July 22, 2010 6:32 PM
Posted by: David Schneier
backup,
data breach,
HIPPAA,
offsite storage,
PCI,
regulatory,
Regulatory Compliance,
Security,
security breachI'm fond of saying that a business entity complies with regulatory and industry requirements for one of two reasons: because it helps protect sensitive information or because they have to. Some may argue that regardless of the reason, both will get you to the same place with the same...
May 10, 2010 4:59 AM
Posted by: David Schneier
compliance,
FDIC,
GLBA,
governance,
GRC,
HIPAA,
PCI,
Regulatory Compliance,
risk,
risk assessment,
SOXIn the past, I've made sometimes flip and irreverent comments about the weekly FDIC announcements that land in my inbox regarding bank closings. Despite the mind-numbing number of institutions that have been closed over the past year or so and the somewhat extensive list of institutions I've...
February 23, 2010 4:17 AM
Posted by: David Schneier
Audit,
bcp,
disaster recovery,
GLBA,
PCI,
Regulatory Compliance,
risk assessment,
SOX,
Vendor ManagementHere's me about to eat crow.
After nearly a decade of railing against software as a solution to address the challenges of regulatory/industry compliance, I'm being forced to reconsider my position.
I've long advocated that an institution or organization could just as easily develop manual...
December 1, 2009 1:49 AM
Posted by: David Schneier
bank,
banking,
checking account,
credit card,
FDIC,
identify theft,
online fraud,
PCI,
PII,
Regulatory Compliance,
routing number,
social security numbersI want to play a game with you, sort of like the compliance equivalent of the Rorschach inkblot test. I’m going to throw out a phrase and I want you to write down the first acronym that comes to mind.
Ready? Here we...
October 29, 2009 7:28 PM
Posted by: Marcia Savage
PCII was shocked and saddened today to learn of the unexpected passing of David Taylor, founder of the PCI Knowledge Base. My deepest sympathy goes to his family.
Dave founded the PCI Knowledge Base, a research community that shares information to help organizations achieve PCI compliance, after a...
August 18, 2009 8:05 PM
Posted by: David Schneier
Audit,
FDIC,
GLBA,
PCI,
regulatory,
Regulatory Compliance,
SOXI was away from the office last week trying squeeze in a family vacation before the kids head back to school. Despite taking the occasional phone call and replying to a number of emails, there was still plenty waiting for me today when I returned to my normal...
July 17, 2009 1:58 PM
Posted by: David Schneier
Audit,
compliance,
cyber security,
FFIEC,
GLBA,
PCI,
regulations,
Regulatory Compliance,
Security,
SOXDespite earning a living in the space, I often question the value of regulatory compliance.
How is it that a business can be PCI-compliant but still have glaring vulnerabilities? How is it that despite layer upon layer of controls...
July 2, 2009 2:53 AM
Posted by: David Schneier
Audit,
compliance,
GLBA,
governance,
GRC,
PCI,
Regulatory Compliance,
SOXA while back I’d written about the Unified Compliance Framework from Network Frontiers, which takes quite literally every regulation and framework within the IT domain and maps them in such a way where you can identify how a single control addresses multiple requirements. In...
June 22, 2009 3:46 PM
Posted by: David Schneier
Audit,
compliance,
GLBA,
obama,
OTS,
PCI,
Regulatory Compliance,
SOXI had a great piece lined up for this week about a governance project I’m working on but was waylaid by all the news that hit the radar around regulatory reform.
In what may be the understatement of the year, the plans revealed last week by President...