Get Informed.

Take the first step in identifying your priorities, conducting a side-by-side product analysis and finding a solution that suits your needs.
Download your Buyer's Guide »

Get Started.

See IdentityIQ in action and how it can work for you.
Request your one-on-
one demo today »

Get Support.

Take advantage of SailPoint's helpful resource center with a collection of documentation on a range of today's hottest topics in identity management.
Learn more »

Get Informed.

Take the first step in identifying your priorities, conducting a side-by-side product analysis and finding a solution that suits your needs.
Download your Buyer's Guide »

Get Started.

Make the most of SailPoint's online support system, Compass, to plan, pilot, implement and deploy SailPoint IdentityIQ across your entire organization.
Log in now »

Get Support.

SailPoint's customer support portal is available 24x7. Request an account today and get the help you need.
Learn more »

Get Informed.

Take the first step in identifying your priorities, conducting a side-by-side product analysis and finding a solution that suits your needs.
Download your Buyer's Guide »

Get Started.

Learn more about how to become a SailPoint partner today.
Contact us »

Get Support.

SailPoint partners can access the knowledgebase, training info and more on Compass.
Request an account today »

Get Informed.

On a deadline? Reach out to the SailPoint PR team. Contact Erin Hanley at pr@sailpoint.com or 512-346-2000 ext. 32.
Contact Us »

Get Started.

Keep in touch with the latest news from SailPoint by subscribing to our quarterly newsletter.
Subscribe today »

Get Support.

Contact us today and let us know how we can help you.
Learn more »

Get Informed.

Keep in touch with the latest news from SailPoint by subscribing to our quarterly newsletter.
Subscribe today »

Get Started.

Join one of the industry's fastest growing companies! Visit our Careers page to see available opportunities.
Apply today »

Get Support.

Contact us today and let us know how we can help you.
Learn more »

Get Informed.

Keep in touch with the latest news from SailPoint by subscribing to our quarterly newsletter.
Subscribe today »

Get Started.

See IdentityIQ in action and how it can work for you.
Request your one-on-
one demo today »

Get Support.

Contact us today and let us know how we can help you.
Learn more »

Get Support.

Talk directly to a member of SailPoint's technical support team by calling: +1 (512) 346-2000 x 771.
Get support »

Get Informed.

Customers have access to user community discussions, the knowledgebase, training and documentation on Compass.
Request an account today »

Get Started.

Login to Compass, the online community portal, to access the support portal and get answers today.
Log in now »

Bookmark and Share

New Auditor Survey Confirms Poor Communication, Inefficiencies Cripple IT Compliance Efforts

Risk-Based Approach Widely Viewed as Key to Gaining Control of Access to Critical Systems and Data

TRAVERSE CITY, Mich. and AUSTIN, Texas, August 6, 2007 – New research from the Ponemon Institute reveals that, despite the importance internal auditors and corporate compliance professionals place on ensuring proper access to systems and data – 70 percent of respondents say it is critical to IT compliance – the majority report inadequacies in current practice. Eighty-two percent say a risk-based approach would be more effective.

"Audit and compliance professionals are clearly struggling to gain control over issues at the heart of IT compliance, knowing who has access to what in your organization," said Larry Ponemon, chairman and founder, Ponemon Institute. "They must do an incredibly complex and important job the hard way – manually and reactively – and they know it. Almost all would prefer to focus their efforts on the areas of greatest business risk, but they need help getting there."

Commissioned by SailPoint Technologies, the survey, entitled Audit & Compliance Professionals: Survey on Identity Compliance, examines the views of auditors and corporate compliance staff on the state of compliance practices that focus on ensuring proper access to systems and data. Findings from analysis of 845 responses point to a number of inadequacies including:

  • Reliance on Manual Processes – Audit and compliance staff rely on manual efforts to manage compliance processes. Fifty-eight percent manually monitor and test controls on user permissions and activities, depending almost exclusively on reports generated by others rather than software tools (90 percent).
  • Lack of Centralized Control – Organizations have not established clear ownership of compliance oversight or processes around reporting on and monitoring user access to critical systems and data, with a wide majority conducting compliance efforts in a decentralized fashion at the application or department level (86 percent). Fragmentation of the data and distribution of responsibility among many groups are cited as the top two barriers to automating compliance.
  • Poor Communication and Collaboration – Audit and compliance staff report little to no collaboration with departments who share responsibility for IT compliance (61 percent), citing a poor understanding of risk management and compliance among other departments as the key barrier (65 percent).
  • Inattention to Business Risk – Asked if their organizations focus their compliance resources or efforts based on risk, half do not think so or are unsure, and the majority report the information necessary to quantify risk is simply not available (58 percent).

The full survey offers a comparative analysis of responses from audit and compliance staff with responses from IT security professionals to an earlier companion survey published by the Ponemon Institute in March 2007, also commissioned by SailPoint. Major points of agreement between the groups are poor collaboration and reliance on manual processes: IT professionals report little to no collaboration with audit and compliance staff (65 percent), citing a lack of technical expertise as the key barrier (42 percent); and 53 percent characterize efforts as manual and labor-intensive. Eightythree percent of IT respondents also say a risk-based approach would be more effective for ensuring proper access to systems and data. Key differences are business drivers – audit/compliance groups seek better control and security (44 percent) while IT groups seeks higher efficiency (40 percent).

"Organizations are achieving compliance by throwing people at the problem, but they don't know where their risks are," said Jackie Gilbert, vice president of marketing and founder of SailPoint. "By taking steps to centralize and automate their efforts, companies can begin to regain control with a sustainable and effective approach that allows them to identify and reduce potential business risks like intellectual property loss, privacy breaches, brand damage and inaccurate financial reporting."

For a copy of the Audit & Compliance Professionals: Survey on Identity Compliance, go to http://www.sailpoint.com/studies/ponemon2. Please visit the Resource Center at http://www.sailpoint.com for a copy of the companion piece Survey on Identity Compliance.

About The Ponemon Institute

The Ponemon Institute© is dedicated to advancing responsible information and privacy management practices in business and government. To achieve this objective, the Institute conducts independent research, educates leaders from the private and public sectors and verifies the privacy and data protection practices of organizations in a variety of industries.

About SailPoint

SailPoint Technologies, Inc. develops software with unique "Identity Intelligence" that helps organizations achieve regulatory compliance, improve internal controls and manage risks associated with the proliferation of enterprise-wide identity data. Founded in December 2005, SailPoint is based in Austin, Texas.