Remove privacy-vs-security
article thumbnail

May Our Self-Insured Health Plan Limit Eligibility to Employees Vaccinated Against COVID-19?

ThomsonReuters

The following groups may be treated as distinct groups of “similarly situated” individuals for purposes of the HIPAA nondiscrimination rules: (1) groups of participants based on a bona fide employment-based classification, such as length of service or full-time vs. part-time status; (2) participants as a separate group from beneficiaries (e.g.,

105
105
article thumbnail

Security vs Compliance: Where Do They Align?

Audit Board

If you’ve been wondering where security practices and compliance requirements align and where they diverge, you’re not alone. Security and compliance have synergies, but they aren’t the same, and it can be challenging to tease them apart. What Is Security? Here are some common categories for security tools: .

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

What’s New With ISO 27002? What You Need to Know About the ISO 27001 Control Set Update

Audit Board

27002 includes generic information security controls as well as implementation guidance for organizations looking to implement the 27001 Information Security Management Systems (ISMS) standard. What Are the Changes to ISO/IEC 27002:2022 vs ISO/IEC 27002:2013? The 11 new controls are as follows: Physical security monitoring.

article thumbnail

Six Categories CISOs Should Address in the Board Report

Audit Board

Rise in supply chain security incidents across competitors, representing an emerging threat for the organization. Emerging regulatory pressures from the federal government or privacy regulators. Good KPIs are a measurement of the company’s own performance against key security metrics. Number of overdue action plans by team.

article thumbnail

Top Takeaways From the 2023 Focus on the Future Report

Audit Board

Cyber/data security and talent remain the top risks facing organizations, with over 80% of respondents seeing cyber/data security as a “very high” or “higher than average” vulnerability, and nearly three of four responding the same for talent. Audit Effort vs. Risk Level: A Troubling Lack of Alignment.