{"id":58,"date":"2020-04-01T09:19:00","date_gmt":"2020-04-01T09:19:00","guid":{"rendered":"https:\/\/www.pwvconsultants.com\/blog\/?p=58"},"modified":"2020-06-04T01:34:47","modified_gmt":"2020-06-04T01:34:47","slug":"best-practices-for-staying-compliant","status":"publish","type":"post","link":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/","title":{"rendered":"Best Practices for Staying Compliant"},"content":{"rendered":"\n<p>Most businesses do compliance training once a year. It consists of a series of slideshows followed by a quiz that must be passed in order to continue doing your job. These same businesses often do a yearly audit as well to verify that all facets of the business remain in compliance. The problem with both of these is that it\u2019s far to infrequent. How can companies guarantee compliance? Everyone is most compliant on the day they are audited. What about the other 364?<\/p>\n\n\n\n<p>Auditing more frequently than once a year is a positive step. But doing so can be a large undertaking depending on business size. It can be costly in both time and money. It\u2019s a step in the right direction, but most businesses are not capable of doing monthly or even quarterly audits. So how can you ensure that your business remains in compliance?<\/p>\n\n\n\n<p>There are two best practices businesses can employ to ensure year-round compliance. First, implement proper training practices, and second, start toll gating.<\/p>\n\n\n\n<p>Annual training, testing and auditing is not enough. It\u2019s not targeted enough, it\u2019s basically giving the same training to everyone in the company whether it applies to them or not. While annual training and testing may be sufficient for those in certain positions, employees who are on the front lines and touching data on a regular basis should undergo training and testing on a quarterly basis, at minimum. This method keeps compliance in front of everyone, gives them a refresher and keeps them thinking about what they are doing to protect the company, clients and co-workers.<\/p>\n\n\n\n<p>The second, and probably most effective, way to remain compliant is to implement toll gating. This isn\u2019t a road block that prevents someone from doing their job, this is adding a small step that makes someone think before working with data. For example, a customer service rep gets a call. While on the call, the rep determines they need to pull certain sensitive data. They submit a request to their manager, who has a two minute SLA, to approve or disapprove the request. This step does not impact the rep\u2019s ability to do their job, but it will make them stop and think about whether the information they are requesting is actually needed. Without this step, the rep could pull up sensitive data they might not need and risk exposing a customer\u2019s information. With the step in place, the rep is more likely to try and solve the problem without contacting the manager, thus limiting exposure.<\/p>\n\n\n\n<p>This example can also apply to coders. Many places don\u2019t have code security review policies in place. But if a business pushes new code, a security review should be conducted as part of the process. If it doesn\u2019t pass the security review, it reverts back to the coder to fix it before it ever hits the system. This will teach coders to code securely from the beginning as opposed to having to fix code that\u2019s already been breached.<\/p>\n\n\n\n<p>Compliance governing bodies generally put programs in place, because someone has done something bad. Compliance is generally a reaction, resulting in a law, a bill or a set of rules that must be followed or there are repercussions. Most businesses have their employees complete this training as part of onboarding and annually to  \u201ccheck a box\u201d, but they do not take steps to ensure that compliance is followed throughout the year. The result is problems arise on the 364 days they aren&#8217;t under audit resulting in fines and fees accrued and customer data exposed. Implementing more frequent training and toll gating practices helps ensure businesses remain in compliance year-round.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Businesses have to follow compliance regulations or face steep fines. There are two best practices to help you stay in compliance year-round.<\/p>\n","protected":false},"author":1,"featured_media":61,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[6,4,14],"tags":[30,17],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v22.2 (Yoast SEO v22.2) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Best Practices for Staying Compliant - PWV Consultants<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Best Practices for Staying Compliant\" \/>\n<meta property=\"og:description\" content=\"Businesses have to follow compliance regulations or face steep fines. There are two best practices to help you stay in compliance year-round.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/\" \/>\n<meta property=\"og:site_name\" content=\"PWV Consultants\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/PWV-Consultants-110444033947964\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-01T09:19:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-06-04T01:34:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1700\" \/>\n\t<meta property=\"og:image:height\" content=\"2560\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Pieter VanIperen\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@PWV_Consultants\" \/>\n<meta name=\"twitter:site\" content=\"@PWV_Consultants\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Pieter VanIperen\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/\"},\"author\":{\"name\":\"Pieter VanIperen\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/person\/c15d5d40126a8ad906cb3067de95f8d4\"},\"headline\":\"Best Practices for Staying Compliant\",\"datePublished\":\"2020-04-01T09:19:00+00:00\",\"dateModified\":\"2020-06-04T01:34:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/\"},\"wordCount\":620,\"publisher\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg\",\"keywords\":[\"Compliance\",\"Security\"],\"articleSection\":[\"Compliance\",\"Information Security\",\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/\",\"url\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/\",\"name\":\"Best Practices for Staying Compliant - PWV Consultants\",\"isPartOf\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg\",\"datePublished\":\"2020-04-01T09:19:00+00:00\",\"dateModified\":\"2020-06-04T01:34:47+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#primaryimage\",\"url\":\"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg\",\"contentUrl\":\"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg\",\"width\":1700,\"height\":2560,\"caption\":\"Photo by Carl Newton from Pexels\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.pwvconsultants.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Best Practices for Staying Compliant\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#website\",\"url\":\"https:\/\/www.pwvconsultants.com\/blog\/\",\"name\":\"PWV Consultants\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.pwvconsultants.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#organization\",\"name\":\"PWV Consultants\",\"url\":\"https:\/\/www.pwvconsultants.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/04\/logo-alternate-e1585773530392.png\",\"contentUrl\":\"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/04\/logo-alternate-e1585773530392.png\",\"width\":98,\"height\":84,\"caption\":\"PWV Consultants\"},\"image\":{\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/PWV-Consultants-110444033947964\",\"https:\/\/twitter.com\/PWV_Consultants\",\"https:\/\/www.linkedin.com\/company\/pwv-consultants\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/person\/c15d5d40126a8ad906cb3067de95f8d4\",\"name\":\"Pieter VanIperen\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8b294918257a810803e2befc9a71b7bc?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8b294918257a810803e2befc9a71b7bc?s=96&d=mm&r=g\",\"caption\":\"Pieter VanIperen\"},\"description\":\"PWV Consultants is a boutique group of industry leaders and influencers from the digital tech, security and design industries that acts as trusted technical partners for many Fortune 500 companies, high-visibility startups, universities, defense agencies, and NGOs. Founded by 20-year software engineering veterans, who have founded or co-founder several companies. PWV experts act as a trusted advisors and mentors to numerous early stage startups, and have held the titles of software and software security executive, consultant and professor. PWV's expert consulting and advisory work spans several high impact industries in finance, media, medical tech, and defense contracting. PWV's founding experts also authored the highly influential precursor HAZL (jADE) programming language.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/pwv-consultants\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Best Practices for Staying Compliant - PWV Consultants","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/","og_locale":"en_US","og_type":"article","og_title":"Best Practices for Staying Compliant","og_description":"Businesses have to follow compliance regulations or face steep fines. There are two best practices to help you stay in compliance year-round.","og_url":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/","og_site_name":"PWV Consultants","article_publisher":"https:\/\/www.facebook.com\/PWV-Consultants-110444033947964","article_published_time":"2020-04-01T09:19:00+00:00","article_modified_time":"2020-06-04T01:34:47+00:00","og_image":[{"width":1700,"height":2560,"url":"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg","type":"image\/jpeg"}],"author":"Pieter VanIperen","twitter_card":"summary_large_image","twitter_creator":"@PWV_Consultants","twitter_site":"@PWV_Consultants","twitter_misc":{"Written by":"Pieter VanIperen","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#article","isPartOf":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/"},"author":{"name":"Pieter VanIperen","@id":"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/person\/c15d5d40126a8ad906cb3067de95f8d4"},"headline":"Best Practices for Staying Compliant","datePublished":"2020-04-01T09:19:00+00:00","dateModified":"2020-06-04T01:34:47+00:00","mainEntityOfPage":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/"},"wordCount":620,"publisher":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#primaryimage"},"thumbnailUrl":"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg","keywords":["Compliance","Security"],"articleSection":["Compliance","Information Security","Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/","url":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/","name":"Best Practices for Staying Compliant - PWV Consultants","isPartOf":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#primaryimage"},"image":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#primaryimage"},"thumbnailUrl":"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg","datePublished":"2020-04-01T09:19:00+00:00","dateModified":"2020-06-04T01:34:47+00:00","breadcrumb":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#primaryimage","url":"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg","contentUrl":"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/03\/time-lapse-photography-2280165-scaled.jpg","width":1700,"height":2560,"caption":"Photo by Carl Newton from Pexels"},{"@type":"BreadcrumbList","@id":"https:\/\/www.pwvconsultants.com\/blog\/best-practices-for-staying-compliant\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.pwvconsultants.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Best Practices for Staying Compliant"}]},{"@type":"WebSite","@id":"https:\/\/www.pwvconsultants.com\/blog\/#website","url":"https:\/\/www.pwvconsultants.com\/blog\/","name":"PWV Consultants","description":"","publisher":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.pwvconsultants.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.pwvconsultants.com\/blog\/#organization","name":"PWV Consultants","url":"https:\/\/www.pwvconsultants.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/04\/logo-alternate-e1585773530392.png","contentUrl":"https:\/\/www.pwvconsultants.com\/blog\/wp-content\/uploads\/2020\/04\/logo-alternate-e1585773530392.png","width":98,"height":84,"caption":"PWV Consultants"},"image":{"@id":"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/PWV-Consultants-110444033947964","https:\/\/twitter.com\/PWV_Consultants","https:\/\/www.linkedin.com\/company\/pwv-consultants"]},{"@type":"Person","@id":"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/person\/c15d5d40126a8ad906cb3067de95f8d4","name":"Pieter VanIperen","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pwvconsultants.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8b294918257a810803e2befc9a71b7bc?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8b294918257a810803e2befc9a71b7bc?s=96&d=mm&r=g","caption":"Pieter VanIperen"},"description":"PWV Consultants is a boutique group of industry leaders and influencers from the digital tech, security and design industries that acts as trusted technical partners for many Fortune 500 companies, high-visibility startups, universities, defense agencies, and NGOs. Founded by 20-year software engineering veterans, who have founded or co-founder several companies. PWV experts act as a trusted advisors and mentors to numerous early stage startups, and have held the titles of software and software security executive, consultant and professor. PWV's expert consulting and advisory work spans several high impact industries in finance, media, medical tech, and defense contracting. PWV's founding experts also authored the highly influential precursor HAZL (jADE) programming language.","sameAs":["https:\/\/www.linkedin.com\/company\/pwv-consultants"]}]}},"_links":{"self":[{"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/posts\/58"}],"collection":[{"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/comments?post=58"}],"version-history":[{"count":3,"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/posts\/58\/revisions"}],"predecessor-version":[{"id":182,"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/posts\/58\/revisions\/182"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/media\/61"}],"wp:attachment":[{"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/media?parent=58"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/categories?post=58"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pwvconsultants.com\/blog\/wp-json\/wp\/v2\/tags?post=58"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}