Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Enterprise security executives need to make practices such as safe USB use and discreet handling of patient or customer data as commonplace as not accepting luggage from strangers in airports or wearing a seat belt when driving. . But they can't do it alone; it takes an entire organization to secure corporate assets, protect data from breaches and make sure enterprisewide risk remains low. "Security is everyone's responsibility," says John Kirkwood, vice president of Information Security Strategy at American Express, who spoke recently at a Boston seminar hosted by risk-management company Consul. Kirkwood, formerly chief information security officer at the financial services giant, says his role has evolved from security policy maker to enterprise risk-management evangelist. "Security has gone from being a server room concern to a boardroom type of issue," he says. The link for this article located at Network World is no longer available. . Comprehensive collaboration is vital for safeguarding company resources and maintaining robust information security.. Enterprise Security, Data Protection Strategies, Risk Management Strategies. . Brittany Day
Corporate governance and regulation were one of the dominant themes of 2004 and look set to continue to be so throughout 2005. Corporate governance relates to how an organisation is run, and has repercussions for almost every department – particularly Finance, HR, Auditing, Procurement and IT. Due to the nature of the potential content of email, ranging from a simple customer query to financial projections, the use of this application demands particular attention to ensure that its management helps to secure regulatory compliance. . From the late 1990s, numerous new regulations have been introduced in both the United States and Europe, often in the wake of corporate scandals where unethical business practices fell foul of existing financial reporting and disclosure rules. The backlash from these high profile episodes prompted newer corporate compliance legislation, such as Basel II in Europe and Sarbanes-Oxley in the United States. This is now being implemented alongside the likes of the EU Data Protection Directives and the Privacy & Electronic Communications Regulation, to ensure that companies put and keep their houses in order. The link for this article located at Help Net Security is no longer available. . From the late 1990s, numerous new regulations have been introduced in both the United States and Eur. corporate, governance, regulation, dominant, themes, continue. . LinuxSecurity.com Team
Employee misuse of corporate e-mail has been a source of liability for numerous organizations, and many are now moving to develop policies that define appropriate usage. Businesses are also increasingly adopting policies to ensure that government regulations are met, sensitive business . . . . Employee misuse of corporate e-mail has been a source of liability for numerous organizations, and many are now moving to develop policies that define appropriate usage. Businesses are also increasingly adopting policies to ensure that government regulations are met, sensitive business data is secure and customer privacy is protected. Below, in no particular order, are the top 10 things IT policy-makers should consider when developing corporate e-mail policies. One of a company's paramount concerns when developing a corporate e-mail policy should be to explicitly define what constitutes acceptable use of the organization's e-mail system. The policy should clearly state whether personal use is permitted, and if so, how much (number of e-mail messages, percentage of hours in the office, etc.). If employees are granted personal use, steps should be taken to outline what types of correspondence and content will be considered unacceptable or offensive. The link for this article located at ComputerWorld is no longer available. . Establishing robust data protection protocols is essential to ensure the confidentiality of critical data and adhere to legal standards.. Secure Communications, Email Policy, Corporate Governance, Data Protection, Employee Conduct. . LinuxSecurity.com Team
The British government has urged companies to take IT security more seriously, amid concern that almost three-quarters of firms have no policy on information security. Speaking at an event in London on Tuesday, e-commerce minister Stephen Timms said it is . . . . The British government has urged companies to take IT security more seriously, amid concern that almost three-quarters of firms have no policy on information security. Speaking at an event in London on Tuesday, e-commerce minister Stephen Timms said it is unacceptable that just 27 percent of companies have an IT security policy, according to a recent official survey. Timms believes that many senior company executives are failing to give enough attention and resources to this critical issue. "If only 27 percent of companies actually have a policy on this issue then the challenge of engaging the other 73 percent of company boards is a real and important one," said Timms. "This basic failure to set objectives and goals fed through into the survey's findings of a host of management shortfalls -- under-investment, lack of analysis of investment, lack of appropriate personnel policies, security processes and technical security," he added. Timms was speaking in London at the Information Assurance Advisory Council's third annual symposium, where he also explained that the government is promoting best practice standards to address the issue. The link for this article located at ZDNet is no longer available. . The UK authorities stress the importance of safeguarding information technology, noting that a significant number of companies do not have adequate measures and funding in place.. IT Security Policies,Risk Management Strategies,Corporate Governance. . Anthony Pell
Move over, CEO, CIO, and COO. Your titles are passe compared to the newest position in high demand from corporate headhunters -- Chief Privacy Officer. With consumers increasingly concerned about their privacy and new technology able to track Internet users . . . . Move over, CEO, CIO, and COO. Your titles are passe compared to the newest position in high demand from corporate headhunters -- Chief Privacy Officer. With consumers increasingly concerned about their privacy and new technology able to track Internet users click by click, companies are rapidly hiring privacy officers and giving them broad powers to set policies that protect consumers from invasion and companies from public relations nightmares. . Move over, CEO, CIO, and COO. Your titles are passe compared to the newest position in high demand f. titles, passe, compared, newest, position, demand. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.