05/08/2012 | Governance, Risk & Compliance
View this short video to see what you can expect when you attend the Risk & Compliance track at IANS' Information Security Forums!
03/30/2012 | Governance, Risk & Compliance
The Risk and Compliance track at the IANS Mid-Atlantic Information Security Forum was led by Faculty members Randy Sabett and Alex Hutton. Because security personnel are often asked by their employers to wear the hats of law enforcement, auditors, and regulators, IANS delegates are always keen to hear from our resident legal counsel how to best deal with the growing burden that
03/15/2012 | Regulations & Legislation
Most organizations that hold sensitive information likely have at least a rudimentary data breach response plan in place. For many companies, it’s a regulatory or contractual requirement. Other companies may do it as a best practice. In this End User Client Briefing, Randy Sabett answers questions like: Who do you call? When do you call them? What happens during the engagement?
03/14/2012 | Regulations & Legislation
Most organizations that hold sensitive information likely have at least a rudimentary data breach response plan in place. For many companies, it’s a regulatory or contractual requirement. Other companies may do it as a best practice. In this End User Client Briefing, Randy Sabett answers questions like: Who do you call? When do you call them? What happens during the engagement?
03/06/2012 | Governance, Risk & Compliance
Cloud governance is an area that security teams are internally debating and refining more than ever before. Governance describes how different groups work with each other, report to each other, provide data and metrics to each other, and so on. In a cloud relationship it is necessary to strike a balance between the cloud service provider (CSP) and consumer. In this document Dave
02/07/2012 | Enterprise Risk Management
The current wave of consumerization of IT will not wane any time soon. The next decade will be marked by a growing amount of consumer-grade technology, which will continue to bleed over into the corporate environment. This document will address the steps an organization can take to securely allow personally liable mobile devices on the corporate network, keeping in mind legal and
12/27/2011 | Governance, Risk & Compliance
The Risk and Compliance track at IANS’ Forums focuses on the relationships and interactions between policy, legislation, and government on one hand, and data security on the other hand. In a nutshell, this is the track that deals with all of the shades of grey around liability and legal obligations. Among other issues, this track addresses applicable laws and regulations (
12/14/2011 | Enterprise Risk Management
“Information risk” is a tricky topic with which many IANS client grapple. For most security professionals, there is a fine line to walk between offering up the right amount of information and spreading FUD throughout their companies. Combining his experiences from the Verizon Business RISK Team, a top 25 financial institution, and several other major organizations, IANS Faculty
10/27/2011 | Governance, Risk & Compliance
With the rapid blurring of information borders, IANS clients, typically large, multinational organizations, often ask how to protect their data assets, especially as it pertains to international communication. Because laws, rules, and regulations can quickly become too cumbersome to manage, IANS Faculty Jeffrey Ritter provides his thoughts on how to start creating an effective
09/28/2011 | Enterprise Risk Management
In a world where borders are blurring and social media is the prevalent form of communication, Hart Rossman, IANS Faculty and CTO at SAIC, recommends taking a progressive approach to information security that will create greater value for the security professional as well as his/her organization as a whole. In the following interview, Hart shares his thoughts on why and how