Posts Tagged ‘SMB’
Friday, September 18th, 2015
I’ve been working with hundreds of businesses over the past fifteen years, and I’ve found many common challenges that they are always trying to address, as well as some common, dangerously incorrect, beliefs about security and privacy. There are some common misconceptions that are unique to one-person to small businesses.
Here are four common recurring incorrect information security and privacy beliefs of small businesses, and the facts that these businesses need to know: (more…)
Tags:Dell, Information Security, IT compliance, policies and procedures, power more, powermore, privacy, privacy professor, privacyprof, risk management, security awareness, security training Rebecca Herold, small business, SMB
Posted in Information Security, privacy, Privacy and Compliance | No Comments »
Friday, March 2nd, 2012
I am looking forward to the day when we can look at the news headlines and not see some report about a lost or stolen computing device or storage device that contained unencrypted personal information and/or other sensitive information. And, I also want to stop seeing stories reappear about such an incident, such as the stolen NASA laptop with the clear text Space Station control codes that was stolen last year, but is making the headlines yet again today. NASA is a large enough, and tech savvy enough, organization to know better! However, there are many organizations that simply don’t understand what a valuable information security tool encryption is. I work with many small to medium sized businesses (SMBs), all of which have legal obligations (such as through HIPAA and HITECH, along with contractual requirements) to protect sensitive information, such as personal information. Over the past year I’ve heard way too many of them make remarks such as… (more…)
Tags:BA, business associate, CE, covered entity, encrypt, encryption, HIPAA, HITECH, IBM, medium business, midmarket, PHI, privacy, privacy professor, privacy rule, privacyprof, protected health information, Rebecca Herold, safeguards, security, security rule, small business, SMB, W-2, W2
Posted in Information Security | 1 Comment »
Wednesday, December 12th, 2007
I have learned a lot about domain name maintenance and management issues over the past week! As a follow-up to my blog post yesterday, I have since discovered that as a result of a divestiture *two* registrars claim control of my domain (that I created and have owned and used since 2002); one in Australia has primary control, and the one I have always communicated with in Washington state has secondary control…I never knew this before.
(more…)
Tags:awareness and training, customer service, domain name, ICANN, Information Security, IT compliance, policies and procedures, registration redemption, risk management, SMB
Posted in Miscellaneous | No Comments »
Thursday, August 16th, 2007
Yesterday I was at the Iowa State Fair literally all day; from 8am to around 8:30pm. Despite the 95 degree extremely humid weather it was such a fun day! The cloudy skies and nice breezes helped a lot. We didn’t get to probably half of the exhibits and activities. And I was *VERY* disappointed I didn’t see any of the at least 4 presidential hopefuls who were on the grounds; the place is so big I guess we were always in the wrong place at the right time.
(more…)
Tags:awareness and training, Information Security, Iowa State Fair, IT compliance, PCI DSS, personally identifiable information, PII, policies and procedures, privacy, risk management, SMB, Visa
Posted in Information Security, Privacy and Compliance, Training & awareness | No Comments »
Tuesday, February 6th, 2007
Tags:awareness and training, BSA, Information Security, intellectual property, IT compliance, policies and procedures, SMB, software licensing
Posted in Information Security, Laws & Regulations, Training & awareness | No Comments »
Tuesday, February 6th, 2007
Tags:awareness and training, BSA, Information Security, intellectual property, IT compliance, policies and procedures, SMB, software licensing
Posted in Information Security, Laws & Regulations, Training & awareness | No Comments »
Friday, February 2nd, 2007
I ran across this on the FTC site, an email to send to folks that links to an animation to help make them aware of phishing messages; isn’t this cool!? The FTC sight provides this as an awareness raising communication. It’s a little long, and hopefully the folks going to this link will have their sound turned off so it doesn’t shock their desk neighbors, but all in all it is a great, FREE (paid for by U.S. tax dollars), awareness communication to warn about the threats involved with phishing messages.
(more…)
Tags:awareness and training, FTC, Information Security, IT compliance, phishing, policies and procedures, privacy, SMB
Posted in government, Information Security, Training & awareness | No Comments »