<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Following the White Rabbit Blog : HIPAA</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/HIPAA/default.aspx</link><description>Tags: HIPAA</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Compliance: Ushering in the Apocalypse!?</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2008/11/17/compliance-ushering-in-the-apocalypse.aspx</link><pubDate>Mon, 17 Nov 2008 03:56:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:86635</guid><dc:creator>RafalLos</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/securitysoftware/blogs/rafal/rsscomments.aspx?PostID=86635</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2008/11/17/compliance-ushering-in-the-apocalypse.aspx#comments</comments><description>&lt;p&gt;&amp;nbsp; I read an interesting article tonight, on my flight out to Washington, DC for the CSI Conference (where I hope to meet some of you... ping me if you&amp;#39;re here and I haven&amp;#39;t talked to you yet).&amp;nbsp; This article, titled &amp;quot;&lt;a class="" title="The Coming HIPAAcalypse" href="http://takingthehelloutofhealthcare.com/blog/2008/11/14/the-hipaapocalypse/" target="_blank"&gt;The Coming HIPAAcalypse&lt;/a&gt;&amp;quot;, presented a very grim view of compliance with the HIPAA regulations, but the author could have just as easily been talking about PCI or any other regulation.&amp;nbsp; As I read this article I couldn&amp;#39;t help but think... &amp;quot;What does it have to be this difficult?&amp;quot;&amp;nbsp; I say this from experience, having been there in the thicket of PCI compliance in a previous job - trying to manage the complexities of budget, compliance need, and resources with frustration to spare - but does it really have to be so hard?&lt;/p&gt;
&lt;p&gt;&amp;nbsp; Thinking in the context of web applications - that&amp;#39;s the focus of this blog - everyone has them in their business.&amp;nbsp; What&amp;#39;s more, everyone has mission-critical applications in their business.&amp;nbsp; Further than that... these applications must be available, usable AND secure... 24x7x365.&amp;nbsp; This can at times seem like an unattainable goal when you add compliance to the mix.&amp;nbsp; You know you&amp;#39;ve been there, and you&amp;#39;ve wondered how you&amp;#39;re going to solve these issues.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;I offer a glimmer of hope.&amp;nbsp; When it comes to compliance, &lt;strong&gt;automation is the key&lt;/strong&gt;.&amp;nbsp; You won&amp;#39;t get more staff, more budget, or more resources especially with the looming economic conditions so how do you get into the compliance winner&amp;#39;s circle?&amp;nbsp; Automation.&amp;nbsp; If you can find a way to automate some of your security &amp;quot;testing&amp;quot;, you may be able to get complianct faster and have a few dollars left over for other critical security initiatives.&amp;nbsp; Automation of testing, data aggregation, and presentation of IT Risk as a component of compliance makes it easier to not only assess where your company is on the compliance journey - but also helps to (to use an old cliche) &amp;quot;do more with less&amp;quot;.&amp;nbsp; If you&amp;#39;re facing compliance challenges, and web applications are involved... this should ring bells for you.&amp;nbsp; If you&amp;#39;re interested in hearing more, or a message more customized to your specific situation - contact me directly, I may have an answer you can live with.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=86635" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/compliance/default.aspx">compliance</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/HIPAA/default.aspx">HIPAA</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/security+automation/default.aspx">security automation</category></item></channel></rss>