Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

May 16, 2008

SEC Regulation S-P Proposals To Improve The Security Of Customer Information Within Brokerage Shops

Do you work for a brokage house, have a subsidiary that is a brokerage house, or do any type of work with a brokerage house? If so, then you should be aware of the Securities and Exchange Commission (SEC) proposed changes to Regulation S-P in March of this year.

In general, the proposed amendments to Regulation S-P...

 
Continue reading SEC Regulation S-P Proposals To Improve The Security Of Customer Information Within Brokerage Shops...

May 15, 2008

CAN-SPAM: Record Judgment Along With Updated Rules

I was at the Secure360 conference (a fabulous event, btw) this week, and I'm just getting to an important current topic: CAN-SPAM.

On Monday (5/12) the FTC announced an update to the Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM) law.

 
Continue reading CAN-SPAM: Record Judgment Along With Updated Rules...

March 19, 2008

Useful Data Protection (Privacy) Law Sites


This morning I took a little time to update my long listing of world-wide data protection (privacy) laws.

Here are some of them you may find helpful:

 
Continue reading Useful Data Protection (Privacy) Law Sites...

March 17, 2008

HIPAA *HAS* Impacted Healthcare Providers...Despite Lack Of Enforcement

I have written many times about how the U.S Department of Health and Human Services (HHS) has severely weakened the planned privacy and security goals of the Health Insurance Portability and Accountability Act (HIPAA) to require healthcare covered entities (CEs) to implement strong safeguards for the protected health information (PHI) with which they've been entrusted. And I still believe that.

However, after reading a another report today I realized something...

 
Continue reading HIPAA *HAS* Impacted Healthcare Providers...Despite Lack Of Enforcement...

March 10, 2008

Iowa Privacy Breach Bill Has Much Of Its Teeth Pulled

Iowa introduced a new bill, SSB 3200, on February 20 to establish a state privacy breach notification law.

As originally worded it would have also required merchants to follow credit and debit card industry data security rules and make them liable to banks for costs they incurred after a breach of payment card transaction data not retained in compliance with those rules. However, in the past week SSB 3200 was amended in committee to remove the retailer liability provisions.

A companion bill, HSB 721, was introduced February 26.

February 9, 2008

New Information Technology Crime Law in Saudi Arabia

Here's an interesting new law in Saudi Arabia...

"New Law to Combat Information Technology Crimes

 
Continue reading New Information Technology Crime Law in Saudi Arabia...

February 1, 2008

A New Privacy/Security Breach Notice Law Soon In The Land Down Under?

Another country appears to be on the verge of passing a privacy breach notice law...

 
Continue reading A New Privacy/Security Breach Notice Law Soon In The Land Down Under?...

January 6, 2008

Privacy, The 5th Amendment And PGP Passwords

While doing some encryption research I ran across this Vermont ruling made on November 29, 2007.

It provides some good lessons about computer forensics and investigation and password management.

 
Continue reading Privacy, The 5th Amendment And PGP Passwords...

December 28, 2007

New U.S. Law Effective Jan 1 Prohibits Lithium Batteries In Checked Luggage

I like to carry extra laptop and cell phone batteries with me when I travel for more than a couple of days at a time, especially if going outside the country. I fried a cell phone once using a faulty outlet converter overseas, so now I like to play it safer by depending upon extra batteries. It was fairly simple to pack the extra batteries into my checked luggage. It was a good simple way to have a backup power source while travelling.

Well, as of next Tuesday that simplicity is no more.

 
Continue reading New U.S. Law Effective Jan 1 Prohibits Lithium Batteries In Checked Luggage...

December 27, 2007

FTC Behavioral Advertising Privacy Principles: Give Them Your Feedback!

On December 10 the U.S. Federal Trade Commission (FTC) announced that the FTC commissioners voted unanimously to have principles to govern online behavioral advertising. At the same time they released their proposed principles to guide the development of self-regulation in this area.

 
Continue reading FTC Behavioral Advertising Privacy Principles: Give Them Your Feedback!...

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.