Mark Ballard reports: Staff working for Her Majesty’s Courts Service have breached security on the government database that stores personal data about everyone in the UK. Also, local authorities sacked 26 employees last year for snooping on personal data stored on the Department for Work and Pensions (DWP) Customer Information System (CIS), which, with 90…
Category: Commentaries and Analyses
Visa To Acquirers: Stop Forcing PAN Retention
Evan Schuman writes: Visa on Wednesday (July 14) sent a direct message to acquiring banks: Stop making retailers retain credit card information unless you want to stop servicing Visa. A key Visa security executive (Eduardo Perez, the head of global payment system security) said the brand is now merely “strongly encouraging [acquirers] to not require”…
No more anonymous “private practice” on HHS breach list
HHS has now started revealing the names of the HIPAA-covered entities who had previously been listed only as “private practice” in their list of those having breaches affecting 500 or more individuals. PHIprivacy.net had been one of a number of entities that had complained about private practices being shielded, but OCR had interpreted the Privacy…
Data Breaches: A Black Hole – ITRC
The Identity Theft Resource Center is singing to this choir. Their most recent press release: As of June 30th, The Identity Theft Resource Center® recorded 341 individual breaches for the first six months of 2010. Unfortunately, hundreds of breaches have been veiled from the public, delayed in publication, or not listed on any public lists….
Hacker in AT&T iPad case breaks gagging order
Andy Carvell writes: An alleged hacker has broken the terms of a gagging order to speak out about his arrest and prosecution in an extraordinary rant on his group’s website. Last month, hackers exposed an embarrassing security flaw affecting iPad customers on AT&T, causing red faces all round at the telecoms provider. Shortly after the…
Information Security: Governmentwide Guidance Needed to Assist Agencies in Implementing Cloud Computing
From Information Security: Governmentwide Guidance Needed to Assist Agencies in Implementing Cloud Computing GAO-10-855T (pdf), July 1, 2010 Summary Cloud computing, an emerging form of computing where users have access to scalable, on-demand capabilities that are provided through Internet-based technologies, reportedly has the potential to provide information technology services more quickly and at a lower…