The most popular and comprehensive Open Source ECM platform
Compliance: Multiple Regulations? Merge and Conquer
There are a lot more regulations under the umbrella of compliance than just Sarbanes-Oxley (SOX). IT groups, especially those in the financial services area, are under pressure to comply with multiple regulations from federal and state governments that may include BASEL II, Patriot Act, GLBA, PCI, SEC 17a3-4 (Email Retention), and CA SB 1386. But there’s more. Consider HIPAA, 21CFR11, and don’t forget the non-US equivalents to these and other regulations. In the US there are more than 100 such regulations. And this doesn’t include regulations relative to a specific industry.
Standardized frameworks or methodologies have grown up that try to address specific regulations. Rather than starting from scratch, the framework saves companies money by outlining a proven set of best practices. The CobiT (Control Objectives for Information and related Technology) framework is often used when addressing Sarbanes-Oxley. Guidelines from FFIEC (Federal Financial Institutions Examination Council) is a framework targeting GLBA (Gramm-Leach-Bliley Act) compliance. ISO 17799/27001 security guidelines are often used to ensure compliace with HIPAA.
Ideally, for enterprises to address compliance across multiple regulations, a comprehensive global approach to policy is needed. But that isn’t easy. Manually mapping requirements point by point from individual regulations into a common company policy can be daunting, especially given the ever evolving nature of the regulations. Fuzzy mappings complicate the process: similar, but not identical, requirements can create problems in determining how to deal with conflicts. Many IT organization attempt to build in-house multi-purposed compliance systems but often give up because of the complexity.
Some software companies are now creating solutions to address compliance when multiple regulations are involved. Software-based Common Contol Frameworks allows a company to create a single policy, a sort of Compliance Management System (CMS). These systems can merge the rule-sets from regulations and can identify how changes to any one particular rule would affect any other control or policy in the system. Reports can be generated that detail compliance status with respect to a specific regulation.
With the ever-growing complexity surrounding compliance and multiple reguations, it seems only natural that custom software solutions would evolve to address the problem.













