A staggering number of industry and governmental regulations exist today, each with a security requirement. In most cases, requirements state the responsibility of management for establishing and maintaining an adequate internal control and audit structure, procedures for financial and regulatory reporting. Organizations must provide an assessment of the effectiveness of the internal control structure and procedures. These assessments must show the ability to detect problems with data alteration and general security; analyze overall data security; protect and maintain data validity; and remediate data integrity issues within a repeatable process framework From a network security perspective, this means a company needs to secure their IT environment by protecting, analyzing and remediation their vulnerabilities in a repeatable controlled manner. |