|
Ethical
Hacker
CISSP
|
New laws are in place to make someone in your
organization, often Sr. management, liable for
not showing documented proof of due diligance
in protecting the client information.
CA SB1386
is a fairly new bill that can hold Sr. management
liable in courts for civil damages or face class
action lawsuits. The law covers every enterprise,
public or private, doing business with California
residents and mandates public disclosure that
a security breach has occurred, which can ruin
the reputation of any business.
The Health
Insurance Portability and Accountability Act
(HIPAA) Privacy Rule became effective April
14. The HIPAA Privacy Rule is federal law, that
carries penalties of up to $250,000 in fines
and jail time of up to 10 years. The rule applies
to "electronic protected health information"
-- essentially, patients' medical records and
other personal health care information. It affects
every company that transmits protected health
information in electronic form, which includes
health plans, health care clearinghouses and
health care providers. Full compliance requires
these entities to understand the threats and
liabilities to this protected data and that
they implement a wide variety of safeguards
and security best practices.
The Gramm-Leach-Bliley
Act signed into law on Nov. 12, 1999 requires
financial institutions to Assess Risk, Manage
and Control Risk, Oversee Service Providers,
and Adjust security programs as needed based
on changing risk. One specific provision requires
the business to "Identify reasonably foreseeable
internal and external threats that could result
in unauthorized disclosure, misuse, alteration,
or destruction of customer information or customer
information systems."
We can have security professionals with real-world
experience to help you by:
- Penetration testing to test your perimeter
- Internal security assessment to internal
threats
- HIPPA compliant
- Risk assessment, documenting your vulernabilities,
and aid in reducing your risks to those vulnerabilities.
- Policies and procedures
|