Search Realtime IT Compliance

Entries from Realtime Community | IT Compliance tagged with 'privacy incident'


Blackberry Disposal Lessons From McCain & Palin

Another real-life example to show the importance of having effective policies and procedures in place for not only information disposal, but also for the disposal of computers and storage media......

Laptop Containing PII of 1 Million+ People Sold On eBay for $141

I've been doing a lot of work with data retention and disposal policies and procedures lately, remembering the silly things I have read about with regard to organizations getting rid of their computers, such as selling their computers on eBay...

FTC Hands Down Another FTC Act Noncompliance Penalty For Bad Online Application Security

Yesterday the U.S. Federal Trade Commission (FTC) handed down yet another penalty against an online retailer, Life is good, Inc., for not properly safeguarding their online ecommerce applications. The FTC charged they were in violation of the FTC Act because...

FTC Fines Mortgage Co. For Tossing PII Into Dumpster: FACTA/FCRA, GLBA, & FTC Act Violations

On December 17 the U.S. Federal Trade Commission (FTC) fined and penalized American United Mortgage Company for throwing the personally identifiable information (PII) and financial information of its customers and consumers into an open, publicly-accessible dumpster. Under the terms of...

There Are MANY Software Licensing and Awareness Tools Available For All Business Sizes and Budgets

Earlier this week I posted about one of the Business Software Alliance (BSA) initiatives for enforcing software licensing compliance, "Another Approach To Licensing Compliance." There are *MANY* software licensing tools and awareness communications that businesses of all sizes, and with...

DHS IT Security EBK: Don't Complain After They Are Published...Comment On Them While You Can!

The Department of Homeland Security (DHS) recently released the draft "IT Security Essential Body of Knowledge (EBK)" for public comment and feedback. This 45-page document outlines the skill sets the groups working with the DHS have determined as being necessary...

Do Employers Need GPS And Logs When They Have YouTube and Facebook To Monitor Employees?

I don't know why I continue to be surprised at the stupid things some people do, but apparently some people will never realize how much of themselves they are giving away when they post their pictures and other personal information...

Email is for "Old People": Do Lack of Laws Make IM and Texting Ripe for Exploiting Children & Teens?

My 13-year-old-niece wrote an article for me about social engineering, and I got a chuckle out of her writing, "Maybe I'm old-fashioned, but I only use email. I don't have my own FaceBook site." Can you imagine email being old-fashioned?!...

6 "Scary Stuff" Privacy Terms IT, Info Sec and Privacy Folks Should Know

Robert Ellis Smith sent me an email yesterday to let me know about his most recent article in Forbes magazine, "Scary Stuff." It's a very interesting read and highlights some terms that, to date, I have not seen in print...

Information Security and Privacy Leaders, Get Your Elevator Speeches Ready For Your CxOs!

My father was the superintendent of the public school district where I grew up in Missouri. He was a very hands-on type of leader; when he was not filling out forms, writing reports, making plans, or in meetings he was...

Another Approach To Licensing Compliance

My blog posting from earlier talked about how the MPAA is trying to combat movie piracy. I just visited the LinkedIn site and was intrigued to find an ad from the Business Software Alliance (BSA) offering up to $1,000,000...yes, US...

Don't Throw Away The Privacy Of All And Jeopardize Network Security To Run A Compliance Tool

Many times software designed to enforce legal compliance, or find network users who are breaking laws, bring along with them greater risks to information security and privacy....

Show "Home Alone" To Raise Social Engineering Awareness

I hope those of you who celebrated Thanksgiving had a great one! I spent a very nice day with my family at my brother's house. After getting back home we decided to watch some Christmas movies, so we spent the...

Show Your CFO and CEO the Potential Financial Impact of a Privacy Breach

My central Iowa Infragard president, Tom Conley sent all our members a note on Wednesday with a link to a site that contains 9 variables to help demonstrate the range of financial impact to organizations that experience an incident involving...

Something You Should Know: FTC Is Aggressively Going After Companies With Poor Security

Of all the U.S. government regulatory oversight agencies, the Federal Trade Commission (FTC) is the most active and aggressive in looking for and applying penalties to organizations that not only are in noncompliance with laws and regulations, but also those...

Why Would You Trust Microsoft To Store Your Sensitive Health Information?

Today Microsoft launched their new web portal, HealthVault to store, for free, "medical histories, immunization and other records from doctors' offices and hospital visits, including data from devices like heart monitors. It is also tied to a health information search...

The Need to Build Security In: Poor Implementation of Indianapolis Public Schools Website Allows Viewing of PII For 7000+ Students and Teachers

Today Monsters and Critics reported, "Indianapolis Public Schools exposes thousands to risk of identity theft." Apparently the Indianapolis Public Schools (IPS) website "that allows teachers to post reviews, student-writing samples, grades, and other confidential material to the IPS network" was...

Vulnerabilities of Transport Services & Privacy Incident Example: Wellpoint CD Containing PII of 75,000 People, Lost During UPS Transport, Found

A CD containing the clear text personal information of 75,000 WellPoint Empire Blue Cross and Blue Shield New York members that was reported lost on February 9 while being transported by UPS has been found. The CD was lost when...

Identity Theft: More Info On Fallout From The TJX Breach

The Akron Beacon Journal reported February 5 more impacts of the massive TJX breach that occurred late in 2006 that may have impacted over 40 million individuals according to the Wall Street Journal....

PCI DSS and GLBA Compliance & Privacy Breach: Lawsuits Filed Against TJX

Let's look at the events that have occurred with the recent TJX computer hack and resulting privacy breach and identity thefts:...

Puget Sound Energy Ordered to Pay $995,000 For Selling Customer Personal Information

Puget Sound Energy, Washington state's largest electricity and natural gas utility, with over 1 million customers in 11 western Washington counties, was ordered to pay a total of $995,000 in fines for selling their customer information to marketing companies over...

Routine Personal Information Posting in the U.S. State Government Agencies

NBC news ran a story about how many state government agencies post sensitive personally identifiable information (PII) on their websites. In this case an Ohio county court "routinely posted traffic tickets and other public records on its Web site."...

Laptop Protection Advice for The Holidays

Yesterday EARTHtimes, which appears to be a general news site, carried a story with a cute title that caught my eye, "Don't be a turkey: Protect your laptop during holiday travel."...

The State of Information Security According to E&Y

This year's Ernst & Young Global Information Security Survey 2006 is out and it is always an interesting read. Arguments aside about the statistical accuracy of such surveys, it still provides useful information and also helps to track progress in...

Information Assurance: Make a Perspective Adjustment; It's All About the Business

Last week I was at the Computer Security Institute 33rd Annual Computer Security Conference & Exhibition where Chris Grillo and I also gave our post-conference seminar, "Effectively Partnering InfoSec and Privacy For Business Success". It was interesting to hear the...

Another Tool for your Awareness Arsenal

The FTC recently made available a pretty neat privacy in socieal networking sites awareness raising quiz, "Buddy Builder."...

Consumers Want Identity Theft Protection Through Homeowner Insurance

An interesting article was released yesterday in the Insurance Journal, "J.D. Power: Homeowners Want Carriers to Offer Identity Theft." It indicates that the 2006 Homeowners Insurance Study, results of feedback from 9,045 homeowners insurance policy holders in the U.S., finds...

Information Security Compliance Webcast

My friend and professional colleague, Kevin Beaver, is giving a webcast on Tuesday, November 14, "How to manage the ongoing information security requirements for SOX, HIPAA, GLBA and other key regulations: A single solution." Kevin has great experience with information...

Website Privacy and Security Lessons From the USPS

Last Friday (10/27) Washington Technology published an interesting article, "USPS site is much more than just a presence on the Web" about the privacy challenges of the United States Postal Service (USPS) website. It is interesting and revealing to see...

Site Tags

Site tags used on this blog: