COMPLIANCE SOLUTIONS
HIPAA
Sarbanes Oxley
PCI
Regulatory Compliance
Data Privacy
 
request a demo >>
submit request >>
RESOURCES & DOWNLOADS
Datasheets
White Papers
Case Studies
Recorded Webinars
Product Downloads & Updates
Register for Product Demo
Open Source Security Policy
Compliance Guide
"Because of Sarbanes-Oxley, we had corporate internal auditors telling us we needed to be compliant with a whole list of specifications. This was also necessary to help us prepare for external audits"

Gavin Inman, Stryker Corporation,
Interdivisional Database Administrator
Full Case Study
 
 
 
A Quick Summary:
There are a number of additional U.S. and international standards that impact data security management and regulatory compliance. Rather than react to individual regulations, we advise our clients to implement one comprehensive security plan that takes into account all of the applicable laws.

GLBA
The Gramm-Leach-Bliley Act (GLBA) directly impacts financial institutions in the United States. The act’s Privacy Rule requires financial institutions to ensure the security and confidentiality of customer records and information. The Safeguards Rule, which is enforced by the Federal Trade Commission, requires financial institutions to have a security plan to protect the confidentiality and integrity of personal consumer information. A number of companies have been prosecuted recently for being out of compliance.

FISMA
The Federal Information Security Management Act, or FISMA, is a U.S. federal law designed to ensure the effectiveness of security controls over information resources that support federal government operations and assets. The act mandates yearly audits - the results of which are provided to the Office of Management and Budget. The National Institute of Standards and Technology (NIST) supports FISMA by developing publications that provide guidance and best security practices to government agencies, including Special Publication 800-53, “Recommended Security Controls for Federal Information Systems.”

BASELII
The Basel II accord, created by the Basel Committee on Banking Supervision, deals in part with the international standards for measuring the adequacy of a bank's capital. Its goal is to provide greater consistency in the way banks and banking regulators approach risk management across national borders. The accord requires banks to measure and control credit, market, and operational risks, including information security. Banks that comply with Basel II are allowed to maintain smaller capital reserves, which can be a key competitive advantage. Much like Sarbanes-Oxley compliance in the United States, banks need to demonstrate adequate controls over information systems that store and serve financial data.

The PowerTech Solution

PowerTech provides a suite of security solutions that allow organizations to ensure the security, confidentiality and integrity of information stored on the IBM AS/400 and iSeries systems. And for organizations without an information security policy, PowerTech provides an open source security policy that provides best practices for implementing a data security program on the iSeries and AS/400 platform.

Compliance Monitor provides banks and other companies with the ability to conduct regular risk and vulnerability assessment. Auditors, examiners, and IT Staff get prompt notice of any identified exceptions to established security policy.

Network Security ensures that safeguards are in place to protect the confidentiality and integrity of customer information. Access across the network to AS/400 and iSeries is controlled according to set rules and network activity is logged to secure journals.

Authority Broker is used to enforce separation of duties on critical production systems. IT staff and programmers are only granted access to powerful user accounts (profiles) on an as-needed basis.

Encryption allows companies to protect their most sensitive data by rendering it into a form that is unreadable by humans. Data can be encrypted directly in the databases or on backup tapes where it is stored.


 
©2008 The PowerTech Group, Inc. All Rights Reserved Sitemap  Privacy Policy