Information Age: News, analysis & insight for IT & business leaders

 

Non-stop compliance

25 February 2006  

With the growth of the regulatory imperative to provide corporate information in a reliable and timely fashion, organisations need to ensure their data systems and processes are up to the job.

Compliance and business continuity are inextricably linked. Directly cited in several of the major pieces of compliance legislation, the provision of highly reliable access to information is no longer an option but a requirement for many organisations.

Most forms of compliance compel enterprises to retain and protect critical business and customer data - and to make it retrievable when necessary. For example, the UK's Data Protection and Freedom of Information Acts require quick and reliable data retrieval systems, and their fixed deadlines for producing information demand a dependable environment.

Thus any organisation which may need to produce information under the terms of such legislation must have a business continuity plan (BCP) that will allow them to access important data at any time.

The need for a BCP is even written directly into specific laws. Rule 446 of the New York Stock Exchange, requires listed members to disclose their continuity plans for dealing with a major disruption to their business and demands a yearly review of the BCP. To add extra assurance to investors, several companies such as investment banks Morgan Stanley and Goldman Sachs, have posted their BCPs on their web sites.

 
 

Compliance laws/standards impacting business continuity

  • Basel II
  • Data Protection Act
  • Freedom of Information Act
  • International Financial Reporting Standards
  • NASDAQ stock exchange's Rule 3500 Series
  • New York Stock Exchange's Rule 446
  • Sarbanes-Oxley Act's Section 404

     
 

Standards bodies, like the International Standards Organisation (ISO) and the Information Security and Audit Control Association (ISACA), offer guidance on the scope of BCPs. For example, the ISACA's Control Objectives for Information Technology (COBIT) encourages managers to "assess regularly the need for uninterruptible power supply batteries and generators for critical information technology applications".

And ISO17799, originally a Department of Trade and Industry code of practice in the UK, has an entire section entitled 'Business Continuity Management', specifying how best to test, maintain and reassess continuity plans.

Those underscore the notion that continuity and solid business performance are two sides of the same coin. According to John Bace, an analyst at IT industry advisor, Gartner: "A corporate performance management framework that includes operational risk management procedures using business continuity planning will create an explicit link between compliance, performance management and value."

 
 

Business continuity's compliance components

  • Disaster recovery
  • Back-up and recovery software
  • SAN and RAID storage systems
  • Grid databases
  • Uninterruptible power supplies
  • Data centre outsourcing

     
 

The compliance imperative for continuity has contributed to the resurgence in demand for data centre hosting or co-location. Pressures on companies to ensure the high-availability of their IT services has encouraged many to look for a third party supplier to take on the responsibilities and ensure high levels of corporate data availability.

That emphasises how compliance approaches can have significant business advantages that go beyond simply adhering to governmental or industry-wide rules.

And while not everyone is convinced (a recent sample survey by Gartner suggested that 75% of mid-sized businesses still feel that compliance efforts bring them no additional business benefits) the advice from analysts is still sound.

Compliance is a by-product of "running your business well, with good process and tight systems", says the Butler Group.


Comments 

There are currently no comments on this article

People who read this also read...

 
Advertisement

White Papers

Read article

Developing ios Solutions for Business

Whitepapers

Quickly develop and deploy custom iPad and iPhone solutions. With FileMaker Pro, iPad and iPhone solutions can be prototyped and completed in hours or days versus weeks or months. No iOS application programming or design experience is required.

Read article

IDC Spotlight: Access Control and Certification

Whitepapers

Read this brief for best practices on managing user access compliance.

Read article

GPS World

Whitepapers

Is the PREMIER global media brand serving the exploding world of positioning and navigation for OEM, commercial and consumer applications.

More
div class="banner">