Showing posts with label data theft. Show all posts
Showing posts with label data theft. Show all posts

Monday, April 16, 2012

Top Technology Initiatives for 2012

Advances in information technology have empowered everyone to access and manage information anywhere at anytime. Although there are significant benefits that technology makes possible, such as greater flexibility, efficiency and productivity, there are also concerns with increased risks to information security. This was evident from the 2012 Top Technology Initiatives Survey of the American Institute of Certified Public Accountants (AICPA).


The survey found that securing the IT environment is this year’s top business technology priority. It also measured the confidence level in achieving technology priorities. For example, a large number of the survey respondents said they were confident that their organizations (or their clients’ organizations) have taken the actions necessary to secure the IT environment. However, respondents were the least confident with the following two aspects of IT Security: (1) Protecting all mobile devices (laptops, tablets, mobile phones, etc.) to prevent a data breach; and (2) Ensuring that data will be safe in the event of a cyber-attack or mobile device loss.

For more information, read the AICPA 2012 Top Technology Initiatives Survey Results. Also refer to the Top Technology Initiatives Archive.

Thursday, October 6, 2011

Communication Technologies put Privacy at Risk


According to a recent survey, Canadians are heavy users of social networks and other communications technologies, but many are not taking basic steps to protect their personal information. A telephone survey of 2,000 randomly selected adults, commissioned by the Office of the Privacy Commissioner of Canada (OPC), found that three-quarters (74%) of respondents own at least one mobile communications device, such as a cell phone, smart phone or tablet. However, only 4 in 10 use password locks for the devices, or adjust their settings to limit the sharing of personal information that may be stored on the devices.

The Canadians and Privacy Survey 2011 found that one-third of Canadians use public Wi-Fi sites, such as those located at coffee shops and airports, where online communication may not always be protected by encryption. Of those, fully 85% admitted to some concern about possible risks to the security of their personal information.

The poll, conducted by Harris/Decima, also found that just over half (51%) of respondents use social networking sites, such as Facebook, MySpace and LinkedIn. Fortunately, 4 in 5 said they take advantage of privacy settings that allow them to control access to their online content. Even so, 45% of all respondents who use social networking sites acknowledged that they are concerned about the associated risks to their privacy.

Thursday, September 22, 2011

Mobile insecurity

The proliferation of mobile computing has brought on a number of challenges, specifically around security issues. Smartphones are repeating a pattern witnessed in the 1980s with desktop computers. They flood into the corporate fold without any rational plan. And very often, they are introduced by employees who can’t resist the status statement these devices make. The greatest obstacle to security is the users themselves. People believe nothing of value resides on their device, yet much can be used for identity theft, intellectual property theft or espionage. Everyone likes these devices for the immediacy and convenience, and don’t want to be bothered with security barriers, especially passwords. This is why many users deactivate the password protection, which to begin with is very rudimentary and requires only a four-digit PIN identification. In a regular notebook, that would never be accepted as security. To learn more, read the article “Mobile insecurity” in the September 2011 CAmagazine online.

Wednesday, June 15, 2011

Data-Centric Security - A CICA White Paper

In most organizations, data that was once static and stored in one place now moves freely from platform to platform throughout the organization and beyond. Because data is now often generated and modified by users and is resident in different forms and versions in different places simultaneously, maintaining a secure environment is a growing challenge. A White Paper issued by the Canadian Institute of Chartered Accountants (CICA) suggests that a data-centric policy should be the focus for management, auditors and others involved in securing data in this new mobile environment. The term “security” is taken in its broadest sense to include confidentiality, integrity (accuracy, completeness and validity) and availability. (Read the CICA publications on Data-Centric Security and

Wednesday, March 16, 2011

AICPA/CICA Privacy Maturity Model

The AICPA/CICA Privacy Maturity Model (PMM) is based on Generally Accepted Privacy Principles (GAPP) and the Capability Maturity Model which has been in use for almost 20 years. In developing the PMM, it was recognized that each organization’s personal information privacy practices may be at various levels, whether due to legislative requirements, corporate policies or the status of the organization’s privacy initiatives. It was also recognized that, based on an organization’s approach to risk, not all privacy initiatives would need to reach the highest level on the maturity model. Each of the 73 GAPP criteria is broken down according to the five maturity levels. This allows entities to obtain a picture of their privacy program or initiatives both in terms of their status and, through successive reviews, their progress. (For more information, visit the CICA Privacy Resource Centre online.)

Friday, September 10, 2010

The top 10 tech issues for 2010


Annually, the Information Technology Advisory Committee (ITAC) of the Canadian Institute of Chartered Accountants (CICA)  consults with the profession to learn what its greatest concerns are. In performing an analysis of the top 10 technology issues, newer technologies and their impact on business were considered and were addressed within the context of the more established issues. This year, the top ranked issue was compliance requirements. This is followed by the impact of the recession, information management, public trust and emerging technologies (such as cloud computing, social networks and personal technology). Other top 10 issues include collaborative-extended enterprises, infrastructure, IT governance, IT resources and skills, and knowledge management. Learn more by reading the online article "The top 10 tech issues" in the September 2010 issue of CAmagazine.

Friday, June 18, 2010

Data Security Remains Top Concern for CPAs, Survey Shows


According to the American Institute of Certified Public Accountants' (AICPA) 21st annual Top Technology Initiatives Survey, data security will remain the most pressing concern over the next 12 to 18 months. This is the eighth consecutive year the issue has made the top of the list. The results of the 2010 survey will be discussed at the AICPA Top Technology Initiatives Webinar on June 23, 2010. The webinar will put the survey results in context using practical examples to provide participants with an introduction to each initiative and its implication for their clients. (Read the article "Data Security Remains Top Concern for CPAs, Survey Shows" at the Journal of Accountancy online.)

Wednesday, May 12, 2010

5 Ways to Keep Customer Information Safe

Every time you do business with a customer or a client, you wind up with access to some very sensitive information, such as payment accounts. Without appropriate protection in place, clients may find themselves asking why they should trust you. If you handle any part of your business online, the chances of someone gaining access to information immediately goes up. But, there are steps you can take to keep your customers' information safe. (Read the article "5 Ways to Keep Customer Information Safe" at Open Forum online.)

Tuesday, January 19, 2010

IT Security Predictions for 2010

Researchers from IBM and Sophos shared their thoughts on what the security threat landscape will look like for enterprises and consumers alike in 2010. Their predictions run the gamut from threats to social networking sites to an increase in attackers targeting hosted services. (Read the online article IT Security Predictions for 2010.)

Monday, December 14, 2009

Privacy guidelines take aim at identity theft and security breaches

The Canadian Institute of Chartered Accountants (CICA) and the American Institute of Certified Public Accountants (AICPA) have expanded their privacy framework to include guidance for securing personal information. The changes address best practices for securing portable devices and ensuring the strength of privacy controls. The guidance also covers disposal and destruction of personal information. (Read the article Guidelines Aimed at Thwarting ID Theft, Security Breaches Unveiled at Journal of Accountancy online.)

Tuesday, October 6, 2009

Canada - Ernst & Young survey on risk management

According to a recent survey by Ernst & Young, corporate fraud, data theft and financial reporting risk can cost organizations dearly. That’s why it’s so important for today’s businesses to get their risk management strategies right. By doing so, they can protect their valuable assets and also create a competitive advantage. In The future of risk: Protecting and enabling performance, Ernst & Young finds 96% of organizations believe they can improve risk management, while nearly half say committing additional resources to risk management could actually drive a competitive edge. The survey also finds coverage of multiple risk functions has become increasingly difficult to manage and is compounded by a lack of alignment. (Read the article "Ignoring risk management is risky, survey says" in the October 2009 CAmagazine online.)