Posts Tagged ‘risk management’
Thursday, September 6th, 2007
I recently did a privacy impact assessment (PIA) for a marketing company and remembered that the U.S. Do Not Call list entries expire after 5 years! Most people do not realize this…did you know this?
(more…)
Tags:awareness and training, Do Not Call, FTC, Information Security, IT compliance, PIA, policies and procedures, privacy, privacy impact assessment, risk management, telemarketer
Posted in Laws & Regulations | 3 Comments »
Wednesday, September 5th, 2007
Hey, this week is Global Security Week!
The theme this year is “Privacy in the 21st Century.” Have you sent any communications about this topic out to your personnel?
(more…)
Tags:awareness and training, Global Security Week, Information Security, IT compliance, policies and procedures, privacy, risk management, state breach notice laws
Posted in Laws & Regulations, Privacy and Compliance | No Comments »
Monday, September 3rd, 2007
Last week I participated in an interesting discussion on the Security Catalyst site about using web bugs within an organization. I pointed Cutaway to a paper I wrote a couple of years ago, “Quit Bugging Me!”
(more…)
Tags:awareness and training, Cutaway, Information Security, IT compliance, policies and procedures, privacy, risk management, Security Catalyst, web bugs
Posted in Information Security, Privacy and Compliance | No Comments »
Saturday, September 1st, 2007
On August 21, 2007, there was a significant court decision made possibly impacting future Sarbanes-Oxley Act decisions in “CENTRAL LABORERS‚Äô PENSION FUND v.INTEGRATED ELECTRICAL SERVICES INC; HERBERT ALLEN; WILLIAM W REYNOLDS; JEFFREY PUGH”
(more…)
Tags:awareness and training, CENTRAL LABORERS’ PENSION FUND, HERBERT ALLEN, Information Security, INTEGRATED ELECTRICAL SERVICES INC, IT compliance, JEFFREY PUGH, policies and procedures, privacy, risk management, Sarbanes Oxley, SOX, WILLIAM REYNOLDS
Posted in Laws & Regulations, Privacy and Compliance | No Comments »
Friday, August 31st, 2007
I’ve talked several times about some of the risks of using the social networking sites, such as here and here.
Here is an example of how others can post information about you on these sites that will continue to haunt you for years to come.
(more…)
Tags:awareness and training, Information Security, IT compliance, MySpace, policies and procedures, privacy, privacy breach, risk management, social networks
Posted in Information Security, Laws & Regulations, Privacy and Compliance | 2 Comments »
Thursday, August 30th, 2007
And another very interesting USA Today article, “Japan will research Net replacement.”
(more…)
Tags:awareness and training, Europe, Information Security, Internet use, IT compliance, Japan, policies and procedures, privacy, risk management, surveillance, U.S.
Posted in government, Information Security | 2 Comments »
Thursday, August 30th, 2007
A very interesting article in USA Today caught my eye, “Beijing police will patrol Web virtually”
(more…)
Tags:awareness and training, China, Information Security, Internet use, IT compliance, policies and procedures, privacy, risk management, surveillance
Posted in government, Privacy and Compliance | 1 Comment »
Wednesday, August 29th, 2007
I like to run. I try to run almost every day from 3.5 – 6 miles. It stimulates my thinking, refreshes my mind and body, and I truly have the best ideas and thoughts while I’m running. I could not have written my books, chapters and articles if it were not for running.
(more…)
Tags:awareness and training, Information Security, IT compliance, policies and procedures, privacy, risk management, running
Posted in Information Security, Privacy and Compliance, Training & awareness | No Comments »
Tuesday, August 28th, 2007
Well, if you look at the results of my very unscientific poll from last week, it appears there is a very wide range of opinions about the use of social networking sites at work.
(more…)
Tags:awareness and training, facebook, Information Security, IT compliance, MySpace, personally identifiable information, PII, policies and procedures, privacy, risk management, social networking, YouTube
Posted in Information Security, Privacy and Compliance | 2 Comments »
Monday, August 27th, 2007
Tags:awareness and training, Information Security, IT compliance, personally identifiable information, PII, policies and procedures, privacy, risk management
Posted in government, Privacy and Compliance | 2 Comments »