Designing Common Control Frameworks: A Model for Evaluating Information Technology Governance, Risk, and Compliance Control Rationalization Strategies

Lance Hayden · Information Security Journal A Global Perspective · 2009

Information security professionals are faced with increasing compliance obligations associated with laws, regulations, and industry standards. Meeting multiple control framework requirements separately can be costly and inefficient due to similarities between various frameworks that produce redundancy duplication of effort in the organization's compliance initiatives. To mitigate these inefficiencies many organizations are seeking to streamline and rationalize frameworks in ways that combine overlapping control objectives into a smaller set of controls that still meet the requirements of all frameworks included. This article discusses strategies for such rationalizations, including the benefits and limits of specific strategies.

Read the paper · More papers on PaperTik