PCI-DSS
PCI-DSS has been widely adopted as the high priority standard for enterprise IT organizations to comply. Tons of money and resources have been spent into the compliance projects. However, low efficiency of investment, particularly at access and audit areas, becomes the new pain on the journey.
Sarbanes Oxley Act
USA SEC public list companies must meet the compliance requirements from Sarbanes Oxley Act, which require the complete and integrated internal control systems.
BS7799/ISO27001
In ISO27001, titile A15.1.3 requires to protect the organization's operating records, and titile A15.2.1 requires IT managers must assure all security procedures on the right track, complying to the requirements by security policy and standards.

