<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Awareity&#039;s Lessons Learned Blog</title>
	<atom:link href="http://awareity.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://awareity.wordpress.com</link>
	<description>Secure knowledge sharing with the right people at the right time...</description>
	<lastBuildDate>Thu, 17 Dec 2009 16:03:24 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='awareity.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/6d0e1fbed5d59b32a35812d992a8d62f?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Awareity&#039;s Lessons Learned Blog</title>
		<link>http://awareity.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://awareity.wordpress.com/osd.xml" title="Awareity&#039;s Lessons Learned Blog" />
		<item>
		<title>DHS Learns a Lesson: &#8220;What Happens on the Internet, Stays on the Internet!&#8221;</title>
		<link>http://awareity.wordpress.com/2009/12/17/dhs-learns-a-lesson-what-happens-on-the-internet-stays-on-the-internet/</link>
		<comments>http://awareity.wordpress.com/2009/12/17/dhs-learns-a-lesson-what-happens-on-the-internet-stays-on-the-internet/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 16:03:24 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Lessons Learned]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Napolitano]]></category>
		<category><![CDATA[Security Awareness Training]]></category>
		<category><![CDATA[TSA]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=253</guid>
		<description><![CDATA[In response to the recent inadvertent TSA exposure of an improperly redacted PDF document containing highly detailed information on Passenger Screening procedures used by TSA officials at U.S. airports, several lawmakers have apparently asked Department of Homeland Security Secretary Janet Napolitano to review any legal remedies available to stop Web Sites from reposting the leaked [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=253&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>In response to the recent inadvertent TSA exposure of an improperly redacted PDF document containing highly detailed information on Passenger Screening procedures used by TSA officials at U.S. airports, several lawmakers have apparently asked Department of Homeland Security Secretary Janet Napolitano to review any legal remedies available to stop Web Sites from reposting the leaked security manual.</p>
<p>First a couple reminders:</p>
<ul>
<li>”What Happens on the Internet, Stays on the Internet”</li>
<li>The US legal system does not have jurisdiction over all of the Internet</li>
</ul>
<p>Perhaps the same lessons being taught to students regarding the dangers of posting personal information or photographs of themselves online should be relayed to government employees with access to the Internet.  Once that information is out there, it is highly unlikely you will ever get it back…just like there is no “UNSEND” button to click after you sent an e-mail you did not mean to send.</p>
<p>What we really need are real solutions that address these and other real life issues.  This incident reveals the real and critical need for awareness and accountability across all levels of government.  All personnel should be provided with “situational awareness” and “customized training” to ensure all appropriate personnel understand:</p>
<ul>
<li>What types of information can be shared or not shared</li>
<li>How to properly share information</li>
<li>Who information can be shared with</li>
<li>How to protect/redact sensitive information</li>
<li>And many other situational awareness issues that all appropriate personnel need to know</li>
</ul>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/253/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=253&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/12/17/dhs-learns-a-lesson-what-happens-on-the-internet-stays-on-the-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
		<item>
		<title>TSA Launches Review &#8211; Implementing Lessons Learned</title>
		<link>http://awareity.wordpress.com/2009/12/09/tsa-launches-review-implementing-lessons-learned/</link>
		<comments>http://awareity.wordpress.com/2009/12/09/tsa-launches-review-implementing-lessons-learned/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 20:29:09 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Lessons Implemented]]></category>
		<category><![CDATA[Lessons Learned]]></category>
		<category><![CDATA[Security Procedures]]></category>
		<category><![CDATA[Transportation Security Administration]]></category>
		<category><![CDATA[TSA]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=249</guid>
		<description><![CDATA[The Transportation Security Administration said it is launching a “full review” of an incident in which the agency posted on the internet a sensitive manual outlining security procedures for law enforcement officers, diplomats, prisoners, federal air marshals and others. 
Yet another Lesson Learned in 2009.  We all need to use Lessons Learned from others so they [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=249&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The Transportation Security Administration said it is launching a “full review” of <a href="http://bit.ly/8aslzE" target="_blank">an incident</a> in which the agency posted on the internet a sensitive manual outlining security procedures for law enforcement officers, diplomats, prisoners, federal air marshals and others. </p>
<p>Yet another Lesson Learned in 2009.  We all need to use Lessons Learned from others so they become Lessons Implemented to ensure better safety and better results in TSA&#8230;and most every other organization.</p>
<p>2009 has provided hundreds of lessons learned and the majority of them reveal a widening gap involving a lack of awareness, a lack of accountability and a lack of oversight. </p>
<p>Blaming the administration or calling it an honest mistake or brain fade are not solutions.  What organizations really need are better solutions and better tools to keep up with mounting risks, escalating regulations, constant changes and updates to situational awareness and a growing need to securely share information.</p>
<p>Organizational leaders need better management and oversight tools to &#8220;connect the dots&#8221; and implement lessons learned so we can eliminate gaps and weak links and achieve better results.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/249/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=249&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/12/09/tsa-launches-review-implementing-lessons-learned/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
		<item>
		<title>123 Failed Banks…the Killer Gap</title>
		<link>http://awareity.wordpress.com/2009/11/16/123-failed-banks%e2%80%a6the-killer-gap/</link>
		<comments>http://awareity.wordpress.com/2009/11/16/123-failed-banks%e2%80%a6the-killer-gap/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 18:18:30 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Knowledge Management]]></category>
		<category><![CDATA[OK, Then What?]]></category>
		<category><![CDATA[Budgets]]></category>
		<category><![CDATA[Failed Banks]]></category>
		<category><![CDATA[Killer Gap]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/2009/11/16/123-failed-banks%e2%80%a6the-killer-gap/</guid>
		<description><![CDATA[123 banks have now been closed this year and questions continue to mount with each bank closing.
One of the questions is: What role is the Killer Gap playing in these bank closures?
Have you heard of the Killer Gap?
The Killer Gap is the result of the following trends:

Mounting Risks
Increasing Costs (Security, Compliance, Business Continuity, Management, etc.)
Escalating [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=247&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>123 banks have now been closed this year and questions continue to mount with each bank closing.</p>
<p>One of the questions is: What role is the Killer Gap playing in these bank closures?</p>
<p>Have you heard of the Killer Gap?</p>
<p>The Killer Gap is the result of the following trends:</p>
<ul>
<li>Mounting Risks</li>
<li>Increasing Costs (Security, Compliance, Business Continuity, Management, etc.)</li>
<li>Escalating Regulations</li>
<li>Changing Economic Conditions</li>
</ul>
<p>Combined with:</p>
<ul>
<li>Decreasing Budgets</li>
<li>Limited Resources</li>
<li>Traditional Management Tools</li>
<li>Poor/Outdated Decision Making</li>
</ul>
<p> <img class="alignnone size-medium wp-image-246" title="2009-1110-Killer-Gap" src="http://awareity.files.wordpress.com/2009/11/2009-1110-killer-gap.gif?w=300&#038;h=175" alt="2009-1110-Killer-Gap" width="300" height="175" /></p>
<p>This widening gap presents difficult challenges for every organizational leader and their organization and can lead to expensive, embarrassing and business ending results.</p>
<p>Is your organization prepared to control and manage the Killer Gap?</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/247/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/247/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/247/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/247/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/247/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=247&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/11/16/123-failed-banks%e2%80%a6the-killer-gap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>

		<media:content url="http://awareity.files.wordpress.com/2009/11/2009-1110-killer-gap.gif?w=300" medium="image">
			<media:title type="html">2009-1110-Killer-Gap</media:title>
		</media:content>
	</item>
		<item>
		<title>Aligning Security and Company Risk &#8211; Lessons Learned from Others&#8217; Mistakes</title>
		<link>http://awareity.wordpress.com/2009/11/13/aligning-security-and-company-risk-lessons-learned-from-others-mistakes/</link>
		<comments>http://awareity.wordpress.com/2009/11/13/aligning-security-and-company-risk-lessons-learned-from-others-mistakes/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 16:59:30 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Lessons Learned]]></category>
		<category><![CDATA[ASIS]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[General Dynamics]]></category>
		<category><![CDATA[Providence Health]]></category>
		<category><![CDATA[Security Management]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=242</guid>
		<description><![CDATA[Excellent Lessons Learned from Major Incidents
There is a saying that no leader will live long enough to learn from their own mistakes, so great leaders learn from other people’s mistakes too.
As I was reviewing titles from the November issue of Security Management (an ASIS publication) and on the lookout for lessons learned, I came across [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=242&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong>Excellent Lessons Learned from Major Incidents</strong></p>
<p>There is a saying that no leader will live long enough to learn from their own mistakes, so great leaders learn from other people’s mistakes too.</p>
<p>As I was reviewing titles from the November issue of Security Management (an ASIS publication) and on the lookout for lessons learned, I came across the following title:  <strong><em><a href="http://bit.ly/2zXbX9" target="_blank">Aligning Security and Company Risk</a></em></strong></p>
<p>I clicked on the link and read an article that featured two major security/compliance incidents and what steps leaders from General Dynamics Corporation and Providence Health &amp; Services took after major incidents occurred at their organizations.</p>
<p>The article really got my attention when I read the first paragraph:</p>
<p><em>After a major incident, companies often decide that they need to purchase new security products to prevent a recurrence of the problem. But sometimes the solution may be nontechnical: to better align security and business risks and to enforce existing policies.</em></p>
<p>The article offers lessons learned from two organizational leaders who realized their security, compliance and business management efforts needed to be better aligned and that no technology solution was going to “fix” their problems, gaps and weaknesses. </p>
<p>Are you organization’s security, compliance and risk management efforts aligned?</p>
<p>Does your organization have policies and procedures that help all appropriate personnel understand how your organization’s business processes are aligned?</p>
<p>Do all appropriate personnel understand their specific roles, responsibilities and obligations with respect to Security Management?  Compliance Management?  Risk Management? Reputation Management?</p>
<p>Does your organization need to modernize outdated, fragmented or manually intensive efforts that are making your organization vulnerable to expensive risks or a major incident?</p>
<p>In my experiences performing risk, vulnerability, compliance, safety and continuity assessments…most organizations can definitely learn from other leaders’ and other organizations’ mistakes sooner than later.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/242/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=242&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/11/13/aligning-security-and-company-risk-lessons-learned-from-others-mistakes/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
		<item>
		<title>House Ethics Committee Standards Breach – Lessons Learned Part Two</title>
		<link>http://awareity.wordpress.com/2009/11/11/house-ethics-committee-standards-breach-%e2%80%93-lessons-learned-part-two/</link>
		<comments>http://awareity.wordpress.com/2009/11/11/house-ethics-committee-standards-breach-%e2%80%93-lessons-learned-part-two/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 18:08:18 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Lessons Learned]]></category>
		<category><![CDATA[Committee on Standards]]></category>
		<category><![CDATA[Ethics Committee]]></category>
		<category><![CDATA[Information Sharing]]></category>
		<category><![CDATA[situational awareness]]></category>
		<category><![CDATA[Training]]></category>
		<category><![CDATA[Washington Post]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=239</guid>
		<description><![CDATA[Teachable Moments vs. Ongoing Awareness Reminders
As a follow up to the previous blog regarding the sensitive ethics document from the Committee on Standards that ended up in the hands of The Washington Post, I wanted to take a look at teachable moments vs. ongoing awareness reminders.
If you go to the Committee on Standards of Official [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=239&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong>Teachable Moments vs. Ongoing Awareness Reminders</strong></p>
<p>As a follow up to the previous blog regarding the sensitive ethics document from the Committee on Standards that ended up in the hands of The Washington Post, I wanted to take a look at teachable moments vs. ongoing awareness reminders.</p>
<p>If you go to the Committee on Standards of Official Conduct <a href="http://bit.ly/1eVMA3" target="_blank">web site</a> and look up their training requirements for 2009 you will see an example of once-a-year training requirements and you will see individual training requirements are based on pay scales.  This seems ironic to me since the Committee on Standards blamed a low-level staffer for the unauthorized access to the sensitive ethics document.</p>
<p>One thing we know from years and years of data is that people do not do things because they are taught…people do things because they are reminded.</p>
<p>What is the lesson learned here?  Once-a-year training is not effective. </p>
<p>What are other lessons learned?  To be effective, once-a-year training should be complemented with ongoing reminders about:</p>
<ul>
<li>Situational Awareness</li>
<li>Risks</li>
<li>Threats</li>
<li>Best Practices</li>
<li>Regulations</li>
<li>Technology Usage</li>
<li>Information Sharing Guidelines</li>
<li>Information Handling Requirements</li>
<li>Legal Due Diligence</li>
<li>And other related issues</li>
</ul>
<p>What other lessons learned or questions does this Committee on Standards incident reveal? </p>
<ul>
<li>Should “low-level staffers” receive different training based on salary? </li>
<li>Should detailees, fellows, unpaid interns, or any other individuals who are employed by an organization and paid for less than 60 days be exempt from training?</li>
<li>Should new employees be allowed to work with sensitive information before training has been completed or be given 60 days to attend live or online training?</li>
<li>If live training is provided, will individuals remember everything that was blasted at them via the “megaphone training approach”?</li>
</ul>
<p>Interestingly enough, the previous questions are directly related to existing guidelines on the Committee of Standards of Official Conduct web site regarding 2009 Ethics Training.</p>
<p>This incident seems to be a great teachable moment about the importance of lessons learned questions that need to be answered and updates that need to be provided to all appropriate individuals as ongoing awareness reminders.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/239/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/239/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/239/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=239&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/11/11/house-ethics-committee-standards-breach-%e2%80%93-lessons-learned-part-two/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
		<item>
		<title>House Ethics Committee Standards Breach &#8211; Lessons Learned</title>
		<link>http://awareity.wordpress.com/2009/11/10/house-ethics-committee-standards-breach-lessons-learned/</link>
		<comments>http://awareity.wordpress.com/2009/11/10/house-ethics-committee-standards-breach-lessons-learned/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 18:29:30 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Lessons Learned]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[Ethics Committee]]></category>
		<category><![CDATA[House]]></category>
		<category><![CDATA[Washington Post]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=236</guid>
		<description><![CDATA[Low-Level Staffer Blamed for Committee on Standards Breach
In case you missed the story last week, multiple lessons learned and teachable moments have emerged from an incident involving a sensitive ethics committee document that ended up in the hands of the Washington Post.  The ethics document exposed numerous ongoing investigations into the conduct of more than [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=236&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Low-Level Staffer Blamed for Committee on Standards Breach</p>
<p>In case you missed the story last week, multiple lessons learned and teachable moments have emerged from an incident involving a sensitive ethics committee document that ended up in the hands of the Washington Post.  The ethics document exposed numerous ongoing investigations into the conduct of more than two dozen House members.  </p>
<p>Most articles seem to be blaming the unauthorized access to the sensitive ethics document on a low-level staffer working from home on their personal laptop using a peer-to-peer file-sharing program which provided unauthorized access to the ethics document. </p>
<p>Asking good questions can be a great way to identify Lessons learned and teachable moments, for example:</p>
<ul>
<li>How many employees/contractors have access to sensitive and confidential information?</li>
<li>How many employees/contractors in your organization work from home?</li>
<li>How many employees/contractors in your organization use a personal laptop for organization related purposes?</li>
<li>How many employees/contractors in your organization use peer-to-peer file sharing programs?</li>
</ul>
<p>Do you have clear policies and procedures and enforcement and consequences defined for each of these situations? </p>
<p>Do you have the ability to track and document awareness and accountability at the individual-level? (Or as the Ethics Committee defines it – low-level staffers?)</p>
<p>How do you keep all appropriate individuals updated on new risks, new regulations, new policies and new teachable moments?</p>
<p>Next lessons learned blog will look at teachable moments and ongoing reminders and which works better…</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/236/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/236/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/236/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=236&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/11/10/house-ethics-committee-standards-breach-lessons-learned/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
		<item>
		<title>Ohio Storage Bins Stolen &#8211; One Man’s Trash Is Another Man’s….</title>
		<link>http://awareity.wordpress.com/2009/11/09/ohio-storage-bins-stolen-one-man%e2%80%99s-trash-is-another-man%e2%80%99s%e2%80%a6/</link>
		<comments>http://awareity.wordpress.com/2009/11/09/ohio-storage-bins-stolen-one-man%e2%80%99s-trash-is-another-man%e2%80%99s%e2%80%a6/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 17:03:11 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Lessons Learned]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[facta red flags]]></category>
		<category><![CDATA[Ohio]]></category>
		<category><![CDATA[Storage Bins]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=233</guid>
		<description><![CDATA[We have all heard the wise old saying….’One man’s trash is another man’s treasure’ and potentially we have yet another lesson learned for organizations who are obligated to protect their client’s personal information.
In this lesson learned from Ohio, three large storage bins were stolen from outside of three different bank branches in three different cities.  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=233&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>We have all heard the wise old saying….’One man’s trash is another man’s treasure’ and potentially we have yet another lesson learned for organizations who are obligated to protect their client’s personal information.</p>
<p>In this <strong><a href="http://bit.ly/3HZpFa" target="_blank">lesson learned</a></strong> from Ohio, three large storage bins were stolen from outside of three different bank branches in three different cities.  Each of the three large storage bins contained paper that was waiting to be shredded and at least one of the storage bins contained personal documents of bank customers.</p>
<p>A few questions this incident brings to mind:</p>
<ul>
<li>Should personal data be stored outside of buildings?</li>
<li>Should trash/storage bins be removable?</li>
<li>Should trash/storage bins be monitored by video cameras?</li>
<li>How should data waiting to be shredded be handled and secured?</li>
<li>Does your organization have policies and procedures for data waiting to be shredded?</li>
<li>Does your organization have information handling agreement with shredder vendors?</li>
</ul>
<p>When it comes to protecting customers’ personal information, many other questions come to mind and many risks and issues have been discussed in previous Lessons Learned Blog entries.</p>
<p>Oh! And don’t forget this lesson learned provides yet another ‘red flag’ that should be added to your FACTA Red Flag Rule program and communicated to all appropriate personnel.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/233/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=233&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/11/09/ohio-storage-bins-stolen-one-man%e2%80%99s-trash-is-another-man%e2%80%99s%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
		<item>
		<title>Common Elements of Failed Financial Institutions (FDIC)</title>
		<link>http://awareity.wordpress.com/2009/11/05/common-elements-of-failed-financial-institutions-fdic/</link>
		<comments>http://awareity.wordpress.com/2009/11/05/common-elements-of-failed-financial-institutions-fdic/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 17:19:05 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Lessons Learned]]></category>
		<category><![CDATA[Failed Banks]]></category>
		<category><![CDATA[FDIC]]></category>
		<category><![CDATA[Financial]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=230</guid>
		<description><![CDATA[Yes, I admit it…I was surfing the FDIC web site this past weekend and I was spending some time reviewing past Financial Institution Letters that the FDIC releases to advise the banking industry of supervisory changes and guidelines.
I came across a Financial Institution Letter for Newly Insured FDIC-Supervised Depository Institutions that included the new changes, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=230&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Yes, I admit it…I was surfing the FDIC web site this past weekend and I was spending some time reviewing past Financial Institution Letters that the FDIC releases to advise the banking industry of supervisory changes and guidelines.</p>
<p>I came across a <a href="http://bit.ly/1nRMtF" target="_blank">Financial Institution Letter</a> for Newly Insured FDIC-Supervised Depository Institutions that included the new changes, as well as a list of common elements from troubled or failed institutions.</p>
<p>The list offers some potential lessons learned for organizational leaders (board of directors, executive management, compliance and others) and so I thought I would share the list.</p>
<ul>
<li>Rapid growth</li>
<li>Over-reliance on volatile funding, including brokered deposits</li>
<li>Concentrations without compensatory management <strong>controls</strong></li>
<li>Significant deviations from approved <strong>business plans</strong></li>
<li>Noncompliance with conditions in the <strong>deposit insurance orders</strong></li>
<li>Weak <strong>risk management practices</strong></li>
<li>Unseasoned <strong>loan portfolios</strong>, which masked the potential deterioration during an economic downturn</li>
<li>Weak <strong>compliance management systems</strong> leading to significant consumer protection problems</li>
<li>Involvement in certain <strong>third-party relationships</strong> with little or no oversight</li>
</ul>
<p>The list identifies the difficulties and complexities of <strong>“connecting the dots”</strong> and reminds bank leaders about many different types of <strong>“dots”</strong> that need better management to ensure better results.</p>
<p>If you are an organizational leader in the financial sector, this is good information!</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/230/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=230&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/11/05/common-elements-of-failed-financial-institutions-fdic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
		<item>
		<title>HHS Strengthens HIPAA Enforcement</title>
		<link>http://awareity.wordpress.com/2009/11/03/hhs-strengthens-hipaa-enforcement/</link>
		<comments>http://awareity.wordpress.com/2009/11/03/hhs-strengthens-hipaa-enforcement/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 15:50:08 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OK, Then What?]]></category>
		<category><![CDATA[ARRA]]></category>
		<category><![CDATA[HHS]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=228</guid>
		<description><![CDATA[If you were busy getting your costume ready for Halloween, you might have missed the news release from HHS on October 30, 2009.  This news release should be taken seriously by all covered entities and organizational leaders that have responsibilities for protected health information (PHI)
The news release announces that HHS has issued an interim final [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=228&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>If you were busy getting your costume ready for Halloween, you might have missed the news release from HHS on October 30, 2009.  <a href="http://bit.ly/ktd3b" target="_blank">This news release</a> should be taken seriously by all covered entities and organizational leaders that have responsibilities for protected health information (PHI)</p>
<p>The news release announces that HHS has issued an interim final rule to strengthen its enforcement of the rules within HIPAA to conform to the HIPAA enforcement regulations made by the HITECH Act.</p>
<p>As you may remember, the Health Information Technology for Economic and Clinical Health (HITECH) Act was enacted as part of the American Recovery and Reinvestment Act (ARRA) of 2009, which modified the HHS Secretary’s authority to impose civil money penalties for violations occurring after February 18, 2009.</p>
<p>I am curious if organizational leaders are taking notice of a trend that is catching on with strengthening enforcement of regulations?</p>
<p>The FDIC, OSHA, SEC, FINRA, FTC and others have announced they are also strengthening enforcement of regulations. </p>
<p>Are organizational leaders are paying attention and taking steps to strengthen their management programs? </p>
<p>Stay tuned….</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/228/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=228&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/11/03/hhs-strengthens-hipaa-enforcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
		<item>
		<title>Fact or Fiction with Tweets and Web Sites</title>
		<link>http://awareity.wordpress.com/2009/11/02/fact-or-fiction-with-tweets-and-web-sites/</link>
		<comments>http://awareity.wordpress.com/2009/11/02/fact-or-fiction-with-tweets-and-web-sites/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 17:02:45 +0000</pubDate>
		<dc:creator>awareity</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Megaphone Management]]></category>
		<category><![CDATA[CalPERS]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Megaphones]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://awareity.wordpress.com/?p=224</guid>
		<description><![CDATA[The battle of the megaphones…it’s on!
The California Public Employees’ Retirement System (CalPERS) has launched a web site to target misinformation and offers a way to let its members, employees, employers and others keep up with issues in national health care reform, pension investments and security.
CalPERSResponds.com is the new web site that will also link to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=224&subd=awareity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The battle of the megaphones…it’s on!</p>
<p>The <a href="http://bit.ly/48QNYv" target="_blank">California Public Employees’ Retirement System (CalPERS) has launched a web site</a> to target misinformation and offers a way to let its members, employees, employers and others keep up with issues in national health care reform, pension investments and security.</p>
<p>CalPERSResponds.com is the new web site that will also link to its social media posts on Twitter, Facebook and YouTube.</p>
<p>According to Patricia Macht, CalPERS director of external affairs, “There’s a lot of information and misinformation about CalPERS” and “We hope this site will help separate the facts from fiction and provide some education, insight and clarity to these issues.”</p>
<p>So now that multiple social networking sites are here to stay, are other organizations also planning to build a bigger microphone so they can shout over the top of the other microphones? </p>
<p>Megaphones – especially bigger and louder ones – are they really the most effective or efficient solution for communicating information to trusted members, employees and partners when information overload is already a serious problem?</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awareity.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awareity.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awareity.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awareity.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awareity.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awareity.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awareity.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awareity.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awareity.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awareity.wordpress.com/224/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=awareity.wordpress.com&blog=4444419&post=224&subd=awareity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://awareity.wordpress.com/2009/11/02/fact-or-fiction-with-tweets-and-web-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e415eb7c8ec00a288836d151f698dd64?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">awareity</media:title>
		</media:content>
	</item>
	</channel>
</rss>