Regulatory requirements have IT jumping through hoops to meet them, although these mandates are also driving bigger security budgets.
Editor’s note: This is the fourth installment of a five-part series on the threats facing IT executives and how to mitigate them.
As challenging as the security demands imposed by some new regulatory requirements have been, they’ve also presented IT managers with a golden opportunity to make network improvements.
Of particular influence have been the Sarbanes-Oxley (SOX) Act’s financial reporting standards for publicly traded companies and the Health Insurance Portability and Accountability Act (HIPAA), federal security rules for patient data that take effect next month for healthcare organizations.
For companies that spent several months striving to understand SOX or HIPAA, the requirements brought good news: For some IT departments, upper management generously opened purse strings to acquire new auditing and security protections.
“SOX was very much a driver for getting Configuresoft’s Enterprise Configuration Manager and other tools,” says Bill Randall, IT director at Red Robin Gourmet Burgers, a Greenwood Village, Colo., restaurant chain.
Configuresoft’s ECM, which Red Robin added to 30 servers and about 200 workstations, documents and tracks operating system and application configurations and password changes, while ensuring compliance with a written policy.
According to Randall, that capability helps meet the SOX requirements that organizations document their systems for auditing purposes.
“When we knew SOX was coming down the pike, we used it as an opportunity to better document our procedures because we know this will be part of the financial audit, which includes the SOX audit, that our auditor Deloitte will do later this year,” Randall explains. “The IT audit is a big part of that review because IT is the gatekeeper for the financial controls.”
Manual documentation and audit and policy-enforcement process would have taken Red Robin’s IT department more than 12 hours, but automating the process through ECM reduced it to 10 minutes.
Red Robin also deployed the NetIQ Security Manager to centrally monitor and analyze network logs across the network, which included firewalls and intrusion-prevention systems .
“At the beginning of the year, we hadn’t budgeted for all this,” Randall says of the unexpected bonanza. But as the company examined its own practices, it became clear that SOX compliance would mean hiring more systems experts or implementing better automation – and Red Robin opted for the latter.
United Parcel Service (UPS), which has 360,000 employees, is choosing to approach SOX compliance by deploying security best practices across the board. UPS is giving everyone the handheld dynamic-password token SecurID from RSA Security for two-factor authentication to remotely access applications such as payroll benefits. The worldwide package delivery firm also is using IBM Tivoli’s identity management software to automate user provisioning.
“Sarbanes-Oxley has been a way to improve audits for compliance reasons,” says Jim Flynn, systems manager for security policy and strategy at UPS in Atlanta.
Regulations such as SOX and HIPAA don’t exactly spell out what technologies must be used to stay on the safe side of the law. However, many IT managers appear convinced that regulatory compliance in the end will come down to the commonsense notion of best practices in management of identity, passwords, system logs and vulnerability assessment.
“For HIPAA, we needed to more robustly manage IDs,” says Buddy Gillespie, CIO and vice president at WellSpan Health, a healthcare provider in Southeast Pennsylvania, which deployed Courion’s user-provisioning software to centrally track how 6,000 users accessed applications.
“It cost us somewhere between $75,000 and $100,000, but it was reasonable enough to fit into out HIPAA budget,” says Gillespie, adding upper management pays close attention to meeting HIPAA’s security rules for protecting unauthorized access to patient data.
Eben Berry, manager of IS at Network Health, a healthcare provider in Cambridge, Mass., says senior management within his organization also has been highly focused over the last year on meeting HIPAA security regulations. Although he won’t release specific financial figures, Berry says this focus helped the IT department get almost double the security budget it had before.
“HIPAA brought the visibility up to senior management, and we made five additional purchases for security purposes that probably wouldn’t have been on the radar without it,” Berry says. Network Health also conducted a HIPAA compliance check-up on itself using assessment tools from Askia and Mag Mutual’s TurboCharge HIPAA Security.
|
Network Health also recently purchased WholeSecurity’s host authentication, eEye Digital Security’s Retina scanner and SurfControl’s Web filter product to restrict access to the Web and lessen the chance of downloading viruses and spyware.
HIPAA is making it easier for Good Samaritan to get security funding, too, according to Chuck Christian, director of IS at the 1,000-employee hospital in Vincennes, Ind.
Good Samaritan girded for HIPAA security by getting together with other hospitals, state government regulators and attorneys under the umbrella of the Indiana HIPAA Task Force, which meets once a month.
To improve controls on access to applications, Good Samaritan decided to deploy Imprivata’s single sign-on software and appliance, which cost about $70,000. The hospital is also looking into the type of software that would monitor outbound e-mail and other communication to make sure confidential patient data isn’t transmitted over the Internet without authorization. “This is all private and confidential information, and we need to keep it that way,” Christian says.




