Special Reports - CIOInsight
Home arrow Special Reports arrow Page 2 - 5 Smart Practices for IT Risk,
Governance and Compliance
RECENT NEWS



CIO STRATEGY
The Perfect IT Book for the Business?

Parkinson needs a book that explains IT to the business. Got any suggestions?    

  Special Reports


5 Smart Practices for IT Risk,
Governance and Compliance



By Doug Bartholomew


  Table of Contents:
  1. 5 Smart Practices for IT Risk,
    Governance and Compliance
  2. ' Develop understanding of how '
  3. ' Use technology to enforce '
  4. ' Define requirements versus best '
  5. ' Work in tandem with '
  6. ' Leverage industry standards such '

After interviewing CIOs and other experts, we offer five smart practices for IT governance, risk and compliance.

Rate This Article:
Add This Article To:

5 Smart Practices for IT Risk,
Governance and Compliance - ' Develop understanding of how '


( Page 2 of 6 )

IT influences risk and compliance.">

1. Develop a comprehensive, corporatewide understanding of how technology inf luences risk and compliance.

"It's important to first incorporate risk into the overall framework and lexicon of how you manage the organization," says Jeffrey Weber, managing director of Protiviti's technology risk practice. Adds Joe Atkinson, a partner at PriceWaterhouseCoopers, "When it comes to compliance obligations, all well managed companies want to comply, but the challenge is that you don't have unlimited resources to do so. That's where having an enterprise vision is very important. It helps the company start to rationalize the allocation of resources."

Most experts agree that in this early stage of scoping out the extent of a company's risk and the processes and systems needed to ensure compliance with laws and regulations, IT must be involved from the get-go. "Regardless of the model you apply, IT must be at the table," Atkinson says. "The only way to be effective at this is with the appropriate application of IT."

Robert Worrall, senior vice president and CIO at Sun Microsystems, recommends the first thing any CIO do is "get the organization aligned around compliance. Most IT people do not recognize the need for compliance, so training is needed," he says.

From an organizational standpoint, Worrall has found it helpful for the CIO, especially in a large corporation, to delegate someone with both IT and compliance experience to focus on training. At Sun, he has assigned a senior director of compliance for IT, who is a former internal auditor of IT systems. "He understands how an auditor looks at things and he can respond in a language auditors understand," Worrall says.

Next page: 2. Use technology to enforce and monitor compliance rules and processes.



 
 
>>> More Special Reports Articles          >>> More By Doug Bartholomew
 


FEATURED SPONSORED VIDEOS

FEATURED SPONSORED ARTICLES

Erasable E-Paper Saves Trees, Cuts Costs

Why Smart Companies Should Adopt the Lessons of Gaming

Interest in Mobile WiFi Hotspots Fuels New Solutions

A Closer Look at Public Cloud Security

View More Articles

  Brought to You By
Click Here




EDITORS' PICKS

LATEST STORIES


Advertisement
FEEDBACK
Ziff Davis Enterprise RSS Feeds

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 77% of the Fortune 500 Manage Content Securely with Box.
  • Leverage your virtual computing environment with Dell.
  • Build an IT Infrastructure That Delivers the Future
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • eWEEK Quick LInks