Skip the navigation
Opinion

Privacy software: Who are the early leaders?

By Jay Cline
August 12, 2010 11:43 AM ET

Computerworld - Anybody responsible for data privacy soon discovers a hard truth -- privacy compliance is a highly manual undertaking. Whether it's tracking where all of the company's data is or keeping up with changes in obscure privacy laws, the privacy professional is often sentenced to a life behind spreadsheets. If privacy didn't deal with cutting-edge social issues, it might contend for the most tedious job in the corporate center.

But the tedium may be lifting.

The privacy profession, which just 10 years ago fit into a single conference room in Washington, has grown large enough to form a reliable market for software products. When in 2006 I first estimated the North America-dominated privacy-advice market at $400 million, membership in the International Association of Privacy Professionals (IAPP) stood at 2,000. The IAPP now has over 6,000 members, according to its recent paper on the future of the privacy profession. Other benchmarks such as the number of privacy consultants and lawyers suggest the world privacy-advice market is now around $1 billion.

A handful of software entrepreneurs has noticed. Together they form what I'd call the "privacy GRC" market, where GRC stands for "governance, risk and compliance." GRC makes up most of what privacy people do.

It's not a big market. To put things into perspective, Gartner is only in its third year of analyzing the nascent IT GRC market. The privacy GRC market is at the moment no more than just a subset of that.

Nonetheless, the number of privacy GRC products is growing. Over the past year I noticed more of these booths at the privacy conferences I attended. So I commissioned research analyst Michael Lotti to help me investigate.

What did we find?

1. Foundational regulatory mapping and policy features

One of the biggest pain points of the privacy officer is the continued churn of new privacy regulations. Global corporations are now subject to an overlapping web of data privacy and security laws and standards. To cope, their privacy staff are busy tracking legislation and mapping the common requirements in each law to a set of unified control statements. An example of a control statement is "encrypt sensitive data transmitted outside Company networks." The privacy people -- months later, usually -- then group these controls into enterprise policies.

Most of the tools that Michael and I looked at -- including those from Archer, brinQa, Agiliance, ControlCase, Avior Computing and Consult2Comply -- automate this chore, albeit to varying degrees. Among these, Consult2Comply stands out from the crowd for the number of regulations mapped and the flexibility of how to reorient the mapping to your own needs.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
CA Technology Brief: CA Point of View: Content Aware Identity & Access Management
This paper explores the concept of content-aware IAM, describes the integrated architecture for this new approach, and highlights the benefits that this approach...
Google: Security for Google Apps Messaging & Collaboration
Content provided by Google

Find out about how Google creates a security-based platform for Google Apps, covering topics like information security, physical security, and...
An Interactive Guide: Bring Your Own Device
BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
Fundamental Principles of Network Security
This paper covers the fundamentals of secure networking systems, including firewalls, network topology and secure protocols. Best practices are also given that introduce...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs