Compliance, backup, and recovery

By Dan Blacharski  7 comments

Compliance with the ever-increasing array of legislative mandates presents a burden to management and IT staff alike. If you’re in financial services, you are bound by Gramm-Leach-Bliley; in health care, by HIPAA; or if you’re a publicly-held corporation, Sarbanes-Oxley. If you process credit card payments, there are PCI-DSS rules to consider.

In addition, there are state regulations that transcend the state—such as California’s SB1386 (California Information Practice Act). Although this is a California state law, it has become a de facto nationwide practice because of its scope. Any company that maintains any information about a resident of California, whether the company is in California or not, must comply—and as a result, almost every midsize to large company falls under its purview.

SB 1386 requires policies and procedures to be put in place to ensure that personal data is safe from outside attack, and in addition, requires a procedure for creating a public notification if such an attack does occur. Although it applies only to California residents, as a practical matter, a company complying with SB1386 would offer the same safeguards to all data for all customers, California resident or not. The goal of a company complying with this regulation is to focus more on the first requirement (prevention), so that the second requirement (public notification) is not required.

Although specific technology is not stated in the legislation, two key principals relating to backup and recovery systems would be ensuring the integrity of the stored data, and imposing authentication and authorization controls over the stored data.

In the healthcare business, HIPAA is one of the most far-reaching pieces of legislation that has had a major impact throughout the entire industry. Meant as legislation to improve the efficiency of the healthcare system, it also minimizes the incidence of fraud and protects the privacy of patient data. Several pieces of technology throughout the enterprise will be touched by HIPAA, most notably storage and backup—since HIPAA mandates access controls over sensitive data.

Gramm-Leach-Bliley imposes similar controls over personal data as it relates to financial institutions, setting out technological requirements to protect the personal information of the financial institutions’ clients.

Sarbanes-Oxley, on the other hand, deals with financial data instead of client data, but it also imposes the same mandates that call for strict security controls over stored information. Section 404 of Sarbanes-Oxley is the part that deals specifically with “internal controls,” which sets out a broad requirement for internal security, including the concepts of authentication, authorization, and encryption, as well as auditing capabilities, over stored financial data.

Chances are, if you’re any larger than a mom ‘n pop operation, you are under the purview of one of these regulations, even if you don’t realize it. In many instances, it may not even be readily apparent—if you are a contractor or supplier to a company that falls under one of these compliance mandates, chances are, you too, will have to comply, for the sake of your client.

7 comments

    Anonymous 1 year ago
    Every organization has policies and procedures that must be complied to ensure effectiveness and efficiency on its processes. Important data need to be backed up regularly to prevent losing such a huge amount of it if ever an outside attack will occur. Also, security is a very important issue and should be well manage.Best,Mitch ReyesGraphic Artist-Buy Micro Niche Finder Advertisment
    Anonymous 1 year ago
    In papers filed with the US Supreme court this week, Justice Department lawyers indicate swiss replica watches the office to curtail emissions that grounds climate change belongs to the Environmental rolex watches Protection Agency and to Congress.
    Anonymous 1 year ago
    Yes, there are many different companies which provide service to recover data. They recover lost data by using advanced tool and new techniques.
    Anonymous 2 years ago
    Lakers coach Phil Jackson has recently carried out the rectification of the team, wow goldhe asked the players to be severely restricted the use of mobile phones blog and other virtual social networking tools. This provision is directed at the network this summer,wow power leveling a major role in Ron Artest.Jackson joined the Ron Artest of the new proposed requirements.wow goldZen Master in the praise of Artests offensive talent and professional attitude towards the Schmidt asked Artest must clearly understand the situation and self-positioning, wow power levelingto be honest in the new season from the defensive to start. 9.28C
    Anonymous 2 years ago in reply to Anonymous
    great article, my favorite wow gold aion gold andwow gold tobuy wow gold
    Anonymous 2 years ago
    I spent a lot of time searching for a good scanner at an affordable price. I tired many different ones before I found Search-and-destroy Antispyware but when I tired it I was very happy with the results. I would recommend the antispyware solution from Search-and-destroy to anyone searching for a great scan that works just as well as Norton and many of the others that you would pay more for. Visit http://www.Search-and-destroy.com to find out more and to give this scan a try just like I did. I’m sure you will love it as much as I do.
    Anonymous 2 years ago
    Yes... back and data recovery is very urgent... it is a must known!

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      StorageWhite Papers & Webcasts

      White Paper

      ESG ~ HP StoreOnce: the Next Wave of Data Deduplication

      Leveraging deduplication in backup environments yields significant advantages. The cost savings in reducing disk capacity requirements change the economics of disk-based backup. For some organizations, it allows disk-based backup-and, importantly, recovery-to be extended to additional workloads in the environment. For others, deduplication makes it possible to introduce disk-based backup where it may not have been feasible before.

      White Paper

      Evaluator Group: Storage Federation - IT Without Limits (Analysis of HP Peer Motion with Storage Federation)

      As the role of IT increases within organizations, the need to move data when and where it is needed is critical to support emerging business requirements. This has become increasingly difficult due to the huge growth of data volumes. This white paper sponsored by HP + Intel evaluates a solution that aims to enable the movement of data without physical limitations. Read now and see how this could enable agility and efficiency.

      White Paper

      HP Converged Storage Sets the Stage for the Next Era of Computing

      Enterprise storage has undergone many changes in recent years - with converged storage and infrastructure 2.0 paving the way for reduced IT infrastructure costs and greater performance. This report discusses the latest trends that are setting the stage for the next era of computing. Learn about the new infrastructure and storage trends that are changing the way business storage works today.

      White Paper

      AppAssure vs Acronis

      In this study of data protection for environments with virtual and physical servers running Windows, openBench Labs tested AppAssure Backup and Replication software v 4.7 and Acronis Backup & Recovery 11. Both solutions utilize block-based technology to unify data protection operations.

      White Paper

      Guaranteeing 100% Backup Recovery

      The single biggest challenge for IT personnel involved in the data protection process is making sure that their backups are recoverable every time. Management and users won't remember the ninety-nine successful recoveries but they will always remember the one failure.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question