News & Analysis as of

Software Risk Management Compliance

Sheppard Mullin Richter & Hampton LLP

FedRAMP 20x – Major Overhaul Announced to Streamline the Security Authorization Process for Government Cloud Offerings

On March 24, 2025, the Federal Risk and Authorization Management Program (“FedRAMP”) announced a major overhaul of the program, which is being called “FedRAMP 20x.” The FedRAMP 20x announcement stated there are no immediate...more

Robinson+Cole Data Privacy + Security Insider

Joint Cybersecurity Advisory Released on Ghost (Cring) Ransomware

The Cybersecurity & Infrastructure Security Agency, the Federal Bureau of Investigation, and the Multi-State Information Sharing and Analysis Center released an advisory on February 19, 2025, providing information on Ghost...more

Ankura

Optimizing Organizational Efficiency Through Tool Rationalization

Ankura on

In an era where technology drives business success, organizations often find themselves managing an overwhelming number of tools and applications — whether purchased officially through procurement or individually at a...more

Warner Norcross + Judd

Lessons from CES 2025: The Legal Side of Product Innovation — What Every Manufacturer and Supplier Needs to Know

Warner Norcross + Judd on

The 2025 Consumer Electronics Show (CES) — one of the world’s most influential tech events — once again showcased groundbreaking innovations that are shaping the future of technology. I was among the over 141,000 attendees of...more

Harris Beach Murtha PLLC

Have a SaaS Contract in Place? You May Need an AI Addendum

Virtually every business has signed an agreement with a software as a service (“SaaS”) provider at one time or another. And now, virtually every SaaS provider (it seems, at least) is coming out with an AI-related feature or...more

McCarter & English Blog: Government Contracts...

They Did It. They Really Did It! The Arrival of the FAR CUI Proposed Rule

After years of anticipation, the Federal Acquisition Regulation (FAR) Council has announced the arrival of its proposed rule to enhance the safeguarding of Controlled Unclassified Information (CUI) in federal contracts (the...more

Mitratech Holdings, Inc

From Cost Center to Profit Driver: How HR Software Impacts the Bottom Line

For years, Human Resources has often been perceived as a necessary expense. You’re heard it: a cost center focused on administrative tasks. Why? For years, HR was like that one drawer in your kitchen – full of tangled...more

A&O Shearman

The EU Cyber Resilience Act - What You Need to Know

A&O Shearman on

The EU Cyber Resilience Act (CRA) entered into force on 10 December 2024. The CRA is the first legislation of its kind in the world that aims to enhance the cyber security of products or software with a digital component...more

Pillsbury - Internet & Social Media Law Blog

The Importance of Opting In: Pitfalls of AI Enablement Without Client Buy-In

Imagine you’re an associate at a consulting firm. You’re surprised to see a new “AI Assist” button appear in your email application one morning. Without any training or guidance from your firm’s IT department, you decide to...more

Procopio, Cory, Hargreaves & Savitch LLP

3 Steps to Protect Highly Sensitive Assets in an M&A Deal

Due diligence is a necessary part of any M&A transaction. This process can be an exhaustive deep dive into the target company’s history. In some cases, the buyer wants to assure itself of certain highly confidential and...more

Foley & Lardner LLP

Foley Automotive Update - January 2025.

Foley & Lardner LLP on

Foley & Lardner announced the 2024 installment of its Auto Trends series—A Year in Review: Updates, Trends and the Road Ahead. This series delves deep into the transformative forces shaping the automotive world by providing...more

Sheppard Mullin Richter & Hampton LLP

Governmental Practice Cybersecurity and Data Protection: 2024 Recap & 2025 Forecast Alert

To kick off the New Year (and as is now tradition, since we put out a similar Recap & Forecast last year), Sheppard Mullin’s Governmental Practice Cybersecurity & Data Protection Team has prepared a cybersecurity-focused 2024...more

Lowenstein Sandler LLP

Key Considerations When Adopting Artificial Intelligence as a CFTC-Regulated Firm

Lowenstein Sandler LLP on

On December 5, 2024, the U.S. Commodities Futures Trading Commission (CFTC) staff (Staff) issued a staff advisory (Advisory) on the use of artificial intelligence (AI) by market participants in CFTC-regulated markets.1 Staff...more

Goodwin

Texas AG Reaches First-of-its-Kind Settlement With Healthcare AI Company Over Hallucination Rate Claims

Goodwin on

In a recent settlement, the Texas attorney general resolved allegations that Pieces Technologies, Inc. (Pieces), a healthcare generative AI company, misrepresented the hallucination rate of its generative AI product to...more

Harris Beach Murtha PLLC

Key Considerations for Selling AI Software to the Government

Harris Beach Murtha PLLC on

The federal government is the biggest purchaser in America and that extends to the SaaS space. On September 24, 2024, the Office of Management and Budget (OMB) released Memorandum M-24-18, offering updated guidelines for the...more

Latham & Watkins LLP

DORA: Just Over Three Months Until Take Off

Latham & Watkins LLP on

The deadline is fast approaching for in-scope financial entities and their ICT service providers to conform to the EU’s new digital operational resilience regulation. With effect from 17 January 2025, a broad range of EU...more

NAVEX

Brainstorming Ways to Brainstorm Compliance Risks

NAVEX on

Compliance officers need to think about fraud and misconduct risks all the time, which means you need to talk to others in your organization about exactly how those risks might happen – but what’s the right way for you to do...more

Mitratech Holdings, Inc

After the Microsoft Outage: The Lingering Impact and Global Outlook on Business Continuity Planning (BCP)

In the aftermath of what could be one of the most widespread global information technology outages in history, organizations are putting a renewed focus on combating old vulnerabilities that can have cascading effects. ...more

NAVEX

AI is a New Risk Domain that Compliance Officers Must Actively Manage

NAVEX on

Let’s take a moment to address the elephant in the room: AI risk. The hype surrounding generative AI, like Chat GPT, is encouraging more people and organizations to use it. This creates a clear need to address business...more

Ankura

Navigating Privacy Compliance Challenges for Startup Success

Ankura on

Startups face unique challenges that can impact their success and sustainability. Obstacles such as financial constraints (inadequate funding or limited cash flow) and resource constraints often result in small teams having...more

Health Care Compliance Association (HCCA)

Privacy Briefs: October 2023

Report on Patient Privacy 23, no. 10 (October, 2023) Kaiser Foundation Health Plan Inc. and Kaiser Foundation Hospitals will pay California $49 million to resolve allegations that they unlawfully disposed of hazardous waste,...more

NAVEX

State of R&C Report Key Finding – Opportunity Exists to Leverage Compliance Data

NAVEX on

The operations of a modern enterprise generate a dumbfounding amount of data – much of it without really trying. Every third-party piece of software, every transaction, every spreadsheet, every document, every contract,...more

NAVEX

The Rise of ESG Risk and Compliance

NAVEX on

Environmental, social and governance (ESG) is frequently covered in the news – especially given the growing attention paid by investors and stakeholders to how businesses operate. More and more, investors use ESG reports to...more

Holland & Knight LLP

Technology Due Diligence for M&A Transactions: A Primer

Holland & Knight LLP on

In most merger and acquisition (M&A) transactions, the pace of the transaction, focus on the operational and financial performance of the target, and the competition created by multiple potential buyers make it a challenge to...more

Opportune LLP

What You Need To Know Before Starting an ETRM System Implementation Process

Opportune LLP on

Find out everything you need to know before starting an ETRM system implementation. Over the last two decades many energy companies that engaged in the purchase and sale of commodities as a matter of course in transacting...more

26 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide