Tag archive for "CPEs"

CFO/CSO/CPO, CISSP, Events, Presentations

NYS CyberSecurity Conference – Social Media & Cloud Computing Threats to Privacy, Security and Liberty – June 5 2012

Comments Off 14 May 2012

http://www.dhses.ny.gov/ocs/awareness-training-events/conference/2012/index.cfm

June 5, 2012, 11 am

 

Social Media has quickly woven itself into the very fabric of everyday life. This boom in sharing, even the most banal of details, has had a resounding impact on how our children, employees and colleagues communicate.

Using case studies from the US and around the world, we’ll examine how people have lost jobs, college admissions, college degrees, fortunes and freedom through (un)social media.

We’ll also investigate the rampant OVERCOLLECTION of customer and subscriber data by major corporations and governments.

We’ll also discuss some strategies and steps we can take to protect civil liberties and privacy in the age of Social Media.

Events, Presentations

ASIS 58 – Social Media & Cloud Computing Threats to Privacy, Security and Liberty – Sep 11, 2012

Comments Off 14 May 2012

Sep 11, 2012 – ASIS 58

Social Media & Cloud Computing Threats to Privacy, Security and Liberty, Session 3183
http://www.asis2012.org/Pages/Seminar-Home-Page.aspx

 

Social Media has quickly woven itself into the very fabric of everyday life. This boom in sharing, even the most banal of details, has had a resounding impact on how our children, employees and colleagues communicate.

Using case studies from the US and around the world, we’ll examine how people have lost jobs, college admissions, college degrees, fortunes and freedom through (un)social media.

We’ll also investigate the rampant OVERCOLLECTION of customer and subscriber data by major corporations and governments.

We’ll also discuss some strategies and steps we can take to protect civil liberties and privacy in the age of Social Media.

CISSP, Events

ISC2 SecureNewJersey – Dec 3, 2012 – Social Media & Cloud Computing Threats to Privacy, Security and Liberty

Comments Off 14 May 2012

Social Media & Cloud Computing Threats to Privacy, Security and Liberty

 

Social Media has quickly woven itself into the very fabric of everyday life. This boom in sharing, even the most banal of details, has had a resounding impact on how our children, employees and colleagues communicate.

Using case studies from the US and around the world, we’ll examine how people have lost jobs, college admissions, college degrees, fortunes and freedom through (un)social media.

We’ll also investigate the rampant OVERCOLLECTION of customer and subscriber data by major corporations and governments.

We’ll also discuss some strategies and steps we can take to protect civil liberties and privacy in the age of Social Media.

Events

ISC2 Baltimore – Dec 5, 2012 – Social Media & Cloud Computing Threats to Privacy, Security and Liberty

Comments Off 14 May 2012

Social Media & Cloud Computing Threats to Privacy, Security and Liberty

 

Social Media has quickly woven itself into the very fabric of everyday life. This boom in sharing, even the most banal of details, has had a resounding impact on how our children, employees and colleagues communicate.

Using case studies from the US and around the world, we’ll examine how people have lost jobs, college admissions, college degrees, fortunes and freedom through (un)social media.

We’ll also investigate the rampant OVERCOLLECTION of customer and subscriber data by major corporations and governments.

We’ll also discuss some strategies and steps we can take to protect civil liberties and privacy in the age of Social Media.

Events

NYCLA CLE – What do attorneys need to know about Cyber Forensics – 4/24/12

Comments Off 25 March 2012

Update on Cybersecurity Issues: What do Attorneys need to know about CyberForensics

Tuesday, April 24, 2012,

6:00 PM – 9:00 PM

Member Price: $125Non-Member

Attorney Price: $175

Location: 14 Vesey Street

Course ID: C042412

Credits: 3 MCLE

Credits3 MCLE

Credits: 1 Ethics; 2 PP; Transitional and Non-transitional also NJ

Register at http://nycla.org/index.cfm?section=CLE&page=CLE_Detail&itemID=2683&dateID=20120424

 

Course Description:Developments involving cybersecurity issues are changing at an explosive rate. Join the Cyberspace Committee in exploring the recent developments affecting cybersecurity including a discussion of real world case studies, examination of current technology trends and their current and impending erosion of 4th and 5th Amendment protections, recent guidance from the courts, FTC and other regulatory bodies, the impact of major federal and private information security laws and regulations and more.

Faculty:

Program Co-sponsor: NYCLA’s Cyberspace Committee

Faculty: Raj Goel, brainlink.com and Natalie Sulimani, Law Offices of Natalie Sulimani

via NYCLA – New York County Lawyers’ Association.

accountants, Articles, attorneys, Events, Presentations

Nassau County Bar Attorneys & Accountants Committee 2/27/12

Comments Off 27 February 2012

The Nassau County Bar Attorneys Accountants Committee has asked me to present on selected Cyber-Security topics.

 

When; Feb 27, 2012

Where: Nassau County Bar Association

15th & West Streets

Mineola, NY 11501

516-747-4070

 

One of the topics we discussed is the role of the of the Cyberforensics examiner when encountering Child Porn (CP).

 

The consensus from the Attorneys, Accountants and CFEs was that anything found during the examination is covered by attorney-client privilege.

That view conflicts with federal laws.  Unlike any other type of evidence, merely possessing more than 3 pieces of CP is a Federal Offense.

 

Attorneys have been prosecuted for possessing CP while they were conducting research on behalf of their client.  See the case of Attorney Leo Thomas Flynn at http://www.brunolaw.com/prosecution-serves-as-warning.html

 

My reading of the Leo Flynn case says that he won on a technicality – South Dakota state laws allow Attorneys to view/research CP during an active case.  As do several other states.

However, Federal law offers no such immunity.

 

Most Forensics Examiners, myself included, will notify Law Enforcement if/when I encounter CP during the course of a forensics examination.

Unlike attorneys, Cyberforensics Examiners, Accountants, etc do NOT have a attorney-client privilege shield, and CP is one of the exemptions to Attorney-client privilege.

 

In my opinion, I think the fundamental error that attorneys have with CP is that they think that if someone downloaded CP, it is a crime that occurred in the past.

If a client commits a crime and tells his or her attorney about a past-deed, the attorney is legally and morally obligated to stay silent about it.

 

However, having CP stored on your harddrive is NOT a crime in the past.  It is a crime in the present.

Therefore, if you as the attorney take

 

Think of CP as plutonium – if you found plutonium and put it in your pocket, the activity of finding plutonium occurred in the past.  The damage caused by radiation however, is an ongoing and present danger.  Similar rules apply here.  The client may have downloaded or acquired CP in the past, but the mere possession of it by anyone NOT in Law Enforcement, is illegal.

 

So attorneys, CFEs, etc, please interview your clients regarding CP before you take on the case – or as soon as you suspect it.

You CANNOT shield your client if they have more than 3 items of CP.

Possessing CP is an active crime, and must be reported to law enforcement asap.  Otherwise, the DAs office, FBI or Secret Service will put you through years of litigation hell, as they did Leo Thomas Flynnhttp://www.brunolaw.com/prosecution-serves-as-warning.html

 

Learn More

http://www.brunolaw.com/prosecution-serves-as-warning.html

http://www.giancolalaw.com/news/Duty-Privilege-and-Immunity.html

http://mntech.typepad.com/msba/2010/03/why-divorce-lawyers-should-get-up-to-speed-on-cybercrime-law.html

http://www.floridalawreview.com/2010/giannina-marin-possession-of-child-pornography-should-you-be-convicted-when-the-computer-cache-does-the-saving-for-you/

http://articles.forensicfocus.com/2011/11/22/is-your-client-an-attorney-be-aware-of-possible-constraints-on-your-investigation-part-2-of-a-multi-part-series/

http://sogweb.sog.unc.edu/blogs/ncclaw/?p=1346

http://www.americanbar.org/newsletter/publications/youraba/201203article04.html

 

Events, Presentations

NYIT Vancouver – 2/21/12

Comments Off 19 February 2012

On Feb 21, 2012, Raj Goel, CISSP (NYIT ’95) addressed the Surrey Board Of Trade on selected Information Security Topics.

 

We ( students and Faculty of NYIT-Vancouver) discussed the challenges to Privacy, Security and Civil Rights, and the role colleges can play today in developing the workforce, technologists, and civil libertarians of tomorrow.

 

Slides are available here - 2012-02-21-NYIT-Vancouver-RajGoel-v3.pdf

Events

LICFE 2/9/2012

Comments Off 08 February 2012

 

The Long Island Chapter of the Association of Certified Fraud Examiners has invited me to educate their members on the following topics:

ID Fraud tsunami: Social media, cloud computing & national ids
Social Media has quickly woven itself into the very fabric of everyday life. This boom in sharing, even the most banal of details, has had a resounding impact on how our children, employees and colleagues communicate.
Using case studies from the US and around the world, we’ll examine how people have lost jobs, college admissions, college degrees, fortunes and freedom through (un)social media.
We’ll also investigate the rampant OVERCOLLECTION of customer and subscriber data by major corporations and governments.
We’ll also discuss some strategies and steps we can take to protect civil liberties and privacy in the age of Social Media.

Continue Reading

Articles, Webinars

What to Teach Your Kids, Employees and Interns about Social Media

Comments Off 07 February 2012

This 31-minute webinar shows you how

  • Kids have been denied College Admissions, thrown out of college or kicked out of their majors
  • Interns and employees have cost their employers thousands (or millions) of dollars
  • How kids and adults have gone to jail, around the world, due to mistakes in Social Media

Please share this webinar with

  • CIOs, CSOs, CPOs, Compliance Officers
  • Parents of High school & College Students
  • High School & College Student
  • High School teachers
  • College Professors
  • Guidance Counselors
  • Interns
  • New Employees

Events

ISC(2) SecureSanAntonio – Jan 19, 2012

11 Comments 10 November 2011

Jan 19, 2012

San Antonio Marriott Northwest
3233 NW Loop 410
San Antonio, Texas 78213

 

Privacy and Security Challenges With Cloud Computing

6 CPEs for CISSPs and ISC2 members

 

Dropbox, Gmail, Facebook, Amazon Web Services — they’ve become part of the IT DNA. More than that, they have become household verbs.

 

Individual consumers and complete corporations moving to Social Media and the cloud has had a resounding impact on how our profession manages enterprise security. In this day-long, interactive event, we’ll explore strategies for managing the risks associated with:

-Data Loss Prevention
-Brand Protection
-Privacy Erosion
-Malware Protection
- FTC’s regulatory sanctions
- Guidance from the Courts, FTC, HHS and other regulatory bodies on Cloud Computing and Social Media

Many of the tools to protect our organizations and users are deployed and in use already. Join us as we share techniques from our peers in making the best use of our past investments to mitigate these risks and more.

Grab the PDf from http://www.brainlink.com/whitepapers/2012-01-19-RajGoel-ISC2-Secure_San_Antonio_Dallas_Cloud_Privacy_Concerns_FINAL.pdf

Events

ISC(2) SecureDallas – Jan 20 2012

3 Comments 10 November 2011

 

Jan 20, 2012

Dallas/Ft Worth Marriott Solana
5 Village Circle
Westlake, TX 76262

 

Privacy and Security Challenges With Cloud Computing

6 CPEs for CISSPs and ISC2 members

 

Dropbox, Gmail, Facebook, Amazon Web Services — they’ve become part of the IT DNA. More than that, they have become household verbs.

 

Individual consumers and complete corporations moving to Social Media and the cloud has had a resounding impact on how our profession manages enterprise security. In this day-long, interactive event, we’ll explore strategies for managing the risks associated with:

-Data Loss Prevention
-Brand Protection
-Privacy Erosion
-Malware Protection
- FTC’s regulatory sanctions
- Guidance from the Courts, FTC, HHS and other regulatory bodies on Cloud Computing and Social Media

Many of the tools to protect our organizations and users are deployed and in use already. Join us as we share techniques from our peers in making the best use of our past investments to mitigate these risks and more.

This event was a huge hit in Denver and looks to be the BIGGEST bash in Texas!

Grab the PDf from http://www.brainlink.com/whitepapers/2012-01-19-RajGoel-ISC2-Secure_San_Antonio_Dallas_Cloud_Privacy_Concerns_FINAL.pdf

accountants, attorneys, CFO/CSO/CPO, CISSP, Events

Nov 8 2011 – ISC2 Brighttalk – Dealing With Risk and Vulnerabilities in the Enterprise

Comments Off 24 October 2011

Cloud Privacy Concerns – Over sharing and Over Collecting

Social Media has quickly woven itself into the very fabric of everyday life and computing. This boom in sharing, even the most banal of details, has had a resounding impact on how our profession manages enterprise security. In this presentation we’ll explore strategies for managing the risks associated with:

  • Job loss, revenue loss
  • Data Loss Prevention
  • Brand Protection
  • Privacy Erosion
  • Malware Protection

We’ll examine the basic law that governs ALL internet activity in the US.
We’ll further delve into KEY FTC decisions that impact online activity.
Using case studies from the US and around the world, we’ll examine how people have lost jobs, college degrees, fortunes and freedom through social media.
We’ll investigate the rampant OVERCOLLECTION of customer and subscriber data by major corporations.
And finally, we’ll review success stories from the past 300 years, where lone individuals and committed groups have improved security, society and human life spans.

3 CPEs will be offered.

Register at: https://isc2.brighttalk.com/node/914

 

CISSP, Events

ISC2 SecureBoston Oct 19, 2011

Comments Off 28 September 2011

Oct 19, 2011 – Full Day ISC2 Local Event

Oversharing: Managing Risk in the Social Age
Co-presented by Raj Goel and Brandon Dunlap

Social Media has quickly woven itself into the very fabric of everyday life and computing. This boom in sharing, even the most banal of details, has had a resounding impact on how our profession manages
enterprise security. In this day-long, interactive event, we’ll explore strategies for managing the risks associated with:

  •  Data Loss Prevention
  •  Brand Protection
  •  Privacy Erosion
  •  Malware Protection

We’ll also outline the cultural effects of Social Media on the enterprise as Generation Y, the Millenials, begin entering the workplace with expectations of open sharing.Many of the tools to protect our organizations and users are deployed and in use already. Join us as we share techniques from our peers in making the best use of our past investments to mitigate these risks.


 

Download the file here:

2011-10-19-RajGoel-ISC2-Secure_Boston_Cloud_Computing_Oversharing_OverCollecting.pdf

 

Events

AppAssure/SMBNation HIPAA Compliance Webinar

Comments Off 07 September 2011

Thursday, September 8, 2011 10:00 AM – 11:00 AM PDT

And with the recent penalties against UCLA Health System ($ 865,000), Rite-Aid ( $ 1M), CVS ($ 2.25M), Massachusetts General ($ 1M) and Cignet ($ 4.3M), the Office of Civil Rights is finally showing that it means business.

Several key requirements for HIPAA compliance are
- backups and records retention.
- Disaster Recovery
- Business Continuity

This webinar, by Raj Goel, a renowned expert on HIPAA/HITECH Compliance,  will give you an overview of how AppAssure helps health care providers meet HIPAA/HITECH compliance, while solving critical business challenges, effectively.

Speakers: Harry Brelsford and Raj Goel

Register here!: https://www1.gotomeeting.com/register/516144041

Articles

Backing Up Documents in the Cloud

Comments Off 22 August 2011

Raj Goel, CISSPCTOBrainlink International, Inc.raj@brainlink.com

917-685-7731

Raj’s LinkedIn profile

This article appeared on LAW.com

 

John Edwards (no, not THAT John Edwards) did a great job of summarizing various backup tools available for CLOUD backups, and some risks inherent in it.

My opinion is that law firms should NOT be using public or hybrid clouds, as dangers to client-confidentiality and potential litigation liabilities out-weigh any short-term savings.

 

PRIVACY

Rajesh Goel, chief technology officer at Brainlink International, a New York-based compliance security consulting firm, warns that storing data in the cloud could, under some circumstances, pose a privacy risk to client data. “If a firm is large enough and they have the financial and technical resources to build their own private cloud, then the advantages of cloud computing are compelling,” he says. “For firms lured by the low cost/save money siren song of public and hybrid clouds, there’s danger ahead.”

Goel observes that while the Electronic Communications Privacy Act assures that e-mail has a 180-day right to privacy, information held in databases has zero days of privacy protection. “All online applications … can be classified as databases, under the strict definition of ECPA,” Goel asserts.

Goel says that attorneys also need to be aware of another potential privacy threat. “The Patriot Act allows law enforcement to use National Security Letters to obtain information about individuals and companies from service providers,” he says. “Most NSLs forbid the service provider from notifying their clients that they have released information to law enforcement, based on NSLs.”

Goel adds that lawyers with clients in highly regulated areas, such as health care and financial services, also need to fully investigate their situation and privacy risk potential before sending files into the cloud.

Full Article is available at http://www.law.com/jsp/article.jsp?id=1202509461694&Backing_Up_Documents_in_the_Cloud&slreturn=1&hbxlogin=1

 


Raj Goel, CISSP, is chief technology officer of Brainlink International, an IT services firm. He is located in  New York and can be reached at raj@brainlink.com.

About, Presentations

Presentation Topics

Comments Off 13 July 2011

Each of my talks runs from 45-120 minutes.

I present the specific topic in 45 minutes, or really dive into it for 2 hours.

Multiple topics can also be combined into 2,3,4 or 6-hour sessions for 1/2-day and full-day events.

The agendas/descriptions for each of the topics is:


1) Perils of Social Media – How Facebook, Google, Twitter, Social Media & Cloud Computing are creating Threats to Privacy, Security and Liberty

Social Media has quickly woven itself into the very fabric of everyday life. This boom in sharing, even the most banal of details, has had a resounding impact on how our children, employees and colleagues communicate.

Using case studies from the US and around the world, we’ll examine how people have lost jobs, college admissions, college degrees, fortunes and freedom through (un)social media.

We’ll also investigate the rampant OVERCOLLECTION of customer and subscriber data by major corporations and governments.

We’ll also discuss some strategies and steps we can take to protect civil liberties and privacy in the age of Social Media.


2) Trends in Financial Crimes

This interactive and lively discussion presents an overview of US laws (HIPAA, Sarbanes Oxley (SOX), Gramm Leach Bliley Act (GLBA), PCI CISP Credit Card Compliance, the growing number of US state data breach notification laws). We trace the history of information security regulations and ID Theft. We examine credit theft and the threat it poses to the American banking industry, as well as the global economy and what governments around the world are doing to combat these crimes.

Special attention is paid to trends and growth in financial crimes, including:

* ID Theft
* Mortgage/Title Fraud
* SPAM /Botnet for Hire
* Credit Fraud
* Case Studies from around the world

Length: 50 minutes


3) Are you Googling your Clients’ privacy away?

This presentation addresses how various services offered by Google can become a threat to your companies’ privacy and confidentiality policies.

It deals with Google’s capabilities to capture and aggregate information with or without user knowledge. Special attention is given to Google’s key offerings such as:

* Google Searches
* GMail
* Orkut
* Google Toolbar
* Google Desktop
* Android
* Chrome Browser
* Case Studies from around the world

Length: 50 Minutes


4) Expanding your practice using LinkedIn

* This seminar will discuss Common myths about LinkedIn
* Proper uses and misuses of LinkedIn
* The power of LinkedIn Groups
* Case Studies examine different LinkedIn profiles, and how to create effective profiles

Length: 50 Minutes


5) Living in a MultiCompliance World – Part I HIPAA, Sarbanes-Oxley, Gramm-Leach-Bliley and PCI-DSS compliance

This presentation provides an overview of the major federal and private information security laws and regulations in the United States.

Case studies examine the real-world impact of non-compliance, analysis of documented cases and guidance on implementing multi-compliance effectively.

Length: 90 minutes


6) Living in a MultiCompliance World – Part II

This presentation provides an ovewview of the impact the 37+ state privacy breach laws have on the federal regulations and PCI-DSS compliance. We examine the New York State Privacy Breach law in depth.

Length: 90 minutes


7) Lessons Learned From the FTC

The FTC has emerged as the leading investigator of privacy and security breaches, and has sanctioned companies and institutions across industries for breaches.  This presentation reviews the FTC’s track record, examines lessons learned from each sanction, and provides guidance based on current and proposed regulations.

Over the last decade, in the absence of a national Consumer Privacy Watchdog/Czar, the Federal Trade Commission (FTC) has set the standard for what it considers acceptable, and unacceptable behavior for companies and organizations conducting business within the United States.

The FTC doesn’t involve itself in the minutae of security standards ‘ala HIPAA, PCI, etc, nor does it dictate what protocols or technologies companies need to use.  Rather, the FTC uses it’s Constitutional and Congressional mandate for regulating Interstate Commerce to hold companies accountable for their breaches.

This presentation will examine the FTC’s track record, put the sanctions in a larger context of privacy and security breaches, and most importantly, we will look at where the FTC is trending with the FTC Health Breach and RED FLAG regulations.

Length: 90 minutes


8 ) PCI Compliance is an expensive, moving target.

Many firms have chosen to become PCI compliant, others are content to sit by the sidelines and hope they won’t get caught.

Countless other firms have engaged in PCI compliance efforts, only to fall short and have significant breaches while being PCI compliant.

Pay NOW for effective, common-sense based compliance, or pay LATER in FTC fines, PCI fines and lawsuits.
Either way, you’re going to pay.

This presentation looks at a Dollars and Cents approach to PCI compliance.PCI Compliance is an expensive, moving target.

Length: 45 minutes


9) Privacy and Security Challenges With Cloud Computing for Attorneys, Accountants and Business Owners

Dropbox, Gmail, Facebook, Amazon Web Services — they’ve become part of the IT DNA.  More than that, they have become household verbs.

Individual consumers and complete corporations moving to Social Media and the cloud has had a resounding impact on how our profession manages enterprise security. In this interactive event, we’ll explore strategies for managing the risks associated with:

- Data Loss Prevention
- Brand Protection
- Privacy Erosion
- Malware Protection
- FTC’s regulatory sanctions
- Guidance from the Courts, FTC, HHS and other regulatory bodies on Cloud Computing and Social Media

 

This has been presented twice at NYCLA(New York County Lawyers Association)  and makes for a great ETHICS CLE for your law practice or Bar association.

Length:  45-90 minutes


10) Case Studies in Privacy and Security failures from around the globe

We examine large breaches from around the world (US, Canada, Japan, South Korea, Israel, UK, etc), focusing on the historical, cultural and social factors that contributed to the breach.

We also draw out the common threads that tie these breaches together, into a comprehensive narrative.
Length: 45-90 minutes

 

CISSP, Webinars

Streamlining and Ensuring Continuous Compliance

Comments Off 13 July 2011

http://www.brighttalk.com/webcast/5385/22557

accountants, attorneys, Webinars

Grow Your Practice Using LinkedIn

Comments Off 13 July 2011

http://slidesha.re/nb71L5

Continue Reading

Events

ISC(2) Security Congress 2011

Comments Off 12 July 2011

Sep 19-21, 2011

Orange County Convention Center, Orlando, Florida

Lessons Learned From The FTC (Federal Trade Commission)

Summary:

The FTC has emerged as the leading investigator of privacy and security breaches, and has sanctioned companies and institutions across industries for breaches. This presentation reviews the FTC’s track record, examines lessons learned from each sanction, and provides guidance based on current and proposed regulations.

Abstract Text

Over the last decade, in the absence of a national Consumer Privacy Watchdog/Czar, the Federal Trade Commission (FTC) has set the standard for what it considers acceptable, and unacceptable behavior for companies and organizations conducting business within the United States.

The FTC doesn’t involve itself in the minutae of security standards ‘ala HIPAA, PCI, etc, nor does it dictate what protocols or technologies companies need to use. Rather, the FTC uses it’s Constitutional and Congressional mandate for regulating Interstate Commerce to hold companies accountable for their breaches.

This presentation will examine the FTC’s track record, put the sanctions in a larger context of privacy and security breaches, and most importantly, we will look at where the FTC is trending with the FTC Health Breach and RED FLAG regulations.

Whether you deal with physical security, digital security, Risk Management or Compliance, you WILL learn something valuable, and relevant here.

 

Webinars

Trends in Financial Crimes

Comments Off 12 July 2011

http://www.brighttalk.com/webcast/188/3182

What to teach your kids about Social Media

Comments

Thanks Raj Scott Dunkerley Regional Manager Security- SLED South-West Cisco SecureX (Scott Dunkerley)

Quote Rotator

Loading Quotes...

© 2012 Raj Goel, CISSP. Powered by WordPress.

Daily Edition Theme by WooThemes - Premium WordPress Themes