Compliance alone should never be the only goal
Continue reading "Manage Risk As A Strategy, Comply With Regulations As A Tactic"
In tough times, compliance efforts may seem optional
Continue reading "Screw Compliance, We're Trying to Survive"
To remain compliant, your approach must grow in scale with your business
Continue reading "What Works For One Does Not Work For Two"
Compliance is about being better and not just proving you are right
Continue reading "You Need Help, Not An Accomplice"
As soon as you train your colleagues about compliance, noncompliance is back in charge
Continue reading "Your Compliance Is Decaying Every Day"
Compliant systems do more than prevent problems -- they help solve problems that happen
Continue reading "Be Ready To Clean Up That Mess"
Information security is at the mercy of your entire staff's habits
Continue reading "Someone Left The Keys In Your Compliance System"
Too many in business assume compliance is primarily a technology issue
Continue reading "Technology Cannot Solve All Your People Problems"
Compliance in many organizations is seen as only a costly inconvenience
Continue reading "Nobody Cares About HIPAA"
It may be boring or scary to management, but compliance is ultimately their burden to bear
Continue reading "Six Things Management Needs To Better Understand About Compliance"
The best insurance for your organization is often the processes required for compliance
Continue reading "It's True: Compliance Can Be Good For Your Business"
Many businesses fool themselves about their compliance problems
Continue reading "Five Dangerous Compliance Assumptions"
Compliance is not a tool for dodging work or dismissing business needs
Continue reading "Being A Security Bully Does Not Make You Compliant"
Small and midsize businesses often let the cost of compliance obscure important benefits
Continue reading "Compliance And 'The Little Guys'"
Organizations need to know what constitutes a breach of identity data according to state laws and how to respond
Continue reading "The Mechanics Of Breach Notification "
State and Federal laws require notification when a breach of protected information occurs. You need to know which laws apply and how to comply
Continue reading "Breach Notification: Know The Rules"
Regulations require organizations to periodically assess security and compliance practices; the key is to understand how to do so effectively -- without breaking the bank
Continue reading "Partner Management 3: How To Assess Prospective Partners"
Partner management is a key element to any compliance program. Assessing a partner’s ability to meet your compliance requirements is critical to managing these relationships. The first step is to determine the partner’s understanding of its responsibility and ensuring that it is capable of meeting it.
Continue reading "Partner Management: Assessing Compliance Capability And Willingness"
Understanding the risk associated with a partner relationship and managing it accordingly is key
Continue reading "Partner Management: Compliance Program Is Essential"
The FFIEC recommends that organizations provide additional business and fraud detection controls to offset weaknesses in authentication technology.
Continue reading "FFIEC Goes Beyond Traditional Authentication "
The FFIEC has issued guidance on authentication in financial transactions. The guidance recommends risk based selection of authentication mechanisms and layered security. It also warns organizations about increased threats and weaknesses in certain accepted authentication mechanisms.
Continue reading "New FFIEC Authentication Guidance Calls For Layers"
Risk assessments are are critical part of regulatory compliance, but many organizations don’t implement them well. Risk assessments, as part of a risk management program, help ensure that the right controls are in place to secure data and comply with regulations.
Continue reading "The Criticality Of Risk Assessments: FISMA, HIPAA, And Other Regs"
The PCI Security Council’s revocation of a QSA’s status spells trouble for unscrupulous QSAs and shows that the Council means business in enforcing its quality standards.
Continue reading "PCI QSA Status Revocation A Shot Across The Bow For QSAs?"
New Dark Reading Compliance Tech Center will cover relationship between security initiatives and compliance initiatives
Continue reading "Dark Reading Launches New Tech Center On Security And Compliance"