29 July 2005

The Identity Theft Protection Act...

As the legislation for the ID Theft Bill makes it's way through the full Senate, one has to wonder what will change. What behavior are we trying to influence here?

Approved on a voice vote, the Identity Theft Protection Act requires data brokers, government agencies and educational institutions to disclose security breaches to consumers within 45 days if there is a "reasonable risk" of identity theft involved in the breach.

The evidence of possible identity theft includes such factors as whether the data containing sensitive information is useable by an unauthorized third party and whether the data is in the possession of an unauthorized third party that is likely to commit identity theft.

Under the bill's language, companies and other organizations are required to develop, maintain and enforce a written program for the security of sensitive information. Physical and technological safeguards will be mandated through rules and regulations developed by the Federal Trade Commission (FTC).

Within a year of the passage of the bill, the FTC is required to develop procedures for authenticating the credentials of any third party to which sensitive personal information is to be transferred or sold by a data broker or other organization.

For security breaches involving 1,000 or more consumers, the firms responsible for the breaches must not only notify consumers but also the FTC. The agency, in turn, will post a report of the breach on its Web site without disclosing any sensitive personal data.

For breaches of fewer than 1,000 records that do not create a reasonable risk of identity, the data broker must still notify the FTC.


The real work begins for those institutions who thought they were exempt from regulations like the FTC SafeGuard Rule and the Gramm-Leach-Bliley Act (GLBA). Now they must do what the banks,thrifts and other OCC controlled organizations have been doing for years. Spending more money and resources on Information Security. Sure, human factors will have their toll even on those who have been complying with these laws for years. Bank of America and others have been burned. What is more interesting to see going forward is how the third-party processors and other information supply chain companies will behave, and for that matter, what the largest institutions will do to audit these business partners.

Stealing and selling sensitive information is the work of increasingly criminal organizations, located in countries across the globe. And even in our own back yard here in the United States. Let's just hope that organizations who are taking our sensitive personal identifiable information to verify our identity have the right people, right resources and take this legislation seriously this time.

27 July 2005

Whistleblowing: The Age of Undersight...

The impact of "Whistleblowing" on your organizations ability to detect fraud is only as good as your safeguards for retaliation. Who will step forward if they think that their job or personal safety is at risk? This article by Daniel Westman sums up many of the issues surrounding "Undersight".

Edmund Burke's famous 18th-century dictum encapsulates why compliance efforts cannot rely on written policies or codes of conduct alone. After all, Enron had policies on paper forbidding the practices that brought down the company. Without people willing to report violations of law or codes of conduct, compliance efforts inevitably will be frustrated.

The thesis of this article is that the new civil and criminal whistleblower provisions of Sarbanes-Oxley, coupled with growing acceptance of whistleblowing in both the law and popular culture, may create a climate in which employees more frequently engage in "undersight" to report violations of law or policy. "Undersight" is a term this author has coined to describe corporate employees who witness potential fraud first-hand and voice their concerns, in contrast with "oversight" through which corporate outsiders attempt to detect fraud relying on second-hand information.


Undersight is a culture issue. No one wants to be known as the "Stool Pigeon" or the "Rat" who attempts to undermine the organization with a warning bell about someone or some procedure that is flawed. How you promote the use of "Undersight" in your company begins with management behavior.

To the extent that fear of retaliation has deterred employees from identifying themselves by openly raising concerns, the ability to make anonymous complaints knowing that such complaints must be investigated may encourage whistleblowing. Put differently, before SOX, it may have been easier to rationalize remaining silent based on fears of retaliation. The new stature given to anonymous complaints, however, may give employees greater assurance that their identities will not be discovered, and that their concerns still will be addressed. Thus, a common rationalization for not blowing the whistle may be significantly undermined.


Even as SOX has heightened the issues around detecting and reporting internal fraud by employees, it still may be the external auditors who remain the bad guys. Have you ever made it obvious to an outside auditor that you have a "hunch" or suspect something isn't right? Just remember, you don't have to wait. Audit Committee's are obligated to investigate any anonymous tips, regardless of the outcome.

25 July 2005

The Cost of War...

At a recent meeting of the ISSA in the Washington, DC area there was much discussion about the governments spending agenda on Information Security. And for good reason.

It seems that the Office of Management and Budget is moving towards a model for procurement that will support the Federal Enterprise Architecture(FEA) E-Gov initiatives. The fear is that Information Security is being put in a "box" for easier and more efficient ordering for federal agencies, except INTEL and DOD. They are not impacted by the latest move to a "Center of Excellence" for InfoSec.

CISO's at these federal agencies are operating with their hands tied in an effort to improve their FISMA grades with declining budgets and line items being moved from their control to the "Center of Excellence".

As a result of the FEA PMO’s analysis of the FY 2006 budget data, OMB established the IT Security Line of Business to propose common solutions and architecture strengthening the ability of all agencies to identify vulnerabilities, defend against threats and manage resulting risks. The FEA PMO will guide this LoB initiative through development of a common solution architecture by:

• Providing initial direction on EA work products (i.e., common solutions and target architecture);
• Reviewing EA work products and providing feedback;
• Reviewing service components developed by the LoB;
• Identifying areas for reuse or standardization across agency architectures; and
• Identifying agency movement toward LoB standards and services in their EA

Transition Strategy

The FEA PMO and the LoB task force will collaborate on identifying potential common solutions (e.g., training/awareness, incident response, certification and accreditation, the selection of security products, reporting, implementation of security configurations, policy and budget coordination, disaster recovery, contingency planning, and access controls), and will identify business processes and systems impacted if a security service is standardized or outsourced.

Use of the FEA Practice and reference models to identify areas for reuse and standardization will result in better and more consistent security management processes and controls across the Federal government.


Has the cost of war finally gotten to the point where we have finally made "Information Security" and "Contingency Planning" a commodity to be put in a box? Not until the agencies are standardized on configurations, hardware/software and other baseline security appliances and applications will you have the ability to do what is initially intended by the initiative. To save money, resources and redundancy.

Information and Physical security is a moving target for a reason. It evolves in response to attackers new tools and exploits probing to find the latest vulnerabilities. We wish the non-INTEL and DOD agencies luck in their new mission to secure their respective enterprises.

22 July 2005

The Spectrum of Trust...

What is TRUST? Can you see it? Can you hear it? Can you feel it? Maybe all of these. But does it live on a dynamic spectrum?

No Trust<----------Trust Exists--------->Implicit Trust

When you trust someone or something, you put "faith" in it. You are more inclined to invest your time and effort to spend time with it and to ensure that it thrives and grows. Because when you move from the far left where "No Trust" exists and move to the right, somewhere along that spectrum trust begins to exist. And it isn't until you get to a point when you never think about it again, that maybe you can say that trust is "Implicit".

Steven Mufson has an interesting perspective on risk and trust:

As much as President Bush or British Prime Minister Tony Blair say we won't let terrorists change our lives, this could be the start of a new era, and not in a good way. There is something unsettling about the idea of turning America into a nation of snitches and amateur spies. Is the guy taking photos of the George Washington Bridge a terrorist or the next Henri Cartier-Bresson? Are people wandering in front of national monuments scoping out targets or are they tourists? And do you trust the strangers around you to make those judgments based on looks and feelings?

All the same, on the Metro last week, I departed from my usual routine of simply reading the newspaper, or looking over a manuscript, or daydreaming. I found myself glancing up to look at the other passengers and their bags, or to gauge the distance to the stairs, or read the instructions on the emergency exits. Reassuring? Maybe.

In any case, this week you'll be able to find me on the platform waiting for the next train.


Taking risks is about degrees of trust. The amount of risk you decide to accept is directly tied to the degree to which you are willing to trust the entity that you are placing your faith in. Whether it's your spouse, your broker, your boss, your company, your partner, your supplier, your board of directors, your congressman or your government; each entity lives and changes on this spectrum of trust.

19 July 2005

Phishing Risk: Two-Factor Authentication to the Rescue...

In a recent banking survey conducted by the Risk Management Association (RMA) on Operational Risk Management, 105 institutions responded. Over one third indicated their greatest risk was "Unauthorized Access" from both insiders and outsiders together with attacks on bank systems.

What was obvious from the survey was that no matter the size of the institution, both Internet and Vendor Risk are pervasive. With banks with assets over $100Bn, the highest risk was ineffective IT planning that aligned investment with business priorities.

It's no wonder that institutions like the National Australia Bank (NAB) and others are losing tens of millions of dollars per year from Internet Banking Fraud.

NAB is losing about A$1 million a month to Internet banking fraud, according to a confidential internal document acquired by Australian newspaper Herald Sun BusinessDaily.

According to the newspaper article, the document was issued to senior technology staff as part of a drive to improve online security and stem a "tide of losses".

The report warns that Internet banking fraud is on the increase with criminals using "increasingly sophisticated" ways of stealing customers' details. The document also claims fraudsters are tricking Web banking customers into becoming couriers and moving stolen funds out of the country.


With two-factor authentication in the wind, it's no wonder you see vendors scrambling for time with bankers CIO's to sway their thinking on the best approach to this business issue.

According to figures from The Australian Bankers Association (ABA), the country's banks lost A$10 million to online fraud last year.

The ABA said in March that Australian banks would introduce an industry standard for two-factor authentication for verifying online banking customers later this year, although each bank is free to choose its own method of secondary identification.


Bank of America has already adopted the PassMark technology. Sitekey is one anti-phishing method that associates an image with an online ID to give the consumer a higher level of assurance that they are logging into the correct site. E-Trade has chosen RSA's technology for their site.

Putting an end to account hijacking is a primary concern of the US FDIC and they welcome your input.

18 July 2005

Digital Discovery: Electronic Evidence Risk...

In the latest issue of Board Member Magazine, Lisa Ferri reminds us of the importance of the risk of Electronic Evidence.

If the only thing better than learning from your mistakes is learning from the mistakes of others, then directors need to take a lesson from Philip Morris. Last year the tobacco giant was slapped with a $2.75 million fine by a federal court. The offense? Wrongful destruction of e-mails, otherwise known in legal circles as spoliation of evidence. The court found that at least 11 Philip Morris executives “at the highest corporate level” were guilty of violating a court order concerning document retention. In other words, they purged and paid the price.

United States of America v. Philip Morris USA Inc., et al. is a cautionary tale of the problems awaiting companies that are either unaware of or unprepared for the world of electronic evidence. The rules governing that world are evolving at warp speed.


In the United States, does an employee need the companies permission to seize your computer at the workplace for electronic evidence? In order to be more informed about this procedure and the legal implications in your enterprise, see CCIPS.

Warrantless workplace searches occur often in computer cases and raise unusually complicated legal issues. The starting place for such analysis is the Supreme Court's complex decision in O'Connor v. Ortega, 480 U.S. 709 (1987). Under O'Connor, the legality of warrantless workplace searches depends on often-subtle factual distinctions such as whether the workplace is public sector or private sector, whether employment policies exist that authorize a search, and whether the search is work-related.


Your compliance or legal office can provide you with the guideance for any employee that is suspected of violating company policies with regard to computers crime or theft of confidential information or intellectual property. The question remains, what policy is in existence today and what methods have been utilized for full disclosure to employees that may impact their rights of privacy on the job?

For more help on this subject see: Best Practices for Seizing Electronic Evidence.

Just remember, Forensics and gathering electronic evidence in a criminal matter is in opposition to your recovery. Once a violation has occured, you can make changes, clean up the problem and get back to normal or you can preserve the crime scene for evidence. It's one or the other. If it's not, then that is when you run into problems. Document retention strategies in combination with Forensic Digital Discovery procedures are critical to any organization that cares to mitigate the ongoing risks of electronic evidence.

15 July 2005

External Risk: The Economics of Catastrophe...

The risk of an active 2005 hurricane season is raising the stakes for business in the energy and financial services sectors at an accelerated pace.

Hurricanes are threatening our oil production in the Gulf of Mexico and crude is trading at $US61.

Oil prices rose for a second day, after the US Government said more than half of Gulf of Mexico output remained shut down following Hurricane Dennis. A new storm is approaching the region, raising concern about supply shortages.

Production in the Gulf was 43 per cent of normal at noon New York time yesterday, compared with 4 per cent the previous day, figures from the US Minerals Management Service showed. Tropical storm Emily formed in the Caribbean and next week might reach the gulf, the source of a third of US oil output.

"Now there are worries about this tropical storm, Emily, they're getting all these big storms really quite early in the season," said David Thurtell, commodity strategist at Commonwealth Bank.

"If you get these continued disruptions, then second-half production is going to disappoint."


Insurers and other firms in the financial services sector are at risk if regulators don't allow them to increase premiums. Business could be impacted by those higher premiums or the risk of losing coverage all together.

Last year was difficult for insurers as four major hurricanes in the Southeast triggered about $23 billion in payouts.

In Florida, where insurers paid the most damages from last year's hurricanes, companies have so far had little success in getting regulators to allow higher premium prices.

But another year of hurricanes on par with 2004 could give insurers more leverage in applying for higher premiums, said Mike Paisan, an insurance analyst at Legg Mason in New York.

"If Florida regulators do not allow higher prices, major insurers could threaten to withdraw. Having fewer insurance companies there would definitely raise prices," Paisan said.


The risk of loss from external events such as these are hard to predict, yet easier to prepare for each year. Predictive models are getting better and the largest and most savvy insurers are using them to their benefit. AIR's Catastrophe Models are a prime example.

Lloyd's Loss Modeling Department has licensed AIR Worldwide's catastrophe risk management system to assess the risk from global catastrophes and for the simulation of Realistic Disaster Scenarios (RDS).

RDSs test the ability of the market and individual syndicates to withstand large catastrophes such as a major hurricane hitting the Miami area or a severe earthquake striking downtown Los Angeles. By bringing the AIR models in house, Lloyd's risk management team will have a better understanding of the potential impact of such scenarios. All Lloyd's managing agents are required to complete RDS exercises annually.

14 July 2005

Corporate Governance: Testing for Organizational Disease...

Now that the 25 year sentence has been handed down in the Worldcom corporate goverance and fraud case, it's obvious that prosecuting white collar crime cases is a real challenge.

In the HealthSouth Corp. fraud trial, the jury made a different decision and the CEO was acquited.

Some lawyers suggested white-collar cases are inevitably difficult to present to jurors, whether they live in Birmingham or New York. "It's different from a drug deal or a bank robbery," said Donald Stern, a Boston attorney who was formerly that city's top federal prosecutor. "It's not obvious that a crime has been committed."


What the Board of Director's and Executive Management do know is that it's time to make some more changes in Corporate Governance initiatives. The relationships with the shareholders is bound to continue to be a challenge for any management team and they realize that they must be creating a culture full of ethics and risk management principles.

At the end of the day it comes down to the evidence presented to the jury. And the evidence is typically a presentation of information utilizing forensic methods of discovery. Dr. Thomas R. O'Connor at NCWC has some interesting background on the subject of Investigative Methods in Forensic Accounting.

Signs of financial crime can be initially detected in a variety of ways -- by accident, by whistle-blowing, by auditors, by data mining, by controls and testing, or by the organization's top management requesting an inspection on the basis of mere suspicion. Ideally, fraud detection ought to be recognized as an important responsibility throughout every organization, and every employee in an organization ought to be familiar with the disciplinary consequences for breach of trust as well as failure to report criminal misdeeds against the organization. On a practical level, however, there are steps to the investigative method used in an organizational context that are far from these ideals, and reaching the "breakthrough" point is more an art than science. It is the purpose of this lecture note to outline the investigative methods and procedures used in most cases.


Red Flags of Organizational Behavior:

1. Unrealistic performance compensation packages -- the organization will rely almost exclusively, and to the detriment of employee retention, on executive pay systems linked to the organization's profit margins or share price.

2. Inadequate Board oversight -- there is no real involvement by the Board of Directors, Board appointments are honorariums for the most part, and conflicts of interest as well as nepotism (the second cousin to corruption) are overlooked.

3. Unprofitable offshore operations -- foreign operation facilities that should be closed down are kept barely functioning because this may be where top management fraudsters have used bribes to secure a "safe haven" in the event of need for swift exit.

4. Poor segregation of duties -- the organization does not have sufficient controls on who has budget authority, who can place requisitions, or who can take customer orders, and who settles or reconciles these things when the expenses, invoices, or receipts come in.

5. Poor computer security -- the organization doesn't seem to care about computer security, has slack password controls, hasn't invested in antivirus, firewalls, IDS, logfiles, data warehousing, data mining, or the budget and personnel assigned to IS. Simultaneously, the organization seems over-concerned with minor matters, like whether employees are downloading music, chatting, playing games, or viewing porn.

6. Low morale, high staff turnover, and whistleblowers -- Low morale and staff shortages go hand-in-hand, employees feel overworked and underpaid, frequent turnover seems to occur in key positions, and complaints take the form of whistleblowing.


As we move forward on strategies for improving ethics and protecting corporate assets it's clear that educating board members and employees to the symptoms of corporate disease can be a key initiative. That education and awareness program could be the beginning of a whole new era of high performing companies. And for that matter, the programs effectiveness may be the first test of any organizations health.

13 July 2005

Terrorism Risk: Moving Beyond Fear...

In the aftermath of the July 7th London Terrorist Bombings the investigation and forensics are quickly answering our most obvious questions. Who? How? Why?

Yet we must be reminded that fear is an obstacle between us and truly understanding the event. It creates paralysis. It even makes us react in ways that can only be called stupid if we are to improve our safety and security.

The fear is in your mind and not based upon the real risks. Moving beyond fear and making sound decisions for the future involves looking beyond the newspaper headlines. It means looking at the threats and the effectiveness of the countermeasures. Now it means making prudent and logical security trade-offs. Beware of those who may cloak their actions as security-related to terrorism.

Let's not surround ourselves with security countermeasures that makes us have a false sense of security. To invest millions or billions more money in transportation security for the mass transit systems will help deceive us even more. Those who don't understand security or how to make trade-offs spend too much money and resources on countermeasures that don't and won't work.

When a threat is inevitable, focusing on prevention can blind you. Terrorism in the sense we are witnessing in London or Spain or monthly in Israel or Iraq is destined to continue without warning for many decades to come. The brand Al Qaeda is here to stay.

Security is about risk prevention. Safety is protecting assets from unplanned and undetermined actions. Security is for those deliberate and intentional acts such as theft and other criminal attacks. Preventing terrorist acts that are planned and intended to inflict damage, death and destruction is like trying to prevent people from stealing or committing fraud. Countermeasures such as walls, safes, guards, cryptography, ID cards or watermarks are largely ineffective and technology only makes security more complex.

What is changing is the focus on the reality of threats that we can't totally prevent. Bruce Hoffman's article The Logic of Suicide Terrorism sums this up nicely:

Nearly everywhere in the world it is taken for granted that one can simply push open the door to a restaurant, café, or bar, sit down, and order a meal or a drink. In Israel the process of entering such a place is more complicated. One often encounters an armed guard who, in addition to asking prospective patrons whether they themselves are armed, may quickly pat them down, feeling for the telltale bulge of a belt or a vest containing explosives. Establishments that cannot afford a guard or are unwilling to pass on the cost of one to customers simply keep their doors locked, responding to knocks with a quick glance through the glass and an instant judgment as to whether this or that person can safely be admitted. What would have been unimaginable a year ago is now not only routine but reassuring. It has become the price of a redefined normality.

In the United States in the twenty months since 9/11 we, too, have had to become accustomed to an array of new, often previously inconceivable security measures—in airports and other transportation hubs, hotels and office buildings, sports stadiums and concert halls. Although some are more noticeable and perhaps more inconvenient than others, the fact remains that they have redefined our own sense of normality. They are accepted because we feel more vulnerable than before. With every new threat to international security we become more willing to live with stringent precautions and reflexive, almost unconscious wariness. With every new threat, that is, our everyday life becomes more like Israel's.


The bomb sniffing bomb proof bus is coming to Jerusalem soon to augment the human security already present to deter and detect terrorist suicide bombers. All too often, two of the most important questions are forgotten:

1. What new potential security risks does this new solution cause?

2. What new trade-offs and expenses are a result of implementing the new solution?

01 July 2005

Let the Class Action Discovery Begin...

CardSystems Class Action law suit has been filed. Let the discovery begin.

ERIC PARKE and ROYAL SLEEP
CLEARANCE CENTER, INC., a California
corporation, On Behalf Of Themselves, All
Others Similarly Situated, and in the Interest of
the General Public of the State of California,
Plaintiffs,

vs.

CARDSYSTEMS SOLUTIONS, INC., a
corporation; MERRICK BANK
CORPORATION, a corporation; VISA
INTERNATIONAL SERVICE
ASSOCIATION, a corporation; VISA U.S.A.
INC., a corporation; MASTERCARD
INTERNATIONAL INCORPORATED, a
corporation; and DOES 1-200, inclusive,
Defendants.

A class-action suit has been filed in California against CardSystems, Visa, and MasterCard seeking a declaration that CardSystems violated due standards of care in its data-security methods and that the card companies failed to provide timely notice of the nature and extent to which credit-card data was compromised.
According to the lawsuit, CardSystems had been alerted "by other entities" late last year that consumer data had been exposed and failed to take prompt remedial action or notify consumers. The suit alleges that CardSystems violated Visa and MasterCard rules against storing consumer information and also violated the Payment Card Industry Data Security standard by improperly storing credit-card and transaction data, failing to maintain a firewall, failing to restrict access to its computers, and failing to encrypt cardholder data.

The suit charges that MasterCard was remiss in not publicly disclosing the breach until June 17, even though it had been informed by CardSystems of the breach in May and had traced fraudulent incidents back to CardSystems in April.


The legal and regulatory motions are moving towards even more controls to see that banking and other personal information is protected properly. A national law is in the works in the US to try and stem the tide of the ID Theft tidal wave. Who is going to pay for all of this added security and regulation? The consumer is.

The insider case at Bank of America, Wachovia and two other banks -- involving a far smaller number of accounts than the hackers' assault on CardSystems Solutions -- could prove to be far worse for consumers, said Avivah Litan, an analyst with Stamford, Conn.-based Gartner Inc., an information technology research firm.

``It may not be bigger, but that stuff is a lot more dangerous,'' Litan said. ``These are people who have access to a lot more personal information, so it's very serious.''

Wachovia and Bank of America were forced to alert more than 100,000 customers in May after police in New Jersey charged nine people, including seven bank workers, in a plot to steal financial records of thousands of bank customers.


Why try and rob banks or hijack armored car's when you can sell someone's ID and Account Info for $10.00 X 100,000? What we are experiencing is a "Breakpoint" in the system. A point at which all of the rules change. What are the new rules for success going to be moving past this turning point?

At Breakpoint, the rule change is so dramatic that continuing to use the old rules will not work any longer. We have reached a "Breakpoint"!

29 June 2005

ERM Conference has a COSO bonus...

The 2005 Enterprise Risk Conference sponsored this Fall by The Conference Board is focused on How to Execute ERM in your company, topics include:

* What Does your Board of Directors Need?
* How to Articulate and Develop Risk Appetite within your Unique Culture
* COSO in the Real World
* Managing and Coordinating Risk Management Roles
* From SOX Compliance to ERM Value
* Tools, Techniques and Approaches for Building Sustainable ERM Program
* The Value Proposition for ERM: A Case Study
* Town Hall Session
* Quantitative Measurement of Operational and Strategic Risk: Fact or Fiction
* Integrating ERM into Strategy
* Integrating ERM with Performance Management


Mercer Oliver Wyman is the sponsor and they certainly know Risk Management Consulting. What is interesting about the conference is the location. The Financial District in New York City is "Ground Zero" for much of the risks that any organization is encountering these days whether they are credit, market or operational.

What is really the call here?

This conference is intended for executives who need a better understanding of the roadmap for a strategic risk management program. The 2005 ERM Conference is intended for Chief Risk Officers and everyone charged with overseeing integrated risk management in their companies. Attendees at past conferences have included CROs, CFOs, General Auditors, strategy, finance and operating executives.

The most relevant topic we see at this two day conference could be good for those CRO's who still are unclear about COSO:

COSO in the Real World
Concurrent Session C1: 1:15 - 2:15 pm


COSO has provided the “standard” for enterprise risk management.
We will talk about how companies are using the COSO guidelines
and how they are adapting them for their companies. We will also
learn the level of interest at corporations to follow COSO guidelines.
Should you be thinking about this? How do you respond to board
inquiries about COSO?

Jeff Cooper
Director, Enterprise Risk Management
Capital One Corporation

Greg Grieff
Enterprise Risk Manager
Chicago Mercantile Exchange Inc.

If you don't know about COSO, here is an Executive Summary

27 June 2005

Audit Committee's Allies...

The Audit Committee and it's chairperson are evolving into a significant "PowerBase" within our corporate ecosystems. What the shareholders are demanding makes the Audit Committee even more important in providing the information and communication of the true "State of Affairs".

Spencer Stuart has recently completed a study of 50 Audit Committee Chairs to get their perspectives.

The product of in depth conversations with a select group of highly respected audit committee chairs in Europe and North America, Global Fifty: Perspectives of Leading Audit Committee Chairs reveals how changing regulatory requirements have affected the functioning and composition of the audit committee, its interaction with corporate management and advisers, and audit committee recruitment. Specifically, the study examines:

* The audit committee's heightened role in assessing business risks
* The compliance demands of Section 404 and the business impact of the regulatory requirements
* The challenges to recruiting qualified audit committee members, including a discussion about the real and perceived increase in director liability
* Recommended practices for running an efficient and effective audit committee
* The elevated role of the internal auditor
* The potential long-term consequences of regulatory changes on the accounting profession


Having a diverse Audit Committee is a key component in having an effective team working on behalf of management and the shareholders. Beyond someone with a CPA or Finance background, you need someone with Operations and Technology experience. They should not have an adverse relationship with the C-level management. If they do, then this could be a sign that current management is under a higher level of scrutiny than they would like. It could be a signal that the Audit Chair is not getting the answers they need or are being blocked from getting the facts. Audit committee's always need the ability to get the answers to their questions quickly and without major hassles. Maybe even more importantly, they need allies to assist them in getting those facts and answers as efficiently and effectively as possible.

A new breed of Audit Committee ally is emerging to take on those tasks that they are not equipped to perfom themselves. These firms who are allies with Audit Committees can bring substantial talent and resources to the table on a tactical basis. These boutique consulting, audit and research firms are typically comprised of former executives from large corporations, systems integrators or the big four accounting firms. They work in tandem with the Audit Committee Chair to assist them in getting answers, background and profiles that provide them the bigger picture. And sometimes, it's that bigger picture that provides them with the insight and information to they require to do their job. To protect and preserve corporate assets.

For a look at one trusted firm, see Caveat Research.

24 June 2005

Negative Stock Price Reaction to Announcements of Operational Loss Events...

This article by Cummins, Lewis and Wei has an interesting hypothesis regarding Operational Risk and the Market Values of institutions.

The Market Value Impact of Operational Risk Events for U.S. Banks and Insurers

Abstract:
This paper conducts an event study analysis of the impact of operational risk events on the market values of banks and insurance companies, using the OpVar database. We focus on financial institutions because of the increased market and regulatory scrutiny of operational losses in these industries. The analysis covers all publicly reported banking and insurance operational risk events affecting publicly traded U.S. institutions from 1978-2003 that caused operational losses of at least $10 million - a total of 403 bank events and 89 insurance company events. The results reveal a strong, statistically significant negative stock price reaction to announcements of operational loss events. On average, the market value response is larger for insurers than for banks. Moreover, the market value loss significantly exceeds the amount of the operational loss reported, implying that such losses convey adverse implications about future cash flows. Losses are proportionately larger for institutions with higher Tobin's Q ratios, implying that operational loss events are more costly in market value terms for firms with strong growth prospects.


Here are a few other papers worth exploring on Operational Risk Management:

Implications of Alternative Operational Risk Modeling Techniques

Operational Risk in Financial Service Providers and the Proposed Basel Capital Accord: An Overview

22 June 2005

Operational Risk: Call Center Fraud

The risk of offshoring is rearing it's head again as the infamous Sun Tabloid has uncovered Call Centre Fraud in India impacting banks and other firms that outsource these operations.

City of London police are investigating allegations that a call centre worker in India sold the bank account details of 1000 UK customers to an undercover reporter, raising fresh fears about the security of customer data at offshore centres. UK daily tabloid The Sun claims a reporter was able to buy personal bank account details for £4.25 each from an IT worker in Delhi. The worker reportedly told the journalist that he could sell up to 200,000 names a month.


Let's review the Benefits of BS 7799-2: 2002 Information Security Management System Certification:

· Brings your organization to compliance with legal, regulatory, and statutory requirements including HIPAA, Gramm-Leach-Bliley (GLBA), Sarbanes-Oxley, California SB1386, CFR21:Part 11, EU-Directive, and many others...

· Significantly limits security and privacy breaches that can cost millions: examples include lost information, downtime, internal/external threats, consumer driven litigation, etc.

· Ensures that a commitment to security and privacy exists at all levels and that all employees are educated on security and privacy within your business

· Provides your organization with continuous protection that allows for a flexible, effective, and defensible approach to security and privacy

· Reduces operational risk; vulnerabilities are mitigated


Here is another good lesson from the International Security Forum.

Section:CB61 Third Party Access Source: ISF

Objective:
To ensure that access to the application by a third party is only provided once a risk assessment has been performed and a formal agreement, such as a contract, has been established.

Standard of Good Practice:

Third parties (ie external organisations, such as customers or suppliers and members of the public) that require access to the application should be subject to additional controls. They should only be granted access on completion of a satisfactory risk assessment and if supported by a formal agreement.

Risk assessments of third party access arrangements should take account of the:

· criticality and sensitivity of information and systems to be accessed
· relationship with prospective third parties (including the strength of their security practices) and the nature of the associated business process
· technical aspects of connection (including the effectiveness of IT infrastructure, access control mechanisms, methods of connection and any vulnerabilities in third party networks)
· obligations implicit in any agreements such as providing a third party with a reliable service or timely and accurate information. Agreements should be documented in a formal contract and approved by the business ‘owner’.

The contract should:
· oblige third parties to comply with good business practices and provide information about any security incidents
· clearly state the services to be provided such as the business practices to be adopted, timeframes for completion of transactions and an agreed process for resolving disputes
· specify agreed security arrangements, such as those for managing changes / incidents, restricting access and preserving the confidentiality of important business information
· include arrangements for ensuring that transactions cannot be repudiated
· protect intellectual property rights
· include the right to audit third party security arrangements.

Third party access arrangements should be reviewed periodically to ensure that risks remain within an acceptable limit.


The International Security Forum (ISF): Formerly known as the European Security Forum, the ISF has developed a standard of good practice for its forum members. The Forum’s Standard for Information Security is loosely based on the British Standard 7799 and COBIT. The Forum’s Standard of Good Practice addresses 5 primary aspects of information security, 30 control areas and 133 control sections.

20 June 2005

US National Preparedness Month: September 2005

National Preparedness Month is planned for September 2005 in the US to raise awareness and to "Get Ready". This is the time to focus on an "All Hazards" approach to preparedness and the American Red Cross and Department of Homeland Security will be emphasizing just that.

“We are pleased to have the American Red Cross, which has long been a leader in emergency preparedness and response, co-sponsor National Preparedness Month 2005,” said Homeland Security Secretary Michael Chertoff. “The commitment of the American Red Cross and the members of National Preparedness Month Coalition are integral as we work to encourage all Americans to prepare for emergencies. As leaders in their communities, these organizations will help spread life saving information and move the entire nation toward a greater state of preparedness.”

National Preparedness Month will provide Americans with a variety of opportunities to learn more about preparing for emergencies, including natural disasters and potential terrorist threats. Events, activities, and messages across the nation will encourage individuals to get an emergency supply kit, make a family emergency plan, be informed about different threats and get involved in preparing their communities.


In support of this important national initiative, local, regional and national events are being planned. 1SecureAudit will be providing free webinar's on how to create your own Corporate Emergency Response Team (CERT):

The 1SecureAudit Corporate Emergency Response Team Web Briefing will provide you with the Critical Success Factors to set up your own Emergency Preparedness Team and to make your business more resilient.

Preparing for unplanned interruptions has always been a good business practice. Availability is the name of the game and 1SecureAudit has been helping companies plan for and recover from interruptions of all kinds. Remember, any facility that acts as the primary location for business operations, whether housing your people, systems or both must be addressed.

Briefing Topics include:

· How to set up your own CERT

· Benefits of CERT Implementation

· Resources available for free

· Critical Lessons Learned


The reasons why an organization may need to evacuate its offices are not always site-specific. Some causes, such as a fire or power outage, may pertain to the systems or facility itself, while others like terrorism are external in nature - and equally unexpected. Regional events such as hurricanes, travel bans, and business interruptions at other local facilities may not physically affect your headquarters, but they do impact the ability of your people to reach it.

What you may be doing already
Having a formal evacuation plan for the facility in place, as well as plans for staff to work from home or other company facilities.

Possible weaknesses in your plan
Untested plans might prove to be ineffective and chaotic. Alternate facilities may not have required equipment and access to systems and data. Notifications of key personnel must be real-time and redundant to insure the correct message gets through every time.

Business Crisis and Continuity Management solutions from 1SecureAudit:

· Help you reduce or avoid revenue losses
· Prepare you for unplanned business crisis and disruptions
· Help you create Corporate Emergency Response Teams for the Enterprise
· Protect your mission-critical data by leveraging an ironclad infrastructure
· Reduce downtime and increase employee safety and productivity
· Enable you to resume business and employee activities more quickly and cost- effectively following a disaster or other unplanned interruption
· Help you reduce the cost of Terrorism Risk Insurance premiums

To register for an upcoming
CERT Webinar click here.

17 June 2005

DHS: GAO Report on Cyber Security...

The GAO report on the Department of Homeland Security's (DHS) Cyber Readiness is now out. The GAO Report Highlights are nothing new.

CNET'S Charles Cooper's commentary on the subject is to say the least, tired.

Will any of this light a fire in Washington? As a political issue, cybersecurity rarely leads the evening network newscasts. New legislation to establish the weighty-sounding position of Assistant Secretary for Cybersecurity may help. So might the passage of the DHS Cybersecurity Enhancement Act of 2005. (Money and authority never hurt.)

But a drumbeat of criticism nonetheless is growing in response to current events.

Maybe the new blood at DHS will take the criticism to heart and order a recalibration, because there's no time to waste. More than 1,000 new worms and viruses were discovered in the last six months alone. What's more, networks will run into more complex worms and viruses--some of which will be deployed by politically motivated hackers--in 2005 and beyond.


The point is valid yet the private sector is the one who is ultimately responsible for their own risk management and mitigation when it comes to protecting vital systems and networks. They already know this and don't expect the DHS or the government in general to be able to do much about the threat. Afterall, look how resilient the Internet has become. The measures taken in design, redundancy and failover is already a proven factor. What isn't proven is that each private sector company who has responsibility for the economic security of our nation has an "A" on their report card.

The fact is that when it comes to Information Technology, we are just bad housekeepers. It's complexity is part of the issue, the other is that the majority just don't have any clue what goes in to making it all work, 24/7. When you take the laptop home on the weekend and let the kids surf on AOL with it you are setting up your company for more house work back at the corporate shop. Insider threats from spyware and malicious code caused by plugging that laptop back in to the corporate network have been slowed, yet everyday the "Help Desk" rings with dozens if not hundreds of issues like this.

The DHS doesn't have a priority on stemming the tide of these script kiddies using tools like Metasploit. They have a priority on finding, arresting and prosecuting the few that are stealing Intellectual Property, Personal ID's, and government secrets. We can only hope that Congress gives them more resources to make a real difference.

15 June 2005

D&O: A Board of Director's Check-Up...

In a recent presentation by NASDAQ Insurance Agency, President and CEO Bill McGinty had some wise advice. Read your policies with extra care and your legal team at your side.

The Important Issues in Directors and Officers Liability Insurance

The Escalating Awards Issue – The average securities litigation settlement escalated from $16 million to over $36 million. Are your insurance limits sufficient?

The Shared Limits Issue – Over the last decade D&O policies have extended coverage to include protection for the corporation (“Entity Coverage”) as well as including coverage for employment practices liability and even some Errors and Omissions coverage. The result has been a cost effective program that has the effect of diluting the actual protection available to the Directors and Officers. In effect, the extension of coverage circumvents the original purpose of Directors and Officers Inability Insurance.

The Severability Issue – In the event of corporate misrepresentation such as significant financial restatements raising to a level sufficient for the rescission of the D&O, the innocent Outside Directors lose their policy protection along with the Inside Directors. The optimal situation is language insuring that innocent directors will be severed from the effect of the rescission of the policy making the policy non-rescindable under certain conditions.

The Bankruptcy Issue – Bankruptcy Courts have been considering arguments that D&O insurance proceeds are a corporate asset and denying or delaying the use of insurance proceeds for defense for Directors and Officers. Pre-set allocation of limits between the Corporation and the Directors and Officers provides some protection from the Bankruptcy courts. A safe haven may be separating protection for the corporation and the individual Directors and Officers.

Other items on your D&O Checklist should include: (Source: NASDAQ Insurance Agency)

1. Aggressively participate in brokering your D&O Program.

2. Insist on direct meetings with insurance carrier underwriters

3. Investigate higher "Side A" limits (cost-saving strategy)

4. Learn the difference between the denial of a claim and rescission of your policy.


What is at issue here is the plaintiffs recovering as much for their clients as possible, and that has included personal assets of the directors.

This article from Randy Myers at Corporate Board Member sums this up quite nicely:

Tim Burns, a partner at Neal Gerber & Eisenberg in Chicago says that you should always demand approval of the insurance and make sure your company doesn’t put off the purchase or renewal of D&O until the last minute, giving you less time and clout in negotiating coverage.

What if plaintiffs in a strong bargaining position insist—as happened with WorldCom and Enron—that they won’t settle without taking a piece of your hide? Burns has a possible way to work around this: buy yet another additional layer of insurance protection, with a unique provision that the layer of insurance disappears if a plaintiff goes after your personal assets. Given that stark choice, he suggests, most plaintiffs would take the insurance money at hand rather than gamble on reaching your personal funds. Burns says he has had informal conversations with insurance companies about underwriting such policies and expects they’ll become available if sufficient demand materializes.

13 June 2005

NORA is Now Dressed in Blue...

Now that Jeff Jonas's NORA (Non-Obvious Relationship Awareness) and SRDnet.com have been dressed in IBM Blue, a.k.a., DB2 Entity Analytic Solutions it's anyones guess who or what will be "Connecting the Dots."

DB2 Relationship Resolution answers the question "Who Knows Who?" IBM DB2 Relationship Resolution software begins where most solutions leave off, extending the customer view to identify and include the non-obvious relationships among individuals and organizations. An individual's relationships can provide a more complete view of their risk or value to your organization, whether they're a customer, prospect, or employee - even if an individual is trying to hide or disguise his or her identity.


Industry applications DB2 Relationship Resolution has tremendous application in industries such financial services, insurance, government, law enforcement, health care and life sciences, and hospitality. Organizations in these and other industries can use Relationship Resolution to: Connect insiders to external threats.

> Find high & low value customer relationships.
> Give fraud detection applications x-ray vision.
> Determine "network" value of the customer.
> Protect customers, employees, & national security.

What types of relationships can Relationship Resolution find?

> A potential employee who shares a P.O. Box with a convicted ID thief
> An account holder who shares a cellular account w/ a known money launderer
> An account exec who shares the same address as your hottest prospect
> A customer who lived with a wanted terrorist suspect
> An employee who lists your largest account holder as an emergency contact

DB2 Anonymous Resolution determines "Who is Who and Who Knows Who... Anonymously? It enables multiple organizations to selectively share data and leverage proprietary data in a matter that never exposes sensitive information, while still identifying relationships and developing leads.


"Finding the Needle" is not really the right analogy here. It's more like, let's find the one piece of straw in this haystack that meets this range of parameters. However, false positives and false negatives are always the name of the game when it comes to these kinds of solutions.

In order for this solution to work accurately, first you have to know "Who is Who". If this means that some how you have the same name as someone else, and that someone else has links to other people that are on a "Watch List", then you could become a false positive. The only ways to solve this are to feed the system with more information such as addresses, social security numbers, dates of birth and all the normal ways to more effectively ID people who have the same name. It also allows you to cross check who had an insurance policy, drivers license or any other data that would show up on a credit application such as your mothers maiden name. The other strategy is to make sure that you go "public" with who you are, where you live and what your blood type is so that their starting point will always verify who you are, for certain.

"The seemingly simple questions of 'who is who?' and 'who knows whom?' cut across a wide variety of business problems today," said Janet Perna, general manager, IBM Information Management Software. "The SRD technology provides solutions to these age-old problems with unparalleled speed and accuracy."

SRD software strengthens IBM's middleware portfolio via a multidimensional approach to analytics that dramatically extends the capabilities of identity-based applications. The combination provides value to business partners who deliver business intelligence and other applications that might require a single customer view, fraud detection, or customer relationship management across many industries, such as government, banking, insurance and healthcare.

"The combination of SRD technology with IBM's middleware platform will bring a new era of accuracy, speed and scale to business analytics," said John Slitz, CEO, SRD.


The biggest question now is; how do you find some entity that we don't know we are looking for? That is why it's important to see who is connected to what, a phone number, a bank account, an address, a frequent flyer number or a license plate. These patterns and relationships will ultimately give us the "insight" we need to detect a potential plot to commit fraud, launder money or attack a target.

03 June 2005

Critical Infrastructure Protection: NISAC to the Rescue

The NISAC has a small $20.M budget yet a very important task. Educating the next generation of Robert Oppenheimer proteges. Oppenheimer was the leader of the 20's something team that created nuclear devices known as "Little Boy" and "Fat Man" that helped end WWII with Japan.

In collaboration with Sandia National Laboratories, LANL (Los Alamos National Labs) through CHS (Center for Homeland Security) has also established the National Infrastructure Simulation and Analysis Center, or NISAC, whose contribution to homeland security is to identify infrastructure vulnerabilities to feasible terrorist threats.


NISAC's function is to figure out the answers to some difficult questions or "What if's". A good example might be: Should a dirty bomb make it's way past our detection and defenses in Long Beach and God forbid be detonated, how long can we afford to keep the port closed? The answer has an economic impact and a socially political paradox that requires unbiased thinking. That is where NISAC comes in.

These NISAC students have been selected by the Office of Educational Programs (OEP), which hosts the program for the U.S. Department of Homeland Security (DHS). The Science and Technology Directorate supports the program, which is open to any student interested in pursuing scientific and technological innovations that can be applied to the DHS.

Through the Program, DHS supports the growth and mentoring of the next generation of scientists as they study ways to prevent terrorist attacks within America, reduce America's vulnerability to terrorism and minimize the damage and recovery efforts from attacks that occur.


Given that the policy makers and scientists are now looking at how critical infrastructure has sophisticated interdependencies, it's time to use some of our great computing assets to answer these really hard questions. Seven of Sandia's computers are the fastest supercomputers in the world and even the older models are faster than most corporate or university machines. NISAC can do most of it's modeling on even a cluster of Dell's that have enough muscle to get the answers faster than the 6 week waiting list for time on supercomputers at Los Alamos.

CHS is home for some agent-based modeling projects that are used to help answer really hard questions. Especially about the behavior of humans in the aftermath of such significant business disruptions as closing the port of Long Beach. Or Houston?

The Los Alamos National Laboratory's Center for Homeland Security is evolving into the premier homeland security resource for the nation in the areas of Chemical and Biological Threat Reduction, Nuclear and Radiological Threat Reduction, and Borders, Information, and Infrastructure Protection. As an intramural Laboratory, we are a trusted DHS resource that responds in a continually adaptive, highly responsive manner to all technical requests. Through the steady development of our ReachBack capability the Center has permeated all corners of the Laboratory engaging the full resources of the Los Alamos National Laboratory to be brought to bear on DHS issues, crises, and questions. The Center for Homeland Security is viewed as a valued asset to regional, state, and local homeland security organizations because of our willingness to engage these entities and assist in helping them prepare, train, and if necessary, respond to both terrorist events and natural disasters.


Unfortunatley for the scientists, testing the models is difficult since 85% of the critical infrastructure is owned by the private sector. These corporate giants such as Verizon, Con Edison, Archers Daniel and the major banking institutions all are under the "Liability" constraint to share their precious and proprietary data, maps and diagrams. DHS is helping to smooth the way for more diligent cooperation in the legal discussions.

Let's just hope that we can give the scientist's what they need to do their job, faster and with more accuracy. Only then will we be able to truly understand the matrix of critical infrastructure in our country.

01 June 2005

Hurricane Season 101: Contingency Plan

Now that the Atlantic Hurricane season has now started, it's time for a little review.

Contingency Plan Objective:

To provide individuals with a documented set of actions to perform in the event of a disaster, enabling information processing to be resumed within critical timescales.

Contingency plans should be formulated to ensure that staff are aware of the steps they would be required to take in the event of a disaster affecting the computer installation.

The format and content of contingency plans should comply with enterprise-wide standards / procedures, form part of a wider business continuity plan and be distributed to all individuals who would require them in case of an emergency. Such individuals should be informed of their responsibilities and equipped to fulfil them.

Plans should include:

· conditions for their invocation
· the critical timescales associated with the business applications supported by the installation
· a schedule of key tasks to be carried out, responsibilities for each task and a list of services to be recovered, in priority order
· information security controls applied during the recovery process
· arrangements for processing from last successful back-up to time of disaster and then to resumption of normal service
· provisions for the clearance of any processing back-logs that may have built up during the system outage
· resuming processing using alternative facilities
· procedures specified in sufficient detail to be followed by individuals who do not normally carry them out.


Source: ISF Section IP7 - Service Continuity
If there is a serious interruption to information processing, for example if a disaster occurs, the computer installation may be unavailable for a prolonged period. Considerable forethought is required to enable information processing to continue in these circumstances and to keep the business impact to a minimum. Accordingly, this area covers the development and content of contingency plans, and the coverage and validation of contingency arrangements.

31 May 2005

External Events: Training and Simulation to Mitigate Risk

Every so often you come across a company or technology that is worthy of consideration for your enterprise. With hundreds of vendors products in several categories of Operational Risk, the Reality Response Division of AIS is one for your training and simulation portfolio.

The risk of loss from external events is a growing emphasis by many OPS Risk Officers. Preparedness is a key strategy to mitigating hazards and minimizing the loss of property and life. Imagine for a moment that you have a complete model of your facility, building or mall. A virtual model. One that you can use to train employees, staff and other suppliers about the idiosyncratic nature of your evacuation procedures or shelter-in-place locations. Not only is this method of training smart, it is cost effective and allows for participant interaction directly with the model and the procedures.

Real-time training with people in one room or multiple locations it does not matter. The participants can be exercised without exposure to potentiall hazardous situations until they are ready for a complete and full test of the simulation with a live scenario. The other applications include your physical security teams.

In today's uncertain world, security forces are asked to combat a wide variety of public safety threats - local street crime, terrorist attacks, and international conflicts occur with alarming frequency. At AIS, we understand these threats and have developed an extensive offering of training programs to enhance the performance of security forces on the front lines.

> Judgmental Use-of-Force
> Firearms Training
> Counter-Terrorism
> Chem-bio Response
> Marksmanship Training
> Incident Command
> Tactical Carbine
> Tactical Handgun Skills
> Rifle Instructor
> Behavior Pattern Recognition
> Checkpoint Security


Advanced Interactive Systems, Inc., (www.ais-sim.com) provides comprehensive training solutions for people in positions where lives are on the line, including law enforcement, military, government, security, corrections and emergency responders. AIS manufactures PRISim training simulators that provide lethal and less-lethal weapons handling and judgment skills. The AIS Ltd. group designs and builds anti-terrorist and other special application training facilities for military and special operations groups, with installations in more than 60 countries. The Reality Response Division manufactures interactive simulation systems and synthetic environments that provide reality-based training for CBRNE (chemical, biological, radiological, nuclear, explosive) hazard response tasks. Headquartered in Seattle, Washington, AIS Inc. is a privately-owned company with offices in Washington D.C.; McLean, Virginia; Monterey, California; Orlando, Florida; Abu Dhabi, UAE; Singapore, Malaysia Farnham, England.

27 May 2005

Software Quality Risk Assurance: Feasible or Desireable?

For those of you who have never heard of the Metasploit project, now you have. This could be your worst nightmare or it could be your best ally.

This is the Metasploit Project. The goal is to provide useful information to people who perform penetration testing, IDS signature development, and exploit research. This site was created to fill the gaps in the information publicly available on various exploitation techniques and to create a useful resource for exploit developers. The tools and information on this site are provided for legal penetration testing and research purposes only.


In a recent presentation by Dr. Eric Cole, CTO of the Advanced Technology Research Center at Sytex, Metasploit was highlighted as a tool that could be utilized to attack your own systems. Why?

At the 50,000 ft. level, the logic goes something like this. You have to utilize the same tools that attackers use on your own networks to understand exactly where your vulnerabilities lie. If only the Chief Risk Officer or Chief Information Security Officer only knew what challenges they really face in the next phase of Information Warfare.

The ethics of providing such tools is no different than other debates that are embedded in the US Constitution. The Right to Bear Arms. At some point the topic of regulation will become louder than it is today. What really matters is that the technology companies invest more heavily in software quality assurance and they do more diligent testing. Many have realized the cost of catching a bug or vulnerability after general release costs exponentially more dollars to fix than at an early stage of software development.

And that is exactly why the Metasploit project exists. Six Sigma Software Quality Risk Assurance is neither feasible nor desirable for most companies who choose to develop operating systems and applications for the high technology sector.

25 May 2005

A Risk Strategy for Corporate Business Survival - Lesson 5 - Document

“4D”
A Risk Strategy for Corporate Business Survival
Deter. Detect. Defend. Document.

By Peter L. Higgins

Lesson 4 of a 4 Part Series


The Mission
Document the normal so you know when and where there is an unauthorized result. In order for the attacker to obtain their objective, the target must produce this unauthorized result. These might include:

· Increased Access
· Disclosure of Information
· Corruption of Information
· Denial of Service
· Theft of Resources

In order to understand that an attack is actually occurring, normal results have to be documented and a historical trend has to be established. What is normal? How do you know what normal looks and feels like? You document, store, record and analyze what normal is. If you have done this for long enough and across the potential targets the attacker is trying to exploit, then you will know the second an unauthorized result takes place.

The Take Away
Documenting the behavior of people, processes, systems and external events is a vital component of a complete strategy for risk mitigation. Understanding what normal “is”, begins with effective documentation and analysis. Many organizations begin to document long after it is too late or as a result of a significant business disruption. Documentation remains to be a challenge for many, and a task that attackers know is likely to be left undone or behind schedule.

Conclusion
A “4D” Risk Strategy for Business Survival is only effective if it is operating on a continuous basis. You must create the culture and the due diligence to see that it becomes part of the fabric of the organization internally and with outsourced partners or suppliers. Only then will the attacker realize that this combination to deter, detect, defend and document is alive and growing in your enterprise. This is when attackers become discouraged, afraid, uncertain and ultimately ready for a new and less formidable adversary.

Attackers use tools to exploit a vulnerability to create an action on a target that produces an unauthorized result, to obtain their objective. These “4D” lessons should put you on the way to creating a more survivable business.

Peter L. Higgins is the Managing Director of 1SecureAudit, an Operational Risk Management Solutions firm located in McLean, VA. He can be reached at higginsp@1SecureAudit or 703 245 3020.

24 May 2005

A Risk Strategy for Corporate Business Survival - Lesson 3 - Defend

“4D”
A Risk Strategy for Corporate Business Survival
Deter. Detect. Defend. Document.

By Peter L. Higgins

Lesson 3 of a 4 Part Series


The Mission
Defend the target from any actions by the attackers tools. Targets may include a person, facility, account, process, data, component, computer, Intranet network or Internet. Actions against the target are intended to produce the unauthorized result. Some action categories are labeled:

· Probe
· Scan
· Flood
· Authenticate
· Bypass
· Spoof
· Read
· Copy
· Steal
· Modify
· Delete

The Take Away
In order to understand how to defend your corporate assets, you have to attack them yourself using a continuous combination of tools and tests. Only then will you find out where your single point of failure lies and where the attacker is going to successfully exploit a vulnerability you didn’t know exists.

23 May 2005

A Risk Strategy for Corporate Business Survival - Lesson 2 - Detect

“4D”
A Risk Strategy for Corporate Business Survival
Deter. Detect. Defend. Document.

By Peter L. Higgins

Lesson 2 of a 4 Part Series


The Mission
Detect the use of tools by the attackers. These tools are what they use to assess the vulnerabilities within and throughout the organization. These tools include surveillance, physical attack, information exchange, user commands, scripts or programs, autonomous agents, toolkits, distributed tools or data taps. Some are high tech and most are the craft of social engineers.

The attackers are using a combination of these tools and tactics to exploit corporate vulnerabilities in:

· Design
· Implementation
· Configuration


The Take Away
Just about any significant business disruption can be traced back to the fact that the attacker was able to effectively exploit the organizations defenses using a systematic method and the correct tools. Detection of threats begins by detecting the use of tools. Whether it’s the surveillance of an individual or of a facility. Whether it’s the design of the building or the software code for the E-Commerce system. Whether it’s the implementation of security cameras or the firewall. Whether it’s the configuration of the controls for access to the vault or to the ERP system. You have to continuously detect the use of the attackers tools and their methods to exploit your vulnerabilities.

21 May 2005

A Risk Strategy for Corporate Business Survival - Lesson 1 - Deter

“4D”
A Risk Strategy for Corporate Business Survival
Deter. Detect. Defend. Document.

By Peter L. Higgins


Lesson 1 of a 4 Part Series

Executive Summary
Our corporate assets are under attack by a continuous barrage of new laws, new employees, new competitors and new exploits. Business survival in the next decade will require a more effective and robust risk strategy to deter, detect and defend against a myriad of new threats to the organization.

Modern day attackers include hackers, spies, terrorists, corporate raiders, professional criminals, vandals and voyeurs. Simply said, these attackers use tools to exploit vulnerabilities. They create an action on a target that produces an unauthorized result. They do this to obtain their objective.

Here are four key lessons to create a “4D” risk strategy in your enterprise.

Lesson 1 – Deter

The Mission

Deter the attacker from launching a salvo of new threats to compromise your organizations assets. You first have to understand the value of your corporate assets to determine what are the most valuable in the eyes of your adversary. You must make it increasingly more difficult for these valuable assets to be attacked or you will find yourself under the constant eye of those who wish to create a significant business disruption.

These attackers are individuals who take on these quests or objectives for several key reasons. They include financial gain, political gain, damage or the simple challenge, status or thrill. It’s your job to create deterrence for each one of these objectives.

The Take Away
In order to effectively deter potential risks to your corporate assets, first you have to understand what they are and how valuable they are in the eyes of each kind of attacker. The more valuable the target, the more deterrence it requires.

19 May 2005

Cyber-Crime & E-Forensics...

Companies such as Intelligent Computer Solutions are making the Computer Forensic investigators more effective. In fact, they are making it more difficult for those hackers, attackers and others to steal corporate information and assets, abuse acceptable use policies and to harm the reputation of organizations.

Intelligent Computer Solutions (ICS) is the technology leader in the design and manufacture of high-speed Hard Drive Duplication equipment, Software Cloning Solutions and Diagnostic Systems. Having developed the hard drive duplication technology (and holding a US Patent C,131,141), ICS has gained international name recognition for 14 years of customer service and for providing its customers with cutting edge solutions.

Intelligent Computer Solutions is a prominent supplier of Law Enforcement & Computer Forensic Systems to Law Enforcement personnel ranging from local police departments to Federal and International agencies. ICS units are being used today by government agencies in the US, Canada, Europe, the Middle East, China, Australia and New Zealand.


Online Fraud and other internal mischief is keeping the industry busy working with clients on a number of issues including:

"Consumers and businesses alike must remain constantly vigilant about personal and financial information," said Patricia Kachura, senior vice president for ethics and consumer affairs at The DMA. "E-mail scams are becoming more sophisticated and scammers are becoming more organized, and efficient in exploiting illegally obtained personal information to the fullest extent possible."

Financial fraud, for example, costs consumers and businesses billions of dollars annually. Based on a 2004 poll of 5,000 people in the U.S., the industry analyst firm Gartner calculated that $2 billion a year is lost to banking scams, including online fraud and phishing.

The top five spam scams for April as identified by the NCFTA include:

1. Web Mobs: Web mobs are well organized groups of computer-savvy criminals who form hierarchical networks on the Internet in order to commit identity theft and fraud with personal identification and financial information. After gathering victim information via phishing schemes, the Web mob buys and sells the information among its members or through online auctions. They use Web sites and chat forums to discuss and exchange techniques and tools.

2. Cross-Site Scripting (CSS): CSS vulnerability is caused by the failure of a Web site to validate the intended address of user input, such as personal or financial information supplied to make an online purchase, before returning that data to the client's Web-browser. Instead, that information is sent to another, unauthorized site. This is called cross-site scripting and is caused when an intruder causes a legitimate Web server to unknowingly send a page to a victim's browser that contains malicious script or HTML. The malicious script runs with the privileges of a legitimate script originating from the legitimate Web server and redirects the information to the intruder's Web server. More information on this practice is available at http://www.cert.org/archive/pdf/cross_site_scripting.pdf.

3. Pharming Attacks: Pharming is the redirecting of a Web request to another location entirely. On a computer hijacked by pharmers, for example, a user will type a URL (such as their bank's Web address), but will unknowingly be redirected to a designated phishing site that looks very familiar. Because the user did not click on any obscure link, the site will appear to be legitimate.

4. Phishing: Phishing is by far the most abundant scam witnessed by the NCFTA to-date., Bank and credit card phishing scams are constantly evolving, making it more difficult to identify the forgery. Source codes which have been used to determine where "phished" information was being sent after it was harvested, are now being hidden by phishers. Phishers are also disabling mechanisms such as 'right-click' on the phishing sites for the purpose of masking the compromised URL.

5. Spyware - Trojans & Malicious Code: This is software that surreptitiously performs certain tasks on your computer, typically without the user's consent. This may include collecting personal information about you, or infecting your computer with a Trojan or malicious code. Such instruments can cause your computer to be used for other criminal conduct, such as Denial of Service attacks, or to act as part of a spam relay network.

Spyware and Trojans are downloaded onto a user's computer in two ways. First, the most frequent way is by accessing Web sites containing them. Secondly, such tools can infect a computer through a spam e-mail that includes a link to a site containing spyware or Trojans. In some instances a user need not even open the e-mail attachment for it to execute or load to your computer without one seeing it occur.

These identified spam scams are based solely on limited NCFTA data. However, this information is shared with the FBI, which, with assistance from The DMA's Slam Spam project, provides law enforcement authorities with a much more robust understanding of the top spam scams.

06 May 2005

Offshoring: Audit Processes and Facilities

Thanks to Christopher Koch for his article on "Don't Export Security".

U.S.-based companies routinely underestimate the extra elements of risk introduced into the offshoring equation by issues like poor infrastructure, political instability and legal systems that don't line up with Western practices, says Ken Wheatley, vice president, corporate security of Sony Electronics. "People are so focused on saving money and shifting operations that they don't think about the safeguards that need to be put in place," he says. "They assume that people in different countries have the same mind-set and safeguards and sense of due diligence, and that's just not the case."


Ken Wheatley is correct and more companies need to have offshoring due diligence that makes sense. Here are a few key questions for any organization considering an outside supplier relationship.

What is the importance of the function or process being performed to the mission critical components of our daily operations? If the answer is high, then you know that your first risk mitigation step may be to re examine whether this should ever be outsourced!

If the answer is medium or low, you should ask for the last audit results on these key areas of ISO 17799. And if these haven’t been audited, then why risk handing over any activities to any supplier without thorough due diligence.

A.12.1- Compliance with legal requirements to avoid breaches of any criminal and civil law, statutory, regulatory or contractual obligations and of any security requirements.

A.11.1 - Business continuity management to counteract interruptions to business activities and to protect critical business processes from the effects of major failures and disasters.

A.7.1 - Secure areas to prevent unauthorized physical access, damage and interference to business premises and information.

A.6.1 – Security in job definition and resourcing to reduce the risks of human error, theft, fraud or misuse of facilities.


All the controls and standards don’t mean a thing until someone tests their effectiveness. Sadly, many organizations still have a long way to go to becoming compliant with even their most fundamental security policies

03 May 2005

E-Mail and Digital Discovery: What is Your Policy?

The interpretations of "E-mail Retention" policy is still an issue in managing legal risk and many are still scratching their heads for answers. What is a Chief Compliance Officer(CCO) to do these days to conquer the data and records retention explosion?

The Sarbanes-Oxley Act of 2002
All public companies are required to save records relevant to the audit process, including e-mails, for seven years. The real-time disclosure rule, will force companies to monitor the contents of e-mail for material events.

Securities and Exchange Commission Rule 17A-4
Stemming from the Securities Exchange Act of 1934, this rule requires brokerages to save e-mails in an easily accessible place for two years.

The Health Insurance Portability and Accountability Act of 1996
Privacy rules dictate what information health-care companies can and cannot include in e-mails.

Medicare
Health-care companies are required to retain e-mails that are especially important during audits.

Other legislation
The Can-Spam Act of 2003 for marketers, the Tread Act of 2000 for the automotive industry, the Gramm-Leach-Bliley Act of 1999 and the USA Patriot Act of 2001 all force companies in many industries to change the way they manage e-mail.


The four aspects of good e-mail management: storage, archiving, indexing and policy enforcement are where the CCO, CIO and General Counsel are all converging with their current conversations. What remains to be done, is for the technologies to catch-up and to assist especially in indexing and policy enforcement. You can bet that some organizations are making a copy of every single e-mail sent and putting it into a vault. And others who will retain e-mail only for 30 days before it is deleted forever. The policy is different depending on the type of organization and the number of times you are served with "Discovery" requests from legal counsel.

Jeffrey Schwarz, an Information Technology Partner from McDermott, Will & Emery, was quoted in the January 15 issue of CIO in an article addressing how federal regulations, from HIPAA to Sarbanes-Oxley, have moved e-mail management to a top priority for CIOs. "E-mail has become the primary medium for how we communicate," Mr. Schwarz commented. "Four years ago we used paper and FedEx. Now almost everything is done over e-mail." He continued saying, "We are trying to make a system do something that it wasn't designed to do. E-mail wasn't designed to be a document repository. It was meant to be send, read, delete. But now you can't delete. There are regulations that don't let you do that."


Regulatory Compliance is not a traditional IT training ground until now. It's critical that an information management policy and regulatory procedure fusion take place at the board level to insure against the risks associated with e-mail retention or lack there of. But still, what is the Chief Compliance Officer going to do to mitigate these risks sooner than later?

E-Evidence and Digital Forensics are sought after disciplines these days at large law firms and other specialized consultancies. E-mail litigation is fueling this fire. The "E-Mail Trail" called by some is the "Smoking Gun" that gets juries convinced and plaintiffs huge awards or convictions.

The demand is only likely to increase as the volume of cases with digital evidence increases, according to the Department of Justice.

"Cyber-crime is obviously something that is a national priority," said Steve Bunnell, chief of the criminal division at the U.S. attorney's office in Washington, D.C., which recently established a cyber-crime division.

"Computer crimes are something that crosses borders. ...There is really a premium on getting the right and left hand working together," Bunnell said.

Courtrooms and universities are welcoming more lawyers specializing in electronic crime. They are setting the stage for the evolution of "cyber-law" as the debate over digital evidence -- and what limits may be put on it -- is raging among legal scholars and law enforcement, Brenner said.

27 April 2005

Terrorism Risk...

For a copy of the 2005 Aon Terrorism Risk Map Click here to visit their site. It has their risk ratings for every territory in the world.

The Teorrism Risk Map shows that participation in the US-led Iraq coalition has increased terrorism risk in countries such as Australia, Poland and Estonia. There is concern that Al-Qaida and other international terrorist organizations could take advantage of anti-western sentiment and launch terrorist attacks in these countries in future. Businesses which originate from these countries should also be aware of threats to their operations and personnel abroad as evidenced by incidents such as the terrorist attack on the Australian embassy in Indonesia, the recent bombing of a British theater and school in Qatar and the thwarted plot to blow up the Italian embassy in Lebanon.

"Terrorism is not a new threat and many international businesses have to date been rightly pre-occupied with the risks facing their operations in the Middle East, Africa and the Gulf. Although companies do need to be aware of the global picture, the 2005 map highlights the need for vigilance in so called 'safer' European countries," commented Paul Bassett, executive director in Aon's Crisis Management division.

"Companies must acquire as much knowledge as possible about the risks they face and their exposure to those risks in order to minimize the human and financial impact of such attacks. Businesses can then assess how best to allocate their expenditure on insurance and counter terrorism risk management procedures effectively," he added.


What does all of this mean? It means that now more than ever the insurance industry is going to look more closely at the risk of your people and property being in harms way. And if they are, then what is being done to mitigate those risks. It all comes down to what the insurance companies want from you as a client. To buy more insurance. If that is all you do, then you have missed several other strategic and tactical means for protecting your organizations vital assets.

25 April 2005

CEO's vs. Boards...

There is another interesting perspective in this months Corporate Board Member Magazine regarding the trust factor between the CEO and the Board of Directors.

It seems that there is still a major battle going on here with some companies but the question is why does it exist? More and more the shareholders are upset with performance and other key issues and they are putting the pressure on Directors to act. What is a shareholder to think when the annual shareholders meeting becomes a one-way conversation and the Q & A is herded into the last 15 minutes and there is no longer a live mic on the floor. If there are suspected hostile or threatening entities in the audience then security should do their duty and remove these individuals. However, when the executive management are clearly shutting down a meaningful open dialogue with the shareholders, then the Board of Directors should be questioned on their allegiance.

Of course there are many examples of where the Chairman of the Board is still the CEO and this is one topic for another date. What is interesting in the debate on the anxiety between the executives and the board these days is this:

After nearly three years of fallout from Sarbanes-Oxley, plus the frightening realization that directors may be held financially liable for their oversight failures, boards are no longer looking at their CEOs with wonder. In fact, they’re downright skeptical. “Trust in the CEO is not at the levels it used to be,” says Richard Koppes, a director of Apria Healthcare and Valeant Pharmaceuticals International. Adds Philip Burguieres, chairman emeritus of Weatherford International and a former CEO of Panhandle Eastern Corp. and Cameron Iron Works: “The element of trust seems to be gone. A few guys have done great harm.”

Obviously the vast majority of CEOs are trustworthy, but all have been slimed to some extent by the scandals of recent years. In 2003 a joint BusinessWeek/Harris Poll survey found that nearly 80% of Americans believed that CEOs of large companies put their own interests before those of workers and shareholders.

To say that boards don’t trust the CEO is not to say that they suspect dishonesty. If they did, turnover at the top of the corporate totem pole would be even higher than it is. Last year 663 CEOs decamped to other jobs, retired, or were fired, down from the high-water mark of 1,106 in 2000, according to Challenger Gray & Christmas, an outplacement firm that keeps track of these peregrinations. Rather, what boards fear is that their CEO isn’t leveling with them, that all information that directors receive about the company is filtered through the CEO’s ego.

When McKinsey & Co., a management consulting firm, surveyed 150 directors in 2004, 81% said that the CEO largely or completely controlled and shaped what board members learned about the company. Only 30% said they felt they really knew what was going on. Directors want to take more control of the information they are getting, and that’s a direct challenge to the CEO’s power.


The risks facing organizations today go way beyond the typical issues you hear about in the Board of Directors meeting or the Audit committee conference calls. The risk of a systemic failure of the corporation is at it's roots a failure of the way information is collected, processed and delivered. Think about the simple process of sales forecasting and you begin to see where the root problem is. At each step of the roll-up and the chain of management there is another layer of guess work and sanitization. If a Board member ever got the chance to ride in the field with a seasoned sales rep and also attend a district sales meeting during a pipeline analysis then they would begin to understand why the CEO is guarding the "Corporate Fort" at all costs.

21 April 2005

Here is How to Protect Your Organization...

Rob Norton's cover story on Risk is a great primer to what corporate executives and board members around the globe have known for some time.

Crooked managers. Changing technology. Financial surprises. Who knows what company-killers lie ahead? Here’s how directors can protect themselves.

No single four-letter word is more likely to raise a board’s collective blood pressure these days than risk. The recent parade of corporate scandals can be blamed in part on a lack of effective systems to recognize and manage risk—not just insurance matters but broad operational and financial hazards to the enterprise. Now risk management has risen to the top of the agenda for many directors. Often the job falls under the authority of the audit committee, but some U.S. boards, including that of MCI (formerly WorldCom), have appointed special risk management committees. The boards of several European and Canadian companies have adopted formal processes aimed at alerting directors to the extent to which the outfits are exposed to risk and how it is managed.

The risks that blew up in the faces of boards at companies such as WorldCom, Enron, and Parmalat all come under the general category of operational risk, broadly defined as the danger of loss resulting from inadequate or failed internal processes, people, or systems, or from external events. These can include:

• Unscrupulous managers.
• Business interruptions caused by terrorism, war, or natural disaster.
• Supply-chain breakdowns.
• Changing technology.
• Increased competition.


Fortunately, the article mentions "Supply Chain Risk" as an area that needs more scrutiny as companies continue to increase offshoring and outsourcing to gain competitive advantages. This area of Operational Risk is a growing concern by not only shareholders, but the plaintiffs who follow the aftermath of Eliot Spitzer's investigations.

A significant business disruption (SBD) will occur at your organization each day, week, and month this year. The question remains that of what you are already doing to manage these inevitable incidents. We suggest a "4D" approach:

Deter

Detect

Defend

Document


This "4D" Managed Services approach to managing Operational Risk provides the initial framework for creating a strategic enterprise risk management (ERM) initiative in the organization. Each area has it's own tools, systems and processes yet each is connected to the Risk Nervous System via the 1SecureAudit Operational Risk Enterprise Architecture. (OREA)

OREA utilizes a proven and systematic approach for risk assessment, data capture, risk treatment and reporting. To facilitate efforts to transform the organization into one that has lower volatility of earnings growth and is more secure, 1SecureAudit co-designs the Operational Risk Enterprise Architecture (OREA), a business-based framework for organizational-wide improvement.

People
· Employee Fraud / Malice
· Unauthorized Activity
· Rogue Trading
· Employee Misdeed
· Employment Law
· Loss/lack of personnel

Processes
· Payment / Settlement
· Delivery / Selling
· Documentation / Contract
· Valuation / Pricing
· Internal / External Reporting
· Compliance

Systems
· Technology Investment
· Development
· Access
· Capacity
· Failures
· Security Breach

External
· Legal Liability
· Criminal Activities
· Outsourcing
· Suppliers / Insourcing
· Disasters / Infrastructure
· Regulatory / Political

OREA is constructed through a collection of interrelated “reference meta models” designed to facilitate cross-lines of business analysis and the identification of duplicative processes, departments, gaps, and opportunities for collaboration within and across lines of business (LOB). This OREA and Business Reference Model is intended for use in analyzing investments in Operational Risk projects and other capital assets. It also serves as a foundation for the development of a broader architecture that can serve as the platform for a comprehensive budget and performance reporting system that supports enterprise wide business risk integration and change management initiatives.