An organization is considering purchasing an IGA tool. The manager asks the administrator to explain what compliance features the IGA tool provides for separation of duties, protecting personally identifying data and privileged access, and how the company can prove to the auditors that they comply with all laws and regulations.
Is this a good explanation of one of such features?
Proposed Solution / Statement:
"The vendor has provided proof that the tool complies with HIPAA, PCI-DSS, SoX, ISO 27002 and the GDPR. The fact that we use this IGA tool is sufficient legal proof for the auditors that we comply with all regulations."
Does this proposed solution meet the requirement / solve the scenario?
Submit