Solving the compliance vs. mobile dilemma

14.09.2006
It's like an irresistible force about to crash head-on into an immovable object. On one side is a growing army of mobile employees, many of whom carry sensitive information with them when they leave the office. On the other side are federal regulations protecting the confidentiality, integrity and availability of that sensitive data.

Devices such as laptops, handhelds, smartphones and thumb drives are easily lost or stolen. If that happens, and if the device carries regulated data, your organization likely will be out of compliance with regulations. For Bill Bergen, the need to prevent that problem became obvious one day in a routine meeting.

"I was in a boardroom, and there was a thumb drive in the crack of a chair," recalled Bergen, CIO and vice president of technology services at Workscape Inc., a software and services provider focused on benefits administration and compensation planning.

"I pulled it out and said, 'OK, we just funded a project.' It turned out the thumb drive didn't have any data on it that was subject to regulation, but if you aren't on top of it every day, you lose touch with the risk."

Bergen and other experts said that while mobile technology can significantly increase productivity, it puts the compliance efforts of many organizations at risk. It's an issue that many organizations haven't dealt with head-on, they said.

Conflicting demands