<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>Risk Management and Compliance</title>
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Tue, 07 Sep 2010 01:35:00 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/abc" -->

	<item>
		<title>Social Media Warfare: Are you attacking or defending?</title>
		<description><![CDATA[Image via CrunchBase Is there such a thing as Social Media Warfare? We have had cyber warfare going on for years now. So it should be an obvious &#8220;YES&#8221; that Social Media warfare exists. But is that true?  To get to a full blown war opposing sides go through an escalation process. Where are we [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/09/06/social-media-warfare-are-you-attacking-or-defending/</link>
			</item>
	<item>
		<title>Building a Social Media Policy</title>
		<description><![CDATA[Image by ivanpw via Flickr Social Media Policy Social Media has become part of the user community several years ago. Today we have social media in the corporate environment. The main problem we have is how social media has evolved. It has been a bottom up approach. By bottom up I mean that the consumer [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/08/11/building-a-social-media-policy/</link>
			</item>
	<item>
		<title>Corporate Reputation Management: Can a company require you register your Social Media Profile with Human Resources?</title>
		<description><![CDATA[Image via CrunchBase When you join a company, you relinquish certain rights. The workplace is not a democracy. Yet many people still think that their corporate email, their corporate computers and the data they use is &#8220;theirs&#8221;. Who owns that data? Well the answer is the company. Companies are concerned with data loss prevention. A [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/05/25/corporate-reputation-management-can-a-company-require-you-register-your-social-media-profile-with-human-resources/</link>
			</item>
	<item>
		<title>Data Lifecycle Management: How to reduce risk, Part 2</title>
		<description><![CDATA[Data Lifecycle Management: How to reduce risk Part 2 The Data Lifecycle Management (DLM) goes through 5 steps: creation, usage, transport, storage and destruction. Most companies have parts of this lifecycle under control, but that means there are lots of areas for gaps in the control measures that could let a threat affect the data. [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/05/02/data-lifecycle-management-how-to-reduce-risk-part-2/</link>
			</item>
	<item>
		<title>Data Lifecycle Management: How to reduce risk (part1)</title>
		<description><![CDATA[The Data Lifecycle goes through 5 steps: creation, usage, transport, storage and destruction. ]]></description>
		<link>http://blog.kraasecurity.com/2010/04/21/data-lifecycle-management-how-to-reduce-risk-part1/</link>
			</item>
	<item>
		<title>What are the features you need a Windows Security Host Diagnostic tool?</title>
		<description><![CDATA[Image via Wikipedia There is a lot of focus on network security and application security today. Years ago it was operating system security that was all the rage. But with the advent of the strict requirements of some of the regulations such as HIPAA, PCI, SOX, and FISMA, more attention needs to be paid to [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/04/01/what-are-the-features-you-need-a-windows-security-host-diagnostic-tool/</link>
			</item>
	<item>
		<title>Washington State implements PCI law</title>
		<description><![CDATA[Image via Wikipedia PCI laws are expanding around the country. Washington State is the latest to add a law to their books. Washington state follows Nevada and Minnesota in implementing Payment Card Industry Data Security Standard (PCI), the law is HB 1149. It changes the breach notification law they already had on the books. The [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/03/30/washington-state-implements-pci-law/</link>
			</item>
	<item>
		<title>What are the challenges with protecting electronic documents?</title>
		<description><![CDATA[Image via Wikipedia We have seen a lot of problems with Adobe vulnerabilities. Adobe has been getting beat up with all the negative publicity in the past few months. Apple is restricting access to Adobe on their devices. Has anyone tried their remote desktop sharing? I wonder if some vulnerability will be release in that [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/03/29/what-are-the-challenges-with-protecting-electronic-documents/</link>
			</item>
	<item>
		<title>What is Social Media INSecurity?</title>
		<description><![CDATA[Image via CrunchBase  The trends in Social Media are heading towards more sharing of information. But sharing of information has moved beyond your circle of friends and family. Social media is becoming less social and more&#8230; well more corporate. Or more like many people shouting in a bar, you are all in close proximity, but [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/03/24/what-is-social-media-insecurity/</link>
			</item>
	<item>
		<title>Can you protect yourself on Social Media?</title>
		<description><![CDATA[Image via Wikipedia One of the greatest challenges to privacy and security in the next several years is Social Networks and Social Media. Sites like Facebook, Twitter, LinkedIn, MySpace and others can be the downfall of valuing information. The ability to share and provide information is completely the opposite of network security requirements.  This is [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/03/01/can-you-protect-yourself-on-social-media/</link>
			</item>
	<item>
		<title>When will Vendors provide Risk Assessments of their products?</title>
		<description><![CDATA[Image via Wikipedia Vendor risk assessment are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/</link>
			</item>
	<item>
		<title>What is the value of a Data Breach?</title>
		<description><![CDATA[Image by Getty Images via Daylife SC magazine just reported that the Ponemon Institute has determined the cost of a data breach is $204 per record. &#8220;Data breaches last year cost organizations $204 per exposed record on average, which represents an almost two percent increase over 2008, according to the fifth annual &#8220;Cost of  Data [...]]]></description>
		<link>http://blog.kraasecurity.com/2010/01/27/what-is-the-value-of-a-data-breach/</link>
			</item>
	<item>
		<title>Ponemon Institute Cyber megatrends &#8211; Some Additions Needed</title>
		<description><![CDATA[Ponemon Institute recently released their  Cyber megratrends as listed below. While I agree with these I think there were a couple that could easily be added to the list. First, I would either add or modify Web 2.0 into Web 3.0. Lets look to what is going to happen versus what is happening. Incremental change [...]]]></description>
		<link>http://blog.kraasecurity.com/2009/11/28/ponemon-institute-cyber-megratrends-some-additions-needed/</link>
			</item>
	<item>
		<title>HIPAA Vendor Compromised Healthcare Records</title>
		<description><![CDATA[This is story that is several months old, but as I came across it, i thought it would make a good point. A vendor handling healthcare records has lost social security numbers of people in March of 2009. In this case, Health insurer Aetna, Inc., is reportedly providing 65,000 individuals with free credit monitoring for [...]]]></description>
		<link>http://blog.kraasecurity.com/2009/11/12/hipaa-vendor-compromised-healthcare-records/</link>
			</item>
	<item>
		<title>HIPAA Compliance Data Breach with a Foreign Supplier</title>
		<description><![CDATA[Recently, the Economic Times Report in India discussed a successful &#8220;Sting operation by a UK agency in which some health related data was bought from a medical transcription company&#8221; . What this means is all that perosnal and HIPAA confidential data that was being transfered for transcription got stolen in the most likely scenario.  There [...]]]></description>
		<link>http://blog.kraasecurity.com/2009/11/03/hipaa-compliance-data-breach-with-a-foreign-supplier/</link>
			</item>
	<item>
		<title>IPhone Apps Every Road Warrior Entrepreneur Needs</title>
		<description><![CDATA[The Blackberry has been the mainstay of the business world for years. But as we know, the IPhone is eating away at market share. There are over 75,000 apps for the IPhone now and growing steadily. For those who have Blackberry Thumb, you can probably look forward to IPhone Index Finger at some point in [...]]]></description>
		<link>http://blog.kraasecurity.com/2009/10/22/iphone-apps-every-road-warrior-entrepreneur-needs/</link>
			</item>
	<item>
		<title>Information Devaluation Through Phishing</title>
		<description><![CDATA[Image via Wikipedia Information Devaluation Through Phishing The value of information has been decreasing over time. How do you see this isn the real world? There are two ways, one can be seen from the user perspective and the other from the attacker/bad guy perspective. From a user point of view, the most obvious method [...]]]></description>
		<link>http://blog.kraasecurity.com/2009/09/25/information-devaluation-through-phishing/</link>
			</item>
	<item>
		<title>FTC&#8217;s Additional Rules for HIPAA Security</title>
		<description><![CDATA[FTC&#8217;s Additonal Rules for HIPAA Security The Federal Trade Commission (FTC) recently issued a rule which gives more scope to the data breach notification rules as part of the Health Insurance Portability and Accountability Act (HIPAA). The addition targets companies that provide health info in an online storage facitlity. Things like Google Health or Healthvault [...]]]></description>
		<link>http://blog.kraasecurity.com/2009/08/23/additonal-rules-for-hipaa-security/</link>
			</item>
	<item>
		<title>Credit Card Theft Put Miami on the Map</title>
		<description><![CDATA[Miami is a fun place to live and work (there are actually people who work here). Its a great vacation spot, people enjoy the nightlife and now we have something else to crow about. The largest credit theft ring was based here! According to Bloomberg, &#8220;Albert Gonzalez, a 28-year-old Miami resident, and two hackers living [...]]]></description>
		<link>http://blog.kraasecurity.com/2009/08/19/credit-card-theft/</link>
			</item>
	<item>
		<title>Stolen laptop with employee information- yet again</title>
		<description><![CDATA[Stolen laptop with employee information- yet again The Associated Press reported that a Williams Cos. Inc. laptop containing personal and compensation information was stopen from a workers vehicle. The laptop had over 4,400 current and former employees records. Information like names, birth dates, Social Security numbers and compensation data was on it. How many times [...]]]></description>
		<link>http://blog.kraasecurity.com/2009/08/07/stolen-laptop/</link>
			</item>
</channel>
</rss>
