Posts Tagged ‘data protection’

ISMS Certification Does Not Equal Regulatory Compliance

Wednesday, October 31st, 2012

Last week I got the following question:

“By becoming ISO 27001 certified does that automatically mean we comply with HIPAA and HITECH requirements?  Are there any requirements of HIPAA/HITECH that are not required to meet ISO 27001 standards?”

This is not the first time I’ve gotten this question, and others similar. As new technology businesses, cloud services and other businesses are popping up to provide services to large regulated organizations, start-ups are increasingly looking for a way to differentiate themselves from their competitors, and also prove that they have not only effective security controls in place, but that they also (more…)

Repost From Social Media to Lose Customers and Friends Fast

Monday, October 22nd, 2012

Last week one of my Facebook friends started a “friends only” discussion on his wall. It was a very interesting discussion, and one of his friends took the discussion, pretty much verbatim, and posted within a “public” (as in meant for the world to see) popular blog site. So the information on the Facebook page, where around 250 – 300 people could see the posts were now in a location where the bazillion (possibly a bit fewer) blog readers could see all the posts and the full names of those who made them. This is not the first time a situation like this has occurred.  A lot of the information posted on people’s social media pages are really tempting to take and use as examples, or for business activities such as for marketing and promotions. However, doing so could get you into some personal and/or legal hot water.  As organizations and individuals consider taking information they find on social media sites, they need to consider the reasons why doing so may not be a good idea after all.

Reason #1: It will (more…)

Understanding Data Protection from 4 Critical Perspectives

Tuesday, May 5th, 2009

Today I gave a webcast (27 minutes) about “Understanding Data Protection from 4 Critical Perspectives” and it is now available online through this link

(more…)

Encryption Solution Reviews

Wednesday, March 18th, 2009

Here are some encryption solution reviews, from David Strom at PC World, that anyone who wants to protect their laptop data, as well as information security, and yes privacy, practitioners should find useful…

(more…)

Deloitte Survey Shows the Need for Effective Training

Wednesday, September 19th, 2007

Deloitte Touche Tohmatsu just released their “2007 Global Security Survey” report.

(more…)

International PII Data Transfers: New Requirements from Spain

Monday, July 30th, 2007

In this global economy it is important for you to know, understand and follow the data protection laws in all the countries where you have offices, have customers, store personally identifiable information (PII) and from where PII is accessed. Each country has nuances within their laws that could create quite a big obstacle if you are doing business there and find you must suddenly stop because you are out of compliance with their data protection laws.

(more…)

Reminder: Your “Privacy in the 21st Century” Submissions Need to Be in by July 27th…This Friday!

Tuesday, July 24th, 2007

Last week I posted about this year’s Global Security Week.

(more…)

Privacy in the 21st Century: Show Your Creativity for Global Security Week!

Thursday, July 19th, 2007

Global Security Week (GSW) is September 3rd through 9th.
The topic this year is “Privacy in the 21st Century.”

(more…)

Norman Borlaug: A Great Role Model for the Power of One

Thursday, July 19th, 2007

I have heard many information assurance (IA) professionals, when they are feeling frustrated, angry, or whatever other negative feelings we all have at one time or another, say what they are doing is not making a difference, or say they feel they are looked down upon by others in their organization as a “necessary evil.” They often feel that one person cannot make a difference.

(more…)

UK Annual Privacy Report: Businesses Need To Give Individuals Access to Their PII, and More Awareness and Training Is Needed

Wednesday, July 18th, 2007

Monday I talked about France’s 2006/2007 CNIL privacy report. The United Kingdom (UK) also recently released their 2006/2007 data protection report.

(more…)