|  | | CHAPTER CHAIR | | James Adams Director JANUS Associates, Inc. I n 1050 Washington Blvd Stamford, CT 06901 Phone: (203)251-0238 jima@janusassociates.com Primary Purpose The Data Security Chapter is for providers, their customers and advisors that use sensitive digital information in the course of conducting outsourcing business and need to secure data from unauthorized access. Sensitive data may be regulated, such as health and financial records or intellectual property such as source code and designs. IN Chapter members can expect to learn and stay on top of data security and how it affects their company, their job, and the outsourcing industry. Members will exchange knowledge and ideas on the legal, technical, organizational, and competitive issues related to data security and outsourcing. IN Executive Committee Limited to senior executives of corporate members. Designed to be representative of the different types of members (e.g., customers, providers, advisors, etc.) IN Meeting Frequency Quarterly Meeting Type Face-to-face (office, meeting room); social (restaurant); teleconference  Guest Speakers The Chapter will consider guest speakers who are industry analysts and data and privacy experts from professional organizations. Topics to include: I N1. What outsourcing professionals need to know about data protection and why it matters IN N2. Cross-border data protection issues N3. Information protection as business driver (service provider and customer) IN Non-Solicitation Policy All IAOP Chapters adhere to the non-solicitation policy. Click here to view the policy. I | IAOP Chapter: Data Security Next webinar to be held on July 16, 2009! The next Data Security Chapter webinar, hosted by corporate member JANUS Associates, will be held Thursday, July 16, from 1:00 - 2:00 p.m. EDT. Industry experts from JANUS Associates will share valuable insights on the “Changing Security Issues Involved in the ARRA (Stimulus) Act and How it Might Affect Outsourcing.” Join us to learn what you need to do to protect your organization. Mark your calendar and plan join us – Stay tuned for additional details! IAOP members wishing to attend the upcoming meeting please email the chapter coordinator at amanda.corbett@outsourcingprofessional.org If you are not as yet a member of IAOP and would like a guest pass for the meeting, please Request a Guest Pass. IAOP Members: Click Here and login to download past meeting presentations for all IAOP chapters. Meeting held - October 21, 2008 A Data Security Chapter webinar, hosted by corporate member JANUS Associates, was held on Tuesday, October 21, 2008. The program topic was “Outsourcing in Today’s New Risk Averse Business Climate: Why Information Security is becoming a top business priority and what you need to do.” Karl W. Muenzinger, CISSP, CISM, MBCI and Project Manager of JANUS Associates, shared his expertise about the dramatic effect the rapidly changing financial landscape will have on outsourcing. He shared valuable information about what you need to do to prepare for it! He covered real-life business cases where strong information security was used as a market differentiator and where information security breaches cost more than any benefit they derived. He provided insight about how lax information security can be a deal breaker. He reviewed the regulatory trend for increased due diligence, information security standards and approaches to demonstrating strong security. Webinar Held Wednesday, April 30, 2008 The latest Data Security Webinar took place on April 30, 2008 at 11:00 a.m. (PDT). Data Security chapter chair, Frank Teruel of Vormetric, and guest speakers Tom Grubb of Polivec and Gabe Zubizaretta conducted a dynamic discussion concerning: “The Impending US Economic Down-turn…What does it mean for Outsourcing and the Safety of Your Data”. The presentation was split into three parts beginning with Gabe Zubizaretta who spoke to the subject of outsourcing trends among emerging technical and non-technical enterprises, Tom Grubb who addressed extending your behavioral infrastructure to ensure the protection of your data and Frank Teruel who wrapped up with developing and extending a data security eco-system across your outsourcers’ environment. A question and answer session completed the program. Face to Face Meeting of the Data Security Chapter The Data Security Chapter of IAOP held a face to face meeting at the 2006 Summit on February 20, 2006. Pat Fisher, President of Janus Associates, Tom Grubb, Chapter Chair and Heather Mark (CISSP) presented growing evidence that data security poses a significant challenge to service providers and their customers. An informal survey was conducted to determine the attitude of those in the outsourcing industry regarding the protection of sensitive data. Download the survey results here. After the formal presentation, suggestions for future topics and speakers were discussed. Inaugural Meeting of the Data Security Chapter The inaugural meeting of the Data Security Chapter was held on February 14th, 2006 at 2:00 pm Eastern Time via web conference. The meeting was hosted by chapter chair Tom Grubb of Vormetric. To keep consumers' trust and minimize the risk of a security breach when outsourcing, the premise of the meeting suggests that organizations need to take steps to ensure that personal data is safeguarded in vendor relationships. Chairman’s Summary The Data Security Chapter of the IAOP, bringing together providers, their customers and advisors that use sensitive digital information in the course of conducting outsourcing business, held its first meeting on February 14th, 2006 via teleconference and web-seminar. IAOP Executive Director Michael Corbett provided an overview of the outsourcing industry and the IAOP. Tom Grubb described the Data Security chapter goals and objectives, followed by information describing why data security matters to outsourcing professionals. Mr. Grubb explained that disclosure laws such as California SB1386 push data theft into the media, which prompts customers and consumers to demand more legislation to protect data. Then he used a case study to show how a single public data breach at an India-based service provider caused long lasting brand damage evidenced by almost 10,000 Google many months after the breach occurred. Dr. Larry Ponemon, chairman and founder of Ponemon Institute, and Sandra Hughes, chief privacy officer of Procter & Gamble presented the Vendor Information Clearinghouse, a framework developed by the Ponemon Institute. Ponemon and Hughes explained that the VIC is a Web-based infrastructure and process for registering qualified vendors and for disclosing baseline qualifications for handling information about people and households. They invited outsourcing professionals to consider adopting the VIC as a means for customers to validate service providers they are dealing with. This validation process will help construct and corroborate confidence in doing business where private data is exchanged between service provider and vendor. Tom Grubb from Vormetric wrapped up the meeting with the encouragement to submit ideas, thoughts and suggestions to IAOP in order for the group to continue to grow and remain topically focused for 2006. Topic suggestions may be sent to her directly at tgrubb@vormetric.com. Meeting Agenda: · 5-10 minute introduction by Mike Corbett, IAOP Executive Director · 10 minutes by Tom Grubb, Why data securitys is important to Outsourcing Professionals · 30 minutes by Dr. Larry Ponemon and Sandy Hughes, Lose Their Data — Lose Their Trust: Enabling Secure Vendor Relationships |