<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FERPA Archives - Jay Longley</title>
	<atom:link href="https://jaylongley.com/tag/ferpa/feed/" rel="self" type="application/rss+xml" />
	<link>https://jaylongley.com/tag/ferpa/</link>
	<description>Innovator, Technologist &#38; Aviator</description>
	<lastBuildDate>Sun, 24 Mar 2024 20:32:28 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://jaylongley.com/wp-content/uploads/2022/09/cropped-skull01-32x32.jpg</url>
	<title>FERPA Archives - Jay Longley</title>
	<link>https://jaylongley.com/tag/ferpa/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>What is a CISO and Why do I need one in 2024</title>
		<link>https://jaylongley.com/what-is-a-ciso-and-why-do-i-need-one-in-2024/</link>
		
		<dc:creator><![CDATA[Jay]]></dc:creator>
		<pubDate>Fri, 12 Jan 2024 13:04:12 +0000</pubDate>
				<category><![CDATA[CISO]]></category>
		<category><![CDATA[201 cmr 17]]></category>
		<category><![CDATA[FERPA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Insurance]]></category>
		<guid isPermaLink="false">https://jaylongley.com/?p=952</guid>

					<description><![CDATA[<p>Lets breakdown the driving reasons behind the hiring or outsourcing of a CISO....</p>
<p>The post <a href="https://jaylongley.com/what-is-a-ciso-and-why-do-i-need-one-in-2024/">What is a CISO and Why do I need one in 2024</a> appeared first on <a href="https://jaylongley.com">Jay Longley</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Lets breakdown this question into a topic that most organizations fall under and the largest reasons driving the hiring or outsourcing of CISOs&#8230;.that topic is Compliance.  </p>



<p><h2>Responsibilities of a CISO</h2></p>



<p><h4>Ensuring Regulatory Compliance</h4>A key responsibility of the <a href="https://ciso.eccouncil.org/">CISO</a> is to ensure that the organization is compliant with various regulations such as HIPAA (Health Insurance Portability and Accountability Act), 201 CMR 17 (Massachusetts’ standards for the protection of personal information), and FERPA (Family Educational Rights and Privacy Act). Each of these regulations has specific requirements for the protection of sensitive and personal information.</p>



<p><h4>HIPAA Compliance</h4>Ensuring the security and confidentiality of protected health information (PHI), which includes implementing physical, network, and process security measures.</p>



<p><h4>201 CMR 17 Compliance</h4>Adhering to Massachusetts&#8217; standards for protecting personal information of residents, which includes creating a written information security program (WISP) and implementing comprehensive security measures.</p>



<p><h4>FERPA Compliance</h4>Protecting the privacy of student education records and controlling the disclosure of information from these records.</p>



<p><h4>Avoiding Legal and Financial Penalties</h4>Non-compliance with regulations like HIPAA, FERPA, and 201 CMR 17 can result in significant legal and financial penalties. A CISO helps in avoiding these penalties by ensuring adherence to regulatory standards.</p>



<p><h4>Building Trust with Stakeholders</h4>Compliance with these regulations is often a requirement for doing business, especially in industries like healthcare and education. A CISO helps in building trust with clients, partners, and regulatory bodies.</p>



<p><h4>Developing and Maintaining WISPs</h4>Creating and maintaining Written Information Security Programs (WISPs) as required by certain regulations like 201 CMR 17. These programs outline the administrative, technical, and physical safeguards in place to protect personal information.</p>



<p><h4>Liaison with Insurance Carriers</h4>Working closely with insurance carriers, especially in the context of cybersecurity insurance. Insurance carriers often require robust cybersecurity practices as a precondition for coverage. The CISO plays a crucial role in meeting these requirements and demonstrating compliance to insurers.</p>



<p><h4>Regular Audits and Reporting</h4>Conducting regular audits to ensure compliance with these regulations and preparing reports for regulatory bodies. This includes staying updated with any changes in the legal landscape related to information security.</p>



<p><h4>Employee Training and Policy Development</h4>Developing policies and training programs specific to these regulations. This includes educating employees about compliance requirements and best practices for protecting sensitive information.</p>



<p><h4>Risk Management</h4>A CISO’s role in risk management is crucial not just in identifying and mitigating security risks but also in ensuring that compliance risks are effectively managed.</p>



<p><h2>In Summary</h2>In 2024, the role of a CISO extends beyond just safeguarding against cyber threats; it encompasses a pivotal role in ensuring that organizations meet their legal and regulatory obligations related to information security. This includes managing complex compliance requirements, aligning security policies with regulatory standards, and liaising with insurance carriers to meet coverage prerequisites.</p>



<p>View more CISO resources here:<br><a href="https://jaylongley.com/category/ciso/" target="_blank" rel="noreferrer noopener">https://jaylongley.com/category/ciso/</a></p>
<p>The post <a href="https://jaylongley.com/what-is-a-ciso-and-why-do-i-need-one-in-2024/">What is a CISO and Why do I need one in 2024</a> appeared first on <a href="https://jaylongley.com">Jay Longley</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
