• Skip to primary navigation
  • Skip to main content

American Cyber Security Management

Secure and certify all your data and processes

  • LinkedIn
  • Twitter
  • YouTube
  • Services
    • MSP/MSSP
    • Privacy
    • Security
    • ISO/IEC 27001:2022 Training & Certification
    • Secure DevOps
    • InfoSec Risk Management
    • Incident Response Planning
    • Artificial intelligence Readiness Offering
    • AppSec-as-a-Service
    • CISO As A Service
    • DPO As A Service
    • Security Monitoring
    • Security Operations
    • Awareness Training
  • Frameworks
    • CPA
    • CCPA/CPRA
    • GDPR
    • ISO 27001:2022
    • NIST 800-171
    • NIST 800-53
    • US Privacy Laws
  • News
  • Careers
    • DPO
    • CISO
  • Partners
  • About Us
    • Privacy Notice
    • Cookie Policy
  • Contact Us

Released draft of the proposed American Data Privacy and Protection Act provides insight into what’s on the horizon

September 28, 2022 By American Cyber Security Management

Earlier this summer, a draft was released of the  American Data Privacy and Protection Act (ADPPA) that is making its way through the legislative process. Although any formally proposed legislation will likely vary in some respects, this draft of the ADPPA provides some insight into what can be expected from any upcoming final iterations of the legislation. 

The stated purpose of the ADPPA is “to provide consumers with foundational data privacy rights, create strong oversight mechanisms, and establish meaningful enforcement.” The ADPPA identifies four key components to achieve its purpose: (1) a duty of loyalty; (2) consumer data rights; (3) corporate accountability; (4) enforcement and applicability. 

ADPPA outlines a duty of loyalty which is based on data minimization, certain loyalty duties, privacy by design, and loyalty to individuals with respect to pricing. In general, a covered entity shall not collect, process, or transfer covered data beyond what is reasonably necessary, proportionate, and limited to provide or maintain a specific product or service. With some exceptions, ADPPA restricts the collection, processing, and transferring of certain information, including Social Security Numbers, geolocation data, biometric information, and other sensitive personal information. 

To be ADPPA compliant, a covered entity must establish and implement policies, practices, and procedures regarding the collection, processing, and transfer of covered data, which adequately safeguard data, mitigate privacy risks, and promote compliance with all applicable privacy laws. 

Under ADPPA, a covered entity may not deny, charge different prices or rates, or condition (or effectively condition), the provision of a service or product to an individual on the individual’s agreement to waive any privacy rights guaranteed by the ADPPA. 

Included in consumer data rights are: consumer awareness, transparency, individual data ownership and control, right to consent and object, and data protections for children and minors. To support these consumer data rights, ADPPA includes provisions governing third-party collecting entities, civil rights and algorithms, data security and protection of covered data, and opt-out mechanisms. 

In addition to recognizing consumer rights and organizations’ duties, ADPPA also establishes certain corporate accountability measures for executives such as the required designation of at least one corporate privacy officer. 

Although it is unclear when the United States will join the growing list of nations with comprehensive privacy legislation on the books, American Cyber Security Management is positioned to assist companies and organizations in proactively assessing and remediating their data privacy and cybersecurity management needs. 

To learn more about how ACSM can help your organization please use our contact page https://www.americancsm.com/contact-us/ and schedule a free discovery call today.

American Cyber Security Management is a leader in data privacy, cybersecurity, and Compliance. Our mission is to help enterprises protect their data from internal and external threats. We offer on-demand assessment, implementation, and sustainability services that focus on Privacy and Cybersecurity readiness and compliance, risk reduction, and mitigation.    https://www.americancsm.com

Filed Under: Cyber Security News

ACSM Presents at CSA Fall Summit 2022

September 26, 2022 By American Cyber Security Management

AmericanCSM.com (ACSM) is proud to announce that Carlin Dornbusch will present at the Cloud Security Alliance (CSA) Denver Fall Summit ‘22. The CSA Fall Summit is an annual event held this year at The Tivoli Center (900 Auraria Pkwy 900 Auraria Parkway Denver, CO 80204) on October 18, 2022. This all-day event brings together Colorado’s best cloud security experts to discuss and share the latest in Security, Compliance, and Privacy. Carlin will be presenting the latest in Dark Patterns. Dark Patterns are Privacy anti-patterns that businesses have implemented in order to extract more information from consumers than expected. This session will focus on identifying these patterns through numerous examples, and a discussion of the current state of issue and privacy compliance.

You can register for the CSA Fall Summit here: https://www.eventbrite.com/e/csa-colorado-fall-summit-2022-registration-354978429037

To learn more about how ACSM can help support your data privacy needs, please use our contact page https://www.americancsm.com/contact-us/ and schedule a free consultation call today.
American Cyber Security Management is a leader in data privacy, cybersecurity, and Compliance. Our mission is to help enterprises protect their data from internal and external threats. We offer on-demand assessment, implementation, and sustainability services focusing on Privacy and Cybersecurity readiness and compliance, risk reduction, and mitigation.    https://www.americancsm.com

Filed Under: Cyber Security News

ACSM and Shellman talk ISO-27001

August 31, 2022 By American Cyber Security Management

AmericanCSM.com (ACSM) and Schellman are coming together to discuss the value of ISO-27001 Certification.  ACSM’s CEO, Carlin Dornbusch (https://www.linkedin.com/in/carlindornbusch/ ), and ACSM’s VP, Paul Herbka (https://www.linkedin.com/in/pherbka/ ), talk with Schellman’s ISO Practice Director, Danny Manimbo (https://www.linkedin.com/in/danny-manimbo-2b199718/), on September 15th, 1:00 pm ET, about the value of businesses becoming ISO-27001 certified. If you are interested in learning more about ISO-27001 certification for your business, or what it takes to get there, this informative presentation will answer many of your questions.

You can register for this webinar here: https://www.schellman.com/the-true-value-of-iso-27001-and-how-to-get-certified 

ACSM is now offering ISO-27001 Lead Auditor and Lead Implementer certification courses for individuals leading their businesses to this important certification. You can learn more about ACSM’s new ISO-27001 Certification Training here: https://www.americancsm.com/iso27001training/

To learn more about how ACSM can help support your data privacy needs, please use our contact page https://www.americancsm.com/contact-us/ and schedule a free consultation call today.

American Cyber Security Management is a leader in data privacy, cybersecurity, and Compliance. Our mission is to help enterprises protect their data from internal and external threats. We offer on-demand assessment, implementation, and sustainability services that focus on Privacy and Cybersecurity readiness and compliance, risk reduction, and mitigation.    https://www.americancsm.com

Filed Under: Cyber Security News

It is time to be thinking about RMISC 2022

June 28, 2022 By American Cyber Security Management

The Rocky Mountain Information Security Conference returns in person this year. Mark your calendar for September 21-23 in downtown Denver Colorado. Early Bird Registration is open now until July 20.

Register Here

AmericanCSM.com is a Silver level sponsor this year and is coordinating another Privacy Day for the Community Day Pre-Conference Workshops. Come enjoy an entire FREE day (Wednesday, September 21st) of CPE/CLE certified Privacy Training.

Filed Under: Cyber Security News

Privacy Program Culture Change

May 24, 2022 By American Cyber Security Management

Are you still using some of those expensive privacy tools? Did your subject-matter expert, who owned those tools, find another job?

So many businesses have spent $MM’s on privacy tools, over the past 4 years in an effort to scramble to be GDPR or CCPA compliant and help sustain their new privacy program. And let’s face it, very few companies had a privacy program before GDPR, let alone U.S.-based businesses. With resource changes, COVID-19, more investment into cybersecurity and privacy, and work-from-home necessities, every business has been challenged to keep these programs afloat.

Invariably, it comes down to culture. The management of data and how data is handled is at the root of every privacy program. A business can write policies and procedures, checkboxes in the compliance portal, automatically respond to a DSAR request, and update its public privacy notice, BUT it can still not have a privacy program that any privacy professional would recognize. Without the mindset and attitude to protect data, the business will not survive on tools alone. As they say “it takes a village”. The tone-at-the-top must be delivered in a believable way so that staffers can implement the necessary changes and place the appropriate controls in place to maintain the processes of a real privacy program.

AmericanCSM.com has helped numerous businesses around the world develop and advance their privacy programs. Our privacy professional experts assess, develop and guide our clients through the highly dynamic world of regulations, but more importantly, we help instill a sense of custodial ownership in the business. Our approach with our pragmatic processes and recommendations can be quickly implemented to create long-lasting change. Business units become more agile and inter-operate at a level they have not been able to in the past. We can make the changes in a business easy to implement in short order.

ACSM has been helping businesses protect their assets and improve their security and privacy posture since 2006. Our skilled team can help your business understand its cyber weaknesses and potential threats as well as improve your security, privacy, and compliance postures. Our services include penetration testing, maturity assessments, cyber security and privacy implementation assistance, CISO-as-a-Service, and DPO-as-a-Service, to mention a few.

To learn more about how ACSM can help support your data privacy needs, please use our contact page https://www.americancsm.com/contact-us/ and schedule a free consultation call today.

Filed Under: Cyber Security News

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 10
  • Page 11
  • Page 12
  • Page 13
  • Page 14
  • Interim pages omitted …
  • Page 26
  • Go to Next Page »
  • ISSA
  • ISACA
  • ISC2
  • IAPP
  • CSA
  • CIS
  • Privacy Notice
  • Cookie Policy
  • Services
  • Frameworks
  • News
  • Careers
  • Partners
  • About Us
  • Contact Us

Copyright © 2026 American Cyber Security Management