Find White Papers
Home
About Us
List Your Papers
    
> Splunk Inc. > Demystifying Compliance

Demystifying Compliance

White Paper Published By: Splunk Inc.

Compliance is high on the IT agenda today, yet no one seems to have a clear picture of what it really involves. Inconsistent interpretation by different auditors, regulators and vendors means what worked in one year's audit could fail in the next. This whitepaper is designed to help Demystify Compliance as it relates to IT and give you some simple recipes for analyzing your own environment in the light of specific mandates.



Tags : 
compliance, splunk, it agenda, it security, regulations, proof-of-compliance, pci, hipaa

Splunk Inc.
Published:  Jun 02, 2009
Type:  White Paper
Length:  5 pages

Demystifying Compliance
Compliance is high on the IT agenda. What does it involve?
Compliance on the IT Agenda Myth #2: Compliance is an IT security issue.
Compliance is high on the IT agenda today, yet no one seems to The reality: Sure, a lot of compliance mandates have a security have a clear picture of what it really involves. Inconsistent dimension because they are trying to control the risk of things like interpretation by different auditors and regulators means what information leakage and sabotage. But just as many mandates are worked in one year's audit could fail in the next. Escalating concerned with the integrity and availability of mission-critical enforcement and penalties and a higher standard for "duty of care" applications, and so preventing, detecting and responding to have organizations scrambling for answers and solutions. ordinary failures matters just as much. And beyond that, there are a lot of mandates that govern business issues such as use of insider Vendors of everything from access control to email are claiming information, which are really outside the realm of IT although IT they address compliance requirements But most companies have a systems play a role in recording the evidence.limited notion of exactly how IT systems relate to compliance. Glib claims of "compliance packages" that are supposed to be total Myth #3: I have to store my original logs for 7 years.solutions for one or another regulation sell the idea that all you The reality: Where does it say that? Almost no mandates, and have to do is plug them in and you'll be compliant. certainly not the most common ones concerning IT departments, Companies or organizations who bought these packages are often specify log retention times. Log retention times are driven by finding out their auditors are still not happy. Even with a variety of assessments of what it will take to service other requirements such solutions in place, IT remains in reactive mode, shouldering the cost as the need to investigate incidents, detect long term patterns, and of responding to multiple requests for new reports, access to new prosecute intruders. You may want to keep 7 years available, but you data sources, and specific investigations. may choose different strategies for more recent vs archived data.
IT is also finding that the need to lock down access to data sources Myth #4: A speci!c set of reports will make me compliant.and systems is the hidden enemy of meeting auditor's demands The reality: See Myth #1. The regulations almost never list a specific and can have a serious impact on the ability to respond to real IT report. There are reports that can clearly assist with particular incidents, problems and failures. requirements, such as the need to review failed logins, but they We're not going to tell you that just plugging a product in and require a lot of fine-tuning for each unique environment. At best, a turning on a few canned reports will make you compliant. Instead, set of standard reports is a starting place. The dirty secret: most we'd like to demystify compliance as it relates to IT and give you compliance report packs are developed by product managers some simple recipes for analyzing your own environment in the reading the regulations and taking a guess at what kinds of reports light of specific mandates. might be helpful.
In the end, your best compliance solution in the face of an audit or Myth #5: I need to buy a commercial solution to be compliant.negligence lawsuit is to demonstrate an understanding of the sprit The reality: Your decision to buy a log management system rather of the mandates that apply to your organization. than roll your own logging infrastructure should be based on ROI. A We'll start by smashing some of the myths about compliance. well designed system should save you on initial development and integration as well as make ongoing log reporting, ad-hoc analysis Top Five Compliance Myths and alerting more efficient. But the regulations don't say you have to buy a commercial system, and the vendors of these systems don't Myth #1: Compliance equals regulations with speci!c actions have any special insight into what it takes to make you compliant. The reality: Most regulations have fuzzy or no detail about IT So if these are myths, what's the truth?implementation. And many compliance demands arise from internal assessments of risk of business disruption or lit... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search