Legal quicksand: Shrink-wrap and click-wrap agreements – Part 2

Typical Shrink-Wrap Terms and Conditions While the type of terms and conditions found in shrink-wrap agreements vary greatly from vendor to vendor, there are a number of common themes. In general, shrink-wrap agreements include the following potentially problematic terms: [...]

Legal quicksand: Shrink-wrap and click-wrap agreements – Part 22020-05-18T14:47:38-07:00

Legal quicksand: Shrink-wrap and click-wrap agreements – Part 1

Shrink-wrap and click-wrap agreements are the fine print you see, among other things, when you click through terms and conditions in accessing an online service (e.g., in connection with a cloud computing service) or as part of the installation [...]

Legal quicksand: Shrink-wrap and click-wrap agreements – Part 12020-05-18T14:54:06-07:00

DFARS 252.204-7012: Terms to know

DFARS 252.204-7012 requires that, as a DoD contractor, your organization and your subcontractors must obtain certification of compliance. The deadline has now passed to meet DFARS compliance rules that put cybersecurity safeguards on what the U.S. government calls 'controlled unclassified [...]

DFARS 252.204-7012: Terms to know2020-07-14T22:41:27-07:00

What changed in NIST 800-171 r1?

If you must comply with NIST 800-171 under DFARS you may wonder what has changed with the first revision, released in December, 2016.  There are two substantive changes:  "Information Systems" has been replaced by "Systems" throughout the document.  This mean the [...]

What changed in NIST 800-171 r1?2017-07-10T21:15:22-07:00

What nineteen audiences in twelve months taught me?

Navigating Fear in the Security and Compliance World

In advancing technology it is fear of having a project go sideways, over budget or fail to accomplish the stated objective that has many frozen. What if that technology we recommend doesn’t work as we hope? What if it is something required by law (such as encryption in healthcare) that we fear an unknown outcome so much that we won’t act? What if we miss a key component of a project or underestimate the effort required and the entire project goes over our budget?

What nineteen audiences in twelve months taught me?2014-12-17T23:02:14-08:00

Who has a Legal Obligation to Upgrade Windows XP, Office 2003 and Exchange 2003?

The best source of information covering this requirement comes from NIST, the National Institute for Standards and Technology.  They have a set of documents that are the standards for many requirements.  There is nothing specific in the NIST guidelines about the end of life for Windows XP, however, the need to provide Flaw Remediation is clear and that is what the X, Office 2003 and Exchange 2003 support requirements fall under.

 For example, NIST Special Publication (SP) 800-531 requires the SI-2, Flaw Remediation security control, which includes installing...

Who has a Legal Obligation to Upgrade Windows XP, Office 2003 and Exchange 2003?2024-04-21T19:43:10-07:00

Ransomware Gangs Are Now Stealing Passwords

A few months back I wrote a blog called, Don’t Get Caught by a Ransomware Gang.   The blog warned that ransomware gangs are loading malware onto computers.  Back then the threat was in the form of unwanted encryption of your [...]

Ransomware Gangs Are Now Stealing Passwords2018-08-22T11:24:07-07:00