Industry Concerns for the Assessment Site

written by: Sean Martin; article published: year 2008, month 01;


In: Root » Business » Customer services » Industry Concerns for the Assessment Site

Dutch French Spanish Portuguese Italian German Japanese Chinese Korean Russian Arabic Bookmark and Share this Article

An issue of major importance is the industry in which the customer organization conducts its business. The amount of legislation, regulation, and industry-related practices that influence the way organizations are run today is phenomenal. It can be a daunting task to merely keep up with the overall legislation that rapidly changes on a regular basis, let alone all the industry-specific or best-practice components that impact information security requirements. You will be asking your customer organization’s POC for this information, but he or she may not know it all. That is why we usually recommend that you create a base list of questions and ask in a yes/no format whether these specific rules or guidelines apply in the customer environment. This approach might help jog the memory or understanding of the people you are working with. Then, of course, the last question would be a little more open-ended. Here are a few examples of base issues:

- Health Insurance Portability and Accounting Act of 1996 (HIPAA)

- National Institute of Standards and Technologies (NIST)

- Sarbanes-Oxley

- Gramm-Leach-Bliley (GLB)

- Financial Management and Accountability (FMA) Act

- Federal regulations

- What other regulations, legislation, and guidelines do you follow?

- Family Education Rights and Privacy Act (FERPA)

As you can see, we have touched on only a few issues here; many more could come into play, depending on the customer organization’s industry. The federal regulations alone can fill multiple pages. Since these areas vary widely and carry a large amount of detailed information, personnel resources with the understanding of the regulations in your specific upcoming environment can often be more difficult to schedule than technical resources, so be sure to find out this information as soon as possible.

Disclaimer

1) E-articles is not responsible for the information contained by this article as well for any and all copyright infringements by authors and writers. E-articles is a free information resource. If you suspect this article for any copyright infringement, please read the terms of service and contact us to investigate the problem.
2) E-articles is not responsible for inaccuracies, falsehoods, or any other types of misinformation this article may contain and will not be liable for any loss or damage suffered by a user through the user's reliance on the information gained here.

link to this article