https://www.techtarget.com/searchsecurity/answer/How-can-companies-implement-ITSM-compliance-standards
How can companies map ITSM innovations to regulations?
Those responsible for IT service management (ITSM) consistently struggle to align tech innovation with existing regulations, policies and procedures. Contracts are often not written to anticipate the innovations and these failures in foresight can create significant ITSM compliance risks.
Privacy, information security, confidentiality and intellectual property rules often express requirements using imprecise words such as "reasonable," "suitable" or "adequate" to define the level of quality required for specific services or systems. An example rule could read, "Employers shall adopt and use reasonable controls appropriate to the sensitivity of the health information records of their employees."
I refer to these terms as SIAM terms, because they are Semantically Intentionally Ambiguous in Meaning. These words are descriptors for a system, process, control or known data set. The challenge for ITSM managers is to align its innovations to compliance regulations or contract requirements with ambiguous terms like these.
When trying to decode SIAM terms for ITSM compliance risk, use a simple formula: X is Y if, where X is the object or thing, and Y is the SIAM term.
X= privacy control
Y= reasonable
Plug into the formula X is Y if so your statement reads: The privacy control is reasonable if…
What follows the "if" are answers to the following seven questions (be forewarned, the answers are not always easy to express):
Answering these questions produces a well-designed alignment between the ITSM innovations and compliance regulations or rules that are, in themselves, not authored to be easily aligned.
This Ask the Expert is based on "Bridging the Chasm of SIAM", a chapter in Jeffrey Ritter's book, Achieving Digital Trust: The New Rules for Business at the Speed of Light.
12 Oct 2018