<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>ACM Queue - Compliance</title>
    <link>https://queue.acm.org/listing.cfm?item_topic=Compliance&amp;qc_type=topics_list&amp;filter=Compliance&amp;page_title=Compliance&amp;order=desc</link>
    <description />
    <item>
      <title>What Went Wrong?: Why we need an IT accident investigation board</title>
      <link>https://queue.acm.org/detail.cfm?id=3475967</link>
      <category>Compliance</category>
      <pubDate>Tue, 13 Jul 2021 18:40:10 GMT</pubDate>
      <author>Poul-Henning Kamp</author>
      <guid isPermaLink="false">3475967</guid>
    </item>
    <item>
      <title>Enclaves in the Clouds: Legal considerations and broader implications</title>
      <link>https://queue.acm.org/detail.cfm?id=3448126</link>
      <category>Compliance</category>
      <pubDate>Tue, 26 Jan 2021 11:15:50 GMT</pubDate>
      <author>Jatinder Singh, Jennifer Cobbe, Do Le Quoc, Zahra Tarkhani</author>
      <guid isPermaLink="false">3448126</guid>
    </item>
    <item>
      <title>Standards Advice: Easing the pain of implementing standards</title>
      <link>https://queue.acm.org/detail.cfm?id=1687192</link>
      <description>My mother took language, both written and spoken, very seriously. The last thing I wanted to hear upon showing her an essay I was writing for school was, "Bring me the red pen." In those days I did not have a computer; all my assignments were written longhand or on a typewriter, so the red pen meant a total rewrite. She was a tough editor, but it was impossible to question the quality of her work or the passion that she brought to the writing process. All of the things Strunk and White have taught others throughout the years my mother taught me, on her own, with the benefit of only a high school education and a voracious appetite for reading.</description>
      <category>Compliance</category>
      <pubDate>Wed, 30 Dec 2009 14:18:47 GMT</pubDate>
      <author>George Neville-Neil</author>
      <guid isPermaLink="false">1687192</guid>
    </item>
    <item>
      <title>Seeking Compliance Nirvana: Don&amp;rsquo;t let SOX and PCI get the better of you</title>
      <link>https://queue.acm.org/detail.cfm?id=1160455</link>
      <description>&lt;h3&gt;Seeking Compliance Nirvana&lt;/h3&gt;&#xD;&lt;h4&gt;Don&amp;rsquo;t let SOX and PCI get the better of you&lt;/h4&gt;&#xD;&lt;h4&gt;Greg A. Nolann&lt;/h4&gt;&#xD;&lt;p&gt;Compliance. The mere mention of it brings to mind a harrowing list of questions&#xD;  and concerns. For example, who is complying and with what? With so many standards,&#xD;  laws, angles, intersections, overlaps, and consequences, who ultimately gets&#xD;  to determine if you are compliant or not? How do you determine what is in scope&#xD;  and what is not? And why do you instantly think of an audit when you hear the&#xD;  word compliance?&lt;/p&gt;&lt;p&gt;&#xD;  To see the tangled hairball that is compliance, just take a look at my company.&#xD;  It is on the hook for SOX (Sarbanes-Oxley Act of 2002), as we are a publicly&#xD;  traded company; for a number of banks for the PCI DSS (payment card industry&#xD;  data security standard), also known as Visa CISP (Cardholder Information Security&#xD;  Program); for HIPAA (Health Insurance Portability and Accountability Act);&#xD;  for CA 1786 (and all other states&amp;rsquo; disclosure laws); and for the European&#xD;  Union, its member countries, Japan, Korea, and a handful of other countries&amp;rsquo; privacy&#xD;  and data security laws (these alone could probably spawn an entire series of&#xD;  lessons and lectures!). &lt;/p&gt;</description>
      <category>Compliance</category>
      <pubDate>Fri, 15 Sep 2006 08:48:46 GMT</pubDate>
      <author>Greg A. Nolann</author>
      <guid isPermaLink="false">1160455</guid>
    </item>
    <item>
      <title>Keeping Score in the IT Compliance Game: ALM can help organizations meet tough IT compliance requirements.</title>
      <link>https://queue.acm.org/detail.cfm?id=1160450</link>
      <description>&lt;h3&gt;Keeping Score in the IT Compliance Game&lt;/h3&gt;&#xD;&lt;h4&gt;ALM&amp;nbsp;can help organizations meet tough IT compliance requirements.&lt;/h4&gt;&#xD;&lt;h4&gt;TRACY RAGAN, CATALYST SYSTEMS&lt;/h4&gt;&#xD;&lt;p&gt; Achieving developer acceptance of standardized procedures for managing applications&#xD;  from development to release is one of the largest hurdles facing organizations&#xD;  today. Establishing a standardized development-to-release workflow, often referred&#xD;  to as the ALM (application lifecycle management) process, is particularly critical&#xD;  for organizations in their efforts to meet tough IT compliance mandates. This&#xD;  is much easier said than done, as different development teams have created&#xD;  their own unique procedures that are undocumented, unclear, and nontraceable. &lt;/p&gt;&lt;p&gt;&#xD;  Achieving 100 percent compliance from all development teams requires that the&#xD;  ALM team clearly communicate the levels of compliance to the developers and&#xD;  clearly communicate to upper management which development teams are and are&#xD;  not in compliance. Keeping track of the game using a simple &amp;ldquo;compliance&#xD;  scorecard&amp;rdquo; can do the job. &lt;/p&gt;</description>
      <category>Compliance</category>
      <pubDate>Fri, 15 Sep 2006 08:48:43 GMT</pubDate>
      <author>Tracy Ragan</author>
      <guid isPermaLink="false">1160450</guid>
    </item>
    <item>
      <title>Compliance Deconstructed: When you break it down, compliance is largely about ensuring that business processes are executed as expected.</title>
      <link>https://queue.acm.org/detail.cfm?id=1160449</link>
      <description>&lt;h3&gt;Compliance Deconstructed &lt;/h3&gt; &lt;h4&gt;When you break it down, compliance is largely about ensuring that business  processes are executed as expected.&lt;/h4&gt; &lt;h4&gt;JC CANNON AND MARILEE BYERS, MICROSOFT&lt;/h4&gt; &lt;p&gt; The topic of compliance becomes increasingly complex each year. Dozens of  regulatory requirements can affect a company&amp;rsquo;s business processes. Moreover,  these requirements are often vague and confusing. When those in charge of compliance  are asked if their business processes are in compliance, it is understandably  difficult for them to respond succinctly and with confidence. This article  looks at how companies can deconstruct compliance, dealing with it in a systematic  fashion and applying technology to automate compliance-related business processes.  It also looks specifically at how Microsoft approaches compliance to SOX (Sarbanes-Oxley Act of 2002). &lt;/p&gt; &lt;h4&gt;Compliance Drivers&lt;/h4&gt; &lt;p&gt;  Regulatory legislation and corporate governance are primarily what drives compliance.   Failure to comply with legislation such as Sarbanes-Oxley can lead to fines   and disruption of day-to-day business. Even companies that are not concerned   with regulatory legislation need to protect important corporate resources   such as customer data and trade secrets.&lt;/p&gt;</description>
      <category>Compliance</category>
      <pubDate>Fri, 15 Sep 2006 08:48:42 GMT</pubDate>
      <author>J. C. Cannon, Marilee Byers</author>
      <guid isPermaLink="false">1160449</guid>
    </item>
    <item>
      <title>Box Their SOXes Off: Being proactive with SAS 70 Type II audits helps both parties in a vendor  relationship.</title>
      <link>https://queue.acm.org/detail.cfm?id=1160448</link>
      <description>&lt;h3&gt;Box Their SOXes Off&#xD;&lt;/h3&gt;&#xD;&lt;h4&gt;Being proactive with SAS 70 Type II audits helps both parties in a vendor&#xD;  relationship.&lt;/h4&gt;&#xD;&lt;h4&gt;JOHN BOSTICK, dbaDIRECT&amp;nbsp;&lt;/h4&gt;&#xD;&lt;p&gt;Data is a precious resource for any large organization. The larger the organization,&#xD;  the more likely it will rely to some degree on third-party vendors and partners&#xD;  to help it manage and monitor its mission-critical data. In the wake of new&#xD;  regulations for public companies, such as Section 404 of SOX (Sarbanes-Oxley&#xD;  Act of 2002), the folks who run IT departments for Fortune 1000 companies have&#xD;  an ever-increasing need to know that when it comes to the 24/7/365 monitoring&#xD;  of their critical data transactions, they have business partners with well-planned&#xD;  and well-documented procedures. &lt;/p&gt;&lt;p&gt;&#xD;  In response to a growing need to validate third-party controls and procedures,&#xD;  some companies are insisting that certain vendors undergo SAS (Statement on&#xD;  Auditing Standards) 70 Type II audits. These audits refer to an AICPA (American&#xD;  Institute of Certified Public Accountants) standard that sets forth the practice&#xD;  for evaluating the performance of outside service organizations. (A Type I&#xD;  audit describes the business&amp;rsquo;s controls, noting if they are suitably&#xD;  designed and in place; a Type II audit tests those controls and reports if&#xD;  they are working adequately.)&lt;/p&gt;</description>
      <category>Compliance</category>
      <pubDate>Fri, 15 Sep 2006 08:48:41 GMT</pubDate>
      <author>John Bostick</author>
      <guid isPermaLink="false">1160448</guid>
    </item>
    <item>
      <title>Complying with Compliance: Blowing it off is not an option.</title>
      <link>https://queue.acm.org/detail.cfm?id=1160446</link>
      <description>&lt;h3&gt;Complying with compliance&#xD;&lt;/h3&gt;&#xD;&lt;h4&gt;Blowing it off is not an option.&lt;/h4&gt;&#xD;&lt;h4&gt; ERIC ALLMAN, SENDMAIL&lt;/h4&gt;&#xD;&lt;p&gt;&amp;ldquo;Hey, compliance is boring. Really, really boring. And besides, I work&#xD;  neither in the financial industry nor in health care. Why should I care about&#xD;  SOX and HIPAA?&amp;rdquo;&lt;/p&gt;&#xD;&lt;p&gt;&#xD;  Yep, you&amp;rsquo;re absolutely right. You write payroll applications, or operating&#xD;  systems, or user interfaces, or (heaven forbid) e-mail servers. Why should&#xD;  you worry about compliance issues?&lt;/p&gt;</description>
      <category>Compliance</category>
      <pubDate>Fri, 15 Sep 2006 08:48:39 GMT</pubDate>
      <author>Eric Allman</author>
      <guid isPermaLink="false">1160446</guid>
    </item>
    <item>
      <title>A Requirements Primer: A short primer that provides background on four  of the most important compliance challenges that organizations face today.</title>
      <link>https://queue.acm.org/detail.cfm?id=1160447</link>
      <description>&lt;h3&gt;A Requirements Primer&#xD;&lt;/h3&gt;&#xD;&lt;h4&gt;GEORGE W. BEELER, JR., BEELER CONSULTING and DANA GARDNER, INTERARBOR SOLUTIONS &lt;/h4&gt;&#xD;&lt;p&gt;Many software engineers and architects are exposed to compliance through the&#xD;  growing number of rules, regulations, and standards with which their employers&#xD;  must comply. Some of these requirements, such as HIPAA (Health Insurance Portabililty&#xD;  and Accountability Act), focus primarily on one industry, whereas others, such&#xD;  as SOX (Sarbanes-Oxley Act), span many industries. Some apply to only one country,&#xD;  while others cross national boundaries. To help navigate this often confusing&#xD;  world, &lt;em&gt;Queue&lt;/em&gt; has assembled a short primer that provides background on four&#xD;  of the most important compliance challenges that organizations face today.&lt;/p&gt;&#xD;&lt;h4&gt;SARBANES-OXLEY (SOX)&lt;/h4&gt;&#xD;&lt;p&gt;The Sarbanes-Oxley Act of 2002 can be tidily summed up as trying to answer&#xD;  the not-so-simple question, &amp;ldquo;Says who?&amp;rdquo; when it comes to proper&#xD;  corporate financial reports. Because of a spate of major corporate and accounting&#xD;  scandals at the turn of the century&amp;mdash;perhaps best punctuated by the collapse&#xD;  of Enron and Arthur Andersen&amp;mdash;Sarbanes-Oxley, or SOX, was designed to&#xD;  shore up public and investor confidence in financial reporting.&lt;/p&gt;</description>
      <category>Compliance</category>
      <pubDate>Fri, 15 Sep 2006 08:48:39 GMT</pubDate>
      <author>George W. Beeler, Dana Gardner</author>
      <guid isPermaLink="false">1160447</guid>
    </item>
    <item>
      <title>Playing by the Rules: The complex world of compliance</title>
      <link>https://queue.acm.org/detail.cfm?id=1160436</link>
      <description>&lt;h3&gt;Playing by the Rules&lt;/h3&gt;&#xD;&lt;h4&gt;The complex world of compliance&lt;/h4&gt;&#xD;&lt;h4&gt;Charlene O&amp;rsquo;Hanlon, &lt;em&gt;ACM Queue&lt;/em&gt;&lt;/h4&gt;&#xD;&lt;p&gt;Some of my favorite childhood memories are of playing games with my sister&amp;mdash;both&#xD;  structured games such as Monopoly or hopscotch and imagination-fueled games&#xD;  such as cops and robbers or roller derby girls (don&amp;rsquo;t ask). Regardless&#xD;  of whether the game had established regulations, often our play would devolve&#xD;  into what I call &lt;em&gt;Calvinball&lt;/em&gt;, a term coined in the comic strip &lt;em&gt;Calvin&#xD;  and Hobbes&lt;/em&gt;  referring to the act of making up the rules as you go along.&lt;/p&gt;&#xD;&lt;p&gt;&#xD;  Our Calvinball play had some distinct advantages: It was a lot more fun to&#xD;  change the rules in the middle of the game. No one ever got bored. It allowed&#xD;  us to stretch our minds beyond the parameters of regular play. And&amp;mdash;quite&#xD;  possibly the best advantage&amp;mdash;everybody won in Calvinball. Of course, there&#xD;  was the occasional cry of, &amp;ldquo;Hey, that&amp;rsquo;s not fair!&amp;rdquo; but that&#xD;  person was quickly outnumbered if there were more than two players.&lt;/p&gt;</description>
      <category>Compliance</category>
      <pubDate>Fri, 15 Sep 2006 08:48:31 GMT</pubDate>
      <author>Charlene O'Hanlon</author>
      <guid isPermaLink="false">1160436</guid>
    </item>
  </channel>
</rss>

