• 16Oct

    PCI DSS Compliance Viewed as Less Than Strategic

    In a recent survey conducted by the Ponemon Institute, and supported by the security firm Imperva, it was found that 71% of the firms interviewed don’t view the Payment Card Industry Data Security Standard (PCI DSS) as a strategic initiative for their organization(s).

    The data in this report states at least the following reasons for the lack of strategic importance linked to PCI DSS: (1) its hard work and requires constant monitoring and maintenance, (2) there is the perception that good security does not increase market share — i.e. consumers do not reward companies when nothing bad happens, and (3) most companies reported that they don’t believe the worst will happen to them — and — even if it does, they anticipate being able to handle the cost of the breach and move on.

    Another observations was that 79% of this very same group has experienced a data breach that involved the loss or theft of credit card information.

    The data in this report also hints that to incur the cost of a breach is cheaper than paying for what it takes to protect the systems and data.

    George Hulme wrote about  more details of this report’s findings in an article posted on the InformationWeek’s Security Weblog — which you can read by clicking here.

    You can also access this free report by registering at the following website:

    https://www.imperva.com/ld/ponemon.asp

    Filed under: Information Security, Risk Management, Security and Privacy, credit card industry
    Tags: consumer data protection act, Data Breach, data security, Information Security, PCI Compliance, PCI-DSS, privacy laws, Risk Management
    No Comments
  • 18Sep

    CPA’s Request Exemption from Red Flag Rules

    Lora Bentley, another one of our favorite bloggers, has recently focused her writing skills in an article published by IT BusinessEdge.  In that article she addresses the recent request by The American Institute of Certified Public Accountants to be exempt from the Federal Trade Commission’s Red Flag Rules.

    Read this article to understand more about this important issue.

    Filed under: Information Security, Security and Privacy, cybersecurity
    Tags: American Institute of Ceertified Public Accountants, consumer data protection act, CPA, data record retention, Federal Trade Commission, online privacy, privacy rights, Red Flag Rules, Risk Management
    No Comments
  • 28Aug

    Deceased Person’s Data Still Part of HHS Data Breach Notice Rule

    Lora Bentley, in her recent posting in the ITBusinessEdge blog, wants to remind us that the data breach notification rule promulgated by the U.S. Department of Health and Human Services (HHS) pursuant to the HITECH Act, even applies to individuals the covered entity knows to be deceased.

    Given the fact that each state and territory law has its own position on this rule, and, in fact, where some do not have such a stipulation of notice regarding deceased persons, each organization must pay careful attention to protect themselves from potential privacy breach lawsuits stemming from the HHS rule. 

    Click here to read this article and remember to follow the link within this article to the HHS rule as published in the Federal Register for public comment.

    Filed under: Information Security, Security and Privacy
    Tags: consumer data protection act, Data Breach, HITECH Act, Information Security, privacy laws, U.S. Department of Health and Human Services
    No Comments
« Previous Page

Navigation:

  • Compliance Blog Home
  • About Radian Compliance

Category:

  • Business Continuity
    • BS 25999
  • Compliance Management
    • Risk Management
  • credit card industry
  • cybersecurity
  • E-Discovery
  • Events
  • General
  • Information Security
    • ISO 27001
  • IT Service Management
    • ISO 20000
  • Security and Privacy
  • Supply Chain Management

Archives:

  • 2011
  • 2010
  • 2009
  • 2008
  • 2007
  • 2006

Web Links:

  • Continuity Compliance
  • Illinois I.T. Association
  • Radian Compliance Main

Meta:

  • RSS
  • Comments RSS
  • Valid XHTML
  • XFN
© 2012 Radian Compliance, LLC. All Rights Reserved. Entries RSS Comments RSS Login