Avian influenza, or bird flu, is a contagious viral disease caused by certain types of influenza viruses that occur naturally among birds. Usually, these viruses do not infect humans, but several cases of human infection with bird flu viruses have been reported recently.
Why could this become an Operational Risk for your organization? Currently, these viruses are circulating in bird populations in Asia, and have resulted in severe illness and death in humans. Since the recent outbreaks of this strain began in 2004, more than 120 people have been confirmed as infected and more than 60 have died. Most human cases are thought to have occurred through contact with infected poultry or contaminated surfaces. However, some scientists worry that if the virus were able to mutate and be able both to infect people and then to spread easily from person to person in a sustained fashion, a global "influenza pandemic" (worldwide outbreak of the disease) could begin.
This WHO Avian Flu Fact Sheet can provide some of the answers on the disease.
operational risk
24 November 2005
21 November 2005
Simulation & Analysis: COOP on Steroids...
All of the planning tools that have automated the process of developing BCCM and COOP documentation have addressed only a small piece of the total mosaic for operational risk management. There is however a new "kid" on the block that is worth keeping your eye on. This is because they have created the tools for doing critical simulation and analysis of the impact of significant business disruptions to our critical infrastructures.
While we have all the confidence that there is a market for tools like these, the largest challenge still remains. Human Factors.
All of the scenario planning and simulation is important to create new contingency procedures or the application of new methods for mitigating the impact of such scenarios. However, the human factors are and will remain unknown until you actually exercise and effectively test that scenario. Only testing will tell you what people did or didn't do or why they reacted the way they did. The psychological and physiological unknowns are what throw the planners and simulation operators for a loop every time.
We hope that FortiusOne also gives their clients the insight they require to create the most realistic and optimal tests to determine what the real outcomes will look like before and after a natural disaster or terrorist event.
operational risk
FortiusOne’s target market encompasses both the public and private sector. The former includes federal, state, local and international segments, with primary emphasis on Homeland Security, National Defense, Intelligence and Emergency Management for critical infrastructure vulnerability assessments and consequence management. FortiusOne’s private sector market addresses risk analysis for the Banking/Financial Services, Transportation, Energy, Telecommunications, Insurance and general Supply Chain segments with primary emphasis on business continuity planning, business optimization and disaster recovery. Market size exceeds $40B and is upward trending in both public and private sectors. Recent events and consequences related to hurricane Katrina, terrorist threats and attacks, and corporate management/mis-management events have created intense interest in FortiusOnes’s products and services. The Company’s revenue model for both public and private sectors includes fixed price product pricing for basic assessments with additional high valued consultation for detailed analysis of specific client defined scenarios.
While we have all the confidence that there is a market for tools like these, the largest challenge still remains. Human Factors.
All of the scenario planning and simulation is important to create new contingency procedures or the application of new methods for mitigating the impact of such scenarios. However, the human factors are and will remain unknown until you actually exercise and effectively test that scenario. Only testing will tell you what people did or didn't do or why they reacted the way they did. The psychological and physiological unknowns are what throw the planners and simulation operators for a loop every time.
We hope that FortiusOne also gives their clients the insight they require to create the most realistic and optimal tests to determine what the real outcomes will look like before and after a natural disaster or terrorist event.
operational risk
17 November 2005
ISO 27001 : Information Security Management...
What Is ISO 27001?
This particular standard defines and specifies an 'Information Security Management System', known as an ISMS. It compliments the existing ISO 17799 security standard, and specifies a general framework for the creation and maintenance of the security process within an organization.
These two standards (ISO 17799 and ISO 27001) are closely related, and although their scope is wide, they have very distinct roles.
ISO 27001 defines the overall requirements for the security management system itself, the focus being on management. It is this standard, rather than ISO 17799, against which certification is offered. It was based upon an earlier standard, known as BS7799-2, but has been more closely aligned with other quality management standards.
operational risk
ISO 27001, titled "Information Security Management - Specification With Guidance for Use", is the replacement for BS7799-2. It is intended to provide the foundation for third party audit, and is 'harmonized' with other management standards, such as ISO 9001 and ISO 14001.
The basic objective of the standard is to help establish and maintain an effective information management system, using a continual improvement approach. It implements OECD (Organization for Economic Cooperation and Development) principles, governing security of information and network systems.
This particular standard defines and specifies an 'Information Security Management System', known as an ISMS. It compliments the existing ISO 17799 security standard, and specifies a general framework for the creation and maintenance of the security process within an organization.
These two standards (ISO 17799 and ISO 27001) are closely related, and although their scope is wide, they have very distinct roles.
ISO 27001 defines the overall requirements for the security management system itself, the focus being on management. It is this standard, rather than ISO 17799, against which certification is offered. It was based upon an earlier standard, known as BS7799-2, but has been more closely aligned with other quality management standards.
operational risk
09 November 2005
The Risk of 4GW: It's Here to Stay...
In today's OSAC 20th Annual Briefing at the U.S. State Department Bureau of Diplomatic Security we witnessed some excellent briefs from corporate CSO's and keynotes from Sandy Weill, COB of Citigroup and Dr. Condoleeza Rice, U.S. Secretary of State.
All had the theme of the day, the valuable and lasting public private partnership established twenty years ago by former U.S. Secretary of State George P. Shultz. There was much talk of the current risk of Fourth Generation Warfare (4GW), the same method of guerilla warfare described in The Sling and the Stone. In the middle of the presentations, many of our PDA's and phones began their vibrations and buzzing. Within a few minutes, the podium was announcing the latest attack on our own corporate assets in the capital of Jordan.
The Overseas Security Advisory Council (OSAC) now claims over 3,000 U.S. companies, educational institutions, religious groups, and non-governmental organizations as members known as constituents. Although OSAC is rarely in the limelight, the ways in which it helps American businesses fight terrorism abroad is unparalleled.
Is that a "Predator" taking off?
Mission
Tomorrow, in our second day of the OSAC briefing the room will be missing many of the constituent members as they begin the investigations and deploy new resources in the pursuit of justice.
operational risk
All had the theme of the day, the valuable and lasting public private partnership established twenty years ago by former U.S. Secretary of State George P. Shultz. There was much talk of the current risk of Fourth Generation Warfare (4GW), the same method of guerilla warfare described in The Sling and the Stone. In the middle of the presentations, many of our PDA's and phones began their vibrations and buzzing. Within a few minutes, the podium was announcing the latest attack on our own corporate assets in the capital of Jordan.
At least 57 people were killed and more than 100 injured when suicide bombers blew themselves up at three hotels in Amman, the capital of Jordan.
The hotels were popular with foreigners and many of the guests were involved in work in Iraq. The attacks destroyed the fragile calm that Jordan has enjoyed despite its proximity to Iraq and the support of its ruler, King Abdullah, for American and British policy in Iraq.
Major Bashir al-Da'aja, a police spokesman, said: "There were three terrorist attacks on the Grand Hyatt, Radisson SAS and Days Inn hotels and it is believed that the blasts were suicide bombings." Said Darwazeh, the health minister, said there were more than 50 dead but the toll could rise.
The Overseas Security Advisory Council (OSAC) now claims over 3,000 U.S. companies, educational institutions, religious groups, and non-governmental organizations as members known as constituents. Although OSAC is rarely in the limelight, the ways in which it helps American businesses fight terrorism abroad is unparalleled.
Is that a "Predator" taking off?
Mission
The MQ-1 Predator is a medium-altitude, long-endurance, remotely piloted aircraft. The MQ-1's primary mission is interdiction and conducting armed reconnaissance against critical, perishable targets. The MQ-1 Predator carries the Multi-spectral Targeting System with inherent AGM-114 Hellfire missile targeting capability and integrates electro-optical, infrared, laser designator and laser illuminator into a single sensor package. The aircraft can employ two laser-guided Hellfire anti-tank missiles with the MTS ball.
Tomorrow, in our second day of the OSAC briefing the room will be missing many of the constituent members as they begin the investigations and deploy new resources in the pursuit of justice.
operational risk
01 November 2005
Online Pharmaceutical Counterfeiting: The Digital Threat...
Pharma healthcare companies all over the globe are working hard to identify counterfeit drugs and to put these criminals out of business. This operational risk strategy saves countless lives each year. The first article in a series on counterfeiting at CSO Online misses a key focus on the Internet Channel of Distribution. In order to pursue this growing threat, organizations must consider the use of real professionals to deter, detect, defend and document effectively in order to have a comprehensive anti-counterfeiting program.
All of the forensic markers and post testing due diligence will not stem the tide of bogus pharma web sites selling counterfeit drugs. An effective corporate risk intelligence process combines both the low tech (HUMINT) sources and the high tech methods (DIGITAL SURVEILLANCE) from a single entity. Only then will the data fusion and correlation of information allow for a legal, competent and rapid interdiction of this lethal threat.
operational risk
The continuing growth of the Internet provides counterfeiters with ready access to unsuspecting consumers. Since goods purchased via the Internet are normally delivered through the conventional mail system, they frequently by-pass national regulations for the distribution of controlled goods.
The use of intelligent Internet surveillance with proprietary software, enables the detection of illicit distribution, trademark abuse, objectionable association and counterfeit activities, which can then be countered in a highly focused manner.
Authentix identifies client products on sale from suspect counterfeit sources, retrieves them anonymously and tests them for authenticity. In cases of minor misdemeanors they issue Cease & Desist letters for clients and monitor compliance. Where counterfeit or diverted product is retrieved, they support our clients through legal remediation by maintaining a documented chain of evidence.
All of the forensic markers and post testing due diligence will not stem the tide of bogus pharma web sites selling counterfeit drugs. An effective corporate risk intelligence process combines both the low tech (HUMINT) sources and the high tech methods (DIGITAL SURVEILLANCE) from a single entity. Only then will the data fusion and correlation of information allow for a legal, competent and rapid interdiction of this lethal threat.
Counterfeit medicines are a global scourge. The World Health Organization (WHO) estimates that as much as 10 percent of the half-trillion-dollar pharmaceutical market is counterfeit. In some developing countries, more than half of the drug supply may be fake. Every year, thousands die from ingesting fake medicines, many of which have been produced in squalid conditions using ingredients such as boric acid and highway paint.
operational risk
28 October 2005
Zombies Being Hunted: Trick or Treat?
The FTC and Microsoft are going Zombie Hunting just in time for Halloween.
OnGuard Online has been launched to help consumers and business become more aware and educated on digital threats. This site is in collaboration with private industry and:
U.S. Department of Homeland Security
U.S. Federal Trade Commission
U.S. Postal Inspection Service
U.S. Department of Commerce
There is a whole of common sense here yet it is encouraging to see that the Fed's are now acknowledging that ID Theft is out of control. The financial services industry is certainly at risk as long as consumers are banking online and using their PC's to pay their bills.
If haven't already, you should consider signing up for alerts from US-CERT.
operational risk
"The widespread use of zombie computers to commit crimes over the Internet presents a very real danger to law-abiding computer users," said Tim Cranton, the director of Microsoft's Internet Safety division.
Earlier this year, Cranton said, Microsoft set up a "clean" PC, then infected it with malicious code commonly used by attackers to turn a computer into a zombie. Researchers then monitored the PC's use of the Internet for 20 days, and tallied the number of messages sent through it.
"In those 20 days, this one computer received 5 million connection requests from spammers, and sent 18 million spam messages," said Cranton.
That amount of data was impossible to analyze, so Microsoft focused on the three most-active spamming days, when 470,00 connection requests were made of the PC, and about 1.8 million messages were sent through it.
OnGuard Online has been launched to help consumers and business become more aware and educated on digital threats. This site is in collaboration with private industry and:
U.S. Department of Homeland Security
U.S. Federal Trade Commission
U.S. Postal Inspection Service
U.S. Department of Commerce
There is a whole of common sense here yet it is encouraging to see that the Fed's are now acknowledging that ID Theft is out of control. The financial services industry is certainly at risk as long as consumers are banking online and using their PC's to pay their bills.
If haven't already, you should consider signing up for alerts from US-CERT.
operational risk
25 October 2005
The Risk of A Blueprint For Action...
Now that Tom Barnett has released his newest book, Blueprint For Action: A Future Worth Creating it will be interesting to see the outcome.
However, before we make any comments or offer our own analysis, we are going to finish the entire book. Page 33 of 362. Stay tuned.
In the mean time, you can visit his web site and blog to find out more about his journey.
However, before we make any comments or offer our own analysis, we are going to finish the entire book. Page 33 of 362. Stay tuned.
In the mean time, you can visit his web site and blog to find out more about his journey.
24 October 2005
Hurricane Risk: Floridians Take On Another Cat. 3...
The residents of Florida have learned some lessons over the past 14 months about preparedness. They have just been blasted by another Category 3 storm with over a month left to the end of the season. The estimates are now coming in that Wilma will have a significant impact with over $5B. in insured damages.
In the wake of Hurricanes Katrina and Rita, hospitals across the United States of America are re-evaluating their disaster recovery plans. VHA, the national health care alliance, surveyed member hospitals across the country, and nearly half of those who responded are planning to modify their disaster plans - changing their evacuation plans, seeking alternative communication systems and preparing for extended periods of self-sufficiency.
More than 350 hospital leaders and managers, ranging from chief executive officers and chief nursing officers to materials managers, pharmacists and emergency department coordinators, responded to the VHA survey. According to respondents, nearly half (48.2 percent) are planning to change their disaster recovery plans.
Hurrican Wilma came ashore with winds of 125 mph near Cape Romano, about 20 miles south of Naples, at about 6:30 a.m. local time. The coastal parts of Collier County, which includes Naples and nearby beach resort Marco Island, haven't been hit by a hurricane since 1960.
The state was hit by a record four hurricanes last year, causing a combined $22.9 billion in insured damages. Charley accounted for $7.5 billion, Ivan caused $7.1 billion, Frances resulted in $4.6 billion and Jeanne left $3.7 billion in insured damages.
Hurricane Katrina, which struck the U.S. Gulf Coast in August, is expected to be the most costly U.S. disaster for insurers. Storm modeler Risk Management Solutions Inc. estimated $40 billion to $60 billion in claims, as much as three times the $20.8 billion produced by Hurricane Andrew, which hit Florida in 1992.
In the wake of Hurricanes Katrina and Rita, hospitals across the United States of America are re-evaluating their disaster recovery plans. VHA, the national health care alliance, surveyed member hospitals across the country, and nearly half of those who responded are planning to modify their disaster plans - changing their evacuation plans, seeking alternative communication systems and preparing for extended periods of self-sufficiency.
More than 350 hospital leaders and managers, ranging from chief executive officers and chief nursing officers to materials managers, pharmacists and emergency department coordinators, responded to the VHA survey. According to respondents, nearly half (48.2 percent) are planning to change their disaster recovery plans.
Here are a few reminders for getting your Business Ready:
1. If you rent, lease or share office space, coordinate and practice evacuation and other emergency plans with other businesses in your building or facility.
2. Conduct regularly scheduled education and training seminars to provide co-workers with information, identify needs and develop preparedness skills.
3. Include preparedness training in new employee orientation programs.
4. Do tabletop exercises with members of the emergency management team. Meet in a conference room setting to discuss individual responsibilities and how each would react to emergency scenarios.
5. Schedule walk-through drills where the emergency management team and response teams actually perform their designated emergency functions. This activity generally involves more people and is more thorough than a tabletop exercise.
6. Practice evacuating and sheltering. Have all personnel walk the evacuation route to a designated area where procedures for accounting for all personnel are tested. Practice your “shelter-in-place” plan.
7. Evaluate and revise processes and procedures based on lessons learned in training and exercise.
8. Keep training records.
21 October 2005
Phishing: The Takedown...
Why Phishing Incident Response Plans May Not Be Optional.
The Treasury Department’s Office of the Comptroller of the Currency issued a bulletin in July that outlines the steps banks should take to mitigate the risks of phishing. Among other things, national banks were told they must file suspicious activity reports, or SARs, if they are the target of a spoofing incident.
Last December, the Federal Deposit Insurance Corp. issued guidelines for how financial institutions can mitigate phishing risks. The document warns that “the financial service industry’s current reliance on passwords for remote access to banking applications offers an insufficient level of security” and describes better options, such as two-factor authentication.
Phishing as a operational risk to an institution requires effective deterence as well as detection. These comments from a recent article at CSO Online paint the picture about why a takedown is a necessary response to a phishing incident.
As this article mentions, their are several very reputable firms who can assist you with the takedown. It may be even more important to have a 24 X 7 detection service monitoring the Internet for new web sites popping up and to get you ready for the barrage of spam e-mail onto the net to spoof your unsuspecting consumers. For more information on this, see Cyveillance.
Another important note is the PR and communications crisis management that is necessary to keep customers informed, the public aware of your Anti-Phishing strategy and more. You see, at the end of the day 99% of online banking customers won't leave you because you had an incident. They will leave you if you don't handle the response correctly.
The Treasury Department’s Office of the Comptroller of the Currency issued a bulletin in July that outlines the steps banks should take to mitigate the risks of phishing. Among other things, national banks were told they must file suspicious activity reports, or SARs, if they are the target of a spoofing incident.
Last December, the Federal Deposit Insurance Corp. issued guidelines for how financial institutions can mitigate phishing risks. The document warns that “the financial service industry’s current reliance on passwords for remote access to banking applications offers an insufficient level of security” and describes better options, such as two-factor authentication.
Phishing as a operational risk to an institution requires effective deterence as well as detection. These comments from a recent article at CSO Online paint the picture about why a takedown is a necessary response to a phishing incident.
The Takedown
The window of opportunity for a phisher is the time between when a phishing e-mail goes out and when the fraudulent website collecting information is taken down. Left unchecked, a phishing site may stay up for days or even weeks, as information trickles in from dawdling customers who've fallen for the scam. A good takedown process can slam that window shut within hours.
Nowadays, the attempt to do a takedown is standard fare—so standard, in fact, that the Treasury Department's Office of the Comptroller of the Currency has issued guidelines about the steps banks should take to disable spoofed websites. (Takedown, which essentially just relocates the problem, may be the only defense that the targeted company has. Prosecutions of phishers have been next to nonexistent, due to the difficulty of tracing how personal information has been captured, sold and exploited.)
As this article mentions, their are several very reputable firms who can assist you with the takedown. It may be even more important to have a 24 X 7 detection service monitoring the Internet for new web sites popping up and to get you ready for the barrage of spam e-mail onto the net to spoof your unsuspecting consumers. For more information on this, see Cyveillance.
Another important note is the PR and communications crisis management that is necessary to keep customers informed, the public aware of your Anti-Phishing strategy and more. You see, at the end of the day 99% of online banking customers won't leave you because you had an incident. They will leave you if you don't handle the response correctly.
17 October 2005
Corporate Governance: Deja Vu...
This is another sad story of Operational Risks far from being managed or in this case even considered when so many "Red" flags were waving in the wind.
This one has lot's of people sick to their stomach and more are going to be checking in to the local clinic before this one is over. Everyone will be pointing fingers and wondering why SOX didn't save the day. The truth of the matter is Mr. Bennett is a true master at "Social Engineering" and was able to use his power to do the same thing that others in a position like his have done in the past. The finance industry is built on trust and this will be another lesson on why due diligence on a 24 x 7 basis is a harsh neccesity.
NEW YORK, Oct 17 (Reuters) - Financial services companies beware: The fast meltdown of futures and commodities broker Refco Inc. (RFX.N: Quote, Profile, Research) may cause investors to think twice before making bets on similar types of ventures.
The crisis at Refco in the past week has happened even as new U.S. financial reporting rules and increased auditor oversight -- the result of a wave of scandals at companies such as Enron and WorldCom in 2001-2002 -- were supposed to have better protected shareholders from such debacles.
There have also been plenty of hard looks at the behavior of executives throughout corporate America in recent years, as witnessed by the high-profile criminal trials of one-time highflyers like WorldCom's Bernard Ebbers and Dennis Kozlowski of Tyco International Ltd. (TYC.N: Quote, Profile, Research)
Still, New York-based Refco's former chief, 57-year-old Briton Phillip Bennett, managed to escape heavy scrutiny while building up Refco and even during its initial public offering of shares.
He was charged with securities fraud last week over allegations he hid about $430 million in company debt. Bennett's lawyer has said there is "no justification" for his client's arrest.
This one has lot's of people sick to their stomach and more are going to be checking in to the local clinic before this one is over. Everyone will be pointing fingers and wondering why SOX didn't save the day. The truth of the matter is Mr. Bennett is a true master at "Social Engineering" and was able to use his power to do the same thing that others in a position like his have done in the past. The finance industry is built on trust and this will be another lesson on why due diligence on a 24 x 7 basis is a harsh neccesity.
11 October 2005
The Impact of Katrina: A Look Into The OPS Risk Crystal Ball...
The impact of hurricane Katrina is only beginning and it's easy to see how many institutions may be starting the battle with their insurance companies.
These "Expected" external events the likes of Katrina and Rita have impacted about 280 financial institutions in the Gulf Coast of the U.S.. These institutions represented around $270B. in assets and many are now looking to the insurance industry for payouts on those policies that transfered some of their risks.
Looking into the crystal ball, let's consider the public testimony of Steven G. Elliott, Senior Vice Chairman Mellon Financial Corporation before the Subcommittee on Financial Institutions and Consumer Credit Committee on Financial Services - U.S. House of Representatives in 2004:
While overall the Fed and the institutions resilience is to be commended compared with other major critical infrastructures such as the Energy sector, we still have a long way to go with contingency planning. The regulators and insurance industry is looking at Business Crisis and Continuity Management with a new found diligence especially with the institutions outsourcing and supply chain partners.
Beyond the impact of Katrina, talking and listening to the OCC, FDIC and the Federal Reserve this week at the Risk Management Association (RMA) Annual Conference in Washington, DC produced some additional views and questions in the operational risk crystal ball:
1. Regulators are reinforcing the need for a comprehensive risk framework.
2. Does the amount of capital that I hold support the risks that we are engaged in?
3. Does our institution have excess capital?
4. How do I differentiate our risks by industry or geography to address concentrations and impact from cycles?
5. How do I integrate risk management into the Strategic Planning Process to make sure the methodology is understood and objectives are being communicated from the Board?
There must be the development of new risk management models that allow for the addition of new risk events and the elimination of those factors that may no longer be relevant.
These "Expected" external events the likes of Katrina and Rita have impacted about 280 financial institutions in the Gulf Coast of the U.S.. These institutions represented around $270B. in assets and many are now looking to the insurance industry for payouts on those policies that transfered some of their risks.
Looking into the crystal ball, let's consider the public testimony of Steven G. Elliott, Senior Vice Chairman Mellon Financial Corporation before the Subcommittee on Financial Institutions and Consumer Credit Committee on Financial Services - U.S. House of Representatives in 2004:
"Banks should view risk mitigation tools as complementary to, rather than a replacement for, thorough internal operational risk control. Having mechanisms in place to quickly recognize and rectify legitimate operational risk errors can greatly reduce exposures. Careful consideration also needs to be given to the extent to which risk mitigation tools such as insurance truly reduce risk, or transfer the risk to another business sector or area, or even create a new risk (e.g. legal or counterparty risk)."
"Investments in appropriate processing technology and information technology security are also important for risk mitigation. However, banks should be aware that increased automation could transform high-frequency, low-severity losses into low-frequency, high-severity losses. The latter may be associated with loss or extended disruption of services caused by internal factors or by factors beyond the bank’s immediate control (e.g., external events). Such problems may cause serious difficulties for banks and could jeopardize an institution’s ability to conduct key business activities."
While overall the Fed and the institutions resilience is to be commended compared with other major critical infrastructures such as the Energy sector, we still have a long way to go with contingency planning. The regulators and insurance industry is looking at Business Crisis and Continuity Management with a new found diligence especially with the institutions outsourcing and supply chain partners.
Outsourcing of activities can reduce the institution’s risk profile by transferring activities to others with greater expertise and scale to manage the risks associated with specialized business activities. However, a bank’s use of third parties does not diminish the responsibility of management to ensure that the third-party activity is conducted in a safe and sound manner and in compliance with applicable laws. Outsourcing arrangements should be based on robust contracts and/or service level agreements that ensure a clear allocation of responsibilities between external service providers and the outsourcing bank. Furthermore, banks need to manage residual risks associated with outsourcing arrangements, including disruption of services.
Beyond the impact of Katrina, talking and listening to the OCC, FDIC and the Federal Reserve this week at the Risk Management Association (RMA) Annual Conference in Washington, DC produced some additional views and questions in the operational risk crystal ball:
1. Regulators are reinforcing the need for a comprehensive risk framework.
2. Does the amount of capital that I hold support the risks that we are engaged in?
3. Does our institution have excess capital?
4. How do I differentiate our risks by industry or geography to address concentrations and impact from cycles?
5. How do I integrate risk management into the Strategic Planning Process to make sure the methodology is understood and objectives are being communicated from the Board?
There must be the development of new risk management models that allow for the addition of new risk events and the elimination of those factors that may no longer be relevant.
07 October 2005
The Risk of Pandemic: A Global Threat...
Pandemic: A Worldwide Outbreak of Influenza is now getting attention on many global fronts including a plea by U.S. President George Bush to vaccine manufacturers to step up their production and R & D. In recent weeks, senior officials here have embarked on a public information campaign, warning of the possibility of a lethal pandemic which could claim millions of lives.
Mr Bush has even suggested that the US military would be used to quarantine affected areas of the United States in the event of an outbreak. What exactly is a pandemic?
And where there is a threat like this, the criminal minds begin to see opportunity for unsuspecting prey. Roche is now on alert and you should be also.
Mr Bush has even suggested that the US military would be used to quarantine affected areas of the United States in the event of an outbreak. What exactly is a pandemic?
An influenza pandemic is a global outbreak of disease that occurs when a new influenza A virus appears or “emerges” in the human population, causes serious illness, and then spreads easily from person to person worldwide. Pandemics are different from seasonal outbreaks or “epidemics” of influenza. Seasonal outbreaks are caused by subtypes of influenza viruses that are already in existence among people, whereas pandemic outbreaks are caused by new subtypes or by subtypes that have never circulated among people or that have not circulated among people for a long time. Past influenza pandemics have led to high levels of illness, death, social disruption, and economic loss.
And where there is a threat like this, the criminal minds begin to see opportunity for unsuspecting prey. Roche is now on alert and you should be also.
Swiss drug maker Roche urged consumers on Friday not to buy its flu drug Tamiflu over the Internet to avoid the risk of purchasing potentially counterfeit pills as they build stockpiles in case of a bird flu pandemic.
With experts predicting that millions could die if the bird flu strain H5N1 mutates into a human flu virus, some consumers appear to be building up their own reserves of the drug, doubling up on governments' efforts to prepare for a pandemic.
05 October 2005
CyberCrime: What is the Real Truth?
The CSI/FBI Computer Crime and Security Survey is now published and some of the results are enlightening to say the least.
Since this is not a research paper, we can't publish the statistics of our main interest in the survey. Please see Table 1 on Page 14 for the next comment to have any relevance regarding the percent of respondents who "Don't Know" how many incidents they have encountered.
If one quarter don't know the number of security incidents, then that is around 175 companies who are flying blind or don't care about measuring the frequency, nature or cost of breaches. This is why we don't buy the general trend in Figure 14 that attacks or misuse detected are declining over the past 12 months.
Since this is not a research paper, we can't publish the statistics of our main interest in the survey. Please see Table 1 on Page 14 for the next comment to have any relevance regarding the percent of respondents who "Don't Know" how many incidents they have encountered.
If one quarter don't know the number of security incidents, then that is around 175 companies who are flying blind or don't care about measuring the frequency, nature or cost of breaches. This is why we don't buy the general trend in Figure 14 that attacks or misuse detected are declining over the past 12 months.
27 September 2005
Rita and The Suicide Bomber...
Now that the U.S. is dealing with the aftermath of a Category 3 hurricane "Rita" and the U.K. is analyzing it's response to the 7/7 "Suicide Bombers", what operational risks do they have in common?
The answer is plain and the truth hurts. There is no stopping either threat and they will always find a way to inflict significant losses to our property and human lives. These threats are at opposite ends of the spectrum however when it comes to the event itself.
One attacker is tracked and shown on national television as it grows and bears down on it's next target. We know when and where. The other attacker is hard to detect in advance and operates in stealth. Now the question again is, what do they have in common? In both cases, we know they are coming again.
Our preparation and planning for the next incident itself, using a myriad of scenario-based exercises or tests can assist those who deter and detect these threats as well as those who will be tasked to alert or defend and help recover from the next one. These are both risks that you can help mitigate the consequences and the impact although one could argue the likelihood is inevitable and increasing.
What is less predictable is human behavior. The emotions, actions and attitudes of dozens, thousands or millions of people can't be predicted. One can only learn from these events and over the course of history, establish a baseline of knowledge. The next incident will be different and it will have some of the same characteristics.
Human behavior is the key to our greatest risk management challenges. Both the U.K. and the U.S. have seen the pictures of bomb and hurricane casualties in the past three months. Human behavior in one case has the attributes of a well-trained and coordinated response. The other case is rapidly becoming a "Case Study" for those public servants who are learning what went wrong. While it's unfair to compare the scope of the two scenarios, it's obvious that we still don't have a firm grasp on human behavior.
The answer is plain and the truth hurts. There is no stopping either threat and they will always find a way to inflict significant losses to our property and human lives. These threats are at opposite ends of the spectrum however when it comes to the event itself.
One attacker is tracked and shown on national television as it grows and bears down on it's next target. We know when and where. The other attacker is hard to detect in advance and operates in stealth. Now the question again is, what do they have in common? In both cases, we know they are coming again.
Our preparation and planning for the next incident itself, using a myriad of scenario-based exercises or tests can assist those who deter and detect these threats as well as those who will be tasked to alert or defend and help recover from the next one. These are both risks that you can help mitigate the consequences and the impact although one could argue the likelihood is inevitable and increasing.
What is less predictable is human behavior. The emotions, actions and attitudes of dozens, thousands or millions of people can't be predicted. One can only learn from these events and over the course of history, establish a baseline of knowledge. The next incident will be different and it will have some of the same characteristics.
Human behavior is the key to our greatest risk management challenges. Both the U.K. and the U.S. have seen the pictures of bomb and hurricane casualties in the past three months. Human behavior in one case has the attributes of a well-trained and coordinated response. The other case is rapidly becoming a "Case Study" for those public servants who are learning what went wrong. While it's unfair to compare the scope of the two scenarios, it's obvious that we still don't have a firm grasp on human behavior.
23 September 2005
Survive: A Strategy for Every Business...
Well over two years ago upon our founding, 1SecureAudit joined a global organization of people who really "Get it". Who understand and demonstrate the necessity and true philosophy of Business Crisis and Continuity Management. Is your U.S. institution a member? Do you have top executives who are contributing strategic resources and knowledge to the survival of your business? Ignoring the multitude of significant threats and business disruptions to your enterprise is nothing less than a lack of corporate strategy for long term survival.
As another Category 4 hurricane bears down on the U.S. for the second time in a month, we can only hope that the business community in Texas is ready. Gods speed to the people of Houston and beyond.
Launched in 1989, Survive has since grown throughout the world to become the leading forum for expertise and information exchange among business continuity management practitioners and professionals, and all managers and directors with responsibility for ensuring the resilience and ultimate survival of their companies.
Originally focused largely on the back-up and recovery of IT and communications systems, Survive is now the only organisation of its kind in the world addressing the continuity needs of the entire organisation.
Our members are concerned about everything from protecting the company data and staff safety, to safeguarding the reputation and value of the whole enterprise.
The demands are growing on public and private sector organisations to prove they have processes in place to maintain continuous impressive performance 365 days a year, regardless of unusual internal or external circumstances. Such demands can be almost impossible to meet. But through understanding how organisations of different shapes and sizes tackle the difficult issues, members learn how to build resilience into their businesses and how to make business continuity a core part of the their company culture.
Business continuity management is about not making excuses. It's about being wise before the event. It is a state of mind that understands great organisations never moan they didn't do well because of the state of the economy, a fire at the warehouse, an internal fraud, or a strike by a group of key workers. Great organisations do well anyway.
As another Category 4 hurricane bears down on the U.S. for the second time in a month, we can only hope that the business community in Texas is ready. Gods speed to the people of Houston and beyond.
21 September 2005
Adaptation + Visible OPS = Managed Change
Managing Complextiy and change in any enterprise is an Information Technology nightmare. Adaptive can assist you in managing change.
In this article from George Spafford he articulates the essence of change management in the IT worldview.
For those of us who use and advocate "Visible Ops", here are 4 reminder steps to running more effective ITIL operations in your enterprise:
1. Stabilize the Patient
2. Catch & Release and Find Fragile Artifacts
3. Establish Repeatable Build Library
4. Enable Continuous Improvement
Visit ITPI for more.
A picture is worth a thousand words.
A model is worth a thousand pictures.
An Adaptation is worth a thousand models.
The Zachman Framework™ is often mistaken by some to be a 6 x 6 matrix. We believe that it is not. We see it as a structured, multidimensional management framework that helps organizations plan, design and implement complex, adaptable information systems. Our view of the framework is shown in this Adaptive rotating hexagon.
We believe that the Zachman Framework guides an organization to define its own unique business and technology "language". This language answers the questions about Why, What, How, Who, When and Where related to an enterprise's strategies, business processes and a number of more concrete levels of an information technology architecture.
The Framework is designed so that people with different perspectives can communicate. The different user perspectives are analagous to those with any complex engineering scenario - "Planner", "Owner", "Designer", "Builder", "Sub-contractor" and the final result - "Operating Enterprise".
In this article from George Spafford he articulates the essence of change management in the IT worldview.
"Change is pervasive through the organization and has huge impacts on the operations of the business. People at all levels in IT must understand and value the fact that as the level of complexity increases in a system, the value of effective change management processes increases.
Studies have shown that 80 percent of the fires that IT fights and 80 percent of security breaches are caused by human error. The vast majority of the problems in IT, and thus for the overall organization, will arise from human limitations in the face of escalating systemic complexity."
For those of us who use and advocate "Visible Ops", here are 4 reminder steps to running more effective ITIL operations in your enterprise:
1. Stabilize the Patient
2. Catch & Release and Find Fragile Artifacts
3. Establish Repeatable Build Library
4. Enable Continuous Improvement
Visit ITPI for more.
19 September 2005
Reputation Risk: Is Murphy to Blame?
Any board member or executive today is well aware of the direct impact an adverse event or significant business disruption can have on shareholder value and customer confidence. When it does happen, how many people just throw up their hands and shout, Murphy's Law!
Murphy is all about managing the "What if's" and planning for their possibility. Here is an example. Are you moving your business sometime soon? What is the possibility that when you do, you will be able to use your e-mail the day you open your new doors? More than one business has been subjected to the Law's of Murphy whenever a complex and logistical project or program is underway. If you are one of those corporate executives who has been unable to use your e-mail or web services the Monday after the big office move, you are not alone. The question is not that it could happen, it's what impact will it have on both customer and employee satisfaction the day it happens, and beyond.
This Corporate Board Member article sums up the impact of Reputation Risk on your organization.
In your future planning to mitigate the Operational Risks associated with Murphy and your reputation, we are reminded of a few of our favorite Murphy's Laws:
1. Computer systems are unreliable, but humans are even more unreliable. Any system which depends on human reliability is unreliable.
2. If there is a possibility of several things going wrong the one that will cause the most damage will be the one to go wrong.
3. A difficult task will be halted near completion by one tiny, previously insignificant detail.
4. High speed chases will always proceed from an area of light traffic to an area of extremely heavy traffic.
5. Every emergency has three phases: PANIC... FEAR... REMORSE.
Do you think you're spending too much time with your team planning? You haven't. Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things go wrong. The organizations whose team has planned for every possible scenario and trained together in live simulations will become the most successful. Their missions will be accomplished on time and within budget.
Incidents of different severity and frequency are happening around you and your organization every day. Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?
Murphy's Law ("If anything can go wrong, it will") was born at Edwards Air Force Base in 1949 at North Base.
It was named after Capt. Edward A. Murphy, an engineer working on Air Force Project MX981, (a project) designed to see how much sudden deceleration a person can stand in a crash.
Murphy is all about managing the "What if's" and planning for their possibility. Here is an example. Are you moving your business sometime soon? What is the possibility that when you do, you will be able to use your e-mail the day you open your new doors? More than one business has been subjected to the Law's of Murphy whenever a complex and logistical project or program is underway. If you are one of those corporate executives who has been unable to use your e-mail or web services the Monday after the big office move, you are not alone. The question is not that it could happen, it's what impact will it have on both customer and employee satisfaction the day it happens, and beyond.
This Corporate Board Member article sums up the impact of Reputation Risk on your organization.
While every Board member knows the importance of managing Enterprise Reputation Risk, the task seems overwhelming. Some Boards are not even trying to proactively manage the risk: their companies will be forced to rely on “reactive” measures after the Reputation Risk event has occurred. These after-the-fact public relations initiatives are expensive and often ineffective. And, since they are event-directed, they don’t provide an ongoing risk structure for the company to identify and control other issues which can cause Reputation Risk. Considering the enormous loss of both financial and franchise value which accompany Reputation Risk, is a Board which only reacts to risk events really doing its job?
In your future planning to mitigate the Operational Risks associated with Murphy and your reputation, we are reminded of a few of our favorite Murphy's Laws:
1. Computer systems are unreliable, but humans are even more unreliable. Any system which depends on human reliability is unreliable.
2. If there is a possibility of several things going wrong the one that will cause the most damage will be the one to go wrong.
3. A difficult task will be halted near completion by one tiny, previously insignificant detail.
4. High speed chases will always proceed from an area of light traffic to an area of extremely heavy traffic.
5. Every emergency has three phases: PANIC... FEAR... REMORSE.
Do you think you're spending too much time with your team planning? You haven't. Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things go wrong. The organizations whose team has planned for every possible scenario and trained together in live simulations will become the most successful. Their missions will be accomplished on time and within budget.
Incidents of different severity and frequency are happening around you and your organization every day. Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?
15 September 2005
The Global State of Information Security: Still Risky Business...
Operational Risks are rising and executives are more interested in preparing their employees for the next crisis.
In a recent worldwide study by CIO Magazine and PWC concerning their risks, thousands of security leaders are fanning the flames over so many breaches and so little insight.
The survey asked about next year's 2006 top priorities or To-Do List:
The good news is that the budgets are finally rising in light of increased theft of intellectual property and identities along with other major information crimes. Budgets in 2005 are now 13% of the IT budget. Consolidation and compliance are issues to be managed however these have bogged down strategic initiatives for the future.
Even after spending in the billions, incidents are still rising and these are the sources of the attacks:
59% - Malicious code
26% - Unknown
25% - Unauthorized entry
21% - Denial-of-service
And what is the most enlightening or discouraging statistic from this group is the answer to the question: When an incident does occur as a result of an attack, who do you tell?
No One - 55%
Customers - 16%
Partners/suppliers - 14%
Is there some correlation between the 26% unknown sources of attacks and the 55% of the incidents where no one is told about it.
In a recent worldwide study by CIO Magazine and PWC concerning their risks, thousands of security leaders are fanning the flames over so many breaches and so little insight.
The survey asked about next year's 2006 top priorities or To-Do List:
1. Business Crisis and Continuity Management
2. Employee Training and Awareness programs
3. Data Backup
4. Overall Information Security Strategy
5. Network Firewalls
The good news is that the budgets are finally rising in light of increased theft of intellectual property and identities along with other major information crimes. Budgets in 2005 are now 13% of the IT budget. Consolidation and compliance are issues to be managed however these have bogged down strategic initiatives for the future.
Even after spending in the billions, incidents are still rising and these are the sources of the attacks:
59% - Malicious code
26% - Unknown
25% - Unauthorized entry
21% - Denial-of-service
And what is the most enlightening or discouraging statistic from this group is the answer to the question: When an incident does occur as a result of an attack, who do you tell?
No One - 55%
Customers - 16%
Partners/suppliers - 14%
Is there some correlation between the 26% unknown sources of attacks and the 55% of the incidents where no one is told about it.
12 September 2005
The Paradox of Privacy...
The banking industry has much to do to overcome the flat curve for new online customers. If this latest Ipsos Insight Research is correct, then privacy remains a significant issue in the consumers mind.
Promising not to sell your information to third parties is only part of the problem. The financial institutions are still using direct marketers and other data mining companies to make sure their latest loan offer goes to the most qualified and relevant customer. In some cases, the banks are doing much of the analysis in-house and only sending the "Bulk Mailers" the correctly correlated data records.
This New York Times article, Europe Zips Lips; U.S. Sells ZIPs, by Eric Dash sums it up quite nicely:
With Identity Theft and Money Laundering as the two top issues with almost every banking institution, you would think that these 3rd party mailers would be consistently monitored and audited just as the banks are. Nothing could be farther from reality.
The proliferation of "phishing" and highly publicized hacker tactics have thwarted industry efforts to convince customers that online banking is safe. Results of the survey include:
83 percent of survey respondents who conduct their personal banking online reported concerns over protecting their personal information from theft.
73 percent of people said personal information theft is a deterrent for them to use online banking survey respondents were equally concerned about banks selling their personal information to a third party, with 72 percent of respondents citing the issue as "extremely" or "very important."
Promising not to sell your information to third parties is only part of the problem. The financial institutions are still using direct marketers and other data mining companies to make sure their latest loan offer goes to the most qualified and relevant customer. In some cases, the banks are doing much of the analysis in-house and only sending the "Bulk Mailers" the correctly correlated data records.
This New York Times article, Europe Zips Lips; U.S. Sells ZIPs, by Eric Dash sums it up quite nicely:
One thing that both privacy cultures have in common is that it is becoming harder for either to control what is and isn't kept private. Information is increasingly the lifeblood of the global economy, not to mention the global fight against terrorism and the quarry of hackers.
As this year's data breaches and compromises have shown, no one really knows how safe the world's vast pool of confidential data is, and therefore how protected anyone is against an invasion of data privacy.
Mr. Reidenberg, the law professor, compares the current situation to the stock market meltdown after the 1929 crash. America responded then by creating the Securities and Exchange Commission and a host of financial disclosure and accounting reforms. The need to safeguard sensitive data, Mr. Reidenberg said, "will necessitate the United States focusing on the legal way we structure information processing, just like we needed to do in the 1930's to put the economy back on stable footing."
With Identity Theft and Money Laundering as the two top issues with almost every banking institution, you would think that these 3rd party mailers would be consistently monitored and audited just as the banks are. Nothing could be farther from reality.
08 September 2005
Corporate Social Responsibility...
Corporate Social Responsibility (CSR) is getting a real work out since our planet's latest natural catastrophe, Hurricane Katrina. Organizations and companies many of us have never heard of are contributing supplies, manpower and aid to the recovery of this key economic region of the U.S..
Social responsibility is a matter more companies are paying close attention to these days and the potential risk that a blind eye may have on the future performance of the institution. What is most interesting are the stories of corporate heroism coming out of the news reports that validates this thinking. And the reports of those organizations who have failed to answer the call to act in the best interest of their employees and customers.
As the political lines are drawn in the sand, one can only wonder who the real heroes are going to be after this historical event is documented. The mothers, fathers, brothers and sisters. The grand parents and the aunts and uncles. Those who weathered the storm or evacuated in time to keep their loved ones out of harms way. Hundreds of thousands of their stories will never make it to the six o'clock news.
Corporate Social Responsibility spans the spectrum from the local Wal-Mart, Marriott and Bank of America to the corner grocery and gas station. Yet the real winners are those who continue to utilize their own talents and resources to contribute in some meaningful way.
Social responsibility is a matter more companies are paying close attention to these days and the potential risk that a blind eye may have on the future performance of the institution. What is most interesting are the stories of corporate heroism coming out of the news reports that validates this thinking. And the reports of those organizations who have failed to answer the call to act in the best interest of their employees and customers.
The risk of failed processes and programs pertaining to social issues is a real threat to the faith people have in your company and your brand, even if they are not a customer today. Contingency planners understand the impact that adverse business disruptions can have on the performance of the company. Less known is the impact that a lack of social responsibility can have on the damage to the brand and reputation of the organization. Many will soon find out as the truth is told.
As the political lines are drawn in the sand, one can only wonder who the real heroes are going to be after this historical event is documented. The mothers, fathers, brothers and sisters. The grand parents and the aunts and uncles. Those who weathered the storm or evacuated in time to keep their loved ones out of harms way. Hundreds of thousands of their stories will never make it to the six o'clock news.
Corporate Social Responsibility spans the spectrum from the local Wal-Mart, Marriott and Bank of America to the corner grocery and gas station. Yet the real winners are those who continue to utilize their own talents and resources to contribute in some meaningful way.
01 September 2005
Begin the Lessons Learned...Again
In the aftermath of Hurricane Katrina, one can only wonder what will happen next. We are already questioning our abilities to respond. One thing is certain, this will not be the last hurricane of this season or the last crisis event facing the Homeland. In order to make sure that organizations and businesses are even more prepared for the near future and beyond, you must have the correct systems to support your worst case scenario and contingency plans.
EMAware is an emergency management system for agencies, jurisdictions and companies that need to control the flow of information before, during, and after emergencies. Using EMAware, organizations can manage inbound and outbound emergency messages and create workflow rules that automate the process of activating emergencies and notifying key staff and peer organizations.
Total organizational awareness is critical in emergency situations. And behind the awful images of CNN live on location, are thousands of people and computers behind the scenes making the recovery even more effective. Our intelligence branches are using geo-spatial imaging to help coordinate search and rescue operations using satellite pictures. FEMA, the Red Cross and DHS are communicating over secure networks for voice, email and text messaging.
No country has the means to recover faster from a disaster of this magnitude than the United States of America. 9/11 is now in our thoughts again this week. Always remember.
EMAware is an emergency management system for agencies, jurisdictions and companies that need to control the flow of information before, during, and after emergencies. Using EMAware, organizations can manage inbound and outbound emergency messages and create workflow rules that automate the process of activating emergencies and notifying key staff and peer organizations.
EMAware allows you to:
* Automate maintenance of Emergency Action Plans
* Originate, receive and manage CAP and EDXL alerts
* Support staff training and testing
* Integrate siloed monitoring systems
* Manage geographically dispersed offices and mobile workforces
Total organizational awareness is critical in emergency situations. And behind the awful images of CNN live on location, are thousands of people and computers behind the scenes making the recovery even more effective. Our intelligence branches are using geo-spatial imaging to help coordinate search and rescue operations using satellite pictures. FEMA, the Red Cross and DHS are communicating over secure networks for voice, email and text messaging.
No country has the means to recover faster from a disaster of this magnitude than the United States of America. 9/11 is now in our thoughts again this week. Always remember.
31 August 2005
Corporate Emergency Response Teams...
1SecureAudit Joins Nationwide Coalition In Collaboration With The U.S. Department Of Homeland Security's National Preparedness Month
The company will join a wide variety of national, state and local organizations, including the U.S. Department of Homeland Security and the American Red Cross, in educating the public about preparing for emergencies.
For Immediate Release
MCLEAN, Va./EWORLDWIRE/Aug. 31, 2005 --- 1SecureAudit, an emerging leader in Operational Risk Management Solutions for the Financial and Healthcare Services Sectors, and its partners in a national coalition, today announced a free event that will describe the simple steps an organization can take to prepare for an emergency.
As part of a special effort during September, which is National Preparedness Month 2005, 1SecureAudit will join national, state and local organizations, including the U.S. Department of Homeland Security and the American Red Cross, in raising public awareness about the role of preparedness in protecting lives and property. Making an emergency plan, assembling an emergency supply kit and identifying community emergency-response resources greatly improve people's ability to survive a natural or man-made crisis.
"We're taking important steps to help organizations become even more educated, trained and better prepared, and we urge you to take time this month to do the same in your business," said Peter L. Higgins, managing director of 1SecureAudit.
On September 28, 2005, join 1SecureAudit at 1:00 p.m. EDT for a free online webinar to learn how to create corporate emergency response teams (CERT). Produced in cooperation with Long Branch Systems, Inc. of Rockville, Maryland, and ABD Insurance and Financial Services of Redwood City, California, the web-based presentation will highlight tasks that a business can perform now, and issues that it must consider in the future as it develops a comprehensive all-hazards risk program.
Download Details
The company will join a wide variety of national, state and local organizations, including the U.S. Department of Homeland Security and the American Red Cross, in educating the public about preparing for emergencies.
For Immediate Release
MCLEAN, Va./EWORLDWIRE/Aug. 31, 2005 --- 1SecureAudit, an emerging leader in Operational Risk Management Solutions for the Financial and Healthcare Services Sectors, and its partners in a national coalition, today announced a free event that will describe the simple steps an organization can take to prepare for an emergency.
As part of a special effort during September, which is National Preparedness Month 2005, 1SecureAudit will join national, state and local organizations, including the U.S. Department of Homeland Security and the American Red Cross, in raising public awareness about the role of preparedness in protecting lives and property. Making an emergency plan, assembling an emergency supply kit and identifying community emergency-response resources greatly improve people's ability to survive a natural or man-made crisis.
"We're taking important steps to help organizations become even more educated, trained and better prepared, and we urge you to take time this month to do the same in your business," said Peter L. Higgins, managing director of 1SecureAudit.
On September 28, 2005, join 1SecureAudit at 1:00 p.m. EDT for a free online webinar to learn how to create corporate emergency response teams (CERT). Produced in cooperation with Long Branch Systems, Inc. of Rockville, Maryland, and ABD Insurance and Financial Services of Redwood City, California, the web-based presentation will highlight tasks that a business can perform now, and issues that it must consider in the future as it develops a comprehensive all-hazards risk program.
Download Details
29 August 2005
Katrina: Category 4 Storm Blasts U.S....
Now that Hurricane Katrina has made landfall for the second time in the U.S., we are reminded of several important operational risk management topics.
If a third party service provider is being considered for the provision of critical information processing services, the organization requires outsourcing service providers to develop and establish a disaster recovery framework, which defines its role and responsibilities for documenting, maintaining and testing its contingency plans and recovery procedures. The vendor must review, update and test its business continuity plans regularly in accordance with changing technologies, conditions and operation requirements.
The organization must also be prepared for worst-case scenarios for service interruptions when a service provider is unable to continue operations or render the services required. The organization's business continuity plans must include additional vendors or in-house recovery procedures to resume information processing. Arrangements must be made to ensure continued availability of the information service in the event the third party service provider is unable to perform under their contract obligations.
Hibernia Bank, who is merging with Capital One and is in the path of Katrina has this to say about their BCCM operations:
We wish them and all others in the New Orleans, LA and Biloxi areas Gods speed during these difficult days ahead.
If a third party service provider is being considered for the provision of critical information processing services, the organization requires outsourcing service providers to develop and establish a disaster recovery framework, which defines its role and responsibilities for documenting, maintaining and testing its contingency plans and recovery procedures. The vendor must review, update and test its business continuity plans regularly in accordance with changing technologies, conditions and operation requirements.
The organization must also be prepared for worst-case scenarios for service interruptions when a service provider is unable to continue operations or render the services required. The organization's business continuity plans must include additional vendors or in-house recovery procedures to resume information processing. Arrangements must be made to ensure continued availability of the information service in the event the third party service provider is unable to perform under their contract obligations.
Katrina's fury also was felt at the Louisiana Superdome, normally home of professional football's Saints, which became the shelter of last resort for about 9,000 of the area's poor, homeless and frail.
Electrical power at the Superdome failed at 5:02 a.m., triggering groans from the crowd. Emergency generators kicked in, but the backup power runs only reduced lighting and cannot run the air conditioning.
About 370,000 customers in southeast Louisiana were estimated to be without power, said Chenel Lagarde, spokesman for Entergy Corp., the main energy power company in the region.
Hibernia Bank, who is merging with Capital One and is in the path of Katrina has this to say about their BCCM operations:
Elevated back-up generators are in place to support the company's central processing operations in New Orleans in the event of a power outage in the city. Hibernia's operations centers in Houston and Shreveport are ready to serve as data back-up sites. In addition to providing contingency-planning support for the New Orleans center, the Houston center supports Hibernia's Texas operations.
"We constantly monitor the hurricane's track and communicate with emergency officials," said Herb Boydstun, president and CEO. "We have mobilized our people across Louisiana and in Texas to respond to storm-related issues."
Boydstun pointed out that Hibernia has comprehensive contingency plans designed to minimize disruption of service to its customers and to resume operations as soon as possible.
Employees are trained to transfer and recover systems, data and other vital components quickly. In Shreveport, the company has computers with redundant systems that can be activated in case of a New Orleans power outage. Hibernia maintains additional space in the Shreveport area that can quickly be converted to a technology center to support operations routed from New Orleans.
We wish them and all others in the New Orleans, LA and Biloxi areas Gods speed during these difficult days ahead.
26 August 2005
Safety & Security: Wi-Fi to the Rescue...
Have you ever wondered where high value assets are located in your facility or on your campus? Especially those that are mobile assets. Have you ever wondered who and where visitors to your offices are located at any given time? Now Ekahau is making the answers to these and other questions much easier and at a more rapid response. Safety, production costs, and time-to-market are vital points of consideration for industries such as oil refineries, chemical factories and other process-industry facilities. By being able to easily track people, vehicles, and assets, these factors can be made substantially more efficient.
Safety and security applications are numerous especially in healthcare:
• Emergency management - more efficient and faster emergency response
• Patient monitoring - better patient safety and increased throughput
• Workflow management - better staff utilization and increased patient throughput
• Equipment management - reduced need for inventory
• Information delivery - improved workflow, reduced errors
• Billing support & verification - improved revenue capture
We can think of other homeland security and first responder applications using the Ekahau capabilities especially in post event incident management and key personnel tracking inside a closed perimeter. As WiMax and other 802.11 networks are deployed in major metro locations, the applications become wide spread.
Founded in 2000, Ekahau is the recognized leader in location-enabling enterprise Wi-Fi networks. Ekahau's mission is to provide the easiest, most cost effective and accurate positioning solutions for locating people, assets, inventory and other objects using wireless enterprise networks. The Ekahau solution tracks wireless laptops, PDAs, VOIP phones, Wi-Fi tags and other 802.11 enabled devices.
Ekahau’s solution allows businesses to keep track of valuable assets and equipment, improve the overall workflow, and improve the levels of corporate security and customer service. With Ekahau, the critical corporate resources, people and assets, will be always available at the right place and at the right time. As Ekahau's location tracking solution does not require installation of proprietary wireless infrastructure, but can be done individually over the private Wi-Fi network, the deployment cost is kept in minimum, and the overall system payback time is the fastest possible.
Safety and security applications are numerous especially in healthcare:
• Emergency management - more efficient and faster emergency response
• Patient monitoring - better patient safety and increased throughput
• Workflow management - better staff utilization and increased patient throughput
• Equipment management - reduced need for inventory
• Information delivery - improved workflow, reduced errors
• Billing support & verification - improved revenue capture
We can think of other homeland security and first responder applications using the Ekahau capabilities especially in post event incident management and key personnel tracking inside a closed perimeter. As WiMax and other 802.11 networks are deployed in major metro locations, the applications become wide spread.
22 August 2005
HIPAA: Outsourcing Protected Health Information...
At least in the U.S., the Department of Health and Human Services (HHS) is quite clear about Protected Health Information (PHI). What is personal or protected health information and under what circumstances as a business must you keep this information private?
Now let's introduce the offshoring or outsourcing component of running a data intensive and information centric business model. Healthcare is all about the collection, analysis and historical trending of data about our vital signs, symptoms, habits and test results. Where is all of that data being processed and stored from transcribed audio and visual media?
QUESTION: To what extent does the HIPAA Privacy Rule (the "Privacy Rule") govern contracts with foreign contractors and subcontractors?
Do you know that soon your PHI may be located in a Medical Information Bureau (MIB)? And in this case, it could be a real problem or as this scenario describes, it could kill you:
Here's the scenario. A bad guy steals your identity. He ends up in the hospital and pretends to be you. His medical history becomes a part of your "MIB identity, or Medical Information Bureau identity." You could end up being denied insurance -- or much, much worse. If you show up on the medical bureau as having heart disease or diabetes and then show up at the hospital unconscious, they might kill you trying to save you.
Now let's introduce the offshoring or outsourcing component of running a data intensive and information centric business model. Healthcare is all about the collection, analysis and historical trending of data about our vital signs, symptoms, habits and test results. Where is all of that data being processed and stored from transcribed audio and visual media?
Most patients who visit the hospital probably do not spend too much time thinking what happens to information in their medical records after they leave, but in the age of outsourcing, the path of a patient's medical record can be a long and precarious one. Medical Data Theft is a growing concern.
Consider a recent case at a university hospital in California, where the doctor's notes from a patient visit were first sent to a transcription service company in Florida, which decided to subcontract to another firm in Texas. The Texas firm subcontracted the work yet again, ending up with a woman in Pakistan. This Pakistani woman became upset because her payments for her services were late, so she decided to send an e-mail to the university hospital, threatening to post the medical records on the Internet if she was not paid immediately. It might sound like a nightmare, but it is the reality of outsourcing today.
Medical records are secured under HIPAA standards, but when they leave the United States, these rules may not necessarily apply.
QUESTION: To what extent does the HIPAA Privacy Rule (the "Privacy Rule") govern contracts with foreign contractors and subcontractors?
Do you know that soon your PHI may be located in a Medical Information Bureau (MIB)? And in this case, it could be a real problem or as this scenario describes, it could kill you:
Here's the scenario. A bad guy steals your identity. He ends up in the hospital and pretends to be you. His medical history becomes a part of your "MIB identity, or Medical Information Bureau identity." You could end up being denied insurance -- or much, much worse. If you show up on the medical bureau as having heart disease or diabetes and then show up at the hospital unconscious, they might kill you trying to save you.
18 August 2005
Big Blue Gets Serious About ORM...
Big Blue is getting ever more serious about Operational Risk Management. Recently unveiled solutions for biometrics, enterprise risk management frameworks, and customer relationship management cater to their financial customers.
When IBM says listen, most finance sector CIO's stop in their tracks.
As a public company, they are the perfect lab for testing their own systems and solutions, especially when it comes to regulatory compliance issues. The question remains whether the SOX process at IBM will produce positive outcomes. Time will tell. Even more interesting is their approach to "cancelable biometrics". The financial industry is under new pressure to solve some of the operational loss events due to unauthorized access. Authentication using more than a User ID and password is gaining momentum as a result of new focus by the banks to stem the millions of dollars they are losing each month. This solution tries to address the privacy issue for consumers feeling their data is safe and to thwart the value to hackers gaining access and utilizing your personal biometric for fraudulent purposes.
The cryptographers think they have found irreversible algorithms to make this commercially feasible. We wish this becomes a reality.
When IBM says listen, most finance sector CIO's stop in their tracks.
IBM demonstrated a "cancelable" biometrics system, in which a prearranged transformation algorithm intentionally distorts a person's biometric data, such as a fingerprint, rendering the original biometrics useless for identification purposes. The biometrics project was conceived out of a need "to make replacing biometrics as easy as replacing credit cards," said IBM researcher Nalini Ratha during a presentation at IBM's Industry Solutions Lab in Hawthorne, N.Y.
IBM detailed an enterprise risk-management framework intended to help financial institutions cope with a stream of regulations such as Basel II and the Sarbanes-Oxley Act. The central themes of the IBM approach are that risk and compliance need to be managed centrally, and that operational risk, such as the likelihood of losses due to unpredictable events such as natural disasters, needs to be modeled using probabilistic means. IBM tested the risk framework during its own Sarbanes-Oxley compliance process, which involved almost 10,000 financial-control points.
As a public company, they are the perfect lab for testing their own systems and solutions, especially when it comes to regulatory compliance issues. The question remains whether the SOX process at IBM will produce positive outcomes. Time will tell. Even more interesting is their approach to "cancelable biometrics". The financial industry is under new pressure to solve some of the operational loss events due to unauthorized access. Authentication using more than a User ID and password is gaining momentum as a result of new focus by the banks to stem the millions of dollars they are losing each month. This solution tries to address the privacy issue for consumers feeling their data is safe and to thwart the value to hackers gaining access and utilizing your personal biometric for fraudulent purposes.
IBM's system wouldn't entirely solve the replaceability problem of biometrics: If a hacker got hold of a user's fingerprint and made a passable model, he could still wreak havoc with it. What IBM's technology could do, however, is significantly narrow hackers' opportunities to gain access to such data. If a user's fingerprints (or facial photographs, iris scans or any other biological marker) aren't stored in any of the systems she uses them to access, cracking those systems won't give the hacker keys to the victim's biometric kingdom. If a hacker did get in - and the frequency with which companies sheepishly confess to database hacks and inadvertently exposed personal information illustrates the reality of that risk - IBM's system would let a user quickly cancel the compromised biometric profile and generate a new one, akin to replacing a lost or stolen credit card.
The cryptographers think they have found irreversible algorithms to make this commercially feasible. We wish this becomes a reality.
15 August 2005
ISO 17799: Culture Sensitive Best Practices...
“Unlike ISO 17799, however, the SAS 70 is not a "best practices" standard. Instead, it documents the controls in place that satisfy the company's internal control objectives.” This CSO's worldly insights could not be more true.
Implementation of 7799 standards and a comprehensive ISMS provides your organization with a security & privacy governance framework… a one-stop best practices solution for cultural security and privacy issues across the globe. Measuring documented controls across Lines of Business and International Business Units requires a single benchmark. Without a pervasive global information security standard within the organization, employees and management can’t determine if they are improving, or where they are most vulnerable to new threats. Auditors can’t certify if controls are working without a published and well-established set of processes and procedures for checking the validity and evidence of information security.
CSO’s facing a myriad of new Operational Risks are quickly adopting the use of thoroughly tested or proven controls and best practices that span countries and cultures. More importantly, they have also discovered that supply-chain risk extends the reach of their management systems well beyond their own boardroom.
Implementation of 7799 standards and a comprehensive ISMS provides your organization with a security & privacy governance framework… a one-stop best practices solution for cultural security and privacy issues across the globe. Measuring documented controls across Lines of Business and International Business Units requires a single benchmark. Without a pervasive global information security standard within the organization, employees and management can’t determine if they are improving, or where they are most vulnerable to new threats. Auditors can’t certify if controls are working without a published and well-established set of processes and procedures for checking the validity and evidence of information security.
CSO’s facing a myriad of new Operational Risks are quickly adopting the use of thoroughly tested or proven controls and best practices that span countries and cultures. More importantly, they have also discovered that supply-chain risk extends the reach of their management systems well beyond their own boardroom.
11 August 2005
OREA: Operational Risk Enterprise Architecture
What impact does change have on Operational Risk? As Boards of Directors and Executives try to cope with increased market competition, organizational restructuring and mergers or acquisitions; complexity becomes exponential. Change has a monumental impact on risk exposures and consequences.
Adaptive continues to be a leader in the creation of effective Enterprise Architectures to manage risk on a global scale.
Companies who are in highly regulated industry sectors are perfect examples of organizations who must rapidly adapt to new laws, government mandates and must remain proactively compliant. How can you effectively keep pace in managing risk without an Enterprise Architecture? Simply stated: It's literally impossible.
Can you visualize how information flows through your organization? In order to report new information to regulators you first have to know what applications and databases are impacted by the new law or a request for additional data. Without a repository of metamodels to start with, you won't know where to begin.
In the context of Operational Risk Management, Enterprise Architecture enables the construction of end-to-end visualization of the information flows from any point (e.g. origin, final report, any intermediate point), in a form suitable for both business and technical users: and also allows the linkage of the technical definitions to business term descriptions.
If your Operational Risk professionals are not working side by side your Enterprise Architects, maybe it's time you booked that conference room for a few weeks.
Adaptive continues to be a leader in the creation of effective Enterprise Architectures to manage risk on a global scale.
Many organizations have difficulty effectively tracing how their strategies are implemented and how resources are used across the organization. Every year, millions or even billions of currency is lost on mismatches between strategies, processes, performance targets, roles and responsibilities, human resources, IT applications and projects to improve all these.
Top executives recognize that effectively managing an organization requires a clear understanding and alignment of several key factors. However, they typically lack the tools they need to manage the complexity involved. This is where Adaptive's Top Slice Architecture comes in.
To continuously adapt to their changing environments, executives must know about, keep in balance, and communicate several things:
What exactly are the strategies of the organization and how should they be implemented? (Strategy Development and Organizational Change)
What are the processes the organization executes, how are they integrated, and how do they contribute to the strategy of the organization? (Business Process Management)
How are human resources being utilized and whether there is optimum use of skills and resources available across processes and functions? (Human Resource Management)
To what extent is the organization chart a proper reflection of appropriate roles and responsibilities, in order to effectively and efficiently carry out all work?(Organization Management)
What IT applications are available in the organization, how do they interface and what processes and functions do they support? (IT Portfolio Management)
How does the performance of each process, each function and each individual add up to the organizationÂs performance? (Performance Management)
What projects are currently underway, how do they effect and impact change, what processes and IT applications do they change and how does this contribute to the strategy of the organization? (Project & Program Management)
Companies who are in highly regulated industry sectors are perfect examples of organizations who must rapidly adapt to new laws, government mandates and must remain proactively compliant. How can you effectively keep pace in managing risk without an Enterprise Architecture? Simply stated: It's literally impossible.
Can you visualize how information flows through your organization? In order to report new information to regulators you first have to know what applications and databases are impacted by the new law or a request for additional data. Without a repository of metamodels to start with, you won't know where to begin.
In the context of Operational Risk Management, Enterprise Architecture enables the construction of end-to-end visualization of the information flows from any point (e.g. origin, final report, any intermediate point), in a form suitable for both business and technical users: and also allows the linkage of the technical definitions to business term descriptions.
If your Operational Risk professionals are not working side by side your Enterprise Architects, maybe it's time you booked that conference room for a few weeks.
09 August 2005
US National Security: Critical Infrastructure Protection...
Now that InfraGard has a Memorandum of Understanding with DHS, only time will tell what impact the new formalized relationship will have on national preparedness.
FBI Director Mueller's keynote is another indicator that public / private cooperation is essential to the government in order to protect our vital national assets.
WASHINGTON--(BUSINESS WIRE)--Aug. 8, 2005--InfraGard National Members Alliance (INMA) today announced it has struck an official Memorandum of Understanding (MOU) with the Department of Homeland Security (DHS) Private Sector Office (PSO) regarding a Strategic Partnership. The announcement was made at the 2005 "InfraGard Congress," InfraGard's annual business meeting, which is taking place today at the JW Marriott in Washington D.C.
The purpose of the MOU between InfraGard and DHS is to outline the objectives of a Strategic Partnership between the two parties, as well as their related roles and responsibilities. A Strategic Partnership between InfraGard and DHS will provide both organizations with the opportunity to develop and cultivate existing relationships between the government and the private sector in an effort to engage private sector subject matter experts for the protection of our nation's critical infrastructure.
"InfraGard highly values its MOU with DHS, and is looking forward to engaging our local members with DHS leadership to identify issues and develop programs to address them," said Dr. Phyllis Schneck, chairman of the Board of Directors, InfraGard National Members Alliance. "DHS has expressed interest in InfraGard's success in engaging subject matter experts in all 50 states across all 14 critical infrastructure sectors to build trusted relationships with Federal, state and local law enforcement and government agencies. Additionally, the relationship between DHS and InfraGard is critical as our membership grows to serve as the primary liaison between private sector and all areas of government and law enforcement."
The joining of forces between InfraGard and DHS will enable both organizations to raise security awareness more effectively in communities across the country. Through National and local events coordinated by InfraGard across its 84 chapters, DHS leadership will have a forum to better inform the business community about homeland security programs and initiatives. In turn, the private sector will have a channel via InfraGard to communicate its issues to DHS, and also provide direct feedback about DHS initiatives.
FBI Director Mueller's keynote is another indicator that public / private cooperation is essential to the government in order to protect our vital national assets.
"Director Mueller's participation in the InfraGard 2005 National Conference is proof positive of the significant role InfraGard has played in National security. Furthermore, thanks in large part to InfraGard's vision and dedication, law enforcement agencies across local, state and Federal levels actively are and will continue to work together to secure the United States from threats to its critical infrastructure."
In addition to Mueller's keynote at the InfraGard 2005 National Conference there also will be tracks and technical sessions dedicated to the following topics: Drinking Water Security; Maritime and Port Vulnerabilities and Security; Computer Forensics; Cyber Security; First Responders; Financial Institution Security; Regulatory Compliance; and Supervisory Control and Data Acquisition (SCADA) Systems.
08 August 2005
Healthcare Risk: Counterfeiting & Online Pharmacies...
Pharmaceutical companies are on the offensive along with the FDA to rid the Internet from bogus Online Pharmacies.
The continuing growth of online pharmacies provides dealers and counterfeiters with ready access to unsuspecting consumers. Since goods sold online are typically sent through the conventional mail system, they frequently by-pass national regulations for the distribution of controlled goods.
Jim Kouri's thoughts on this subject are correct:
The use of effective operational risk mitigation strategies for Pharma and Healthcare companies, enables the detection of illicit distribution, trademark abuse, objectionable association and counterfeit activities, that can then be countered in a highly focused manner. The outcomes can save lives and millions of dollars per year.
For a list of Certified Online Pharmacies see:
VIPPS Program
For more information on this health care risk see:
Safe Medicines
The continuing growth of online pharmacies provides dealers and counterfeiters with ready access to unsuspecting consumers. Since goods sold online are typically sent through the conventional mail system, they frequently by-pass national regulations for the distribution of controlled goods.
Jim Kouri's thoughts on this subject are correct:
Those Americans demanding the US government to allow citizen's access to foreign prescription drugs should heed the concerns of the world's foremost health organization. According to the World Health Organization's definition a counterfeit medicine "is one which is deliberately and fraudulently mislabelled with respect to identity and/or source. Counterfeiting can apply to both branded and generic products and counterfeit products may include products with the correct ingredients or with the wrong ingredients, without active ingredients, with insufficient active ingredients or with fake packaging."
It is estimated that one in 20 pharmaceutical products on the market is counterfeit, with the number rising to one in three in some developing countries.
Counterfeit pharmaceuticals are manufactured and distributed by criminals, companies or individuals who have the desire to make money unlawfully. They may contain too much, too little or no active ingredient, the wrong ingredients or high levels of impurities, contaminants and even toxic substances. They could be reject or out-of-date formulations withdrawn from the market which are obtained by counterfeiters, relabelled as bona fide product and introduced back into circulation. They have killed and injured thousands around the world.
The use of effective operational risk mitigation strategies for Pharma and Healthcare companies, enables the detection of illicit distribution, trademark abuse, objectionable association and counterfeit activities, that can then be countered in a highly focused manner. The outcomes can save lives and millions of dollars per year.
For a list of Certified Online Pharmacies see:
VIPPS Program
For more information on this health care risk see:
Safe Medicines
05 August 2005
ORM for Board Directors: 4D Risk Strategy...
Savvy Operational Risk Management Executives and Audit Committee Directors should ask themselves the following questions:
Do we have the management systems we require to audit compliance, risk, and claims data?
Are the corporate data collection systems automated?
Are we in compliance with state and federal regulations affecting my industry?
How do we merge data from internal and external sources so it provides me with a holistic view of risk?
How do we easily compare data across Lines of Business?
How do we chart risk exposures in real-time for the company as a whole?
How do we access our audit information in the organization?
In our current threat environment, interested parties inside and outside of an organization are demanding more accountability from Board Directors to handle all facets of Operational Risk Management (ORM). This cannot happen until there is a clear understanding of the different types of risk that could impact the company as well as the consequences and frequency.
In order to survive, corporations need a "4D Risk Strategy". Only then, can any of these questions begin to be answered with any certainty.
Do we have the management systems we require to audit compliance, risk, and claims data?
Are the corporate data collection systems automated?
Are we in compliance with state and federal regulations affecting my industry?
How do we merge data from internal and external sources so it provides me with a holistic view of risk?
How do we easily compare data across Lines of Business?
How do we chart risk exposures in real-time for the company as a whole?
How do we access our audit information in the organization?
In our current threat environment, interested parties inside and outside of an organization are demanding more accountability from Board Directors to handle all facets of Operational Risk Management (ORM). This cannot happen until there is a clear understanding of the different types of risk that could impact the company as well as the consequences and frequency.
In order to survive, corporations need a "4D Risk Strategy". Only then, can any of these questions begin to be answered with any certainty.
02 August 2005
National Preparedness Month 2005 Coalition Members...
NATIONAL PREPAREDNESS MONTH 2005 COALITION MEMBERS
AS OF August 1, 2005
The U.S. Department of Homeland Security and the American Red Cross are working with a wide variety of public and private sector organizations to educate the public about the importance of emergency preparedness. Throughout September, these organizations will provide information, host events and sponsor activities that disseminate emergency preparedness messages to and encourage action in their customers, members, employees, stakeholders and communities across the nation. Below is a listing of the 166 members of the 2005 National Preparedness Month Coalition as of August 1, 2005.
Click Here to Join the National Preparedness Month Coalition Members
1SecureAudit is hosting a Webinar in collaboration with Long Branch Systems and ABD Insurance, Inc. on September 28th, 2005. We hope you will join us!
AS OF August 1, 2005
The U.S. Department of Homeland Security and the American Red Cross are working with a wide variety of public and private sector organizations to educate the public about the importance of emergency preparedness. Throughout September, these organizations will provide information, host events and sponsor activities that disseminate emergency preparedness messages to and encourage action in their customers, members, employees, stakeholders and communities across the nation. Below is a listing of the 166 members of the 2005 National Preparedness Month Coalition as of August 1, 2005.
Click Here to Join the National Preparedness Month Coalition Members
1SecureAudit is hosting a Webinar in collaboration with Long Branch Systems and ABD Insurance, Inc. on September 28th, 2005. We hope you will join us!
29 July 2005
The Identity Theft Protection Act...
As the legislation for the ID Theft Bill makes it's way through the full Senate, one has to wonder what will change. What behavior are we trying to influence here?
The real work begins for those institutions who thought they were exempt from regulations like the FTC SafeGuard Rule and the Gramm-Leach-Bliley Act (GLBA). Now they must do what the banks,thrifts and other OCC controlled organizations have been doing for years. Spending more money and resources on Information Security. Sure, human factors will have their toll even on those who have been complying with these laws for years. Bank of America and others have been burned. What is more interesting to see going forward is how the third-party processors and other information supply chain companies will behave, and for that matter, what the largest institutions will do to audit these business partners.
Stealing and selling sensitive information is the work of increasingly criminal organizations, located in countries across the globe. And even in our own back yard here in the United States. Let's just hope that organizations who are taking our sensitive personal identifiable information to verify our identity have the right people, right resources and take this legislation seriously this time.
Approved on a voice vote, the Identity Theft Protection Act requires data brokers, government agencies and educational institutions to disclose security breaches to consumers within 45 days if there is a "reasonable risk" of identity theft involved in the breach.
The evidence of possible identity theft includes such factors as whether the data containing sensitive information is useable by an unauthorized third party and whether the data is in the possession of an unauthorized third party that is likely to commit identity theft.
Under the bill's language, companies and other organizations are required to develop, maintain and enforce a written program for the security of sensitive information. Physical and technological safeguards will be mandated through rules and regulations developed by the Federal Trade Commission (FTC).
Within a year of the passage of the bill, the FTC is required to develop procedures for authenticating the credentials of any third party to which sensitive personal information is to be transferred or sold by a data broker or other organization.
For security breaches involving 1,000 or more consumers, the firms responsible for the breaches must not only notify consumers but also the FTC. The agency, in turn, will post a report of the breach on its Web site without disclosing any sensitive personal data.
For breaches of fewer than 1,000 records that do not create a reasonable risk of identity, the data broker must still notify the FTC.
The real work begins for those institutions who thought they were exempt from regulations like the FTC SafeGuard Rule and the Gramm-Leach-Bliley Act (GLBA). Now they must do what the banks,thrifts and other OCC controlled organizations have been doing for years. Spending more money and resources on Information Security. Sure, human factors will have their toll even on those who have been complying with these laws for years. Bank of America and others have been burned. What is more interesting to see going forward is how the third-party processors and other information supply chain companies will behave, and for that matter, what the largest institutions will do to audit these business partners.
Stealing and selling sensitive information is the work of increasingly criminal organizations, located in countries across the globe. And even in our own back yard here in the United States. Let's just hope that organizations who are taking our sensitive personal identifiable information to verify our identity have the right people, right resources and take this legislation seriously this time.
27 July 2005
Whistleblowing: The Age of Undersight...
The impact of "Whistleblowing" on your organizations ability to detect fraud is only as good as your safeguards for retaliation. Who will step forward if they think that their job or personal safety is at risk? This article by Daniel Westman sums up many of the issues surrounding "Undersight".
Undersight is a culture issue. No one wants to be known as the "Stool Pigeon" or the "Rat" who attempts to undermine the organization with a warning bell about someone or some procedure that is flawed. How you promote the use of "Undersight" in your company begins with management behavior.
Even as SOX has heightened the issues around detecting and reporting internal fraud by employees, it still may be the external auditors who remain the bad guys. Have you ever made it obvious to an outside auditor that you have a "hunch" or suspect something isn't right? Just remember, you don't have to wait. Audit Committee's are obligated to investigate any anonymous tips, regardless of the outcome.
Edmund Burke's famous 18th-century dictum encapsulates why compliance efforts cannot rely on written policies or codes of conduct alone. After all, Enron had policies on paper forbidding the practices that brought down the company. Without people willing to report violations of law or codes of conduct, compliance efforts inevitably will be frustrated.
The thesis of this article is that the new civil and criminal whistleblower provisions of Sarbanes-Oxley, coupled with growing acceptance of whistleblowing in both the law and popular culture, may create a climate in which employees more frequently engage in "undersight" to report violations of law or policy. "Undersight" is a term this author has coined to describe corporate employees who witness potential fraud first-hand and voice their concerns, in contrast with "oversight" through which corporate outsiders attempt to detect fraud relying on second-hand information.
Undersight is a culture issue. No one wants to be known as the "Stool Pigeon" or the "Rat" who attempts to undermine the organization with a warning bell about someone or some procedure that is flawed. How you promote the use of "Undersight" in your company begins with management behavior.
To the extent that fear of retaliation has deterred employees from identifying themselves by openly raising concerns, the ability to make anonymous complaints knowing that such complaints must be investigated may encourage whistleblowing. Put differently, before SOX, it may have been easier to rationalize remaining silent based on fears of retaliation. The new stature given to anonymous complaints, however, may give employees greater assurance that their identities will not be discovered, and that their concerns still will be addressed. Thus, a common rationalization for not blowing the whistle may be significantly undermined.
Even as SOX has heightened the issues around detecting and reporting internal fraud by employees, it still may be the external auditors who remain the bad guys. Have you ever made it obvious to an outside auditor that you have a "hunch" or suspect something isn't right? Just remember, you don't have to wait. Audit Committee's are obligated to investigate any anonymous tips, regardless of the outcome.
25 July 2005
The Cost of War...
At a recent meeting of the ISSA in the Washington, DC area there was much discussion about the governments spending agenda on Information Security. And for good reason.
It seems that the Office of Management and Budget is moving towards a model for procurement that will support the Federal Enterprise Architecture(FEA) E-Gov initiatives. The fear is that Information Security is being put in a "box" for easier and more efficient ordering for federal agencies, except INTEL and DOD. They are not impacted by the latest move to a "Center of Excellence" for InfoSec.
CISO's at these federal agencies are operating with their hands tied in an effort to improve their FISMA grades with declining budgets and line items being moved from their control to the "Center of Excellence".
Has the cost of war finally gotten to the point where we have finally made "Information Security" and "Contingency Planning" a commodity to be put in a box? Not until the agencies are standardized on configurations, hardware/software and other baseline security appliances and applications will you have the ability to do what is initially intended by the initiative. To save money, resources and redundancy.
Information and Physical security is a moving target for a reason. It evolves in response to attackers new tools and exploits probing to find the latest vulnerabilities. We wish the non-INTEL and DOD agencies luck in their new mission to secure their respective enterprises.
It seems that the Office of Management and Budget is moving towards a model for procurement that will support the Federal Enterprise Architecture(FEA) E-Gov initiatives. The fear is that Information Security is being put in a "box" for easier and more efficient ordering for federal agencies, except INTEL and DOD. They are not impacted by the latest move to a "Center of Excellence" for InfoSec.
CISO's at these federal agencies are operating with their hands tied in an effort to improve their FISMA grades with declining budgets and line items being moved from their control to the "Center of Excellence".
As a result of the FEA PMO’s analysis of the FY 2006 budget data, OMB established the IT Security Line of Business to propose common solutions and architecture strengthening the ability of all agencies to identify vulnerabilities, defend against threats and manage resulting risks. The FEA PMO will guide this LoB initiative through development of a common solution architecture by:
• Providing initial direction on EA work products (i.e., common solutions and target architecture);
• Reviewing EA work products and providing feedback;
• Reviewing service components developed by the LoB;
• Identifying areas for reuse or standardization across agency architectures; and
• Identifying agency movement toward LoB standards and services in their EA
Transition Strategy
The FEA PMO and the LoB task force will collaborate on identifying potential common solutions (e.g., training/awareness, incident response, certification and accreditation, the selection of security products, reporting, implementation of security configurations, policy and budget coordination, disaster recovery, contingency planning, and access controls), and will identify business processes and systems impacted if a security service is standardized or outsourced.
Use of the FEA Practice and reference models to identify areas for reuse and standardization will result in better and more consistent security management processes and controls across the Federal government.
Has the cost of war finally gotten to the point where we have finally made "Information Security" and "Contingency Planning" a commodity to be put in a box? Not until the agencies are standardized on configurations, hardware/software and other baseline security appliances and applications will you have the ability to do what is initially intended by the initiative. To save money, resources and redundancy.
Information and Physical security is a moving target for a reason. It evolves in response to attackers new tools and exploits probing to find the latest vulnerabilities. We wish the non-INTEL and DOD agencies luck in their new mission to secure their respective enterprises.
22 July 2005
The Spectrum of Trust...
What is TRUST? Can you see it? Can you hear it? Can you feel it? Maybe all of these. But does it live on a dynamic spectrum?
No Trust<----------Trust Exists--------->Implicit Trust
When you trust someone or something, you put "faith" in it. You are more inclined to invest your time and effort to spend time with it and to ensure that it thrives and grows. Because when you move from the far left where "No Trust" exists and move to the right, somewhere along that spectrum trust begins to exist. And it isn't until you get to a point when you never think about it again, that maybe you can say that trust is "Implicit".
Steven Mufson has an interesting perspective on risk and trust:
Taking risks is about degrees of trust. The amount of risk you decide to accept is directly tied to the degree to which you are willing to trust the entity that you are placing your faith in. Whether it's your spouse, your broker, your boss, your company, your partner, your supplier, your board of directors, your congressman or your government; each entity lives and changes on this spectrum of trust.
No Trust<----------Trust Exists--------->Implicit Trust
When you trust someone or something, you put "faith" in it. You are more inclined to invest your time and effort to spend time with it and to ensure that it thrives and grows. Because when you move from the far left where "No Trust" exists and move to the right, somewhere along that spectrum trust begins to exist. And it isn't until you get to a point when you never think about it again, that maybe you can say that trust is "Implicit".
Steven Mufson has an interesting perspective on risk and trust:
As much as President Bush or British Prime Minister Tony Blair say we won't let terrorists change our lives, this could be the start of a new era, and not in a good way. There is something unsettling about the idea of turning America into a nation of snitches and amateur spies. Is the guy taking photos of the George Washington Bridge a terrorist or the next Henri Cartier-Bresson? Are people wandering in front of national monuments scoping out targets or are they tourists? And do you trust the strangers around you to make those judgments based on looks and feelings?
All the same, on the Metro last week, I departed from my usual routine of simply reading the newspaper, or looking over a manuscript, or daydreaming. I found myself glancing up to look at the other passengers and their bags, or to gauge the distance to the stairs, or read the instructions on the emergency exits. Reassuring? Maybe.
In any case, this week you'll be able to find me on the platform waiting for the next train.
Taking risks is about degrees of trust. The amount of risk you decide to accept is directly tied to the degree to which you are willing to trust the entity that you are placing your faith in. Whether it's your spouse, your broker, your boss, your company, your partner, your supplier, your board of directors, your congressman or your government; each entity lives and changes on this spectrum of trust.
19 July 2005
Phishing Risk: Two-Factor Authentication to the Rescue...
In a recent banking survey conducted by the Risk Management Association (RMA) on Operational Risk Management, 105 institutions responded. Over one third indicated their greatest risk was "Unauthorized Access" from both insiders and outsiders together with attacks on bank systems.
What was obvious from the survey was that no matter the size of the institution, both Internet and Vendor Risk are pervasive. With banks with assets over $100Bn, the highest risk was ineffective IT planning that aligned investment with business priorities.
It's no wonder that institutions like the National Australia Bank (NAB) and others are losing tens of millions of dollars per year from Internet Banking Fraud.
With two-factor authentication in the wind, it's no wonder you see vendors scrambling for time with bankers CIO's to sway their thinking on the best approach to this business issue.
Bank of America has already adopted the PassMark technology. Sitekey is one anti-phishing method that associates an image with an online ID to give the consumer a higher level of assurance that they are logging into the correct site. E-Trade has chosen RSA's technology for their site.
Putting an end to account hijacking is a primary concern of the US FDIC and they welcome your input.
What was obvious from the survey was that no matter the size of the institution, both Internet and Vendor Risk are pervasive. With banks with assets over $100Bn, the highest risk was ineffective IT planning that aligned investment with business priorities.
It's no wonder that institutions like the National Australia Bank (NAB) and others are losing tens of millions of dollars per year from Internet Banking Fraud.
NAB is losing about A$1 million a month to Internet banking fraud, according to a confidential internal document acquired by Australian newspaper Herald Sun BusinessDaily.
According to the newspaper article, the document was issued to senior technology staff as part of a drive to improve online security and stem a "tide of losses".
The report warns that Internet banking fraud is on the increase with criminals using "increasingly sophisticated" ways of stealing customers' details. The document also claims fraudsters are tricking Web banking customers into becoming couriers and moving stolen funds out of the country.
With two-factor authentication in the wind, it's no wonder you see vendors scrambling for time with bankers CIO's to sway their thinking on the best approach to this business issue.
According to figures from The Australian Bankers Association (ABA), the country's banks lost A$10 million to online fraud last year.
The ABA said in March that Australian banks would introduce an industry standard for two-factor authentication for verifying online banking customers later this year, although each bank is free to choose its own method of secondary identification.
Bank of America has already adopted the PassMark technology. Sitekey is one anti-phishing method that associates an image with an online ID to give the consumer a higher level of assurance that they are logging into the correct site. E-Trade has chosen RSA's technology for their site.
Putting an end to account hijacking is a primary concern of the US FDIC and they welcome your input.
18 July 2005
Digital Discovery: Electronic Evidence Risk...
In the latest issue of Board Member Magazine, Lisa Ferri reminds us of the importance of the risk of Electronic Evidence.
In the United States, does an employee need the companies permission to seize your computer at the workplace for electronic evidence? In order to be more informed about this procedure and the legal implications in your enterprise, see CCIPS.
Your compliance or legal office can provide you with the guideance for any employee that is suspected of violating company policies with regard to computers crime or theft of confidential information or intellectual property. The question remains, what policy is in existence today and what methods have been utilized for full disclosure to employees that may impact their rights of privacy on the job?
For more help on this subject see: Best Practices for Seizing Electronic Evidence.
Just remember, Forensics and gathering electronic evidence in a criminal matter is in opposition to your recovery. Once a violation has occured, you can make changes, clean up the problem and get back to normal or you can preserve the crime scene for evidence. It's one or the other. If it's not, then that is when you run into problems. Document retention strategies in combination with Forensic Digital Discovery procedures are critical to any organization that cares to mitigate the ongoing risks of electronic evidence.
If the only thing better than learning from your mistakes is learning from the mistakes of others, then directors need to take a lesson from Philip Morris. Last year the tobacco giant was slapped with a $2.75 million fine by a federal court. The offense? Wrongful destruction of e-mails, otherwise known in legal circles as spoliation of evidence. The court found that at least 11 Philip Morris executives “at the highest corporate level” were guilty of violating a court order concerning document retention. In other words, they purged and paid the price.
United States of America v. Philip Morris USA Inc., et al. is a cautionary tale of the problems awaiting companies that are either unaware of or unprepared for the world of electronic evidence. The rules governing that world are evolving at warp speed.
In the United States, does an employee need the companies permission to seize your computer at the workplace for electronic evidence? In order to be more informed about this procedure and the legal implications in your enterprise, see CCIPS.
Warrantless workplace searches occur often in computer cases and raise unusually complicated legal issues. The starting place for such analysis is the Supreme Court's complex decision in O'Connor v. Ortega, 480 U.S. 709 (1987). Under O'Connor, the legality of warrantless workplace searches depends on often-subtle factual distinctions such as whether the workplace is public sector or private sector, whether employment policies exist that authorize a search, and whether the search is work-related.
Your compliance or legal office can provide you with the guideance for any employee that is suspected of violating company policies with regard to computers crime or theft of confidential information or intellectual property. The question remains, what policy is in existence today and what methods have been utilized for full disclosure to employees that may impact their rights of privacy on the job?
For more help on this subject see: Best Practices for Seizing Electronic Evidence.
Just remember, Forensics and gathering electronic evidence in a criminal matter is in opposition to your recovery. Once a violation has occured, you can make changes, clean up the problem and get back to normal or you can preserve the crime scene for evidence. It's one or the other. If it's not, then that is when you run into problems. Document retention strategies in combination with Forensic Digital Discovery procedures are critical to any organization that cares to mitigate the ongoing risks of electronic evidence.
15 July 2005
External Risk: The Economics of Catastrophe...
The risk of an active 2005 hurricane season is raising the stakes for business in the energy and financial services sectors at an accelerated pace.
Hurricanes are threatening our oil production in the Gulf of Mexico and crude is trading at $US61.
Insurers and other firms in the financial services sector are at risk if regulators don't allow them to increase premiums. Business could be impacted by those higher premiums or the risk of losing coverage all together.
The risk of loss from external events such as these are hard to predict, yet easier to prepare for each year. Predictive models are getting better and the largest and most savvy insurers are using them to their benefit. AIR's Catastrophe Models are a prime example.
Hurricanes are threatening our oil production in the Gulf of Mexico and crude is trading at $US61.
Oil prices rose for a second day, after the US Government said more than half of Gulf of Mexico output remained shut down following Hurricane Dennis. A new storm is approaching the region, raising concern about supply shortages.
Production in the Gulf was 43 per cent of normal at noon New York time yesterday, compared with 4 per cent the previous day, figures from the US Minerals Management Service showed. Tropical storm Emily formed in the Caribbean and next week might reach the gulf, the source of a third of US oil output.
"Now there are worries about this tropical storm, Emily, they're getting all these big storms really quite early in the season," said David Thurtell, commodity strategist at Commonwealth Bank.
"If you get these continued disruptions, then second-half production is going to disappoint."
Insurers and other firms in the financial services sector are at risk if regulators don't allow them to increase premiums. Business could be impacted by those higher premiums or the risk of losing coverage all together.
Last year was difficult for insurers as four major hurricanes in the Southeast triggered about $23 billion in payouts.
In Florida, where insurers paid the most damages from last year's hurricanes, companies have so far had little success in getting regulators to allow higher premium prices.
But another year of hurricanes on par with 2004 could give insurers more leverage in applying for higher premiums, said Mike Paisan, an insurance analyst at Legg Mason in New York.
"If Florida regulators do not allow higher prices, major insurers could threaten to withdraw. Having fewer insurance companies there would definitely raise prices," Paisan said.
The risk of loss from external events such as these are hard to predict, yet easier to prepare for each year. Predictive models are getting better and the largest and most savvy insurers are using them to their benefit. AIR's Catastrophe Models are a prime example.
Lloyd's Loss Modeling Department has licensed AIR Worldwide's catastrophe risk management system to assess the risk from global catastrophes and for the simulation of Realistic Disaster Scenarios (RDS).
RDSs test the ability of the market and individual syndicates to withstand large catastrophes such as a major hurricane hitting the Miami area or a severe earthquake striking downtown Los Angeles. By bringing the AIR models in house, Lloyd's risk management team will have a better understanding of the potential impact of such scenarios. All Lloyd's managing agents are required to complete RDS exercises annually.
14 July 2005
Corporate Governance: Testing for Organizational Disease...
Now that the 25 year sentence has been handed down in the Worldcom corporate goverance and fraud case, it's obvious that prosecuting white collar crime cases is a real challenge.
In the HealthSouth Corp. fraud trial, the jury made a different decision and the CEO was acquited.
What the Board of Director's and Executive Management do know is that it's time to make some more changes in Corporate Governance initiatives. The relationships with the shareholders is bound to continue to be a challenge for any management team and they realize that they must be creating a culture full of ethics and risk management principles.
At the end of the day it comes down to the evidence presented to the jury. And the evidence is typically a presentation of information utilizing forensic methods of discovery. Dr. Thomas R. O'Connor at NCWC has some interesting background on the subject of Investigative Methods in Forensic Accounting.
As we move forward on strategies for improving ethics and protecting corporate assets it's clear that educating board members and employees to the symptoms of corporate disease can be a key initiative. That education and awareness program could be the beginning of a whole new era of high performing companies. And for that matter, the programs effectiveness may be the first test of any organizations health.
In the HealthSouth Corp. fraud trial, the jury made a different decision and the CEO was acquited.
Some lawyers suggested white-collar cases are inevitably difficult to present to jurors, whether they live in Birmingham or New York. "It's different from a drug deal or a bank robbery," said Donald Stern, a Boston attorney who was formerly that city's top federal prosecutor. "It's not obvious that a crime has been committed."
What the Board of Director's and Executive Management do know is that it's time to make some more changes in Corporate Governance initiatives. The relationships with the shareholders is bound to continue to be a challenge for any management team and they realize that they must be creating a culture full of ethics and risk management principles.
At the end of the day it comes down to the evidence presented to the jury. And the evidence is typically a presentation of information utilizing forensic methods of discovery. Dr. Thomas R. O'Connor at NCWC has some interesting background on the subject of Investigative Methods in Forensic Accounting.
Signs of financial crime can be initially detected in a variety of ways -- by accident, by whistle-blowing, by auditors, by data mining, by controls and testing, or by the organization's top management requesting an inspection on the basis of mere suspicion. Ideally, fraud detection ought to be recognized as an important responsibility throughout every organization, and every employee in an organization ought to be familiar with the disciplinary consequences for breach of trust as well as failure to report criminal misdeeds against the organization. On a practical level, however, there are steps to the investigative method used in an organizational context that are far from these ideals, and reaching the "breakthrough" point is more an art than science. It is the purpose of this lecture note to outline the investigative methods and procedures used in most cases.
Red Flags of Organizational Behavior:
1. Unrealistic performance compensation packages -- the organization will rely almost exclusively, and to the detriment of employee retention, on executive pay systems linked to the organization's profit margins or share price.
2. Inadequate Board oversight -- there is no real involvement by the Board of Directors, Board appointments are honorariums for the most part, and conflicts of interest as well as nepotism (the second cousin to corruption) are overlooked.
3. Unprofitable offshore operations -- foreign operation facilities that should be closed down are kept barely functioning because this may be where top management fraudsters have used bribes to secure a "safe haven" in the event of need for swift exit.
4. Poor segregation of duties -- the organization does not have sufficient controls on who has budget authority, who can place requisitions, or who can take customer orders, and who settles or reconciles these things when the expenses, invoices, or receipts come in.
5. Poor computer security -- the organization doesn't seem to care about computer security, has slack password controls, hasn't invested in antivirus, firewalls, IDS, logfiles, data warehousing, data mining, or the budget and personnel assigned to IS. Simultaneously, the organization seems over-concerned with minor matters, like whether employees are downloading music, chatting, playing games, or viewing porn.
6. Low morale, high staff turnover, and whistleblowers -- Low morale and staff shortages go hand-in-hand, employees feel overworked and underpaid, frequent turnover seems to occur in key positions, and complaints take the form of whistleblowing.
As we move forward on strategies for improving ethics and protecting corporate assets it's clear that educating board members and employees to the symptoms of corporate disease can be a key initiative. That education and awareness program could be the beginning of a whole new era of high performing companies. And for that matter, the programs effectiveness may be the first test of any organizations health.
Subscribe to:
Posts (Atom)