<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>The Compliance and Security Connection</title>
    
    
    <link rel="alternate" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/" />
    <id>tag:typepad.com,2003:weblog-1324582</id>
    <updated>2008-11-20T05:00:00-08:00</updated>
    <subtitle>A look at the complexities of securing privileged information in today's evolving IT environment and the impact growing compliance mandates have on daily IT operations.</subtitle>
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/typepad/ecorablog/the_compliance_and_securi" /><feedburner:info uri="typepad/ecorablog/the_compliance_and_securi" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
        <title>BS 25999- The Standard and Its Value Proposition</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/ZRLmbIicmKA/bs-25999--the-standard-and-its-value-proposition.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/11/bs-25999--the-standard-and-its-value-proposition.html" thr:count="2" thr:updated="2010-03-16T18:59:34-07:00" />
        <id>tag:typepad.com,2003:post-58746530</id>
        <published>2008-11-20T05:00:00-08:00</published>
        <updated>2008-11-20T05:00:00-08:00</updated>
        <summary>BS 25999 became a formal business continuity standard in November 2007. Since then, a very large number of organizations from all around the world in both the public and private sector began evaluating the standard, as well as the value...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Continuity" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Avalution Consulting" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Brian Zawada" />
        <category scheme="http://sixapart.com/ns/types#tag" term="BS 25999" />
        <category scheme="http://sixapart.com/ns/types#tag" term="BS 25999 certification" />
        <category scheme="http://sixapart.com/ns/types#tag" term="BS 25999 compliance" />
        <category scheme="http://sixapart.com/ns/types#tag" term="business continuity" />
        <category scheme="http://sixapart.com/ns/types#tag" term="business continuity program" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration audit reporting" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Auditor Pro" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Software" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Michael Godin" />
        <category scheme="http://sixapart.com/ns/types#tag" term="system configurations" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>BS 25999 became a formal business continuity standard in November 2007. Since then, a very large number of organizations from all around the world in both the public and private sector began evaluating the standard, as well as the value associated with the certification process. </p>
<p>Recently, Brian Zawada, CEO of Avalution Consulting, joined me for a web presentation introducing BS 25999, outlining why it's different from other standards and regulatory requirements, and addressing what an organization needs to do in order to be compliant with its requirements. The presentation also offered some recent observations on how BS 25999 compliance can improve business continuity program performance - even if the organization never pursues certification. </p>
<p>Joining Mr. Zawada was Michael Godin, Senior Systems Engineer with Ecora Software. Michael shared how an automated configuration audit and compliance reporting solution like Ecora Auditor Pro can automate important enterprise configuration audit reporting that will not only aid in your BS 25999 certification process, but will also ensure those standards continue to be sustained. </p>
<p>I'm pleased to let you know that a Flash recording of this presentation is available now. By simply <a href="http://www.ecora.com/ecora/webinars/ondemand.asp/bs25999/" title="Introducing BS 25999 webinar">registering here</a>, you will be able to download the recording of Brian and Michael's presentation and be able to download a PDF of the Powerpoint slides they used.</p>
<p>What you will learn by downloading and watching this Webinar:</p>
<ul>
<li>An introduction to BS 25999 
<li>Why BS 25999 is different from other standards and regulations 
<li>What a company needs to do to become compliant with BS 25999 
<li>How BS 25999 compliance can improve your business continuity program 
<li>The importance of automating the discovery and reporting of enterprise configuration attributes for establishing a business continuity program 
<li>Establishing policies and rules to measure against current system configurations to ensure BS 25999 standards are maintained </li>
</li></li></li></li></li></ul>
<p><em>Contributed by Mark Tordoff</em></p></div>
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/11/bs-25999--the-standard-and-its-value-proposition.html</feedburner:origLink></entry>
    <entry>
        <title>Leveraging ISO 27001 for Improving the Security, Compliance and Performance of Information Systems</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/NPtcQaUu0Fs/leveraging-iso-27001-for-improving-the-security-compliance-and-performance-of-information-systems.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/11/leveraging-iso-27001-for-improving-the-security-compliance-and-performance-of-information-systems.html" thr:count="2" thr:updated="2010-03-16T19:02:09-07:00" />
        <id>tag:typepad.com,2003:post-58603738</id>
        <published>2008-11-17T05:37:10-08:00</published>
        <updated>2008-11-17T05:37:10-08:00</updated>
        <summary>Steve Wright, Senior Manager for Risk &amp; Advisory Services at PriceWaterhouseCoopers LLP, has worked with many international organizations to complete ISO27001 Certification projects over the past eight years and has worked with many of these same corporations to establish information...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IT Governance, Risk, and Compliance" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Auditor Professional 4.5" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CMMI" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CobiT" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration audit and analytics" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Software" />
        <category scheme="http://sixapart.com/ns/types#tag" term="HIPAA" />
        <category scheme="http://sixapart.com/ns/types#tag" term="information security management systems" />
        <category scheme="http://sixapart.com/ns/types#tag" term="ISO 27001" />
        <category scheme="http://sixapart.com/ns/types#tag" term="ISO9001" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT compliance reporting" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="ITIL" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff " />
        <category scheme="http://sixapart.com/ns/types#tag" term="Michael Godin" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI DSS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PriceWaterhouseCoopers" />
        <category scheme="http://sixapart.com/ns/types#tag" term="SOX" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Steve Wright" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>Steve Wright, Senior Manager for Risk &amp; Advisory Services at PriceWaterhouseCoopers LLP, has worked with many international organizations to complete ISO27001 Certification projects over the past eight years and has worked with many of these same corporations to establish information security management systems (ISMS) compliant with Corporate Governance requirements such as - Combined Code, HIPAA, SOX, CobiT, ITIL, PCI DSS, ISO9001 and CMMI. </p>
<p>Recently, Steve joined me to share his conclusions on best practices for "future-proofing" ISO27001 implementations and maximizing ROI. Steve demonstrated how leading organizations are embracing the best practices to achieve regulatory compliance and create a Management System for Internal Control. Steve also covered how to leverage an ISMS for security, risk, compliance and operational benefit. </p>
<p>Joining Steve was Michael Godin, Senior Systems Engineer with Ecora Software. Michael shared how Ecora's Auditor Professional 4.5 can help to establish a comprehensive understanding of your infrastructure's configuration, how to create policies and rules based on ISO27001 to determine the gaps in your present configuration, and how to effectively identify and remediate gaps that may develop to ensure compliance with your standards is sustained.</p>
<p>I'm pleased to let you know that a Flash recording of this presentation is available now. By simply <a href="http://www.ecora.com/ecora/webinars/ondemand.asp/siemens0811/" target="_blank" title="Register and download the ISO 27001 Ecora webinar">registering here</a>, you will be able to download the recording of Steve and Michael's presentation and be able to download a PDF of the Powerpoint slides they used. </p>
<p>What you'll learn by downloading and watching this Webinar: </p>
<ul>
<li>How ISO 27001 ISMS is being used today 
<li>What some of the challenges of implementing an ISMS are and how are they overcome 
<li>How to make an ISMS the platform for the future and maximize your ROI 
<li>Identifying cases outside of traditional security and how to choose a platform that will support them 
<li>How an automated configuration audit and analytics solution can make ISO 27001 more successful </li>
</li></li></li></li></ul>
<p><span style="FONT-SIZE: 12px; FONT-FAMILY: Trebuchet MS"><em>Contributed by Mark Tordoff</em></span></p></div>
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/11/leveraging-iso-27001-for-improving-the-security-compliance-and-performance-of-information-systems.html</feedburner:origLink></entry>
    <entry>
        <title>An Update on the Ecora Blog</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/ef0gDppRMCQ/an-update-on-th.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/10/an-update-on-th.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-57305821</id>
        <published>2008-10-20T13:19:58-07:00</published>
        <updated>2008-10-20T13:19:58-07:00</updated>
        <summary>I just wanted to write a brief note to let everyone know that I will be unable to make new posts to the Ecora Software blog for a while due to some new surgery that I will be having this...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IT News" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Software" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>I just wanted to write a brief note to let everyone know that I will be unable to make new posts to the Ecora Software blog for a while due to some new surgery that I will be having this Wednesday that will have me sidelined for quite some time.</p>

<p>I am looking forward to regaining my full health and being able to return and share new thoughts and even new topics with you soon.</p>

<p>Thanks to each of you for taking the time to read my thoughts and especially to so many of you who have taken the time to post comments over the past few years.</p>

<p>Best regards,</p>

<p>Mark</p></div>
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/10/an-update-on-th.html</feedburner:origLink></entry>
    <entry>
        <title>Introduction to Effective Records and Data Management Programs</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/XTqly2tWxzc/introduction-to.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/09/introduction-to.html" thr:count="5" thr:updated="2010-01-28T13:29:16-08:00" />
        <id>tag:typepad.com,2003:post-55402428</id>
        <published>2008-09-10T02:22:56-07:00</published>
        <updated>2008-09-10T02:22:56-07:00</updated>
        <summary>Today at 1pm Eastern, I will be participating in a webinar featuring Rebecca Bates Manno, Ken Tuggle, Bob Webb, and Bob Dibert, who are attorneys with the Louisville, Kentucky office of Frost Brown Todd LLC; and Michael Godin, a Senior...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Data Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Bob Dibert" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Bob Webb" />
        <category scheme="http://sixapart.com/ns/types#tag" term="change management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="criminal conduct sanctions" />
        <category scheme="http://sixapart.com/ns/types#tag" term="data management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Auditor Professional 4.5" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Software" />
        <category scheme="http://sixapart.com/ns/types#tag" term="eDiscovery" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Frost Brown Todd LLC" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ken Tuggle" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Michael Godin" />
        <category scheme="http://sixapart.com/ns/types#tag" term="obstruction of justice statutes" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rebecca Bates Manno" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Records and Data Management Programs" />
        <category scheme="http://sixapart.com/ns/types#tag" term="records retention" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>Today at 1pm Eastern, I will be participating in a webinar featuring Rebecca Bates Manno, Ken Tuggle, Bob Webb, and Bob Dibert, who are attorneys with the Louisville, Kentucky office of Frost Brown Todd LLC; and Michael Godin, a Senior Systems Engineer with Ecora Software.</p>

<p>In this presentation, our presenters from Frost Brown Todd will teach you how to avoid the devastating problems that your company may face if it does not implement and maintain an effective records retention and data management program. Specifically, you will learn how to develop an effective records retention and data management program for your company; how to staff your record and data management team; how to avoid obstructing justice in the course of destroying documents and data; and the benefits of having a records retention program in place when (not if) your company becomes involved in an audit, investigation or lawsuit.</p>

<p>Michael will follow our attorney-presenters to share how Ecora's Auditor Professional 4.5 can provide comprehensive reporting of how the infrastructure protecting your data is configured, particularly how to create policies and rules validating system configurations around critical data continue to be sustained, and how to identify changes in your system configuration that could make you vulnerable to an internal or external data breach.</p>

<p>You can register for this session by <a href="http://www.ecora.com/ecora/webinars/webinar.asp/2008-09-10/">registering here</a>.</p>

<p>This session covers:</p>

<ul><li>What is a Records and Data Management Program (RDMP)?</li>

<li>Developing an effective RDMP</li>

<li>Implementing the RDMP</li>

<li>Reconciling Record Retention Policies with Obstruction of Justice statutes</li>

<li>The emergency of eDiscovery Law</li>

<li>Avoiding Criminal Conduct Sanctions</li>

<li>Prevention vs. Cure: Understanding the infrastructure surrounding your data</li></ul>

<p>I hope you are able to join us for this important, free presentation.</p>

<p><em><span style="font-size: 0.6em;">Contributed by Mark Tordoff</span></em></p></div>
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/09/introduction-to.html</feedburner:origLink></entry>
    <entry>
        <title>ITIL version 3: One Year Later</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/QuReeocwP8Q/itil-version-3.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/09/itil-version-3.html" thr:count="2" thr:updated="2010-01-28T13:29:45-08:00" />
        <id>tag:typepad.com,2003:post-55363650</id>
        <published>2008-09-09T07:56:05-07:00</published>
        <updated>2008-09-09T07:56:05-07:00</updated>
        <summary>It's been a little over a year since the introduction of version 3 of the IT Infrastructure Library (ITIL). Gary Anthes did a great job documenting "How to Get More Out of ITIL with Version 3" in the July 21st...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IT Governance, Risk, and Compliance" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Alan Claypool" />
        <category scheme="http://sixapart.com/ns/types#tag" term="AutoNation Inc." />
        <category scheme="http://sixapart.com/ns/types#tag" term="change management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="City of Tampa" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Computerworld" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Dale Ott" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Auditor Pro" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Florida" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Gary Anthes" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT Infrastructure Library" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT Service Management Forum International" />
        <category scheme="http://sixapart.com/ns/types#tag" term="ITIL" />
        <category scheme="http://sixapart.com/ns/types#tag" term="itSMF UK" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Megan Pendlebury" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Phyllis Drucker" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Pink Elephant" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Progress Energy Inc." />
        <category scheme="http://sixapart.com/ns/types#tag" term="Sarasota County Government and Schools" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Sheri Cassidy" />
        <category scheme="http://sixapart.com/ns/types#tag" term="U.K. Office of Government Commerce" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;It's been a little over a year since the introduction of version 3 of the IT Infrastructure Library (ITIL). Gary Anthes did a great job documenting &lt;a href="https://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=321499&amp;amp;pageNumber=2"&gt;&amp;quot;How to Get More Out of ITIL with Version 3&amp;quot; in the July 21st edition of Computerworld&lt;/a&gt;. In today's post, I'd like to share some of the points Gary made that stood out to me.&lt;/p&gt;

&lt;p&gt;Before we do that, let's touch on the basic difference between version 2 and 3. Megan Pendlebury, the Service Management Executive with itSMF UK, does a good job of &lt;a href="http://www.nccmembership.co.uk/pooled/articles/BF_WEBART/view.asp?Q=BF_WEBART_305505"&gt;sharing her impressions&lt;/a&gt; of what's different.&lt;/p&gt;&lt;blockquote dir="ltr"&gt;&lt;p&gt;&amp;quot;V2 took a very process driven view and led to people working within their own silo rather than seeing the entire picture of what was being done within IT and the business they were underpinning. V3 in contrast takes a 'lifecycle' approach to managing services. It's closer aligned to how businesses are actually run, allowing IT to integrate more closely.&amp;quot;&lt;/p&gt;&lt;/blockquote&gt;&lt;p dir="ltr"&gt;According to Pendlebury, the most common comment she is hearing is &amp;quot;we are still working on V2 and will not be looking at V3 for a while.&amp;quot; Pendlebury responds to this by saying, &amp;quot;the truth of the matter is that if you are implementing V2 you are already implementing V3.&amp;quot; This is reinforced by comments made in Anthes' story by Phyllis Drucker, director of consolidated services at AutoNation Inc. She said, &amp;quot;We'll lay v3 over our processes and see if there are any gaps&amp;quot;, as opposed to scrapping their work on implementing V2.&lt;/p&gt;

&lt;p dir="ltr"&gt;Besides not abandoning V2 efforts, Anthes offers 4 other keys to gaining value from ITIL v. 3.&lt;/p&gt;

&lt;ol dir="ltr"&gt;&lt;li&gt;&lt;div&gt;Do get started on V3. It's worth it.&lt;/div&gt;&lt;/li&gt;

&lt;li&gt;&lt;div&gt;Look at the tools.&lt;/div&gt;&lt;/li&gt;

&lt;li&gt;&lt;div&gt;Prepare for culture shock.&lt;/div&gt;&lt;/li&gt;

&lt;li&gt;&lt;div&gt;Don't expect to find everything in v3 - or like everything you find.&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;

&lt;p&gt;Anthes' article is full of valuable input from a number of IT professionals regarding their impression of V.3. Here are some to consider:&lt;/p&gt;&lt;blockquote dir="ltr"&gt;&lt;p&gt;&amp;quot;What's so nice about v3 is that it really takes you back to the basics of business, and then you design your service to meet those.&amp;quot;&amp;nbsp; Alan Claypool, manager of business applications, city of Tampa, FL&lt;/p&gt;

&lt;p&gt;&amp;quot;We got into ITIL, and by our third year, we realized that our tools were not allowing us to do some of the things we wanted to do. In hindsight, we could have made much faster progress has we had better tools.&amp;quot; Sheri Cassidy, manager of process engineering services, Progress Energy Inc.&lt;/p&gt;

&lt;p&gt;&amp;quot;We've all talked about the loss of service in the U.S.. I think this [ITIL v3] is a way to structurally put it back in place.&amp;quot; Dale Ott, director of service management, Sarasota County Government and Schools, Sarasota, FL&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;If you are looking for more information on ITIL v3, contact the U&lt;a href="http://www.ogc.gov.uk/"&gt;.K. Office of Government Commerce&lt;/a&gt;, organizations like &lt;a href="https://www.pinkelephant.com/en-US/"&gt;Pink Elephant&lt;/a&gt; or user groups like &lt;a href="http://itsmfi.org"&gt;IT Service Management Forum International&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;If you are looking for a tool to help you with infrastructure configuration and change management, consider &lt;a href="http://www.ecora.com/ecora/products/auditor_professional.asp"&gt;requesting a demonstration&lt;/a&gt; of &lt;a href="http://www.ecora.com/ecora/products/auditor_professional.asp"&gt;Ecora Auditor Pro&lt;/a&gt;. It will help you lay a solid foundation for adopting ITIL v3 in your organization's IT infrastructure.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;span style="font-size: 0.6em;"&gt;Contributed by Mark Tordoff&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;/div&gt;
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/09/itil-version-3.html</feedburner:origLink></entry>
    <entry>
        <title>Basics on the Federal Desktop Core Configuration standards</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/TaFUQNtBTe0/basics-on-the-f.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/09/basics-on-the-f.html" thr:count="10" thr:updated="2010-03-11T07:35:22-08:00" />
        <id>tag:typepad.com,2003:post-55323980</id>
        <published>2008-09-08T14:42:58-07:00</published>
        <updated>2008-09-08T14:42:58-07:00</updated>
        <summary>It was the end of March that all federal agencies were supposed to meet the Federal Desktop Core Configuration (FDCC) policy for all Microsoft Windows XP and Vista systems by using the Security Content Automation Protocol, otherwise known as SCAP...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IT Governance, Risk, and Compliance" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="CCE" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Common Configuration Enumeration" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Common Platform Enumeration" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Common Vulnerabilities and Exposures" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Common Vulnerability Scoring System" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CPE" />
        <category scheme="http://sixapart.com/ns/types#tag" term="credit unions" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CVE" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CVSS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Defense Information Systems Agency" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Department of Homeland Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="DHS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="DISA" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Auditor Pro" />
        <category scheme="http://sixapart.com/ns/types#tag" term="eXtensible Configuration Checklist Description For" />
        <category scheme="http://sixapart.com/ns/types#tag" term="FDCC" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Federal Desktop Core Configuration" />
        <category scheme="http://sixapart.com/ns/types#tag" term="healthcare agencies" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Microsoft Windows XP" />
        <category scheme="http://sixapart.com/ns/types#tag" term="National Institute of Standards and Technology" />
        <category scheme="http://sixapart.com/ns/types#tag" term="National Security Agency" />
        <category scheme="http://sixapart.com/ns/types#tag" term="NIST" />
        <category scheme="http://sixapart.com/ns/types#tag" term="NSA" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Open Vulnerability Assessment Language" />
        <category scheme="http://sixapart.com/ns/types#tag" term="OVAL" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Payment Card Industry Data Security Standard" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI-DSS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Processor" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ron Gula" />
        <category scheme="http://sixapart.com/ns/types#tag" term="SCAP" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Security Content Automation Protocol" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Tenable Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="US Air Force" />
        <category scheme="http://sixapart.com/ns/types#tag" term="USAF" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Vista" />
        <category scheme="http://sixapart.com/ns/types#tag" term="XCCDF" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;It was the end of March that all federal agencies were supposed to meet the Federal Desktop Core Configuration (FDCC) policy for all Microsoft Windows XP and Vista systems by using the Security Content Automation Protocol, otherwise known as SCAP (pronounced S-cap).&lt;/p&gt;

&lt;p&gt;Each agency is required to submit their FDCC reports to the National Institute of Standards and Technology (NIST). The FDCC policy came about using an interesting collaboration of numerous agencies working with Microsoft, including NIST, the Department of Homeland Security, the Defense Information Systems Agency, the National Security Agency, and the US Air Force.&lt;/p&gt;

&lt;p&gt;While the title of the policy would lead you to believe it is primarily focused on the respective Microsoft operating systems, the policy actually extends to cover assorted components such as firewalls, antivirus, web browsers, and more.&amp;nbsp; In &lt;a href="http://www.processor.com/editorial/article.asp?article=articles%2Fp3021%2F32p21%2F32p21.asp"&gt;an article appearing in the May 23rd issue of Processor&lt;/a&gt;, Ron Gula, chief executive officer and chief technical officer for &lt;a href="http://www.tenablesecurity.com"&gt;Tenable Security&lt;/a&gt; speaks well of SCAP in comparison to the Payment Card Industry Data Security Standard (PCI-DSS) when he says, &amp;quot;SCAP has very specific settings that are applied to specific operating systems. It's taking the ambiguity out of system configurations.&amp;quot;&lt;/p&gt;

&lt;p&gt;According to the article, written by Sandra Kay Miller, here are some specifics on SCAP:&lt;/p&gt;&lt;blockquote dir="ltr"&gt;&lt;p&gt;&amp;quot;SCAP is a suite of open standards that function together to deliver automated vulnerability management, measurement, and policy compliance evaluation. The XCCDF (eXtensible Configuration Checklist Description Format) and OVAL (Open Vulnerability Assessment Language) are assessment protocols. The reference protocols include the CCE (Common Configuration Enumeration), CPE (Common Platform Enumeration), CVSS (Common Vulnerability Scoring System), and CVE (Common Vulnerabilities and Exposures). &lt;br /&gt;&lt;br /&gt;SCAP will allow security technologies to exchange systems and vulnerability information through a common format, thus allowing individual agencies the flexibility to use configuration management and security solutions that best meet their needs and budgets.&amp;quot;&lt;/p&gt;&lt;/blockquote&gt;&lt;p dir="ltr"&gt;While the FDCC was established for government agencies to establish desktop configuration standards, the SCAP standards offer a lot of value to nongovernment organizations too. According to Gula,“You’ll see organizations like credit unions and healthcare agencies—those who work with the government—implementing FDCC.&amp;quot; It is likely that many government organizations will make this a prerequisite for doing future business with their agency, especially if any electronic data is required to be shared between the two parties as part of doing business.&lt;/p&gt;

&lt;p dir="ltr"&gt; The configuration audit and compliance reporting capabilities of Ecora Auditor Pro can aid both government agencies and non-government organizations in assessing current desktop configurations and identify variances from the SCAP standards. To learn more about the Federal Desktop Core Configuration policy and how to audit your desktop configurations against SCAP standards, you can view this &lt;a href="http://www.ecora.com/ecora/webinars/techtalk1.asp"&gt;web recording on Standardizing Windows Desktop Configurations&lt;/a&gt;.&lt;/p&gt;

&lt;p dir="ltr"&gt;&lt;em&gt;&lt;span style="font-size: 0.6em;"&gt;Contributed by Mark Tordoff&lt;/span&gt;&lt;/em&gt; &lt;/p&gt;&lt;/div&gt;
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/09/basics-on-the-f.html</feedburner:origLink></entry>
    <entry>
        <title>Virtualization continues to grow, so how do you control the sprawl?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/eucVbfFTNZ4/virtualization.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/09/virtualization.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-55196788</id>
        <published>2008-09-05T13:42:41-07:00</published>
        <updated>2008-09-05T13:42:41-07:00</updated>
        <summary>According to recent research from IDC, "the pace of adoption of virtualized servers is incredibly rapid among organizations that are using virtualization, with 35% of servers purchased in 2007 being virtualized and 52% of those bought in 2008 expected to...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="change management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="data centers" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Auditor Pro" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Compliance Center" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Executive Dashboard" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Software" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IDC" />
        <category scheme="http://sixapart.com/ns/types#tag" term="InformationWeek" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT audit" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT compliance" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Joe Hernick" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Lorna Garey" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Microsoft Hyper-V" />
        <category scheme="http://sixapart.com/ns/types#tag" term="virtual machines" />
        <category scheme="http://sixapart.com/ns/types#tag" term="virtual migrations" />
        <category scheme="http://sixapart.com/ns/types#tag" term="virtual servers" />
        <category scheme="http://sixapart.com/ns/types#tag" term="virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VM sprawl" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VMware" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VMware ESX" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;According to &lt;a href="http://www.idc.com/getdoc.jsp?containerId=prUK21327108"&gt;recent research from IDC&lt;/a&gt;, &amp;quot;the pace of adoption of virtualized servers is incredibly rapid among organizations that are using virtualization, with 35% of servers purchased in 2007 being virtualized and 52% of those bought in 2008 expected to be so.&amp;quot; Now, while this was research of the European market, it is pretty easy to assume that these increases are probably representative of the US market as well, with possibly higher percentages. However, while these numbers reflect the number of servers purchased, it doesn't begin to capture the number of Virtual Machines being deployed on those servers.&lt;/p&gt;

&lt;p&gt;The recent edition of InformationWeek featured &lt;a href="http://www.informationweek.com/news/hardware/virtual/showArticle.jhtml?articleID=210003820"&gt;an article by Joe Hernick and Lorna Garey&lt;/a&gt; discussing why it is &amp;quot;Time to Halt Runaway VM Sprawl.&amp;quot; At the very beginning of the article, Hernick and Garey ask the question, &amp;quot;How will you audit for compliance if you don't know where all your production VMs reside, or even how many you have?&amp;quot; &lt;/p&gt;

&lt;p&gt;As good as that statement is, it really only addresses have of the compliance concern surrounding virtualization. In the IDC study, their research showed that &amp;quot;the majority of virtualization is still for test and development and for network server applications.&amp;quot; In many companies, this likely means that some customer data, including potential data that falls under compliance regulations, is stored in virtual test environments. &lt;/p&gt;

&lt;p&gt;In addition, the IDC research also found that &amp;quot;virtualization is growing as a datacenter strategy in itself rather than as part of other projects.&amp;quot; Why is that significant? It means in a growing number of IT departments, not only is the test environment virtualized, so is the production environment and, in all likelihood, so is the back-up data center used for disaster recovery and business continuity purposes. This means you need to understand how VMs are configured in each of these three virtualization environments if they hold data that falls under any of a growing number of government and industry regulations.&lt;/p&gt;

&lt;p&gt;If you are just transitioning from physical&amp;nbsp; to virtual servers, Hernick and Garey offer these recommendations:&lt;/p&gt;

&lt;ul&gt;&lt;li&gt;Admit you need to put a policy in place for how physical to virtual migrations are to be executed&lt;/li&gt;

&lt;li&gt;Live by the credo that &amp;quot;a virtual server is still a server&amp;quot;, with all the policies and security and management concerns of a physical box&lt;/li&gt;

&lt;li&gt;Build a mission statement laying out the organizational goals for virtualization&lt;/li&gt;

&lt;li&gt;Inventory your physical and virtualized environments (&lt;a href="http://www.ecora.com/ecora/products/auditor_professional.asp"&gt;Ecora Auditor Pro&lt;/a&gt; can be a tremendous help here)&lt;/li&gt;

&lt;li&gt;Overlay compliance and data security policies and organizational and management requirements (again, Ecora Auditor Pro and its &lt;a href="http://www.ecora.com/ecora/products/incomand.asp"&gt;Executive Dashboard&lt;/a&gt; and &lt;a href="http://www.ecora.com/ecora/products/compliance_center.asp"&gt;Compliance Center&lt;/a&gt; can be a real asset here)&lt;/li&gt;

&lt;li&gt;Put strict controls in place on VM creation (Auditor can also help in identifying unapproved VMs that may be deployed)&lt;/li&gt;&lt;/ul&gt;

&lt;p&gt;As IT becomes more and more dependent on virtual environments, especially with the availability of Microsoft's Hyper-V in addition to VMware ESX, as well as the growing number of other players in the virtualization space, it will become increasingly more critical to be able to quickly access the number of VMs in your environment, understand how they are configured, and be able to track changes to those configurations on an ongoing basis.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;span style="font-size: 0.6em;"&gt;Contributed by Mark Tordoff&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;/div&gt;
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/09/virtualization.html</feedburner:origLink></entry>
    <entry>
        <title>Data Loss Prevention is an International Issue</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/8LSLfEAXibI/data-loss-preve.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/09/data-loss-preve.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-55081162</id>
        <published>2008-09-03T09:49:53-07:00</published>
        <updated>2008-09-03T09:49:53-07:00</updated>
        <summary>Steve Wright is a Senior Manager for Risk Assurance Services with PriceWaterhouseCoopers in the United Kingdom. Steve and I have worked collaboratively over the past year on a number of web presentations related to issues related to ISO 27001 and...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Data Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="data intelligence" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Data Loss Prevention" />
        <category scheme="http://sixapart.com/ns/types#tag" term="data security training" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Auditor Pro" />
        <category scheme="http://sixapart.com/ns/types#tag" term="identity and access management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Information Systems" />
        <category scheme="http://sixapart.com/ns/types#tag" term="ISO 27001" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="password policies" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI Data Security Standard" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Police National Computer" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PriceWaterhouseCoopers" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Risk Assurance" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Steve Wright" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://www.linkedin.com/in/stevewright1970"&gt;Steve Wright&lt;/a&gt; is a Senior Manager for Risk Assurance Services with PriceWaterhouseCoopers in the United Kingdom. Steve and I have worked collaboratively over the past year on a number of web presentations related to issues related to ISO 27001 and the PCI Data Security Standard. In fact, Steve will be doing a presentation with Ecora on &lt;em&gt;How companies are using the PCI Data Security Standard for improving the Security &amp;amp; Performance of Information Systems&lt;/em&gt; on September 24th at 10am Eastern. You can register &lt;a href="http://www.ecora.com/ecora/webinars/webinar.asp/2008-09-24/"&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Recently, British papers reported on the loss of a significant number of criminal records from the Police National Computer. In response, Steve was willing to share these thoughts on the subject of preventing data loss.&lt;/p&gt;

&lt;p&gt;&amp;quot;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;Unfortunately, Friday 22 August 2008, we once again awoke to the news of yet another data loss incident. This time, it is the personal records and intelligence on tens of thousands of UK prisoners, including secret dossiers on the UK’s 10,000 priority criminals – a kind of who’s who in the criminal world. Such a lapse in basic data security also puts at risk police informants, as a number of unspecified people included in the data breach were enlisted on the drug intervention programmes.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;This makes the data highly valuable in underground world of data intelligence and literally can put ‘lives at risk’. &lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;The incident appears to involve another third party responsible for handling the data, but alas, the data had been unencrypted for data transfer reasons – the very opposite of when data should have remained encrypted.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;So what could of have been done to prevent such an incident in the first place?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;Well, it may be easy with hindsight to point the finger and cry negligence. The Home Office investigation will no doubt come to some conclusions, but it does not matter now, for 88,000 prisoner records is currently unaccountable for. One possible solution would be for the Home Office to look at what could have been done to prevent such a loss occurring in the first place – also known as a Data Loss Prevention (DLP) review. A DLP review could have possibly identified areas of potential weakness in either the Home Office or its trusted third parties key data handling processes and hopefully mitigated or managed the risk accordingly. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;What is Data Loss Prevention?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;DLP addresses three fundamental questions: &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;(1) Where is my confidential information being held? – This includes the data’s entire lifecycle or journey and where the data is being stored (third parties, off-shoring, outsourcing) &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;(2) How is the data being used? – This should include why, when, what and who accessed it &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;(3) How can we best prevent data from being lost? – What are the risks and thus what possible mitigating actions could be deployed to avoid loss, theft or compromise?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;At the heart of Data Loss Prevention is understanding what the value of the data is to the organization, how everyone is responsible for ensuring its ‘health and safety’ – in essence, this can only be achieved through a comprehensive understanding of the risk (risk analysis) facing your data, and educating the people who handle or access it, i.e. mandatory training for all people who come into contact with it.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;This may appear like a basic concept, but it is one that is often neglected - as with treating any symptoms, understanding the cause is paramount. Understanding why data is important to others and how easily it can be lost, compromised, manipulated or stolen, is a critical part of the process of understanding DLP and winning the ‘hearts and minds’ of every employee, third parties and person who comes into contact with the data.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;Either way, once the UK Home Office has completed its investigation and lessons learnt, we can be pretty much guess what some of the findings and recommendations will be – Possible Finding; ‘a systematic failing of following basic procedure, further exacerbated by the lack of adequate training on data security procedures. In other words, a pragmatic approach to DLP may have avoided such an incident; and by ensuring all persons who come into contact with the data (i.e. third parties) receive an appropriate level of mandatory security and data handling training, such lapses in basic data security may be avoided in the future.&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;span face="Arial"&gt;An item that I might add to Steve's comments are the essential need to understand how the infrastructure is configured around where key data is stored and accessed, as well as the applications that use this data. Without ensuring that access is limited to authorized personnel only and that appropriate security steps are employed related to password length, complexity, and frequency of updating, especially those for administrative accounts, any data is prone to be inappropriately access and potentially leveraged for criminal activity. As we'll demonstrate in Steve's upcoming presentation, &lt;a href="http://www.ecora.com/ecora/products/auditor_professional.asp"&gt;Ecora Auditor Pro&lt;/a&gt; can automate the identification of current users, password information and NTFS share and permissions so that you can quickly remediate situations that don't meet your security policies and, in all likelihood, external government or industry regulations.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span lang="EN-GB"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 0.6em;"&gt;Contributed by Steve Wright, Senior Risk and Data Security Practitioner at PwC and Mark Tordoff&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;











&lt;/div&gt;
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/09/data-loss-preve.html</feedburner:origLink></entry>
    <entry>
        <title>What the Current Economic Uncertainty Means for IT</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/kzfjR3JM3Kk/what-the-curren.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/09/what-the-curren.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-54570738</id>
        <published>2008-09-02T06:00:00-07:00</published>
        <updated>2008-09-02T06:00:00-07:00</updated>
        <summary>This has been a difficult period of time for all of us, on both a business and personal level. The rising cost of fuel has impacted us all, and nearly every region of the county has faced some type of...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IT News" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Bryan Cote" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CIO Magazine" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration attributes" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration standardization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="data security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Democratic convention" />
        <category scheme="http://sixapart.com/ns/types#tag" term="dotcom bust" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Dow Chemical" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Auditor Pro" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Software" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Gartner" />
        <category scheme="http://sixapart.com/ns/types#tag" term="InformationWeek" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT audits" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT costs" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IT standardization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Laurie M. Orlov" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mack Murrell" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="NBCOlympics.com" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Republican convention" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Sarbanes-Oxley" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Y2K" />
        <category scheme="http://sixapart.com/ns/types#tag" term="YouTube" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span face="Calibri"&gt;This has been a difficult period of time for all of us, on both a business and personal level. The rising cost of fuel has impacted us all, and nearly every region of the county has faced some type of significant weather-related challenge in the past six months. &lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span face="Calibri"&gt;Now that the weather has improved and fuel prices have moderated some, people have been distracted by the current Olympic Games in Beijing, as is probably evidenced by the amount of &lt;/span&gt;&lt;a href="http://www.youtube.com/"&gt;&lt;span style="color: #800080;"&gt;YouTube&lt;/span&gt;&lt;/a&gt;&lt;span face="Calibri"&gt; or &lt;/span&gt;&lt;a href="http://www.nbcolympics.com/"&gt;&lt;span style="color: #800080;"&gt;NBCOlympics.com&lt;/span&gt;&lt;/a&gt;&lt;span face="Calibri"&gt; hits your network has seen in the past two weeks. Throw in the typical summer vacations and the upcoming Democratic and Republican conventions to kick-off one of the most significant Presidential elections in decades, and it’s clear that the upheaval to the economy isn’t going to end immediately.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span face="Calibri"&gt;&lt;strong&gt;The Impact on IT Budgets&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span face="Calibri"&gt;According to a &lt;/span&gt;&lt;a href="http://www.tmcnet.com/usubmit/-stare-down-bear-it-spendings-getting-squeezed-our-/2008/07/28/3570550.htm"&gt;&lt;span face="Calibri"&gt;recent survey by &lt;em&gt;InformationWeek&lt;/em&gt;&lt;/span&gt;&lt;/a&gt;&lt;span face="Calibri"&gt;, &lt;/span&gt;&lt;span style="FONT-SIZE: 9pt; LINE-HEIGHT: 115%; FONT-FAMILY: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;“&lt;/span&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;of more than 600 business technology executives who responded to our most recent survey, 40% say they decreased IT spending this past quarter relative to their original 2008 budgets; for companies with annual revenue of more than $500 million, it's 50%.”&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;The survey indicates that budgets going forward this year are not likely to grow. In fact, a large percentage said they were expecting cutbacks. According to the article, “39% say they're cutting, and those cutbacks could be significant, with 19% saying their IT spending this year will be down more than 10%.”&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;&lt;strong&gt;What to Consider When Making Cuts&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;If you are faced with the unenviable task of reducing an IT budget that you already scrutinized before you submitted it, what are some things you should consider? According to Laurie M. Orlov of CIO Magazine, you should consider the future.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;In her article, &lt;em&gt;&lt;a href="http://www.cio.com/article/389463/Your_IT_Budget_When_Cutting_Costs_Look_to_the_Future"&gt;&lt;span style="color: #800080;"&gt;When Cutting IT Costs, Look to the Future&lt;/span&gt;&lt;/a&gt;&lt;/em&gt;, Ms. Orlov talks about some of the mistakes that were made following the dotcom bust and the Y2K spending hangover and suggests different tactics should be considered in the current economic downturn.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Here are three suggestions she has:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;ol type="1" style="MARGIN-TOP: 0in"&gt;&lt;li class="MsoNormal" style="MARGIN: 0in 0in 10pt; mso-list: l1 level1 lfo1"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Protect hard-to-fill roles&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;

&lt;li class="MsoNormal" style="MARGIN: 0in 0in 10pt; mso-list: l1 level1 lfo1"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Bring on the interns&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;

&lt;li class="MsoNormal" style="MARGIN: 0in 0in 10pt; mso-list: l1 level1 lfo1"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Solicit ideas from your staff and peers&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Those work well for maintaining some of the human capital of the organization and maintaining a solid workforce, but it doesn’t begin to address the need to continuously maintain business services , keep corporate and personal data secure, and continue to meet a growing number of compliance mandates aimed at IT.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;In the same issue of CIO Magazine, &lt;/span&gt;&lt;a href="http://www.cio.com/article/365613/How_Dow_Chemical_Keeps_Its_IT_Costs_Low"&gt;&lt;span style="color: #800080;"&gt;Mack Murrell, Dow Chemical’s vice president of IT, shares some ideas&lt;/span&gt;&lt;/a&gt;&lt;span face="Calibri"&gt; that begin to shed light on some technology decisions you can make to help in tight economic times like we’re in now.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Here are some of the key items Murrell shares:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;ul type="disc" style="MARGIN-TOP: 0in"&gt;&lt;li class="MsoNormal" style="MARGIN: 0in 0in 10pt; mso-list: l0 level1 lfo2"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;“We look at cost management from a strategic point of view. I’ve got a three-to-five year look ahead on costs.”&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;

&lt;li class="MsoNormal" style="MARGIN: 0in 0in 10pt; mso-list: l0 level1 lfo2"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Dow has controlled IT costs by maintaining an “appropriate” level of IT standardization&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;

&lt;li class="MsoNormal" style="MARGIN: 0in 0in 10pt; mso-list: l0 level1 lfo2"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;IT customizes solutions only when necessary&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;One key, as the article states, is certainly standardization. In this case, the reference was to standardizing of hardware and applications. But, when you are standardizing your infrastructure, it is also important to standardize how they are configured. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Standardizing configurations ensures that your infrastructure will perform at its optimum potential and that critical business services will be available for both your external and internal customers. However, this requires the ability to know how you expect systems to be configured, can easily document how they are really configured, and what discrepancies exist between the two so that corrections can be made.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;In addition, nearly every organization faces multiple internal and external audits of their IT infrastructure. A lot has changed since the passage of Sarbanes-Oxley back in 2002.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;Audit firms have spent a great deal of time and effort over the past six years hiring and training auditors to be much more knowledgeable about the type of configuration controls that should be in place to reduce the potential risk that might otherwise exist to regulated data in your infrastructure. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;Beyond that, Sarbanes-Oxley is no longer the only audit concern facing IT. In fact, &lt;/span&gt;&lt;a href="http://www.gartner.com/it/content/498300/498334/risk1brochure.pdf"&gt;&lt;span style="color: #800080;"&gt;Gartner analysts&lt;/span&gt;&lt;/a&gt;&lt;span face="Calibri"&gt; are now forecasting that “by 2012, the number of regulations that directly affect IT operations will double.” In challenging economic times, it is vital that you can respond to various audit demands without the need for a lot of manual effort or external sub-contractors that you can’t afford.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;In addition to the suggestions made by Ms. Orlov and Mr. Murrell, if you don’t have an automated solution for effectively documenting and auditing the configuration attributes across your enterprise, let me suggest &lt;/span&gt;&lt;a href="http://www.ecora.com/ecora/register/auditor_professional_45.asp"&gt;&lt;span style="color: #800080;"&gt;requesting a personal demonstration&lt;/span&gt;&lt;/a&gt;&lt;span face="Calibri"&gt; of a tool like &lt;/span&gt;&lt;a href="http://www.ecora.com/ecora/products/auditor_professional.asp"&gt;&lt;span style="color: #800080;"&gt;Ecora Auditor Pro&lt;/span&gt;&lt;/a&gt;&lt;span face="Calibri"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Arial"&gt;&lt;span face="Calibri"&gt;&lt;em&gt;&lt;span style="font-size: 0.6em;"&gt;Contributed by Mark Tordoff and Bryan Cote&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/09/what-the-curren.html</feedburner:origLink></entry>
    <entry>
        <title>Top 10 eDiscovery Trends</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/ecorablog/the_compliance_and_securi/~3/G5gAGa24NAA/top-10-ediscove.html" />
        <link rel="replies" type="text/html" href="http://www.ecorablog.com/the_compliance_and_securi/2008/08/top-10-ediscove.html" thr:count="3" thr:updated="2010-02-05T01:07:31-08:00" />
        <id>tag:typepad.com,2003:post-54566478</id>
        <published>2008-08-29T06:00:00-07:00</published>
        <updated>2008-08-29T06:00:00-07:00</updated>
        <summary>I had so much fun with Wednesday's Top 10 list, that I thought I'd end the week with another. Over the past few months, I've had the privilege to host three separate webinars with William Morris and Jane Hils Shea...</summary>
        <author>
            <name>Mark Tordoff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="eDiscovery" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Clearwell Systems" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration auditing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="configuration management" />
        <category scheme="http://sixapart.com/ns/types#tag" term="data loss litigation fines" />
        <category scheme="http://sixapart.com/ns/types#tag" term="data privacy protection law" />
        <category scheme="http://sixapart.com/ns/types#tag" term="e-discovery analysis" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Auditor Pro" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Ecora Software" />
        <category scheme="http://sixapart.com/ns/types#tag" term="eDiscovery" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Frost Brown Todd LLC" />
        <category scheme="http://sixapart.com/ns/types#tag" term="identity and access" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Inc." />
        <category scheme="http://sixapart.com/ns/types#tag" term="information security standards" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Intellitactics" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Jane Hils Shea" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mark Tordoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Sunil Bhargava" />
        <category scheme="http://sixapart.com/ns/types#tag" term="system outages" />
        <category scheme="http://sixapart.com/ns/types#tag" term="William Morris" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.ecorablog.com/the_compliance_and_securi/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;I had so much fun with Wednesday's Top 10 list, that I thought I'd end the week with another.&lt;/p&gt;

&lt;p&gt;Over the past few months, I've had the privilege to host three separate webinars with William Morris and Jane Hils Shea from &lt;a href="http://www.frostbrowntodd.com/"&gt;Frost Brown Todd LLC&lt;/a&gt; and Sunil Bhargava from &lt;a href="http://www.intellitactics.com/int/"&gt;Intellitactics&lt;/a&gt;. &lt;/p&gt;

&lt;p&gt;William is an Associate in the Intellectual Property Department of Frost Brown Todd and, back in April, he addressed the issue of &lt;a href="http://www.ecora.com/ecora/webinars/ondemand.asp/eDiscovery/"&gt;How You Can Secure the Infrastructure Around the Data You Must Save&lt;/a&gt; in a webinar with Ecora. In June, Sunil, who is the Chief Technology Officer at Intellitactics, joined us to highlight &lt;a href="http://www.ecora.com/ecora/webinars/ondemand.asp/inttactics_5ways/"&gt;5 Ways to Avoid High Data Loss Litigation Fines&lt;/a&gt;. Just last week, Jane, the chair of the Privacy and Information Security Law Practice Group at Frost Brown Todd LLC, share important information related to &lt;a href="http://www.ecora.com/ecora/webinars/ondemand.asp/emerging_issues_080820/"&gt;Current and Emerging Issues in Data Privacy Protection Law&lt;/a&gt;. You can click on each link to register and watch any of the presentation recordings.&lt;/p&gt;

&lt;p&gt;Given the importance of IT documentation to litigation cases outside of the typical regulatory compliance headlines, I was pleased to see that Clearwell Systems, Inc. shared a paper on what they feel the Top 10 Trends in e-Discovery are. You can &lt;a href="http://clearwellsystems.com/offers/top10/"&gt;accesss the paper here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;nbsp; 1.&amp;nbsp; &amp;quot;E-Discovery Teams&amp;quot; are Coalescing -- Recognizing that e-discovery is changing from an ad-hoc event to a formal business process, both law firms and corporations are beginning to develop cross-functional &amp;quot;E-Discovery Teams&amp;quot; to help navigate the transition from reactive fire drills to proactive management.&lt;br /&gt;&amp;nbsp; &amp;nbsp;2.&amp;nbsp; Early Case Assessments Become Mainstream -- Understanding where a party stands at the earliest stages of litigation is critical to the outcome of a case. By selecting the right technology and implementing tools optimized for e-discovery analysis, legal professionals are better able to find and interpret key case facts from mountains of electronic case data.&lt;br /&gt;&amp;nbsp; &amp;nbsp;3.&amp;nbsp; &amp;quot;Search&amp;quot; Goes Under the Microscope -- Recent case law scrutinizes attorneys who navigate the search process alone; consensus between parties is critical. For a keyword search to pass judicial muster, it must be an agreed upon &amp;quot;Collaborative Search Approach&amp;quot; or adopt a &amp;quot;Best Practices &amp;amp; Data Driven Search Approach.&amp;quot;&lt;br /&gt;&amp;nbsp; &amp;nbsp;4.&amp;nbsp; E-Discovery Moves In-House -- Corporations are bringing pieces of e-discovery in-house to reduce costs and streamline the process. Certain tasks will likely remain outsourced (e.g., forensic collection, large scale distributed review), whereas other routine tasks are quickly being brought in house (e.g., searching, culling, processing, analysis).&lt;br /&gt;&amp;nbsp; &amp;nbsp;5.&amp;nbsp; Review Mantra: &amp;quot;Smarter not Harder&amp;quot; -- Reducing the size of case datasets by removing irrelevant documents has been proven to lower processing costs by up to 80 percent, and reduce review workloads by up to 90 percent. In-house and outside counsel have significantly fewer documents to review, thus lowering resource requirements and cost.&lt;br /&gt;&amp;nbsp; &amp;nbsp;6.&amp;nbsp; The Standard of Care is Rising -- Rapidly -- The bar and bench is now using a common language around a new set of e-discovery challenges that did not exist until recently. As a result, attorneys and the parties they represent are getting fined and sanctioned for e-discovery negligence and abuse that would have been overlooked a year or two ago.&lt;br /&gt;&amp;nbsp; &amp;nbsp;7.&amp;nbsp; ESI Expands Well Beyond Email -- Legal professionals recognize the need to choose an e-discovery method that is flexible enough to encompass emerging communication technologies such as blogs, Wikis,voice over IP (VOIP), Webmail services, text and instant messaging, etc.&lt;br /&gt;&amp;nbsp; &amp;nbsp;8.&amp;nbsp; Custodial Data Increases by Orders of Magnitude -- Increasing volumes of data have reached a critical &amp;quot;tipping point,&amp;quot; placing greater importance on data searching and aggressive use of ECA to quickly cull down data sets, in addition to automated document review methodologies.&lt;br /&gt;&amp;nbsp; &amp;nbsp;9.&amp;nbsp; Non-Manual Document Review -- Rising costs and compressed production deadlines are influencing attorneys to employ an iterative searching process that automatically weeds out confidential and other non-responsive and/or privileged documents prior to production.&lt;br /&gt;&amp;nbsp; 10.&amp;nbsp; Vendors Struggle to Adapt to the Evolving Landscape -- E-discovery has become more complex and specialized; thorough research must be conducted prior to selecting a solution.&lt;/p&gt;

&lt;p&gt;While much of what Clearwell addresses in the trends is specific to their offering, there are two things that are important to grasp when looking at e-Discovery that may be required as part of current or future litigation.&lt;/p&gt;

&lt;p&gt;1. You will potentially need to store sensitive data in your systems longer than you have typically done, so that it will be available to produce in the event of litigation. Because of other potential regulations regarding the security of this data, you will need to be especially diligent to put proper safeguards around any part of your infrastructure that is involved in the use, transmission or storage of that information.&lt;/p&gt;

&lt;p&gt;2. Often, rulings in litigation cases involving electronic information are determined based on the ability or inability of defendent to produce evidence to the court supporting that their systems were properly documented or that appropriate identity and access policies were actually being deployed and maintained in their infrastructure. Failure to continually document your infrastructure and validate the configuration setting against appropriate information security standards will likely cost you significantly, not only in fines but in court-imposed, mandatory ongoing audits. This is where an automated configuration audit and compliance reporting solution like &lt;a href="http://www.ecora.com/ecora/products/auditor_professional.asp"&gt;Ecora Auditor Pro&lt;/a&gt; can yield tremendous benefits, not only to daily operations for identifying the root cause of system outages, but for avoiding potentially costly litigation settlements and reputation-bruising news headlines.&lt;/p&gt;

&lt;p&gt; &lt;em&gt;&lt;span style="font-size: 0.6em;"&gt;Contributed by Mark Tordoff&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;/div&gt;
</content>


    <feedburner:origLink>http://www.ecorablog.com/the_compliance_and_securi/2008/08/top-10-ediscove.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 --><!-- nhm:dynamic-ssi -->
