Regulation Manager
Public companies must comply with multiple regulations or standards that
frequently have significant overlap and redundancy. For example, ISO 27002, PCI
DSS, and COBIT require many of the same protections in terms of information
security. Addressing each regulation separately will mean doing the same
compliance work two, three, or more times. Ideally, the enterprise would define
and manage the minimum set of controls necessary, and use many of the same
controls to satisfy the requirements of multiple regulations and standards.
ProcessUnity Regulation Manager provides tools to help the
enterprise achieve full regulatory compliance with the least number of controls.
These include:
- A structured inventory of relevant regulations, provisions, and
sub-provisions
- Tools to associate provisions and sub-provisions with the relevant
controls
- Reports showing the controls that satisfy each regulatory provision and
highlighting any regulatory gaps
In addition this application comes with a set of reference controls for information security pre-mapped to several common standards and regulations.
|
|