skip to main content
column
Free Access

Seeking Compliance Nirvana: Don’t let SOX and PCI get the better of you

Published:01 September 2006Publication History
Skip Abstract Section

Abstract

Compliance. The mere mention of it brings to mind a harrowing list of questions and concerns. For example, who is complying and with what? With so many standards, laws, angles, intersections, overlaps, and consequences, who ultimately gets to determine if you are compliant or not? How do you determine what is in scope and what is not? And why do you instantly think of an audit when you hear the word compliance? To see the tangled hairball that is compliance, just take a look at my company. It is on the hook for SOX, as we are a publicly traded company; for a number of banks for the PCI DSS, also known as Visa CISP; for HIPAA; for CA 1786; and for the European Union, its member countries, Japan, Korea, and a handful of other countries’ privacy and data security laws.

Index Terms

  1. Seeking Compliance Nirvana: Don’t let SOX and PCI get the better of you

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in

          Full Access

          • Published in

            cover image Queue
            Queue  Volume 4, Issue 7
            Compliance
            September 2006
            37 pages
            ISSN:1542-7730
            EISSN:1542-7749
            DOI:10.1145/1160434
            Issue’s Table of Contents

            Copyright © 2006 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 1 September 2006

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • column

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader

          HTML Format

          View this article in HTML Format .

          View HTML Format