Posts Tagged ‘Information Security’
Friday, December 28th, 2007
I like to carry extra laptop and cell phone batteries with me when I travel for more than a couple of days at a time, especially if going outside the country. I fried a cell phone once using a faulty outlet converter overseas, so now I like to play it safer by depending upon extra batteries. It was fairly simple to pack the extra batteries into my checked luggage. It was a good simple way to have a backup power source while travelling.
Well, as of next Tuesday that simplicity is no more.
(more…)
Tags:awareness and training, Department of Homeland Security, department of transportation, Information Security, IT compliance, lithium batteries, policies and procedures, risk management, security awareness, security training, travel safety, U.S. law
Posted in Laws & Regulations | 1 Comment »
Thursday, December 27th, 2007
On December 10 the U.S. Federal Trade Commission (FTC) announced that the FTC commissioners voted unanimously to have principles to govern online behavioral advertising. At the same time they released their proposed principles to guide the development of self-regulation in this area.
(more…)
Tags:awareness and training, behavioral advertising, cookies, FTC, FTC Act, Information Security, IT compliance, policies and procedures, privacy, privacy policy, privacy principles, risk management, security awareness, security training, web bugs
Posted in Laws & Regulations, Privacy and Compliance | No Comments »
Wednesday, December 26th, 2007
Tags:American United Mortgage Company, awareness and training, disposal rule, FACTA, FCRA, FTC, FTC Act, GLBA, Information Security, IT compliance, policies and procedures, privacy, privacy incident, privacy policy, privacy rule, risk management, security awareness, security training
Posted in Information Security, Non-compliance Sanctions Examples, Privacy and Compliance | No Comments »
Friday, December 21st, 2007
This morning I did a podcast interview with bankinfosecurity and they already have it posted!
During the interview I answered and expanded upon five questions and issues:
(more…)
Tags:awareness and training, bankinfosecurity, breach response, incident response, Information Security, IT compliance, policies and procedures, privacy, privacy breach, privacy policy, risk management, security awareness, security training
Posted in Privacy and Compliance | No Comments »
Friday, December 21st, 2007
It is time for some humorous entertainment to complement the holiday season, and PGP Corporation has provided it!
Kevin Beaver pointed me to a great YouTube clip, “The 12 Threats of Christmas.”
(more…)
Tags:awareness and training, Information Security, IT compliance, Kevin Beaver, PGP, policies and procedures, privacy, privacy policy, risk management, security awareness, security training
Posted in Training & awareness | No Comments »
Thursday, December 20th, 2007
Most folks are looking at what’s coming in 2008. Heck, let’s go a bit further and look at some potentially big changes slated for 2009!
I just read an interesting Business Week story, “Just Ahead: A Wider Wireless World.”
In February, 2009 analog television broadcasting will be terminated.
(more…)
Tags:awareness and training, Information Security, IT compliance, policies and procedures, privacy, privacy policy, risk management, security awareness, security training, wireless security
Posted in Information Security | No Comments »
Thursday, December 20th, 2007
Most folks are looking at what’s coming in 2008. Heck, let’s go a bit further and look at some potentially big changes slated for 2009!
I just read an interesting Business Week story, “Just Ahead: A Wider Wireless World.”
In February, 2009 analog television broadcasting will be terminated.
(more…)
Tags:awareness and training, Information Security, IT compliance, policies and procedures, privacy, privacy policy, risk management, security awareness, security training, wireless security
Posted in Information Security | 1 Comment »
Thursday, December 20th, 2007
I just learned about a new survey that’s going on, “The State of Information Security Survey 2008.”
Bankinfosecurity is using it to try to get the best picture of how financial institutions are doing when it comes to information security at their institutions.
(more…)
Tags:awareness and training, bankinfosecurity, Information Security, IT compliance, policies and procedures, privacy, privacy policy, risk management, security awareness, security training
Posted in Information Security | No Comments »
Wednesday, December 19th, 2007
For the past 10 years I have been driving the same, reliable, non-troublesome car. It still looks good enough (I don’t really worry about driving an “it” kind of car). However, it is getting a bit rattly, and my friends have been increasingly giving me a hard time about continuing to drive it past the 200,000 mile mark. I never really cared much until my starter went out a couple of months ago. I wondered, what if this had happened to me while I was in a neighboring state at a client site? Sure, I have AAA, but it would still be a hassle. So, I decided if I saw a car I really liked and that had all the features I wanted, I would splurge and get a new car.
Well…I just happened to find a car I absolutely loved after seeing and driving it. I was at the dealer paying for it yesterday, and the sales person asked for my Social Security Number (SSN).
(more…)
Tags:awareness and training, FERPA, GLBA, HIPAA, identity theft, Information Security, Iowa law, IT compliance, personally identifiable information, PII, policies and procedures, privacy, privacy policy, risk management, security awareness, security training, social security number, SSN
Posted in Privacy and Compliance | 1 Comment »
Tuesday, December 18th, 2007
Organizations have faced legal and regulatory requirements for literally decades. However, IT compliance is relatively young.
U.S. healthcare organizations reacted with alarm over the passage of the Health Insurance Portability and Accountability Act (HIPAA) of 1996. The U.S. financial organizations soon followed suit with their reaction to the passage of the Gramm Leach Bliley Act (GLBA), also known as the Financial Modernization Act, of 1999. But probably the biggest whammy felt by the largest numbers of organizations was the passage of the Sarbanes Oxley (SOX) Act of 2002.
(more…)
Tags:awareness and training, GLBA, HIPAA, Information Security, IT compliance, ITIL, PCI, policies and procedures, privacy, privacy policy, risk management, security awareness, security training, SOX
Posted in Privacy and Compliance | No Comments »