Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Boiling Down PCI DSS Compliance; It's Really Just Common Sense Information Security | Main | Avoid Being Sued And Losing Customers: Don't Go Changing Your Privacy Policy Willy-Nilly! »

You Will Be Judged By The Company You Keep: 4 Good Reasons (And More) To Ensure Your Business Partners Have Good Information Security Programs

Over the past few years I have done well over a hundred business partner security program reviews for organizations who wanted to ensure that the organizations to whom they were entrusting their sensitive data, or other business processing, had appropriate security and privacy policies, practices, training and were generally trustworthy.

By now most organizations realize that performing information security program reviews or audits of their business partners is a good idea if the partners have been entrusted with sensitive data or access to networks and systems. But performing business partner reviews is more than just a good idea.

• It is a requirement of multiple laws and regulations

• It is typically necessary to demonstrate due diligence

• It may be necessary to comply with contractual requirements

• It can be necessary to comply with your own posted privacy and security policies, depending on how they are worded

I wrote about this in detail for my August CSI Alert column, "You Will Be Judged By the Company You Keep."

Within the article I discuss the many laws that address the need for performing business partner reviews, along with at least 14 actions you should take for business partner security program reviews.

If you are trying to determine whether or not you should do business partner security program reviews I invite you to read my article and let me know what you think.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/483

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.