Compliance Spending Found Profitable
The IT Policy Compliance Group (IT PCG) has published its ann
ual report on IT Governance, Risk and Compliance. The 2008 Report, which can only be downloaded by members, looks at research conducted with more than 2600 organizations.
According to the published brief, security and compliance spending can lead to higher profits, lower expenses and improved customer satisfaction. Although many companies dread spending on compliance and security, even with the risks associated with cost-cutting methodologies, the report indicates that companies that move up the IT governance, risk and compliance (IT GRC) maturity scale are seeing a high return on their efforts.
IT GRC encompasses practices to deliver greater business value from IT strategy, investment and alignment, as well as mitigating risk and conforming to compliance mandates. What the data shows us is that IT GRC mature companies enjoy higher revenues & profits while spending less on regulatory compliance. These best practices also lead to a reduced risk if a data loss were to occur - from .4% of revenue in mature organizations vs 9.6% for less mature companies.
Those companies considered most mature were not necessarily large business, but businesses that have effectively adapted security process frameworks to their businesses. Less-mature companies tend to over-focus on operational process frameworks.
You can continue reading about this report from Network world, where there’s a great overview.



Who Breached: Graphic Data (holding 3rd party data)
Health Insurance Portability and Accountability Act (HIPAA). The new consortium that will create these best practices is called the 




The article weighs the cost of encryption technologies, which can be low, with the higher cost and complexity associated with key management and recovery. Andreas talks a good deal about 

Recent Comments
10/07/2008 11:32 am
1 Comment
10/06/2008 04:15 am
1 Comment
09/30/2008 08:15 am
1 Comment
09/09/2008 12:06 pm
2 Comments
08/29/2008 10:13 pm
1 Comment