Data Risk Governance

Exploring the intersection between information security, privacy, technology and the law.

Archive for June, 2009

ISM3 – Information Security Management Maturity Model

Posted by Matt on June 24, 2009

http://www.ism3.com/

Posted in Information Privacy, Information Security | Leave a Comment »

Mortgage Lender slapped with GLBA sanctions (FTC Consent Order)

Posted by Matt on June 17, 2009

http://www.realtime-itcompliance.com/noncompliance_sanctions_exampl/2009/06/ftc_issued_consent_order_for_g.htm

Posted in Federal Statutes, Information Privacy, Information Security | Leave a Comment »

Peter Bernstein, author of “Against the Gods” dies at 90.

Posted by Matt on June 12, 2009

http://newschoolsecurity.com/2009/06/a-farewell-to-bernstein/

If you have ever thought about reading Peter’s book “Against the Gods” or even purchased it and never made it past the first few pages, it is worth the read. In fact, it should be required reading for risk managers of all types.

Posted in Risk Assessment, Risk Management & Compliance | Leave a Comment »

Legal Cloud?

Posted by Matt on June 11, 2009

A company called Legal Cloud has developed a cloud service offering tailored for the legal industry vertical.  Is it hype piled on hype?

http://cloudsecurity.org/2009/05/08/legal-cloud-have-it-your-way/

www.legalcloud.com

Posted in Information Privacy, Information Security | Leave a Comment »

Analysis of the FFIEC Multi-Factor Authentication Guidance

Posted by Matt on June 10, 2009

An analysis of the FFIEC Multi-Factor Authentication Guidance can be found here.

Posted in Information Security, Regulation, Risk Assessment, Risk Management & Compliance | Leave a Comment »

A Sample Risk Assessment Model for Information Security

Posted by Matt on June 10, 2009

I’ve added a sample risk assessment that was conducted to help inform a decision on whether or not to encrypt internal network traffic. While the risk assessment is specific to one company in the financial sector, the underlying risk model is broadly applicable and can be modified to suit a variety of needs.  The can also be found under the Risk Management category.

Posted in Risk Assessment, Risk Management & Compliance, Risk Models | Leave a Comment »

Cloud Computing Is Not New

Posted by Matt on June 4, 2009

Bruce Schneier accurately sums up the Cloud Computing hype cycle.

http://www.schneier.com/blog/archives/2009/06/cloud_computing.html

Posted in Uncategorized | Leave a Comment »

 
Follow

Get every new post delivered to your Inbox.