<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercesarbox.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>compliance initiatives</title>
 <link>http://www.fiercesarbox.com/tags/compliance-initiatives-0</link>
 <description></description>
 <language>en</language>
<item>
 <title>Get a grip on encryption and databases</title>
 <link>http://www.fiercesarbox.com/story/get-grip-encryption-and-databases/2008-08-08?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FS0</link>
 <description>&lt;p&gt;As you know, storage issues have rocketed to the forefront of the IT agenda, driven mainly by Sarbanes-Oxley and other compliance initiatives. That has made them targets for various hackers. SQL injection attacks, among other activities, are rising, notes &lt;em&gt;SC&lt;/em&gt; magazine.&amp;nbsp;So while encryption is not the complete answer, it makes sense. Unfortunately, the fact remains that many companies still have not embraced encryption.&amp;nbsp;The practice itself raises several issues; Do you encrypt everything, or just some data?&amp;nbsp;Where do you encrypt it?&amp;nbsp;There are lots of solutions&amp;nbsp;out there.&amp;nbsp;It&#039;s always a good time to get started on these issues. &lt;a href=&quot;http://www.scmagazineuk.com/Storage-Whats-in-store/article/113392/&quot;&gt;Article&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercesarbox.com/story/get-grip-encryption-and-databases/2008-08-08#comments</comments>
 <category domain="http://www.fiercesarbox.com/tags/compliance-initiatives-0">compliance initiatives</category>
 <category domain="http://www.fiercesarbox.com/tags/databases">Databases</category>
 <category domain="http://www.fiercesarbox.com/tags/encryption-0">Encryption</category>
 <category domain="http://www.fiercesarbox.com/tags/hackers">Hackers</category>
 <category domain="http://www.fiercesarbox.com/tags/key-management">Key Management</category>
 <category domain="http://www.fiercesarbox.com/tags/storage-issues">Storage Issues</category>
 <pubDate>Fri, 08 Aug 2008 14:46:35 -0400</pubDate>
 <dc:creator>Jim Kim</dc:creator>
 <guid isPermaLink="false">1497 at http://www.fiercesarbox.com</guid>
</item>
<item>
 <title>Time for compliance scoring?</title>
 <link>http://www.fiercesarbox.com/story/time-compliance-scoring/2008-07-25?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FS0</link>
 <description>&lt;p&gt;&lt;em&gt;TechRepublic&lt;/em&gt; makes the point that &quot;most organizations simply do not have the time to dedicate the resources to deliver an accurate [control] assessment. While there are many tools that can address the technology aspects of compliance, not all offer a comprehensive approach to scoring all factors.&quot; To that end, it reviews the Modulo Risk Manager Platform, which Modulo markets as part of its GRC platform, as a way to provide security index scores to assess compliance initiatives in a way that spans more than just technology.&amp;nbsp;You can use the service to score various employees and facilities, such as the data center. &lt;a href=&quot;http://blogs.techrepublic.com.com/security/?p=519&quot;&gt;Article&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercesarbox.com/story/time-compliance-scoring/2008-07-25#comments</comments>
 <category domain="http://www.fiercesarbox.com/tags/compliance-initiatives-0">compliance initiatives</category>
 <category domain="http://www.fiercesarbox.com/tags/control-assessment">Control Assessment</category>
 <category domain="http://www.fiercesarbox.com/tags/manager-platform">Manager Platform</category>
 <category domain="http://www.fiercesarbox.com/tags/risk-manager">Risk Manager</category>
 <category domain="http://www.fiercesarbox.com/tags/technology-aspects">Technology Aspects</category>
 <pubDate>Fri, 25 Jul 2008 12:43:47 -0400</pubDate>
 <dc:creator>Jim Kim</dc:creator>
 <guid isPermaLink="false">1483 at http://www.fiercesarbox.com</guid>
</item>
<item>
 <title>GRC initiatives gaining, compliance still a must-do</title>
 <link>http://www.fiercesarbox.com/story/grc-initiatives-gaining-compliance-still-a-must-do/2008-04-01?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FS0</link>
 <description>&lt;p&gt;
We&#039;ve discussed the idea that compliance initiatives can yield strategic benefits, if done right. A new survey from AMR Research seems to suggest that more companies are getting on board with this idea. Companies will spend more than $32 billion on &lt;a href=&quot;http://www.fiercesarbox.com/tags/grc&quot;&gt;governance, risk management and compliance (GRC)&lt;/a&gt; in 2008. That&#039;s an increase of 7.4 percent over 2007. Meanwhile, spending on Sarbanes-Oxley compliance is expected to grow only 2 percent to $6.2 billion. What to make of this? The fact is, that a lot of GRC investment relates to Sarbox compliance. Rather than a Sarbox-specific project, why not include the project as part of larger, more strategic, deployment? Risk-management, intimately related to Sarbox, is seen as a big driver behind the trend.   
&lt;/p&gt;
&lt;p&gt;
For more: &lt;br /&gt;
- here&#039;s the &lt;a href=&quot;http://biz.yahoo.com/prnews/080325/netu061.html?.v=42&quot;&gt;release&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Related Articles:&lt;/strong&gt;&lt;br /&gt;
CFOs face complex GRC software decisions. &lt;a href=&quot;http://www.fiercesarbox.com/story/cfos-face-complex-grc-software-decisions/2008-02-26&quot;&gt;Article&lt;/a&gt;&lt;br /&gt;
Will the economy zap compliance issues? &lt;a href=&quot;http://www.fiercesarbox.com/story/will-economy-zap-compliance-initiatives/2008-02-05&quot;&gt;Article&lt;/a&gt;&lt;br /&gt;
GRC software seems to be rising. &lt;a href=&quot;http://www.fiercesarbox.com/story/grc-software-seems-to-be-rising/2007-03-13?utm_medium=rss&amp;amp;utm_source=sarbox_sap&quot;&gt;Article&lt;/a&gt;&lt;br /&gt;
Oracle aims for GRC eco-system. &lt;a href=&quot;http://www.fiercesarbox.com/story/oracle-aims-grc-eco-system/2007-11-20&quot;&gt;Article&lt;/a&gt;
&lt;/p&gt;
</description>
 <comments>http://www.fiercesarbox.com/story/grc-initiatives-gaining-compliance-still-a-must-do/2008-04-01#comments</comments>
 <category domain="http://www.fiercesarbox.com/tags/amr-research-0">AMR Research</category>
 <category domain="http://www.fiercesarbox.com/tags/compliance-processes">compliance</category>
 <category domain="http://www.fiercesarbox.com/tags/compliance-initiatives-0">compliance initiatives</category>
 <category domain="http://www.fiercesarbox.com/tags/governance">governance</category>
 <category domain="http://www.fiercesarbox.com/tags/governance-risk-management-and-compliance-grc">governance risk management and compliance (GRC)</category>
 <category domain="http://www.fiercesarbox.com/tags/grc">GRC</category>
 <category domain="http://www.fiercesarbox.com/tags/oracle">Oracle</category>
 <category domain="http://www.fiercesarbox.com/tags/risk-management-0">Risk Management</category>
 <category domain="http://www.fiercesarbox.com/tags/strategic-benefits">strategic benefits</category>
 <pubDate>Tue, 01 Apr 2008 07:59:59 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">1367 at http://www.fiercesarbox.com</guid>
</item>
</channel>
</rss>
