Agiliance for the High Technology Industry

The high-technology industry needs to address various regulations: those imposed on the industry, as well as those it needs to comply with based on the operations of its business units. For example, an electronics contract manufacturer that builds components for the medical device industry needs to also abide by FDA regulations.

Key regulations and mandates include:

  • Companies that sell to medical device companies are required to comply with FDA GXP regulations, which place a huge emphasis on change management and security of the IT infrastructure.
  • WEE and ROHS requirements include ensuring that the component history can not be tampered with through unauthorized access.
  • Companies doing business in the state of California have to comply with SB 1386 the California Security Breach Information Act.
  • Credit card companies have created the Payment Card Industry Data Security Standard (PCI DSS) and have setup strict compliance guidelines for consumer electronics companies that directly sell products on the web via credit cards.
  • Publicly traded technology companies need to comply with the Sarbanes-Oxley Act (SOX).

As a result, companies in the technology industry need to comply simultaneously with multiple regulations and mandates that impact information systems security issues. To deal with multiple regulations, organizations have deployed a wide array of products which add layers of protection but also add significant complexity and cost. Despite substantial investments, most organizations still struggle to find a mechanism to define and enforce the right policies and controls to comply with such overlapping regulations in a cost effective manner.

The Agiliance IT-GRC platform was specifically designed to address these issues. Its solution enables you to:

  • Implement frameworks such as ISO 17799/27001, COBIT and others
  • Gain a holistic and real-time view of security, compliance and risk across your whole enterprise
  • Enforce and monitor policies & controls across functional and geographical boundaries within an organization
  • Improve compliance with federal and state regulations, as well as with industry mandates.