Home > Ask the Data Center Experts > Governance, risk management and compliance strategies Questions & Answers > How do we make sense of vendors pitching compliance products?
Ask The Data Center Expert: Questions & Answers
EMAIL THIS

How do we make sense of vendors pitching compliance products?

Adrian  Bowles EXPERT RESPONSE FROM: Adrian Bowles

Pose a Question
Other Data Center Categories
Meet all Data Center Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 27 April 2005
Is there any way to make sense of vendors pitching compliance products? Should we be looking to software vendors to provide tools to help us maintain regulatory compliance?

>

The potential downside of compliance errors has struck fear with CFOs, CEOs, and now CIOs, so it is no surprise that virtually every software vendor has added a compliance spin to their message. As we approach the 30th anniversary of the Pet Rock phenomenon, caution is in order for those tempted to buy based on packaging rather than functionality. Four simple principles should guide your decisions:

  1. Improved processes for governance, security and privacy can meet many compliance requirements. Nothing beats software for process monitoring, management and reporting, so a complete solution will be software-aided if not software-centric.
  2. No application is a substitute for vigilance. Software should be part of the solution, but human processes are critical. Beware of IT solutions that promise too much.
  3. Everything that can be audited should be audited. Well, that might not be true, but it is likely to be the position of your auditors, who tend to be a conservative bunch. Our position is that all data used to manage your business should be created and managed by processes - including the software and people involved - that may be audited if desired. Tools are available to audit databases, and enterprise applications now offer auditing features, so this should be a requirement for all new systems.
  4. The basic rules for vendor due diligence have not changed with the advent of compliance requirements. Exercise caution when dealing with new vendors, but don't rule them out based solely on size or longevity. Partial solutions for compliance problems are coming from established players and upstarts, and neither has a monopoly on innovation. Stick to the fundamentals when evaluating technical merit and business viability. The new requirement is to involve the appropriate domain experts from finance and legal when the regulations make their inclusion in the review process appropriate.


BROWSE BY TAG
Governance, risk management and compliance strategies,   Managing data center outsourcing services and vendors,   Data center operations management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Governance, risk management and compliance strategies
How often should we be recertifying users of key systems?

Managing data center outsourcing services and vendors
Data center outsourcing best practices and pitfalls to avoid
IT services consolidation: Data centers weigh risks
Big IT shops look to rent data center facilities
IT managers offer tips on cutting data center costs
Data centers deal with the fallout of mergers and acquisitions
FBI raids Dallas data center colocation company
Texas Memory Systems increases solid-state disk capacity: News in brief
CRG West preps data centers for cloud computing customers
Data center panel weighs cloud computing risks, rewards
Disaster recovery strategies: Should you outsource, manage in-house or partner?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
indemnification  (SearchDataCenter.com)
on-demand computing  (SearchDataCenter.com)
TCO  (SearchDataCenter.com)
Teraplex  (SearchDataCenter.com)
utility computing  (SearchDataCenter.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Building Green Data Centers
HomeNewsTopicsITKnowledge ExchangeTipsBlogsMultimediaWhite PapersEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2005 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts