Archive for 'Simplified'

Zapped With A Data Security Breach

Zapped With A Data Security Breach

passwordsOn Sunday, January 15 2012, Zappos notified its employees that there was a data breach in their internal network. The breach made headlines and news around the world, which makes sense considering the popularity of the eCommerce company. I believe that CEO, Tony Hsieg, handled the situation beautifully and I look forward to seeing the outcome of the breach.

Zappos has been known in the Continue Reading →

Super Slick SaaS Service Shares Information Security Secrets

Super Slick SaaS Service Shares Information Security Secrets

saas-security-controlsAs a marketing person at an information assurance firm I spend a lot of my time looking at both of these issues. I have recently noticed that “ahead of the curve” organizations are increasingly using their information security posture as a marketing tool. I thought the approach taken by a SaaS company that we were reviewing on behalf of a customer was intriguing.

The page I landed on was ...

Continue Reading →

New PII And PCI Concerns For Retail Stores

New PII And PCI Concerns For Retail Stores

wireless-pii-pciWhen it comes to accepting payments, retail stores, companies are faced with Payment Card Industry (PCI) and Personally Identifiable Information (PII) concerns. CNET recently published an article on Google’s newest product, Wallet. The product allows consumers to use their Android device to send contact-less payments to retailers via Near Field Communication (NFC) technology. In the article, Continue Reading →

ISO 27005 Risk Assessments in Healthcare

ISO 27005 Risk Assessments in Healthcare

healthcare-27005Although important, it is not often you hear about ISO 27005 in Healthcare Information Security articles.   The Health Information Technology for Economic and Clinical Health Act (HITECH) authorized incentive payments through Medicare and Medicaid to clinicians and hospitals when they use EHRs privately and securely to achieve specified improvements in care delivery. The legislation ties payments specifically to the “meaningful use” of Electronic Health Records (EHR) and via ...

Continue Reading →

ISO 27002 Gap Assessment vs BITS Shared Assessment

ISO 27002 Gap Assessment vs BITS Shared Assessment

security assessmentDuring a recent discussion, a customer asked John Verry what the differences are between an ISO 27002 Gap Assessment and a BITS Shared Assessment. As usual, we decided to educate our blog readers with the answer to that question.

ISO 27002 Gap Assessment

An ISO 27002 Gap Assessment provides an assessment of an organization’s implementation of ISO 27002 control recommendations. The gap analysis is a good step ...

Continue Reading →
Page 1 of 6 12345...»