Search Realtime IT Compliance

Entries from Realtime Community | IT Compliance tagged with 'personal privacy'


Don't Manage Employee Online Activities By Requiring Their IDs & Passwords!

I read a story about a city government agency actually asking job applicants to provide their IDs and passwords for any online social networking type of site they participate in......

Where And How Do You Dispose Of Your Cell Phones and Paper Documents?

Something I'm planning to do this summer with my sons is to do some dumpster diving, with the advice of my police and security services company owner friends, to see just how much personal information is left out for just...

Where And How Do You Dispose Of Your Computers, CDs, USB Drives, Etc.?

In the past few years I've performed over 100 information security and privacy program reviews for the vendors and business partners of my clients, and I have often found these contracted organizations have lax to non-existent to outragiously irresponsible computer...

$54 Million Lawsuit Against Best Buy For Losing Laptop

I knew the civil suits for lost laptops would start soon. Thanks so much to my buddy Alec for pointing out this story to me! Raelyn Campbell took a laptop computer to Best Buy to get fixed, and three months...

Potty Pics Poo-Poo Privacy

This is a sad example of how others take it upon themselves to invade the privacy of others and don't understand that they're doing anything wrong......

Insider Threat Example: Programmer Sentenced To 30 Months In Jail And $81,200 Fine

Here's a case I blogged about amost exactly a year ago, but it is worth revisiting since the sentencing for the crime was just handed down and it was significant. If you haven't already, put this in your file of...

Terrorists Over 50 Don't Fly According To The DHS

I just read this and found the implication that folks over 50 years of age are not terrorist threats rather odd. Today the U.S. Department of Homeland Security released some new rules related to READ ID....

13 Minnesota Students Disciplined For Facebook Photos

I've blogged several times, such as here, here and here, about how information posted to the Internet, such as on Facebook and other social networking sites, cannot be considered as being private or secure, have been used to make hiring...

Egregious Privacy Infringment: Fire Chief Emails Photo Of Topless Crash Victim

Here is an example of how personnel can take photos and videos and completely invade the privacy of others, particularly those who have no voice to say stop. A Central Florida fire chief will likely lose his job for widely...

Retail Locations Have Unique Challenges With PCI DSS Compliance

I've been intrigued lately with PCI DSS compliance. It has all retailers on edge, has multiple vendors drooling, and has spawned new laws and bills, such as in Minnesota and Texas. I've had interesting discussions about it with those who...

PCI DSS and Identity Theft

Over the past month or so I've been discussing the Payment Card Industry (PCI) Data Security Standards (DSS) with some of my information assurance practitioner friends and colleagues and what they've been doing to meet the requirements and accompanying challenges....

Privacy Law: Leahy & Specter File Personal Data Privacy Act of 2007 Bill

On Tuesday, February 6, U.S. Sen. Patrick Leahy, D-Vt., and Sen. Arlen Specter, R-Pa., filed legislation,the Personal Data Privacy Act of 2007, that would, among other things, require organizations to notify consumers of security breaches as well as mandate the...

Privacy Breach: Bank in UK Sends Personal Data of 75,000 Customers to 1 Customer Requesting Her Own Statement

The Halifax Bank of Scotland sent the complete account information for 75,000 of their customers to one customer who had requested a copy of her own statement....

HIPAA: Congressional and GAO Reports Say HHS Needs To Make Changes To Protect Patient Privacy

According to a congressional testimony report posted February 1, "Private Health Records: Privacy Implications of the Federal Government's Health Information Technology Initiative," the Department of Health and Human Services (HHS) needs to do more to address privacy and security concerns...

PCI DSS and GLBA Compliance & Privacy Breach: Lawsuits Filed Against TJX

Let's look at the events that have occurred with the recent TJX computer hack and resulting privacy breach and identity thefts:...

Site Tags

Site tags used on this blog: