August 18, 2009 8:05 PM
Posted by: David Schneier
Audit,
FDIC,
GLBA,
PCI,
regulatory,
Regulatory Compliance,
SOXI was away from the office last week trying squeeze in a family vacation before the kids head back to school. Despite taking the occasional phone call and replying to a number of emails, there was still plenty waiting for me today when I returned to my normal...
August 8, 2009 3:31 AM
Posted by: David Schneier
assessment,
Audit,
breach,
insider threat,
Regulatory Compliance,
risk assessment,
SecurityI was reading an article last week about how there’s been a recent increase in the number of reported security breaches caused by internal resources. The insider threat is not a new one as corporate espionage is as old as civilization but it certainly is getting more...
July 27, 2009 8:56 PM
Posted by: David Schneier
banking,
compliance,
FDIC,
regulations,
Regulatory ComplianceI can’t think of any more telling comment about where I am in my professional life than what I’m about to offer:
Sheila Bair rocks!
If you don’t know who she is, well, shame on you. Because...
July 17, 2009 1:58 PM
Posted by: David Schneier
Audit,
compliance,
cyber security,
FFIEC,
GLBA,
PCI,
regulations,
Regulatory Compliance,
Security,
SOXDespite earning a living in the space, I often question the value of regulatory compliance.
How is it that a business can be PCI-compliant but still have glaring vulnerabilities? How is it that despite layer upon layer of controls...
July 8, 2009 3:45 PM
Posted by: David Schneier
Audit,
compliance,
cyber security,
FERC cyber security,
GLBA,
NERC,
Regulatory Compliance,
SOXI had a eureka moment recently that I’d like to share.
In considering the implications of the recently announced changes by MasterCard that will now require PCI Level 2 merchants to be assessed by a Qualified Security Assessor (QSA) it occurred to me...
July 2, 2009 2:53 AM
Posted by: David Schneier
Audit,
compliance,
GLBA,
governance,
GRC,
PCI,
Regulatory Compliance,
SOXA while back I’d written about the Unified Compliance Framework from Network Frontiers, which takes quite literally every regulation and framework within the IT domain and maps them in such a way where you can identify how a single control addresses multiple requirements. In...
June 22, 2009 3:46 PM
Posted by: David Schneier
Audit,
compliance,
GLBA,
obama,
OTS,
PCI,
Regulatory Compliance,
SOXI had a great piece lined up for this week about a governance project I’m working on but was waylaid by all the news that hit the radar around regulatory reform.
In what may be the understatement of the year, the plans revealed last week by President...
June 12, 2009 8:49 PM
Posted by: David Schneier
assessment,
Audit,
compliance,
GLBA,
PCI,
Regulatory Compliance,
risk,
risk assessmentI had two great conversations this week regarding risk assessments (jeez, does that ever sound geeky).
The first conversation centered on what an associate was expecting to accomplish via the risk assessment process and the second one was a general conversation about the proper approach to...
June 4, 2009 8:26 PM
Posted by: David Schneier
CIP,
FERC cyber security,
NERC,
PCI,
Regulatory ComplianceThrough an odd turn of events over the past few months I’ve found myself actively engaged with a group that’s focusing quite a bit of effort on NERC CIP. For those of you not in the know, NERC (North American Electric Reliability Corporation) is to the energy...