SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Case Studies and Best Practices From Canada and Internationally

Software helps companies comply

Software helps companies comply

By:  Vanessa Ho  On: 30 Mar 2006 For: ComputerWorld Canada Creator

New software from Symantec Corp. may help make it easier for organizations to comply with various regulations like Sarbanes-Oxley and PIPEDA. Released in March, Symantec BindView Policy Manager 3.0 allows organizations to do three key things to help with policy and compliance management, according to Indy Chakrabarti, product-marketing manager for Symantec.

New software from Symantec Corp. may help make it easier for organizations to comply with various regulations like Sarbanes-Oxley and PIPEDA.

Released in March, Symantec BindView Policy Manager 3.0 allows organizations to do three key things to help with policy and compliance management, according to Indy Chakrabarti, product-marketing manager for Symantec.

The offering lets organizations create policies by either importing existing ones or using sample templates provided in the program. Using these templates, it is possible to create a malware policy that states anti-virus is installed, up-to-date and running in the organization as well as attest that people have read that policy.

Policy Manager also allows organizations to validate compliance with regulations and frameworks, something for which many organizations have often struggled, said Chakrabarti.

”It can take large organizations forever to do audits for compliance. They will have multiple audits ongoing and have to redo audits for every regulation in every quarter,” he said. Auditors are usually working from multiple spreadsheets with hundreds of sub-objectives or policies to make sure they are complying with multiple regulations, he added.

Chakrabarti said Policy Manager eases the workload on auditors by breaking down all regulations and frameworks into basic units that are common across all and allows links to those units in order to control statements that might, for example, ensure anti-virus is installed within the organization. Through these links an organization can demonstrate compliance with required regulations, he said.

The software also lets organizations demonstrate compliance. Policy Manager places all compliance information gathered from different IT administrators and anti-virus tools, backup and data protection programs into one location rather than having to obtain the information from individual sources each month. For example, information that showed anti-virus did run on a particular server would be stored with the malware policy.

However, Chakrabarti said Policy Manager only informs organizations that there are compliance problems. It doesn’t fix them. If the program discovers any non-compliant servers or workstations, then a second software program such as Symantec’s Compliance Manager 3.0 is needed to solve the problem.

“Regulations actually require you to have segregation of duties where one person reports on compliance issues and another fixes things,” Chakrabarti said.

James Quin, a senior research analyst with London, Ont.-based Info-Tech Research Group, said using policy management software like Symantec’s provides savings. He said it costs an average public company millions of dollars a year to hire third-party compliance auditors. “Sarbanes-Oxley compliance is a specialized field and requires a significant amount of manpower,” Quin said. Having a tool that easily validates compliance shortens the time required to prove compliance and cuts the cost, he said.


Sign up for our Newsletters












Print |  Views: 826   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Vanessa Ho Vanessa Ho is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.