Title :
Regulatory Compliance and Information Security Assurance
Author_Institution :
Fac. of Bus. & Econ., Univ. of Lausanne, Lausanne
Abstract :
According to all security studies recently published, the regulatory compliance appears as one of the most important drivers in security spending, representing the bigger part of security operating costs. Regulatory compliance is very often mentioned to attest an improved performance and accountability in security mechanism and procedures. This paper aims to analyse the contribution of different laws, rules, regulations standards, frameworks related to the IT Security. Compliance and conformity concepts in information security are discussed: i) to enlighten the relationship between the regulatory compliance and the overall security level for a given organization ii) to reveal the importance of the regulatory compliance for the information security assurance.
Keywords :
security of data; standards; IT security; compliance and conformity concepts; information security assurance; regulatory compliance; Availability; Costs; Event detection; Financial management; ISO standards; Information management; Information security; Legislation; Performance analysis; Terrorism;
Conference_Titel :
Availability, Reliability and Security, 2009. ARES '09. International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
978-1-4244-3572-2
Electronic_ISBN :
978-0-7695-3564-7
DOI :
10.1109/ARES.2009.29