Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

April 29, 2008

Corporate Communications Officers Tying The Hands Of Information Security and Privacy Pros

I've been here at the CSI SX conference for the past few days, and I've had the great opportunity and pleasure of speaking with a large number of folks while here. I was finally able to meet Ron Woerner in person (nice to meet you Ron!) after communicating with him in the Security Catalyst Community over the past 1+ year.

I love coming to these conferences and just talking with the participants. There is always at least one topic for which I receive enlightenment that I had not considered before. During the past few days I've spoken with 4 to 5 people who are responsible for information security, all from highly regulated industries, who all say despite their adequate to even generous information security and privacy budgets, some of their most important information security and privacy efforts are being quashed by their corporate communications offices; those responsible for the messages that are sent to personnel throughout the enterprise.

 
Continue reading Corporate Communications Officers Tying The Hands Of Information Security and Privacy Pros...

April 3, 2008

Going Topless...I Like It!

A few weeks ago I was at a meeting for a professional organization I belong to, giving a talk about privacy breach response, and the audience was great; around 40 in attendance, all visibly listening and interested and participating. I love to look and see everyone's faces as I am talking; seeing if they are confused, in agreement, or otherwise are reacting to the ideas and recommendations I am talking about.

I was around 20 minutes into my talk when someone's cell phone started ringing...playing a John Phillip Sousa march. LOUDLY. I kept talking, and everyone was still listening...trying to listen...but the darn phone kept playing! People then started looking around...and finally I stopped and said, "Does someone need to get that?" One of the folks then reached down and answered it; and then left the room. Quite an unnecessary interruption.

 
Continue reading Going Topless...I Like It!...

March 14, 2008

Information Security and Privacy Areas MUST Collaborate For Their Initiatives To Be Effective

For the past several years I have written often, and given much training, to demonstrate and emphasize the need for information security and privacy areas to collaborate in their efforts. There are just too many topic overlaps between the two areas to NOT work together cooperatively.

Effectively addressing and coordinating Privacy and Information Security initiatives has moved to the top of the list for companies maintaining customer and employee information. However, there are often gaps in communication and collaboration between Privacy and Information Security activities.

 
Continue reading Information Security and Privacy Areas MUST Collaborate For Their Initiatives To Be Effective...

March 10, 2008

Twelve Messaging Risks to Address Now

The first article within the March issue of my new e-journal, "IT Compliance in Realtime" is "Twelve Messaging Risks to Address Now."

Here are a few excerpts...

 
Continue reading Twelve Messaging Risks to Address Now...

March 4, 2008

Did You Know This Was National Consumer Protection Week?

Here's another event related to compliance, information security and privacy to put on your calendar...

This is National Consumer Protection Week (NCPW) in the U.S.

 
Continue reading Did You Know This Was National Consumer Protection Week?...

February 28, 2008

Promoting Science and Technology

I participate in the LinkedIn community, and I was intrigued this morning to find a question posted by Bill Gates (yes Microsoft Bill)!

"How can we do more to encourage young people to pursue careers in science and technology?"

 
Continue reading Promoting Science and Technology...

February 26, 2008

Great Information Security and Awareness Event Coming In April

There's a great information security and privacy awareness event coming up, Internet Safety Night on April 23, 2008, 6:30-8:30 p.m.

 
Continue reading Great Information Security and Awareness Event Coming In April...

February 8, 2008

Two Types Of Young Hackers

Here's an interesting juxtaposition of hacker-related news articles...

When scanning today's news I saw the headline, "Teen Is World's Youngest 'Ethical Hacker'"

 
Continue reading Two Types Of Young Hackers...

February 7, 2008

More Info Security & Privacy Education Will Reduce The Numbers Of Incidents

Here's a good article for all information security and privacy pros to read and show their business leaders. If nothing else show them the last paragraph:

 
Continue reading More Info Security & Privacy Education Will Reduce The Numbers Of Incidents...

February 6, 2008

Did You Know February 12 is "Safer Internet Day"?

I got a nice message from Brian Honan yesterday letting me know that February 12 is "Safer Internet Day," or SID for short; (Thanks Brian!)

 
Continue reading Did You Know February 12 is "Safer Internet Day"?...

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.