April 14, 2012 2:23 PM
Posted by: David Schneier
Add new tag,
ATM,
Audit,
compliance,
GLBA,
PCI,
regulation,
regulations,
regulatory,
Regulatory Compliance,
SecurityTwo weeks ago news broke about a huge, massive leak of credit card information from a processor called Global Payments and I braced for a firestorm of media coverage that was sure to follow. Two weeks hence and it's pretty much a non-event. A few days ago the State of Utah reported a breach of...
March 23, 2012 3:24 PM
Posted by: David Schneier
assessment,
Audit,
compliance,
GRC,
HIPAA,
PCI,
regulations,
regulatory,
Regulatory Compliance,
risk,
risk assessment,
SOXIn early 2004 I co-authored my first Sarbanes-Oxley (SOX) controls framework for a client. Just about the entire thing required manual testing that, if everything worked as planned would require a full-time resource to support. About thirty seconds after submitting the framework draft to the...
March 6, 2012 6:00 PM
Posted by: David Schneier
breach,
compliance,
data breach,
data security,
GLBA,
PCI,
regulations,
regulatory,
Regulatory Compliance,
SecurityTwo weeks ago, about two hours before departing on a long weekend trip to welcome back baseball in Florida I received an email from my bank indicating that there's been suspicious activity on my Visa check card and that it's been suspended. Considering that under normal conditions I think my...
December 22, 2011 9:44 PM
Posted by: David Schneier
assessment,
Audit,
compliance,
GLBA,
NPPI,
PCI,
PII,
regulatory,
Regulatory Compliance,
risk,
risk assessmentLet me begin by sharing a story from the way back files. In the mid 80’s when I was first starting out in my career I was working as a junior programmer in Manhattan. Courtesy of playing on the corporate softball team I became acquainted with a fairly diverse group of...
October 13, 2011 10:42 PM
Posted by: David Schneier
compliance,
Facebook,
identify theft,
LinkedIn,
NPPI,
PCI,
PII,
privacy,
regulatory,
Regulatory Compliance,
SecurityI just came to find out that I’m old. It was somewhat sudden and sort of unexpected as I’m not quite half way to one hundred and have fooled myself into thinking that old doesn’t roll in until somewhere beyond sixty. But apparently one persons middle-aged...
June 24, 2011 2:43 PM
Posted by: David Schneier
cloud,
compliance,
compliant,
FDIC,
FFIEC,
guidance,
NCUA,
PCI,
regulatory,
Regulatory Compliance,
regulatory guidanceOh how the times have changed. Once upon a time I was part of a group of peers who waited for new album releases, camped out over night for concert tickets and once even waited on line for the annual release of Strat-O-Matic's baseball set (perhaps the nerdiest thing I've ever done). And all of...
April 8, 2011 10:45 AM
Posted by: David Schneier
Audit,
compliance,
GLBA,
governance,
GRC,
HIPAA,
PCI,
regulations,
regulatory,
Regulatory Compliance,
risk,
SOX,
UCFAfter nearly a quarter century of working in and around the corporate IT domain I have a grand total of four bold predictions I've made that stand out. Three of them I had nailed dead on and the fourth never panned out a fact that confounds me still to this day.
The...
December 28, 2010 8:55 PM
Posted by: David Schneier
assessment,
Audit,
cloud,
cloud computing,
data security,
data warehouse,
GLBA,
PCI,
regulatory,
Regulatory Compliance,
SOXIt's a popular time of the year for people like myself who publish any form of content to either reflect on the year that was or make predictions on the year that's to be. Confidentially those are typically easy pieces to write and I'm generally happy to take advantage of such opportunities....
December 10, 2010 6:45 PM
Posted by: David Schneier
assessment,
Audit,
FFIEC,
GLBA,
PCI,
red flags,
red flags identity theft,
regulatory,
Regulatory Compliance,
Security,
security awareness,
SOXSometime back in August I blogged about addressing outstanding compliance tasks before the year's end. We see it every year in my practice: Compliance and security folks wake up sometime right around now in a bit of a panic and realize that they're about to miss hitting on certain key regulatory...