Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

March 27, 2008

Who Had The Brilliant Idea To Outsource U.S. Passports?

Okay, after the recent passport files snooping debacle I found today's news story, "Outsourcing passports 'profound liability'" very ironic and concerning.

Not only for the reported huge waste of taxpayers' dollars, but also for the security risks...

 
Continue reading Who Had The Brilliant Idea To Outsource U.S. Passports?...

January 11, 2008

Terrorists Over 50 Don't Fly According To The DHS

I just read this and found the implication that folks over 50 years of age are not terrorist threats rather odd.

Today the U.S. Department of Homeland Security released some new rules related to READ ID.

 
Continue reading Terrorists Over 50 Don't Fly According To The DHS...

January 2, 2008

Don't Expect Privacy At The Iowa Caucuses

I am happy to live in Iowa. I've enjoyed getting to see the presidential hopefuls in the state for the past 1+ years. I always vote during presidential elections, but I've never yet declared a party; I really don't want to be listed in who knows how many places under such a label. However, this year I would really like to participate in the Iowa caucus.

 
Continue reading Don't Expect Privacy At The Iowa Caucuses...

December 2, 2007

New U.S. Cybersecurity Special Assistant Appointed on November 28

On November 28 U.S. President G. W. Bush appointed Marie O'Neill Sciarrone to be Special Assistant to the President for Homeland Security and Senior Director for Cybersecurity and Information Sharing Policy.

 
Continue reading New U.S. Cybersecurity Special Assistant Appointed on November 28...

November 14, 2007

U.S. Federal Teleworking Report Reminds Us that Teleworking Saves Time and Resources, But Must Be Done With Safeguards In Place

On November 6 there was a an interesting hearing held by the U.S. Subcommittee on Federal Workforce, Postal Service, and the District of Columbia about teleworking in the federal agencies.

Considering large numbers of privacy breaches occurring within government agences involving mobile computing devices and storage devices, this caught my eye.

 
Continue reading U.S. Federal Teleworking Report Reminds Us that Teleworking Saves Time and Resources, But Must Be Done With Safeguards In Place...

November 12, 2007

The Deputy Director of National Intelligence Does Not Understand Key Concepts Of Privacy

I found a report yesterday, "Intelligence deputy to America: Rethink privacy" quite interesting. The impact on privacy...the actual definition, not the definition Donald Kerr, the principal deputy director of national intelligence, thinks it should be...would not only be a huge step backward for the country, but it would also increase the threats to personally identifiable information (PII) exponentially.

 
Continue reading The Deputy Director of National Intelligence Does Not Understand Key Concepts Of Privacy...

November 11, 2007

French Supreme Court Decision Points Out Importance Of Using Monitoring Notices Wherever In The World You Have Personnel

I just read about a French Supreme Court decision made on October 10 (you can see a Google English rough translation of it here) that is significant to organizations who have employees in France, or anywhere worldwide for that matter, and the organization's employee monitoring practices.

 
Continue reading French Supreme Court Decision Points Out Importance Of Using Monitoring Notices Wherever In The World You Have Personnel...

November 4, 2007

Do Something To Change Information Security, Privacy and Compliance...Contact Congress!

I, along with a very large number of other bloggers, writers and instructors, often pick apart data protection and privacy laws and regulations, and point out how certain portions of them are infeasible for most organizations to implement, and talk about the types of laws that should be inacted to protect personally identifiable information (PII) and privacy. But how many of us actually do something about it and contact our lawmakers to communicate this information?

 
Continue reading Do Something To Change Information Security, Privacy and Compliance...Contact Congress!...

October 27, 2007

APEC Privacy Framework: Viewpoints from the FTC, TRUSTe & Marty Abrams

One of the sessions I attended at the IAPP Privacy Academy this past week was "APEC Update - Self Regulatory Approaches to Cross Border Transfers of Personal Data." The presenters were: Pamela Jones Harbour, Commissioner, Federal Trade Commission (FTC), Marty Abrams, Executive Director, Center for Information Policy Leadership, and Fran Maier, Executive Director and President, TRUSTe.

 
Continue reading APEC Privacy Framework: Viewpoints from the FTC, TRUSTe & Marty Abrams...

September 27, 2007

DHS Exploding Generator Shows Dire Need For Better Computer Security

Scanning the news this morning, this CNN headline caught my eye, "Mouse click could plunge city into darkness, experts say"

The first sentence is compelling:

 
Continue reading DHS Exploding Generator Shows Dire Need For Better Computer Security...

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.