Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

May 16, 2008

SEC Regulation S-P Proposals To Improve The Security Of Customer Information Within Brokerage Shops

Do you work for a brokage house, have a subsidiary that is a brokerage house, or do any type of work with a brokerage house? If so, then you should be aware of the Securities and Exchange Commission (SEC) proposed changes to Regulation S-P in March of this year.

In general, the proposed amendments to Regulation S-P...

 
Continue reading SEC Regulation S-P Proposals To Improve The Security Of Customer Information Within Brokerage Shops...

May 12, 2008

At the Secure 360 Conference

Tomorrow and Wednesday I'm doing some sessions at the Secure 360 conference in St. Paul, Minnesota. I'm really looking forward to also seeing the other sessions while here (yes, I've arrived and getting some work done in my room)!

 
Continue reading At the Secure 360 Conference...

May 8, 2008

A Couple Of Little Known HIPAA Facts

Last week I was contacted by Corey Goodman, a reporter for HCPro, about a story he is doing that sounds like it will be quite interesting! He is collecting examples and anecdotes about "little know HIPAA facts" and asked me to contribute some for his article.

I anticipate that he will be cutting the couple of little known facts I provided to him down quite a bit, so I wanted to provide them here not only as a future reference for myself, but also for those of you who may be interested!

 
Continue reading A Couple Of Little Known HIPAA Facts...

May 7, 2008

Another Example Of How Internet Information Impacts Employment Decisions

I've blogged several times about how employers are inreasingly using information found on the Internet to make hiring, and firing, decisions, such as here and here.

I've also written about it several times, such as here.

Here's another example to add to your files for how information posted to social networking sites, such as MySpace and Facebook, can impact your employment situation where a woman graduating with an education degree was denied teaching credentials, and this is not the first time a situation has occurred similar to this...

 
Continue reading Another Example Of How Internet Information Impacts Employment Decisions...

May 5, 2008

Click Wrap Contracts: Creating Them And Agreeing To Them

There was an interesting article in this week's issue of Privacy and Security Law, "Clickwrap Notifying Software Recipients Of Pop-Up Installation Is Valid, Enforceable" (a subscription site).

 
Continue reading Click Wrap Contracts: Creating Them And Agreeing To Them...

May 4, 2008

What Business Leaders Need To Know About Employee Privacy

Here it is May, and I'm just now getting all of my April IT Compliance in Realtime Journal articles blogged about! Being in Las Vegas for a week at CSI SX / Interop really put a monkey wrench in my blogging activity last week.

While at the conference I spoke with many information security and IT leaders about privacy. Most have customer privacy on their minds, but a significant portion have not thought about employee privacy issues.

So, this article, "What Business Leaders Need To Know About Employee Privacy," which is the third in my April IT Compliance in Realtime Journal issue, is pretty timely.

Download the April issue to get a much prettier, formatted version. Here is the unformatted article...

 
Continue reading What Business Leaders Need To Know About Employee Privacy...

May 1, 2008

Using DNA Of Family Members To Catch Criminals

I just read an interesting article, "Using kin's DNA to track suspects."

 
Continue reading Using DNA Of Family Members To Catch Criminals...

April 25, 2008

Do We REALLY Need Doctors To Do Consultations Via Email?

A few months ago I had some lively back-and-forth blog postings with a doctor who used email and instant messaging (IM) a lot in his practice; here, here and here.

Today my good friend Alec forwarded me another interesting news article (thanks Alec!) about the use of email by doctors; "It's no LOL: Few US doctors answer e-mails from patients."

 
Continue reading Do We REALLY Need Doctors To Do Consultations Via Email?...

April 24, 2008

Smart Business Leaders Support Effective Log Management Practices and Necessary Resources

The second article in this month's IT Compliance in Realtime Journal is, "Smart Business Leaders Support Log Management."

I wrote this with an audience of information security and privacy personnel, along with IT managers, in mind.

Download the formatted PDF version to get the full content, not to mention a nicer looking document.

Here is the unformatted version...

 
Continue reading Smart Business Leaders Support Effective Log Management Practices and Necessary Resources...

April 23, 2008

My Information Security and Privacy Convergence Webcast Now Available

Yesterday the ISSA posted on their website a free webcast I did, "Information Security and Privacy Convergence"

Here is the synopsis...

 
Continue reading My Information Security and Privacy Convergence Webcast Now Available...

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.