The act of complying with Regulations, Standards and Frameworks is becoming essential business practice. The IDL Compliance Program identifies the compliance issues that are generating compulsory and compelling IT investment across a variety of industry sectors.

Please select a different Industry sector from the menu below:

Utilities Banking Retail Supply Chain Public Sector
Healthcare Pharmaceuticals Automotive Supply Chain Telco

Issue Brief New Policy Driver IT Investment Implications Compliance Timetable
Canada Not-for-Profit Corporation Act Replaces the legislation for not-for-profit organisations to provide them with a “modern corporate governance framework”. Contains corporate governance issues and regulates the production and distribution of financial information. Accounting Systems
Corporate Governance Systems
Processors
Storage
ILM
Data Mining
Security
Disaster Recovery
Processor systems
Operational
Adopting similar approach to SOx and 52-111 IT solutions.
Update to Federal Managers Financial Integrity Act (FMFIA) Came about in light of the internal control requirements of Sarbanes-Oxley. FMFIA focuses on “improving the accountability and effectiveness of Federal programs and operations by establishing, assessing, correcting, and reporting on internal control.” Document Retention - Systems
Email Management - Systems
Content Management
Storage Solutions
Operational
Integrated IT reporting systems.
Design Criteria Standard for Electronic Records Management (ERM) Software Applications (DoD 5015.2) Definition of records management functionality in the US. Establishes baseline definitions and functional requirements for ERM software to be used by government agencies. Private sector should also use as specification as best practice for polices and procedures as well as vendor selection. Beyond specific records management software, this will impact storage and other ILM elements, email systems and processor systems. Operational
Operating and IT solutions emerging.
Access to Information Act This Act extends the present laws of Canada to provide the right of access to information in records under the control of a government institution. Data recovery tools
Data mining
Unstructured Data Repository and Recovery
Security
Backup
Disaster Recovery
Operational
Operating and IT solutions emerging.
Reporting Instructions for the Federal Information Security Management Act (FISMA) FISMA provides the framework for securing the Federal government’s IT. Requires all agencies to report quarterly and annually on the state of security and any remedial action taken to the Office of Management and Budget (OMB). Access security
Firewall
Encryption Technologies
Network Systems
Network Management and trace tools
Operational
Likely to adopt ISO 27001 as a best practice Information Security Management System [ISMS] and the associated integrated IT infrastructure.
Homeland Security Act US Act brought in to improve counter-terrorism measures. This wide-ranging act mandates the processing and sharing of many types of information across many different governmental agencies. Security
Storage
Communications
Data mining
Database
Operational
Likely to adopt ISO 27001 as a best practice Information Security Management System [ISMS] and the associated integrated IT infrastructures.
Government Paperwork Elimination Act - GPEA To allow persons to submit, maintain and disclose information to, and transact with, the government, electronically. The Act therefore, necessitates that federal agencies implement appropriate electronic solutions to improve public sector electronic and on-line interaction capabilities with citizens, reduce agency transaction costs and improve data analysis and access. Document/Content Management
CRM Solutions
Security Solutions
Operational
Operational and integrated IT solutions in procurements.
Help America Vote Act 2002 An act to provide funds to help replace existing punch card voting systems, to establish state-wide voting administration systems and establish minimum voting administration standards. Voting application
Database
Security
Networking
Processing Power
Printers
Optical Character Readers
Audit Trail
Reporting
Operational
Full compliance with section 301 defined voting system operational and IT systems purchasing started.
Multilateral Instrument 52-111 - Reporting on Internal Control over Financial Reporting

Canadian Securities Administrators (CSA)
The proposed requirements are expected to continue the harmonization of Canadian regulatory reporting and certification rules with Sarbanes-Oxley. Under the proposed rules, reporting issuers on the Toronto Stock Exchange (TSX) will have to adhere to the following:- Management will be required to issue a report on the effectiveness of internal control over financial reporting- An external auditor will be required to issue an audit report on management's assessment. Document management systems
Email management systems
Content management Storage & Security solutions
Disaster recovery
Updates to accountancy systems and ERP systems
Processing power, server and network
Operational
Implementation of IT to reduce cost and risk of reporting.
Personal Information Protection and Electronic Documents Act (PIPEDA) Canada PIPEDA is described as an act to “promote the use of electronic commerce by protecting personal information that is collected”. In doing so, PIPEDA prohibits the use of personal data without the explicit permission of the individual involved. It places requirements on the collector of the information to identify the use for the data, obtain permission for collecting the data and to hold it securely. Beyond this it must be shown that the data that has been stored has only been used in the way in which it was intended. Individuals may also request to be shown what has been stored and the uses to which it has been put. Storage
Audit Trail
Backup
Disaster Recovery
Security
Database
Electronic signature technologies
Operational
Operating and IT solutions emerging.
CAN-SPAM Act of 2003 (Controlling the Assault of Non-Solicited Pornography and Marketing Act) US The Act provides controls on the way email is used for commercial purposes. It requires that unsolicited commercial emails are clearly labelled and offer the recipient the ability to opt out. It prohibits the use of deceptive subject lines and false headers. It also stipulates that emails are not sent to automatically generated addresses or addresses gained through underhand ways. Audit Trail
Email Systems
CRM Systems
Authentication Technologies
Operational
Operating and IT solutions emerging.
58-201 Effective Governance and Proposed Multilateral Instrument This law and attendant instrument are in the final discussion stages in Canada. Based on the Toronto Stock Exchange’s (TSX) existing rules for corporate governance, these are expected to be passed for national (Canadian) policy. At the same time the TSX is expected to repeal its own laws to adopt 58-201. Document retention systems
Email management systems
Content management storage solutions
Operational
Fully operational and demand for IT solutions still expected to reduce cost and risks.
Corporate Information Security Accountability Bill Currently a draft bill that calls for US publicly listed firms to adhere to minimum IT security standards that would be set by the Securities and Exchange Commission (SEC). Proposes an annual audit with results to be submitted with annual reports and SoX submissions. Affects a wide range of security products to help companies comply with ‘industry standard’ security practices. Also requires tools to assist with gap analysis, scooping, audit. Potential
Draft bill.
California Database Breach Act. State Bill SB 1386 Applies to all individuals and organizations wishing to do business in California. This bill is designed to protect consumers from identity theft. It builds on existing privacy laws and mandates notice of breach of security or any other exposure. IT security applications and services
Customer data handling
Operational
Fully operational and demand for IT solutions still expected to reduce cost and risk.
Privacy Act The purpose of this Act is to extend the present laws of Canada that protect the privacy of individuals with respect to personal information about themselves held by a government institution and that provide individuals with a right of access to that information. Storage
Security
Data Management
Data Consolidation
Database
Data Mining
Disaster Recovery
Document Management
Operational
In operation and is continually being updated.
Do-Not–Call Registry The Federal Trade Commission (FTC) has amended the Telemarketing Sales Rule (TSR) to give consumers a choice about whether they want to receive most telemarketing calls. It will be illegal for most telemarketers or sellers to call a number listed on the registry. Similar standards and laws in UK, Direct Marketing Association ‘Preferred Services’. Data Storage
CRM
Operational
Adapting contact and call centre IT systems.
Enhancing Services Through the Innovative Use of Information and Technology This enshrines Canada’s e-Government initiatives taking a 10-year strategic vision of the steps and initiatives needed to deliver access to government services. Communications
Internet Services and Technologies
Security and user identification
Storage
Document Management
Data Consolidation
Operational
Steady demand for integrated IT solutions.
ISO 20000
IT Service Management Standard
ISO 20000 comprises two parts: ISO 20000-1 is the 'Specification for Service Management, and ISO 20000-2 is the 'Code of practice for Service Management'.

Together, these form a top-down framework to define the features of service management processes that are essential for the delivery of high quality services.

ISO 20,0000 allows IT organizations to formally certify their IT services, using ITIL [Information Technology Infrastructure Library] global best practice for IT service delivery.
Security Management
Storage Management
Business Application Management
Server, Network & Device Management
Operational
Rapidly adopted as the international standard for IT Service Management based upon ITIL based upon substantial TCO reduction as business case.
ISO 27001 Information Security Standard ISO 27001 is the formal standard against which organizations may seek independent certification of their Information Security Management Systems to reduce businesses’ information security vulnerability. ERP solutions
IT Security Applications and services
Operational
Rapidly being adopted worldwide as the standard for business’ information security.
IAS (International Accounting Standards) International standards on accounting and the regulation of financial result calculation. Designed to improve transparency and represent a step towards a common global accounting standard. Enterprise integration systems
Data gathering systems.
Operational
The legislation will require significant investment in appropriate systems to facilitate internal reporting and data gathering.
Copyright © 2010 Industry Direct Limited. All Rights Reserved.