Are state and federal breach notification mandates unreasonable?

Business Continuity, Compliance, Cybercrime, Government, Identity Theft, Intrusion Detection, Privacy, Risk Management, Security, data theft Comments Off

Organizations unable or unwilling to provide the controls necessary to react immediately to protect customer, employee, or patient information should reconsider keeping it in the first place.


read more from this topic.....


What were they thinking? Security design without the user in mind

Compliance, Government, Policy, Privacy, Security, Security Solutions Comments Off

What responsibility do security vendors and government agencies have to deliver or mandate secure products and services? I found myself asking this question repeatedly last week, as two incidents occurred which prompted a ‘what were they thinking’ response.


read more from this topic.....


Controlling high-risk software: Going after the vendors is not the answer

Compliance, Computer Forensics, Cybercrime, Government, Identity Theft, Intrusion Detection, Malware, Privacy, Risk Management, Security, Security Awareness Training, data theft Comments Off

Well, now that CyberSpy Software doesn’t promote RemoteSpy (a remote keylogger) as super-secret software and doesn’t provide directions on how to use it as such, all is well in the legal realm. What a bunch of nonsense.


read more from this topic.....


Hamachi is good news for SOHOs, but not so good for the enterprise

Compliance, Identity Theft, Privacy, Risk Management, Security Comments Off

In this post, we’ll walk through how Hamachi works, look at some additional free tools you can run over Hamachi connections, and the risk it presents to your business network. We’ll close with a few suggestions for blocking its use.


read more from this topic.....


Free Web content filtering puts safer browsing within reach for everyone

Business Continuity, Compliance, Cybercrime, DNS Security, Phishing, Risk Management, Security, Social engineering, Spyware Comments Off

Earlier this week, I ranted about schools and businesses not using controls to prevent students and employees from viewing unsuitable content on the Web. I thought it appropriate to discuss an easy-to-use solution that fits within everyone’s budget.

read more from this topic.....


Shifting from compliance to security requires patience

Compliance, Risk Management, Security Comments Off

It is not just government managers who require behavior changes when it comes to securing sensitive assets. Managers in private industry often mistakenly see compliance as security. But changing this view takes patient persistence.

read more from this topic.....


Government data losses: Distributed databases are not the answer

Compliance, Cybercrime, Government, Identity Theft, Privacy, Risk Management, Security Comments Off

As elected officials and non-elected government employees struggle with how to arise above bureaucratic, information security ineffectiveness, they continue to plan for and establish large, centralized databases containing our information. Is spreading the data across disparate repositories the answer?

read more from this topic.....


Use application firewalls to secure browser-based solutions

Business Continuity, Compliance, Cybercrime, Firewall, Hacking, Identity Theft, Internet, Intrusion Detection, Privacy, Risk Management, Security, data theft Comments Off

The application firewall is not a replacement for other layers in the controls framework. It supplements them. So what is it and why do you need it? How do you make a business case for another security control?

read more from this topic.....


Video Surveillance: Four ways to protect privacy and achieve business outcomes

Compliance, Computer Forensics, Government, Intrusion Detection, Policy, Privacy, Risk Management, Security, Security Solutions Comments Off

Video surveillance is easy to deploy. An increasing number of employers are exploring implementation of inexpensive video systems to protect employees and the business. Before writing the check, however, there are several regulatory and employee relation safeguards to consider.

read more from this topic.....


FACTA “Red Flags Rule”: Concern for security managers?

Compliance, Government, Identity Theft, Policy, Privacy, Risk Management, Security, data theft Comments Off

Although most of the Red Flag requirements apply to hiring and credit processing practices as well as those related to health facility admissions, PII and ePHI protection are also included. So what does this mean to security managers? It depends

read more from this topic.....

« Previous Entries