If your company hasn’t yet installed a chief compliance officer chances are good they will: 1) do so soon; or 2) leave these responsibilities in your lap.
Given that IT plays a big role in compliance, either way you’re stuck playing a large role in helping ensure your company can live up to stringent business regulations.
And while compliance officers – who can command salaries of $250,000 and more – typically herald from financial or legal backgrounds, the fact that these efforts rely heavily on IT means some of you might be able to parlay your expertise into this new role. (Click for a job description. Even though this one is for healthcare, the basic requirements are likely to be universal.)
Not that you would necessarily want this job. Complying with the likes of the Gramm-Leach-Bliley Act and Sarbanes-Oxley – say nothing of industry specific regulations such as the Health Insurance Portability and Accountability Act – is a huge and daunting undertaking.
“My main concentration for the past 18 months has been IT security audits to ensure compliance with Sarbanes-Oxley Section 404 [management assessment of internal controls] and COBIT,” which are security and control practices issued by the IT Governance Institute, says Michael Kamens, global network/security manager for $2 billion Thermo Electron (see our interview here).
The bulk of the new regulations that require IT support revolve around governance (being able to demonstrate that business processes meet standards) and security/privacy (safeguarding organization assets and sensitive data).
Whether you are handed the job or are just left holding the compliance bag, one of the first objectives is to align your IT and compliance strategies. That is easier said than done, but the good news is that, while IT budgets tend to be fixed, there are often compliance funds that can be called on that might make it possible to kill two birds with one stone.
In fact, many IT executives are using compliance monies for IT investments. And why not? If you can solve a pressing compliance need while at the same time installing technology that advances the business cause, it is a classic win-win.
No matter where you find yourself on the compliance continuum, network executives say a good source of advice is industry peers. Sharing experiences can save heartache.
One overheard tip: If you can’t achieve absolute compliance, you at least want to be able to demonstrate that you consistently follow a set of defensible practices.




