Network World
Thursday, January 8, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

Not a model policy at all

FWIW, Norwiches policy is hardly a model policy.
It does not give any information as to HOW the
PII information is stored, and for how long.
That alone demonstrates clearly to the estute
observer that if good PCI practices are not
in place yet another data breach is possible if
not likely.

Click to read the article this is in response to.

many security obligations

0

I disagree with the commenter who complains that Norwich's policy "does not give any information as to HOW the PII information is stored." The commenter implies that if the policy fails to address HOW, then data are at risk. Yet the methods and standards an enterprise uses to store and protect data can be very complex, and constantly changing. The enterprise does not need to discuss those methods in a privacy policy in order to have legal obligations to protect the PII. Legislatures are enacting many new laws on data retention and security. --Ben http://hack-igations.blogspot.com/2007/08/unfairness-in-minnesotas-credit-card.html

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: