Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

July 2, 2009

Nevada's New Encryption Law; Made Moot By Its Own Data Breach Law?

On May 30, 2009, Nevada enacted a new law, SB 227, which will basically replace NRS 597.970 in January 2010.

In many ways the new law is an improvement over the much more vague, and brief, NRS 597.970. I want to focus here on an improvement, but something that still leaves much to interpretation; that is, what is meant by "encryption"?

 
Continue reading Nevada's New Encryption Law; Made Moot By Its Own Data Breach Law?...

June 30, 2009

Hear Common, Dumb and Dangerous Privacy Assumptions On The Radio!

Today I will be on MyTechnologyLawyer.com radio show to an hour program talking about the common privacy mistakes and assumptions made by businesses. This will be a more in-depth look at the issues from my post from a couple of weeks ago, "5 Common, Dumb and Dangerous Privacy Assumptions"

Here are the details:

 
Continue reading Hear Common, Dumb and Dangerous Privacy Assumptions On The Radio!...

June 29, 2009

South Carolina & Alaska Privacy Breach Notice Laws Go Into Effect July 1

This week two more U.S. breach notice laws go into effect...

 
Continue reading South Carolina & Alaska Privacy Breach Notice Laws Go Into Effect July 1...

June 18, 2009

Don't Manage Employee Online Activities By Requiring Their IDs & Passwords!

I read a story about a city government agency actually asking job applicants to provide their IDs and passwords for any online social networking type of site they participate in...

 
Continue reading Don't Manage Employee Online Activities By Requiring Their IDs & Passwords!...

June 17, 2009

5 Common, Dumb and Dangerous Privacy Assumptions

Today Kevin Beaver posted a nice article, "Dumb things IT consultants do" that included more than one warning about making assumptions. Kevin's nice post made me think about all the dangerous assumptions consulants and practitioners often make when it comes to evaluating privacy practices...

 
Continue reading 5 Common, Dumb and Dangerous Privacy Assumptions...

June 16, 2009

FTC Issued Consent Order for GLBA Privacy Rule and Safeguards Rule Violations

Today the FTC issued a consent order against mortgage lender James B. Nutter & Company for GLBA Privacy Rule and Safeguards Rule violations resulting from having an inadequte information security program and safeguards. The requirements will result in, among other actions, 20 years of ongoing activities by James B. Nutter & Company; much more costly than it would have been to have established appropriate information security safeguards to begin with...

 
Continue reading FTC Issued Consent Order for GLBA Privacy Rule and Safeguards Rule Violations...

June 15, 2009

Info Sec & Privacy Days/Weeks/Months

As I've mentioned a few times before, I'm in the final lap of finishing the 2nd edition of my book, "Managing an Information Security and Privacy Awareness and Training Program." Woo hoo!

Over the weekend I updated "Appendix N - Designated Security and Privacy-Related Days." Here are the days, weeks and months I've found are devoted to raising awareness about various info sec and privacy issues (this is in a much nicer-looking table format in my book)...

 
Continue reading Info Sec & Privacy Days/Weeks/Months ...

June 10, 2009

Healthcare Worker Gets 1 Year In Prison For Posting HIV Victim's Medical Records On Internet

Today a report discussed how a healthcare worker obtained medical information about a patient with HIV that was then posted on the Internet...

 
Continue reading Healthcare Worker Gets 1 Year In Prison For Posting HIV Victim's Medical Records On Internet...

June 9, 2009

Privacy Enhancing Technologies (PETs) & Privacy Threatening Technologies

I'm doing research while working on the 2nd edition of my book, "Managing an Information Security and Privacy Awareness and Training Program"...

 
Continue reading Privacy Enhancing Technologies (PETs) & Privacy Threatening Technologies...

June 8, 2009

Audits Show Things At a Moment in Time; Silly To Sue For Breaches That Happen 1 Year After Audit Conclusion?

There has been much written in the past week about Merrick Bank suing the audit firm, Savvis, because a breach occurred at CardSystems in 2005 even though Savvis had given passing marks for the CardSystems audit that Merrick Bank hired them to perform in 2004 to ensure they were following Visa's Cardholder Information Security Program (CISP); basically a forerunner of the current PCI DSS program. Savvis found that CardSystems was following the CISP requirements. Within a year after the audit, CardSystems experienced a major breach that basically put them out of business.

I have had the great privilege to work as an IT auditor early in my career, for a while as an internal auditor at a large multi-national financial and insurance company, and then doing periodic audits since in various organizations in a wide range of industries since. All wonderful learning experiences!

There are a couple of important points that the judge in this situation should consider, and the lawyers in this case should understand:

 
Continue reading Audits Show Things At a Moment in Time; Silly To Sue For Breaches That Happen 1 Year After Audit Conclusion?...

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.