CSO's desk Articles

No silver bullet for PCI compliance

Eduardo Perez, chairman, PCI Security Standards Council April 01, 2011

All around the world, organizations are moving toward the adoption of updated PCI standards so that they can begin 2012 with assessments against the newest iterations.
 

Post-WikiLeaks: Back to basics

Maurice Hampton, information security and privacy services leader, Clark Schaefer Consulting March 01, 2011

Dust off your company's risk assessment process and make sure it is up to date because this is where your approach to defending against a WikiLeaks type of threat is going to start.
 

Think like a chess player

Ward Spangenberg, director, security operations, Zynga February 01, 2011

The security chief of Zynga offers tips for deterring today's sophisticated attacks. They include understanding attack vectors, quantifying risk, controlling damage and being a trusted leader.
 

The dotted lines of health care

Bryan Cline, CISO and director of information security at Catholic Health East January 03, 2011

Health care chief information security officers (CISOs) have to ask themselves, "What exactly are the security and privacy requirements around EHR?"
 

A change to protect card data

Bruce Rutherford. chairman, PCI Security Standards Council December 01, 2010

From my perspective, 2010 has been a critical year for global payment card security efforts that may ultimately result in a significant reduction in future payment card fraud levels, says Bruce Rutherford, chairman, PCI Security Standards Council.
 

Reducing compliance workloads

Jerry Archer, SVP & CSO, Sallie Mae November 01, 2010

Security is not compliance, and compliance is not security.
 

Don't forget the business process

Stacey Halota, VP, information security and privacy, The Washington Post Co. October 01, 2010

To get a complete picture of where critical information resides, it is very important to inventory at the business process level, says the Washington Post Co.'s Stacey Halota.
 

A cyber bridge for the mountain stream

Ron Baklarz, CISO, Amtrak September 01, 2010

There is a lack of sufficient filtration and protections of internet traffic as implemented by the ISPs.
 

Security is a collaborative effort

Kris Rowley, CISO, state of Vermont August 02, 2010

It is imperative that a team approach be used to meet the security needs of state business, says Kris Rowley, CISO, state of Vermont.
 

Breaking compliance down

Maurice L. Hampton, information security & privacy services leader, Clark Schaefer Consulting July 01, 2010

I am still amazed by the number of organizations that still don't have all of the right people working toward a singular goal of compliance for the organization, says Maurice L. Hampton, information security & privacy services leader, Clark Schaefer Consulting.