None
FR
Seeking Compliance Nirvana: Don’t let SOX and PCI get the better of you
Greg A. Nolann
ACM Queue - Compliance
Seeking Compliance Nirvana Don’t let SOX and PCI get the better of you Greg A. Nolann Compliance. The mere mention of it brings to mind a harrowing list of questions
and concerns. For example, who is complying and with what? With so many standards,
laws, angles, intersections, overlaps, and consequences, who ultimately gets
to determine if you are compliant or not? How do you determine what is in scope
and what is not? And why do you instantly think of an audit when you hear the
word compliance?
To see the tangled hairball that is compliance, just take a look at my company.
It is on the hook for SOX (Sarbanes-Oxley Act of 2002), as we are a publicly
traded company; for a number of banks for the PCI DSS (payment card industry
data security standard), also known as Visa CISP (Cardholder Information Security
Program); for HIPAA (Health Insurance Portability and Accountability Act);
for CA 1786 (and all other states’ disclosure laws); and for the European
Union, its member countries, Japan, Korea, and a handful of other countries’ privacy
and data security laws (these alone could probably spawn an entire series of
lessons and lectures!).