Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts

Friday, March 26, 2010

Privacy and Security Bits and Bytes

Some news items for the last Friday in March -

Another state has joined the Payment Card Industry Data Security Standard ("PCI") bandwagon. On March 22, 2010, Washington state became the third state to incorporate the into law. The Washington House and Senate passed HB 1149 and it has been signed into law by the governor. HB 1149 amends Washington’s breach notice law (and borrows some of its definitions). Similar to Minnesota’s Plastic Card Security Act, HB 1149 provides issuing banks a legal mechanism to collect the costs to reissue payment cards after a payment card security breach. The law is effective July 1, 2010

How often do you change your password? A Symantec report discovers that an astounding 10 percent of us don’t change them AT ALL. Most users don't change password often enough, report says Digital Media - CNET News

Condom Web Site Threatens to Sue Person who Outed Their Leakage - An Indian Web site that sold Durex condoms has threatened legal action against the person who exposed a data breach on the site. Earlier this month, a user of the site noticed that he could view customers' names, addresses, contact numbers and order details, The Register reports.

Following up on a Privacy and Security Bits and Bytes from a couple of weeks ago on the potential privacy implications of copy machines, The Toronto Star has a more in-depth piece on the wealth of information stored on the hard drives of high-end copy machines.

Friday, September 25, 2009

Privacy and Security Bits and Bytes

After a bit of a hiatus, our Friday afternoon feature is back:

  • Do you know what your information is worth on the black market? It may just surprise you. Good piece on a new Symantec tool to let you do the calculations. See Information Security Resources - What Are You Worth On The Black Market?
  • Despite all of the public flurry surrounding security breaches, and customer expectations that the information entrusted to vendors will be secure, a new survey finds that an astounding 71 percent of those companies surveyed said they still weren't making data security a top initiative in their IT budgets, even though 79 percent of them admitted that they had been hit by one or more data breaches since the PCI DSS standard was enacted in 2005. Companies Still Not Securing Customer Data - InternetNews.com.
  • Companies around the world are preparing for the swine flu pandemic and putting policies and procedures in place for workers and business continuity. What, if anything, are people doing about the privacy issues that need to be addressed in that planning?
    Good article, with links to resources here - Protecting Your Privacy During a Pandemic
  • Remember our blog posts on the demise of the Clear program? Next week, the Committee on Homeland Security is holding a hearing on "The Future of the Registered Traveler Program"
    Wednesday, September 30, 2009 @ 2pm
    311 Cannon House Office Building
    The hearing will evaluate the recent cessation of operations by Registered Traveler (RT) providers, actions undertaken by the Transportation Security Administration (TSA), and the impact on airports. There will be a webcast of this hearing.

Should be fascinating viewing. I wonder if we'll hear anymore about whatever happened to all that data???