|
ABSTRACT:
This paper presents a data-centric compliance reference model for identity management solution implementation. Data centric approach focuses on mapping each compliance mandate to sensitive data in applications and then ensure integrity, timeliness and security of such data. The objectives of integrity, timeliness and security are met through the four-step compliance reference model implementation. After describing various solution components in detail, the paper attempted to apply the reference model to SOX, HIPAA and GLB requirements to demonstrate that the data centric approach delivers on the regulatory requirements in the area of identity management.
|