Security teams need to look at the controls they have put in place in their organization and question whether they are shifting risky behavior to different areas and perpetuating problems, says Intel CISO Malcolm Harkins.
The new virtualization guidance issued by the PCI Security Standards Council urges organizations to take a risk-based approach when dealing with virtualization methods, especially within cardholder data environments.
The release of the list coincides with the issuance of the Common Weakness Scoring System that allows software makers to identify vulnerabilities in their programs and buyers to determine software they acquire is secure.
In a case weighing privacy vs. free speech, the U.S. Supreme Court has struck down a Vermont law that requires physicians to give their consent before information about their prescription-writing habits can be sold to help market prescription drugs.
Federal officials should offer detailed guidance on how to conduct a "risk of harm" assessment to comply with the HITECH Act Breach Notification Rule, says Harry Rhodes, director of practice leadership at the American Health Information Management Association.
"It's not enough to know the architecture of the breach system," says Michael Aisenberg of MITRE Corp. "Leaders have to understand the different jurisdiction of where they do business, where their customers are and which breach law applies."
The Office of the National Coordinator for Health IT will soon seek feedback on using certain existing standards for metadata for specific purposes, such as to indicate a patient's privacy preferences, within electronic health records. ONC will then consider the comments before deciding whether to require the use of...
The new orders, signed a month ago by President Obama, detail when the military must seek presidential approval for a specific cyberassault on an enemy and weave cyber capabilities into U.S. war fighting strategy, the AP reports.
Authorities charged Ryan Cleary with distributed denial of service attacks on a British law enforcement agency that LulzSec claimed it hacked on Monday. Police also charged the suspect with attacks claimed by the group Anonymous against two music industry sites last fall.