Commentary

When Privacy Is Paramount For A CIO

"We look forward to audits," says Gerhard Lindenmayer, CIO of DialAmerica Marketing. Say what?

"We look forward to audits," says Gerhard Lindenmayer, CIO of DialAmerica Marketing. Say what?DialAmerica Marketing is one of those companies whose representatives call at dinner time to offer you a discount subscription to Time magazine. As CIO, Lindenmayer is very concerned about the security of the consumer data his company deals with every day, particularly in light of the recent problems other companies have had with exposing personal customer data, inadvertently or through security problems.

One way to ensure the security of his network is by inviting third parties to examine the company's internal processes. "We look forward to audits because every single audit we do makes us that much better," says Lindenmayer. For instance, DialAmerica is audited at least once a year by the banks that fulfill its credit card transactions. More important, the company is audited for its compliance with the Card Information Security Program, part of Payment Card Industry, or PCI, data security standards established by Visa and MasterCard. Visa requires PCI compliance audits take place quarterly. "We chose to have them do it once a month," says Lindenmayer.


More Global CIO Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

The data DialAmerica uses to conduct its business -- names, phone numbers, addresses, ZIP codes, credit card numbers, and Social Security numbers -- is kept at company headquarters in Mahwah, N.J. That data is transferred over a "secure VPN tunnel" to the 27 call centers the company uses across the United States. "We utilize two different carriers for redundant purposes," Lindenmayer says. Also, data encryption is a key strategic effort. "The entire leg over the network is triple encrypted," he says.

That data, along with product offers and product keys, is used to populate the buffers of the electronic dialers that make the phone calls for each call center session. A homegrown interface on a call center worker's workstation displays "only what [data] they need to make the call," Lindenmayer says. No cell phones, papers, pens, or pencils are allowed in those call centers, to keep workers from recording data. At the end of a session the call center worker logs off and the buffers are emptied of data. "At no time do we keep a lot of records out in the field," he says.

It's an insular, mostly homegrown system, which helps Lindenmayer, who's worked for DialAmerica for 25 years, the last three as its CIO, keep it secure. "We've gone to great lengths to lock down the company internally," he says. "We've seen the writing on the wall. We need to be sure we don't lose any of this data."


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links