The Senate Homeland Security Committee, in their infinite wisdom, prodded by SANS' Alan Paller apparently believe they can legislate secure software from IT vendors.That'd be like legislating more secure health records, and personal financial information, and so on. Oh wait, that has been done. And it's not working all that well as far as I can tell.That'd also be like legislating higher-quality cars. Ha! The Feds can work that out ...
Continue Reading......when you're working hard for your money this week. It shines a spotlight on what's happening on our world today and has some interesting security tie-ins as well. Funny how all of this stuff affecting our lives and careers is related."You cannot legislate the poor into freedom by legislating the wealthy out of freedom. What one person receives without working for, another person must work for without receiving. The government ...
Continue Reading...I read the first paragraph in this piece regarding Obama's mandate that we move to electronic medical records (a big step in nationalizing healthcare in this country). It says "The aim is to improve medical care, increase the efficiency of heath care delivery and ultimately cut health care costs." When I co-wrote our book on HIPAA compliance back in 2003, improving medical care, increasing the efficiency of heath care delivery ...
Continue Reading...Is this some insight into where the world is headed with regards to information privacy and security?:UK launches massive, one-year program to archive every emailI'll be curious to see how such control and monitoring affects international business long term in the U.K and across Europe. Some organizations outside Big Brother-ville may not want to take this on. But then again, many in management have their heads buried only thinking short-term ...
Continue Reading...Since our Imperial Federal Government wants more of its "fair share" of taxes from me for 2008, I'm focusing on minimizing my overhead this year. This means no traveling out to RSA for this week's show.I was originally going to go - especially since I can get in for free on a press/blogger pass. But once I started adding up the other costs (plane, hotel, transportation, meals, and other fees/taxes/etc. ...
Continue Reading...Well, Spring Break is over (boohoo) and I'm back in full swing. My mind had a chance to clear while I was out and I thought of some new blog ideas that I'll be posting soon. Plus I have some content that was recently published that I'll be linking to. Also, I'm now writing for SearchCompliance.com (a great resource for us given how compliance is driving a lot of what ...
Continue Reading...This just in (OK, it's really from a couple of days ago): Cybersecurity hearing highlights inadequacy of PCI DSS.But I thought compliance = security!? And anything forced down our throats at the hand of industry bodies and government goons is all we need to manage business risks!? Seriously...how long do you think we'll continue to hear about this...ay yay yay?...
Continue Reading...This just in: from the government agency that brought us HIPAA we now have a new site to help us all deal with the troubling economy. Maybe one day the site can be expanded to include those of us who are affected - both personally and professionally - by security breaches. At least there's hope....and when there's hope, there will be "change". ;)Funny how government creates a crisis and then ...
Continue Reading...Here's an interesting bit about something our legal system is going to have to try to get its arms around. In essence it's jurors using mobile phones to access the Internet to learn more about the trials they're currently serving on. Wow - talk about unintended consequences.I suspect that one of these days, in a few more years once Big Brother has really established himself, we'll have some really advanced ...
Continue Reading...Imagine if someone at work ticked you off and you had the ability to enact a new IT/security policy that only affected that person. Something like no more Internet access or pay-per-use fees for laptops or, say, complete oversight and scrutiny of the person's every action when they're using the computer.Sounds absurd doesn't it....Well, it is and so is this ridiculous new law our House passed yesterday that will tax ...
Continue Reading...