 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Heard, and overheard &#187; compliance</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/heard-and-overheard/tag/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/heard-and-overheard</link>
	<description>Views and counterviews from the Indian IT user landscape</description>
	<lastBuildDate>Tue, 06 Dec 2011 12:13:03 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Overheard talking about the Dodd-Frank Act</title>
		<link>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-the-dodd-frank-act/</link>
		<comments>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-the-dodd-frank-act/#comments</comments>
		<pubDate>Wed, 18 May 2011 14:38:02 +0000</pubDate>
		<dc:creator>Margaret Rouse</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[financial data]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-the-dodd-frank-act/</guid>
		<description><![CDATA[Overheard: Fred Cohen &#8220;[Dodd-Frank compliance] is just a huge undertaking. Y2K is going to be a walk in the park compared to this.&#8221; Today&#8217;s WhatIs.com Word of the Day is Dodd-Frank Act .]]></description>
				<content:encoded><![CDATA[<table border="0" cellspacing="5" cellpadding="5">
<tbody>
<tr>
<td><img src="http://http.cdnlayer.com/itke/blogs.dir/67/files/2011/05/fred_cohen.gif" alt="overheard" /></td>
<td><strong><span style="font-size: medium;color: #ed1c24">Overheard:</span></strong> <strong><strong><span style="font-size: medium;color: #ed1c24">Fred Cohen</span></strong></strong><br />
&#8220;[Dodd-Frank compliance] is just a <a href="http://searchdatamanagement.techtarget.com/news/2240035386/The-Dodd-Frank-Act-could-mean-a-data-management-mess-for-some">huge undertaking</a>. Y2K is going to be a walk in the park compared to this.&#8221;</td>
</tr>
</tbody>
</table>
<p>Today&#8217;s WhatIs.com Word of the Day is  <a href="http://searchfinancialsecurity.techtarget.com/definition/Dodd-Frank-Act">Dodd-Frank Act</a> .</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-the-dodd-frank-act/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Overheard &#8211; database activity monitoring (DAM)</title>
		<link>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-database-activity-monitoring-dam/</link>
		<comments>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-database-activity-monitoring-dam/#comments</comments>
		<pubDate>Tue, 12 Apr 2011 14:02:58 +0000</pubDate>
		<dc:creator>Margaret Rouse</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[data management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-database-activity-monitoring-dam/</guid>
		<description><![CDATA[Overheard: Adrian Lane &#8220;DAM is unique in that it analyzes database queries in near real time to differentiate between normal operations and attacks.&#8221; Today&#8217;s WhatIs.com Word of the Day is database activity monitoring.]]></description>
				<content:encoded><![CDATA[<table border="0" cellspacing="5" cellpadding="5">
<tbody>
<tr>
<td><img src="http://media.techtarget.com/digitalguide/images/experts/alane-sm.jpg" alt="overheard" width="60" height="78" /></td>
<td><strong><span style="font-size: medium;color: #ed1c24">Overheard: Adrian Lane</span></strong><br />
&#8220;DAM is unique in that it <a href="http://searchsecurity.techtarget.com/tip/Database-monitoring-best-practices-Using-DAM-tools">analyzes database queries</a> in near real time to differentiate between normal operations and attacks.&#8221;</td>
</tr>
</tbody>
</table>
<p>Today&#8217;s WhatIs.com Word of the Day is <a href="http://searchsecuritychannel.techtarget.com/definition/database-activity-monitoring">database activity monitoring</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-database-activity-monitoring-dam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Overheard talking about Compliance Officers</title>
		<link>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-compliance-officers/</link>
		<comments>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-compliance-officers/#comments</comments>
		<pubDate>Thu, 10 Mar 2011 17:58:45 +0000</pubDate>
		<dc:creator>Margaret Rouse</dc:creator>
				<category><![CDATA[C-level]]></category>
		<category><![CDATA[compliance]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/heard-and-overheard/?p=196</guid>
		<description><![CDATA[&#8220;&#8230;Some companies have begun forming compliance committees. Here, the IT manager, auditing executives and legal professionals find themselves grouped together as members of a central corporate compliance body.&#8221; &#8212; Paul Korzeniowski Today&#8217;s WhatIs.com Word of the Day is Chief Compliance Officer.]]></description>
				<content:encoded><![CDATA[<table border="0" cellspacing="5" cellpadding="5">
<tbody>
<tr>
<td><img src="http://http.cdnlayer.com/itke/blogs.dir/67/files/2011/03/paulk.jpg" alt="”overheard”" /></td>
<td>&#8220;&#8230;Some companies have begun forming compliance committees. Here, the IT manager, auditing executives and legal professionals find themselves grouped together as members of a central corporate compliance body.&#8221; &#8212; <a href="http://searchcompliance.techtarget.com/tip/Increased-depth-of-compliance-regulations-forces-companies-to-adapt">Paul Korzeniowski</a></td>
</tr>
</tbody>
</table>
<p>Today&#8217;s WhatIs.com Word of the Day is <a href="http://searchcio.techtarget.com/definition/CCO">Chief Compliance Officer</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-compliance-officers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Overheard talking about pharmaceutical detailing</title>
		<link>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-pharmaceutical-detailing/</link>
		<comments>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-pharmaceutical-detailing/#comments</comments>
		<pubDate>Wed, 23 Feb 2011 13:13:07 +0000</pubDate>
		<dc:creator>Margaret Rouse</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/heard-and-overheard/?p=183</guid>
		<description><![CDATA[Doctors may not be using Facebook or Twitter but they are turning to physician-only social networks like Sermo. The physician shift to social media is helped by the growing number of doctors who use smart phones. That means pharma has to change the way it reaches physicians. &#8212; Liz Cermak Today&#8217;s WhatIs.com Word of the [...]]]></description>
				<content:encoded><![CDATA[<table border="0" cellspacing="5" cellpadding="5">
<tbody>
<tr>
<td><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/156/files/2011/02/lizcermak.jpg"><img class="alignnone size-medium wp-image-182" src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/156/files/2011/02/lizcermak.jpg" alt="" width="65" height="75" /></a></td>
<td>Doctors may not be using Facebook or Twitter but they are turning to physician-only social networks like <em>Sermo</em>.   The physician shift to social media is helped by the growing number of   doctors who use smart phones. That means pharma has to change the way  it  reaches physicians. &#8212; <a href="http://www.medcitynews.com/2011/02/pharma-rep-of-the-future-have-smart-phone-and-wont-travel/">Liz Cermak</a></td>
</tr>
</tbody>
</table>
<p>Today&#8217;s WhatIs.com Word of the Day is <a href="http://searchhealthit.techtarget.com/definition/detailing">pharmaceutical detailing</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/heard-and-overheard/overheard-talking-about-pharmaceutical-detailing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Midsized business compliance revisited: Password123</title>
		<link>http://itknowledgeexchange.techtarget.com/heard-and-overheard/smb-compliance-revisited-password123/</link>
		<comments>http://itknowledgeexchange.techtarget.com/heard-and-overheard/smb-compliance-revisited-password123/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 05:04:30 +0000</pubDate>
		<dc:creator>Anilpatrick</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[IT act]]></category>
		<category><![CDATA[medium business]]></category>
		<category><![CDATA[regulation]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/heard-and-overheard/?p=82</guid>
		<description><![CDATA[It’s not always possible highly rate the average Indian SMB, when it comes to security compliance.]]></description>
				<content:encoded><![CDATA[<p>We started off <a href="http://itknowledgeexchange.techtarget.com/heard-and-overheard/boarding-call-for-medium-business-compliance/">the midsized Indian business&#8217;s compliance level debate</a> many an eon back in terms of blog years. Over the weeks, many responses have trickled in, and the views have not been too favorable on the preparedness of Indian midsized businesses when it comes to compliance and security levels. This post collates some of them (as well as my views), so that you can take the call yourself.</p>
<ul>
<li><strong>Software licenses:</strong> We in India don’t buy software, period. But now it might be a good idea to start buying those licenses, at least for the OS. If not, it’s time to take the free OS route, since options like Linux have matured in light years (especially on the GUI front) when it comes to usability for end users. Apps like OpenOffice are quite feature packed, and it’s easier for your users to master the slight learning curve than for the entire organization to sink in an anti-piracy raid.</li>
<li><strong>Lack of defined IT and information security policies:</strong> This issue by itself presents mindset and enforcement challenges associated with regulatory compliance for an SMB. It’s a herculean task to harness the habits of users running loose for so many years on work computers. Even if you manage it, think of the travails when the issue moves up the ladder and you have to convince the top management not to run their laptops using admin level access (or not share passwords with their teenage kids).</li>
<li><strong>Insufficient or non-existent IT controls:</strong> Antivirus solutions that haven’t been updated in weeks, unfettered USB drive use, cracked software, unpatched servers, you get the picture.  Wifi security is yet another question mark.</li>
<li><strong>Malware ridden networks:</strong> Many SMBs ‘breed’ botnets and rootkits which are waiting to be misused by their perpetrators. Club these with fast Internet connections, and your LAN is probably being used to send spam or break into someone’s networks, even as we speak. Do your admins even know how to detect a rootkit? Or rather for that matter, how many admins bother?</li>
<li><strong>Inhouse admins going rogue:</strong> It’s quite common to find your own admins misusing their network privileges to download and run cracked software in SMBs due to lack of control over their activities (and this is based on personal experience).</li>
</ul>
<p>I can ramble all day about what’s wrong with SMB networks and systems, but that’s beside the point. Compliance may not make you the most liked person in the organization, but well, someone has to do the dirty job!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/heard-and-overheard/smb-compliance-revisited-password123/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Boarding call for medium business compliance</title>
		<link>http://itknowledgeexchange.techtarget.com/heard-and-overheard/boarding-call-for-medium-business-compliance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/heard-and-overheard/boarding-call-for-medium-business-compliance/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 10:39:22 +0000</pubDate>
		<dc:creator>Anilpatrick</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[IT act]]></category>
		<category><![CDATA[medium business]]></category>
		<category><![CDATA[regulation]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/heard-and-overheard/?p=17</guid>
		<description><![CDATA[The traditional Indian organization typically shrugs off compliance related IT concerns without a care — after all, most don't deal with foreign companies. But like it or not, compliance is headed your way, even if you don't have any foreign connections!]]></description>
				<content:encoded><![CDATA[<p>Compliance in various forms is almost here, and it will significantly affect Indian medium sized businesses over the next couple of years. As is usually the case, this trend will be primarily driven by regulations, followed by standards. One of the forerunners of this impending wave is the <a href="http://searchsecurity.techtarget.in/news/article/0,289142,sid204_gci1372824,00.html">Information Technology (Amendment) Act, 2008</a>.</p>
<p>With its immense potential for misuse (by the authorities, who else?), the Information Technology (Amendment) Act, 2008 presents a simple message for any Indian medium sized business that relies on IT — shape up or ship out (No wonder that the information security vendors, <a href="http://searchsecurity.techtarget.in/news/article/0,289142,sid204_gci1369637,00.html">consultants</a> and system integrators are <a href="http://searchsecurity.techtarget.in/news/article/0,289142,sid204_gci1378305,00.html">already drooling in anticipation</a>). Yet another compliance, but of significantly lesser impact to many Indian medium sized businesses, is the <a href="http://searchsecurity.techtarget.com/sDefinition/0,290660,sid14_gci1271112,00.html">Payment Card Industry Data Security Standard (PCI DSS)</a> if your organization works with credit or debit card payments. And these are just the tip of the iceberg.</p>
<p>The larger organizations have already mastered the art of compliance to a great extent, so it’s the medium sized business which is likely to be targeted by over enthusiastic IT Act enforcers. Don’t get me wrong, the Information Technology (Amendment) Act, 2008 does have its salient points. But the real danger lies in the Act’s enforcement, which is where your <a href="http://searchwinit.techtarget.com/news/article/0,289142,sid1_gci1249789,00.html">medium sized business needs to have its part clear</a>. If nothing else, it will help you keep your side of affairs manageable.</p>
<p>At the risk of sounding alarmist, I feel that the <a href="http://searchcompliance.techtarget.com/sDefinition/0,290660,sid195_gci1345114,00.html">need for compliance</a> is real for medium sized businesses — especially organizations which have had absolutely no control over inhouse IT systems over the years. Before you break off into a tizzy over this callous statement, just consider the term “objectionable material” as defined by the Indian law. This subjective term can undergo mutilation as per the whims and fancies of the enforcer. For example, the accountant forwarding naughty pictures is sufficient to land your entire organization in hot water with non IT-savvy Police authorities. Or worse, imagine what might happen if the “moral upkeepers” of Indian society decide that they don’t like your organization for some reason or the other. We don’t want to give them more fodder in our hard disks, do we?</p>
<p>I might be going over the top, but many Indian medium businesses have enough skeletons when it comes to their cable closets. Just to drop a hint, <a href="http://searchcio.techtarget.in/tip/0,289483,sid205_gci1376972,00.html">software licensing</a> issues itself should ring enough alarm bells. The sooner we give these ghosts a peaceful burial, the better it will be for all of us.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/heard-and-overheard/boarding-call-for-medium-business-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
