There are at least two Facebook "change-your-password" scams circulating in
spam. Here's the first one. It tries to lure you to a malicious site to steal
your Facebook login information.
sandy ingram's Library tagged → View Popular
Twitter security risks, popularity spark regulatory concerns
"Is using Twitter always right for the enterprise, or is it a risk to a business?"
-
"Is using Twitter always right for the enterprise, or is it a risk to a
business?" -
"If a corporate employee puts out information in a tweet that's IP or private,
anyone in the world can see it.
FTC Announces Expanded Business Education Campaign on 'Red Flags' Rule
The three-month extension, coupled with this new guidance, should enable
businesses to gain a better understanding of the Rule and any obligations that
they may have under it. These steps are consistent with the House Appropriations
Committee’s recent request that the Commission defer enforcement in conjunction
with additional efforts to minimize the burdens of the Rule on health care
providers and small businesses with a low risk of identity theft problems.
Today’s announcement that the Commission will delay enforcement of the Rule
until November 1, 2009, does not affect other federal agencies’ enforcement of
the original November 1, 2008, compliance deadline for institutions subject to
their oversight.
-
The Red Flags Rule is an anti-fraud regulation, requiring “creditors” and
“financial institutions” with covered accounts to implement programs to
identify, detect, and respond to the warning signs, or “red flags,” that could
indicate identity theft. The financial regulatory agencies, including the FTC,
developed the Rule, which was mandated by the Fair and Accurate Credit
Transactions Act of 2003 (FACTA). -
The FTC’s Red Flags Web site, www.ftc.gov/redflagsrule, offers resources to help
entities determine if they are covered and, if they are, how to comply with the
Rule. It includes an online compliance template that enables companies to design
their own Identity Theft Prevention Program through an easy-to-do form, as well
as articles directed to specific businesses and industries, guidance manuals,
and Frequently Asked Questions to help companies navigate the Rule.
Consumer Form Letters and Opt Out Information | Privacy Rights Clearinghouse
Note: The information, advice, and suggestions contained in these letters should be used as an information source and not as legal advice. Send your letter by Certified Mail-Return Receipt Requested. If possible, fax the letter first. Make a copy of your letter for your records before sending.
Cyber Security Audit Spanks Department of Interior | Government Tech | ITBusinessEdge.com
The report sharply criticizes the agency's cyber security performance, calling its personnel "substantially under-qualified." Interior required that staff only get self-certified training; only 13.5 percent of self certifications were relevant and complete.
-
The report sharply criticizes the agency's cyber security performance, calling
its personnel "substantially under-qualified." Interior required that staff only
get self-certified training; only 13.5 percent of self certifications were
relevant and complete. -
The report goes on to say that IT and cyber security governance at the
department is inefficient, wasteful and lacks accountability
Building a Culture of Data Security and Related Privacy Interests in the Workplace
"While employees necessarily forfeit a good deal of privacy when
using company-owned equipment and facilities for their personal interests and
benefits, employers today must be concerned about maintaining privacy and
confidentiality for customers and employees alike with respect to those
individuals’ legally protected personal information such as social security and
driver’s license numbers."
-
In preparing for this Insight, I read an enlightening article
published by the Society for Human Resource Management (SHRM) in its August 2008
issue of HR Magazine titled, "Out of the Breach: Reduce the Risk of Litigation
and Build Confidence in Data Handling by Becoming a Privacy Champion." In this
cover story, senior writer Rita Zeidner presents a case for building a "culture
of privacy" in the workplace. According to Zeidner, privacy experts recommend
training, along with taking other precautionary steps, as the best defense for
avoiding breaches of privacy. -
it is the required thing to do in order to comply with the numerous federal and
state laws that may be applicable, which both define protected employee/customer
data and identify related restrictions with respect to the access, use, storage
and dissemination of the same. If you want to build a culture of privacy in your
workplace with respect to the protection of personal data, the following summary
of Zeidner’s steps might serve as a useful reference: - 2 more annotations...
Google Dashboard Creates Security and Privacy Concerns
"The new Google Dashboard addresses concerns that users have regarding just how
much Google knows about them. Providing a resource like the Google Dashboard
that presents all associated information in one place may actually create more
privacy and security issues than it solves though."
-
Providing a resource like the Google Dashboard that presents all associated
information in one place may actually create more privacy and security issues
than it solves though. -
If you know the right queries to use you can find usernames and passwords,
financial spreadsheets, confidential documents, and more by leveraging the vast
database of indexed information stored at Google. - 3 more annotations...
Study Finds U.S. Small Businesses Lack Cybersecurity Awareness and Policies | Reuters
"Small business owners' cybersecurity policies and actions are not adequate enough to ensure the safety of their employees, intellectual property and customer data, according to the 2009 National Small Business Cybersecurity Study. The study, co-sponsored by the National Cyber Security Alliance (NCSA) and Symantec [Nasdaq: SYMC], as part of this year's National Cyber Security Awareness Month, surveyed nearly 1,500 small business owners across the United States
about their cybersecurity awareness policies and practices."
-
The
study found that while more than 9 in 10 small businesses said they believe
they are safe from malware and viruses based on the security practices they
have in place, only 53 percent of firms check their computers on a weekly
basis to ensure that anti-virus, anti-spyware, firewalls and operating systems
are up-to-date and 11 percent never check them. -
Small business owners'
cybersecurity policies and actions are not adequate enough to ensure the
safety of their employees, intellectual property and customer data, according
to the 2009 National Small Business Cybersecurity Study. The study,
co-sponsored by the National Cyber Security Alliance (NCSA) and Symantec
[Nasdaq: SYMC], as part of this year's National Cyber Security Awareness
Month, surveyed nearly 1,500 small business owners across the United States
about their cybersecurity awareness policies and practices. - 8 more annotations...
Sunbelt Blog: Facebook “change-your-password” spam scam[s] are circulating
"Facebook “change-your-password” spam scam[s] are
circulating
There are at least two Facebook "change-your-password" scams circulating in
spam. Here's the first one. It tries to lure you to a malicious site to steal
your Facebook login information."
-
Facebook “change-your-password” spam scam[s] are
circulating
No anti-virus software or procedures = compliance i$$ue
"Commonwealth Equity Services LLP of Waltham, Mass., agreed to pay the penalty
for failing to have anti-malware software on its reps computers or written
security policies to deal with security breaches. Securities brokers and
registered investment advisors are required by SEC regulations to have written
procedures to protect customer information."
Identity Theft: How to Respond to the New National Crisis
"Your identity - it's the gold standard of the Internet, and fraudsters are out to capture it. Smart card technology provides one potential solution to the identity theft crisis. Watch this video to hear Neville Pattinson, VP of Government Affairs at Gemalto, discuss: \n\nThe advantages of smart card technology; \n\nHow to apply these solutions specifically in e-government and healthcare \nreform; \n\nHow to take back control of your identity in the real and virtual worlds."
AMA - Red Flags Rule - SAMPLE POLICY
"Red Flags Rule
Protect your Patients, Protect Your Practice: What You Need to Know
about the Red Flags Rule
Compliance Date: Nov. 1, 2009
Update: The Federal Trade Commission (FTC) has delayed the compliance
deadline of the Red Flags Rule until Nov. 1, 2009
(read the full press
release)
.
The AMA will utilize this time to convince the FTC and
Congress to republish the rule so that there is sufficient opportunity to
formally comment and state the AMA's objections to physician inclusion in the
program."
electronic verification systems.com
"Welcome to the EVS Blog, our blog dedicated to discussing the latest industry trends, current events, and EVS solution and product information. The EVS Blog is updated each week, so be sure to visit frequently to stay up to date on all
the latest news."
Fighting Fraud with the Red Flags Rule
"The Red Flags Rule requires many businesses and organizations to implement a written Identity Theft Prevention Program designed to detect the warning signs –
or "red flags" – of identity theft in their day-to-day operations. Are you covered by the Red Flags Rule? Read Fighting Fraud
with the Red Flags Rule: A How-To Guide for Business
to:
Find out if the rule applies to your business or organization;
Get practical tips on spotting the red flags of identity theft, taking steps to prevent the crime, and mitigating the damage it inflicts; and
Learn how to put in place your written Identity Theft Prevention Program.
By identifying red flags in advance, you'll be better equipped to spot suspicious patterns when they arise and take steps to prevent a red flag from escalating into a costly episode of identity theft.
Take advantage of other resources on this site to educate your employees and colleagues about complying with the Red Flags Rule."
External attacks start with unintentional mistakes, survey finds
The four walls around a company's data servers are continuing to erode as end users are finding it increasingly easier to use Web-based tools and bring their work home and on the road. The latest survey finds that companies are more concerned than ever about unintentional employee errors that can lead to data leakage.
-
"Companies are finding more than ever before that they really need to have good access policies and the right level of controls associated with those policies," said Chris Young, senior vice president of products at RSA. "Organizations often try to start out with a model of trust between permanent and temporary employees, but they also have to balance that trust with controls."
Security & Privacy Lawyer & Attorney : Foley Hoag Law Firm : About : Security, Privacy and The Law
About
The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.
SANS Institute - 20 Critical Security Controls - Version 2.1
Version 2.1: August 10, 2009
Update: Added NIST SP 800-53 Revision 3 mapping to each control, and updated appendix to include each area of direct mapping between 20 Critical Controls and 800-53 Rev 3 Priority 1 controls.
-
Version 2.1: August 10, 2009
Update: Added NIST SP 800-53 Revision 3 mapping to each control, and updated appendix to include each area of direct mapping between 20 Critical Controls and 800-53 Rev 3 Priority 1 controls.
-
knowledge of actual attacks that have compromised systems provides the essential foundation on which to construct effective defenses.
- 9 more annotations...
Bill Gives DHS Lead on Fed IT Security Policy
The responsibility to oversee information security among federal agencies would shift to DHS from the White House Office of Management and Budget under revisions of the measure, nicknamed U.S. ICE, that updates IT security guidance detailed in the seven-year-old Federal Information Security Management Act (FISMA), according to a senior cybersecurity staff member on the Senate Committee of Homeland Security and Government Affairs.
-
The thinking behind shifting responsibility to DHS from OMB is that Homeland Security has the cybersecurity expertise whereas OMB's proficiency is budgeting. "Already, the Department of Homeland Security is the coordinating agency on cybersecurity," the staffer said. "Now, what you're doing is drastically strengthening the role of DHS by putting into law and then also, giving them the ability to say, with FISMA, approve or not to approve agencies plans, controls, frameworks, the way they secure their systems."
-
The bill also continues the role of the National Institute of Standards and Technology as the key government agency to develop IT security guidance, but leaves it to DHS the decision which guidance has priority.
Cloud Computing Poses E-Discovery, Legal Risks - www.enterprisestorageforum.com
In a presentation titled "Computing (strike that — Litigation) in the Cloud," Steven Teppler, senior counsel at KamberEdelson in New York, said cloud computing and services are a corporate counsel's nightmare.
Information Assurance Client and Partner Support - NSA/CSS
The IA Mission at NSA supports clients and works with partners across government and industry to provide guidance, to ensure the availability of information assurance solutions, and to broaden IA knowledge and skills.
The web sites linked below are provided for the purpose of client and partner collaboration with the IA Mission.
Selected Tags
Related Tags
Top Contributors
Groups interested in privacy
-
Internet Privacy Guide
This is part of my research...
Items: 57 | Visits: 64
Created by: Martin Virtual
-
Information Literacy
guides for safe and product...
Items: 71 | Visits: 76
Created by: Paul Beaufait
Diigo is about better ways to research, share and collaborate on information. Learn more »
Join Diigo
