This week two more U.S. breach notice laws go into effect…
Posts Tagged ‘IT compliance’
South Carolina & Alaska Privacy Breach Notice Laws Go Into Effect July 1
Monday, June 29th, 2009Voice Recognition Software Puts Top Cop In Hot Water
Thursday, June 25th, 2009Yesterday I read a fascinating story from Australia…
Movies and TV Shows to Use for Infosec and Privacy Training and Awareness
Tuesday, June 23rd, 2009After many long hours, I’ve finally submitted the draft manuscript for the 2nd edition of my “Managing an Information Security and Privacy Awareness and Training Program” book. However, I will still have one more chance to make changes. One of the 23 appendices within my book provides lists of resources; books, web sites, activities, games and so on. One of my lists is for movies and television shows that can be used in training or for awareness activities…
Don’t Manage Employee Online Activities By Requiring Their IDs & Passwords!
Thursday, June 18th, 2009I read a story about a city government agency actually asking job applicants to provide their IDs and passwords for any online social networking type of site they participate in…
5 Common, Dumb and Dangerous Privacy Assumptions
Wednesday, June 17th, 2009Today Kevin Beaver posted a nice article, “Dumb things IT consultants do” that included more than one warning about making assumptions. Kevin’s nice post made me think about all the dangerous assumptions consulants and practitioners often make when it comes to evaluating privacy practices…
FTC Issued Consent Order for GLBA Privacy Rule and Safeguards Rule Violations
Tuesday, June 16th, 2009Today the FTC issued a consent order against mortgage lender James B. Nutter & Company for GLBA Privacy Rule and Safeguards Rule violations resulting from having an inadequte information security program and safeguards. The requirements will result in, among other actions, 20 years of ongoing activities by James B. Nutter & Company; much more costly than it would have been to have established appropriate information security safeguards to begin with…
Info Sec & Privacy Days/Weeks/Months
Monday, June 15th, 2009As I’ve mentioned a few times before, I’m in the final lap of finishing the 2nd edition of my book, “Managing an Information Security and Privacy Awareness and Training Program.” Woo hoo!
Over the weekend I updated “Appendix N – Designated Security and Privacy-Related Days.” Here are the days, weeks and months I’ve found are devoted to raising awareness about various info sec and privacy issues (this is in a much nicer-looking table format in my book)…
FTC’s New Red Flags Rules FAQ
Thursday, June 11th, 2009Today the US FTC released “Frequently Asked Questions: Identity Theft Red Flags and Address Discrepancies.”
Here are a couple important things to take away from this FAQ…
Healthcare Worker Gets 1 Year In Prison For Posting HIV Victim’s Medical Records On Internet
Wednesday, June 10th, 2009Today a report discussed how a healthcare worker obtained medical information about a patient with HIV that was then posted on the Internet…
Privacy Enhancing Technologies (PETs) & Privacy Threatening Technologies
Tuesday, June 9th, 2009I’m doing research while working on the 2nd edition of my book, “Managing an Information Security and Privacy Awareness and Training Program“…