo.jpg" alt="" width="139" height="36" />We recently recorded an audio program with Gartner&#8217;s Marc Nicolett to discuss issues related to security and compliance based on what he is seeing out there in the market. To listen, you&#8217;ll need to register on the <a href="http://www.eiqnetworks.com/news/Gartner_Podcast.shtml" target="_blank">eIQ website</a>.</p>
<p>Here is the description:</p>
<blockquote><p>Join this exclusive eIQnetworks podcast to hear Gartner’s VP and      <img class="alignright" style="margin:10px;" src="http://na2.www.gartner.com/images/author/8740.jpg;pv0a50e3bf07ffaba6" alt="" width="80" height="100" />Distinguished Analyst Mark Nicolett and Mike Rothman, eIQnetworks Senior      Vice President of Strategy, discuss the important ways that SIEM can solve      enterprise problems today. Mark Nicolett delves into why organizations      should consider a holistic approach to security and compliance management to      more effectively monitor for potential attacks, anomalies and trends, and      how this data helps enterprises enforce compliance mandates spanning laws,      regulations, best practices, and internal requirements. Mike Rothman then      presents trends he is seeing in the market, which underscore why security      and compliance management must transcend traditional SIEM data to include      broader visibility into enterprise IT.</p></blockquote>
<p>Follow this link to check it out: <a href="http://www.eiqnetworks.com/news/Gartner_Podcast.shtml">http://www.eiqnetworks.com/news/Gartner_Podcast.shtml</a></p>
<br />Posted in Announcements Tagged: Compliance, Gartner, Mark Nicolett, SIEM <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/128/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=128&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/03/18/going-beyond-traditional-siem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://www.gartnerinfo.com/images/GartnerLogo.jpg" medium="image" />

		<media:content url="http://na2.www.gartner.com/images/author/8740.jpg;pv0a50e3bf07ffaba6" medium="image" />
	</item>
		<item>
		<title>eIQcast Episode 4: Drilldown on COBIT</title>
		<link>http://blog.eiqnetworks.com/2009/01/13/eiqcast-episode-4-drilldown-on-cobit/</link>
		<comments>http://blog.eiqnetworks.com/2009/01/13/eiqcast-episode-4-drilldown-on-cobit/#comments</comments>
		<pubDate>Tue, 13 Jan 2009 16:44:32 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[eIQcast]]></category>
		<category><![CDATA[COBIT]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[COSO]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=57</guid>
		<description><![CDATA[In this episode, John Linkous and Mike Rothman drill deep into the COSO/COBIT framework. Why do you care? Well a good part of the acceptable practices of little regulations like Sarbanes-Oxley and FISMA are directly related to COBIT. Thus, if you have to worry about those regulations, you should be familiar with COBIT. Check it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=57&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>In this episode, John Linkous and Mike Rothman drill deep into the COSO/COBIT framework. Why do you care? Well a good part of the acceptable practices of little regulations like Sarbanes-Oxley and FISMA are directly related to COBIT. Thus, if you have to worry about those regulations, you should be familiar with COBIT. Check it out.</p>
<p>Running time: 11:42</p>
<div style="margin-bottom:-5px;"></div>
<div><a href="http://eiqcast.podOmatic.com" target="eiqcast"><img src="http://www.podomatic.com/images/share/player_logo.jpg" border="0" alt="" /></a></div>
<p><a href="http://www.gigyamailbutton.com/wildfire/gigyamailbutton.ashx?url=aHR*cDovL3d3dy5naWd5YS5jb2*vd2lsZGZpcmUvd2Zwb3AuYXNweD9tb2R1bGU9ZW1haWwmdXJsPWh*dHAlM*ElMkYlMkZ3d3clMkVwb2RvbWF*aWMlMkVjb2*lMkZwb2RjYXN*JTJGZW1iZWQlMkZlaXFjYXN*" target="_blank"><img src="http://cdn.gigya.com/wildfire/i/includeShareButton.gif" border="0" alt="" width="60" height="20" /></a><img style="visibility:hidden;width:0;height:0;" src="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyMzE4NjQ5Mjg3ODcmcHQ9MTIzMTg2NDkzNDg3MCZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4.gif" border="0" alt="" width="0" height="0" /></p>
<p>Direct Link: <a href="http://eiqcast.podOmatic.com/entry/2009-01-13T08_32_55-08_00" target="_blank">http://eiqcast.podOmatic.com/entry/2009-01-13T08_32_55-08_00</a></p>
<p>Photo: &#8220;<em>Gold star for me</em>&#8221; originally uploaded by <a href="http://www.flickr.com/photos/bering/2458346701/" target="_blank">Bering</a></p>
<br />Posted in eIQcast Tagged: COBIT, Compliance, COSO, SOX <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/57/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=57&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/01/13/eiqcast-episode-4-drilldown-on-cobit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://www.podomatic.com/images/share/player_logo.jpg" medium="image" />

		<media:content url="http://cdn.gigya.com/wildfire/i/includeShareButton.gif" medium="image" />

		<media:content url="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyMzE4NjQ5Mjg3ODcmcHQ9MTIzMTg2NDkzNDg3MCZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4.gif" medium="image" />
	</item>
		<item>
		<title>Goldman&#8217;s IT Survey says&#8230; Save Money!</title>
		<link>http://blog.eiqnetworks.com/2009/01/12/goldmans-it-survey-says-save-money/</link>
		<comments>http://blog.eiqnetworks.com/2009/01/12/goldmans-it-survey-says-save-money/#comments</comments>
		<pubDate>Mon, 12 Jan 2009 23:03:09 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[User Issues]]></category>
		<category><![CDATA[budgets]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[operating expenses]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=54</guid>
		<description><![CDATA[Interesting data out of Goldman Sachs today. Exhibit 26: In terms of ROI benefits, which types of initiatives will your organization fund in 2009? Projects that will reduce operating expenses including personnel costs 72% Projects that will drive top line revenue growth 59% Projects that will meet compliance obligations 46% Projects that will reduce future [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=54&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Interesting data out of Goldman Sachs today.</p>
<blockquote><p><em>Exhibit 26: In terms of ROI benefits, which types of initiatives will your organization fund in 2009?</em></p>
<p><strong>Projects that will reduce operating expenses including personnel costs 72%</strong><br />
Projects that will drive top line revenue growth 59%<br />
Projects that will meet compliance obligations 46%<br />
Projects that will reduce future capital expenditures 33%<br />
Source: Goldman Sachs IT Spending Survey.</p></blockquote>
<p>So what does that mean? It means that it&#8217;s all about cost containment and that means it&#8217;s all about efficiency. Of course, the only way to gain IT-based efficiency is to automate your security and/or compliance activities (probably both).</p>
<p>That&#8217;s why a lot of folks (including eIQ) are going to be pretty focused on the ideas of security and compliance automation this year. That&#8217;s going to be one of the only ways to get projects funded.</p>
<p>So over the next week, I&#8217;ll be doing a series on cost containment here at eIQviews. We&#8217;ll focus on areas that are applicable for automation, as well as strategies for communicating these imperatives to senior management (that will eventually need to foot the bill) for any new tools for automation.</p>
<br />Posted in User Issues Tagged: budgets, Compliance, operating expenses <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/54/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=54&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/01/12/goldmans-it-survey-says-save-money/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>
	</item>
		<item>
		<title>The Great Thing About Standards&#8230;</title>
		<link>http://blog.eiqnetworks.com/2008/10/22/the-great-thing-about-standards/</link>
		<comments>http://blog.eiqnetworks.com/2008/10/22/the-great-thing-about-standards/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 12:28:24 +0000</pubDate>
		<dc:creator>jlinkous</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[frameworks]]></category>

		<guid isPermaLink="false">http://eiqviews.wordpress.com/?p=20</guid>
		<description><![CDATA[“…is that there are so many of them to choose from”, or at least so goes the old saying. Information security is no exception; the byzantine tangle of best practices, standards, frameworks, and various governmental and industry mandates that are either dedicated to information security or contain security-related requirements shows no sign of abatement or [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=20&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin:0 0 10pt;"><span style="font-size:10pt;line-height:115%;"><span style="font-family:Calibri;">“…is that there are so many of them to choose from”, or at least so goes the old saying.<span> </span>Information security is no exception; the byzantine tangle of best practices, standards, frameworks, and various governmental and industry mandates that are either dedicated to information security or contain security-related requirements shows no sign of abatement or unification anytime soon.<span> </span>Of course, if you’re a person who’s responsible for implementing all that stuff in your environment, you’re probably feeling some pain.<span> </span>Establishing common controls to meet compliance is a well-tested approach to meeting compliance, but where to begin?</span></span></p>
<p class="MsoNormal" style="margin:0 0 10pt;"><span style="font-size:10pt;line-height:115%;"><span style="font-family:Calibri;">Fortunately, some standards and frameworks for managing security are really starting to mature, to the point where they can become a starting point for building risk-driven common controls that easily map to regulations and other compliance drivers.<span> </span>Most of these frameworks and standards have been around for a number of years but through a combination of broad adoption, continuous feedback from adopters, and a mature management and improvement process, they are rapidly becoming a great starting point for building comprehensive information security.<span> </span>Here are three that I believe are well-balanced (addressing both technical and logical controls), risk-based (where the implementation of some or all controls is based on an analysis of risk to systems and data), and can be implemented across any industry:</span></span></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;margin:0 0 0 .5in;"><span style="font-size:10pt;line-height:115%;font-family:Symbol;"><span>·<span style="font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-family:&quot;"> </span></span></span><span style="font-family:Calibri;"><strong><span style="font-size:10pt;line-height:115%;">PCI Security Council (PCI) Data Security Standard (DSS) 2.0</span></strong><span style="font-size:10pt;line-height:115%;"> – Recently released, the 2.0 version of the PCI-DSS standard focuses on a solid combination of static, pre-defined technical controls (e.g., minimum password lengths and complexity requirements), risk-based technical controls (e.g., business continuity infrastructure), and logical controls (e.g., written policies and procedures, and separation of duty).<span> </span>Although designed specifically for securing chain of custody around credit card data, PCI-DSS is rapidly becoming a standard of controls that organizations are applying to different types of data.<br />
</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;margin:0 0 0 .5in;"><span style="font-size:10pt;line-height:115%;font-family:Symbol;"><span>·<span style="font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-family:&quot;"> </span></span></span><span style="font-family:Calibri;"><strong><span style="font-size:10pt;line-height:115%;">ISACA Control Objectives for Information Technology (COBIT) 4.1</span></strong><span style="font-size:10pt;line-height:115%;"> – The COBIT framework has long been a framework for managing information security.<span> </span>With a focus on processes – not just technology – COBIT has become the standard high-level framework used by global auditing firms to audit against compliance with SOX Sections 302/404, J-SOX, and other major financial regulations that address financial controls.<span> </span>Like other frameworks, COBIT is relatively light on technical controls (although there are some specific technical controls defined for applications, such as event auditing and monitoring); instead, the goal of COBIT is to provide a framework for using risk-based decisions to build and maintain a complete IT management program.<br />
</span></span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent:-.25in;margin:0 0 10pt .5in;"><span style="font-size:10pt;line-height:115%;font-family:Symbol;"><span>·<span style="font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-family:&quot;"> </span></span></span><span style="font-family:Calibri;"><strong><span style="font-size:10pt;line-height:115%;">International Standards Organization (IS) 27002:2005</span></strong><span style="font-size:10pt;line-height:115%;"> – One of many IT-related best practice documents issued by ISO, ISO27002 (formerly known as ISO17799) is geared toward helping an organization establish risk-based decisions to build and maintain a security program.<span> </span>Unlike COBIT, which is focused on general IT controls, ISO27002 focuses very squarely on information security.<span> </span>Being part of the ISO family, ISO27002 is augmented with additional ISO-delivered guidance to help certain verticals – healthcare and financial services, for example – implement specific controls that are not only ISO27002 compatible, but compatible with other industry-specific laws and guidance.</span></span></p>
<br />Posted in Compliance Tagged: best practices, Compliance, controls, frameworks <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=20&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2008/10/22/the-great-thing-about-standards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
	</channel>
</rss>