<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
   <channel>
      <title>Realtime Community | IT Compliance</title>
      <link>http://www.realtime-itcompliance.com/</link>
      <description>The Realtime IT Compliance Community is an objective source for information related to IT Compliance, regulations, information security, and data protection.  The community provides a wide range of resources including blogs, articles, white papers, forums and podcast as well as links to external resources.</description>
      <language>en</language>
      <copyright>Copyright 2009</copyright>
      <lastBuildDate>Thu, 02 Jul 2009 17:55:52 -0500</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

      
      <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
         <title>Nevada's New Encryption Law; Made Moot By Its Own Data Breach Law?</title>
         <description>On May 30, 2009, Nevada enacted a new law, &lt;a href="http://www.leg.state.nv.us/75th2009/Bills/SB/SB227.pdf"&gt;SB 227&lt;/a&gt;, which will basically replace NRS 597.970 in January 2010.  

In many ways the new law is an improvement over the much more vague, and brief, NRS 597.970.  I want to focus here on an improvement, but something that still leaves much to interpretation; that is, what is meant by "encryption"?&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=e96KwbBch4Y:y35yPevxjPY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=e96KwbBch4Y:y35yPevxjPY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/e96KwbBch4Y/nevadas_new_encryption_law_mad.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/privacy_and_compliance/2009/07/nevadas_new_encryption_law_mad.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Laws &amp; Regulations</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">encryption</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">Nevada</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">PII personally identifiable informaton</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">SB 227</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">SB 347</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Thu, 02 Jul 2009 17:55:52 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/privacy_and_compliance/2009/07/nevadas_new_encryption_law_mad.htm</feedburner:origLink></item>
      
      <item>
         <title>Stolen Print Documents With PII Found On Crook; Otherwise UCM Would Not Have Known The Reports Were Stolen</title>
         <description>Late last week one of my alma maters, &lt;a href="http://www.kmbc.com/news/19873666/detail.html"&gt;the University of Central Missouri, reported that two printed computer reports containing 7000 students' names, social security numbers, phone numbers, addresses, and birthdates were stolen from somewhere on the campus&lt;/a&gt;.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=_x5qfZcTftg:CEyq3PpqFSo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=_x5qfZcTftg:CEyq3PpqFSo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/_x5qfZcTftg/stolen_print_documents_with_pi.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/privacy_incidents/2009/07/stolen_print_documents_with_pi.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy Incidents</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">identity fraud</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">identity theft</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">personally identifiable information</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">PII</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy breach</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Wed, 01 Jul 2009 21:31:08 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/privacy_incidents/2009/07/stolen_print_documents_with_pi.htm</feedburner:origLink></item>
      
      <item>
         <title>Hear Common, Dumb and Dangerous Privacy Assumptions On The Radio!</title>
         <description>Today I will be on MyTechnologyLawyer.com radio show to an hour program talking about the common privacy mistakes and assumptions made by businesses.  This will be a more in-depth look at the issues from my post from a couple of weeks ago, "&lt;a href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/5_common_dumb_and_dangerous_pr.htm"&gt;5 Common, Dumb and Dangerous Privacy Assumptions&lt;/a&gt;"

Here are the details:&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=PntodD777tw:68Ibmcu3GR4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=PntodD777tw:68Ibmcu3GR4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/PntodD777tw/hear_common_dumb_and_dangerous.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/hear_common_dumb_and_dangerous.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">mytechnologylawyer</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Tue, 30 Jun 2009 07:48:24 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/hear_common_dumb_and_dangerous.htm</feedburner:origLink></item>
      
      <item>
         <title>South Carolina &amp; Alaska Privacy Breach Notice Laws Go Into Effect July 1</title>
         <description>This week two more U.S. breach notice laws go into effect...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=3UrMYa3B3BU:U231TGgVHqE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=3UrMYa3B3BU:U231TGgVHqE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/3UrMYa3B3BU/south_carolina_alaska_privacy.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/laws_regulations/2009/06/south_carolina_alaska_privacy.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Laws &amp; Regulations</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">breach notice law</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">personally identifiable information</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">PII</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Mon, 29 Jun 2009 13:20:55 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/laws_regulations/2009/06/south_carolina_alaska_privacy.htm</feedburner:origLink></item>
      
      <item>
         <title>Voice Recognition Software Puts Top Cop In Hot Water</title>
         <description>Yesterday I read a fascinating story from Australia...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=CLTXJxz_x0M:9PfanN1n12E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=CLTXJxz_x0M:9PfanN1n12E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/CLTXJxz_x0M/voice_recognition_software_put.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/miscellaneous/2009/06/voice_recognition_software_put.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Miscellaneous</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">biometrics</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">voice recognition</category>
        
         <pubDate>Thu, 25 Jun 2009 20:42:17 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/miscellaneous/2009/06/voice_recognition_software_put.htm</feedburner:origLink></item>
      
      <item>
         <title>Movies and TV Shows to Use for Infosec and Privacy Training and Awareness</title>
         <description>After many long hours, I've finally submitted the draft manuscript for the 2nd edition of my "Managing an Information Security and Privacy Awareness and Training Program" book.  However, I will still have one more chance to make changes.  One of the 23 appendices within my book provides lists of resources; books, web sites, activities, games and so on.  One of my lists is for movies and television shows that can be used in training or for awareness activities...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=TJTRlD59Ieg:LOADPYSEU3I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=TJTRlD59Ieg:LOADPYSEU3I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/TJTRlD59Ieg/movies_and_tv_shows_to_use_for.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/training_awareness/2009/06/movies_and_tv_shows_to_use_for.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Training &amp; awareness</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Tue, 23 Jun 2009 09:03:18 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/training_awareness/2009/06/movies_and_tv_shows_to_use_for.htm</feedburner:origLink></item>
      
      <item>
         <title>Don't Manage Employee Online Activities By Requiring Their IDs &amp; Passwords!</title>
         <description>I read a story about a city government agency actually asking job applicants to provide their IDs and passwords for any online social networking type of site they participate in...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=qbk7N2G0Qn4:6eCa5XIKoGI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=qbk7N2G0Qn4:6eCa5XIKoGI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/qbk7N2G0Qn4/dont_manage_employee_online_ac.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/dont_manage_employee_online_ac.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Government</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Information Security</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">Bozeman</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">insider threat</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">personal privacy</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Thu, 18 Jun 2009 21:24:49 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/dont_manage_employee_online_ac.htm</feedburner:origLink></item>
      
      <item>
         <title>5 Common, Dumb and Dangerous Privacy Assumptions</title>
         <description>Today Kevin Beaver posted a nice article, "&lt;a href="http://bit.ly/BN25s"&gt;Dumb things IT consultants do&lt;/a&gt;" that included more than one warning about making assumptions.  Kevin's nice post made me think about all the dangerous assumptions consulants and practitioners often make when it comes to evaluating privacy practices...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=1ANR_H-xW4Q:n18DNXOEcpk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=1ANR_H-xW4Q:n18DNXOEcpk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/1ANR_H-xW4Q/5_common_dumb_and_dangerous_pr.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/5_common_dumb_and_dangerous_pr.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Information Security</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">personally identifiable information</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">PIA</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">PII</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy impact assessment</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Wed, 17 Jun 2009 21:29:55 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/5_common_dumb_and_dangerous_pr.htm</feedburner:origLink></item>
      
      <item>
         <title>FTC Issued Consent Order for GLBA Privacy Rule and Safeguards Rule Violations</title>
         <description>Today the FTC issued a consent order against mortgage lender James B. Nutter &amp; Company for GLBA Privacy Rule and Safeguards Rule violations resulting from having an inadequte information security program and safeguards.  The requirements will result in, among other actions, 20 years of ongoing activities by James B. Nutter &amp; Company; much more costly than it would have been to have established appropriate information security safeguards to begin with...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=XaujXqRTQf4:9BC7W1prg6k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=XaujXqRTQf4:9BC7W1prg6k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/XaujXqRTQf4/ftc_issued_consent_order_for_g.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/noncompliance_sanctions_exampl/2009/06/ftc_issued_consent_order_for_g.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Information Security</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Laws &amp; Regulations</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Non-compliance Sanctions Examples</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">GLBA</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">Gramm Leach Bliley Act</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">Privacy Rule</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">Safeguards Rule</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Tue, 16 Jun 2009 16:56:54 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/noncompliance_sanctions_exampl/2009/06/ftc_issued_consent_order_for_g.htm</feedburner:origLink></item>
      
      <item>
         <title>Info Sec &amp; Privacy Days/Weeks/Months </title>
         <description>As I've mentioned a few times before, I'm in the final lap of finishing the 2nd edition of my book, "&lt;u&gt;&lt;strong&gt;&lt;a href="http://www.amazon.com/Managing-Information-Security-Awareness-Training/dp/0849329639/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1245075120&amp;sr=1-1"&gt;Managing an Information Security and Privacy Awareness and Training Program&lt;/a&gt;&lt;/strong&gt;&lt;/u&gt;."  Woo hoo!  

Over the weekend I updated "Appendix N - Designated Security and Privacy-Related Days."  Here are the days, weeks and months I've found are devoted to raising awareness about various info sec and privacy issues (this is in a much nicer-looking table format in my book)...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=DT4BVoCIlRg:7QRQLYKT-1U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=DT4BVoCIlRg:7QRQLYKT-1U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/DT4BVoCIlRg/info_sec_privacy_daysweeksmont.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/training_awareness/2009/06/info_sec_privacy_daysweeksmont.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Information Security</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Training &amp; awareness</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Mon, 15 Jun 2009 10:06:33 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/training_awareness/2009/06/info_sec_privacy_daysweeksmont.htm</feedburner:origLink></item>
      
      <item>
         <title>FTC's New Red Flags Rules FAQ</title>
         <description>Today the US FTC released "&lt;a href="http://www.ftc.gov/os/2009/06/090611redflagsfaq.pdf"&gt;Frequently Asked Questions: Identity Theft Red Flags and Address Discrepancies&lt;/a&gt;."

Here are a couple important things to take away from this FAQ...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=ZKC6mP4DW6Q:jfVRWdhWMe4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=ZKC6mP4DW6Q:jfVRWdhWMe4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/ZKC6mP4DW6Q/ftcs_new_red_flags_rules_faq.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/laws_regulations/2009/06/ftcs_new_red_flags_rules_faq.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Laws &amp; Regulations</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">FCRA</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">Red Flags Rules</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Thu, 11 Jun 2009 21:12:46 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/laws_regulations/2009/06/ftcs_new_red_flags_rules_faq.htm</feedburner:origLink></item>
      
      <item>
         <title>Healthcare Worker Gets 1 Year In Prison For Posting HIV Victim's Medical Records On Internet</title>
         <description>Today a report discussed how a healthcare worker obtained medical information about a patient with HIV that was then posted on the Internet...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=jptuJCgdNCA:u6nSarh9otM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=jptuJCgdNCA:u6nSarh9otM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/jptuJCgdNCA/healthcare_worker_gets_1_year.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/privacy_incidents/2009/06/healthcare_worker_gets_1_year.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Information Security</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy Incidents</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">HIPAA</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">insider threat</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">patient privacy</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Wed, 10 Jun 2009 19:22:16 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/privacy_incidents/2009/06/healthcare_worker_gets_1_year.htm</feedburner:origLink></item>
      
      <item>
         <title>Privacy Enhancing Technologies (PETs) &amp; Privacy Threatening Technologies</title>
         <description>I'm doing research while working on the 2nd edition of my book, "&lt;a href="http://www.amazon.com/gp/product/0849329639/ref=s9_simz_gw_s4_p14_i1?pf_rd_m=ATVPDKIKX0DER&amp;pf_rd_s=center-2&amp;pf_rd_r=0CGE70RX60VVZQ5GSYWM&amp;pf_rd_t=101&amp;pf_rd_p=470938631&amp;pf_rd_i=507846"&gt;Managing an Information Security and Privacy Awareness and Training Program&lt;/a&gt;"...&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=Ce3OmGrJd7k:s5D8t5DQ_a4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=Ce3OmGrJd7k:s5D8t5DQ_a4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/Ce3OmGrJd7k/privacy_enhancing_technologies.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/privacy_enhancing_technologies.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Information Security</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">PETs</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy enhancing technologies</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Tue, 09 Jun 2009 16:23:48 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/privacy_enhancing_technologies.htm</feedburner:origLink></item>
      
      <item>
         <title>Audits Show Things At a Moment in Time; Silly To Sue For Breaches That Happen 1 Year After Audit Conclusion?</title>
         <description>There has been much written in the past week about &lt;a href="http://www.scmagazineus.com/Bank-sues-Savvis-over-2005-CardSystems-breach/article/137616/"&gt;Merrick Bank suing the audit firm, Savvis, because a breach occurred at CardSystems in 2005 even though Savvis had given passing marks for the CardSystems audit that Merrick Bank hired them to perform in 2004 to ensure they were following Visa's Cardholder Information Security Program (CISP)&lt;/a&gt;; basically a forerunner of the current PCI DSS program.  Savvis found that CardSystems was following the CISP requirements.  Within a year after the audit, CardSystems experienced a major breach that basically put them out of business.

I have had the great privilege to work as an IT auditor early in my career, for a while as an internal auditor at a large multi-national financial and insurance company, and then doing periodic audits since in various organizations in a wide range of industries since.  All wonderful learning experiences! 

There are a couple of important points that the judge in this situation should consider, and the lawyers in this case should understand:&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=R76HXyO3WHA:kvkCtgKeC4o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=R76HXyO3WHA:kvkCtgKeC4o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/R76HXyO3WHA/audits_show_things_at_a_moment.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/audits_show_things_at_a_moment.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Information Security</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">CardSystems</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">CISP</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">Merrick Bank</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">PCI DSS</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">Savvis</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
         <pubDate>Mon, 08 Jun 2009 10:10:25 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/privacy_and_compliance/2009/06/audits_show_things_at_a_moment.htm</feedburner:origLink></item>
      
      <item>
         <title>Great InfoSec and Privacy Info and Resources This Week On Twitter</title>
         <description>I got my week's issue of Time magazine in the mail today, and lo-and-behold the cover and feature story was about Twitter!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=7eGWUyZLaSo:4uUOJDpRUrA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?a=7eGWUyZLaSo:4uUOJDpRUrA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
         <link>http://feedproxy.google.com/~r/RebeccaHeroldOnCompliancePrivacyAndInformationSecurity/~3/7eGWUyZLaSo/great_infosec_and_privacy_info.htm</link>
         <guid isPermaLink="false">http://www.realtime-itcompliance.com/information_security/2009/06/great_infosec_and_privacy_info.htm</guid>
        
          <category domain="http://www.sixapart.com/ns/types#category">Information Security</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Privacy and Compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#category">Training &amp; awareness</category>
        
        
          <category domain="http://www.sixapart.com/ns/types#tag">awareness and training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT compliance</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">IT training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">policies and procedures</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacy training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">privacyprof</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">risk management</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">security training</category>
        
          <category domain="http://www.sixapart.com/ns/types#tag">twitter</category>
        
         <pubDate>Fri, 05 Jun 2009 20:24:39 -0500</pubDate>
      <feedburner:origLink>http://www.realtime-itcompliance.com/information_security/2009/06/great_infosec_and_privacy_info.htm</feedburner:origLink></item>
      
   </channel>
</rss>
