The majority of organizations - 64 percent - with poor regulatory audit results are the exact same firms with the most loss of or theft of sensitive data (Figure 1).
Figure 1: Firms with the most data loss and theft

Source: IT Policy Compliance Group, 2007
Guidance recommendations
The evidence is in: if you want to protect sensitive data, you have to put in place the same procedures, controls, objectives, and practices that make for successful regulatory audits.
· Benchmark your own regulatory audit results against the industry
· Identify your strengths and weaknesses
· Gather organizational support for making the needed changes to improve results
© IT Policy Compliance Group, 2007
|