Compliance

A jumble of acronyms that stand for an overwhelming number of federal mandates have marched compliance right to the front of most leading security professionals' minds. With SOX, GLBA, HIPAA, FISMA keeping CSOs up at night, SC Magazine offers its Compliance sector, your guide to meeting federal requirements.

Latest Compliance News

Final settlement reached in CVS HIPAA violation suit

Angela Moscaritolo June 25, 2009

CVS Caremark must implement an information security program and obtain assessments of its effectiveness every other year for 20 years to settle federal charges.
 

FTC releases FAQs on Red Flags Rules

Angela Moscaritolo June 12, 2009

A new frequently-asked-questions document aims to clear up some of the confusion around the Red Flags Rules.
 

Bank sues Savvis over 2005 CardSystems breach

Angela Moscaritolo May 28, 2009

Utah-based Merrick Bank claims to have lost $16 million as a result of a 2005 breach of payment card processor CardSystems Solutions and is now seeking legal restitution.
 

Study finds IT security pros cheat on audits

Angela Moscaritolo May 27, 2009

IT security professionals might think of auditing as a pain, but some are actually cheating to get audits passed, according to a study released Wednesday.
 

GAO report finds security lagging at federal agencies

Dan Kaplan May 21, 2009

Federal agencies continue to be lax in their implementation of information security programs, according to a new report from the Government Accountability Office.
 

Compliance Opinions

PCI DSS compliance: You can't just check the boxes

PCI DSS compliance: You can't just check the boxes

Brian Eberhardy, senior consulting engineer for SenSage May 01, 2009

Recent breaches at organizations that were certified as PCI DSS compliant, continue to prove that compliance doesn't completely eliminate the risk of a data breach.
 
Be careful with the Rockefeller-Snowe bill

Be careful with the Rockefeller-Snowe bill

Luther Martin, chief security architect, Voltage Security April 16, 2009

Some parts of the Rockefeller-Snowe bill make sense, while other parts may cause unexpected consequences.
 
CASE STUDY: Stock Yards Bank & Trust

CASE STUDY: Stock Yards Bank & Trust

Greg Masters February 13, 2009

A biometric solution helps Stock Yards Bank & Trust manage passwords and aids in compliance efforts.
 

Compliance Vendors

Aveksa

The Aveksa Access Governance Platform is the industry’s first comprehensive solution for access governance, risk and compliance management. It is comprised of the Aveksa Compliance Manager, which automates the monitoring, reporting, certification and remediation of user entitlements; the Aveksa Role Manager, which enables role discovery, modeling and maintenance; and the ...

High Tower Software

High Tower is a global provider of Security Information and Event Management (SIEM) products that analyze and manage large volumes of network and security log data in real-time, helping organizations improve attack identification and meet regulatory compliance requirements for security.

Nitro Security

NitroSecurity supplies information security products that protect business information and infrastructure with solutions that reduce business risk exposure and increase network and information availability by monitoring, protecting and alerting organizations about suspicious or harmful network activities.

Shavlik Technologies LLC

Over 10,000+ organizations worldwide trust Shavlik Technologies to simplify their complex enterprise network security. Designed to reduce risk and improve the use of IT resources, Shavlik products automate: • Patch and Configuration Management • Application Control • Audit Reporting • Compliance Management

Tenable Network Security

Tenable Network Security® is a leader in Unified Security Monitoring and creator of the award winning Nessus® vulnerability scanner. Tenable's products have been designed to monitor systems and networks against a number of the established compliance standards. It is important to note that a secure infrastructure is achieved through a ...