Welcome Guest. | Log In | Register | Membership Benefits

Manage Risk As A Strategy, Comply With Regulations As A Tactic


Posted by Glenn S. Phillips @ 02:42 PM ET | May 17, 2012

Compliance alone should never be the only goal

Continue reading "Manage Risk As A Strategy, Comply With Regulations As A Tactic"


Topics:   Security Views : Compliance Tech Center



Screw Compliance, We're Trying to Survive


Posted by Glenn S. Phillips @ 09:13 AM ET | May 08, 2012

In tough times, compliance efforts may seem optional

Continue reading "Screw Compliance, We're Trying to Survive"


Topics:   Security Views : Compliance Tech Center



What Works For One Does Not Work For Two


Posted by Glenn S. Phillips @ 08:29 AM ET | May 02, 2012

To remain compliant, your approach must grow in scale with your business

Continue reading "What Works For One Does Not Work For Two"


Topics:   Security Views : Compliance Tech Center



You Need Help, Not An Accomplice


Posted by Glenn S. Phillips @ 09:35 AM ET | Apr 20, 2012

Compliance is about being better and not just proving you are right

Continue reading "You Need Help, Not An Accomplice"


Topics:   Security Views : Compliance Tech Center



Your Compliance Is Decaying Every Day


Posted by Glenn S. Phillips @ 11:26 AM ET | Apr 16, 2012

As soon as you train your colleagues about compliance, noncompliance is back in charge

Continue reading "Your Compliance Is Decaying Every Day"


Topics:   Security Views : Compliance Tech Center



Be Ready To Clean Up That Mess


Posted by Glenn S. Phillips @ 11:14 AM ET | Apr 11, 2012

Compliant systems do more than prevent problems -- they help solve problems that happen

Continue reading "Be Ready To Clean Up That Mess"


Topics:   Security Views : Compliance Tech Center



Someone Left The Keys In Your Compliance System


Posted by Glenn S. Phillips @ 11:37 AM ET | Mar 29, 2012

Information security is at the mercy of your entire staff's habits

Continue reading "Someone Left The Keys In Your Compliance System"


Topics:   Security Views : Compliance Tech Center



Technology Cannot Solve All Your People Problems


Posted by Glenn S. Phillips @ 03:58 PM ET | Mar 22, 2012

Too many in business assume compliance is primarily a technology issue

Continue reading "Technology Cannot Solve All Your People Problems"


Topics:   Security Views : Compliance Tech Center



Nobody Cares About HIPAA


Posted by Glenn S. Phillips @ 03:27 PM ET | Mar 15, 2012

Compliance in many organizations is seen as only a costly inconvenience

Continue reading "Nobody Cares About HIPAA"


Topics:   Security Views : Compliance Tech Center



Six Things Management Needs To Better Understand About Compliance


Posted by Glenn S. Phillips @ 02:24 PM ET | Mar 08, 2012

It may be boring or scary to management, but compliance is ultimately their burden to bear

Continue reading "Six Things Management Needs To Better Understand About Compliance"


Topics:   Security Views : Compliance Tech Center



It's True: Compliance Can Be Good For Your Business


Posted by Glenn S. Phillips @ 08:32 AM ET | Mar 01, 2012

The best insurance for your organization is often the processes required for compliance

Continue reading "It's True: Compliance Can Be Good For Your Business"


Topics:   Security Views : Compliance Tech Center



Five Dangerous Compliance Assumptions


Posted by Glenn S. Phillips @ 11:12 AM ET | Feb 23, 2012

Many businesses fool themselves about their compliance problems

Continue reading "Five Dangerous Compliance Assumptions"


Topics:   Security Views : Compliance Tech Center



Being A Security Bully Does Not Make You Compliant


Posted by Glenn S. Phillips @ 03:20 PM ET | Feb 15, 2012

Compliance is not a tool for dodging work or dismissing business needs

Continue reading "Being A Security Bully Does Not Make You Compliant"


Topics:   Security Views : Compliance Tech Center



Compliance And 'The Little Guys'


Posted by Glenn S. Phillips @ 09:14 AM ET | Feb 07, 2012

Small and midsize businesses often let the cost of compliance obscure important benefits

Continue reading "Compliance And 'The Little Guys'"


Topics:   Security Views : Compliance Tech Center



The Mechanics Of Breach Notification


Posted by Richard E. Mackey, Jr. @ 06:02 PM ET | Jan 27, 2012

Organizations need to know what constitutes a breach of identity data according to state laws and how to respond

Continue reading "The Mechanics Of Breach Notification "


Topics:   Security Views : Compliance Tech Center



Breach Notification: Know The Rules


Posted by Richard E. Mackey, Jr. @ 06:23 PM ET | Jan 20, 2012

State and Federal laws require notification when a breach of protected information occurs. You need to know which laws apply and how to comply

Continue reading "Breach Notification: Know The Rules"


Topics:   Security Views : Compliance Tech Center



Partner Management 3: How To Assess Prospective Partners


Posted by Richard E. Mackey, Jr. @ 10:06 AM ET | Jan 07, 2012

Regulations require organizations to periodically assess security and compliance practices; the key is to understand how to do so effectively -- without breaking the bank

Continue reading "Partner Management 3: How To Assess Prospective Partners"


Topics:   Security Views : Compliance Tech Center



Partner Management: Assessing Compliance Capability And Willingness


Posted by Richard E. Mackey, Jr. @ 09:33 AM ET | Dec 09, 2011

Partner management is a key element to any compliance program. Assessing a partner’s ability to meet your compliance requirements is critical to managing these relationships. The first step is to determine the partner’s understanding of its responsibility and ensuring that it is capable of meeting it.

Continue reading "Partner Management: Assessing Compliance Capability And Willingness"


Topics:   Security Views : Compliance Tech Center



Partner Management: Compliance Program Is Essential


Posted by Richard E. Mackey, Jr. @ 12:02 PM ET | Nov 26, 2011

Understanding the risk associated with a partner relationship and managing it accordingly is key

Continue reading "Partner Management: Compliance Program Is Essential"


Topics:   Security Views : Compliance Tech Center



FFIEC Goes Beyond Traditional Authentication


Posted by Richard E. Mackey, Jr. @ 07:02 PM ET | Oct 18, 2011

The FFIEC recommends that organizations provide additional business and fraud detection controls to offset weaknesses in authentication technology.

Continue reading "FFIEC Goes Beyond Traditional Authentication "


Topics:   Security Views : Compliance Tech Center



New FFIEC Authentication Guidance Calls For Layers


Posted by Richard E. Mackey, Jr. @ 10:00 AM ET | Sep 24, 2011

The FFIEC has issued guidance on authentication in financial transactions. The guidance recommends risk based selection of authentication mechanisms and layered security. It also warns organizations about increased threats and weaknesses in certain accepted authentication mechanisms.

Continue reading "New FFIEC Authentication Guidance Calls For Layers"


Topics:   Security Views : Compliance Tech Center



The Criticality Of Risk Assessments: FISMA, HIPAA, And Other Regs


Posted by Richard E. Mackey, Jr. @ 09:19 AM ET | Sep 04, 2011

Risk assessments are are critical part of regulatory compliance, but many organizations don’t implement them well. Risk assessments, as part of a risk management program, help ensure that the right controls are in place to secure data and comply with regulations.

Continue reading "The Criticality Of Risk Assessments: FISMA, HIPAA, And Other Regs"


Topics:   Security Views : Compliance Tech Center



PCI QSA Status Revocation A Shot Across The Bow For QSAs?


Posted by Richard E. Mackey, Jr. @ 09:47 AM ET | Aug 24, 2011

The PCI Security Council’s revocation of a QSA’s status spells trouble for unscrupulous QSAs and shows that the Council means business in enforcing its quality standards.

Continue reading "PCI QSA Status Revocation A Shot Across The Bow For QSAs?"


Topics:   Security Views : Compliance Tech Center



Dark Reading Launches New Tech Center On Security And Compliance


Posted by Tim Wilson @ 12:01 AM ET | Aug 15, 2011

New Dark Reading Compliance Tech Center will cover relationship between security initiatives and compliance initiatives

Continue reading "Dark Reading Launches New Tech Center On Security And Compliance"


Topics:   Dark Dominion : Compliance Tech Center




Go on to the weblog archives...






  1. Cookies, Social Media And FireSheep
  2. SMB Guide To Credit Card Regulations, Part 2: The Low-Hanging Fruit
  3. HP And The Scary Corporate Fifth Column Concept
  4. Taking USB Attacks To The Next Level
  5. NoSQL: Not Much, Anyway
  1. Taking Cybersecurity Lessons To The Bank
  2. Researchers See Real-Time Phishing Jump
  3. 'BlackSheep' Sniffs Out Firesheep WiFi-Hacking
  4. Slideshow: Ten Free Security Monitoring Tools
  5. A Different Spin On Sleuthing Stuxnet
  6. M&A Activity Muddles Database Security
  1. Secure Managed Web Hosting Saves 960.gs from Malicious Hackers
  2. Access Governance as a Business Service: An Integrated Strategy for Automation with ITSM
  3. Business Driven Access Management and Governance: Simplifying the Delivery and Governance of Access Throughout
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
  June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
 
Featured Webcasts
Featured Whitepapers
Featured Reports