Find White Papers
Home
About Us
List Your Papers
    
> CA. > The Six Steps to Compliance: Gaining Control of Your Agency’s Response to Regulations, Legislation

The Six Steps to Compliance: Gaining Control of Your Agency’s Response to Regulations, Legislation

White Paper Published By: CA.

CA Clarity PPM Helps Conform to Multiple Mandates with One Solution. CA can help streamline your response to multiple mandates. Learn more about compliance strategies and solutions by requesting CA's Federal Compliance ROI The Six Steps to Compliance White Paper.



Tags : 
enterprise applications, best practices, corporate governance

CA.
Published:  Feb 06, 2009
Type:  White Paper
Length:  7 pages

White Paper
Compliance = ROI
The Six Steps to Compliance. Gaining Control of Your Agency's Response to Regulations, Legislation and Mandates.If good governance is the primary aim of the regulations What is Compliance? your agency must address, then compliance consists of:Compliance is the management function that makes sure your agency is adhering to all applicable rules 1. Defining and establishing governance in practiceand guidance that may apply as you conduct your 2. Identifying and addressing threats to governancemission and operations. In practice, this means 3. Tracking and reporting your governance effortsnavigating a complicated web of intersecting laws, Governance is both a practical and required priority for regulations and procedures (see chart below). your agency. But without careful planning and effective As complex as they may be, all of your compliance system support, compliance becomes an overwhelming challenges have one thing in common. They are burden that can compromise your agency's real mission.intended to establish governance over the way your CA can help you address the complex demands of agency uses the resources entrusted to it. compliance by:Governance is the establishment of rigorous controls . Optimizing operationsamong people, processes and technology, so that all . Enhancing performanceoperations are guided by strict policies and standards . Reducing costsfor efficient practices. . Automating tracking and reportingOMB Circular A-123, for example, calls for implementing This white paper outlines the key concepts of compliance operational and internal financial controls, as well for and shows you how to maximize ROI from your IT assessing and mitigating risks to those controls. investments and enable your agency's mission.
neThe Compliance Challenge: h t 8o c 0tC 5A c 2 t - 1A nyThese are just some of the interlocking requirements rc -t A oceA A v iAA DcI I A tag oMFR PAA v cfederal agencies must meet. SO n iM Gi SP SF R l r e-F M IAGG F F C I P C F P F E H S OMB: Circular A-11. Providing business cases/funding justi?cation for capital and IT investments ? ? ? ? ? ? ? ? ? ? ?. Filing Exhibits 300 and 53OMB: Circular A-130 . Implementing capital planning processes and controls ? ? ? ? ?. Providing information via dissemination systems. Safeguarding information against riskOMB: Circular A-123. Implementing ?nancial and internal operational controls ? ? ? ? ?. Maintain rigorous ?nancial reporting. Assess and mitigate risks to controlsOMB: Appendix III to Circular No. A-130 (Primary FISMA implementation). Implementing agency-wide security programs ? ? ?. Documenting security and certifying it is adequate to risksNIST: FIPS Pub 201, PIV I and PIV II (Primary HSPD-12 implementation) ? ?. Implementing personnel identi?cation and veri?cation programs
GPRA Government Performance and Results Act of 1993: Requires agencies to develop strategic plans, set performance goals, and report annually on actual performance compared to goals.FFMIA Federal Financial Management Improvement Act of 1996: Requires agencies to have ?nancial management systems that substantially comply with the federal ?nancial management systems requirements, standards promulgated by the Federal Accounting Standards Board (FASAB), and the U.S. Standard General Ledger (USSGL) at the transaction level.FMFIA Federal Managers Financial Integrity Act of 1982: Requires agencies to establish and maintain internal control. The agency head must annually evaluate and report on the control and ?nancial systems that protect the integrity of federal programs. CFO Act Chief Financial Of?cers Act: Requires agencies to both establish and assess internal controls related to ?nancial reporting. Requires the preparation and audit of statements.IG Act Inspector General Act of 1978: Provides for independent reviews of agency programs and operations. IGs are required to submit semi-annual reports to Congress on signi?cant abuses and de?ciencies identi?ed during reviews and recommended actions to correct those de?ciencies.PRA Paperwork Reduction Act of 1995: Requires that agencies perform their information resource management activities in an ef?cient, effective, and economical manner.Clinger- The Clinger-Cohen Act of 1996 (Also known as the Information Technology Reform Act of 1996): Requires agencies to use a disciplined capital planning and investment control (CPIC) process ... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search