DoD efforts to shore up security extends to vendors, partners, and suppliers

As the Department of Defense continues its efforts to improve security provisions and practices for handling its information — especially with respect to sensitive but unclassified data — it is expanding its focus beyond its own…

Carrot or stick on cybersecurity?

Interesting post from GovInfoSecurity.com’s Eric Chabrow a couple of days ago, in which he borrows some conclusions from a Frontline documentary on the airline industry called “Flying Cheap” and applies them to the current debate about…

More action, not just talk, needed on cybersecurity

Former acting federal cybersecurity chief Melissa Hathaway used the public forum afforded her by the Internet Security Alliance yesterday to warn that the government is losing the sense of urgency it needs to tackle the many…

There’s a lot to think about from FTC privacy roundtables

The Federal Trade Commission (FTC) has now completed two of its three scheduled roundtable discussions as part of the “Exploring Privacy” series. The focus of these sessions is to raise and discuss issues, not to try…

Information sharing actions in the name of national security test international privacy laws

The Secure Flight program recently implemented under the authority of the Transportation Security Administration (TSA) is raising a number of privacy issues not just in the United States, but also in foreign countries whose privacy laws…

Policies without enforcement simply aren’t enough to guard against internal threats

Two recent studies of financial sector employees, sponsored by security vendors Cyber-Ark and Actimize, and reported last week by Tim Wilson of InformationWeek, indicate that employees are ready and willing to steal information from their employers,…

More options, no resolution on bridging public and private sector security standards

As regularly noted in this space, one of the big points of disagreement in attempts to achieve greater levels of information integration, particularly health information exchanges, is how to reconcile disparate security and privacy standards in…