Being a CISO is a tough gig. The perpetual deluge of news items on hack after hack, breach after breach, has finally conveyed that data security is an imperative for all companies, large and small. But the perception still lingers that the Chief Information Security Officer (or her
Information Bytes
The law blog for data with people problems
Information Bytes, published by Information Governance Group, focuses on practical aspects of information governance including data retention, data management, defensible disposition, and data security. The blog addresses compliance with regulatory requirements, risk mitigation related to data handling, and strategies for maximizing the value of organizational information. It covers topics such as establishing legally validated records retention schedules, implementing information management policies, data breach response readiness, and aligning information governance initiatives with business objectives. The content also explores the intersection of information governance with litigation discovery and privacy regulations, providing guidance for organizations to manage information cost-effectively while controlling legal and security risks.
Latest from Information Bytes - Page 6
Why govern our information? Reason #11: Thousands of federal and state records retention laws apply to your company
Dr. Stephen Covey reminded us that “important” is not the same thing as “urgent.” Records retention reminds us that important is not the same thing as exciting. I get it – records retention schedules are boring. But the fact remains that…
Has the Illinois Supreme Court opened the floodgates on biometric data privacy cases? You bet your sweet BIPA
Why govern our information? Reason #12: Unnecessary business data causes unnecessary litigation costs
“If your clients don’t have a records management system, they may as well take their money out into the parking lot and set it on fire.”
– Former U.S. District Court Magistrate Judge John Facciola
We all know that ediscovery…
Law firm insider threats don’t take a break for the holidays — they may get worse.
Most people have elevated stress during the holiday season — work, travel, family, money, time. And holiday stress can make people inattentive, tired, frustrated, and willing to take short cuts, especially when it comes to computer and Internet use. This…
If you teach a man to phish …
With PII breach notification statutes, the rules keep changing
Whew – we’ve survived yet another round of states enacting or amending their PII breach notification laws. If a trial lawyer’s vacation is the time between her question and the witness’s answer, a data security lawyer’s vacation is when state…
Law firm data retention – they can’t hack what you no longer have
Last week’s post explored why law firms need data security policies. Before we move on, I’d be remiss if I didn’t mention another policy that’s absolutely crucial for the law firm’s data security posture – a records management policy, coupled…
Law firms, data security policies, and cobblers’ kids
You’d think, among all types of businesses, that law firms would be at the front of the pack in having a data security policy. After all, law firms regularly tell their clients how important it is to have effective policies…
How to gain assurance against human security vulnerabilities
If you had a choice between doctors to perform surgery on you, which would you pick: a doctor who has sat through training on how to perform an appendectomy; or assurance that your doctor will successfully perform your appendectomy?
The answer seems…

