User Blogs

User Blogs

Discussions and Blogs
Tags >> Compliance
Nov 23
2011

Decision is Key!

Posted by Didier Godart in Risk Management , Compliance

Didier Godart

In my previous blog "Something Rotten in my Kingdom" I asked the question: Can we envisage a way to improve security through compliance? 

Nov 09
2011

Something is rotten in my kingdom

Posted by Didier Godart in Information Security , Compliance

Didier Godart

Ten years ago, self-regulation through the implementation of good security practices was thought to be the way organizations would protect their, and our, sensitive data but the number of reported security incidents demonstrates that self-regulation doesn't actually work. It's like hoping that a kid does his home work only because he fully understands all the benefit for himself. Actually, this kind of self-governing behaviour requires some level of maturity and a deep self-consciousness of the risks faced.

Oct 03
2011

My thoughts on the 2011 Verizon PCI Compliance Report

Posted by Didier Godart in PCI , Information Security , Compliance

Didier Godart

If you ever endeavour getting data about the compliance rate from PCIco or the Payment Brands you would know how challenging it is, probably more challenging than finding the Holy Grail. So in this context the release of the Verizon 2011 Payment Card Industry Compliance Report is quite enlightening for the security industry and merchant community. It gives us a good sense of reality of the field.

Jun 17
2011

67% of Companies Fail Credit Card Security Compliance

Posted by Robert Siciliano in PCI , Compliance

Robert Siciliano

All merchants who accept credit cards are now subject to strict Payment Card Industry standards, rules, and regulations, which require a level of security that took about five years to finally implement.

Apr 19
2011

ISACA Survey: Regulatory Compliance Is Top Concern in 2011

Posted by Cinthia Pilar in Governance , Compliance

Cinthia Pilar

Regulatory compliance will be the top business issue affecting enterprise information technology (IT) in the next 12 to 18 months, according to a major new ISACA member survey of more than 2,400 IT, security, and audit and assurance managers from 126 countries worldwide.

Mar 08
2011

Glad to join the community - Security and Compliance

Posted by Robb Reck in Information Security , Compliance

Robb Reck

I am very excited to have been invited to participate in the community here at itgrcforum.com. My professional passion is finding the sweet spot where security and compliance work as enablers of the business rather than impediements. I look forward to sharing my thoughts on practical ways that security and compliance professionals become that kind of asset to their business. What follows is the revised version of a piece I wrote in 2010 for my own site, but I believe it will nicely introduce you to my take on security, compliance and business.

Mar 03
2011

Compliance breakdowns helped fuel financial crisis

Posted by Cinthia Pilar in Risk Management , Governance , Financial Crisis , Ethics , Compliance

Cinthia Pilar

The congressionally appointed Financial Crisis Inquiry Commission released a 535-page report on Thursday blaming the meltdown in part on compliance breakdowns and deficiencies.

Dec 09
2010

Compliance for outsourcers

Posted by Arno Kapteyn in Outsourcing , Compliance

Arno Kapteyn

This evening I attended a round table session organized by the Dutch chapter of ISACA. Antal, the presenter, did his best to show how compliance can influence the outsourcing relationship. At the end of the presentation Job, the host, concluded that this was a complex subject and that more time could, and should, be spent explaining all possible consequences. Antal, Job: sorry but I disagree with that conclusion.

Dec 09
2010

To GRC or not to GRC, that is the question

Posted by Arno Kapteyn in Governance , Compliance

Arno Kapteyn

Don’t you love the use of abbreviations? Often before you learn what the abbreviation stands for you have to read to the end of the story completely dazed about what it is the writer is trying to say. So let’s not do that: GRC stands for Governance, Risk and Compliance. These three functions are important to all organizations. Wikipedia define GRC as ‘an increasingly recognized term that reflects a new way in which organizations can adopt an integrated approach to these three areas.’

Oct 29
2010

Interview With Lyle Smith, Director of Global SOX Compliance at Walmart Stores Inc.

Posted by Cinthia Pilar in SOX , Compliance

Cinthia Pilar

Interview With Lyle Smith, Director of Global SOX Compliance at Walmart Stores Inc.

Oct 29 2010 - Since the enacting of the Sarbanes-Oxley (SOX) Act 2002, publicly quoted businesses have experienced a tightening of financial reporting regulations. Lyle Smith, Director of Global SOX Compliance, Walmart Stores Inc. gives his insight as to how the SOX provisions are continuing to impact companies across America. Lyle is a speaker at our partner event the 20th Edition SOX Compliance & Evolution to GRC Conference from November 4-5, 2010 at the Doubletree Hotel in Philadelphia, PA.

Subscribe via Email

 Your Email:
Banner

Subscribe via Email

 Your Email:

Tag Cloud

2012 abduction Aberdeen Group alarm alarms Android Apple Apps ATM Skimming Audit Bank Fraud Banking Security BillGuard botnet BPM breaches BS 25999 burglar burglary Business Continuity BYOD Cloud Cloud Security Cobit Compliance computer failure Consumer IT Tips contactless credit card credit card breaches Credit Card Fraud credit cards credit fraud Cross-Device Security Cyber Security cyberbullying cybercrime cybercriminals cybersecurity cyberwise data Data Backup Data Breaches Data Storage DDOS Device Reputation Digital Forensics Digital Security digitally secure Disaster Recovery DNS download DPI driver's license dumps E-Commerce eBanking Electronic Discovery Electronic ESI electronic passport EMV Endpoint Security Epsilon ERM ESI Ethics Events Facebook FCC FCPA FDIC Federal Government FFIEC Financial Crisis Fraud gaming Gartner Geo-tagging gold farming Governance GPS grc Green IT grey charges Hackers Hacktivism HP IAM iCloud ID Theft Identity theft Information Management Information Security Information Supply Insider Threat Internal Audit Internal Controls internet safety IP address ISACA ISO 27000 ISO 27001 ISO 31000 IT Alignment it compliance it governance IT GRC Forum Events it risk management IT Security IT Service Management ITIL jailbreaking Jobs laptop security Litigation Malware marathon Member Discount Mobile Apps Mobile Banking mobile device Mobile Device Management Mobile Devices Mobile payment mobile phone mobile security Mobile Wallet mSecurity Multi-Regulatory Compliance multifactor authentication myblog Network Security New Years NFC Online Backup Online Banking online dating online gaming online identity online privacy online safety Online Security online shopping Operational Management OSHA Outsourcing P2P Security Panel Partner Offers passwords PCI Performance Management personal data personal device Personal Security pheasting phishing Policy predator Privacy Prize Draw QR Codes ransomeware ransomware Regulation E resume fraud Risk Assessment Risk Management RSA Rules safety tips scam scammer scammers Scams Seasonal Security security apps sext skimming Skimming Fraud small business smartphones smishing Social Media social network Social Security SOX spammers spokesman Spyware SSDs Standards strangers Strategy tablets tax scams Tech tech support technology Threat Management Tokenization TQM Twitter typosquatting Virus VPN web Webcast Q&A Wi-Fi WIFI wireless
Banner