Compliance is about the Culture
In this SearchSecurity.com video, Eric Holmquist (holmquistadvisory.com) discusses how the holy grail of compliance is building a streamlined program that can easily accommodate the changing regulatory environment.
At 7:00 he outlines the importance ofAwareness,
Accountability,
Action-ability.
Accomplishing this is not possible by executing a check-list. It can only be made possible through the implementation of an institution-wide program. Risk Management and Compliance should no longer be the once a year "circle the wagons!" activity. At 17:45, he points out that the key is "getting compliance baked into the culture". Eric says that the people we rely on for compliance in our institutions are not really excited about compliance. We need to have it as part of every one's regular work day. Are you implementing programs that will 'bake compliance into your culture"? Successes? Challenges?http://searchsecurity.bitpipe.com/detail/RES/1248818843_233.html&li=234183?asrc=EM_DWC_9093274&uid=9089723 <Requires registration to Techtarget>
Posted by Denis ONeil CISSP