Forum Replies Created
-
AuthorPosts
-
May 29, 2024 at 5:59 pm in reply to: Does your organization already have a document library already and, if not, where will you store documents? #60006Robert CollinsParticipant
Yes, electronic document repositories specific to ITAM with libraries of policy templates, policies, processes and procedures. We source these and share with our customers
May 29, 2024 at 5:56 pm in reply to: Name legislations you’re familiar with that likely will affect your ITAM program. #60005Robert CollinsParticipantHere are some examples I can supply. Depending on the state, there will be more. In addition there will be regulations in other regions; APAC (Asia Pacific Countries), EMEA (Europe, Middle East, and Africa), LATAM (Latin America).
These are some of the US Federal laws and regulations that impact ITAM in the United States of America.
Sarbanes-Oxley Act (SOX) – This law mandates strict reforms to improve financial disclosures from corporations and prevent accounting fraud. It impacts ITAM in terms of record-keeping and the management of electronic records.
Federal Information Security Management Act (FISMA) – It requires federal agencies to develop, document, and implement an information security and protection program.
Health Insurance Portability and Accountability Act (HIPAA) – HIPAA sets the standard for protecting sensitive patient data. Any company that deals with protected health information (PHI) must ensure that all the required physical, network, and process security measures are in place and followed.
Gramm-Leach-Bliley Act (GLBA) – This act obliges financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data.
Federal Information Technology Acquisition Reform Act (FITARA) – This law aims to reform the management and acquisition of federal information technology.
Federal Risk and Authorization Management Program (FedRAMP) – This program provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies.
Cybersecurity Information Sharing Act (CISA) – This act encourages the sharing of information about cybersecurity threats between the government and companies in the private sector.
The National Institute of Standards and Technology (NIST) Special Publications – NIST SP 800 series provide guidelines and best practices for federal information systems, including those relevant to ITAM.
The Defense Federal Acquisition Regulation Supplement (DFARS) – This set of regulations includes requirements for safeguarding defense-related data and reporting cybersecurity incidents.
The Federal Acquisition Regulation (FAR) – This regulation governs the acquisition process by which the federal government acquires goods and services, including IT assets.
The Economic Espionage Act (EEA) – This act makes the theft or misappropriation of a trade secret a federal crime.
The Children’s Online Privacy Protection Act (COPPA) – It imposes certain requirements on operators of websites or online services directed to children under 13 years of age.
The Patriot Act – This law includes provisions that impact ITAM, particularly in the areas of data retention and surveillance.
The Privacy Act of 1974 – This act establishes a code of information practices that governs the collection, maintenance, use, and dissemination of personally identifiable information about individuals that is maintained in systems of records by federal agencies
Others are periodically added in response to incidents, and often, State and Local regulations and ordinances are established that mirror those found at the Federal level as grants and other support are aligned to and reinforced by these.
May 29, 2024 at 5:33 pm in reply to: What educational events will you attend to improve your ITAM skills? #60004Robert CollinsParticipantAll available events possible with a nod to cost of course, virtual, physical, exchanges, community memberships, social media
May 29, 2024 at 5:28 pm in reply to: Discuss whether communication or education is more important. #60003Robert CollinsParticipantcommunication and education are combined as they are forms of each other, the same really
Robert CollinsParticipantincoming vs dispositioned assets = total expected inventory qty of assets, point in time
May 29, 2024 at 4:46 pm in reply to: What do you think is the most important policy for an ITAM program? #59996Robert CollinsParticipantAll requests must come through the ITSM solution
May 29, 2024 at 4:39 pm in reply to: Policies must be enforced. What consequences will there be if they are not followed? #59994Robert CollinsParticipantthis will go down on your permenant record
May 29, 2024 at 4:35 pm in reply to: Consider a process in your organization and brainstorm how to simplify it. #59993Robert CollinsParticipantFirst fully map the process then analyze, find the bottlenecks, look at timing and apply improvements to efficiency
May 29, 2024 at 4:29 pm in reply to: In what ways will your office culture affect how you communicate? #59992Robert CollinsParticipantit won’t change
May 29, 2024 at 4:21 pm in reply to: What’s the first policy you’ll create and enforce in your ITAM program? #59990Robert CollinsParticipantdiscovery
May 29, 2024 at 2:02 pm in reply to: Critique the roles and responsibilities, what other key stakeholder might be present in your organization? #59977Robert CollinsParticipantAll users are stakeholders, therefore all users are expected to be identified and communicated. If any are identified as exceptions then the process to inform ITAM needs to be adjusted to take that into consideration.
May 29, 2024 at 1:49 pm in reply to: Consider the executives you’ll have to convince. What negotiation skills will you have to use? #59976Robert CollinsParticipantall of them, I’m sure.
May 29, 2024 at 1:39 pm in reply to: What roles and responsibilities do you have or anticipate you’ll have in your ITAM program? #59975Robert CollinsParticipantAll of them.
Robert CollinsParticipantThis is no more than a current vs future state excercise, I do these for every customer for any processes that we together deem are in scope.
May 29, 2024 at 1:16 pm in reply to: What non-verbals are you using right now as you read these discussion questions? #59971Robert CollinsParticipantreading
-
AuthorPosts