Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Thursday, August 9, 2007

Report - “Audit & Compliance Professionals: Survey on Identity Compliance”

A new report has been released by Ponemon Institute, called “Audit & Compliance Professionals: Survey on Identity Compliance”.

Based on an overview document provided by Ponemon, this survey reveals that “despite the importance internal auditors and corporate compliance professionals place on ensuring proper access to systems and data, .., the majority report inadequacies in current practice. 82% say a risk-based approach would be more effective. … Audit and compliance professionals are clearly struggling to gain control over issues at the heart of IT compliance, knowing who has access to what in your organisation”

In a nutshell, “this survey confirms poor communication, inefficiencies cripple IT compliance efforts”. The views of auditors and corporate compliance staff are examined. Findings from analysis of 845 responses indicate a set of inadequacies, including:

  • Reliance on Manual Processes;
  • Lack of Centralised Control;
  • Poor Collaboration and Communication;
  • Inattention to Business Risks.

More details about findings and instructions about how to download this report can be found here.

No comments: