This section of the Regulatory Compliance Planning Guide focuses on mapping regulations to technology solutions. It introduces and defines the process that the team developed to translate relatively nonprescriptive regulations to specific technologies that can help address regulatory compliance and privacy assurance objectives.
This section uses two IT control maps to present this process. Each map provides a grid with technology solution categories. Each intersection in the maps indicates if the relevant technology solution category can address the regulatory and privacy requirements of that IT control. Finally, this section provides an applied example and a summary of this process.
This section includes the following topics:
| • | Mapping Regulations to a Control Framework. This topic presents an overview of how the major regulations and standards map to specific technology solution categories using a sample control framework. |
| • | Technology Solutions for Regulatory Compliance. This topic presents the technology solution categories that are relevant to regulatory compliance. |
| • | Technology Solutions for IT Control. This topic shows how each of the control framework categories maps to specific technology solutions. IT managers can use this map to determine the IT control types that they want to implement. |
| • | Applied Example. This topic demonstrates how specific regulations drive specific technology solutions through an applied example. It is based on the earlier mappings in this section of the guide. |
| • | Summary. This topic briefly reiterates the main points of this section of the guide. |