Archive for the ‘Privacy and Compliance’ Category
Thursday, August 30th, 2007
A very interesting article in USA Today caught my eye, “Beijing police will patrol Web virtually”
(more…)
Tags:awareness and training, China, Information Security, Internet use, IT compliance, policies and procedures, privacy, risk management, surveillance
Posted in government, Privacy and Compliance | 1 Comment »
Wednesday, August 29th, 2007
I like to run. I try to run almost every day from 3.5 – 6 miles. It stimulates my thinking, refreshes my mind and body, and I truly have the best ideas and thoughts while I’m running. I could not have written my books, chapters and articles if it were not for running.
(more…)
Tags:awareness and training, Information Security, IT compliance, policies and procedures, privacy, risk management, running
Posted in Information Security, Privacy and Compliance, Training & awareness | No Comments »
Tuesday, August 28th, 2007
Well, if you look at the results of my very unscientific poll from last week, it appears there is a very wide range of opinions about the use of social networking sites at work.
(more…)
Tags:awareness and training, facebook, Information Security, IT compliance, MySpace, personally identifiable information, PII, policies and procedures, privacy, risk management, social networking, YouTube
Posted in Information Security, Privacy and Compliance | 2 Comments »
Monday, August 27th, 2007
Tags:awareness and training, Information Security, IT compliance, personally identifiable information, PII, policies and procedures, privacy, risk management
Posted in government, Privacy and Compliance | 2 Comments »
Friday, August 24th, 2007
on 8/22/2007 a very interesting and useful report was released by the European Network and Information Security Agency (ENISA), “Information security awareness initiatives: Current practice and the measurement of success.”
(more…)
Tags:awareness and training, data protection law, ENISA, EU Data Protection Directive, European Union, Information Security, IT compliance, personally identifiable information, PII, policies and procedures, PricewaterhouseCoopers, privacy, privacy law, risk management
Posted in Information Security, Privacy and Compliance, Training & awareness | 3 Comments »
Thursday, August 23rd, 2007
As a follow-up to my blog posting yesterday, I wanted to point out that the European Union (EU) Data Protection Authorities (DPAs) have been very active in pursuing data protection law compliance.
(more…)
Tags:Article 29 Working Party, awareness and training, data protection law, EU Data Protection Directive, European Union, Information Security, IT compliance, policies and procedures, privacy, privacy law, risk management
Posted in Privacy and Compliance | No Comments »
Wednesday, August 22nd, 2007
Multi-national organizations doing business in Europe must know and understand not only their obligations to protect personally identifiable information (PII) under the European Union (EU) Data Protection Directive 95/45/EC, but they must also know and understand the data protection laws within each of the EU member countries.
(more…)
Tags:awareness and training, data protection law, EU Data Protection Directive, European Union, Information Security, IT compliance, policies and procedures, privacy, privacy law, risk management
Posted in Laws & Regulations, Privacy and Compliance | No Comments »
Monday, August 20th, 2007
Over the weekend I read yet another news article about social networking sites and the related risks. This time it was about how schools are implementing rules to address cyber bullying on the Internet; “Students To Be Punished For MySpace Postings.”
(more…)
Tags:awareness and training, facebook, Information Security, IT compliance, MySpace, personally identifiable information, PII, policies and procedures, privacy, risk management, social networking
Posted in Information Security, Privacy and Compliance | 2 Comments »
Monday, August 20th, 2007
The new U.S. Social Security number (SSN) No Match Rule was published August 15 in the Federal Register. You can also see it here.
This new regulation provides directives for the letters the U.S. Social Security Administration (SSA) issues to employers when the SSA discovers that an SSN does not match the information provided by the employer.
(more…)
Tags:awareness and training, Department of Homeland Security, DHS, Information Security, IT compliance, no match letter, no match rule, PII, policies and procedures, privacy, risk management, social security administration, social security number, SSA, SSN
Posted in Laws & Regulations, Privacy and Compliance | 1 Comment »
Friday, August 17th, 2007
Just because a social networking site says it is secure, and even if it has “TRUSTe,” “Hacker Safe” or other security and privacy assurance stamps on the site, it does not mean that bad things cannot happen. Take Facebook as a case in point.
(more…)
Tags:andyitguy, awareness and training, facebook, hacker safe, Information Security, infosecblog, IT compliance, policies and procedures, privacy, risk management, social network, truste
Posted in Information Security, Privacy and Compliance, Privacy Incidents | 2 Comments »