Posts Tagged ‘risk management’

Maine Seed Company Website Hacked: Demonstrates SMB Vulnerability & Questions Hacker Safe Seals

Saturday, March 3rd, 2007

This is the time of the year that thoughts turn to gardening as seed catalogs start filling the mailboxes. I enjoy having fresh-grown vegetables from my garden; nothing is better than a deep red, ripe, juicy Big Boy Beefsteak tomato right off the vine. These seed companies are overwhelmingly small to medium-sized businesses (SMBs). Many have gone online in the past few years, bucking the century-long tradition of depending primarily upon postal mail for their sales.

(more…)

RINBOT/DELBOT Virus Running Rampant In the Wild: Exploits Anti-Virus Software Vulnerabilities Allowing Access to Business Networks

Thursday, March 1st, 2007

CNN reported today that Sophos was warning new strains of RINBOT, also known as DELBOT, could be stealthily be infecting business networks worldwide.
What can this new version do?

(more…)

U.S. Federal CIOs More Concerned About Information Security and Privacy Than In the Past

Wednesday, February 28th, 2007

Monday (2/26) the ITAA issued a press release reporting the resuults of a survey of 47 government CIOs.
They found that:

(more…)

Legislation Passed to Strengthen Bush’s Privacy and Civil Liberties Oversight Board

Tuesday, February 27th, 2007

On February 15 the Senate Homeland Security and Governmental Affairs Committee approved legislation with provisions to strengthen President Bush’s Privacy and Civil Liberties Oversight Board. The provisions were part of a bill, the “Improving America’s Security Act of 2007” (S. 4), aimed at implementing unfulfilled recommendations of the 9/11 Commission. Full text of the 227-page S. 4 bill is available online.

(more…)

U.S. Privacy Related Bills Introduced February 15 & 16

Monday, February 26th, 2007

Before the U.S. House adjourned Febuary 16 and the Senate adjourned February 17 for a week-long recess, they submitted some bills with privacy impacts.

(more…)

U.S. Privacy Related Bills Introduced February 15 & 16

Monday, February 26th, 2007

Before the U.S. House adjourned Febuary 16 and the Senate adjourned February 17 for a week-long recess, they submitted some bills with privacy impacts.

(more…)

Exploring Identity Verification Solutions and Identity Theft Prevention

Friday, February 23rd, 2007

Earlier this week the FTC announced in a press release an identity theft prevention workshop they are hosting April 23 – 24.

(more…)

Audit Reveals Poor Computer & Data Disposal Practices At Idaho National Laboratory

Thursday, February 22nd, 2007

Yesterday Government Computer News reported bad computer disposal methods at the Idaho National Laboratory that leaves confidential and restricted data, including nuclear details, vulnerable.

(more…)

Free Access, For a Limited Time, to Great Information Security, Privacy and Compliance Information

Wednesday, February 21st, 2007

For a limited time you can get free access to a ton of great EDPACS papers.

(more…)

Laptop Theft: Financial Company Given $1.9 Million Penalty Following Incident for Inadequate Security Program

Tuesday, February 20th, 2007

For the first time, the United Kingdom financial regulators, the U.K. Financial Services Authority (FSA), gave a financial institution, the Nationwide Building Society, the U.K.’s largest “building society” (a member-owned mortgage lending and banking services institution) a penalty for poor data security, issuing a ¬£980,000 ($1.9 million) fine based on their response to the 2006 theft of a laptop computer containing sensitive customer data according to a February 14 notice from the FSA.

(more…)