Search Realtime IT Compliance

Entries from Realtime Community | IT Compliance tagged with 'privacy policy'


Do Your Legal Contracts Conflict with Your Web Site Privacy Policy?

Over the years I've found while doing website privacy policy reviews and gap analyses that a large portion of organizations make promises within their posted web site privacy policies that they do not support by internal procedures, and that they...

Do Your Legal Contracts Trick Web Site Visitors into Installing Spyware?

Over the past few years I've done a lot of research and reviewed a lot of privacy policies, and it's really been amazing to see how the wording in many of them are not providing any privacy protections to website...

Phisherthieves Like Banks Best

Here's a pretty good mainstream news story from CNN to give to your business leaders to raise their awareness and understanding about phishing......

$54 Million Lawsuit Against Best Buy For Losing Laptop

I knew the civil suits for lost laptops would start soon. Thanks so much to my buddy Alec for pointing out this story to me! Raelyn Campbell took a laptop computer to Best Buy to get fixed, and three months...

Give a Hoot, Don't Privacy Pollute!

I just saw a term that can be used really well with non-technical folks, "data pollution." I wish I had thought of that term!...

Potty Pics Poo-Poo Privacy

This is a sad example of how others take it upon themselves to invade the privacy of others and don't understand that they're doing anything wrong......

U.S. DoD Workers Give Military Secrets To China

Here are two more insider threat incident examples to put into your files and use within your information security and privacy training curriculum and awareness communications:...

Blog Info OK'd To Use To Make Medical Insurance Coverage Decision

Hopefully most people know by now that whatever you post on the Internet is not private, and that basically anyone can read it. Hopefully most people know by now that it is a growing trend for employers to use information...

New Information Technology Crime Law in Saudi Arabia

Here's an interesting new law in Saudi Arabia... "New Law to Combat Information Technology Crimes...

Two Types Of Young Hackers

Here's an interesting juxtaposition of hacker-related news articles... When scanning today's news I saw the headline, "Teen Is World's Youngest 'Ethical Hacker'"...

More Info Security & Privacy Education Will Reduce The Numbers Of Incidents

Here's a good article for all information security and privacy pros to read and show their business leaders. If nothing else show them the last paragraph:...

Today Google Provides Another Path For Data Leakage

Here's one more thing for IT, Information Security and Privacy folks to put on their list of things to worry about......

Did You Know February 12 is "Safer Internet Day"?

I got a nice message from Brian Honan yesterday letting me know that February 12 is "Safer Internet Day," or SID for short; (Thanks Brian!)...

Encryption So Easy Even A Terrorist Can Use It

It seems all business leaders would understand by now, after literally thousands of privacy incidents in recent years, that they need to encrypt personally identifiable information (PII) stored on mobile computers and mobile storage devices, and when sending PII through...

FBI Plans to Catalog Everyone's Physical Characteristics, and Bush Does Away With Privacy Oversight Board

Here's something scary... I just saw a new CNN report that made me go, "Huh?!" "FBI wants palm prints, eye scans, tattoo mapping"...

What Companies Do You Trust With Your Privacy?

For the past few years the Ponemon Institute has done surveys to determine the U.S. companies most trusted to protect privacy....

Don't Let Your Folks Fall For This Scary Spam

Today I got a death threat email message. This particular type of spam is not really new, but because they will be very scary for most people to get, many recipients will fall for them. The address header and text...

A New Privacy/Security Breach Notice Law Soon In The Land Down Under?

Another country appears to be on the verge of passing a privacy breach notice law......

Blog Changes...More Papers, Less Daily Opinions

When I started blogging a couple of years ago (actually in January 2006...just realized I passed my anniversary!), I would not only post daily to my blog, but I would also publish 3 - 4 research papers or white papers...

Were You Taken Offline?

Today, "Internet failure hits two continents" Were you impacted? If you were, then you probably aren't reading this right now... :)...

A Stolen Health Insurer's Laptop With PII Is Not Necessarily A HIPAA Violation

While scanning the news blurb summaries today, the statement, "This is a violation of HIPAA." caught my eye. Hmm...let's see what this is about... This statement was actually within the reader comments to the story, "Blue Cross reports theft of...

AccuSearch Fined ~$200,000 For Pretexting & Selling Phone Numbers

Yesterday the U.S. Federal Trade Commission (FTC) announced AccuSearch, Inc., was guilty of violating federal law by selling consumer phone records to third parties without consumers’ knowledge or authorization....

Cell Phone Text Messages Are Private...NOT!

Uh oh...talk about a couple of folks who were caught with their hand in the cookie jar (so to speak)...and caught lying under oath. CNN recently ran a story about how Christine Beatty resigned from her position as chief of...

Some more information and ideas for Data Privacy Day, January 28

Last Thursday I posted about how tomorrow (1/28) is International Data Privacy Day. I was delighfully surprised to receive an email in response to my blog post from Leonardo Cervera, the coordinator of Data Privacy Day 2008! Be sure to...

Insider Threat: Worker Deletes 7 Years of Files; Lesson? Make Backups!!

Here is another example of what a worker, entrusted with access to business files, can do...and also provides a lesson about business continuity... I just watched a CNN clip, "Cyber Sabotage" that provides a very good example of how costly...

January 28 is International Data Privacy Day

Did you know that International Data Privacy Day is fast approaching? On Monday, January 28 the United States joins 27 European countries to celebrate Data Privacy Day 2008. "The day will feature several efforts to promote the importance of data...

Improve Information Security And Privacy By Engaging Your Personnel And Their Children...Our Future Information Security and Privacy Leaders

Personnel will understand information security and privacy issues better if they can relate to the issues within their own lives. If they can see how the issues impact their family members and friends, that helps to raise awareness even more....

Social Engineering Schemes Increase: Great Case Study From An Actual Event

Last month I finished the second issue of my Protecting Information publication and the topic couldn't be more timely: social engineering. Just today I have already read in my daily news items 5 articles about social engineering! One in particular,...

CMS Announces Plans To Actively Audit Hospitals For HIPAA Compliance

The U.S. Centers for Medicare and Medicaid Services (CMS) announced last week that they plan to audit 10 - 20 hospitals for HIPAA compliance in the next 9 months according to a Government Health IT article....

Insider Threat Example: Former Cox Employee Sent To Jail (And More) For Hacking System

It is not only important, but absolutely necessary, to let personnel know what your information security and privacy policies are, along with your organization's sanctions, and then consistently enforce your policies. If personnel know that policies are not enforced, and...

FTC Hands Down Another FTC Act Noncompliance Penalty For Bad Online Application Security

Yesterday the U.S. Federal Trade Commission (FTC) handed down yet another penalty against an online retailer, Life is good, Inc., for not properly safeguarding their online ecommerce applications. The FTC charged they were in violation of the FTC Act because...

Clearly Justify Your Information Security and Privacy Policies

I'm helping one of my clients with updating their information security and privacy policies, aligning them with ISO 27002, and creating new policies to fill gaps as necessary based upon the organization's risks. I was speaking with the CISO this...

CMS Hires A Fox To Guard The HIPAA Henhouse

I just read a very interesting article, "CMS' HIPAA watchdog presents potential conflict" that made me go Hmmm!! The genesis of the article is that the Centers for Medicare and Medicaid Services (CMS), the agency that is responsible for the...

Man Pleads Guilty To Loading Keylogger Software On Public Computers Worldwide To Collect PII and Commit Fraud

Here's another good example of an actual cybercrime that was allowed to occur because poor of safeguards on computers provided for public use. On January 9, 2008, Mario Simbaqueba Bonilla plead guilty to installing keylogger software on hotel business center...

FTC Behavioral Advertising Privacy Principles: Give Them Your Feedback!

On December 10 the U.S. Federal Trade Commission (FTC) announced that the FTC commissioners voted unanimously to have principles to govern online behavioral advertising. At the same time they released their proposed principles to guide the development of self-regulation in...

FTC Fines Mortgage Co. For Tossing PII Into Dumpster: FACTA/FCRA, GLBA, & FTC Act Violations

On December 17 the U.S. Federal Trade Commission (FTC) fined and penalized American United Mortgage Company for throwing the personally identifiable information (PII) and financial information of its customers and consumers into an open, publicly-accessible dumpster. Under the terms of...

Be Prepared For Privacy Breaches!

This morning I did a podcast interview with bankinfosecurity and they already have it posted! During the interview I answered and expanded upon five questions and issues:...

The 12 Threats of Chistmas

It is time for some humorous entertainment to complement the holiday season, and PGP Corporation has provided it! Kevin Beaver pointed me to a great YouTube clip, "The 12 Threats of Christmas."...

New Wireless = New Vulnerabilities = More Incidents?

Most folks are looking at what's coming in 2008. Heck, let's go a bit further and look at some potentially big changes slated for 2009! I just read an interesting Business Week story, "Just Ahead: A Wider Wireless World." In...

Information Security Survey for Financials

I just learned about a new survey that's going on, "The State of Information Security Survey 2008." Bankinfosecurity is using it to try to get the best picture of how financial institutions are doing when it comes to information security...

Responding To Customers Asking About Your Company's Use of SSNs

For the past 10 years I have been driving the same, reliable, non-troublesome car. It still looks good enough (I don't really worry about driving an "it" kind of car). However, it is getting a bit rattly, and my friends...

Supporting Compliance With ITIL

Organizations have faced legal and regulatory requirements for literally decades. However, IT compliance is relatively young. U.S. healthcare organizations reacted with alarm over the passage of the Health Insurance Portability and Accountability Act (HIPAA) of 1996. The U.S. financial organizations...

18 IT Compliance, Info Sec & Privacy Links to Fortune's 101 Dumbest Business Moments in 2007

Tis the season for lists upon lists upon lists. However, Fortune's "101 Dumbest Moments in Business" for 2007 caught my eye for being rather unique-sounding. There were *MANY* dumb information security and privacy business moments in 2007; I wondered, did...

2 Years Following Major Privacy Breach, Bahamas Puts Up Data Protection Web Site

A couple of years ago I finally took my family on a vacation to the Bahamas after not going on any type of vacation for several years. Five months later I learned...from my friends and not from the hotel...that a...

"Awards" Given For E-Commerce Site Privacy Policies...The Best And The Worst

I ran across some interesting e-commerce site "awards" recently published by CyberStreetSmart.org. They identified the recipients of their "screen door" (the award retailers DON'T want) and "steel door" (retailers want this) awards based upon the privacy protections the sites had...

Avoid Being Sued And Losing Customers: Don't Go Changing Your Privacy Policy Willy-Nilly!

Many organizations dangerously change their posted privacy policies often, and often without giving notice to their customers. It is important to always keep in mind that your posted privacy policy is a legally binding contract with your customers. You cannot...

Privacy Not Only Requires Securing PII, It Also Requires Keeping the Trust of Your Customers

Recently I was speaking with a client about a new Internet e-commerce application they were testing, and I asked them to give a demonstration. One of the questions I asked while watching was whether there were any ways in which...

Site Tags

Site tags used on this blog: