Remove category
article thumbnail

Security Compliance & Data Privacy Regulations

eSecurity Planet

But those aren’t the only laws or regulations that affect IT security teams. There are plenty of others to worry anyone with job titles that include terms like “compliance,” “privacy,” and “security,” from CSOs on down. See the Top Governance, Risk and Compliance (GRC) Tools. PIPL Raises the Bar – And the Stakes.

article thumbnail

First American Financial Pays Farcical $500K Fine

Krebs on Security

Under First American’s documented vulnerability remediation policies, the data leak was classified as a security weakness with a “level 3” severity, which placed it in the “medium risk” category and required remediation within 45 days. “That’s a high-risk vulnerability.

Insurance 286
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

What is information classification and how is it relevant to ISO 27001?

IT Governance

Originally published 26 June 2013. Information classification is a process in which organisations assess the data that they hold and the level of protection it should be given. Organisations usually classify information in terms of confidentiality – i.e. who is granted access to see it. appeared first on IT Governance Blog.

IT 69
article thumbnail

NIST Releases Final Cybersecurity Framework

Hunton Privacy

On February 12, 2014, the National Institute of Standards and Technology (“NIST”) issued the final Cybersecurity Framework , as required under Section 7 of the Obama Administration’s February 2013 executive order, Improving Critical Infrastructure Cybersecurity (the “Executive Order”).

article thumbnail

Department of Commerce Issues Notice of Inquiry Regarding Incentives to Adopt Improved Cybersecurity Practices

Hunton Privacy

On March 28, 2013, the Department of Commerce’s Notice of Inquiry into “Incentives to Adopt Improved Cybersecurity Practices” was published in the Federal Register (78 Fed. The Notice of Inquiry provides a 30-day comment period and states that Commerce will submit its recommendations to the President no later than June 12, 2013.

article thumbnail

Malaysian Data Protection Law Takes Effect

Hunton Privacy

On November 14, 2013, the Minister of the Malaysian Communications and Multimedia Commission (the “Minister”) announced that Malaysia’s Personal Data Protection Act 2010 (the “Act”) would be going into effect as of November 15, marking the end of years of postponements. The law imposes cross-border transfer restrictions.

article thumbnail

Partnering With Tech and Fintech Firms: Key EU/UK Regulatory Considerations for the Payments Sector

Data Matters

In addition, banks are subject to extensive ongoing regulatory requirements, including in respect of governance, risk management, capital, and liquidity, which a fintech or technology firm may not have the ability to meet without making substantial changes to its policies, procedures, and operations. Adopt a mixed strategy.