<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercesarbox.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>standpoint</title>
 <link>http://www.fiercesarbox.com/tags/standpoint</link>
 <description></description>
 <language>en</language>
<item>
 <title>Tools and tips for enterprise risk management</title>
 <link>http://www.fiercesarbox.com/story/tools-and-tips-for-enterprise-risk-management/2007-05-15?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FS0</link>
 <description>&lt;P&gt;
&lt;P align=left&gt;&lt;A href=&quot;http://www.fiercesarbox.com/story/best-practices-for-boards-and-erm/2007-02-20&quot;&gt;Enterprise risk management&lt;/A&gt; is one of those buzzwords that has carved out more corporate mind share in recent years. Executives have always been focused on managing risk, but the process has been &quot;from a reactive exposure-by-exposure standpoint or a silo approach,&quot; according to some new guidance from the Institute of Management Accountants (IMA). But in today&#039;s climate, most enterprises would be better off with a &quot;proactive, integrated, across-the organization perspective.&quot; A holistic view of risk makes a lot of sense, especially from a large branding perspective. In this view, Sarbanes-Oxley-related risk is one set of &quot;risks that exists under a larger umbrella.&quot; The IMA has just published a new statement on IMA that includes a lot of tips and tools for implementing such a system. The good news is that they allow financial professionals to really grow, underscoring their value to the organization. A copy of the statement, called &quot;Enterprise Risk Management: Tools and Techniques for Effective Implementation,&quot; is available on the IMA &lt;A href=&quot;http://www.imanet.org/smas&quot;&gt;website&lt;/A&gt;. &lt;/P&gt;
&lt;P align=left&gt;For more: &lt;BR&gt;- here&#039;s a &lt;A href=&quot;http://www.webcpa.com/article.cfm?articleid=24166&quot;&gt;release&lt;/A&gt;&lt;/P&gt;

</description>
 <comments>http://www.fiercesarbox.com/story/tools-and-tips-for-enterprise-risk-management/2007-05-15#comments</comments>
 <category domain="http://www.fiercesarbox.com/channel/enterprise-initiatives">Enterprise Initiatives</category>
 <category domain="http://www.fiercesarbox.com/tags/enterprise-risk-management">enterprise risk management</category>
 <category domain="http://www.fiercesarbox.com/tags/managing-risk">managing risk</category>
 <category domain="http://www.fiercesarbox.com/channel/sarbanes-oxley-technology">Sarbanes Oxley Technology</category>
 <category domain="http://www.fiercesarbox.com/tags/standpoint">standpoint</category>
 <pubDate>Mon, 14 May 2007 20:01:39 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">1054 at http://www.fiercesarbox.com</guid>
</item>
<item>
 <title>Software-as-a-service and Sarbox: Good match?</title>
 <link>http://www.fiercesarbox.com/story/software-as-a-service-and-sarbox-good-match/2007-03-20?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FS0</link>
 <description>&lt;P&gt;You&#039;ve probably heard a lot about the rise of software-as-a-service as a model that more companies, big and small, are embracing. Clearly, the notion of paying for software services, hosted elsewhere, on an as-you-go basis makes a lot of sense. Does it offer any advantages from a compliance standpoint? Treb Ryan, CEO of OpSource, noted at a recent conference the software-as-a-service model can be a big benefit in compliance if the service is already &quot;compliant&quot; from a Sarbanes-Oxley, or HIPAA or regulatory perspective. OpSource, which provides a platform for software companies to deliver services, notes that its service has completed a rigorous audit known as a &lt;A href=&quot;http://www.opsource.net/saas/wp_SAS70_TypeII.pdf&quot;&gt;type II SAS 70&lt;/A&gt;, which basically validates that the service is compliant. So the marketing point is that if software-as-a-service (SAS 70-audited anyway) for critical functions can still deliver the benefits and perhaps even save you a few compliance headaches. More software-as-a-service providers will likely start touting this. &lt;/P&gt;
&lt;P&gt;For more: &lt;BR&gt;- here&#039;s an &lt;A href=&quot;http://www.infoworld.com/article/07/03/15/HNmicrosaas_1.html&quot;&gt;article&lt;/A&gt;&amp;nbsp;from &lt;EM&gt;Infoworld&lt;/EM&gt;&amp;nbsp;(scroll down for Ryan&#039;s comments)&lt;/P&gt;

</description>
 <comments>http://www.fiercesarbox.com/story/software-as-a-service-and-sarbox-good-match/2007-03-20#comments</comments>
 <category domain="http://www.fiercesarbox.com/tags/compliance-processes">compliance</category>
 <category domain="http://www.fiercesarbox.com/tags/hipaa">HIPAA</category>
 <category domain="http://www.fiercesarbox.com/channel/sarbanes-oxley-technology">Sarbanes Oxley Technology</category>
 <category domain="http://www.fiercesarbox.com/tags/software-companies">software companies</category>
 <category domain="http://www.fiercesarbox.com/tags/standpoint">standpoint</category>
 <pubDate>Mon, 19 Mar 2007 20:01:39 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">979 at http://www.fiercesarbox.com</guid>
</item>
<item>
 <title>Get a grip on data sharing with partners</title>
 <link>http://www.fiercesarbox.com/story/get-a-grip-on-data-sharing-with-partners/2006-11-21?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FS0</link>
 <description>&lt;P&gt;An Ernst &amp;amp; Young survey suggests that about half of all companies are not taking the risks of data sharing with partners seriously enough. More than 50 percent of respondents to the Annual Global Information Security Survey say they only informally address vendor risks--or not at all. Less than 15 percent require vendors to review their information and privacy practices in light of best practices. This is a obviously not wise from a compliance, privacy or competitiveness standpoint. You may want to develop a more detailed picture of your company&#039;s policies in this area. You will likely be thanked. &lt;A href=&quot;http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&amp;newsId=20061113006045&amp;newsLang=en&quot;&gt;Release&lt;/A&gt;&lt;/P&gt;

</description>
 <comments>http://www.fiercesarbox.com/story/get-a-grip-on-data-sharing-with-partners/2006-11-21#comments</comments>
 <category domain="http://www.fiercesarbox.com/tags/best-practices">best practices</category>
 <category domain="http://www.fiercesarbox.com/tags/competitiveness">competitiveness</category>
 <category domain="http://www.fiercesarbox.com/tags/compliance-processes">compliance</category>
 <category domain="http://www.fiercesarbox.com/tags/standpoint">standpoint</category>
 <pubDate>Mon, 20 Nov 2006 19:01:38 -0500</pubDate>
 <dc:creator />
 <guid isPermaLink="false">835 at http://www.fiercesarbox.com</guid>
</item>
</channel>
</rss>
