<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itsecuritylink.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>ISL | Security Compliance</title>
 <link>http://www.itsecuritylink.com/security_compliance</link>
 <description>IT Security Link | Security Compliance</description>
 <language>en</language>
<item>
 <title>HIPAA In Court &amp; Bogus HIPAA &quot;Certifications&quot;</title>
 <link>http://www.itsecuritylink.com/node/153</link>
 <description>&lt;p&gt;
HIPAA enforcement within the U.S. officially got underway with the first sanction applied the the Department of Health and Human Resources (HHS) in July; I blogged about it &lt;a href=&quot;http://www.realtime-itcompliance.com/noncompliance_sanctions_exampl/2008/07/first_hipaa_sanction_applied_1.htm&quot;&gt;here&lt;/a&gt;.
&lt;/p&gt;</description>
 <comments>http://www.itsecuritylink.com/node/153#comments</comments>
 <pubDate>Mon,  1 Sep 2008 09:57:37 +1000</pubDate>
 <dc:creator>Rebecca Herold</dc:creator>
 <guid isPermaLink="false">153 at http://www.itsecuritylink.com</guid>
</item>
<item>
 <title>The Need For Information Security &amp; Privacy Training &amp; Awareness</title>
 <link>http://www.itsecuritylink.com/node/149</link>
 <description>&lt;p&gt;</description>
 <comments>http://www.itsecuritylink.com/node/149#comments</comments>
 <pubDate>Tue,  1 Jul 2008 23:27:05 +1000</pubDate>
 <dc:creator>Rebecca Herold</dc:creator>
 <guid isPermaLink="false">149 at http://www.itsecuritylink.com</guid>
</item>
<item>
 <title>U.S. HIPAA (Non)Enforcement&#039;s Bigger Hammer</title>
 <link>http://www.itsecuritylink.com/node/140</link>
 <description>&lt;p&gt;
Last fall the U.S. Department of Health and Human Services (HHS) &lt;a target=&quot;_blank&quot; href=&quot;http://www.realtime-itcompliance.com/privacy_and_compliance/2007/09/the_first_ever_hipaa_audit_whe.htm&quot;&gt;contracted the help of Pricewaterhouse Coopers (PwC) to start doing HIPAA compliance audits for them&lt;/a&gt;. 
&lt;/p&gt;</description>
 <comments>http://www.itsecuritylink.com/node/140#comments</comments>
 <pubDate>Sun, 18 May 2008 04:07:05 +1000</pubDate>
 <dc:creator>Rebecca Herold</dc:creator>
 <guid isPermaLink="false">140 at http://www.itsecuritylink.com</guid>
</item>
<item>
 <title>Trust Is Not A Control</title>
 <link>http://www.itsecuritylink.com/node/137</link>
 <description>&lt;p&gt;
Trust is very important to successful business.  Trust is a result of validated reliance upon another person or entity. 
&lt;/p&gt;
&lt;p&gt;
Trust is NOT a control. 
&lt;/p&gt;</description>
 <comments>http://www.itsecuritylink.com/node/137#comments</comments>
 <pubDate>Thu,  3 Apr 2008 04:12:01 +1100</pubDate>
 <dc:creator>Rebecca Herold</dc:creator>
 <guid isPermaLink="false">137 at http://www.itsecuritylink.com</guid>
</item>
<item>
 <title>The U.S. FTC Is Losing A Great Privacy Watchdog</title>
 <link>http://www.itsecuritylink.com/node/130</link>
 <description>&lt;p&gt;
I was surprised to see &lt;a target=&quot;_blank&quot; href=&quot;http://www.ftc.gov/opa/2008/02/majleave.shtm&quot;&gt;an announcement from February 28 that U.S. Federal Trade Commission (FTC) Chairman Deborah Platt Majoras is leaving the FTC at the end of March&lt;/a&gt;.
&lt;/p&gt;</description>
 <comments>http://www.itsecuritylink.com/node/130#comments</comments>
 <category domain="http://www.itsecuritylink.com/taxonomy/term/9">members_opinions</category>
 <pubDate>Tue, 11 Mar 2008 00:51:29 +1100</pubDate>
 <dc:creator>Rebecca Herold</dc:creator>
 <guid isPermaLink="false">130 at http://www.itsecuritylink.com</guid>
</item>
<item>
 <title>The Great Managed Perimeter Security Services Swindle</title>
 <link>http://www.itsecuritylink.com/node/124</link>
 <description>Maybe that is too harsh a title to describe most &quot;managed services&quot; provided by vendors to clients....maybe not?!

The question needs to be asked though. When is the last time a client seriously looked at what they were getting for their large investment and asked some questions of the vendor and most importantly of themselves.
</description>
 <comments>http://www.itsecuritylink.com/node/124#comments</comments>
 <pubDate>Thu, 14 Feb 2008 09:40:58 +1100</pubDate>
 <dc:creator>Drazen Drazic</dc:creator>
 <guid isPermaLink="false">124 at http://www.itsecuritylink.com</guid>
</item>
<item>
 <title>Good Compliance Practices - Ignorance is No Longer Bliss</title>
 <link>http://www.itsecuritylink.com/node/107</link>
 <description>If the Payment Card Industry Data Security Standard (PCI DSS) has done one thing, it’s been to highlight that there are such things as basic, good security practices. &lt;br /&gt;
</description>
 <comments>http://www.itsecuritylink.com/node/107#comments</comments>
 <pubDate>Wed, 19 Sep 2007 11:27:06 +1000</pubDate>
 <dc:creator>Drazen Drazic</dc:creator>
 <guid isPermaLink="false">107 at http://www.itsecuritylink.com</guid>
</item>
</channel>
</rss>
