Ask HN: Frustrations with PCI-DSS, HIPAA, SOX compliance?
https://news.ycombinator.com/item?id=5628547Hi everyone,
I am curious to hear about other people's frustrations with PCI-DSS, HIPAA, or SOX compliance.
From an IT perspective, one of the biggest frustrations I have is with the man-power required to satisfy keeping up with the requirements. A lot of the guidelines are common sense, but the overhead for maintaining change management, documented policies/procedures, approvals, audits, etc are tough. Certainly, in the ideal sense these things are great to have but in reality it is tough to make time for them when you've got other business needs to satisfy.
What are some of your biggest frustrations with compliance and what are some tools you use to 'cope'?
Cheers!