photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for your photos and banter. Photog first is our motto Please refer to the site rules before posting.

Administered by:

Server stats:

246
active users

#compliance

7 posts6 participants0 posts today
Continued thread

Here's another good one: "Portable photographic or video equipment is not allowed in secure rooms unless authorized."
My comment in response: "Do we confiscate employees’ and visitors’ cell phones when they enter 'secure areas'? If not, this rule is violated every time an employee or visitor enters a secure area, and we should probably delete it."
#compliance

Reviewing compliance docs. Found this gem: "All fire doors on a security perimeter must be alarmed, monitored and tested in conjunction with the walls to establish the required level of resistance."
Added this comment: "How are we supposed to 'test' that fire doors and walls in a building provide the required level of fire resistance? I fail to see how such a 'test' can be accomplished without setting the building on fire. Perhaps different wording is required here."
#compliance #pyromania

I still think @EUCommission 's #fines are not a real "#penalty"!

  • Banning #Apple and/or jailing it's C-level in contempt until they comply would be.

After all, if I were to do the same shit [hypothetically, as a small and/or domestic business in the #EU] I'd soon face a judge dismantling my business as a "criminal enterprise" and stripping it for assets to pay damages, alongside confiscating any profits made.

Remember: If the penalty for a crime is a fine it's only illegal for the poor!

Question for #infosec, #compliance, #HIPAA wonks…
My mandatory annual HIPAA training claims that an "unintentional disclosure as a result of a permitted reason" is not a HIPAA violation. They even include the text shown below in one of the training videos.
I've never heard this before. My understanding is that an unintentional disclosure is still a violation, albeit perhaps a less severe one.
Do you agree with the training, and if so, can you point to a source for this?

AVG: waar staan we 7 jaar na de invoering? Was jij erbij? Weet je nog hoe organisaties ineens voor het eerst bezig leken te zijn met verwerkersovereenkomsten (daarvoor heetten ze 'bewerkersovereenkomsten') en iedereen riep 'Het mag niet van de AVG!'?

Ik deed een onderzoek onder privacyprofessionals van 34 onderwijs- en onderzoeksinstellingen om te kijken hoe we de impact van de verordening ervaren en wat deze heeft opgeleverd:

#AVG #GDPR #Privacy #Compliance

pec.surf.nl/7-jaar-avg/

Privacy Expertise Centrum · Compliance AVG: waar staan we 7 jaar na de invoering? - Privacy Expertise CentrumOrganisaties kregen tot 25 mei 2018 de tijd om hun bedrijfsvoering met de AVG in overeenstemming brengen. Wat heeft het opgeleverd?

Please, #infosec and #compliance professionals, I am BEGGING you, WRITE YOUR POLICIES AND PROCEDURES IN THE PRESENT TENSE.
Yes: "…risk assessment results guide appropriate management action…"
*NO*: "…risk assessment results *will* guide appropriate management action…"
Policies and procedures say what the organization DOES, not what it WILL do.
(continued)

Microsoft blockierte das E-Mail-Konto des IStGH-Chefanklägers – ein Weckruf!

Wenn zentrale Institutionen durch ausländische Anbieter lahmgelegt werden können, ist das ein klarer Appell: Europa braucht digitale Souveränität. Als deutsche Anbieter setzen wir bei @mailbox_org auf echte Datenhoheit – unabhängig und sicher. Jetzt handeln! heise.de/news/Strafgerichtshof

heise online · Strafgerichtshof: Microsofts E-Mail-Sperre als Weckruf für digitale SouveränitätBy Stefan Krempl

#compliance : as to a desire, demand, or proposal

- French: conformité

- German: die Zustimmung

- Italian: conformità

- Portuguese: conformidade

- Spanish: conformidad

------------

Join our new subreddit for language learners @ reddit.com/r/LearnANewLanguage

reddit.comCrowdsourcing Languages • r/LearnANewLanguageWe are in the process of revitalizing this subreddit to help language learners. Thank you for being a part of our community!
Continued thread

ISO 27000 nit #3. I had to stare at this for several minutes to try to figure out what "enhancing societal values" was doing in this list. IMO the meaning of all the other list items it clear, but that one's clear as mud. I _think_ what they're trying to get at is improving the security culture within the organization being managed, but honestly, that's just a guess, I'm not even certain that's what they mean.
#infosec #compliance #ISO #ISO27000 #standards #isms

Continued thread

ISO 27000 nit #2: The definition of "risk" provided here, "effect of uncertainty on objectives," is dumb, obscure, unhelpful, bureaucratic gobbledygook. It in no way resembles the dictionary definition of risk, which much more closely approximates what I think of when I use the word risk or see it used in an information security concept. I am challenged to understand why they chose this nonsense definition and what they hope to achieve by it.
#infosec #compliance #ISO #ISO27000 #standards #isms