Compliance Bonanzas
Computerworld - When was the last time you read about a $40,000 retention bonus for someone with a hot skill in IT? I'll bet it was sometime around the turn of the century, when Y2k fears had CEOs wringing their hands and CFOs signing checks for whatever IT asked for.
Today, it's a different story with some eerie echoes. The latest salary bonanzas aren't tied to arcane skills in Cobol programming but to IT auditing experience applicable to the slew of regulatory compliance issues companies are facing. In our front-page story last week ("IT Auditors Coveted, Hard to Find," QuickLink 46577), we wrote about one enterprise risk manager being courted with generous raises, bonuses and stock options from a pair of Fortune 250 companies anxious to get him on staff as the year-end Sarbanes-Oxley compliance deadline looms.
The big accounting firms are also hiring briskly to beef up their in-house expertise in everything from Sarbanes-Oxley and HIPAA to the Patriot Act, the Gramm-Leach-Bliley Act and the European Union's directive on privacy protection. Ernst & Young, for example, has expanded its IT risk practice by 30% in the past 10 months and has 200 openings to fill by the end of next month.
A lot of people I've talked with lately believe -- or maybe hope -- that all these regulatory mandates will turn out to be another kind of bonanza for IT. That they'll force companies to clean out their data closets and reorganize business processes. That they'll usher in new project disciplines, forge stronger IT-business partnerships and strengthen relationships with customers by better protecting their privacy. And, of course, that they'll elevate security and privacy protections to new heights of corporate support.
Those are very seductive notions, and I'd love to believe them. But I also hear the distant ring of the dej? vu bell. An awful lot of ill-conceived ERP projects were launched under the banner of Y2k rescues, and those later came back to bite IT with outrageous cost overruns, disappointing results and a wider-than-ever credibility gap with senior management. The risk of repeating history is a significant one, and there's a lot more at stake than the reputation of the IT organization.
Last week, I moderated a panel discussion at UCLA on regulatory compliance and corporate security, with a speaker lineup that included chief security officers and privacy and legal experts. Attorney Peter Adler, a partner at Washington-based Foley & Lardner, cautioned the audience about creating silos of regulatory compliance expertise - for example, having a set of



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Gov't Legislation/Regulation White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Gov't Legislation/Regulation Webcasts