<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>InfoSec Tools, Tips &#38; Thoughts &#187; Compliance</title>
	<atom:link href="http://infosec3t.com/category/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosec3t.com</link>
	<description>Exploring topics in InfoSec and Cyber Security   including  practical approaches to risk management.</description>
	<lastBuildDate>Sat, 12 May 2012 03:05:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks</title>
		<link>http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/</link>
		<comments>http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/#comments</comments>
		<pubDate>Sun, 23 Jan 2011 18:33:15 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Users]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2397</guid>
		<description><![CDATA[Across all industries, small businesses are increasingly facing new threats related to cyber security. Whereas some have taken minimum steps to address these threats but most have not. New security threats and incidents are reported every day in news reports and a many remain unreported. This underscores the need for cyber security education of small [...]]]></description>
			<content:encoded><![CDATA[<p>Across all industries, small businesses are increasingly facing new <a href="http://infosec3t.com/tag/threats/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threats">threats</a> related to cyber <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>. Whereas some have taken minimum steps to address these <a href="http://infosec3t.com/tag/threats/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threats">threats</a> but most have not. New security <a href="http://infosec3t.com/tag/threats/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threats">threats</a> and incidents are reported every day in news reports and a many remain unreported. This underscores the need for cyber security education of small business owners and managers. These <a href="http://infosec3t.com/tag/threats/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threats">threats</a> have potentially serious consequences and could lead to unrecoverable damage to small businesses.</p>
<p><strong>What are some consequences of the lack of basic cyber security controls?</strong></p>
<ul>
<li>Loss or stolen customer data<a href="http://infosec3t.com/wp-content/uploads/2011/01/logolarge.jpg"><img class="alignright size-medium wp-image-2398" title="SMB Cyber Security Alliance" src="http://infosec3t.com/wp-content/uploads/2011/01/logolarge-300x108.jpg" alt="" width="270" height="97" /></a></li>
<li>Loss of intellectual property</li>
<li>Decreased productivity</li>
<li>Legal liability</li>
<li>Regulatory sanctions and fines</li>
<li>Computer systems downtime</li>
<li>Loss of reputation and customer confidence</li>
<li>Loss of revenue</li>
<li>Banking <a href="http://infosec3t.com/tag/fraud/" class="st_tag internal_tag" rel="tag" title="Posts tagged with fraud">Fraud</a></li>
</ul>
<p><strong>Could this happen to you?</strong></p>
<p>It is very important to understand that neither size nor industry guarantees protection from an attack. The use of computer systems and the Internet makes you vulnerable to attacks and other threats.</p>
<p>A 2010 survey conducted by the Ponemon Institute and Guardian Analytics of over 500 SMBs surfaced these alarming statistics:</p>
<ul>
<li><strong>55%</strong> experienced a fraud attack in the last year</li>
<li><strong>58%</strong> of the incidents involved online banking</li>
<li>Over <strong>50%</strong> experienced multiple incidents</li>
<li><strong>87%</strong> failed to fully recover lost funds</li>
</ul>
<p><strong>You are not a big, well known business. Why would anyone attack you?</strong></p>
<p>While it might be the case that well trained hackers are not very interested in your small company, most online attacks aren&#8217;t carried out by expert hackers. Attacks are perpetrated by low-skilled, common criminals with access to pre-packaged hacking <a href="http://infosec3t.com/tag/tools/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Tools">tools</a>, thereby casting a wide net in hopes of finding an unprotected computer system or network. These <a href="http://infosec3t.com/tag/tools/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Tools">tools</a> are easy to use and readily available on the Internet, often times free of charge. The anonymity of a cyber attack makes it even more attractive to criminals. Many attackers use safe havens in foreign countries which do not have strong cyber crime laws.</p>
<p>Malicious software like viruses, worms, trojan horses, spam, bots are all vectors of cyber attacks that are indiscriminately spreading across the Internet. These attacks don&#8217;t only target your small business computer systems but also seek to use your unprotected systems to launch attack on others.</p>
<p><strong>Hasn&#8217;t IT guy(s) already dealt with this issue?</strong></p>
<p>Although cyber security includes traditional &#8220;IT&#8221;related issues, it primarily focuses on protecting your valuable information from all threats including physical attacks, data corruption, equipment failure, social engineering, and bad security choices due to insufficient security awareness education. Effective cyber security management requires specific training related to threats, vulnerabilities, and risks affecting computer systems, business operational processes, and most importantly you and your employees. One&#8217;s security problems cannot be addressed solely by off the shelf products. Security must be addressed in the boardroom before it is addressed in the computer room.</p>
<p><strong>What are the benefits and cost of cyber security?</strong></p>
<p>Besides avoiding some of the devastating consequences mentioned earlier, good security is simply good business. It does far more than increase customer confidence and protects the integrity of your businesses brand. A secure business increases customer confidence, loyalty and adds to the businesses bottom line.</p>
<p>Responsible businesses understand that risk management mandates that all threats, including cyber threats, be assessed and managed to protect the business, employees and customers.</p>
<p>The potential cost of inaction far outweighs the cost of action. Analyzing your businesses risks allows you to weigh the costs and benefits and make informed decisions.</p>
<p><strong>Where do you start? Where can you get help?</strong></p>
<p>Although improving your security may seem a daunting task, it doesn&#8217;t have to be. Increasing cyber security awareness helps small and medium sized businesses proactively implement simple best practices to protect their businesses. Security should be built into your business processes, information technology (IT), and most importantly your employees and contractors. Each business is unique and faces challenges particular to their operations. There is no magic pill that guarantees 100% security. The SMB Cyber Security Alliance have security experts available to help you understand your unique risks and implement solutions that work your your particular business environment.</p>
<p><strong>Visit us today and sign up for your free membership at http://www.smbcybersecurity.org</strong></p>
<p>The SMB Cyber Security Alliance is volunteer-run organization seeking to increase cyber security awareness in small business communities through education, awareness training, free resources and consultations, and active engagements between small business owners and local security professionals.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/08/defend-your-small-business-against-online-bank-fraud/' rel='bookmark' title='Defend your Small Business against Online Bank Fraud'>Defend your Small Business against Online Bank Fraud</a> <small>Is your banking practices putting your business at risk? Protect...</small></li>
<li><a href='http://infosec3t.com/2010/07/08/security-on-a-shoestring-smb-budget/' rel='bookmark' title='Security On A Shoestring SMB Budget'>Security On A Shoestring SMB Budget</a> <small>The e-mail appeared to be an invitation from an old,...</small></li>
<li><a href='http://infosec3t.com/2010/02/01/facebook-poses-biggest-security-threat-to-businesses/' rel='bookmark' title='Facebook poses biggest security threat to businesses'>Facebook poses biggest security threat to businesses</a> <small>According to it&#8217;s  Security Threats 2010 report published today, security...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Audits could start this year</title>
		<link>http://infosec3t.com/2010/05/12/hipaa-audits-could-start-this-year/</link>
		<comments>http://infosec3t.com/2010/05/12/hipaa-audits-could-start-this-year/#comments</comments>
		<pubDate>Wed, 12 May 2010 22:14:10 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2142</guid>
		<description><![CDATA[The new federal HIPAA privacy and security rule compliance audits of healthcare organizations and their business associates likely will start later this year once a report on a model for the program is completed, a key federal privacy official says. In the next few weeks, Booz Allen Hamilton will provide a status report on its [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2143" title="hss" src="http://infosec3t.com/wp-content/uploads/2010/05/hss.jpg" alt="" width="152" height="152" />The new federal <a href="http://infosec3t.com/tag/hipaa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HIPAA">HIPAA</a> <a href="http://infosec3t.com/tag/privacy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with privacy">privacy</a> and <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> rule compliance audits of  healthcare organizations and their business associates likely will start  later this year once a report on a model for the program is completed, a  key federal <a href="http://infosec3t.com/tag/privacy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with privacy">privacy</a> official says.</p>
<p>In the next few weeks, Booz Allen Hamilton will provide a status  report on its compliance <a href="http://infosec3t.com/tag/audit/" class="st_tag internal_tag" rel="tag" title="Posts tagged with audit">audit</a> study for the Office for Civil Rights in  the Department of Health and Human Services, the governmental unit that  enforces the privacy and security rules, says Susan  McAndrew, OCR&#8217;s deputy director for privacy.</p>
<p>Read Full Article: <a href="http://www.healthcareinfosecurity.com/articles.php?art_id=2517" target="_blank">http://www.healthcareinfosecurity.com/articles.php?art_id=2517</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/' rel='bookmark' title='United States Department of Defense Embraces Hacker Certification'>United States Department of Defense Embraces Hacker Certification</a> <small>Mar 01, 2010 – The U.S. Department of Defense (DoD)...</small></li>
<li><a href='http://infosec3t.com/2010/06/06/pentagon-and-congress-wants-control-of-your-network-during-cyberattack/' rel='bookmark' title='Pentagon and Congress wants control of your network during cyberattack'>Pentagon and Congress wants control of your network during cyberattack</a> <small>There has been a lot of chatter in the news...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/05/12/hipaa-audits-could-start-this-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

