Security News

NIST Cybersecurity Framework: A Quick Guide for SaaS Security Compliance
2022-01-06 08:11

The framework enables organizations to improve the security and resilience of critical infrastructure with a well-planned and easy-to-use framework. Although the CSF was written and updated while SaaS was on the rise, it is still geared towards the classic legacy critical infrastructure security challenges.

CISA Compliance for 2022
2021-12-20 07:04

With the end of the year rapidly approaching, IT professionals should put cyber security at the top of their New Year's resolutions. The reason why this is such a problem is because users very often use their work passwords on various websites to minimize the number of passwords that they must remember.

An introduction to U.S. data compliance laws
2021-11-22 06:30

It applies to companies that control or process personal data of 100,000 or more consumers in a calendar year, or those that control or process personal data of at least 25,000 consumers and derive over half of their gross revenue from the sale of personal data. Colorado Privacy Act: Businesses that operate out of Colorado or collect personal information from Colorado residents must comply with the CPA. It emphasizes the need for organizations to follow existing data protection policies such as HIPAA, and it gives consumers the right to opt out of targeted advertising and having their data sold, among other benefits.

Illuminating the path: Compliance as the key to security-by-design
2021-11-17 07:00

The result of these "Efforts" is often a slapped-together, ad-hoc project that may very well get the job done in the moment, but it doesn't adhere to any sort of best practices, does little to benefit future compliance undertakings, and misses a huge opportunity to bake-in security from the start. As a result, companies lose out on the opportunity to effectively bolster security and security best practices.

Cloud compliance: Falling out of it could spell doom
2021-11-16 06:52

In this Help Net Security interview, Bill Tolson, VP of Global Compliance and eDiscovery at Archive360, talks about the importance of cloud compliance and what companies can do meet the requirements when shifitng to the cloud. What industries are more at risk of cloud compliance issues and why?

When it comes to collaboration tools, firms struggle to keep up with security and compliance
2021-10-26 03:00

Surveying 100 key executives across financial services, Theta Lake found that 83% of respondents are turning off key productivity and usability features of collaboration platforms like Zoom, Microsoft Teams, and Webex due to their organizations' technical inability to adhere to relevant regulatory compliance and security requirements. Collaboration tools need appropriate compliance oversight The top three collaboration features considered to be threats or challenges to privacy and security include: files uploaded or transferred in chats, links shared in chats or onscreen and screenshares.

Compliance does not equal security
2021-10-19 06:00

Compliance was the primary driver for many businesses to build a cyber security program. Starting with frameworks like The Health Insurance Portability and Accountability Act and Visa's Cardholder Information Security Program - which later evolved into the Payment Card Industry Data Security Standards, or PCI DSS - failure to meet compliance requirements was met with strict penalties that included hefty fines or the inability to process payments.

Which technologies can help legal and compliance teams navigate a changing landscape of risk?
2021-10-07 05:00

In this interview with Help Net Security, Zack Hutto, Director of Advisory Services at Gartner's Legal and Compliance Practice, talks about the challenges legal and compliance teams are facing and the technologies that can help them. As digital transformation initiatives continue - or accelerate due to the pandemic - and many companies consider strategic pivots, legal and compliance teams face both new risks and shifting risk tolerances, forcing teams to adapt their advice and support to their respective organizations.

Organizations putting security and compliance at the forefront to strengthen trust perceptions
2021-10-07 04:00

Organizations are more frequently embedding trust metrics into their request for proposals to ensure that potential vendors can also be trusted ecosystem partners. Trusted ecosystems help improve an organization's brand, reputation, and strengthen trust perceptions, which, in turn drive stronger business performance.

Mobile app creation: Why data privacy and compliance should be at the forefront
2021-09-13 05:30

Creating such a custom-made experience requires collecting personal data - and when considering the criticism massive tech companies are garnering for their misuse of sensitive information - mobile app developers must prioritize data privacy and compliance. Data privacy and security and the mobile app creation process.