Category: Compliance Standards

Staying informed about all of the cyber security compliance standards is essential to keeping your company safe from hackers. Read on to learn about the various steps you can take to stay up to date with your industry’s compliance standards.

  • What Is The Patch Management Process For NERC CIP?

    What Is The Patch Management Process For NERC CIP?

    The electric utility industry is built on a foundation that requires an ultimate level of security to operate effectively.  As hackers multiply and their level of sophistication increases rapidly, the electric utility industry must also evolve its cybersecurity defense capabilities.  A recent survey of 140 North American electric utilities found that 88% of respondents expect cyberattacks to increase within the next 2 to 3 years.  That figure is meteoric and most likely slightly distressing for those bulk power system (BPS) operators that haven’t gotten up to speed on patching their software vulnerabilities quite yet.

    (more…)

  • How to Achieve NERC CIP Compliance

    How to Achieve NERC CIP Compliance

    Access to a stable power source is a central component of our daily lives in the modern United States. Power generation, transmission, and delivery has been designated critical infrastructure in the United States, and as such is subject to heightened regulatory scrutiny and security requirements.

    One of the most important regulatory bodies ensuring the security of our critical power infrastructure is the North American Electric Reliability Corporation (NERC). NERC is a not-for-profit corporation that has been granted regulatory authority over the bulk power delivery system in the United States. Maintaining compliance with NERC regulatory standards is an ongoing requirement for entities that fall within the scope of the bulk power system. In this article, we’ll break down what NERC is, what NERC does, and outline how entities within the bulk power system can achieve Nerc compliance through a Nerc compliance program.

    (more…)

  • How Do Cryptocurrency Exchange Providers Stay Protected Against Hackers?

    How Do Cryptocurrency Exchange Providers Stay Protected Against Hackers?

    Cryptocurrencies have been rocking the news headlines for the past few years due to their unprecedented rise in value that has seen people become millionaires from making small investments in them.  Although there has been news of people making loads of money from these investments, there have also been a plethora of stories pertaining to cryptocurrency exchange providers being breached by hackers.  

    The anonymous nature of transactions that some exchanges and cryptocurrency use have led hackers to hone in on these websites and steal billions of dollars in cryptocurrencies from miners and customers alike over the years.  Many of these hacks have led to the short and swift demise of these cryptocurrency exchange providers due to the sheer quantity of breached accounts and value of cryptocurrency that were been stolen.

    (more…)

  • Top 5 Security Breaches of Cryptocurrency Exchange Providers

    Top 5 Security Breaches of Cryptocurrency Exchange Providers

    Cryptocurrency is a constant source of media attention.  It’s new-ish, digital, and an insanely lucrative endeavor to get into.  This perfect storm of positives is the main reason why many people are making a ton of money from mining and selling off their cryptocurrencies.  But even with all the positives that investors can receive from their cryptocurrency efforts, hackers still pose a considerable threat to their sizable profits.  

    (more…)

  • What is the Experian Independent 3rd Party Assessment (EI3PA)?

    What is the Experian Independent 3rd Party Assessment (EI3PA)?

    For a variety of financial service companies, dealing with the credit history of customers is part and parcel of doing business. Whether its issuing a credit card or financing a small business, banks, lenders, and other service providers and institutions routinely utilize credit data from companies like Experian to make the most appropriate business decisions. But theres just one catch – financial institutions need to be careful (and compliant) in the way they handle private credit history information thats shared with them from Experian data.

    (more…)

  • Consequences of Non-compliance With CalOPPA

    Consequences of Non-compliance With CalOPPA

    In 2003, California became the first state in the country to set robust strictures on the visibility of online consumer data. The California Online Privacy Protection Act, also known as CalOPPA, created regulations that required online websites and businesses to prominently display their Privacy Policy in regard to their users data.This law aimed to protect online users’ data and to inform them as to how their data might be tracked, mined, stored, trolled, sold, used, or shared. As of now, the posting of this notification is mandatory for any business or website that accrues personally identifiable information from California residents. CalOPPA states, [A website must] conspicuously post its Privacy Policy on its Web site, or in the case of an operator of an online service, make that policy available. If you are an online business found in non-compliance, if you do not clearly convey to your customers what data you collect, how you collect it, and what you plan to do with it, there are potentially severe ramifications that could cripple your business.

    (more…)

  • California Privacy Policy: What is CalOPPA?

    California Privacy Policy: What is CalOPPA?

    Established in 2003, The California Online Privacy Protection Act (CalOPPA) was the very first state law in the United States that required commercial and online websites to post their privacy policy to the general public. The goal of this act was to protect online users from having their data mined, stored, used, or sold, without their knowledge or consent.

    (more…)

  • Tracking and monitoring all access to network resources and cardholder data (PCI DSS Reqs. 3, 7, 10)

    Tracking and monitoring all access to network resources and cardholder data (PCI DSS Reqs. 3, 7, 10)

    Recent statistics have shown that 42% of consumers feel that credit cards are the safest payment option to protect cardholder data for their online purchases. With more consumers focusing on purchasing online rather than via brick and mortar retailers, this means that online retailers must take extra care in monitoring their network resources as they pertain to their cardholder data. Consumers are well within their entitlement to expect that their credit card transaction is secure once it has been processed. However, that expectation might fall short if the pathways that the payment company develops does not securely transmit their cardholder data once the transaction goes through. It is for this reason (and many others) that securing access to network resources for any organization that processes and/or stores credit card payments is critical.

    (more…)

  • What You Need to Know About NIST Password Guidelines

    What You Need to Know About NIST Password Guidelines

    Almost every online interaction, whether it be a financial transaction, company login, or a simple email conversation, requires the use of a password. With data breaches becoming more common and prolific, passwords have evolved into complex strings of characters that are difficult to remember. Ironically, this conundrum has resulted in stores selling password books for recording all the numerous credentials individuals use on a daily basis; however, this defeats the very purpose of passwords. Consequently, the National Institute of Science and Technology (NIST) began researching past data breaches and experimenting with various password structures to identify better authentication practices. Besides providing NIST definitions for cloud computing, the NIST has also now provided guidelines to create safer passwords. Do you know how to create a safe and effective password for your profiles? Learn about NIST password guidelines and NIST compliance by reading on.

    (more…)

  • How to Improve Your Security With NIST

    How to Improve Your Security With NIST

    Business owners should know the answer to the question, how prepared is your business to face cyber threats? However, most do not. The National Institute of Standards and Technologys (NIST) cybersecurity framework is one of the most recognized structures for improving sensitive data security against todays cyber threats from all devices. Meant to be a voluntary framework for taking security measures to identify and minimize cybersecurity risks, the NIST framework has been used in a wide variety of industries. In this article, well break down why the NIST framework was created, how it is structured, and how it helps to create a robust cybersecurity risk-management strategy. The NIST framework can be daunting at first, particularly for smaller organizations that may not be sure how to leverage the framework to create actionable insights into gaps in their cybersecurity. The information provided in this article should prove as a helpful starting place for organizations wishing to get a brief introduction to the NIST framework, as well as highlight some of the key advantages that adopting the NIST framework brings to organizations of any size.

    (more…)