<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!-- SwishCommand noindex -->
<rss version="2.0">
<channel>
  <title>ComplianceHome: SOX White Papers</title>
  <link>http://www.compliancehome.com/</link>
  <description>ComplianceHome is one of the Web's largest library of resources for compliance management of HIPAA, SOX, FISMA, GLBA, FDA, FFIEC, Basel II, OSHA and ISO 27002/17799. Visit our directories which are the best source on White papers, related news articles, resources on the web, training, webinars, conferences, rules &amp; regulation overview, ask the expert, job and search on vendors, solutions &amp; products.</description>
<image>
  <url>http://www.compliancehome.com/images/rsslogo.gif</url>
  <title>ComplianceHome</title>
  <link>http://www.compliancehome.com/</link>
</image>
  <language>en-us</language>
  <item>
    <title>Using The Hitachi ID Management Suite to Comply with The Sarbanes-Oxley Act of 2002</title>
    <pubDate>Mon, 18 Jul 2011 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract12050.html</link>
    <description>This document includes a brief overview of the Sarbanes-Oxley Act of 2002 (SOX), and describes how it impacts information security in publically traded, US-listed corporations. The Hitachi ID Identity Management Suite is then introduced, and its use to comply with SOX requirements is described. Please note that this document does not constitute legal advice. This document represents the best understanding of Hitachi ID of the relevance of this legislation to information security in general and to identity management in particular.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract12050.html</guid>
  </item>
  <item>
    <title>Mitigating IT Security Risks with Penetration Tests</title>
    <pubDate>Wed, 20 Oct 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract12000.html</link>
    <description>Penetration Testing should do more than assess the external network for obvious flaws.  Discover how enhancing the penetration testing process will ultimately lead to a stronger and more compliant security posture.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract12000.html</guid>
  </item>
  <item>
    <title>The File Transfer Balancing Act  Achieving Compliance Without Compromising Business Agility</title>
    <pubDate>Tue, 25 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11961.html</link>
    <description>The global economy is pushing businesses in virtually every industry to work faster and smarter. The company that cant respond to a customer need almost immediately is destined to lose out to a more nimble competitor that can meet that need. It comes down to agility  how fast a company can adapt to change and respond to demands. This white paper discusses the issues important in designing a process for user-to-user secure file transfer that simultaneously enhances business agility while ensuring that your methods for handling private information adhere to your security and privacy policies. The solution described in this white paper has been chosen by numerous companies in industries that are regulated by Sarbanes-Oxley, HIPAA and other legislation in order to increase their security posture. Read this white paper to learn more</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11961.html</guid>
  </item>
  <item>
    <title>The Top Six Risks of Employee Internet Use and How to Stop Them</title>
    <pubDate>Tue, 25 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11960.html</link>
    <description>When it comes to your employees' use of the Internet, it isnt wise to underestimate the potential for damage to your organization. From a network used by dedicated scientific intellectuals devoted to honest research, the Internet has grown to become the worlds biggest clearinghouse for information of all kinds. At the same time, it has become a haven for inappropriate behavior and systems attacks, as well as posing a liability for any company that doesnt appropriately manage their employees' Internet use. Due to the serious nature of many threats, the Internet use of even one unmonitored employee on a single unmanaged system can ravage a companys internal network, irrevocably delete critical data, and ultimately ruin the companys ability to conduct business. Situations like this arent works of fiction, but actual everyday occurrences for organizations with unprotected networks. Read this white paper to learn more about how to protect your organization from these threats.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11960.html</guid>
  </item>
  <item>
    <title>Building Secure File Transfer Processes that Improve Security and Compliance</title>
    <pubDate>Tue, 25 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11959.html</link>
    <description>Protecting information assetsconfidential intellectual property, sensitive customer data, financial information or private patient informationcontinues to be a top-of-mind issue for all enterprises. A data breach that reveals sensitive information can be costly and devastate the reputation of your organization. There are ways to avoid the situation with the improved ability to secure email attachments and other file transfers. Read this whitepaper to learn about the issues important in selecting a solution for user-to-user secure file transfer that ensures methods for handling sensitive information, adherence to security and privacy policies, and compliance with government mandates for sensitive data handling. Learn how Accellion Secure File Transfer meets these requirements for secure file transfer and seamlessly supports business process agility.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11959.html</guid>
  </item>
  <item>
    <title>Two-Way Communication, Now That's an Idea!</title>
    <pubDate>Mon, 17 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11945.html</link>
    <description>Although one-way communication is often a reality, communication is more effectively viewed as a two-way process in the exchange of information for a mutual goal. My children frequently remind me of this when I quickly pre-judge them based on my sole perspective without their input. While a two-way communication process clearly makes sense, its integration in the business world is often not effective. This includes communications between a companys board and its external auditor.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11945.html</guid>
  </item>
  <item>
    <title>Wireless Security: Ensuring Compliance with HIPAA, PCI, GLBA, SOX, DoD 8100.2 &amp; Enterprise Policy</title>
    <pubDate>Mon, 03 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11937.html</link>
    <description>Just like wired networks, 802.11 wireless LANs require network policies that are designed, implemented, and enforced to maximize network performance and reduce exposure to the inherent security flaws in 802.11 wireless LANs. The many benefits and expected return on investment of a wireless LAN can be wiped out if a security and management policy is not in place and enforced. This paper is designed to guide network administrators and security managers to design, implement, and enforce wireless LAN security policies that enable every organization to fully reap the benefits of wireless LANs without experiencing undue management pains and security holes. This paper will also cover how organizations can comply with regulatory policies like HIPAA, PCI, GLBA - Safeguards Rule, DoD 8100.2, Sarbanes-Oxley Act etc.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11937.html</guid>
  </item>
  <item>
    <title>The Economic Benefits of the Sarbanes-Oxley Act?: Evidence From a Natural Experiment</title>
    <pubDate>Wed, 28 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11936.html</link>
    <description>Section 404 of the Sarbanes-Oxley Act (SOX) requires firms with a public float over $75 million during 2002-2004 to file management reports beginning in 2004, but firms with a smaller float in each of the three years do not need to comply until the end of 2007. Relative to firms that could delay compliance, mandatory filers cut CEO compensation and financial slack, increase ownership by insiders, raise payouts to shareholders, and slow investment growth. These firms experience no change in borrowing costs but enjoy access to longer-term public debt.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11936.html</guid>
  </item>
  <item>
    <title>Integrating The Recent COSO Monitoring Guidance With Your Company's SOX Compliance</title>
    <pubDate>Tue, 13 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11930.html</link>
    <description>Many companies complying with the Sarbanes-Oxley Act of 2002 and subsequent legislation continue to place emphasis on updating process controls and performing transactional testing on an annual basis. Recent guidance released by COSO (the Committee of Sponsoring Organizations) in early 2009 highlights the opportunity for companies to increase the focus on the monitoring component of internal control first addressed in the 1992 COSO framework and the 2006 COSO guidance, Internal Control over Financial Reporting - Guidance for Smaller Public Companies.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11930.html</guid>
  </item>
  <item>
    <title>The Economic Benefits of the Sarbanes-Oxley Act?: Evidence From a Natural Experiment</title>
    <pubDate>Wed, 31 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11913.html</link>
    <description>Section 404 of the Sarbanes-Oxley Act (SOX) requires firms with a public float over $75 million during 2002-2004 to file management reports beginning in 2004, but firms with a smaller float in each of the three years do not need to comply until the end of 2007. Relative to firms that could delay compliance, mandatory filers cut CEO compensation and financial slack, increase ownership by insiders, raise payouts to shareholders, and slow investment growth. These firms experience no change in borrowing costs but enjoy access to longer-term public debt.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11913.html</guid>
  </item>
  <item>
    <title>SOX and Its Effects on IT Security Governance</title>
    <pubDate>Wed, 31 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11912.html</link>
    <description>The Sarbanes-Oxley (SOX) Act is a United States federal law enacted on July 30, 2002 in response to a number of major corporate and accounting scandals including those affecting Enron, Tyco International, Adelphia, Peregrine Systems and WorldCom. This paper discusses the effects of Sarbanes-Oxley (SOX) Act on corporate information security governance practices.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11912.html</guid>
  </item>
  <item>
    <title>Sarbanes-Oxley, Governance and Performance</title>
    <pubDate>Sat, 27 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11905.html</link>
    <description>The author studies the impact of Sarbanes-Oxley Act (SOX) on the relationship between corporate governance and company performance. Five measures of corporate governance are considered during the period 1998-2007. The author finds a negative and significant relationship between board independence and operating performance during the pre-2002 period, but a positive and significant relationship during the post-2002 period. The stock ownership of directors is consistently positively and significantly related to performance for both sub-periods.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11905.html</guid>
  </item>
  <item>
    <title>The Sarbanes Oxley Act of 2002: Implications for Compensation Contracts and Managerial Risk-Taking</title>
    <pubDate>Sat, 27 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11904.html</link>
    <description>This paper shows that the period following the passage of the Sarbanes Oxley Act of 2002 (SOX) is associated with a significant reduction in compensation-based incentives to take risk, which is related to a decline in risky investments. Moreover, consistent with the rules in SOX directly affecting CEOs' incentives to take risk, the document that the decline in risky investments exceeds the amount that would be expected from changes in compensation packages alone. Finally, the paper documents that these effects are robust to controlling for the market decline in 2000/2001 as well as the passage of SFAS 123R.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11904.html</guid>
  </item>
  <item>
    <title>Assessment of the Sarbanes-Oxley Act on the Firm Using a Difference-in-Difference Estimator</title>
    <pubDate>Sat, 27 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11903.html</link>
    <description>The Sarbanes-Oxley Act (SOX) of 2002 which is also known as the Public Company Accounting Reform and Investor Protection Act promulgates the importance of effective internal control systems after a series of accounting scandals in the early 2000's in which firms misreported their earnings. The main objective for the implementation of SOX is to improve the quality and transparency of financial reports and provide investors more confidence in these financial reports by focusing more on internal controls of financial reporting by firms. More importantly, Sections 302 and 404 of this Act require publically traded companies to certify the effectiveness of their internal controls and assessment by its management that the internal controls implemented are adequate.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11903.html</guid>
  </item>
  <item>
    <title>Risk Assessments: The Key To Continuous Compliance</title>
    <pubDate>Sat, 27 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11896.html</link>
    <description>Most financial institutions lack internal resources or the technical expertise necessary to identify all of the risks to information security, making a correct evaluation of risk extremely difficult if not impossible. Therefore, without knowing where threats exist, or their potential severity, within their information systems, a financial institution is ill prepared to combat a threat, mitigate the costs of a breach or even face a Federal or State examiners prying eyes. This white paper explains the value of having qualified experts properly identify and evaluate information risk through a comprehensive risk assessment.  It also shows how developing a continuous risk management program, thus continuous compliance, can benefit the entire organization in a cost-effective manner.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11896.html</guid>
  </item>
  <item>
    <title>The Economic Benefits of the Sarbanes-Oxley Act?: Evidence From a Natural Experiment</title>
    <pubDate>Thu, 18 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11890.html</link>
    <description>Section 404 of the Sarbanes-Oxley Act (SOX) requires firms with a public float over $75 million during 2002-2004 to file management reports beginning in 2004, but firms with a smaller float in each of the three years do not need to comply until the end of 2007. Relative to firms that could delay compliance, mandatory filers cut CEO compensation and financial slack, increase ownership by insiders, raise payouts to shareholders, and slow investment growth. These firms experience no change in borrowing costs but enjoy access to longer-term public debt.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11890.html</guid>
  </item>
  <item>
    <title>Qualys - Using Qualys Guard To Meet Sox Compliance &amp; IT Control Objectives</title>
    <pubDate>Thu, 18 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11889.html</link>
    <description>Currently, there is no single standard framework that explicitly defines what your organization must do for compliance. A big challenge for IT security professionals is navigating this ambiguity and achieving the organization's compliance goals effectively and on budget. This guide covers seven typical IT security compliance errors and outlines the best practices you can immediately apply to your environment to help your company achieve compliance.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11889.html</guid>
  </item>
  <item>
    <title>Managing Transaction Tax Audit Risk</title>
    <pubDate>Thu, 18 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11888.html</link>
    <description>Audits are a fact of life - surveys show 90% of businesses are audited at least once per year. Even in the best economic times, businesses need to be vigilant against unnecessary costs and risks. In challenging times such as these, it's even more critical to avoid missteps, protect cash flow, and derive maximum value from people and processes. This whitepaper from Sabrix tax experts will navigate you to learn how you can protect precious cash flow by proactively addressing audit risk.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11888.html</guid>
  </item>
  <item>
    <title>McAfee Total Protection for Secure Business</title>
    <pubDate>Thu, 18 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11887.html</link>
    <description>Medium size businesses are plagued by the same security risks that the largest enterprises face on a daily basis, but they typically lack the time, budget and IT resources to adequately protect themselves against all of todays sophisticated threats. The list is long and daunting: Trojans, botnets, spam, spyware, malicious web sites, data loss, and data theft. Medium businesses need to enforce acceptable use policies for email and the web, and ensure compliance with government data privacy regulations. A single hacker attack, a single misplaced laptop containing confidential data, a single infected device could cripple a medium size business. McAfee helps keep small and medium businesses like yours protected with a smart, simple, secure solution designed for small and medium enterprise customers. McAfee Total Protection for Secure Business provides comprehensive endpoint, email, web, and data security - all in a single, integrated suite. Best of all, the suite is available from one ve</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11887.html</guid>
  </item>
  <item>
    <title>Effective Information Security: A Win-Win Proposition for the Enterprise and IT</title>
    <pubDate>Mon, 15 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11883.html</link>
    <description>Driven by an accelerated increase in identity theft, consumer fraud, and other personal informationrelated thefts, industry groups and federal and state governments have taken aggressive steps to hold companies and their management accountable for confidential information disclosures. Similarly, enterprises are facing significant challenges in preventing the theft or accidental disclosure of intellectual property (IP) and corporate trade secrets. Ultimately, the challenge of establishing and implementing effective personal information and IP protection solutions falls upon the shoulders of IT management and staff. Securing personally identifiable information (PII) and IP has become a high priority for enterprise management and IT. Read this IDC paper to learn more.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11883.html</guid>
  </item>
  <item>
    <title>Top 10 Steps to Protecting Your Organizations Privacy Data</title>
    <pubDate>Mon, 15 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11882.html</link>
    <description>With numerous news stories detailing public data breaches that have led to sensitive data getting releasedon websites, stolen as part of a laptop theft, or even released accidentally over an email or instant messageorganizations are increasingly under pressure to protect privacy data. Over the last few years, this challenge has been compounded by increasing compliance regulations that can mean fines or even jail time if privacy data is mishandled. In California and other states that have enacted similar laws, organizations are now forced to publicly disclose if computerized data files have been compromised by unauthorized access that might open up the risk for identity theft. The impact on privacy data leaks can impact an organizations brand and public reputation, not to mention put its customers, employees and partners at serious risk. This white paper presents the top ten regulatory compliance requirements to consider when selecting a privacy data protection solution.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11882.html</guid>
  </item>
  <item>
    <title>Demonstrating the ROI for SIEM: Tales from the Trenches</title>
    <pubDate>Tue, 09 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11877.html</link>
    <description>Security professionals sometimes struggle to demonstrate the return on investment for new solutions. Showing clear long-term cost savings or conducting a total cost of ownership (TCO) comparison is a very effective way to show the value of a security investment. Doing so also allows the security team to align with management to make a positive contribution to the business. In this whitepaper, we look at several examples where significant cost savings are demonstrated and the cost of purchase of security information and event management (SIEM) technology has been realized in short periods of time following the SIEM implementation.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11877.html</guid>
  </item>
  <item>
    <title>Mastering The Complexity Of Revenue Management</title>
    <pubDate>Tue, 09 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11876.html</link>
    <description>With complex regulations, continually evolving interpretations and stiff penalties, the mission-critical task of revenue management is more complex than ever. 66% of companies fail to evaluate the revenue impact of deferred revenue, and a whopping 92% of public companies say they still use spreadsheets for critical revenue-accounting tasks, leaving them exposed to a host of issues including compliance, audit and forecasting problems.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11876.html</guid>
  </item>
  <item>
    <title>Blueprint For Sustainable Compliance Solutions</title>
    <pubDate>Tue, 09 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11875.html</link>
    <description>Redwood Software uses its unique combination of process automation and information management technologies to provide practical solutions for sustainable compliance that also deliver measurable business value. The blueprint that we offer here promises a sustainable solution for compliance with Sarbanes-Oxley and other corporate governance requirements while taking advantage of both the lessons learned during the first phases of compliance and the processes and systems that are already in place.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11875.html</guid>
  </item>
  <item>
    <title>Data Archiving: The First Step Toward Managing the Information Lifecycle</title>
    <pubDate>Tue, 02 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11870.html</link>
    <description>Where data archiving is about performance, Information Lifecycle Management is about compliance. The distinction isnt a break with the past C its an evolution. Dolphin helps organizations run crucial business operations better and smarter in SAP. The company has a history of success delivering higher performance and lower total cost of ownership by helping customers using SAP solutions plan and implement strategic ILM and data archiving programs. Read this white paper for a discussion of the business case for data archiving as the first step in an SAP ILM strategy; strategies for Data Archiving, Retention Management and the Retention Warehouse strategy for legacy decommissioning in SAP; and Dolphins bestpractices approach to an effective, long-term ILM strategy.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11870.html</guid>
  </item>
  <item>
    <title>Top Ten Essentials for Privileged Account Management</title>
    <pubDate>Sun, 14 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11860.html</link>
    <description>Properly defining, controlling and monitoring administrative privileges in IT systems continue to be significant challenges for organizations of all sizes. And while in the past, controlling privileged accounts made good business sense, today, it is mandated by regulations such as Sarbanes-Oxley (SOX) Section 404, the Federal and North American Energy Regulations Commission (FERC/NERC), HIPAA 2, and even state level regulations such as the California Information Practice Act and the Massachusetts privacy law 201CMR17. In addition to the increased potential for failing IT security audits, sharing root and other privileged accounts can lead to a significant increase in the risk of fraudulent activities by employees, an even bigger threat to corporate value.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11860.html</guid>
  </item>
  <item>
    <title>Sarbanes-Oxley Roadmap</title>
    <pubDate>Sun, 14 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11852.html</link>
    <description>This</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11852.html</guid>
  </item>
  <item>
    <title>Security Policy: Five Keys to User Compliance</title>
    <pubDate>Sun, 14 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11836.html</link>
    <description>Business users are a key part of a company's security, and even the most conscientious employees can introduce serious breaches of security policy.  IT can do everything in its power to secure the company's confidential documents--provide first-class security infrastructure, develop reasonable security policies and engage in extensive communication and training--yet still people fail to comply.  The solution is to provide security that helps people do their jobs more efficiently, thereby inducing users to follow best security practices without even knowing it.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11836.html</guid>
  </item>
  <item>
    <title>Data Disclosure - Threats and Control</title>
    <pubDate>Mon, 01 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11832.html</link>
    <description>One of the major challenges faced by the enterprise is the re-identification of de-identified data that leads to Data Disclosure. This paper discusses the scenarios which bring the need for de-identification of data and what leads to the data disclosure of such deidentified data .The paper aims to share insights that help Data Custodians in an enterprise, Security Auditor, Risk and Compliance Group, Data Security Subject Matter Expert and the curious minds of the database world.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11832.html</guid>
  </item>
  <item>
    <title>Extending Change Auditing To Exchange Server</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11831.html</link>
    <description>Microsoft Exchange Server, one of the most important production systems in many organizations, is a system consisting of many moving parts that need thorough and secure maintenance. In most companies, groups of two or significantly more IT professionals manage the E-mail infrastructure configuration and without detailed auditing of who did what, where, and when, it is not be possible to detect inadvertent or unauthorized changes to private E-mails with sensitive financial information. The white paper describes different approaches to regular and consistent auditing of changes to Exchange server configuration and permissions.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11831.html</guid>
  </item>
  <item>
    <title>Gaining Control Of Server Configurations</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11830.html</link>
    <description>Failure to maintain change documentation for managed servers is one of the worst things IT professionals can do. Even minor server reconfigurations can potentially impact users and cause major disruptions to business processes. Every time a change is made it must be properly documented for compliance purposes and communicated to all team members to ensure manageability. This white paper outlines major challenges related to management of changes in server configurations and summarizes possible solutions.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11830.html</guid>
  </item>
  <item>
    <title>Auditing SQL Server For Change Tracking And Compliance</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11829.html</link>
    <description>Database servers are typically managed by DBAs, but as long as they support line of business applications, such as CRM and ERP systems, they are frequently touched by application administrators, who change settings, database structure, and perform other tasks DBAs may not be aware of, bringing the question of auditing and compliance to the table for many organizations relying on database servers. This white paper describes the importance of auditing in MS SQL Server environments and suggests different ways of implementation.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11829.html</guid>
  </item>
  <item>
    <title>Auditing Active Directory Changes Efficiently</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11828.html</link>
    <description>Change auditing is one of the key processes that must be implemented in Active Directory in order to get control of changes done by multiple IT administrators, thus protecting sensitive financial information. One single change can put an entire organization at risk, introducing security breaches and compliance issues. Therefore 100% of changes must be tracked and carefully reviewed for possible violations. This white paper describes different approaches to change auditing in Active Directory, talks about their pros and cons.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11828.html</guid>
  </item>
  <item>
    <title>Staying Abreast Of Group Policy Changes</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11827.html</link>
    <description>Windows Group Policy controls essential security and operational aspects of most enterprises that rely on Microsoft-based infrastructure. Without fine-grained auditing of Group Policy, IT departments risk missing major changes that can adversely impact security and business continuity. This white paper describes the topic of auditing in detail and introduces several technologies that can help to overcome the challenge.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11827.html</guid>
  </item>
  <item>
    <title>Preventing Password Expiration Proactively</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11826.html</link>
    <description>Password expiration is a well-known pain for IT help desk personnel. Requests to reset expired passwords can build up to a sizable portion of the total help desk workload, costing both time and money. This whitepaper describes how to prevent password expiration issues proactively.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11826.html</guid>
  </item>
  <item>
    <title>Practical Change Auditing For Virtual Environments</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11825.html</link>
    <description>Virtualization brings great advantages to all organizations, but just like any other infrastructural component, it must be properly secured and audited for increased control of sensitive data and compliance. This white paper gives an overview of auditing in virtualization environments, such as VMware Virtual Center and Microsoft System Center Virtual Machine Manager, and introduces several auditing solutions.  RE</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11825.html</guid>
  </item>
  <item>
    <title>The Business Case For Account Lockout Management</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11824.html</link>
    <description>On the one hand, account lockouts provide a good base for implementing secure password policies and protecting private data. On the other hand, they cause a lot of burden to the IT help desk. The white paper covers the account lockout management process and introduces new cost-effective workflows of account lockout resolution, describing what significant ROI enterprises can achieve through the use of the automated management solutions.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11824.html</guid>
  </item>
  <item>
    <title>Self-Service Password Management</title>
    <pubDate>Fri, 22 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11823.html</link>
    <description>Password practices that improve security are by their nature burdensome to the user. Industry analysts find that 30% of all IT help desk calls are about password issues, at a cost averaging $30 to $60 per call. The solution that has evolved for this problem is called the Self-service Password Reset. The white paper below describes the common benefits and must-have features of the self-service password management solutions available on the market today</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11823.html</guid>
  </item>
  <item>
    <title>Tracking File Access For Auditing And Compliance</title>
    <pubDate>Mon, 18 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11821.html</link>
    <description>File access auditing is a critical requirement for organizations that rely on files to maintain their business critical data, such as accounting records, intellectual property, or patient data. Unauthorized and accidental access and/or changes in files, folder structure, or permissions, can facilitate data theft, render the organization non-compliant, and introduce security threats. This white paper describes the importance of file auditing and different approaches to implementation.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11821.html</guid>
  </item>
  <item>
    <title>Regulatory Compliance Alignment: Antivirus support of compliance with HIPAA, SO, GLB, PCI DSS and FISMA</title>
    <pubDate>Mon, 18 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11820.html</link>
    <description>The antivirus industry currently serves numerous vertical sectors and has done so for many years with great success. This report provides the information necessary to determine where antivirus solutions may help an organization to comply with the regulatory requirements.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11820.html</guid>
  </item>
  <item>
    <title>Health Plan Auditing: 100-Percent-Of-Claims Vs. Random-Sample Audits</title>
    <pubDate>Mon, 11 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11816.html</link>
    <description>This paper addresses an independent study Healthcare Data Management, Inc. (HDM) commissioned to gauge the relative efficacy of 100-percent-of-claims versus random-sample auditing of employee health plans. Multiple data sets of claim errors (</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11816.html</guid>
  </item>
  <item>
    <title>It All Starts with Log Management: Leveraging the Best in Database Security, Security Event Management and Change Management to Achieve Transparency</title>
    <pubDate>Mon, 11 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11814.html</link>
    <description>True Log Management doesnt stop at simply reporting on events, and aims to provide organizations with a closed loop system to provide comprehensive transparency into systems as a whole. A good Log Management solution encompasses in-depth monitoring for databases and applications, compliance and incident management, as well as guided remediation and automated blocking capabilities. By incorporating</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11814.html</guid>
  </item>
  <item>
    <title>How to Implement an Integrated GRC Architecture</title>
    <pubDate>Mon, 11 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11811.html</link>
    <description>Risk Management, Compliance and Governance that followed the corporate failures of the past decade have dramatically changed today's business environment. Organizations world-wide are coping with a proliferation of new regulations and standards, are challenged to do so in a way that supports performance objectives, upholds stakeholder expectations, sustains value and protects organization's brand.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11811.html</guid>
  </item>
  <item>
    <title>General Compliance Framework</title>
    <pubDate>Mon, 11 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11810.html</link>
    <description>Open framework to support Governance, Risk Management and Compliance (GRC) strategic projects and regulatory compliance</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11810.html</guid>
  </item>
  <item>
    <title>Dynamic Data Center Compliance With Tripwire and Microsoft</title>
    <pubDate>Mon, 11 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11806.html</link>
    <description>Compliance is a reality, but IT Operations does not need to become a security expert to monitor the health of their IT infrastructure in real-time. With the Tripwire Compliance Management Pack for System Center, users gain a central, end-to-end solution for monitoring the health and performance of their virtual and physical IT environment while ensuring compliance with critical internal and regulatory compliance standards.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11806.html</guid>
  </item>
  <item>
    <title>Adobe LiveCycle solutions for business process automation</title>
    <pubDate>Mon, 11 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11805.html</link>
    <description>In today's business environment, companies must be able to react to customer demands, competitive threats, and compliance requirements. With Adobe LiveCycle Enterprise Suite (ES2) solutions for business process management (BPM), organizations can quickly respond to all of these challenges.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11805.html</guid>
  </item>
  <item>
    <title>Achieving Efficient Governance Risk and Compliance through Process and Automation</title>
    <pubDate>Mon, 11 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11804.html</link>
    <description>This white paper presents a low risk, high impact approach to gaining control of regulatory compliance. The procedures, tasks, and behaviors that bear upon compliance can be overwhelming. Yet organizations that can master these activities, operate more efficiently, compete more effectively, and build their brands. Learn how Governance, Risk, and Compliance technologies can help by downloading this white paper now.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11804.html</guid>
  </item>
  <item>
    <title>Fast, Affordable SAP for Mid-market Chemicals: Advance your Business Agility</title>
    <pubDate>Sun, 03 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11802.html</link>
    <description>This product brochure highlights how mid-market Chemicals companies now have a full SAP solution specifically designed for them through the collaboration of Atos Origin and SAP. The solution is a rapid implementation of SAP and ongoing support services with per-user pricing that fits the budget of this target market.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11802.html</guid>
  </item>
  <item>
    <title>Control Electronic Discovery Using In-House Resources</title>
    <pubDate>Sun, 03 Jan 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11801.html</link>
    <description>While the focus on electronic discovery can appear to new entrants as unusual and noteworthy in light of FRCP and certain high-profile cases, many involved in this sector have been focusing on the evolution of the law and technology for years. These individuals are the thought leaders on the convergence between process and practicality. It is this insight that comes with specialized expertise. Rather than relinquish control of e-discovery to these experts and their firms, in-house legal teams and their executives are trending toward retaining control of decision-making and acting as collaborative partners throughout the life cycle of a particular matter. It is this equilibrium that will dictate the growth and development of electronic discovery in the years to come, and not simply technology or regulatory guidelines. Those who embrace the internal/external partnership will streamline progression and enhance their readiness for favorable outcomes.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11801.html</guid>
  </item>
  <item>
    <title>Access Certification: Addressing and Building on a Critical Security Control</title>
    <pubDate>Tue, 29 Dec 2009 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/whitepapers/SOX/abstract11794.html</link>
    <description>odays enterprise faces multiple, multi-faceted business challenges in which the management of employees and partners access to enterprise resources is vital. Foremost among these is the challenge of complying with an ever-growing number of regulations governing the integrity and privacy of enterprise data. With the need to protect data comes, of course, the need to closely manage access to it  by knowing at all times who has access to resources and whether their access is appropriate, and by providing documentation of this information in the event of an audit. To succeed, a company must have an identity and access management (IAM) infrastructure in place to ensure that people have access to all the resources they need (but none of those they dont), and to prove in audits that access is being managed correctly and in compliance with internal security policies and external regulations. Moreover, this infrastructure must be based on efficient and effective processes that free people </description>
    <guid isPermaLink="false">http://www.compliancehome.com/whitepapers/SOX/abstract11794.html</guid>
  </item>
</channel>
</rss>
