Posts Tagged ‘FCRA’
Wednesday, March 30th, 2011
Earlier today following my online seminar, “Effective Training and Awareness: The Key to Information Security Success” (http://gocsi.com/Training2011/OD/Awareness), I received the following question:
Where might I locate a summary breakdown of training regulations by industry? i.e. Pharma
(more…)
Tags:awareness, awareness training, CFAA, CSI, DMCA, education, FCRA, FISMA, FOIA, GLBA, HIPAA, HITECH, Information Security, OMB, privacy, Rebecca Herold, Red Flags, regulations, SOX, training
Posted in HIPAA, HITECH, Information Security, Laws & Regulations, privacy, Training & awareness | 3 Comments »
Thursday, June 11th, 2009
Today the US FTC released “Frequently Asked Questions: Identity Theft Red Flags and Address Discrepancies.”
Here are a couple important things to take away from this FAQ…
(more…)
Tags:awareness and training, FCRA, Information Security, IT compliance, IT training, policies and procedures, privacy training, Red Flags Rules, risk management, security training
Posted in Laws & Regulations | No Comments »
Wednesday, December 26th, 2007
Tags:American United Mortgage Company, awareness and training, disposal rule, FACTA, FCRA, FTC, FTC Act, GLBA, Information Security, IT compliance, policies and procedures, privacy, privacy incident, privacy policy, privacy rule, risk management, security awareness, security training
Posted in Information Security, Non-compliance Sanctions Examples, Privacy and Compliance | No Comments »
Friday, November 2nd, 2007
In addition to some great followup questions I got from Andy in response to my blog posting yesterday, “FTC Now Requires Organizations to Have an Identity Theft Prevention Program” I have also received some interesting questions from others about the new Identity Theft Prevention Program Rule, along with having the opportunity to have some interesting discussions with several folks today, such as Linda McGlasson at bankinfosecurity.com.
(more…)
Tags:awareness and training, FACTA, FCRA, Federal Reserve Act, FTC, Identity Theft Prevention Program, Information Security, IT compliance, policies and procedures, privacy, privacy training, risk management, security training
Posted in identity theft, Laws & Regulations | No Comments »
Friday, November 2nd, 2007
In addition to some great followup questions I got from Andy in response to my blog posting yesterday, “FTC Now Requires Organizations to Have an Identity Theft Prevention Program” I have also received some interesting questions from others about the new Identity Theft Prevention Program Rule, along with having the opportunity to have some interesting discussions with several folks today, such as Linda McGlasson at bankinfosecurity.com.
(more…)
Tags:awareness and training, FACTA, FCRA, Federal Reserve Act, FTC, Identity Theft Prevention Program, Information Security, IT compliance, policies and procedures, privacy, privacy training, risk management, security training
Posted in identity theft, Laws & Regulations | No Comments »
Friday, May 4th, 2007
Doing background checks on potential employees, and regularly for certain positions with significant access to personally identifiable information (PII) or managemen capabilities, has been a growing trend in recent years. Such checks are viewed as ways to help prevent putting untrustworthy and significant at-risk individuals into positions where they could perform malicious and/or criminal activities.
(more…)
Tags:awareness and training, employee privacy, FCRA, government, Information Security, IT compliance, policies and procedures, privacy, risk management, state employment law
Posted in government, Laws & Regulations, Privacy and Compliance | No Comments »
Friday, April 20th, 2007
Many information security incidents have occurred through non-technical means by simply and thoughtlessly throwing away printed documents into publicly-accessible trash bins, or even putting computers and sensitive documents out on the streets. I have blogged about this several times, such as here, here, and here.
(more…)
Tags:awareness and training, BS 8470:2006, data disposal, Data Protection Act, disposal rule, FACTA, FCRA, FTC, Information Security, IT compliance, policies and procedures, privacy, risk management
Posted in Information Security, Laws & Regulations, Privacy and Compliance | No Comments »
Monday, March 19th, 2007
I read with interest an article in today’s issue of the BNA Privacy and Security Law Report about over 100 lawsuits that have recently been filed within the California federal courts because of the amount of personally identifiable information (PII) that is printed on credit and debit card receipts.
(more…)
Tags:awareness and training, civil actions, credit reports, data accuracy, FACTA, FCRA, FTC, Information Security, IT compliance, PII, policies and procedures, privacy
Posted in government, identity theft, Information Security, Laws & Regulations, Privacy and Compliance | 4 Comments »
Monday, March 19th, 2007
I read with interest an article in today’s issue of the BNA Privacy and Security Law Report about over 100 lawsuits that have recently been filed within the California federal courts because of the amount of personally identifiable information (PII) that is printed on credit and debit card receipts.
(more…)
Tags:awareness and training, civil actions, credit reports, data accuracy, FACTA, FCRA, FTC, Information Security, IT compliance, PII, policies and procedures, privacy
Posted in government, identity theft, Information Security, Laws & Regulations, Privacy and Compliance | 5 Comments »
Sunday, February 11th, 2007
There now seem to be so many privacy breaches that it is hard to choose which one to discuss…
Last Wednesday, 2/7, Johns Hopkins University reported personal information on 135,000 employees and patients on nine backup tapes were missing that had been given to a contractor, Anacomp Co. Inc., to make microfiche backups.
(more…)
Tags:awareness and training, FACTA, FCRA, FERPA, FTC, FTC Act, HIPAA, identity theft, Information Security, IT compliance, policies and procedures, privacy, privacy breach
Posted in identity theft, Information Security, Laws & Regulations, Privacy and Compliance, Privacy Incidents | 4 Comments »