Search Realtime IT Compliance

Entries from Realtime Community | IT Compliance tagged with 'security risk'


FDIC Releases Updated IT Officer’s Risk Management Program Questionnaire

Last week the U.S. Federal Deposit Insurance Corporation (FDIC) released an updated version of their IT officer's risk management program questionnaire for banks and financial organizations to use to prepare for regulator audits. Information security, privacy and IT pros in...

FTC Settlement For Marketing Via Pop-up Ads: Lessons For All Marketers Regarding Consent & Consumer Complaints

I like to keep my eye on the FTC site; they are very active in catching businesses violating the U.S. FTC Act by practicing unfair and deceptive business practices, particularly via the Internet. They really demonstrate the need for privacy...

And The Award For Best Email Security Awareness Film of 2007 Goes To...

I've been seeing a ton of articles and blog postings for the "Best Security Whatever> of 2007," "Worst Security Exploits of 2007," "Security Projections for 2008" and so on in the past few weeks. Well, I've got my own "Best...

Be Aware: Court Ruling Allows Circumstantial Evidence In Court Case Against Company That Experienced Privacy Breach

So many times...actually almost every time...a privacy breach occurs the company that experienced the breach makes a public statement similar to, "We have no evidence that the personal information has been used fraudulently" or "We do not believe the information...

California Privacy Breach Law Changes Go Into Effect January 1, 2008: Redefines & Broadens "Personal Information" Definition

California's privacy breach notification law SB1386 started the ball rolling with regard to what is now at least 40 U.S. states, including the District of Columbia, that have breach notice laws. Most of the subsequent state laws largely based theirs...

Mobile Security: Goals and Frequent Misses

Most organizations got into mobile computing at the hands of the folks in the various business units, and security was an afterthought. However, recent history has shown numerous incidents that have occurred as a result of not properly addressing mobile...

Insider Threat, the Value of Computer Logs & the Need for Consistent Policy Enforcement

In recent years many organizations have implemented the use of computer logs on their networks to be in compliance with multiple laws. However, here's a perfect example of the value of computer logs beyond just to be in compliance; using...

New U.S. Cybersecurity Special Assistant Appointed on November 28

On November 28 U.S. President G. W. Bush appointed Marie O'Neill Sciarrone to be Special Assistant to the President for Homeland Security and Senior Director for Cybersecurity and Information Sharing Policy....

There Are MANY Software Licensing and Awareness Tools Available For All Business Sizes and Budgets

Earlier this week I posted about one of the Business Software Alliance (BSA) initiatives for enforcing software licensing compliance, "Another Approach To Licensing Compliance." There are *MANY* software licensing tools and awareness communications that businesses of all sizes, and with...

DHS IT Security EBK: Don't Complain After They Are Published...Comment On Them While You Can!

The Department of Homeland Security (DHS) recently released the draft "IT Security Essential Body of Knowledge (EBK)" for public comment and feedback. This 45-page document outlines the skill sets the groups working with the DHS have determined as being necessary...

Do Employers Need GPS And Logs When They Have YouTube and Facebook To Monitor Employees?

I don't know why I continue to be surprised at the stupid things some people do, but apparently some people will never realize how much of themselves they are giving away when they post their pictures and other personal information...

Email is for "Old People": Do Lack of Laws Make IM and Texting Ripe for Exploiting Children & Teens?

My 13-year-old-niece wrote an article for me about social engineering, and I got a chuckle out of her writing, "Maybe I'm old-fashioned, but I only use email. I don't have my own FaceBook site." Can you imagine email being old-fashioned?!...

6 "Scary Stuff" Privacy Terms IT, Info Sec and Privacy Folks Should Know

Robert Ellis Smith sent me an email yesterday to let me know about his most recent article in Forbes magazine, "Scary Stuff." It's a very interesting read and highlights some terms that, to date, I have not seen in print...

Information Security and Privacy Leaders, Get Your Elevator Speeches Ready For Your CxOs!

My father was the superintendent of the public school district where I grew up in Missouri. He was a very hands-on type of leader; when he was not filling out forms, writing reports, making plans, or in meetings he was...

Another Approach To Licensing Compliance

My blog posting from earlier talked about how the MPAA is trying to combat movie piracy. I just visited the LinkedIn site and was intrigued to find an ad from the Business Software Alliance (BSA) offering up to $1,000,000...yes, US...

Don't Throw Away The Privacy Of All And Jeopardize Network Security To Run A Compliance Tool

Many times software designed to enforce legal compliance, or find network users who are breaking laws, bring along with them greater risks to information security and privacy....

Show "Home Alone" To Raise Social Engineering Awareness

I hope those of you who celebrated Thanksgiving had a great one! I spent a very nice day with my family at my brother's house. After getting back home we decided to watch some Christmas movies, so we spent the...

Show Your CFO and CEO the Potential Financial Impact of a Privacy Breach

My central Iowa Infragard president, Tom Conley sent all our members a note on Wednesday with a link to a site that contains 9 variables to help demonstrate the range of financial impact to organizations that experience an incident involving...

7 More Reasons Why Sending Cleartext IM and Email Is *NOT* Secure Even If Your Doc Says It Is...Part 2

As a continuation of my blog posting from Monday, here are 7 additional reasons to add to the previous 4 for why sending cleartext instant messages (IMs) and email is not secure:...

Sending Cleartext IM and Email Is *NOT* Secure Even If Your Doc Says It Is...Part 1

I got some interesting comments and questions, and lots of good direct feedback, about my blog post on sending cleartext patient information last week, "HIPAA: Beware Doctors Who Claim They Don't Have To Follow Safeguard and Privacy Requirements" so I...

Personnel Privacy, New I-9 Forms, Removal of SSN Requirements and IT Involvement

Early this year I did a data flow analysis for I-9 compliance, and I blogged a few months ago about I-9 related issues in "New Tennessee Law Prohibits Using Federal Individual Taxpayer ID as Proof of Immigration Status." I-9 compliance...

A Lesson In IT Backup Media Management From Francis Ford Coppola

As I was reading this week's issue of Time magazine I found a backup lesson given by Francis Ford Coppola!...

HIPAA: Beware Doctors Who Claim They Don't Have To Follow Safeguard and Privacy Requirements

My good friend Alec recently made me aware of a very interesting blog post made by a physician (thanks Alec!) that is frankly quite troubling....

Site Tags

Site tags used on this blog: