Entries from Realtime Community | IT Compliance tagged with 'privacy policy'
Over the years I've found while doing website privacy policy reviews and gap analyses that a large portion of organizations make promises within their posted web site privacy policies that they do not support by internal procedures, and that they...
Posted by Rebecca Herold on October 3, 2008 11:45 AM
Over the past few years I've done a lot of research and reviewed a lot of privacy policies, and it's really been amazing to see how the wording in many of them are not providing any privacy protections to website...
Posted by Rebecca Herold on September 30, 2008 7:31 PM
Here's a pretty good mainstream news story from CNN to give to your business leaders to raise their awareness and understanding about phishing......
Posted by Rebecca Herold on February 13, 2008 2:40 PM
I knew the civil suits for lost laptops would start soon. Thanks so much to my buddy Alec for pointing out this story to me! Raelyn Campbell took a laptop computer to Best Buy to get fixed, and three months...
Posted by Rebecca Herold on February 13, 2008 11:08 AM
I just saw a term that can be used really well with non-technical folks, "data pollution." I wish I had thought of that term!...
Posted by Rebecca Herold on February 12, 2008 9:26 AM
This is a sad example of how others take it upon themselves to invade the privacy of others and don't understand that they're doing anything wrong......
Posted by Rebecca Herold on February 12, 2008 9:12 AM
Here are two more insider threat incident examples to put into your files and use within your information security and privacy training curriculum and awareness communications:...
Posted by Rebecca Herold on February 11, 2008 7:15 PM
Hopefully most people know by now that whatever you post on the Internet is not private, and that basically anyone can read it. Hopefully most people know by now that it is a growing trend for employers to use information...
Posted by Rebecca Herold on February 11, 2008 10:56 AM
Here's an interesting new law in Saudi Arabia... "New Law to Combat Information Technology Crimes...
Posted by Rebecca Herold on February 9, 2008 2:00 PM
Here's an interesting juxtaposition of hacker-related news articles... When scanning today's news I saw the headline, "Teen Is World's Youngest 'Ethical Hacker'"...
Posted by Rebecca Herold on February 8, 2008 9:23 AM
Here's a good article for all information security and privacy pros to read and show their business leaders. If nothing else show them the last paragraph:...
Posted by Rebecca Herold on February 7, 2008 11:40 AM
Here's one more thing for IT, Information Security and Privacy folks to put on their list of things to worry about......
Posted by Rebecca Herold on February 7, 2008 9:05 AM
I got a nice message from Brian Honan yesterday letting me know that February 12 is "Safer Internet Day," or SID for short; (Thanks Brian!)...
Posted by Rebecca Herold on February 6, 2008 9:00 AM
It seems all business leaders would understand by now, after literally thousands of privacy incidents in recent years, that they need to encrypt personally identifiable information (PII) stored on mobile computers and mobile storage devices, and when sending PII through...
Posted by Rebecca Herold on February 5, 2008 9:16 AM
Here's something scary... I just saw a new CNN report that made me go, "Huh?!" "FBI wants palm prints, eye scans, tattoo mapping"...
Posted by Rebecca Herold on February 4, 2008 4:36 PM
For the past few years the Ponemon Institute has done surveys to determine the U.S. companies most trusted to protect privacy....
Posted by Rebecca Herold on February 4, 2008 9:36 AM
Today I got a death threat email message. This particular type of spam is not really new, but because they will be very scary for most people to get, many recipients will fall for them. The address header and text...
Posted by Rebecca Herold on February 1, 2008 12:04 PM
Another country appears to be on the verge of passing a privacy breach notice law......
Posted by Rebecca Herold on February 1, 2008 9:04 AM
When I started blogging a couple of years ago (actually in January 2006...just realized I passed my anniversary!), I would not only post daily to my blog, but I would also publish 3 - 4 research papers or white papers...
Posted by Rebecca Herold on January 31, 2008 11:45 AM
Today, "Internet failure hits two continents" Were you impacted? If you were, then you probably aren't reading this right now... :)...
Posted by Rebecca Herold on January 31, 2008 10:23 AM
While scanning the news blurb summaries today, the statement, "This is a violation of HIPAA." caught my eye. Hmm...let's see what this is about... This statement was actually within the reader comments to the story, "Blue Cross reports theft of...
Posted by Rebecca Herold on January 30, 2008 2:42 PM
Yesterday the U.S. Federal Trade Commission (FTC) announced AccuSearch, Inc., was guilty of violating federal law by selling consumer phone records to third parties without consumers’ knowledge or authorization....
Posted by Rebecca Herold on January 29, 2008 3:59 PM
Uh oh...talk about a couple of folks who were caught with their hand in the cookie jar (so to speak)...and caught lying under oath. CNN recently ran a story about how Christine Beatty resigned from her position as chief of...
Posted by Rebecca Herold on January 28, 2008 7:26 PM
Last Thursday I posted about how tomorrow (1/28) is International Data Privacy Day. I was delighfully surprised to receive an email in response to my blog post from Leonardo Cervera, the coordinator of Data Privacy Day 2008! Be sure to...
Posted by Rebecca Herold on January 27, 2008 7:08 PM
Here is another example of what a worker, entrusted with access to business files, can do...and also provides a lesson about business continuity... I just watched a CNN clip, "Cyber Sabotage" that provides a very good example of how costly...
Posted by Rebecca Herold on January 25, 2008 10:19 AM
Did you know that International Data Privacy Day is fast approaching? On Monday, January 28 the United States joins 27 European countries to celebrate Data Privacy Day 2008. "The day will feature several efforts to promote the importance of data...
Posted by Rebecca Herold on January 24, 2008 1:49 PM
Personnel will understand information security and privacy issues better if they can relate to the issues within their own lives. If they can see how the issues impact their family members and friends, that helps to raise awareness even more....
Posted by Rebecca Herold on January 23, 2008 2:45 PM
Last month I finished the second issue of my Protecting Information publication and the topic couldn't be more timely: social engineering. Just today I have already read in my daily news items 5 articles about social engineering! One in particular,...
Posted by Rebecca Herold on January 22, 2008 2:38 PM
The U.S. Centers for Medicare and Medicaid Services (CMS) announced last week that they plan to audit 10 - 20 hospitals for HIPAA compliance in the next 9 months according to a Government Health IT article....
Posted by Rebecca Herold on January 21, 2008 8:51 PM
It is not only important, but absolutely necessary, to let personnel know what your information security and privacy policies are, along with your organization's sanctions, and then consistently enforce your policies. If personnel know that policies are not enforced, and...
Posted by Rebecca Herold on January 20, 2008 10:54 AM
Yesterday the U.S. Federal Trade Commission (FTC) handed down yet another penalty against an online retailer, Life is good, Inc., for not properly safeguarding their online ecommerce applications. The FTC charged they were in violation of the FTC Act because...
Posted by Rebecca Herold on January 18, 2008 10:56 AM
I'm helping one of my clients with updating their information security and privacy policies, aligning them with ISO 27002, and creating new policies to fill gaps as necessary based upon the organization's risks. I was speaking with the CISO this...
Posted by Rebecca Herold on January 16, 2008 11:46 AM
I just read a very interesting article, "CMS' HIPAA watchdog presents potential conflict" that made me go Hmmm!! The genesis of the article is that the Centers for Medicare and Medicaid Services (CMS), the agency that is responsible for the...
Posted by Rebecca Herold on January 15, 2008 2:30 AM
Here's another good example of an actual cybercrime that was allowed to occur because poor of safeguards on computers provided for public use. On January 9, 2008, Mario Simbaqueba Bonilla plead guilty to installing keylogger software on hotel business center...
Posted by Rebecca Herold on January 14, 2008 9:47 AM
On December 10 the U.S. Federal Trade Commission (FTC) announced that the FTC commissioners voted unanimously to have principles to govern online behavioral advertising. At the same time they released their proposed principles to guide the development of self-regulation in...
Posted by Rebecca Herold on December 27, 2007 10:23 AM
On December 17 the U.S. Federal Trade Commission (FTC) fined and penalized American United Mortgage Company for throwing the personally identifiable information (PII) and financial information of its customers and consumers into an open, publicly-accessible dumpster. Under the terms of...
Posted by Rebecca Herold on December 26, 2007 2:41 PM
This morning I did a podcast interview with bankinfosecurity and they already have it posted! During the interview I answered and expanded upon five questions and issues:...
Posted by Rebecca Herold on December 21, 2007 3:36 PM
It is time for some humorous entertainment to complement the holiday season, and PGP Corporation has provided it! Kevin Beaver pointed me to a great YouTube clip, "The 12 Threats of Christmas."...
Posted by Rebecca Herold on December 21, 2007 10:32 AM
Most folks are looking at what's coming in 2008. Heck, let's go a bit further and look at some potentially big changes slated for 2009! I just read an interesting Business Week story, "Just Ahead: A Wider Wireless World." In...
Posted by Rebecca Herold on December 20, 2007 8:28 AM
I just learned about a new survey that's going on, "The State of Information Security Survey 2008." Bankinfosecurity is using it to try to get the best picture of how financial institutions are doing when it comes to information security...
Posted by Rebecca Herold on December 20, 2007 8:08 AM
For the past 10 years I have been driving the same, reliable, non-troublesome car. It still looks good enough (I don't really worry about driving an "it" kind of car). However, it is getting a bit rattly, and my friends...
Posted by Rebecca Herold on December 19, 2007 11:38 AM
Organizations have faced legal and regulatory requirements for literally decades. However, IT compliance is relatively young. U.S. healthcare organizations reacted with alarm over the passage of the Health Insurance Portability and Accountability Act (HIPAA) of 1996. The U.S. financial organizations...
Posted by Rebecca Herold on December 18, 2007 4:01 PM
Tis the season for lists upon lists upon lists. However, Fortune's "101 Dumbest Moments in Business" for 2007 caught my eye for being rather unique-sounding. There were *MANY* dumb information security and privacy business moments in 2007; I wondered, did...
Posted by Rebecca Herold on December 17, 2007 9:12 PM
A couple of years ago I finally took my family on a vacation to the Bahamas after not going on any type of vacation for several years. Five months later I learned...from my friends and not from the hotel...that a...
Posted by Rebecca Herold on December 16, 2007 11:28 AM
I ran across some interesting e-commerce site "awards" recently published by CyberStreetSmart.org. They identified the recipients of their "screen door" (the award retailers DON'T want) and "steel door" (retailers want this) awards based upon the privacy protections the sites had...
Posted by Rebecca Herold on December 14, 2007 5:23 PM
Many organizations dangerously change their posted privacy policies often, and often without giving notice to their customers. It is important to always keep in mind that your posted privacy policy is a legally binding contract with your customers. You cannot...
Posted by Rebecca Herold on August 10, 2007 4:00 AM
Recently I was speaking with a client about a new Internet e-commerce application they were testing, and I asked them to give a demonstration. One of the questions I asked while watching was whether there were any ways in which...
Posted by Rebecca Herold on July 10, 2007 1:30 AM
Site tags used on this blog: