<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[Blog]]></title>
    <link>http://www.ponemon.org/</link>
    <description></description>
    <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    <item>
      <title><![CDATA[Security of Cloud Computing Users 2013 Study ]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/new-security-of-cloud-computing-users-2013-study-confirms-conflicting-views-on-cloud-security-responsibility</link>
      <description><![CDATA[<p>
	&nbsp;</p>
<p style="text-align: left; ">
	Today we are releasing a very interesting follow up study on how organizations are improving--or not--their cloud security practices. The Security of Cloud Computing Users study shows that when it comes to cloud computing the glass may be half full or half empty because only half or less of respondents have positive perceptions about how their organizations are adopting cloud security best practices and creating confidence in cloud services used within their organization. A significant finding is that only 50 percent of respondents are engaging their security team (always or most of the time) in determining the use of cloud services. We hope you will read the complete report to learn about changes in cloud computing security.&nbsp;Access the full Ponemon Research: <a href="https://www.ca.com/us/collateral/industry-analyst-reports/na/ponemon-institute-security-of-cloud-computing-users-study-2013.aspx">2013 Security of Cloud Computing Users Study</a><br />
	<a href="https://www.ca.com/us/collateral/industry-analyst-reports/na/ponemon-institute-security-of-cloud-computing-users-study-2013.aspx">Highlights: View key takeaways in this infographic</a></p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Risk of Insider Fraud: Second Annual Study]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/risk-of-insider-fraud-second-annual-study</link>
      <description><![CDATA[<p>
	Today we released a new study entitled the <em>Risk of Insider Fraud: Second Annual Study</em> . The research reveals that the number of employee-related incidents of fraud continues to remain high. However, only 44 percent of IT and IT security practitioners say their organization views the prevention of insider fraud as a top security priority and this perception has declined since we first conducted this study in 2011. Contributing to the insider risk is BYOD, employee access of enterprise systems from remote locations and lack of security protocols over edge devices. Some suggestions to address these risks include making training and awareness an important component of a security initiative and monitoring access privileges. These privileges also need to be appropriate for the employees&rsquo; role and responsibility. We hope you will read the full report that discusses the challenges organizations face in minimizing the risk of the malicious and negligent insider. To find out more, visit <a href="http://www.attachmate.com/assets/Ponemon_2012_Report.pdf">http://www.attachmate.com/assets/Ponemon_2012_Report.pdf</a></p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[The Post Breach Boom]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/the-post-breach-boom</link>
      <description><![CDATA[<p>
	Data breaches have become a fact of life for organizations of all sizes, in every industry and in many parts of the globe. While many organizations anticipate that at some point a non-malicious or malicious data breach will occur, the focus of this study is to understand the steps organizations are taking to deal with the aftermath of a breach or what we call the Post Breach Boom. Sponsored by Solera Networks, we conducted The Post Breach Boom study to understand the differences between non-malicious and malicious data breaches and what lessons are to be learned from the investigation and forensics activities organizations conduct following the loss or theft of sensitive and confidential information. The majority of respondents in this study believe it is critical that a thorough post-breach analysis and forensic investigation be conducted following either a non-malicious or malicious security breach. To download the report, please click <a href="http://pages.soleranetworks.com/ponemon.html">http://pages.soleranetworks.com/ponemon.html</a></p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Efficacy of Emerging Network Security Technologies ]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/efficacy-of-emerging-network-security-technologies</link>
      <description><![CDATA[<p>
	&nbsp;</p>
<p>
	One of our latest studies is the <em>Efficacy of Emerging Network Security Technologies</em> our objective is to learn about organizations&rsquo; use and perceptions about emerging network security technologies and their ability to address serious security threats. &nbsp;The emerging technologies examined in this study include next generation firewalls, intrusion prevention systems with reputation feeds and web application firewalls. Some interesting findings include:&nbsp;&nbsp;Securing web traffic is by far the most significant network security concern for the majority of organizations. However, the majority of respondents say network security technologies fall short of vendors&rsquo; promises. Almost half (48 percent) of respondents agree that emerging network security technologies are not effective in minimizing attacks that aim to bring down web applications or curtail gratuitous Internet traffic. To read a copy of the report please click <a href="http://www.juniper.net/us/en/dm/spotlight">http://www.juniper.net/us/en/dm/spotlight</a></p>
<p>
	&nbsp;</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Understanding the Methodology and Staggering Costs in the Annual Cost of Failed Trust Report]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/understanding-the-methodology-and-staggering-costs-in-the-annual-cost-of-failed-trust-report</link>
      <description><![CDATA[<p>
	<strong>Some staggering numbers</strong><br />
	<br />
	Every Global 2000 enterprise faces a total exposure of almost U.S. $400 million over 24 months due to new and evolving attacks on failed cryptographic key and digital certificate management. And adjusting for probability established by survey participants, we found every enterprise risks losing $35 million.<br />
	This findings cap our First Annual Cost of Failed Trust Report: Trusts and Attacks, which quantifies, for the first time, the financial impact of impact of new threats and attacks on our ability to control trust.</p>
<p>
	Complete study is available - <a href="http://www.venafi.com/ponemon-institute-first-annual-cost-of-failed-trust-report/?ls=mb&amp;cid=70150000000KIkw">http://www.venafi.com/ponemon-institute-first-annual-cost-of-failed-trust-report/?ls=mb&amp;cid=70150000000KIkw</a></p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[2012 Most Trusted Companies for Privacy]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/2012-most-trusted-companies-for-privacy</link>
      <description><![CDATA[<p>
	Do we still care about privacy? According to our annual study on privacy trust, more and more of us do care. Our biggest privacy concerns are the fear of identity theft and government intrusions into our personal lives.&nbsp;</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Third Annual Patient Privacy & Data Security Study Released]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/third-annual-patient-privacy-data-security-study-released</link>
      <description><![CDATA[<p>
	Could BYOD increase the risks of a healthcare data breach and medical identity theft? The third annual study on Patient Privacy and Data Security reveals the explosion of mobile devices used in healthcare organizations.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[2013 State of the Endpoint]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/2013-state-of-the-endpoint</link>
      <description><![CDATA[<p>
	Sponsored by Lumension, the <em>2013 State of the Endpoint</em> is our third annual study that tracks endpoint risk in organizations, the resources to address the risk and the technologies deployed to manage threats.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Edelman Privacy Risk Index]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/edelman-privacy-risk-index</link>
      <description><![CDATA[<p>
	We are very pleased to introduce the Edelman Privacy Risk Index developed in collaboration with Ponemon Institute.&nbsp; The Index provides a high level risk coefficient specified for various sized business organizations. The Index is derived from Meta analysis of Ponemon research involving more than 6,400 individuals located in 29 countries.&nbsp; Here is the link to the online calculator:&nbsp; <a href="http://www.edelman.com/privacy-risks/">http://www.edelman.com/privacy-risks/</a></p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[2012 Web Session Intelligence & Security Report: Business Logic Abuse Edition sponsored by Silver Tail Systems ]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/2012-web-session-intelligence-security-report-business-logic-abuse-edition-sponsored-by-silver-tail-systems</link>
      <description><![CDATA[<p>
	&nbsp;</p>
<p>
	<br />
	&nbsp;</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Second Annual Patient Privacy Study Released]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/second-annual-patient-privacy-study-released</link>
      <description><![CDATA[<p>
	Widespread use of mobile devices is putting patient data at risk, according to the latest Ponemon Institute research on healthcare providers&#39; patient privacy practices.While 81 percent of respondents say employees in their healthcare organizations are using mobile devices to collect, store and/or transmit some form of PHI, 49 percent admit their organizations are not doing anything to protect these devices. To download a copy of the report click here:&nbsp; <a href="http://www2.idexpertscorp.com/ponemon-study-2011/" target="_blank">http://www2.idexpertscorp.com/ponemon-study-2011/</a>.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Best Practices in Data Protection Study Released]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/best-practices-in-data-protection-study-released</link>
      <description><![CDATA[<p>
	&nbsp;Sponsored by McAfee, the Best Practices in Data Protection survey is our latest effort to find out what separates the best organizations from the rest. We believe this study is important because it provides insights on how organizations can be more successful when investing in and building a data protection program. The study&#39;s findings reveal five success factors in a data protection program:</p>
<ol>
	<li>
		A formal data protection strategy for the organization and metrics to determine if the strategy is effective.</li>
	<li>
		Key metrics from a management console and observation and regular testing of data protection solutions.</li>
	<li>
		Data protection technology features that focus on privileged users, restriction of access and outbound communications are considered critical</li>
	<li>
		Centralized management of the data protection program with such features as actionable information, policy administration, reporting, automatic securing of endpoints and monitoring.</li>
	<li>
		Automated policies for detection and prevention of end-user misuse of information assets.&nbsp;</li>
</ol>
<p>
	To download the complete report click here: &nbsp;&lt;<a href="https://prod.secureforms.mcafee.com/content/verify?docID=3E46E43C-2252-487A-885B-4C5F125DFB60&amp;cid=WB290&amp;aName=DP&amp;src=web&amp;aType=report&amp;region=us">https://prod.secureforms.mcafee.com/content/verify?docID=3E46E43C-2252-487A-885B-4C5F125DFB60&amp;cid=WB290&amp;aName=DP&amp;src=web&amp;aType=report&reg;ion=us</a>&gt;</p>
<p>
	&nbsp;</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Second annual cost of cyber crime study is released]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/second-annual-cost-of-cyber-crime-study-is-released</link>
      <description><![CDATA[<p>
	Today we released our <u>Second Annual Cost of Cyber Crime Study</u>. &nbsp;Our findings support other research studies suggesting increases in the frequency, severity and overall cost of cyber attacks on private and public sector organizations. Our study is sponsored by HP ArcSight. &nbsp;I would be very pleased to discuss this year&#39;s findings, framework and research methods. &nbsp;Please feel free to call us directly or send an email to research@ponemon.org to schedule a one-to-one meeting.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Most trusted companies for privacy]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/most-trusted-companies-for-privacy</link>
      <description><![CDATA[<p>
	Ponemon Institute is releasing our annual Most Trusted Companies for Privacy study this coming week. &nbsp;This is the eighth year that we conducted a U.S. national consumer study that determines the organizations believed to be most committed to protecting and securing personal information. &nbsp;Our research also determines the underlying factors that consumers perceive as most important or influential to their trust ratings. &nbsp; For more information, please contact research@ponemon.org.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Ponemon Releases Cloud Service Provider Study]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/ponemon-releases-cloud-service-provider-study</link>
      <description><![CDATA[<p>
	Last week with CA Technologies we issued the results of a study of cloud service providers and their views on cloud security. There has been a lot of interest in this study. Readers have reviewed the results and responded with some very good questions and comments. In a nutshell, people &ndash; including us &ndash; were surprised by the results, which showed that cloud providers didn&rsquo;t put security as the No. 1 concern in providing their services.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Are we taking adequate steps to protect the critical infrastructure?]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/are-we-taking-adequate-steps-to-protect-the-critical-infrastructure</link>
      <description><![CDATA[<p>
	Last week I presented the results of our latest study entitled, &quot;The State of IT Security: A Study of Utilities and Energy Companies.&quot; Sponsored by Q1 Labs, this research revealed that utilities and energy companies in our study are more concerned about preventing downtime that stopping a cyber attack. &nbsp;In addition, a majority of respondents said that compliance with standards such as NERC CIP is not a top priority. &nbsp;Most surprisingly, only 16 percent of respondents believe that their organization&#39;s existing controls are designed to protect against exploits and attacks through the smart grid. &nbsp;For more information about this study, please contact research@ponemon.org.</p>
<p>
	&nbsp;</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Cost of a data breach climbs higher]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/cost-of-a-data-breach-climbs-higher</link>
      <description><![CDATA[<p>
	Most privacy advocates and people in the data protection community believe that data breach costs will start coming down eventually because consumers will become somewhat immune to data breach news. The idea is that data breach notifications will become so commonplace that customers just won&rsquo;t care anymore.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Listen to a new podcast on the True Cost of Compliance study]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/listen-to-a-new-podcast-on-the-true-cost-of-compliance-study</link>
      <description><![CDATA[<p>
	Dear friends and colleagues,</p>
<p>
	Please listen to a recent podcast on the True Cost of Compliance study completed last month. &nbsp;Martin KcMeay at Network Security Blog did a great job conducting this 30 minute interview.</p>
<p>
	<a href="http://www.mckeay.net/2011/03/02/network-security-podcast-23/" target="_blank">www.mckeay.net/2011/03/02/network-security-podcast-23/</a></p>
<p>
	If you would like a copy of the full report, please visit Tripwire&#39;s website as follows:</p>
<p>
	<a href="http://www.tripwire.com/ponemon-cost-of-compliance/" target="_blank">www.tripwire.com/ponemon-cost-of-compliance/</a></p>
<p>
	&nbsp;</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Compliance Like a Club]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/compliance-like-a-club</link>
      <description><![CDATA[<p>
	Have you ever noticed how some organizations wield compliance like a club when marketing their products or services?&nbsp;They remind you of the latest in information security regulations, such as the <a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/enforcementrule/hitechenforcementifr.html">HITECH Act</a> or <a href="http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf">Mass 201 CMR 17</a>, and then menacingly predict doom for those who transgress.&nbsp;If you fail to comply, their messages warn like a cross schoolmarm, the boogey man will flash his regulator badge and lower the boom (unless, of course, you buy the appropriate product or service).</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Poor Privacy Practice is Ailing Healthcare Industry]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/poor-privacy-practice-is-ailing-healthcare-industry</link>
      <description><![CDATA[<p>
	It has been more than six years since the ChoicePoint data breach thrust the issue of privacy protection into the headlines. Since then hundreds of information security failures have been disclosed and the tools and techniques used to keep sensitive information safe have advanced at a healthy pace. Recent incidents in the healthcare industry, however, strongly suggest that best practices have not been universally adopted.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Data Center Outages and Data Management]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/data-center-outages-and-data-management</link>
      <description><![CDATA[<p>
	I hear the collective sound of our friends, colleagues, and other interested parties scratching their heads at the release of the most recent piece of Ponemon Institute research, <i><a href="http://info.emersonnetworkpower.com/content/lna-11q1-adds-ponemon-white-paper">National Survey on Data Center Outages</a></i>.&nbsp;You read that right, data center outages.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Information Governance in the Cloud]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/information-governance-in-the-cloud</link>
      <description><![CDATA[<p>
	Just a brief note to bring our recent webinar to your attention.&nbsp; I presented Information Governance in the Cloud along with the good people at&nbsp;Symantec.&nbsp; The presentation is based in part on results from our earlier report, Flying Blind in the Cloud.</p>
<p>
	If you want to view the webinar, presented on the Windows Live Meeting platform, please <a href="https://www.livemeeting.com/cc/symantec_live/view?id=E-EU-071410">click here</a>.</p>
<p>
	If you have any questions or comments about this issue, our report, or the webinar, we&#39;d love to hear from you.</p>
<p>
	Thanks!</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Integrated, Holistic Security Strategies]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/integrated-holistic-security-strategies</link>
      <description><![CDATA[<p>
	Holistic is a popular word these days.&nbsp;Often applied to food and medicine, the word conjures images of natural, healthy living, but the word holistic refers to the function of an entity as a whole, including the interdependence of all its parts.&nbsp;Given this broader meaning, holistic can (and should) be applied when thinking strategically about the way a business organization operates.&nbsp;Successful, well-functioning organizations most adapt to change, be flexible in their relationships, and innovative in their approach to business.&nbsp;They must not only have the capacity to react to change, but to anticipate change and act innovatively.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Benchmarking Information Security Efficiency]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/benchmarking-information-security-efficiency</link>
      <description><![CDATA[<p>
	Recently the Ponemon Institute completed a new project, the Security Efficiency Benchmark Study, the purpose of which was to learn what IT security leaders in the UK and European think are the key components to having an efficient and effective security operation.&nbsp;In other words, we wanted to know what is necessary for achieving data security goals and protect information assets and infrastructure.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Think Before you Cloud]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/think-before-you-cloud</link>
      <description><![CDATA[<p>
	A few years ago, when wireless networking was still relatively new, there were numerous reports of enterprising employees who, frustrated with the pace of new technology integration in their workplace, took it upon themselves to deploy rogue access points &ndash; often hidden behind furniture or above drop-down ceiling panels &ndash; in order to provide convenient mobility around the office.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Fear and Loathing in Online Advertising]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/fear-and-loathing-in-online-advertising</link>
      <description><![CDATA[<p>
	Have you ever seen an interactive advertisement while browsing around on the Web and, even though it was from a brand that you recognized promoting a product, service or event that you found interesting, you simply refused to click on the image because of a nagging sense of trepidation?&nbsp;What <em>really </em>lies beyond that alluring digital veil?&nbsp;Is the offer worth the risk?&nbsp;What of my digital privacy might I be giving up by responding to that message?</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[The Road to Data Breach is Paved with Good Intentions]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/the-road-to-data-breach-is-paved-with-good-intentions</link>
      <description><![CDATA[<p>
	We recently completed some new research with Accenture in which we were surprised to find that, in spite of all the attention being paid to data protection, and in spite of new and updated data protection regulations, complacency is beginning to settle in among many companies.</p>
<p>
	Yes, I said complacency.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[2010 Security in the Trenches]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/security-in-the-trenches</link>
      <description><![CDATA[<p>
	We just completed a survey of federal IT security professionals to examine the data protection posture of government agencies.&nbsp;Through the survey, sponsored by CA, we wanted to see whether or not there is consistency in the perception of rank-and-file employees and executive management as it pertains to the safeguarding of sensitive information, regulatory compliance, and the day-to-day management and execution of a security program.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Training Is the Strongest Link]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/training-is-the-strongest-link</link>
      <description><![CDATA[<p>
	Today we held a RIM College event featuring three noted experts in corporate privacy training programs -- namely, Dean Forbes (Merck), Bob Posch (Merck) and John Block (Media Pro). &nbsp;Our focus is: what are leading companies doing to achieve awareness and knowledge about privacy and data protection requirements?</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Sophos & Ponemon Institute Announces New Study]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/sophos-ponemon-institute-announces-new-study</link>
      <description><![CDATA[<p>
	We are pleased to present<i> The State of Privacy and Data Security Compliance</i> study conducted by Ponemon Institute and sponsored by Sophos. The purpose of the study is to determine if various international, federal and state data security laws improve an organization&rsquo;s security posture. What is the value of compliance and does it correlate with the value of the compliance effort?</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Crowe Horwath & Ponemon release HITECH study]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/crowe-horwath-ponemon-release-hitech-study</link>
      <description><![CDATA[<p>
	I am delighted to share with you our recently completed benchmark study that focuses on healthcare organizations and their ability to comply with new regulations.&nbsp;Of 77 participating covered entities and business associates, 27% percent have not started or are barely aware of what they need to do, 32% are waiting for more details, 14% have a plan but are waiting for more details, and 21% are just starting to act.&nbsp; This data was collected&nbsp;from&nbsp;June&nbsp;through October 2009. If you are affected by the HITECH Act, this benchmark study may be helpful to you.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[eGov Initiative Not Without Risk to Citizen Data]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/egov-initiative-not-without-risk-to-citizen-data</link>
      <description><![CDATA[<p>
	The eGovernment movement is a good thing, and maybe too long in coming given how many years businesses have been taking advantage of technology to provide convenience and a higher quality of service to their customers.&nbsp;Constituent services have been available online for years, certainly, but only recently has the effort to modernize government been policy.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[The Goal is Credibility]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/the-goal-is-credibility</link>
      <description><![CDATA[<p>
	I want to share an article with you that I think has a tremendous lesson for anyone in the business of building trust.&nbsp; The article is from a recent edition of <em>Foreign Policy </em>(reprinted from <em>Joint Force Quarterly</em>), but don&#39;t let the source put you off.&nbsp; Admiral Michael G. Mullen, chairman of the Joint Chiefs of Staff, writes about what it takes to&nbsp;establish credibility&nbsp;and build trust.</p>
<p>
	Admiral Mullen&#39;s perspective is different from yours and mine, but there are nuggets here that are vital no matter what your business.</p>
<p>
	&nbsp;</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Archer-Ponemon Treaty for Data Governance]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/archer-ponemon-treaty-for-data-governance</link>
      <description><![CDATA[<p>
	I&rsquo;m still processing a lot of the information gathered, shared, and created during our 8<sup>th</sup> RIM Renaissance this past weekend in Minneapolis.&nbsp;One of our sessions focused on the creation of an information governance &ldquo;treaty&rdquo; that holds various organizational members to a high standard (consistent with our RIM principles).&nbsp;Please review the following draft document and let me know what you think.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Thank You, Friends of the Ponemon Institute!]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/thank-you-friends-of-the-ponemon-institute</link>
      <description><![CDATA[<p>
	A warm thank you to everyone who made this past weekend&#39;s RIM Renaissance a success.&nbsp; The discussions were lively and productive, and I think we all came away just a little bit smarter as a result of the candor.&nbsp; We do appreciate the enthusiasm that seems to pervade these events, and the willingness to put aside your valuable time to join with us on these annual occasions, as well as the ongoing conversations that take place throughout the year.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[What We have here is, Failure to Communicate]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/what-we-have-here-is-failure-to-communicate</link>
      <description><![CDATA[<p>
	Privacy pro: Do you ever feel like you are working overtime to meet overly ambitious expectations?&nbsp;Are you frustrated by your attempts to outline a plan for protecting sensitive personal information only to get the sense that you are talking to a brick wall?</p>
<p>
	CEO: Are you puzzled as to why the people your company has hired to address security and privacy concerns never seem to meet the objectives you have for them?&nbsp;Are you flummoxed by the fact that the investments you&rsquo;ve made in data security aren&rsquo;t helping to stem the tide of data loss?&nbsp;</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[More Employees Ignoring Data Security Policies]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/more-employees-ignoring-data-security-policies</link>
      <description><![CDATA[<p>
	Does it surprise you to learn that, according to our recent study, <i>Trends in Insider Compliance with Data Security Policies: Employees Evade and Ignore Security, </i>employee compliance with corporate data security policies is on the wane?</p>
<p>
	Why do you think this is?&nbsp; I&rsquo;m seeing a confluence of conditions that appear to be contributing to this challenge to data integrity: the development of new, mobile technologies that empower employees to do more while away from the office; a failure of organizations to keep pace with the ways technology is changing the dynamics of data security; and current economic conditions that are putting increased pressure on individuals to be more productive with fewer resources.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
    <item>
      <title><![CDATA[Dr. Ponemon's Blog]]></title>
      <author></author>
      <link>http://www.ponemon.org/blog/dr-ponemons-blog</link>
      <description><![CDATA[<p>
	Welcome to my new blog. I look forward to sharing some of our thought provoking research. I also look forward to receiving your comments and questions. Stay tuned.</p>
]]></description>
      <pubDate>Sun, 26 May 2013 01:30:57 -0400</pubDate>
    </item>
  </channel>
</rss>
