Entries from Realtime Community | IT Compliance tagged with 'security risk'
Last week the U.S. Federal Deposit Insurance Corporation (FDIC) released an updated version of their IT officer's risk management program questionnaire for banks and financial organizations to use to prepare for regulator audits. Information security, privacy and IT pros in...
Posted by Rebecca Herold on December 10, 2007 7:38 PM
I like to keep my eye on the FTC site; they are very active in catching businesses violating the U.S. FTC Act by practicing unfair and deceptive business practices, particularly via the Internet. They really demonstrate the need for privacy...
Posted by Rebecca Herold on December 9, 2007 8:49 PM
I've been seeing a ton of articles and blog postings for the "Best Security Whatever> of 2007," "Worst Security Exploits of 2007," "Security Projections for 2008" and so on in the past few weeks. Well, I've got my own "Best...
Posted by Rebecca Herold on December 7, 2007 1:09 PM
So many times...actually almost every time...a privacy breach occurs the company that experienced the breach makes a public statement similar to, "We have no evidence that the personal information has been used fraudulently" or "We do not believe the information...
Posted by Rebecca Herold on December 6, 2007 12:24 PM
California's privacy breach notification law SB1386 started the ball rolling with regard to what is now at least 40 U.S. states, including the District of Columbia, that have breach notice laws. Most of the subsequent state laws largely based theirs...
Posted by Rebecca Herold on December 5, 2007 12:47 PM
Most organizations got into mobile computing at the hands of the folks in the various business units, and security was an afterthought. However, recent history has shown numerous incidents that have occurred as a result of not properly addressing mobile...
Posted by Rebecca Herold on December 4, 2007 2:30 AM
In recent years many organizations have implemented the use of computer logs on their networks to be in compliance with multiple laws. However, here's a perfect example of the value of computer logs beyond just to be in compliance; using...
Posted by Rebecca Herold on December 3, 2007 4:09 PM
On November 28 U.S. President G. W. Bush appointed Marie O'Neill Sciarrone to be Special Assistant to the President for Homeland Security and Senior Director for Cybersecurity and Information Sharing Policy....
Posted by Rebecca Herold on December 2, 2007 11:16 AM
Earlier this week I posted about one of the Business Software Alliance (BSA) initiatives for enforcing software licensing compliance, "Another Approach To Licensing Compliance." There are *MANY* software licensing tools and awareness communications that businesses of all sizes, and with...
Posted by Rebecca Herold on December 1, 2007 10:46 AM
The Department of Homeland Security (DHS) recently released the draft "IT Security Essential Body of Knowledge (EBK)" for public comment and feedback. This 45-page document outlines the skill sets the groups working with the DHS have determined as being necessary...
Posted by Rebecca Herold on November 30, 2007 12:10 PM
I don't know why I continue to be surprised at the stupid things some people do, but apparently some people will never realize how much of themselves they are giving away when they post their pictures and other personal information...
Posted by Rebecca Herold on November 29, 2007 10:14 AM
My 13-year-old-niece wrote an article for me about social engineering, and I got a chuckle out of her writing, "Maybe I'm old-fashioned, but I only use email. I don't have my own FaceBook site." Can you imagine email being old-fashioned?!...
Posted by Rebecca Herold on November 28, 2007 7:49 PM
Robert Ellis Smith sent me an email yesterday to let me know about his most recent article in Forbes magazine, "Scary Stuff." It's a very interesting read and highlights some terms that, to date, I have not seen in print...
Posted by Rebecca Herold on November 27, 2007 8:02 PM
My father was the superintendent of the public school district where I grew up in Missouri. He was a very hands-on type of leader; when he was not filling out forms, writing reports, making plans, or in meetings he was...
Posted by Rebecca Herold on November 26, 2007 8:21 PM
My blog posting from earlier talked about how the MPAA is trying to combat movie piracy. I just visited the LinkedIn site and was intrigued to find an ad from the Business Software Alliance (BSA) offering up to $1,000,000...yes, US...
Posted by Rebecca Herold on November 25, 2007 7:29 PM
Many times software designed to enforce legal compliance, or find network users who are breaking laws, bring along with them greater risks to information security and privacy....
Posted by Rebecca Herold on November 25, 2007 4:07 PM
I hope those of you who celebrated Thanksgiving had a great one! I spent a very nice day with my family at my brother's house. After getting back home we decided to watch some Christmas movies, so we spent the...
Posted by Rebecca Herold on November 24, 2007 11:54 AM
My central Iowa Infragard president, Tom Conley sent all our members a note on Wednesday with a link to a site that contains 9 variables to help demonstrate the range of financial impact to organizations that experience an incident involving...
Posted by Rebecca Herold on November 23, 2007 1:54 PM
As a continuation of my blog posting from Monday, here are 7 additional reasons to add to the previous 4 for why sending cleartext instant messages (IMs) and email is not secure:...
Posted by Rebecca Herold on November 21, 2007 12:03 PM
I got some interesting comments and questions, and lots of good direct feedback, about my blog post on sending cleartext patient information last week, "HIPAA: Beware Doctors Who Claim They Don't Have To Follow Safeguard and Privacy Requirements" so I...
Posted by Rebecca Herold on November 19, 2007 7:59 PM
Early this year I did a data flow analysis for I-9 compliance, and I blogged a few months ago about I-9 related issues in "New Tennessee Law Prohibits Using Federal Individual Taxpayer ID as Proof of Immigration Status." I-9 compliance...
Posted by Rebecca Herold on November 18, 2007 7:37 PM
As I was reading this week's issue of Time magazine I found a backup lesson given by Francis Ford Coppola!...
Posted by Rebecca Herold on November 16, 2007 9:34 AM
My good friend Alec recently made me aware of a very interesting blog post made by a physician (thanks Alec!) that is frankly quite troubling....
Posted by Rebecca Herold on November 15, 2007 11:29 AM
Site tags used on this blog: