Showing posts with label controls. Show all posts
Showing posts with label controls. Show all posts

Thursday, March 1, 2012

Complying with the HR Component

At the risk of being called a shameless plugger, I am referring you to my recent book, "Human Resources Guide to Social Media Risks" as a tool for complying with the human resources related threats found on yesterday's Social Media Risk Assessment.


I think that the book is a necessary read for not only HR professionals, but any manager and employee in and around social media (e.g., everyone).  There are some very important lessons in the book that can really help organizations manage their social media risks from an HR perspective.  As I like to say, social media risks are human risks.  They are not technology risks.  A review of the risk assessment document in yesterday's post makes that very apparent.  As such, be sure to pick up a copy of the guide.  I think you'll be very happy you did and I really do believe that you will be doing your organization a great service.

Friday, October 7, 2011

Social Media Password Policies - More Than An Ounce Of Prevention

In early September, the Bank of Melbourne had its Twitter account hijacked by someone that used it to send phishing messages to its followers, many of whom were customers. The tweets sent from the Bank of Melbourne Twitter account contained malicious links.


The likely cause for the account compromise was a weak password used by a staffer with access to Twitter.


This event should serve as a lesson to banks with a social media presence. Just as banks maintain effective password policies to access internal systems, similar policies should be required for external systems.  Employees should be made aware of the damage that can result from lax/poor controls over passwords.  The lack of effective controls can result in reputational harm, regulatory criticism and legal action.