Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Podcast: HITECH Act adds new compliance requirements, penalties | Main | Secure360 Starts Tomorrow! »

Regulatory Requirements for Training and Awareness

Today I had a great conversation with a CISO about the regulatory and legal requirements for organizations to provide information security and privacy training and awareness activities...

There are a growing number of laws and regulations that include requirements for the covered entities to provide some type of information security and/or privacy awareness and training to not only their personnel, but also in some instances to their customers and consumers.

Some of these laws and regulations include, but are not limited to, the following:

  • The Health Information Portability and Accountability Act (HIPAA)
  • 21 CFR Part 11 (Electronic Records/Electronic Signatures)
  • Bank Protection Act
  • Computer Security Act
  • Computer Fraud and Abuse Act (CFAA)
  • Fair and Accurate Credit Transactions Act (FACTA)
  • Red Flags Rule (under FACTA)
  • HITECH Act
  • Privacy Act
  • Freedom of Information Act (FOIA)
  • Federal Information Security Management Act (FISMA)
  • 5 U.S.C. ยง930.301 (for federal offices)
  • Appendix III to OMB Circular No. A-130
  • Digital Millennium Copyright Act (DMCA)
  • GLBA
  • Department of Transportation DOT HM-232
  • Sarbanes-Oxley (SOX) Act
  • The Organization for Economic Cooperation and Development (OECD) Security and Privacy Principles
  • The European Union Data Protection Directive
  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)

Although HIPAA, SOX, GLBA and now the Red Flags Rule are currently the most often discussed regulations that include requirements for awareness and training, education of personnel has been a requirement under guidelines and regulations for years. For instance, the Federal Sentencing Guidelines, enacted in 1991, has a requirement for executive management to educate and effectively communicate to their employees the proper business practices with which they must comply.

I'm going to be covering these issues in depth within the 2nd edition of my book "Managing an Information Security and Privacy Awareness an Training Program" coming out in either late 2009 or early 2010.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/986

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.