IT Compliance Institute - Privacy Enforcement Still... -
[Cached Version]
Published on: 11/16/2007
Last Visited: 8/16/2008
In this regard, says Randy Betancourt, manager of Customer Relationship Management (CRM) solution strategy with SAS, it's possible for companies to devise their own controls and automated processes and to implement them in SAS software, and possibly into products from most major BI, enterprise resource planning, and CRM software vendors.
"The technology stack that is commonly used is very robust with respect to the fact that you can hide any attribute that you collect about customer data, and that granularity of control is typically a function of the operations of those firms [that are collecting the data]," he confirms.
When custom applications or more elaborate scenarios involving heterogeneous systems and multiple locations are factored into the mix, however, compliance can be a much trickier proposition, largely, Betancourt and other experts say, because the process of identifying potential controls becomes more complicated."Every vendor gives you the feature and function set that allows you to instrument these types of controls, it's just how do you map the regulatory and instrumental rules into the software?"he says.