Cost of regulatory security compliance? On average, $3.5M
by GadgetGizmodo
By Ellen Messmer
Network World (US)
FRAMINGHAM (01/31/2011) â" The cost of achieving regulatory security compliance is on average $3.5 million each year, according to a survey of 160 individuals leading the IT, privacy and audit efforts at 46 multinational organizations.
âThe True Cost of Compliance,â a research study done by Ponemon Institute and sponsored by Tripwire, makes the point that if that $3.5 million figure for the average cost sounds high, the average cost for organizations that experience non-compliance-related problems is far higher â" $9.4 million. Costs related to âbusiness disruption, reduced productivity, fees, penalties and other legal and non-legal settlement costsâ pile up when legal and regulatory compliance goals are not met, the study asserts.
MORE RESEARCH: Regulatory compliance hogs security pros attention
The array of regulatory requirements facing organizations runs the gamut from the U.S. state laws for data breach to Sarbanes-Oxley to the European Unionâs Privacy Directive and more. But the Payment Card Industry Data Security Standard was deemed to be âmost importantâ in terms of influence and âthe most difficult to comply with,â according to the surveyâs respondents.
âPCI seems to affect everyone,â says Rekha Shenoy, Tripwireâs vice president of strategy. She adds that the PCI DSS, unlike some compliance requirements, is very âprescriptiveâ in putting forth whatâs expected in terms of technologies and procedures.
The Ponemon report covered industries that include consumer products, technology, retail, industrial, public sector, healthcare, communications, education and research, financial services, transportation, pharmaceutical and energy. The survey respondents hold job titles that include chief information security officer, compliance officer, IT operations leader, audit director and others.
In divvying up âexpense categories,â the report says the use of âspecialized technologies,â âincident management,â and âaudit and assessmentâ take up large portions of data-compliance costs, with the corporate IT department, line of business and legal division regarded as functional areas that account for significant portions of the expenditures.
The burden of both compliance and non-compliance costs were highest in organizations with fewer than 5,000 employees and smallest in organizations with 25,000 to 75,000 employees, where economies of scale may apply.
In terms of the number of internal compliance audits performed each year, the report says âsurprisingly, 28% of companies say they do not conduct compliance audits, and only 11% say they conduct more than five audits each year.â
However, internal compliance audits seem to be worth it. According to the reportâs analysis, âorganizations that conduct three to five internal compliance audits per year have the lowest per capita compliance cost (average $154). The highest compliance cost (average $341) is associated with organizations that do not conduct any internal compliance audits.â In addition, the lowest per capita non-compliance cost (with an average of $226) is said to be associated with organizations that conduct five or more audits, while the highest per capita non-compliance cost (average $1,275) is associated with organizations that do not conduct audits.
Read more about wide area network in Network Worldâs Wide Area Network section.
Popularity: 1% [?]
Powered By WizardRSS
0 comments:
Leave a Comment