Home > Domino News > Embrace system compliance before it's too late
Domino News:
EMAIL THIS

Embrace system compliance before it's too late

By Brian Eastwood, Assistant Site Editor
18 May 2005 | SearchDomino.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Lax e-mail and document retention policies, unsecured servers and inadequate backup plans can land an administrator in the unemployment line, on the witness stand or even in jail. Avoiding such a fate means knowing the basics of compliance.

Christopher Byrne, of the Assurance and Compliance Practice at The Cayuga Group LLC, gave administrators several tips for staying ahead of the game during a breakout session on the first day of Admin2005, the Notes/Domino education and training event in Boston.

Obvious compliance issues stem from regulations like the Sarbanes-Oxley Act, Basel Capital Accord (Basel II), Health Insurance Portability and Accountability Act (HIPAA) and privacy laws, which differ depending on which continent you do business on.

However, Byrne said, compliance also involves internal policies governing the use of instant messaging, Web mail and music files. If an employee is fired for spending too much time in personal e-mail, even though the "no Web-based e-mail" rule is rarely enforced, there could be trouble -- especially if the admins themselves break that rule. "In this current environment, your management will not tolerate it," Byrne told a group of about 50 admins from both public and private companies. "You may think you have great policies in place, but you don't."

The first step toward achieving compliance is risk assessment. "Risk assessment is a subjective process. There's nothing objective about it. It should always be the first thing done," Byrne said. "Risk can never be totally eliminated." He divides risks into threats (financial loss, blackmail, sabotage and disclosing confidential or embarrassing information) and vulnerabilities (compromised passwords, ill-defined policies and a lack of end-user training).

An internal system audit, involving every department within an enterprise, will identify threats and vulnerabilities, Byrne said. Create a user survey on topics like e-mail use, then use the results to build or amend your policies and save them in a Notes database. Even if management knows the risks are there but opts not to do anything about it, Byrne said that's better than not knowing the risks exist at all.

Byrne recommended http://www.auditnet.org as a good source for risk assessment process documents. AuditNet is a Web portal for auditors.

Another important step toward achieving compliance involves control frameworks, the best of which is COBIT (Control Objectives for Information and related Technology). More information on COBIT is available at http://www.itgi.org. "[COBIT] is the only standard generally accepted by auditors across the board," Byrne said. "It gives you a reference framework for management and users [as well as the] IS audit, control and security practitioners."

Byrne said there's no shortage of examples of what happens when control frameworks are missing -- payroll data ends up on the external Internet, the wrong people get access to Social Security numbers or steamy e-mail messages between adulterous colleagues go public and embarrass the entire company.

Tags: IndustryLotus Notes Domino ArchivingLotus Notes Domino Backup and RecoveryLotus Notes Domino Mailbox ManagementVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Industry
Lotus makes mobile partnerships and Notes Traveler top priorities
IBM Lotus to end Notes/Domino 7.x support
Are you ready for LotusLive hosted email services?
Getting ready for Lotusphere 2009
Managing and maintaining mobile devices on Lotus Notes Domino
Considerations for deploying mobile devices on Lotus Notes Domino
Admin2008: administrators and developers speak up
Developers mixed on direction of IBM Lotus R&D
IBM showcases Notes/Domino 8.5; new products at Lotusphere
Looking forward, IBM Lotus needs back-end improvements

Lotus Notes Domino Archiving
Avoid Lotus Notes Domino email archiving ACL issues with AdminP
Archiving Lotus Notes documents to a specified folder
E-discovery rules double-edged sword for CIOs
IM, blogs next target for litigation
Symantec peddles enterprise vault tool
Changing a Lotus Notes database mail file from 'archive' to 'mail'
Email archiving for SMBs: No experience required
School district hooks up affordable compliance archive
Exporting email from Lotus Notes to .EML messages
Email archiving: What's right for your enterprise?

Lotus Notes Domino Backup and Recovery
What is Notes 8.5's DAOS (Domino Attachment and Object Storage) feature?
Lotus Notes and Domino Server backup and recovery
How to automatically create a backup copy of your Domino Directory
Replication best practices for Lotus Domino disaster recovery
The truth about AutoSave in Lotus Notes/Domino 7
Restoring a corrupt Lotus Notes certlog.nsf file
Lotus Notes replication snafu: Accidentally deleted archived email
Nine steps to less expensive, more reliable backups
Microsoft repackages e-mail hosting service
Error restoring an NSF archive file: 'File truncated - file may have been damaged'

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Lotus Notes Server Solutions - Quickr, Domino Server, Websphere
HomeTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersDomino IT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts