<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Situational Room by eIQnetworks &#187; HIPAA</title>
	<atom:link href="http://situationalroom.wordpress.com/tag/hipaa/feed/" rel="self" type="application/rss+xml" />
	<link>http://situationalroom.wordpress.com</link>
	<description></description>
	<lastBuildDate>Thu, 26 Jan 2012 14:02:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='situationalroom.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>The Situational Room by eIQnetworks &#187; HIPAA</title>
		<link>http://situationalroom.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://situationalroom.wordpress.com/osd.xml" title="The Situational Room by eIQnetworks" />
	<atom:link rel='hub' href='http://situationalroom.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Security and Compliance: They Are Not the Same Thing… But That’s OK</title>
		<link>http://situationalroom.wordpress.com/2011/08/29/security-and-compliance-they-are-not-the-same-thing%e2%80%a6-but-that%e2%80%99s-ok/</link>
		<comments>http://situationalroom.wordpress.com/2011/08/29/security-and-compliance-they-are-not-the-same-thing%e2%80%a6-but-that%e2%80%99s-ok/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 13:00:01 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[compliance automation]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SOX]]></category>
		<category><![CDATA[Stuxnet]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=806</guid>
		<description><![CDATA[Does your organization have a security program, or a compliance program?  What’s that you say?  “If we’re complying with security mandates, then we have security”… Well, not really.  It’s time to put the myth to bed. Ultimately, most compliance mandates – PCI DSS, HIPAA, SOX, GLBA, and others – are about protecting one type of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=806&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Does your organization have a <em>security</em> program, or a <em>compliance</em> program?  What’s that you say?  “If we’re complying with security mandates, then we have security”… Well, not really.  It’s time to put the myth to bed.</p>
<p>Ultimately, most compliance mandates – PCI DSS, HIPAA, SOX, GLBA, and others – are about<span id="more-806"></span> protecting one type of data, not necessarily <em><span style="text-decoration:underline;">all</span></em> business data, or all aspects of the systems that store, transmit and process.  In some cases, the target is credit and debit card data (PCI DSS), protected healthcare information (HIPAA), or consumer data (GLBA).  In other cases, it’s a specific type of data, such as financial reports (SOX), and only one aspect of that data (in the case of SOX, integrity of the data… not so much confidentiality or availability).</p>
<p>Regardless of the regulation, their goal is to function as a <em><span style="text-decoration:underline;">starting point</span></em> for a security program that minimally meets their requirements, but is further augmented with additional policies, standards, procedures and controls to protect all valuable assets within the organization.  In order to protect sensitive data from either internal or external threats, it&#8217;s important that systems and processes are developed to achieve not only these minimum regulatory requirements, but the additional objectives that make a full-blown security program – which is actually much is harder than it sounds.  Proving either can also be a real challenge for many organizations.</p>
<p>From a compliance perspective, you “can check all of the boxes” to demonstrate that you’re meeting a regulatory standard, but that doesn&#8217;t mean that your entire infrastructure is secure.  Take Stuxnet, for example, which targeted the industrial software running on Siemens PLCs (programmable logic controllers).  While energy-related organizations could comply with all of the necessary network security regulations relating to their industrial systems (such as the NERC CIP standards), that won&#8217;t stop a Stuxnet-style attack that enters the infrastructure via another part of the network that slowly – but surely – makes its way to its intended target.  In the case of Stuxnet, it was Siemens PLC units.</p>
<p>Ensuring information security and regulatory compliance isn&#8217;t easy.  It often requires different data sets to be analyzed and recorded &#8211; creating additional work for already stretched information security professionals.  Fortunately, there are some basic, overlapping components to many regulations that also happen to be fundamental aspects of good security practices:</p>
<ul>
<li>Visibility into <em><span style="text-decoration:underline;">all</span></em> security-related data (not just one type of data, like logs/events)</li>
<li>Correlation of data to determine when bad things are happening</li>
<li>Demonstration of improvement in compliance and security posture over time</li>
<li>Quantitative risk monitoring to identify systems that are at-risk</li>
<li>Easy reporting to demonstrate both compliance and network security</li>
</ul>
<p>Wouldn’t it be nice if there was a way to capture all your network security data from across an entire Enterprise network in real time and report against different subsets &#8211; not just from today, but yesterday… or last week… or perhaps last month in order to evidence network security or compliance with regulatory mandates?</p>
<p>Somebody ought to develop a <a title="SecureVue" href="http://www.eiqnetworks.com" target="_blank">platform like that</a>…</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/806/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/806/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/806/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/806/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/806/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/806/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/806/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/806/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/806/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/806/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/806/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/806/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/806/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/806/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=806&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2011/08/29/security-and-compliance-they-are-not-the-same-thing%e2%80%a6-but-that%e2%80%99s-ok/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>Press Release: ComplianceVue Packages for PCI DSS, NERC CIP, and HIPAA</title>
		<link>http://situationalroom.wordpress.com/2009/09/09/press-release-compliancevue-packages-for-pci-dss-nerc-cip-and-hipaa/</link>
		<comments>http://situationalroom.wordpress.com/2009/09/09/press-release-compliancevue-packages-for-pci-dss-nerc-cip-and-hipaa/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 00:00:57 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[compliance automation]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=168</guid>
		<description><![CDATA[Today eIQ announced new ComplianceVue Packages, a turnkey offering to address compliance reporting requirements based on its SecureVue® security and compliance management platform. The ComplianceVueTM packages (PCIVueTM, NERCVueTM, and HIPAAVueTM) provide detailed compliance reporting across more than just log data, greatly surpassing the capabilities of competitive products. ComplianceVue packages are available immediately to address PCI-DSS, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=168&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Today eIQ announced new ComplianceVue Packages, a turnkey offering to address compliance reporting requirements based on its SecureVue® security and compliance management platform. The ComplianceVue<sup>TM</sup> packages (PCIVue<sup>TM</sup>, NERCVue<sup>TM</sup>, and HIPAAVue<sup>TM</sup>) provide detailed compliance reporting across more than just log data, greatly surpassing the capabilities of competitive products. ComplianceVue packages are available immediately to address PCI-DSS, NERC CIP and HIPAA regulatory requirements.</p>
<p>“eIQnetworks already correlates data from more data sources than any other solution on the market, and for that reason SecureVue is uniquely positioned to identify sophisticated in-progress attacks or vulnerabilities that log-only solutions will miss,” said Vijay Basani, eIQnetworks’ CEO. “With the ComplianceVue packages, eIQ now offers a turnkey solution for comprehensive compliance reporting across a broad range of security data including events, configuration data, vulnerabilities, and network flows, proving again that ‘log data is not enough’ to properly prove adherence to regulatory rules.”</p>
<p>The new ComplianceVue packages include a SecureVue Central Server, and the associated compliance reporting modules and dashboards required to provide necessary documentation for regulatory-driven audits. Reporting is effortless, and section-specific compliance reports are directly linked to appropriate rules and requirements of each supported regulation, best practice, or standard. Interactive dashboards provide real-time views into key compliance metrics, and provide drill-down into underlying data to support comprehensive internal and external auditing needs.</p>
<p>For more details and benefits on the new ComplianceVue package, check out the full press release on the eIQ site: “<a href="http://www.eiqnetworks.com/news/eIQ_ComplianceVue_Final.shtml">eIQnetworks Introduces ComplianceVue Packages for PCI, NERC and HIPAA to Streamline Regulatory Compliance Reporting</a>”</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/168/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=168&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2009/09/09/press-release-compliancevue-packages-for-pci-dss-nerc-cip-and-hipaa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
	</channel>
</rss>
