GAO Report Stresses Need to Address Flu Related Network Congestion Fears

Officials at the U.S. Government Accountability Office (GAO) recently released a report entitled, "Influenza Pandemic: Key Securities Market Participants are Making Progress, but Agencies Could Do More to Address Potential Internet Congestion and Encourage Readiness". (Read this Report) The Department of Homeland Security (DHS) responded to this report by stating, "An expectation of unlimited Internet access during a pandemic is not realistic -- any more so than an expectation that traffic congestion on hurricane evacuation routes can be completly avoided.  All users which rely on the … [Read more...]

Security Policy — Components of a Good Policy

By:  Lisa DuBrock, CPA, CBC Whether you are tasked with writing your organization’s Information Security Policies or updating an existing security policy or security policies, knowing what is in a well crafted policy is important.  Below are details of many of the areas you should include: Security Definition – All security policies should include a well-defined security vision for the organization.  The security vision should be clear and concise and convey to readers the intent of the policy.  Also included in this section should be details of what if any security standards your … [Read more...]

"Red Flag Rules": Exemption Ruling Announced

By an overwhelming vote of 400-0, the U.S. House approved legislation on October 20, 2009, that exempt certain businesses from the Federal Trade Commission's Red Flag Rules.  As part of that legislation, the FTC is also required to issue new regulation setting out the exemption processes that allow any business to apply for an exemption. With November 1, 2009 as an announced Red Flag Rule compliance deadline, it is very likely that this new ruling will cause the FTC to at least consider the announcement of another delay for this compliance deadline. Under the current ruling, health care, … [Read more...]

Supply Chain Risk Leadership Council – What Is It and Why Should I Know About It?

The Supply Chain Risk Leadership Council is a group of companies that meet four times a year to discuss how to incorporate standardized best practices into their supply chain.  Some of the companies that sit on the council are industry heavyweights, such as CISCO, GE, Boeing, Coca-Cola, Merck and FedEx.  Their mission as stated on their website   http://www.scrlc.com/ is to: “Work together to create best-practice supply chain risk management standards, processes, capabilities and metrics to be adopted within our respective organizations. Leverage this best practices effort to proactively … [Read more...]

Standards Announced for PS-Prep by DHS

On October 15, 2009, Janet Napolitano, Secretary of the Department of Homeland Security (DHS) identified three standards to be included in the PS-Prep; Private Sector Preparedness Program.  The PS-Prep program was created under Title IX of Public Law 110-53: Recommendations from the 9/11 Commission and is a partnership between DHS and the private sector that enables private entities - including businesses, non-profit organizations and universities - to receive emergency preparedness certification from a DHS accreditation system created in coordination with the private sector. The three … [Read more...]

Certification Body: Good Resource for Learning about PSC.1

By: Ben J. Carnevale In support of our staff’s efforts to further expand on the topic of the most recognized certifiable standard related to private security companies --- ANSI/ASIS PSC.1 – 2012: Management System for Quality of Private Security Company Operations --- this posting will introduce and offer our readers additional information and a beginning of a series of steps in the process of bringing a private security company (PSC) into compliance with and/or certification to this standard. One of our contributing writers on this topic-- Lisa DuBrock CPA, CBCP, MBCI, MBA– Managing … [Read more...]

Supply Chain Disruption Report Just Released

For many of our readers and the organizations where they work, any kind of supply chain disruption could easily qualify as a serious incident and one that would easily have been discussed and included in their disaster preparedness planning process. With that thought in mind, our staff recommends reading and potentially adding a recent EventWatch™ 2014 Supply Chain Disruption report to your organization’s business continuity and disaster preparedness team’s reading resource library. This report  This report was funded and supported by Resilinc’s database of over 40,000 suppliers and over … [Read more...]

Private Security Companies and PSC.1

As follow-up to an earlier posting on this website, and to several requests for more information regarding information and background on the ANSI/ASIS PSC.1-2012: Management System for Quality of Private Security Company Operations standard, our staff would like to direct our readers to an article recently posted by James Schmitt from the Human Analytics group. As reported earlier, members of the Human Analytics group participate often as contributing writers to this website and with a rising interest in our readership of standard related activities and private security companies, Schmitt’s … [Read more...]

Emergency Management and America’s PrepareAthon! Campaign

by Ben J. Carnevale Business Continuity, Resiliency and Emergency Management Planning teams are often looking for additional ideas, programs and campaigns to help those teams be more prepared and ready to mitigate losses from potential disasters affecting the organization where they work, and the community where they work and live with their families. Our staff believes that the America’s PrepareAthon™ campaign qualifies as one of the best resources for those teams to look for ideas and assistance for taking action to increase emergency preparedness and resilience. America’s … [Read more...]

Private Security Companies Considering Compliance with PSC.1

by Ben J. Carnevale Recently, our staff has been researching developments related to efforts by both the U.S. Department of Defense and the U.K. Foreign Commonwealth Office to support the creation of a certifiable standard for private security operations. This posting will try to address some of those developments and begin this website’s process to now include these activities as consideration and subject matter encompassed by this website’s   objective to keep our readers informed of all related continuity and compliance requirements affecting their companies where they work and their … [Read more...]

Is Password Recycling Addressed in Your Information Security Metrics?

                              Maria Deutscher, who is a staff writer for SiliconANGLE, recently reported on the results of a new report from Netskope, Inc. reinforcing perhaps much of what our readers already know – e.g. for many - if not most enterprises - cloud security and security metrics of effectiveness and privacy in the cloud remain a “work-in-progress”. Nonetheless, one of those issues of “work-in-process” is bringing attention to the information security related risks surrounding password recycling. However with that being said, this report … [Read more...]

Cyber Security Federal Workforce — Key to Reducing Federal Cyber Security Incident Levels?

In a recent report entitled “Keeping Talent” it was found that the federal cyber security workforce in the U.S. will erode due to fragmented governance and uncoordinated leadership, a complicated federal hiring process, a disconnect between hiring managers and the government's human resource specialists, and more importantly, a lack of qualified and skilled talent to fill these jobs. This report was sponsored and written by the cooperation of the Partnership for Public Service (PPS) and Booz Allen Hamilton groups, and, while it certainly talked of an apparent pending HR risk, of lacking … [Read more...]

FTC Allowed to Proceed with Lawsuit against Hotel Group after Information Security Breaches

This website and its readers are well aware of the risk management challenges and opportunities for companies to make decisions over the growing number of information security breaches related activities. Unfortunately, many of these concerns can easily be lost over these risk mitigation topics for small business firms. Nonetheless, supply chain management dynamics can often force even small business firms to have to pay attention to recent developments in this area of information security enforcement--- and --- it is with this point in mind that our staff focused its attention on the … [Read more...]

2014 US State of Cybercrime Survey Report Now Available

Recently, a report entitled the “2014 US State of Cybercrime Survey” was released and made available to the public.  This survey was co-sponsored by PwC, CSO magazine, The CERT® Division of the Software Engineering Institute at Carnegie Mellon University, and the United States Secret Service.  Cybersecurity leaders from these organizations worked together to evaluate survey responses from more than 500 executives of US businesses, law enforcement services, and government agencies where they identified requirements for effective cyber security processes and procedures and evaluated these … [Read more...]