Organizations responsible for handling and storing customer information must protect personal data, including health records and financial information. In the United States and abroad, regulatory statutes such as the Health Insurance Portability and Accountability Act (HIPAA), Sarbanes Oxley (SOX) and the Payment Card Industry Data Security Standard (PCI DSS) have been established to define responsibilities and practices, and are backed by financial penalties for public or private organizations that fail to comply.

Policy creation and management fulfill compliance while communicating boundaries, expectations, and establishing a culture of compliance within the organization.
policy graphic
Policy management is the process of creating, communicating, and maintaining policies and procedures within an organization.
  1. Have you established roles and responsibilities for data security, cybersecurity, and privacy
  2. Have you identified and documented all the privacy (aka “data protection”) laws and regulations to which you must comply?
  3. Are your cybersecurity and privacy policies, procedures and practices up-to-date?
  4. When was the last time you performed a risk assessment
  5. Did you consider vendor risks?
  6. Are your documents up to date?
  7. Does your documentation cover technology including internet, work-from-home personnel?