Home > Financial Services Information Security Tips > Compliance and Governance Digest > Insuring compliance: Nationwide tackles GLBA
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE AND GOVERNANCE DIGEST

Insuring compliance: Nationwide tackles GLBA


Diana Kelley
03.01.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


By the time the Gramm-Leach-Bliley Act (GLBA) passed in 1999, Nationwide Insurance Companies' Kirk Herath was already a privacy veteran studying the European Union's strict privacy laws. Given that the insurer handled more than 16 million policies, any one of which was a potential security liability, that experience was crucial.

Then there were the agents to consider. Nationwide had some 8,000 who collected and maintained private client information. Though the agents operated as independent representatives, "we were the custodians of their data," Herath says.

Nationwide could not take risks. Two years prior to GLBA's passage, Nationwide put in place a working group of departments, all of which touched some issue related to data privacy. Management supported the group's initial efforts with funding, explains Herath, chief privacy officer (CPO) and associate general counsel at Nationwide.

And two years after GLBA went on the books, Nationwide created an official privacy department with a staff of three -- now seven -- and operationalized GLBA's privacy and security directives. The company first examined the terms of GLBA, then mapped out a privacy statement that delineated all the actions the company would take to regulate the sharing of private data about Nationwide customers.

The biggest task was conducting a data-flow analysis. The process took six months, with the help of PriceWaterhouseCoopers providing data-collection methodologies, and 30 Nationwide staff assigned to conduct surveys and lead discussions company-wide.

In the first three years since the law passed, Herath erred on the side of sharing no data as Nationwide assessed GLBA's impact. Nor did the company have a customer opt-out system. "We didn't know whether we wanted to go the expense of creating one," Herath says.

In the end, Nationwide did purchase an off-the-shelf database to let consumers opt out, manage other preferences and allow Nationwide to cross-sell their data within GLBA's boundaries.

"We tried managing our do-not-call list ourselves, but we realized it was something we had to outsource in order to stay abreast of myriad state and federal laws," Herath says.

Like other CPOs, Herath cites the importance of close relationships with peers in the risk-assessment, IT, security and legal departments. He and Jack Jones, Nationwide's CISO, "are the best of friends. I don't know how I would do my job without him, and I don't know how people in my job get their job done in the unfortunate event where they find themselves at odds with their CISO."

"I see privacy as being inherently legal, and security as inherently technological," Herath says. "If there are two of you in separate organizations fighting for the same thing, you have twice the clout -- and two sources of funding, too."

Jones agrees. "I firmly believe that technology can and does play an important role in an effective information risk management program, but I believe it's a mistake to view technology as anything more than one of the many necessary tools for solving the problem. The scope of an effective information risk management program must also engage the people and process elements."


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
GLBA compliance requirements
Regulators issue standardized privacy notice form for GLBA compliance
Don't forget the cleaning crew in your vendor management program
Massachusetts data protection law has mixed impact on financials
Regulatory reform will require much work ahead
Download presentations from Financial Information Security Decisions 2009
Two conversations about risk assessment
For financial firms, numerous compliance requirements demand baseline controls
GLBA risk assessment steps to success
GLBA's focus on data security has helped financial services, say industry observers
Gramm-Leach-Bliley and you

Compliance and Governance Digest
Seven GRC best practices for information security
Shifting to a flexible information security framework
Vendor contract management: Regulatory guidance is risk-based
Vendor audit and monitoring contractual rights
Data breach protection: Implementing vendor breach safeguards
How to manage security risks in vendor contracts
Red Flags Rule and preparing for new regulations
Companies lagging in PA DSS compliance
Social media: Risk management strategies for financial institutions
FFIEC guidance on RDC: Guidance overview

Site Highlights
Banks scramble to boost online security
Five steps to building information risk management frameworks
Black Hat 2007: For financial firms, availability too often trumps security

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts