How do we reconcile a requirement to keep backups, with a requirement that we be able to purge data on request? [closed]

As part of SOC 2 preparation (and just general operational best-practice) we take regular PostgreSQL backups and keep them for up to a year. One of our partners has a requirement that we be able to delete any data sourced from them on requ… Continue reading How do we reconcile a requirement to keep backups, with a requirement that we be able to purge data on request? [closed]

FBI employee indicted for stealing classified info on FBI cybersecurity work

A federal grand jury has charged an FBI employee for stealing classified documents and keeping them in her home between 2004 and 2017, the FBI announced Friday. The employee, Kendra Kingsley, allegedly took documents that detailed the FBI’s sources and methods the FBI uses to counter cyber threats, as well as those it uses in its counterterrorism and counterintelligence work, according to the indictment. Some of the documents detail specifics of investigations in multiple field offices, details on human sources and gaps in intelligence about foreign intelligence services, according to the indictment. The documents also detail technical capabilities the FBI uses in counterintelligence and counterterrorism work. In some cases, the documents contained information on al Qaeda members and emerging terrorism threats in Africa, as well as a suspected associate of Osama bin Laden, the FBI said. Kingsley worked for the FBI’s Kansas City division as an intelligence analyst, but was […]

The post FBI employee indicted for stealing classified info on FBI cybersecurity work appeared first on CyberScoop.

Continue reading FBI employee indicted for stealing classified info on FBI cybersecurity work

CISO Stories Podcast: Necessity is the Mother of Security

Tatu Ylönen, SSH founder and inventor of Secure Shell, discusses the genesis for the protocol and his keen interest in the application of technological solutions to fundamental cybersecurity challenges – check it out…
The post CISO Stories Podca… Continue reading CISO Stories Podcast: Necessity is the Mother of Security

CISO Stories Podcast: He Fought the FTC Over a Breach and Won

Hopefully, you won’t ever have to hire a lawyer to defend yourself against a government regulator. So what happens when the Federal Trade Commission or other powerful body baselessly accuses your company of wrongdoing where a data breach is concer… Continue reading CISO Stories Podcast: He Fought the FTC Over a Breach and Won

Forensic Focus Legal Update April 2021: Balancing Privacy And Investigation

Privacy is a major theme in this quarter’s legal update, which covers the latest developments with the European Union’s ePrivacy Initiative, some new laws in the United States, recent court decisions, and law enforcement access to third-party data. We … Continue reading Forensic Focus Legal Update April 2021: Balancing Privacy And Investigation