(Length: 18 pages)

March 30, 2004

Demystifying Compliance

Incorporating Compliance Management Into The Business

by Michael Rasmussen

with Steve Hunt, Natalie Lambert


Executive Summary (This is a document excerpt)

Business and financial integrity, privacy, information security, business continuity, and homeland security all place significant regulatory demands on organizations. Faced with the challenge of meeting multiple sets of requirements from regulators and business partners, organizations are confused about how to approach compliance management. To succeed in compliance management, organizations need to have a defined strategy about how to integrate compliance into the organization. Successful compliance management involves: 1) accountability — understanding that executive management and the board are ultimately accountable for compliance; 2) governance — establishing a culture of compliance in the organization; 3) responsibility — appointing someone to be in charge of compliance management; 4) understanding — identifying what the regulators are looking for; 5) architecture — developing a compliance control architecture; and 6) validation — verification that controls are in place and functioning properly.

Buy Risk-Free

Download and print PDF immediately. Price: US $499

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

TABLE OF CONTENTS

NOTES & RESOURCES

itemThe Compliance Mandate

itemExecutives And The Board Are Accountable

itemGovernance Is The Cornerstone Of Compliance

itemAssigning Responsibility For Compliance

itemUnderstand What Regulators Are Looking For

itemBuilding A Compliance Architecture

itemValidating Compliance

Recommendations

itemSatisfying Regulatory Requirements

What It Means

itemCompliance Management Needs To Be A Defined Business Process

Alternative View

itemWhat Do I Need To Do To Get By?

In developing this report, Forrester drew from analyst experience and insight, as well as primary research through advisory consulting and inquiry discussions with clients across industry sectors.

Related Research Documents

itemTackling Security Compliance Challenges

February 27, 2004, Quick Take

itemSecurity Knowledge Management: Defining The CISO Dashboard

January 1, 2004, Planning Assumption

itemEnterprise Risk Management: Beyond the IT Department

September 24, 2003, IdeaByte

itemEnterprise Security Architectures — Organizational Pressures On Information Protection

September 24, 2002, Planning Assumption

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.

Technology: Governance, Risk, & Compliance, IT Management, IT Strategy, Planning, & Governance, Security & Risk, Security Operations
Geography: Asia Pacific, Europe, North America

Archived Teleconference:
corner border corner
Ratings and Comments
NOT YET RATED
corner border corner