Since becoming Vermont's first CISO three years ago, Kris Rowley's been on a quest to create an IT security culture in state government. Rowley's latest initiative, bringing risk assessment in-house, is helping build that culture.
An important component of preparing for a potential HIPAA compliance audit is to complete a "walk through" to make sure privacy and security policies and procedures are practical and effective, former HIPAA enforcer Adam Greene advises.
Four banks were closed by state and federal banking regulators on Friday, July 15. These latest failures bring the tally to 70 failed institutions so far in 2011.
The new FFIEC online authentication guidance update is a good "cookbook" for financial institutions to apply layered security, says Avivah Litan of Gartner.
The Department of Health and Human Services has published a proposed rule that describes privacy, security and many other standards for web-based state insurance exchanges called for under the healthcare reform law.
Now that the FFIEC Authentication Guidance update has been issued, there is no more important task for banking institutions than to conduct their risk assessments, says Matthew Speare of M&T Bank Corp.
Doug Johnson of the American Bankers Association says banking institutions should spend the next five months focusing on their risk assessments, as they work to meet the FFIEC's new authentication guidance update.
The threat of a HIPAA compliance audit could prove to be a powerful incentive for healthcare organizations to take adequate precautions to safeguard patient information.
Disciplining IT and IT security managers following a breach of their systems rarely happens, and perhaps there's a good reason they shouldn't be punished.
Federal regulators won't speculate about how many more financial institutions could be shuttered in 2011, but the number isn't expected to exceed 2010, the most recent "peak" year for failures.
The Obama Administration's cybersecurity proposal for breach notification will require collaboration among differing financial-services providers, within and across borders, says Leigh Williams of BITS.
More organizations that run health information exchanges are offering patients the opportunity to provide more specific levels of consent for the exchange of their records, a new survey by the advocacy group eHealth Initiative shows.
In one of the largest health information breaches reported so far this year, Spartanburg Regional Healthcare System in South Carolina has notified 400,000 of an incident involving the theft of a desktop computer from an employee's car.
Nearly three months after revelation of a year-long information security breach that exposed personal information of some 3.5 million people at the Texas state comptroller's office, the comptroller has named a new chief information security officer and chief privacy officer.
Our website uses cookies. Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing inforisktoday.asia, you agree to our use of cookies.