Forensic examination of secondhand disks
Labels: Compliance, Confidentiality, Forensics, Privacy
Information security news and hot links from NoticeBored, the creative information security awareness service.
Labels: Compliance, Confidentiality, Forensics, Privacy
Labels: Compliance, Confidentiality, Infosec, Law, Privacy

Labels: Compliance, Governance, Infosec, IPR, ISO27000
Labels: Compliance, Risk
Labels: Awareness, Compliance, Infosec, ISO27000, Physical
Labels: Awareness, Compliance
Labels: Accountability, Awareness, Bugs, Change, Compliance, Incidents, Insider, Malware, Office, Risk
"The City watchdog says Norwich Union's life assurance unit did not have effective systems and controls in place to protect customers' confidential information and manage financial crime risks. These failings resulted in a number of actual and attempted frauds against policyholders. Slack call centre security allowed fraudsters to use publicly available information - including names and dates of birth - to impersonate customers and obtain sensitive customer data, says the FSA. In some cases criminals were able to ask for confidential customer records, such as addresses and bank account details, to be altered. The fraudsters then used the information gleaned to request the surrender of 74 customers' policies totalling £3.3 million in 2006. The FSA says its investigation found that Norwich Union Life failed to properly assess the risks posed by financial crime and as a result, its customers were more likely to fall victim to identity theft."
Labels: Compliance, ID theft, Incidents, Privacy, Social engineering
" AB 1298 adds two new breach-triggering data categories to the law of “health insurance information” defined as a health insurance policy or subscriber number(s), any information in an individual’s application and claims history, including any appeals records; and “medical information” including any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional."
Labels: Compliance, ID theft, Law, Privacy
Labels: Compliance
Labels: Compliance
Labels: Compliance
Labels: Compliance
Labels: Compliance
Labels: Audit, Compliance
"This is an automatically generated Delivery Status Notification.
Delivery to the following recipients failed.
abuse@bsi-global.com"
Labels: Compliance

Labels: Awareness, Compliance