Entries from Realtime Community | IT Compliance tagged with 'privacy incident'
Another real-life example to show the importance of having effective policies and procedures in place for not only information disposal, but also for the disposal of computers and storage media......
Posted by Rebecca Herold on December 16, 2008 1:24 PM
I've been doing a lot of work with data retention and disposal policies and procedures lately, remembering the silly things I have read about with regard to organizations getting rid of their computers, such as selling their computers on eBay...
Posted by Rebecca Herold on August 30, 2008 4:41 PM
Yesterday the U.S. Federal Trade Commission (FTC) handed down yet another penalty against an online retailer, Life is good, Inc., for not properly safeguarding their online ecommerce applications. The FTC charged they were in violation of the FTC Act because...
Posted by Rebecca Herold on January 18, 2008 10:56 AM
On December 17 the U.S. Federal Trade Commission (FTC) fined and penalized American United Mortgage Company for throwing the personally identifiable information (PII) and financial information of its customers and consumers into an open, publicly-accessible dumpster. Under the terms of...
Posted by Rebecca Herold on December 26, 2007 2:41 PM
Earlier this week I posted about one of the Business Software Alliance (BSA) initiatives for enforcing software licensing compliance, "Another Approach To Licensing Compliance." There are *MANY* software licensing tools and awareness communications that businesses of all sizes, and with...
Posted by Rebecca Herold on December 1, 2007 10:46 AM
The Department of Homeland Security (DHS) recently released the draft "IT Security Essential Body of Knowledge (EBK)" for public comment and feedback. This 45-page document outlines the skill sets the groups working with the DHS have determined as being necessary...
Posted by Rebecca Herold on November 30, 2007 12:10 PM
I don't know why I continue to be surprised at the stupid things some people do, but apparently some people will never realize how much of themselves they are giving away when they post their pictures and other personal information...
Posted by Rebecca Herold on November 29, 2007 10:14 AM
My 13-year-old-niece wrote an article for me about social engineering, and I got a chuckle out of her writing, "Maybe I'm old-fashioned, but I only use email. I don't have my own FaceBook site." Can you imagine email being old-fashioned?!...
Posted by Rebecca Herold on November 28, 2007 7:49 PM
Robert Ellis Smith sent me an email yesterday to let me know about his most recent article in Forbes magazine, "Scary Stuff." It's a very interesting read and highlights some terms that, to date, I have not seen in print...
Posted by Rebecca Herold on November 27, 2007 8:02 PM
My father was the superintendent of the public school district where I grew up in Missouri. He was a very hands-on type of leader; when he was not filling out forms, writing reports, making plans, or in meetings he was...
Posted by Rebecca Herold on November 26, 2007 8:21 PM
My blog posting from earlier talked about how the MPAA is trying to combat movie piracy. I just visited the LinkedIn site and was intrigued to find an ad from the Business Software Alliance (BSA) offering up to $1,000,000...yes, US...
Posted by Rebecca Herold on November 25, 2007 7:29 PM
Many times software designed to enforce legal compliance, or find network users who are breaking laws, bring along with them greater risks to information security and privacy....
Posted by Rebecca Herold on November 25, 2007 4:07 PM
I hope those of you who celebrated Thanksgiving had a great one! I spent a very nice day with my family at my brother's house. After getting back home we decided to watch some Christmas movies, so we spent the...
Posted by Rebecca Herold on November 24, 2007 11:54 AM
My central Iowa Infragard president, Tom Conley sent all our members a note on Wednesday with a link to a site that contains 9 variables to help demonstrate the range of financial impact to organizations that experience an incident involving...
Posted by Rebecca Herold on November 23, 2007 1:54 PM
Of all the U.S. government regulatory oversight agencies, the Federal Trade Commission (FTC) is the most active and aggressive in looking for and applying penalties to organizations that not only are in noncompliance with laws and regulations, but also those...
Posted by Rebecca Herold on October 7, 2007 3:23 PM
Today Microsoft launched their new web portal, HealthVault to store, for free, "medical histories, immunization and other records from doctors' offices and hospital visits, including data from devices like heart monitors. It is also tied to a health information search...
Posted by Rebecca Herold on October 4, 2007 7:34 PM
Today Monsters and Critics reported, "Indianapolis Public Schools exposes thousands to risk of identity theft." Apparently the Indianapolis Public Schools (IPS) website "that allows teachers to post reviews, student-writing samples, grades, and other confidential material to the IPS network" was...
Posted by Rebecca Herold on May 18, 2007 7:32 PM
A CD containing the clear text personal information of 75,000 WellPoint Empire Blue Cross and Blue Shield New York members that was reported lost on February 9 while being transported by UPS has been found. The CD was lost when...
Posted by Rebecca Herold on March 16, 2007 11:29 AM
The Akron Beacon Journal reported February 5 more impacts of the massive TJX breach that occurred late in 2006 that may have impacted over 40 million individuals according to the Wall Street Journal....
Posted by Rebecca Herold on February 7, 2007 12:15 AM
Let's look at the events that have occurred with the recent TJX computer hack and resulting privacy breach and identity thefts:...
Posted by Rebecca Herold on February 4, 2007 10:01 PM
Puget Sound Energy, Washington state's largest electricity and natural gas utility, with over 1 million customers in 11 western Washington counties, was ordered to pay a total of $995,000 in fines for selling their customer information to marketing companies over...
Posted by Rebecca Herold on January 30, 2007 10:25 AM
NBC news ran a story about how many state government agencies post sensitive personally identifiable information (PII) on their websites. In this case an Ohio county court "routinely posted traffic tickets and other public records on its Web site."...
Posted by Rebecca Herold on January 29, 2007 9:25 PM
Yesterday EARTHtimes, which appears to be a general news site, carried a story with a cute title that caught my eye, "Don't be a turkey: Protect your laptop during holiday travel."...
Posted by Rebecca Herold on November 16, 2006 9:28 PM
This year's Ernst & Young Global Information Security Survey 2006 is out and it is always an interesting read. Arguments aside about the statistical accuracy of such surveys, it still provides useful information and also helps to track progress in...
Posted by Rebecca Herold on November 14, 2006 10:10 PM
Last week I was at the Computer Security Institute 33rd Annual Computer Security Conference & Exhibition where Chris Grillo and I also gave our post-conference seminar, "Effectively Partnering InfoSec and Privacy For Business Success". It was interesting to hear the...
Posted by Rebecca Herold on November 13, 2006 10:01 AM
The FTC recently made available a pretty neat privacy in socieal networking sites awareness raising quiz, "Buddy Builder."...
Posted by Rebecca Herold on November 2, 2006 5:50 PM
An interesting article was released yesterday in the Insurance Journal, "J.D. Power: Homeowners Want Carriers to Offer Identity Theft." It indicates that the 2006 Homeowners Insurance Study, results of feedback from 9,045 homeowners insurance policy holders in the U.S., finds...
Posted by Rebecca Herold on October 31, 2006 1:30 PM
My friend and professional colleague, Kevin Beaver, is giving a webcast on Tuesday, November 14, "How to manage the ongoing information security requirements for SOX, HIPAA, GLBA and other key regulations: A single solution." Kevin has great experience with information...
Posted by Rebecca Herold on October 31, 2006 9:28 AM
Last Friday (10/27) Washington Technology published an interesting article, "USPS site is much more than just a presence on the Web" about the privacy challenges of the United States Postal Service (USPS) website. It is interesting and revealing to see...
Posted by Rebecca Herold on October 30, 2006 4:18 PM
Site tags used on this blog: