COMPLIANCE Articles
Rules of Evidence - Digital Forensics Tools
Searching for clues? Here's how to investigate and use digital forensics and e-discovery tools.
Threat Watch | Cold Boot: Should New Attack on Encrypted Disks Change the Way Lawmakers Approach Disclosure Legislation 'Safe Harbors'?
Recent research from Princeton, McGraw Security Services illustrates how the lack of encryption specifications in legislation could put consumer data at risk.
The Complete Guide to Security Breach Disclosure
Six-part set of articles takes 360-degree look at the implications of new laws that require organizations to notify people whose personal information has been compromised
How to Make Guests Feel at Home (and Still Comply with PCI and SOX Too)
The head of information security for the company that owns the Grand Ole Opry gives a snapshot of his road to SOX compliance
CSO Disclosure Series | Data Breach Notification Laws, State By State
Five years after California's landmark SB 1386, our interactive map shows you which 38 states have passed laws requiring companies to notify consumers whose personal information has been compromised. Part of an in-depth series about disclosing security breaches.
CSO Disclosure Series | What's Next with Disclosure Legislation?
An interview with lawyer and breach notification expert Tanya Forsheit on why the United States still doesn’t have a federal breach notification law. Part of an in-depth series about disclosing breaches
CSO Disclosure Series | The Dos and Don'ts of Disclosure Letters
One security breach, two letters, 11 lessons in the art of telling customers you screwed up. Two PR pros deconstruct the messages that Monster.com and USAJOBS were really giving to customers whose personal information had been disclosed. Part of an in-depth series about disclosing breaches.
CSO Disclosure Series | What California's New Medical Disclosure Law Means for the Rest of Us
New state law AB 1298, aimed at reducing instances of medical identity theft, could prompt similar legislation elsewhere, but experts are still unsure whether out-of-state companies with information about Californians must comply
Numbers: ITIL, COBIT and More; Who Uses What?
Adoption rates around the world for ITIL and other guidelines. From the 2007 Global Information Security Survey.
PCI: Smart or Stupid?
The data security standard isn't as complex as some would have you believe
