<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Chaos to Compliance</title>
	<link>http://chaostocompliance.com</link>
	<description>Compliance and IT security observations</description>
	<pubDate>Tue, 17 Oct 2006 22:09:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.1</generator>
	<language>en</language>
			<item>
		<title>Outsourcing risks, security in India</title>
		<link>http://chaostocompliance.com/?p=1</link>
		<comments>http://chaostocompliance.com/?p=1#comments</comments>
		<pubDate>Sat, 09 Sep 2006 20:23:06 +0000</pubDate>
		<dc:creator>Jim</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://chaostocompliance.com/?p=1</guid>
		<description><![CDATA[I came across several items recently that (taken together) confirm my belief that the privacy breaches we have seen here in the US are just the tip of the iceberg. First, a UK news outlet did an undercover investigation of outsourcers in India, the IT Compliance Institute has a brief summary here. And a news [...]]]></description>
			<content:encoded><![CDATA[<p align="left">I came across several items recently that (taken together) confirm my belief that the privacy breaches we have seen here in the US are just the tip of the iceberg. First, a UK news outlet did an undercover investigation of outsourcers in India, the IT Compliance Institute has a brief summary <a href="http://www.itcinstitute.com/display.aspx?id=2436">here</a>. And a news story on the investigation is <a href="http://www.news.com.au/dailytelegraph/story/0,22049,20535618-5001021,00.html">here</a>.</p>
<div align="left" />The findings are pretty frightening- security is so lax at many of the call centers in India that a black market for identity data is apparently flourishing there. Companies affected that are mentioned in the investigation include some large financials, Barclays and HSBC. Couple this with some findings in a <a href="http://www.csoonline.com/read/090106/fea_exec-3.html">CSO Magazine article</a> that show Indian IT organizations lagging behind their US counterparts in adoption of every key security practice.The takeaway from this is that if you are an organization outsourcing business processes to India (or anywhere really), you need to carefully assess risks inherited from your service provider. You need to understand which of your service providers are storing sensitive data (EPHI, NPI) on your behalf, and what security controls they have in place. And if you are responsible for IT security and are not on top of this in your organization, you need to get on top the risk management for vendors  situation quickly.Jim</p>
]]></content:encoded>
			<wfw:commentRss>http://chaostocompliance.com/?feed=rss2&amp;p=1</wfw:commentRss>
		</item>
	</channel>
</rss>

