Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Gmail HTTPS Doesn't Protect Account, New Setting Does
  • Online Movement Aims to Punish Democrats Who Support Bush Wiretap Bill
  • Apple developing 'stealth' biometric security for iPhone
  • U.S. May Ease Police Spy Rules
  • FBI's Gag Order Lifted, Brewster Kahle (Internet Archive) Speaks!
  • No, *really*, DirecTV -- don't call me!
  • A Wave of the Watch List, and Speech Disappears

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

The top 5 mistakes of privacy awareness programs

Submitted by MacRonin on February 8, 2010 - 12:48pm
  • Companies
  • Databases
  • Editorial
  • Hmmm
  • How-To
  • ID
  • Infrastructure
  • Person Career
  • Privacy
  • Security
  • Standards

The top 5 mistakes of privacy awareness programs: Via Computerworld Privacy News.

Privacy consultant Jay Cline identifies the errors companies often make when trying to educate employees about data protection.

The Health Insurance Portability and Accountability Act requires it. The Payment Card Industry Data Security Standard requires it. The ISO 27001 standard requires it. In fact, every regulation that mandates that reasonable measures be taken to protect information implicitly requires companies to set up training programs to help employees understand what those measures are.

But what does training actually mean?

Many corporations have adopted a check-box approach toward compliance with this obligation. Here are five shortcuts I see them taking instead of using the opportunity to ensure that employees really know how to protect information.

1. Doing separate training for privacy, security, records management and ethics. Do you get one message from your chief privacy officer, one from your chief information security officer, and an annual sign-off on the code of ethics from your legal department? You're not alone. In large companies, the people responsible for specific functions don't want to dilute their messages by mixing them with related topics. So they each go their own way with training and awareness. The result is confused employees who just want one place to go to learn the do's and don'ts of information management.

2. Equating campaign with program. When executives get money to spend on "soft" projects like privacy training, the natural first step is to launch an awareness campaign. Some deploy computer-based training modules. Once they do that, they might think that they have a program in place. But there's a difference between hitting employees with one or two messages a year and surrounding them with reminders that the policies are real, have teeth and are baked into the culture. A true training program has an annually refreshed calendar of messages and training for different employee groups throughout the year.

[...]

Read Original Article:(Via Computerworld Privacy News.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.