Regulatory Compliance Planning Guide

Section 3: Technology Solutions for Regulatory Compliance

Published: June 14, 2006

This topic presents the technology solution categories that are relevant to regulatory compliance. So far, this guide has focused on how regulations can drive specific IT control requirements. Now the focus shifts to the technology solutions that can help address those requirements.

The team created and validated its list of technology solutions, and the categories for them that are relevant to regulatory compliance, against ISO 17799, National Institute of Standards and Technology (NIST SP800) recommendations, and other frameworks. Based on this process, the team arrived at the following 19 technology solution categories:

Document Management

Business Process Management

Project Management

Risk Assessment

Change Management

Network Security

Host Control

Malicious Software Prevention

Application Security

Messaging and Collaboration

Data Classification and Protection

Identity Management

Authentication, Authorization, and Access Control

Training

Physical Security

Vulnerability Identification

Monitoring and Reporting

Disaster Recovery and Failover

Incident Management and Trouble-Tracking

The next topic, Technology Solutions for IT Control, illustrates how each of the control categories in the control framework map to specific technology solutions. You can use these mappings to help determine the types of controls that you want to implement for your organization.


Top of pageTop of pagePrevious2 of 5Next