Posts Tagged ‘PII’
Tuesday, August 28th, 2007
Well, if you look at the results of my very unscientific poll from last week, it appears there is a very wide range of opinions about the use of social networking sites at work.
(more…)
Tags:awareness and training, facebook, Information Security, IT compliance, MySpace, personally identifiable information, PII, policies and procedures, privacy, risk management, social networking, YouTube
Posted in Information Security, Privacy and Compliance | 2 Comments »
Monday, August 27th, 2007
Tags:awareness and training, Information Security, IT compliance, personally identifiable information, PII, policies and procedures, privacy, risk management
Posted in government, Privacy and Compliance | 2 Comments »
Sunday, August 26th, 2007
I’ve talked several times on this blog about my sons, and how they’ve really resonated with the information security and privacy discussions and information I’ve given them. They notice privacy risks and security problems when we’re out in stores or traveling. They point out problems on the Internet. They won’t let me watch their fingers when they enter their passwords on their membership sites so I won’t discover their passwords…even though they know my parent account has access to change them. 🙂
(more…)
Tags:awareness and training, Howie Day, Information Security, IT compliance, personally identifiable information, PII, policies and procedures, privacy, risk management, social networking sites, social psychology
Posted in Training & awareness | 2 Comments »
Friday, August 24th, 2007
on 8/22/2007 a very interesting and useful report was released by the European Network and Information Security Agency (ENISA), “Information security awareness initiatives: Current practice and the measurement of success.”
(more…)
Tags:awareness and training, data protection law, ENISA, EU Data Protection Directive, European Union, Information Security, IT compliance, personally identifiable information, PII, policies and procedures, PricewaterhouseCoopers, privacy, privacy law, risk management
Posted in Information Security, Privacy and Compliance, Training & awareness | 3 Comments »
Tuesday, August 21st, 2007
Last week my blog poll was, “Is your organization planning to pursue ISO 27001 certification in 2007 or 2008?”
I asked this after reading an SC Magazine article that I recently blogged about, “Are the U.S. Numbers Planning For ISMS (ISO 27001) Certification Really At 80%?”
As I had indicated, based upon my many discussions with a very wide range of CISOs, I thought this number was way too high.
And now for the results of my *ADMITTEDLY UNSCIENTIFIC WEBPOLL*…drum roll, please; Thhuudddrrrrrrrrrrrrr…
(more…)
Tags:awareness and training, Information Security, ISMS, ISO 27001, ISO 27001 certification, ISO27002, IT compliance, OECD, PII, policies and procedures, privacy, risk management
Posted in Information Security | 2 Comments »
Monday, August 20th, 2007
Over the weekend I read yet another news article about social networking sites and the related risks. This time it was about how schools are implementing rules to address cyber bullying on the Internet; “Students To Be Punished For MySpace Postings.”
(more…)
Tags:awareness and training, facebook, Information Security, IT compliance, MySpace, personally identifiable information, PII, policies and procedures, privacy, risk management, social networking
Posted in Information Security, Privacy and Compliance | 2 Comments »
Monday, August 20th, 2007
The new U.S. Social Security number (SSN) No Match Rule was published August 15 in the Federal Register. You can also see it here.
This new regulation provides directives for the letters the U.S. Social Security Administration (SSA) issues to employers when the SSA discovers that an SSN does not match the information provided by the employer.
(more…)
Tags:awareness and training, Department of Homeland Security, DHS, Information Security, IT compliance, no match letter, no match rule, PII, policies and procedures, privacy, risk management, social security administration, social security number, SSA, SSN
Posted in Laws & Regulations, Privacy and Compliance | 1 Comment »
Thursday, August 16th, 2007
Yesterday I was at the Iowa State Fair literally all day; from 8am to around 8:30pm. Despite the 95 degree extremely humid weather it was such a fun day! The cloudy skies and nice breezes helped a lot. We didn’t get to probably half of the exhibits and activities. And I was *VERY* disappointed I didn’t see any of the at least 4 presidential hopefuls who were on the grounds; the place is so big I guess we were always in the wrong place at the right time.
(more…)
Tags:awareness and training, Information Security, Iowa State Fair, IT compliance, PCI DSS, personally identifiable information, PII, policies and procedures, privacy, risk management, SMB, Visa
Posted in Information Security, Privacy and Compliance, Training & awareness | No Comments »
Wednesday, August 15th, 2007
I am a huge proponent of privacy impact assessments (PIAs); basically risk assessments for privacy. PIAs can reveal gaps in privacy practices, along with the information security practices used to protect privacy. They are important and effective exercises for all organizations that handle personally identifiable information (PII).
(more…)
Tags:awareness and training, Department of Homeland Security, DHS, Information Security, IT compliance, personally identifiable information, PIA, PII, policies and procedures, privacy, privacy impact assessment, risk management
Posted in Privacy and Compliance | 1 Comment »
Thursday, August 9th, 2007
Over the past few years I have done well over a hundred business partner security program reviews for organizations who wanted to ensure that the organizations to whom they were entrusting their sensitive data, or other business processing, had appropriate security and privacy policies, practices, training and were generally trustworthy.
(more…)
Tags:awareness and training, business partner security review, Information Security, IT compliance, personally identifiable information, PII, policies and procedures, privacy, risk management
Posted in Information Security, Laws & Regulations, Privacy and Compliance | No Comments »