Beyond Compliance: Forrester's 5 Key Principles

Published: Feb. 9, 2010, 1:11 p.m.

Khalid Kark, vice president at Forrester Research, recently wrote an in-depth report on healthcare information security in which he described five key principles.\n\n

In an interview, Kark discusses each principle, including:\n\nTake a risk-based approach and look beyond regulatory compliance, focusing instead on creating a broader security framework;\nFollow the data through its entire life cycle, making sure it's protected when it's in the hands of business partners, outsourcers and others;\nEquip yourself with the ability to monitor and respond to security incidents;\nFocus on third parties and business associates, making sure all agreements spell out security provisions; and\nBe prepared to respond to the changing technology and threat landscape, such as the increasing use of social networks.\n\n

Kark focuses on information security issues for clients of Forrester Research, a Cambridge, Mass.-based firm that offers consulting as well as research reports.