In a series of Information Security Forums, DCR is hosting a presentation on Data Security and Integrity to address executive concerns about Risk Management and Risk Governance Tuesday morning at 8:00AM, February 26th at the FST Summit Conference being held at the Ritz Marina del Rey Resort. Kindly visit fstsummit.com for more info.
Other States Are Likely to Follow California's Mandatory Disclosure Requirement. California's law requires any agency, business or person doing business in the state that owns or licenses computerized data containing personal information to disclose any breach of security of the system.
Data protection company Iron Mountain fails to protect data. GE Money loses data on 650,000 JC Penney credit card holders.
Thieves direct their resources to weak links. Sensitive personal data is being systematically stolen from companies, government agencies, colleges and hospitals.
Personal information on almost one-half of the UK population has been lost. British officials have lost computer disks containing intimate details on 25 million of Britain's 60 million citizens. The disks containing highly sensitive information including names, addresses, birth dates, insurance numbers, and banking details were lost in transit between government agencies.
Convio suffers theft of data that it stored for 92 clients of its GetActive system. The FBI is investigating the theft of e-mail addresses and passwords from nearly 100 nonprofit organizations, including The American National Red Cross, Cooperative for Assistance and Relief Everywhere Inc. (CARE), and the American Museum of Natural History in New York, an Austin-based company said today.
Insider threats lead the way, accounting for approximately 60 percent of the breaches. Many companies inadvertently jeopardize highly sensitive information at the application development level.
Suit Filed on Behalf of 8.5 Million Consumers in Federal District Court. The class action complaint against Certegy Check Services and its parent company, Fidelity National Information Services Inc., claims they failed to implement and maintain adequate security measures to protect consumers' confidential financial and personal information.
U.S. Multinational Fined For Cross-Border Data Transfer. For the first time, a U.S. multinational organization has been fined for violations of the E.U.'s Data Protection Directive, following a recent clampdown by European data protection authorities on breaches of the E.U.'s strict data protection regime.
Stolen Laptop Contained Social Security Numbers, Birth Dates, and Salaries. Policies called for computer files to be encrypted, but Neiman Marcus doesn't know whether that was done and is cautiously acting as if the data on the stolen machine wasn't protected.
Specific Chapters and Articles of E.U. Data Privacy Law. Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
A Disclaimer, Notice, and Rules Were Added in 2001. An important disclaimer, a copyright notice, and rules related to personal data protection in the European Union.
Privacy Is Good for Your Business. How IBM executes oversight of policies for gathering, sharing, and using personal information from customers and employees.
Five Ways to Manage Test Data in Regulated Environments. In many companies, developers use live data in unsound, test environments but remain unmindful of the fallout if that data leaks out. Why should your compliance guard be relaxed when developers use test data to design the systems that store and dole out access to such sensitive information?
A Chronology of Data Breaches. Over 100 million data records of U.S. residents have been exposed due to security breaches since February 2005.