Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Compliance platforms emerging, maturing

By James Kobielus , Network World , 03/06/2007

Compliance has been one of the dominant themes in the post-Enron age of corporate IT. Many software providers tout their offerings as solutions for complying with the Sarbanes-Oxley Act (SOX) and every other regulatory mandate, industry best-practices framework and corporate internal policy.

As a product segment, compliance has defied easy definition and been dominated primarily by point solutions. Compliance-related offerings range across many established niches, including business intelligence, corporate performance management, business process management, identity and access management, application security, change management, risk management, auditing and archiving.

However, over the past year, a new IT product segment has emerged — governance, risk and compliance (GRC) management — that integrates compliance point solutions into comprehensive, service-oriented architecture (SOA)-enabled enterprise suites. Fueling this trend is the growing realization that companies cannot have one stovepipe GRC management infrastructure for each mandate, but must leverage a single infrastructure across all initiatives. Each new investment in compliance-enabling technologies must integrate through SOA into the company’s core GRC management platform.

The most noteworthy recent development in GRC management was SAP’s late-2006 launch of a comprehensive, modular product platform to address a wide range of GRC requirements. Essentially, SAP validated GRC management as an important new enterprise software platform. At the same time, through its product announcements, the vendor has provided an architectural blueprint for the core GRC management functionality: monitoring, verification and optimization of business controls that have been expressed as structured workflows.

First and foremost, SAP provides a GRC management repository that centralizes compliance frameworks, mandates, policies and rules. It also provides a GRC process tool for modeling enterprise controls, executing the associated workflows and enforcing compliance. Its GRC platform includes a compliance dashboard, which provides a high-level rollup and enables detailed drill-down into key business risks across multiple enterprise levels, organizational entities, business processes and IT infrastructures. SAP’s platform enables automatic aggregation of enterprise business-process risks, provides supporting evidence of compliance, pinpoints control violations and enables prioritization of corrective action. It also includes collaborative tools, role-based views and configurable alerts to support operational enterprise risk management involving process stakeholders.

Partner Content

NetScout is one of the world's premier providers of integrated network and application performance solutions.

www.netscout.com

Know First

Get Proactive — Move from Troubleshooting to Monitoring to Management with nGenius K2's Service Dashboard & Intelligent Early Warning Alarms

Watch the Video

Know Where

Get Rapid Performance Problem Isolation with nGenius Performance Manager and Diagnose Problems up to 70% Faster!

Learn More

Know Why

Get the Details to Validate and Solve your Toughest Performance Issues with nGenius InfiniStream and Sniffer Intelligence Modules

Read the Whitepaper

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

What do thes letters stan for when used in sentence such as I am busy...bbs.- Anonymous

Join the Discussion