Compliance and Security. What’s the Difference?

IT Compliance and IT Security are related but distinct. IT Compliance meets the demands of a third party, the SEC or FDA, for instance. IT Security meets the demands of the competitive environment, customer expectations, and the reality of the marketplace. Both IT Compliance and IT Security are essential. Miss on the former, you face potentially significant fines and penalties. Missing the latter, you face potentially losing customers, reputation, etc. IT Consulting can help small and medium-sized businesses meet this challenge.  



Like the Health Insurance Portability and Accountability Act (HIPPA), some frameworks are specific to an industry. Others, like ISO 27001 or ISO 27002, are broad and can be adapted to various sectors. There is overlap in some frameworks. An astute IT compliance consulting team can find ways to create “crosswalks” that allow your company to demonstrate compliance with different regulatory standards without unnecessary duplication of effort. 

HIPPA - The Health Insurance Portability and Accountability Act.

PCI-DSS - Payment Card Industry Data Security Standard.

SOX - Sarbanes-Oxley.

This federal law, which went into effect in 2002, established comprehensive auditing and financial recordkeeping and reporting regulations for corporations. 


