21 September 2004

Phishing: Preventive strategies

As Symantec has recently been publishing their version of the losses sustained from Phishing, the vendors are busy trying to grab market share. Preventive strategies and tools to thwart Phishing attacks are getting more mainstream as companies respond to the new threats.

All of the social engineering that goes into "Phishing" scams will heavily out maneuver the vendors new tools. The consumer is still running windows without patches and will continue to click on bogus e-mail that looks identical to the ones coming from their bank. ScamBlocker, Phishnet and the rest of them will continue to evolve yet the financial losses will continue.

The Symantec point of view is nothing new. What is interesting is the increase of the number of "bots" and other malware roaming the web:

Symantec also recorded a rise in the detection of bots -- "programs that are covertly installed on a targeted system", according to the company, allowing the hacker to control the computer remotely -- from 2,000 detections per day to more than 30,000. The number peaked at 75,000 in one day.


Symantec said malicious code also increased by more than 4.5 times the number it was in the same period in 2003, equating to over 4,496 new Windows viruses and worms, with most aimed at the Win32 operating system.


Symantec says that phishing costs banks $1.2B. If this is true, you can bet who is paying for all of these operational losses.

20 September 2004

SAS is gaining momentum...

More global companies have selected the operational risk measurement framework from SAS, and they seem to be gaining momentum in the marketplace.

The more than 10,000 loss events include events where losses were incurred due to inadequate or failed internal processes, people or systems as well as external events. These could be anything from failed hardware, forgery, embezzlement, and fraud, to natural events such as earthquakes and floods. When assessing the impact of operational risk scenarios on its business, Royal & SunAlliance will use the SAS data both in the scenario analysis process as well as a benchmark for its own internal data.

17 September 2004

1SecureAudit ORM...

Operational risk management protects and enhances shareholder value. 1SecureAudit enhances shareholder value as a primary benefit of its impact on operational risk management (ORM). Clients utilize baseline knowledge, industry experience and ORM decision support to increase operational mission effectiveness by anticipating threats/hazards and reducing the potential for loss. Change and the speed of change continue to provide a challenging environment for the entire financial and health care services industry.

Some of the key trends include:

1. Innovations in products, technology and distribution channels

2. The effect of globalization and regulatory modernization

3. The convergence of capital markets and the ever evolving pace of competition

The many challenges facing health care and financial institutions today are forcing senior management to address the totality of risks and opportunities in various lines of business and in different markets and regulatory environments. Protection of critical infrastructure assets is a Homeland Security priority.

16 September 2004

Flawed FAA system: Operational Risk Super-Sized

The operational risk associated with process error is a major concern these days. Especially when a human is concerned with the continuity and safety of people flying every major airline in the Southwestern U.S.. According to several reports, an FAA worker did not update a flawed FAA system that handles critical communications between controllers and pilots.

The system that failed — a high-tech touch screen tool that allows air traffic controllers to quickly communicate with planes in transit — shut itself down at the Palmdale communications center shortly after 4:30 p.m. Tuesday after a worker did not complete required monthly maintenance.

Then, the backup system failed to work because technicians had rigged it improperly, FAA officials said.


When it comes to processes and the risks associated with them, a software system flaw such as this can cause tremendous business disruption at the minimum. It's the cost of human lives that gets situations like this as much news coverage as it has garnered already. The more interesting news is that these kinds of operational incidents occur in business daily and the public will never know about it. Unless they are on the magnitude of this event. ATM's shelling out too much money. Patients being prescribed the wrong drugs. Both are errors in the systems or processes associated with running a service business. What is more alarming and still yet on the brink of discovery is how much our rush to fix Y2K problems rushed our programmers in making shortcuts, eliminating proper security code at the application level and getting the applications online at the sacrifice of good quality assurance.

Don't blame the FAA. Blame the company they hired to develop the system at the lowest bid, and the highest cost to people who are exposed to it.

15 September 2004

Risk Mitigation Training in Prep for Ivan

Hey New Orleans, got Hurricane Ivan yet? RMS predicts from $4 to $10B in damages.

Business continuity plans are being exercised. People are evacuating. Now we wait for the storm surge that could put New Orleans under 20 feet of water. What about the cities North who will no doubt be experiencing tornados and other severe weather as Ivan roars across Alabama?

Hopefully the owners of buildings and critical infrastructures have provided their employees and tenants with risk mitigation training. For an example of what WTG Properties in Washington, DC has done on this very topic, see this client case. Teaming up with Operational Risk Management firm, 1SecureAudit, they provided their tenants and staff with the training, tools and resources they needed to survive a catastrophic event.

Let's just hope the owners in New Orleans have done the same to prepare for Ivan.

14 September 2004

Cyber Extortion Study is complete...

The Heinz School at Carnigie Mellon has finished it's survey on Cyber Extortion and some of it's findings are surprising.

Companies are still slow to implement preventive strategies and only 21% of the companies surveyed have formal education programs for their employees. Even more shocking is that 63% have not performed a security assessment in the last six months.

Although cognizant of the most commonly perceived security threats and countermeasures, (The most common types of attacks and misuse as reported by the participants of the CSI/FBI survey were virus attacks, unauthorized access and web use by insiders, and denial of service attacks. Ibid) businesses relying on IT often do not address one of the most complex and potentially damaging exposures: Cyber-extortion.

This research has two goals: First, generate the first academically available statistics on the advent and threat of cyber extortion against small and medium sized businesses. Second, create immediately usable guidelines for organizations that may be "at risk" to extortion. The guidelines will describe the most common methods extortionists use against their targets, how to ready your information infrastructures against this, and what to do if you become a victim of extortion - regardless if you plan to work with law enforcement or not.

13 September 2004

Malicious Code: Managed Mail Protection Emerges

When the image contains text you might be vulnerable to a new scam online. This new advertising headline may soon be in vogue, Malicious Code: Managed Mail Protection Emerges.

In a new wave of phishing variants, companies like Citibank are constantly making changes in their systems to adapt to the new online threats from new malicious strategies.

"We continually modify our systems to enhance safeguards for our customers," said a spokesperson for Citibank, a unit of Citigroup Inc., in New York. "It is also important that consumers be aware of these issues and act appropriately."

While individual filtering tools from large vendors have proved largely powerless against the new threat, some security vendors are preparing help in the managed e-mail model as well.

McAfee Inc., of Santa Clara, Calif., will launch a Managed Mail Protection service for small and midsize businesses. The service, which may be extended to large enterprises in the coming months, comprises anti-spam, anti-virus and content filtering. All inbound e-mail goes through McAfee servers before it hits the customer network.

11 September 2004

Third Anniversary of 9/11

As We Mark The Third Anniversary of 9/11 one can imagine how the world will be in the next three years. A globe pock marked by terrorist incidents. Russia, Malaysia are of recent headlines. How soon will the terror strike the US again? Many say before the election and only then will we have what we need to reinforce what work has already been accomplished, and will never be completed.

The people of the free world know in their hearts that the struggles of real estate and religion will continue for decades to come. Only those who are proactive, preventive and aware of the continuously changing threat will survive.

God bless us all.

08 September 2004

PWC Study on Risk...

PricewaterhouseCoopers has found the Ten Attributes they say leads to a world class risk management organization:

• Pay equal attention to quantifiable and unquantifiable risks
• Identify, report and quantify all possible risks
• Let an awareness of risk pervade the enterprise
• Make risk management everybody’s responsibility
• Avoid products and businesses the enterprise does not understand
• Accept that uncertainty exists
• Monitor your risk mangers
• Good risk management delivers value
• Define and enshrine your company’s risk culture.


They also say that reputational risk is the greatest threat in financial institutions. Phil Rivett, global leader, banking/capital markets group, PricewaterhouseCoopers said: “Financial institutions have made significant strides since our last risk management survey two years ago, but our latest findings have revealed that too many organisations are still concentrating on calculating market and credit risk to a further order of accuracy and too few on understanding the totality of the risks they face in order to give themselves a competitive advantage.

07 September 2004

The Wheel of Misfortune

What are some classic cases of operational risk out of control? Check out The Wheel of Misfortune.

One of the best ways to develop risk awareness is to learn from others' mistakes. The Wheel of Misfortune contains instructive case studies of a dozen infamous financial disasters.

Each case study includes a description of the event, an analysis of what happened and exactly what went wrong, and the risk management lessons to be learned.


Your organization could do the same by creating a learning tool for existing and new employees. After all, the best way to keep awareness at a high level is to consistently place reminders about lessons learned.

03 September 2004

WPA2 standard reduces risk...

The new wireless networks in your enterprise are now becoming more secure as a result of the WPA2 standard,says the Wi-Fi Alliance.

WPA2 is ideally suited for enterprises in both the public and private sectors," said Frank Hanzlik, Wi-Fi Alliance managing director. "Products that are certified for WPA2 give IT managers the assurance that the technology meets interoperability standards and in turn helps them manage support and deployment costs."

The 802.11i standard has components of WPA2 already embedded in it and should make the enterprise Wi-Fi solutions finally worth considering on a more enterprise scale. Those organizations who have already deployed previous standards are wide open to vulnerabilities and interception of their sensitive data transmissions.

02 September 2004

The summer of 2004...

The Terrorism Risk Insurance business is on the rise according to a recent Marsh Report on Terrorism Risk. The percentage of policy holders who buy terror coverage increased from 44% to 46% by midyear.

In November 2002, President Bush signed the Terrorism Risk Insurance Act (TRIA) into law. TRIA made it illegal for providers of property & casualty (P&C) insurance to exclude terrorism coverage in their policies. Still, the act did not specify how much insurers could charge for the coverage, and as a result, the price for TRIA coverage varied greatly.

The summer of 2004 will continue to be a prime window for the “What if” discussions of potential terrorist attacks on United States assets located domestically or abroad. It is important to remember several key items as we move into more proactive, preventive and preparedness modes within our global organizations and U.S. based business communities.

The soft targets for these catastrophic plans by our terrorist enemies will continue to focus on the places, events and structures that will provide the most impact, both in loss of life and the long-term economic impact. Based on analysis by RMS in their latest Catastrophe, Injury and Insurance study, the study looks at those cities with the highest density of population at 2:00PM. In the RMS report, New York, Chicago and Washington DC are the top three cities in the US for potential impact of a terrorist incident. San Francisco, Boston, Philadelphia and Los Angeles are next in the line up of populations that are the highest density within several miles of the city center.

The five factors for anti-terrorism threat analysis are Existence, Capability, History, Intention and Targeting. Further defined as follows:

1. Who is hostile to the asset?
2. What tools/weapons have been used in carrying out past attacks?
3. What has the threat element done in the past and how many times?
4. What does the potential threat element or aggressor hope to achieve?
5. Do we know if an aggressor is performing surveillance on our building / asset?

When answering these questions for your particular building, city, business park or community you should keep in mind the goal of our attackers. They want to do the most harm to the most number of people for the longest period of time. While we may not be able to totally prevent a planned incident from happening, we can reduce the impact on our personnel, property and business operations.

01 September 2004

Frances Slams Allstate's stock

Frances Slams Allstate's stock upon fears that the hurricane is going to make landfall any day in Florida.

Shares of Allstate Corp., Ace Ltd. and other insurers fell today as Hurricane Frances approached the Florida coast, threatening to become the second storm packing 140- mile-per-hour winds to hit the state in three weeks.

The impact to the bottom line goes far beyond just the claims by it's customers. In this case, the institutional investors are taking a profit after a 50% increase over the past 18 months.

The other possibility is that they may already be "stretched" after hurricane Charley. Should Frances make landfall in Florida with its current wind strength, it would mark the first time since 1915 that two storms of that magnitude hit the U.S. in the same year, the Miami- based hurricane center's data show.

30 August 2004

Corporations can learn ORM from the US Navy

What is it that corporate management and the US Navy have in common? Corporations can learn ORM from the US Navy principles to earn top safety honors and contribute to mission success.

This is just one example of how the US miltary is using the effectiveness of Operational Risk Management to mitigate the risk of hazards on the job and to ensure the safety of fellow team mates on the job.

“It was evident the first time I came on board and saw the crew’s attention to detail and dedication to their work,” said Capt. Mike D. Budney, commanding officer, Emory S. Land. “But it’s remarkable to note that with the tremendous day-to-day operations, no serious safety mishaps occurred.”

“With a crew this size and the never-ending upkeep that takes place, safety is and will always be our number one priority,” Budney added. “Our Sailors know that and are living proof. I am extremely proud of them!”

While safety is paramount on every ship and submarine in the fleet, these submariners know that safety is not about winning awards, it’s about managing risk to avoid injuries and possible loss of life.

27 August 2004

The next very long war....Cyber Terror

"The Internet is the bold new frontier of crime, but we're the new sheriff in town. For cyber criminals who operate out of Los Angeles or any location around the globe, this posse will bring you to justice," said United States Attorney Debra Wang.

The Six Cyber Terrorists arrested by the US DOJ have set the stage for a long and evasive war. The hope is that the private sector will begin to share more information with the feds to get to the big fish, but this will take time, money and lot's of cooperation with our global partners. China, Korea(s) and the Russian states are the sources of many of our DoS attacks and while we know who they are it is difficult to navigate international laws and jurisdictions.

The good news is that the private sector is working more closely with InfraGard and the 12,000+ members who are helping to protect our critical infrastructures. Money is being allocated to specialized enforcement teams to assist the US Attorney's in doing their jobs more effectively.

It's just going to be a very long war that has to be fought every single day.

25 August 2004

Share Price: A Factor of Corporate Governance?

Corporate Governance is good for the bottom line but even Google hasn't found this out...yet. Their recent coporate governance quotient is 0.2 out of 100.

But, as Ric Marshall, chief analyst for the Corporate Library, notes, it's not necessarily a bad thing. "There is this tendency to dumb things down by making all boards look the same,'' Marshall told the San Francisco Chronicle. "By doing something different and unconventional -- in terms of how the IPO has gone, the multiple share classes, the makeup of the board -- Google is creating something that is different and unusual. Good corporate governance is the creative interaction between directors on the board. What concerns me is the ethics of the people involved and their ability to be creative."

24 August 2004

Real Estate: Antiterrorism Laws

Is the commercial real esate industry subject to our latest antiterrorism laws?

Executive Order 13224 and the prohibited parties list of the Office of Foreign Assets Control (OFAC) is in effect now. It has civil and criminal penalties.

The Money Laundering Control Act, a criminal statute, is in effect now.

The USA PATRIOT Act/Bank Secrecy Act, which requires certain anti-money laundering compliance activities, will result in regulations directly affecting the real estate industry within a matter of months.


See the viewpoints of two legal eagles from Holland & Knight in the DC area on this very topic.

18 August 2004

H.R. 1731 Identity Theft Law

The identity theft penalty enhancement act expands the capabilities of the Justice Department to investigate I.D. theft. See the synopsis here at CSO Online. I.D. theft is one way for the terrorists to keep themselves hidden in the US for a long period of time. It will also help in credit card fraud cases.

17 August 2004

Increased Regulatory Scrutiny for Bank INFOSEC

Banks INFOSEC departments have increasing roles in audits. The Information Security departments must have a systematic program for managing risk in their day to day operations as regulatory requirements for business overlap.

Comprehensive risk management programs are being broadened to encompass operational risk in many banking institutions. This is due to the increasing prevalence of legislation such as Gramm-Leach-Bliley (GLBA) and even sections of Sarbanes-Oxley. The convergence of information security and business is finally making it apparent that the two are very much inseparable.

13 August 2004

Survey identifies main stumbling blocks to successful operational risk management

Survey identifies main stumbling blocks to successful operational risk management:

Difficulties in collating clean data and poor awareness among staff are the major obstacles to effective operational risk management, according to a recent survey by Risk Waters Group and SAS.

The survey of more than 250 financial institutions and regulators identified managing data quality as the number one issue, with respondents reporting difficulties in collating sufficient volumes of historical data and in ensuring reliable data. The second most pressing issue was the poor overall awareness of operational risk issues by staff, due largely to lack of clear education programs in operational risk, lack of communication and limited knowledge sharing.

Regulations such as Basel II place a growing emphasis on operational risk management within financial institutions. Banks are compelled to gather data that they do not currently collect; they are also required to bring that data together from a host of disparate systems into one pool for analysis.

'The two key barriers to financial institutions achieving success relate to basic issues such as data quality and awareness amongst staff. A basic lack of awareness amongst staff often results in insufficient data being collected,' said Peyman Mestchian, head of the risk management practice, SAS UK.

'Employees may not always report losses and therefore impact the accuracy of data available. They need to be educated to a level where they are providing consistent information therefore improving data accuracy. Organisations can use the most sophisticated analytical tools in the world, however if they are not working with comprehensive, real-world data they will miss the real dangers. Inconsistent and inaccurate data will only provide problems and create disagreements. These issues need to be addressed as a matter of some urgency, particularly with latest draft of the New Basel Accord (Basel II) published in June,' continued Mestchian.

To comply with new regulations, organisations require systems that are both scalable and flexible. Systems need to combine qualitative and quantitative data and be able to link external data with internal data. Yet for many having the correct systems in place is still a major challenge.

Survey respondents ranked IT systems failure as the main source of operational risk. An area of growing importance was identified as customer relationship risk, with regulatory and compliance issues (including taxation) third."

11 August 2004

Summer in the City: Unconventional Insurance and Olympian Security in Age of Terrorism Risk

Summer in the City: Unconventional Insurance and Olympian Security in Age of Terrorism Risk:

By Andrew G. Simpson, Jr.

A little more than a year ago, Britain's Prince William celebrated his 21st birthday with a costume party at Windsor Castle. While William was addressing the partying crowd, a stranger wearing a black beard, white turban and pink dress and looking a lot like Osama bin Laden bounded onto the stage, grabbed the microphone, spoke to the crowd and then planted a kiss on Prince William's cheek.

Despite the fact that the Osama look-alike was a comedian, few thought it a laughing matter. If the intruder had been a suicide bomber he could have killed all the senior members of the royal family who were onstage with William. British security forces were promptly taken to task for allowing the stranger to get so close. Immediate steps were taken to beef up security surrounding the royal family.

Summer Security
This summer, while the world is watching the Democratic National Convention (DNC) in Boston, the Republican National Convention (RNC) in New York City and the 2004 Olympic Games in Athens, security forces will be on full alert to prevent breaches like the one that concerned British security a year ago. In Boston, New York and Athens, officials maintain that every precaution is being taken to protect the participants and properties at these events from a close encounter with terrorism."

10 August 2004

A Radical Leap in Trust...A Security Lesson

The other day I received a package in the mail from Fast Company Magazine. I opened the brown padded envelope with the "Security Radar" that this looked like a questionable package. You know, the kind that they warn you about these days. The label looks like it was created by a 4th grader and the package is about a half inch thick and weighs in at about a pound and a half. Could this be the work of a clever "Social Engineer" who knows my modus operandi?

So I held my breath and opened it with great anticipation and fear at the same time. I had no idea it was coming. It's contents was not surprising. A book. A note. And a business card. The card was that of Heath Row, Fast Company Editorial and Community Director. Former Social Capitalist before the uprising. The Book was entitled The Radical Leap, by Steve Farber. The note from the publisher offering 40% off the retail price with orders of ten or more.

The real radical leap on this day was my faith in the label Fast Company. My vulnerability had been exploited by someone known to me. My trust in FC and the brand prompted me to forget everything I have been taught about suspicious packages like this one. Now I'm practicing LEAP every day. Cultivate Love. Generate Energy. Inspire Audacity, and Provide Proof. The lesson here is simple. A radical leap in trust can sometimes blind us from clear thinking. Be careful out there.

06 August 2004

Dangerous Waters

Dangerous Waters: "

Distributed denial-of-service attacks may reshape the way courts evaluate liability for network security breaches.

BY WILLIAM COOK

Distributed denial-of-service (DDOS) attacks—the creation of a hostile computer network used to remotely shut down another network or website—continue to plague the Internet. In the past two years the Internet has experienced a 2,000 percent increase in worm-driven DDOS attacks. Some e-commerce websites have been completely shut down by the attacks and have reported as much as $250,000 in lost sales per half hour that they were down. But the damage doesn't stop there. The users of a victimized system can also suffer significant reputational loss from being unable to conduct business.

However, the legal response to DDOS attacks has been mixed. In the U.S. legal system, civil liability can arise from contract law, tort law or regulation. If one party breaches its contractual obligations, the law provides a remedy to the aggrieved party. Contract law, however, often fails to cover damage to third parties. Suppose a hacker breaks into Company A's inadequately secured network and then uses that network to attack Company B. The attack against Company B disables its networks, causing it to fail to deliver promised services to its customers. Although Company B has no contractual relationship with Company A, can B sue A for losses?

From a tort standpoint, many legal scholars, major law firms and a National Research Council Committee assert that the downstream victim can bring civil action for negligence against the upstream systems that were used as part of the DDOS attack. Reasoning that civil law intends to deter undesirable or wrongful conduct and to compensate those harmed by such conduct, legal theory posits that victims should be allowed to recover losses from third parties that were negligent if that negligence was the direct cause of the loss. In the Internet environment, negligent third parties may be the only source of loss recovery, since criminal law offers no compensation to the victim if the computer criminal cannot be identified. Furthermore, establishing the legal precedent to impose civil damages on a third party, such as a service provider that is proven to be negligent, could motivate companies to invest the necessary resources in improving security.

04 August 2004

IT Spending for Compliance: From SOX 404 to Comprehensive Compliance

IT Spending for Compliance: From SOX 404 to Comprehensive Compliance:

Financial Insights estimates that North American financial institutions spent over $100 million on enterprise performance management solutions in the U.S. and Canada in 2003. This number will grow to $174 million in 2004 and will reach $450 million 2008.

Beyond Sarbanes-Oxley, Comprehensive Compliance

Given the similarities in the applications and infrastructure components required to comply with new regulations impacting financial services firms, including the PATRIOT Act and Basel II, we estimate that a key long-term trend in the market for compliance solutions will be application and infrastructure integration.

On the infrastructure side, we foresee that the data infrastructure supporting compliance activities will become more and more integrated through data warehouses or through applications that can connect to disparate sources. On the application side, we are already seeing firms invest in solutions that meet both anti-money laundering requirements prescribed by the PATRIOT Act as well as SEC and Sarbanes-Oxley-related requirements to monitor for internal fraud and for compliance breaches with securities laws. Investments in such AML/Surveillance solutions have been particularly strong among securities firms.

Specific to Sarbanes-Oxley compliance, we estimate that SOX 404 solutions will become more and more integrated with enterprise performance management applications to facilitate the regulatory reporting process.

Integration will take time. Technologically, it is already here today and IT vendors have been ready with partnerships and attractive solutions. Culturally and organizationally, it is not. Financial services firms have much internal work to do before they can begin to combine disparate compliance processes. Until this time, investments in IT for compliance will continue to remain focused on specific regulations. "

03 August 2004

Recovery Point provides comprehensive, availability end-user hotsite recovery services

Recovery Point

Recovery Point Systems provides comprehensive, availability end-user hotsite recovery services for mission critical, business continuity conscious clients to implement disaster recovery plans including server mirroring, serverhosting, electronic vaulting, workgroup recovery, off-site storage and co-location.

"The replacement facilities on which you stake your organization's ability to survive during a crisis must function smoothly and reliably. We've built redundancy and durability into every critical component of the site so you can rely on our high availability services every day.

* Secure facility with CCTV, access control and 365-day staffing 100 acoustical workspaces with locking storage, expandable to 200
* Owner-occupied site with private parking
* Convenient to major highway, rail and air transportation
* All weather, voice/data 'hitching post' for connectivity to mobile technologies
* Dual diverse fiber feeds via SONET self-healing ring to redundant central offices
* Full UPS support for entire recovery center
* Secure server and telecommunications facilities
* Redundant generator power, ATS and seven-day fuel supply
* Redundant HVAC services
* Full truck loading facilities to support client re-supply during occupancy
* Conference room with satellite TV feed and video-conferencing
* kitchenette, strategy room and six semi-private offices
* UL master building label for lightning protection

Recovery Point Systems is an affiliate of First Federal Corporation, the Baltimore-Washington DC region's leading provider of secure, off-site data storage services for over 20 years. We have the experience, the staff and the resources to meet your recovery requirements in today's complex environment."

02 August 2004

Bush Backs Creating U.S. Antiterrorism Chief

Bush Backs Creating U.S. Antiterrorism Chief

By Frank Csongos

The United States is planning to undertake new measures to fight the Al-Qaeda network and its allies.

Washington, 2 August 2004 (RFE/RL) -- U.S. President George W. Bush has endorsed creating the position of a national intelligence director to oversea the United States' domestic- and foreign-intelligence operations in combating terrorism.

Bush, speaking at the White House today, said the new intelligence chief would be appointed by the president and subject to confirmation by the U.S. Senate.

'The national intelligence director will serve as the president's principal intelligence adviser and will oversee and coordinate the foreign and domestic activities of the intelligence community,' Bush said.

The president said the reorganization of U.S. intelligence services is aimed at creating a better integrated, thoroughly united, and more efficient antiterrorism operation.

The new post was among the recommendations of the official commission that investigated lapses in intelligence that left the United States vulnerable to the 11 September 2001 terrorist attacks.
'The best way to protect the American homeland is to stay on the offense.' -- Bush

'Oversight of intelligence and of...homeland security must be restructured and made more effective,' Bush said. 'There are too many committees with overlapping jurisdiction, which wastes time and makes it difficult for meaningful oversight and reform.'

Bush also adopted another key recommendation of the 9-11 commission -- that of creating a National Counterterrorism Center.

'This new center will build on the analytical work -- the really good analytical work -- of the Terrorist Threat Integration Center and will become our government's knowledge bank for information about known and suspected terrorists,' Bush said. 'The new center will coordinate and monitor counterterrorism plans and activities of all government agencies and departments.'

Leaders of the bipartisan 9-11 commission have insisted that the center and the position of national-intelligence director be placed in the executive office of the president. But Bush said he wants them to be set up outside the White House.

The president said the director and the center should be a 'stand- alone group' to better coordinate.

Bush also dismissed critics who said the war on Iraq has detracted U.S. efforts to fight terrorism.

'The best way to protect the American homeland is to stay on the offense. It is a ridiculous notion to assert that because the United States is on the offense, more people want to hurt us,' Bush said.

Under the reorganization, the Central Intelligence Agency would be managed by a separate director. The national-intelligence director would assume greater responsibility for leading and coordinating intelligence operations both inside and outside the United States.

The president's endorsement for the new post came after U.S. law enforcement authorities strengthened security at financial institutions in New York City; Washington, D.C.; and Newark, New Jersey, following what the U.S. government called extraordinary specific terror threats."

01 August 2004

Secretary Ridge Announces Threat Level Code Orange for Financial Sector in New York City, Northern New Jersey and Washington, D.C.

DHS | Department of Homeland Security | DHS Home Page:


August 1, 2004 - Good afternoon.  President Bush has told you, and I have told you, when we have specific credible information, we will share it.  

This afternoon, we do have new and unusually specific information about where al Qaida would like to attack.  As a result, today, the United States Government is raising the threat level to Code Orange for the financial services sector in New York City, Northern New Jersey and Washington, D.C.  

Since September 11th, 2001, leaders of our commercial financial institutions have demonstrated exceptional leadership in improving its security. However, in light of new intelligence information, we have made the decision to raise the threat level for this sector, in these communities, to bring protective resources to their highest capacity.  This will allow us to increase protection in and around those buildings that require it and also raise awareness for employees, residents, customers and visitors.  We know from experience that increased physical protection and added vigilance from citizens can thwart a terrorist attack. And that is our goal.

This is the first time we have chosen to use the Homeland Security Advisory System in such a targeted way. Compared to previous threat reporting, these intelligence reports have provided a level of detail that is very specific. The quality of this intelligence, based on multiple reporting streams in multiple locations, is rarely seen and is alarming in both the amount and specificity of the information.

While we are providing you with this immediate information, we will continue to update you as the situation unfolds.  As of now, this is what we know:  reports indicate that al Qaida is targeting several specific buildings, including the International Monetary Fund and World Bank in D.C.; Prudential Financial in Northern New Jersey; and Citigroup buildings and the New York Stock Exchange in New York.  Let me assure you, actions to further strengthen security around these buildings are already underway.  Additionally, we’re concerned about targets beyond these and are working to get more information."

30 July 2004

Terrorism Risk Management

Over the past few months’ 1SecureAudit LLC has conducted an independent online poll to determine the areas of Operational Risk that are the largest focus of organizations right now. The results are as follows:

People - 22%
Processes - 31%
Systems - 28%
External Events - 19%


Processes (31%) and Systems (28%) are the two areas that CxO’s have the most control over and are the two main areas that they are working on right now to help mitigate risks.

This means that they have transferred or accepted the risk in the other two areas of Operational Risk Management, People (22%) and External events (19%). The key mechanism for the transfer of risk of people (fraud) and external events (natural disaster) is through insurance. There is a tremendous amount of existing data that the insurance industry understands and therefore they can create the economical products to effectively serve the interests of the corporate organization to hedge these areas of risk, except one. Terrorism Risk.

Terrorism Risk Management

Terrorism Risk includes the risk from attackers both internal and external to the organization. These attackers are using conventional (incendiary explosive devices) and unconventional (digital worms) methods to disrupt the operations and economic well being of corporate organizations, the real estate finance industry and of our critical infrastructures.

The process and systems for managing Terrorism Risk are rapidly changing as the commercial real estate finance and building owners strive to establish new standards. Critical Infrastructure Protection is now a national priority. The key catalysts for change could further motivate infrastructure owners to implement new risk reduction programs and measures.

Some of the key catalysts for change are:

· Insurance – those institutions that are sharing risks that a building owner faces.

· Finance – banks, REIT’s (Real Estate Investment Trusts), and others such as pension funds that provide the capital for investments in commercial infrastructure.

· Regulation – Federal, State and Local jurisdictions that regulate building design, construction and operations.


Overall Terrorism Risk reduction begins with these key catalysts in concert with owners of critical infrastructure, whether that is a corporate office building, a hospital, subway, or a hotel. These soft targets are where the risk management decision-making is already taking new directions.

In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen. Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future. First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.

The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures. The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure. In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles. These need to be exercised on a continuous timetable with extensive documentation, training and reporting.

29 July 2004

Sarbanes-Oxley Readiness...

Following are sample questions from the Sections 302 and 404 Readiness Assessment by Deloitte.

Has your company:

1. Adopted a formal implementation plan (including a timetable) to address the requirements of Sections 302 and 404 of Sarbanes-Oxley?

2. Established communication channels among management, the board of directors, and the audit committee to ensure a timely discussion of the status and issues related to Sections 302 and 404 of Sarbanes-Oxley?

3. Incorporated steps within its implementation plan to address all five elements (control environment, risk assessment, control activities, information and communication and monitoring) of the COSO internal control framework?

4. Established an enterprise-wide control and risk management program in which controls and procedures are documented and continually reevaluated in response to major process or organizational changes?

28 July 2004

Top 10 Most Effective Cybercrime Policies

Top 10 Most Effective Cybercrime Policies

CSO recently partnered with Carnegie Mellon's CERT Coordination Center and the U.S. Secret Service to survey the cybercrime landscape. Here are the methods that our 500 respondents identified as the most effective to fight e-crime.

1. Engage in internal employee monitoring.

2. Have a written inappropriate-use policy.

3. Require employees and contractors to sign acceptable-use policies.

4. Monitor Internet connections.

5. Require internal reporting to management of insider misuse and abuse.

6. Host employee education and awareness programs.

7. Develop a corporate security policy.

8. Conduct new employee security training.

9. Do periodic risk assessments.

10. Conduct regular security audits."

27 July 2004

64% of Companies Have Dedicated Regulatory Compliance Budgets

64% of Companies Have Dedicated Regulatory Compliance Budgets

By: SmartPros Editorial Staff

-- Sixty-four percent of companies currently have budgets dedicated to financial regulatory compliance, with the average budget projected to be $7.2 million in 2005. Among those companies without a current budget, more than half (54 percent) plan to allocate money for compliance initiatives within the next 12 months.

META Group Inc. released its study, 'Organizational Trends in Sarbanes-Oxley and Regulatory Compliance Issues,' which found that companies are dispersing compliance-related spending across a wide range of financial and accounting regulations:

* 56 percent of companies surveyed have allocated resources for compliance with Sarbanes-Oxley (SOX) and the Health Insurance Portability and Accountability Act (HIPAA) regulations

* 48 percent are reserving a portion of compliance spending for USA PATRIOT Act-related initiatives.

* 35 percent have earmarked money for compliance with Financial Modernization Act and 33 percent for Basel II requirements.

* 28 percent have allocated budget for SEC Rule 17a-4, and 27 percent for International Accounting Standards initiatives.

Despite the broad range of funding, the study found one dominant compliance driver: 'SOX has had a significant impact on how regulatory compliance has been viewed and managed,' said Jon Van Decker, vice president with META Group's Enterprise Application Strategies. 'What makes SOX different is the heightened level of security around non-compliance. CIOs as well as other officers of a company can be liable for inaccurate information or insufficient controls, with the possibility of fines or prison sentences.'

Although the severity of non-compliance has elevated SOX management to the highest executive levels within organizations, the study found that most compliance stakeholders are unclear as to where they fit in the compliance plan, relative to their peers. Moreover, those executives presumed to be in charge of compliance may be taking a much more limited role than previously thought.

Less than one-third of study respondents indicated reliance on the CFO as the primary role within compliance. In addition, only 16 percent of companies have tasked the CFO with supervision of the chief compliance officer (CCO) position. Similarly, while many compliance solutions are initially perceived as services solutions, the CIO is often not involved in the final decision-making stages. As a result, only 14 percent of CCOs report into the CIO position."

26 July 2004

eEye Digital Security - Vulnerability Management Solutions

eEye Digital Security - Vulnerability Management Solutions: "

Why Does the Industry Need Blink?

Unknown vulnerabilities represent the greatest threat to enterprises’ digital assets. Contrary to popular belief, many hackers do not wish for worms to be released, as this galvanizes enterprises to patch machines that could otherwise be used as doors into a network. This will continue to be a growing issue as enterprises become more successful at proactive vulnerability assessment and remediation – hackers will focus on ways to compromise systems in a “zero-day” fashion. Since Blink operates by stopping the activity that results from an attack rather than the signature of the attack itself, this technology is able to stop even unknown vulnerabilities from being exploited.

Additionally, as the window continues to shrink between the time vulnerabilities are announced and when enterprises are able to patch their systems, the costs incurred by companies through patch management will continue to grow. A company with thousands of machines in its network can expect to experience millions of dollars in lost productivity and business disruption when patching is immediately required. As a result, enterprises need the ability to defer patching to scheduled maintenance cycles, as well as intermediate protection from attacks that intend to leverage the unpatched vulnerability. By protecting individual machines, Blink allows corporations to patch their systems on a less disruptive, more cost-effective schedule.

Likewise, although the vast majority of enterprises have network-level security elements in place (e.g., firewalls, IDS/IPS, etc.), many remote workers, such as mobile workers, teleworkers, contractors and others, unintentionally acquire vulnerabilities “in the wild” and introduce these vulnerabilities to the corporate network once they reconnect. This internal attack vector is becoming a frequent cause of worms and virus outbreaks. Blink provides the means to isolate and evaluate each machine prior to its reconnection to the network. If any of Blink’s security mechanisms detect unusual behavior, the machine is isolated via its application and system-level firewalls, and the attack is prevented.

Blink also helps enterprises enforce policy compliance by constantly auditing corporate security standard configurations to reduce the risk of compromise. Finally, traditional security measures offer no defense against socially engineered security threats that attack from inside the organization. Even if a user unwittingly downloads a virus or worm, Blink is able to recognize the harmful activity, shut down the offending application, and isolate the machine from the rest of the network.

23 July 2004

Experts laud U.S. program to counter bioterror attack

Experts laud U.S. program to counter bioterror attack:

Matthew B. Stannard, Chronicle Staff

San Diego -- Fast action and the right medicines can save tens of thousands of lives in the event of a bioterror attack, a Stanford expert told a bioweapons conference just hours after President Bush announced Project BioShield, a $5.6 billion program to develop stockpiles of vaccines and antidotes for chemical and biological weapons.

'The most important thing for saving people is ... treating people before they become symptomatic,' said Dean Wilkening, director of science at Stanford's Center for International Security and Cooperation.

Bioweapons, which require days or weeks of incubation to become deadly, provide a crucial window of opportunity to treat those at risk, Wilkening said at a program Wednesday on public policy and biological threats for the Institute on Global Conflict and Cooperation at UC San Diego.

'You have to detect the event and get medicine into people's mouths within this window of opportunity,' he said. 'If enough people become symptomatic ... you've lost the game.'

In the case of anthrax, for example, which has a 2- to 4-day incubation period, if exposed people are treated before that window closes, as many as 95 percent may be saved, Wilkening estimated. But if it takes two weeks to procure the antidote, that figure could drop to 20 percent.

Project BioShield, which Bush signed into law on Wednesday, provides incentives to the drug industry to research and develop bioterror countermeasures, speeds up the approval process for antidotes and lets the government distribute treatments in an emergency, even before they receive Food and Drug Administration approval.

In signing the legislation, Bush said, 'We refuse to remain idle while modern technology might be turned against us,' and promised to enlist American science to 'confront the greatest danger of our time.' He noted that many of the legislators who passed it had 'experienced bioterror firsthand when anthrax and ricin were found on Capitol Hill.''"

22 July 2004

Phishing Attacks Linked To Organized Crime

Bank Systems & Technology > Phishing Attacks Linked To Organized Crime:

Michael Cohn, Security Pipeline

'There's a lot of activity in the former Soviet bloc, the Eastern bloc, Latvia and Ukraine,' says John Curran, supervisory special agent with the Federal Bureau of Investigation's Internet Crime Complaint Center. 'It definitely looks like there are organized groups.'

Phishing involves sending fraudulent e-mails that appears to be from a legitimate organization -- such as a bank, credit card company, online merchant or Internet service provider -- asking the recipient to divulge personal and financial information like birth dates, Social Security numbers and PIN codes. Unlucky victims are then subject to identity theft, monetary losses and credit card fraud.

While Curran notes that a broad array of criminals appears to be involved in phishing attacks, ranging from teenagers to grandmothers, the FBI is investigating links to organized crime. So far, Curran hasn't seen any indication that crime syndicates with ties to the Mafia are involved.

The U.S. Secret Service has also noted an increase in organized crime involvement in phishing. At AIT Global's Annual InfoSec Meeting at the United Nations in June, Robert Caltabiano, assistant to the special agent in charge in the New York Field Office of the U.S. Secret Service, pointed to the increasing presence of organized crime in phishing attacks. Although Caltabiano recommended that victims first go to local law enforcement for help, he noted, 'With phishing attacks, the information goes global.'"

21 July 2004

Operational Risk Enterprise Architecture (OREA)

The operational risks facing corporate organizations today are found across a wide spectrum:

  • People
  • Processes
  • Systems
  • External Events

Now take this and multiply by the number of business units or lines of business in your organization. Now multiply this by the industry environments you operate in, the countries you operate in and the number of transactions you do on an annual basis. This will give you an idea of all of the places you have the potential to experience a "Loss Event." These add up over the course of a day, week, month and quarter to erode your earnings, performance and competitive position.

The only way to come close to managing such a dynamically changing foe is to first understand how the architecture of your business is interdependent or dependent on various components that make up it's structure. Only then can you begin to understand why certain loss events happen and what environment or characteristics make it more probable that they will occur.

Recently, a new law in the US called the Identity Theft Penalty Enhancement Act was signed by President Bush. What is interesting about this fact is that it wasn't until Phishing victims lost $1.2 Billion to identity theft related fraud between 2003 and 2004 that the banking industry, the FTC and our legislators understood one of the important facts in accelerating the mitigation of these loss events. Make the penalties for getting caught more severe, if they ever get caught. The law also allows the US Sentencing Commission to potentially increase the penalties for employees who steal sensitive information from their employers. Watch for more on this in the months to come.

The speed of change in the connected economy has finally subjected modern criminal organizations to finally be acknowledged that they are a larger target for law enforcement and our justice system. Only through effective operational risk architecture will our institutions be able to detect, deter and defend against the next wave of threats to our people, processes, systems and critical infrastructures.

20 July 2004

Fact Sheet: A Better Prepared America: A Year in Review

DHS | Department of Homeland Security | Fact Sheet: A Better Prepared America: A Year in Review:

Fact Sheet: A Better Prepared America: A Year in Review

“Much like homeland security in general, America’s preparedness requires everyone’s help. That’s why we’ve called you together – to continue building an important partnership – one that will result in an enduring and successful strategy for emergency preparedness across the country.”

– Secretary of Homeland Security Tom Ridge

Today, the Department of Homeland Security, the American Red Cross, the George Washington University Homeland Security Policy Institute and the Council for Excellence in Government brought together leaders in disaster preparedness, and response and recovery as part of the “Public Preparedness – A National Imperative” Symposium. Working together, leaders identified certain challenges and barriers to citizen preparedness as well as specific recommendations that will support the Department of Homeland Security’s National Strategy for all Hazards Preparedness to be released later this year.

Preparedness is the responsibility of every American. At the Department of Homeland Security, we are hard at work creating and implementing preparedness plans; developing procedures and policies that will guide our actions in the event of a terrorist attack; conducting training and exercises to ensure that our first responders possess a necessary level of preparedness; enhancing partnerships with state and local governments, private sector institutions and other organizations; and funding the purchase of much-needed equipment for first responders, states, cities, and towns. These activities, along with an active American community, contribute to a level of national preparedness that is critical to achieving our goal of a better prepared America."

COMMENT:
==================================================
Some enlightened citizen soldiers have already been busy preparing Americans for a spectrum of incidents. For more information see:
Risk Mitigation for the Commercial Real Estate Industry

19 July 2004

Carpe Diem

Carpe Diem:


Yesterday's balkanized approach isn't going to get you where you want to go—or reduce your company's risk. CSOs need to seize the opportunities now to centralize security or pay the price later.

BY ANONYMOUS
CSO Magazine

IT'S BECOMING CLEARER and clearer to me that members of the information security community are enamored with the CSO title and have taken it for their own. And apparently there's nobody to challenge them or to correct this overstatement of responsibilities.

In fact, this very magazine recently ran an article noting the creation of the Global Council of CSOs comprising highly regarded information risk management professionals. In it, Howard Schmidt was asked to comment on the apparent lack of inclusion of physical security in the Council's scope. Schmidt confessed that he's "been forgetting to do that." Unfortunately, such oversight sums up the current landscape where we CSOs are unable even to define the elements of corporate protection within our scope of responsibility. (I'm just as dismayed, by the way, at the prospect of a CSO who owns only physical security and investigations as I am by one who is the sole proprietor of information security.)

Why does this balkanized viewpoint bother me? Because security is fundamentally about risk. The business imperative is sponsored by broader, deeper and more immediate risk, and the consequences potentially include corporate and executive survival. Board members and senior executives can no longer think simplistically about securing their corporation with antivirus software and a physical security program comprising a low-bid guard contract and an access control system. CSOs need a business model that clearly defines the scope of security responsibilities and a job description that includes oversight of securing every aspect of the organization.

16 July 2004

Congress approves 'Bioshield' legislation

Congress approves 'Bioshield' legislation:

By Joe Fiorill, Global Security Newswire

Congress approved legislation that would guarantee a government market for medical countermeasures against a biological, chemical, radiological or nuclear attack.

The chamber voted 414-2 in favor of a bill to implement Project Bioshield, which President George W. Bush first proposed in January of last year. The Senate passed identical legislation May 19. Bush is expected within a week or two to sign the bill, which is intended primarily to spur production of drugs that manufacturers would otherwise find unprofitable.

Select Committee on Homeland Security Chairman Christopher Cox, R-Calif., called the passage 'a watershed in our mission to defend America against bioterrorism, establishing our first line of defense against biological weapons.'

'This is the most significant first-responder program in our nation's history. It will ensure that we have treatments immediately on hand to save lives,' Cox said.

Besides authorizing the government to spend $5.6 billion over the next decade on countermeasures produced by private drugmakers, the act would speed National Institutes of Health countermeasure research and development, as well as allow the Food and Drug Administration to approve new drugs more quickly during emergencies.

A $700 million contract for a new anthrax vaccine, the first contract under the new law, is likely to be awarded 'as soon as next month,' said Rep. Jim Turner, D-Texas, the top Democrat on the House committee.

'By bringing researchers, medical experts and the biomedical industry together in new and innovative ways,' Bush said in a statement today, 'we will not only help protect the homeland but also gain insights into other diseases. This will break new ground in the search for treatments and cures while strengthening our overall biotechnology infrastructure.'"

15 July 2004

Most Large Companies See Sarbanes-Oxley Compliance As Part of Broader Corporate Governance Initiative

Most Large Companies See Sarbanes-Oxley Compliance As Part of Broader Corporate Governance Initiative:

Majority Do Not Measure Cost of Regulation, PricewaterhouseCoopers Finds

NEW YORK, July 14 /PRNewswire/ -- By a margin of nearly two to one, large U.S. companies have made compliance with the Sarbanes-Oxley Act part of their regular corporate governance approach and have integrated it with other regulatory activities, according to PricewaterhouseCoopers' Management Barometer.

The survey of senior executives at U.S.-based multinational companies found that:

-- 64 percent say their company's senior management and board of
directors see Sarbanes-Oxley as one of many steps in a larger
corporate governance initiative, while 30 percent say it is simply a
goal to be achieved. Six percent are uncertain.

-- 62 percent report Sarbanes-Oxley is integrated with their other
corporate regulatory compliance processes, but 34 percent say it is
not. Four percent are uncertain.

'Integrating the requirements of Sarbanes-Oxley compliance into ongoing corporate governance and regulatory activities, rather than managing compliance with the law as a separate task, offers the potential for improved business performance in both the short and long term,' said Dan DiFilippo, Partner and U.S. Practice Leader, Governance, Risk and Compliance, at PricewaterhouseCoopers.

Tracking Costs of Compliance


Despite complaints by some companies about the increased costs and regulatory burden imposed by Sarbanes-Oxley, most respondents, 56 percent, said their company does not track and report internally on the costs of Sarbanes-Oxley and other compliance programs. Forty-one percent do track such costs.

'Given the early outcry about Sarbanes-Oxley's added costs, it's surprising that most companies do not document and track this expense,' said DiFilippo. 'However, many companies have only recently begun to understand the types of costs and value associated with compliance efforts. We expect more aggressive monitoring as companies examine the effectiveness of their compliance approach.'

Remediation Efforts Expected

According to the survey, 79 percent of surveyed executives say their company must make improvements in order to comply with Section 404 of Sarbanes-Oxley, which requires companies to file a management assertion and auditor attestation on the effectiveness of internal controls over financial reporting. Among areas needing remediation:

-- Financial processes ......................... 55%
-- Computer controls ......................... 48%
-- Internal audit effectiveness ................. 37%
-- Security controls..................... 35%
-- Audit committee oversight................ 26%
-- Fraud programs.................... 24%

Process Improvements for Future Compliance

Looking ahead, 93 percent of executives expect their company to launch process improvement initiatives to streamline future Sarbanes-Oxley compliance. Among areas cited:

-- Financial reporting..................................63%
-- Risk identification and assessment...........61%
-- Risk mitigation.......................................55%
-- IT security strategy and implementation...55%
-- Internal audit.........................................55%
-- Compliance management........................54%
-- IT oversight and operations.................... 45%

'Companies recognize the need to make improvements in order to comply with the requirements of Sarbanes-Oxley,' said DiFilippo. 'When executives are confident that they are in compliance, many will want to find ways to streamline business processes and make future compliance less difficult.'"

14 July 2004

Keeping Data Under Lock & Key

Keeping Data Under Lock & Key:

By Gregory J. Millman

July/Aug. 2004 (Financial Executive) -- In the fall of 2003, discount airline JetBlue hit heavy weather when a group of passengers filed a class action suit charging breach of contract, invasion of privacy and fraudulent misrepresentation. The reason? The airline had shared passenger information with a government contractor who was preparing a risk assessment study for the Department of Homeland Security.

'In the wake of the Sept. 11 attacks, and as New York's hometown airline, all of us at JetBlue were very anxious to support our government's efforts to improve security,' JetBlue CEO David Neeleman said in an apology posted on the company's Web site.

But JetBlue wasn't alone -- Northwest Airlines and American Airlines faced similar lawsuits. 'There are some indications that the law may not treat handing over that information as a violation of privacy, but these companies have already suffered a fair amount of loss of brand value from the flap,' says Stewart Baker, a Washington, D.C.-based partner in the law firm Steptoe & Johnson.

Only in America, perhaps, can a company get in trouble for sharing information with the government itself. But as the memory of 9/11 recedes, privacy rights and suspicion of the government once again seem to trump security concerns in the minds of many Americans. And companies are finding that privacy laws are confusing, frequently costly and ripe for misinterpretation.

A 2003 Privacy Trust Survey by The CIO Institute of Carnegie Mellon University and the Ponemon Institute asked Americans to rank various institutions, companies and professions in terms of their trustworthiness with personal information. Respondents ranked the Department of Homeland Security second from the bottom -- just ahead of grocery stores, but behind other retailers. What's more, hundreds of lawsuits have been filed against companies that allegedly violated privacy rights while obtaining, using or sharing information. 'The latest figure is $125 million recovered in lawsuits from companies,' says Dr. Alan Westin, Professor of Public Law & Government Emeritus at Columbia University and President and Publisher of Privacy & American Business.

Many companies are struggling just to keep up with the proliferation of privacy-protection measures. 'We have scores, maybe thousands, of laws in the United States on the federal and state level, as well as millions of contracts and as many if not more informal or administrative requirements based on letters from government agencies,' notes Alan S. Goldberg, a Washington-based attorney and former president of the National Health Lawyers Association. A study by IBM and the Ponemon Institute found that some companies spend over $22 million annually on privacy. "

Tripwire_21_CFR11

Tripwire_21_CFR11

The U.S. Food and Drug Administration (FDA) has issued a set of regulations, collectively called 21 CFR11, that provide criteria for acceptance of electronic records and electronic signatures as equivalent to paper records and handwritten signatures executed on paper. These regulations, which apply to all FDA program areas, are intended to permit the widest possible use of electronic technology, compatible with the FDA’s responsibility to promote and protect public health.

Though electronic submissions are currently optional, the FDA is paving the way, with 21 CFR11, for routine and eventually mandatory submission of clinical trial records electronically. The 21 CFR11 provides in-depth guidelines and criteria for ensuring authenticity and integrity of digital records, and for documenting and validating authorized change processes to systems and software involved in the creation of digital records. The common goal is the ability to discern invalid or altered
records and, conversely, to assure accuracy, reliability and validity of electronic records and signatures. Typical FDA regulated activities that can accept 21 CFR11-compliant validated electronic records and signatures include new drug applications (NDAs), medical product license applications (PLAs) and biologics license applications (BLAs).

Tripwire® Integrity Management solutions are a natural fit for organizations that want to use electronic submissions and signatures in compliance with 21 CFR11. Tripwire software enables trust in information technology (IT) and data validation by establishing a baseline of your systems and data in their known good state, and detecting any change from that trusted state.

The trust and validation of electronic data enabled by Tripwire software is so fundamental that it transcends specific industries and regulations, and, yet, satisfies several key comments found in 21 CFR11. In this paper, we will detail which guidelines of the 21 CFR11 are supported by Tripwire software, and how Tripwire software takes a snapshot of what data looks like in its desired state. The software then monitors for differences from the baseline snapshot to see if anything has changed. If change is detected, the administrator is quickly notified and an auditable record is kept. Tripwire software then reports details on which files were added, deleted or changed.

13 July 2004

Director's Cut

Director's Cut:


Board members are turning to specialized software to help manage their affairs.


John P. Mello Jr.,
CFO Magazine

Board membership may have its privileges, but in this era of increased regulatory scrutiny, it also has its risks. This is not to say that sitting on a board of directors is a bad gig. Serving on a board remains one of the most effective ways for executives to network. It can offer rewarding work to those who have decided to step back from full-time jobs. And despite the hue and cry over executive compensation, board members get paid handsomely for their efforts: directors at larger companies typically rake in more than $100,000 in annual total compensation.

Still, these days they earn it. The Enron scandal initiated a new level of liability concerns; the Sarbanes-Oxley Act of 2002 (Sarbox) effectively multiplied the workload for any director willing to take on the job. Meetings are longer and more frequent. And it's arguably toughest for CFOs, who almost inevitably end up on the audit committee of the boards they join.

Longer meetings and heftier reading loads can create real headaches for directors. In some instances, just coordinating the topics for committee meetings can be a pain. Tom Lienhard, who serves on two boards, knows the problem only too well. 'Everyone is very busy, so our work carries over from month to month,' he says. 'Every month we have the same thing on our agenda. It drives me nuts.'

To address this vexation, Lienhard's boards (including the Ronald McDonald House Charities of Spokane, Wash.) recently installed an online software package called Director's Desk. The program, which is designed specifically for board and committee members, is intended to solve many of the logistical problems directors encounter. Using the software, for example, executive-committee members can conduct meetings online. Says Lienhard: 'We've actually been able to get a lot more done in less time.'

Director's Desk is one entry in an emerging category of software aimed at streamlining board communication and increasing board interaction. Some of these programs, including BoardVantage as well as Director's Desk, provide virtual meeting places for board members, along with specialized document management and communication tools. Others, like the suite from The Board Institute, based in Phoenix, help directors assess their own performance. Bret Beresford-Wood, CEO of Director's Desk Corporate Governance Services, in Post Falls, Idaho, believes the board-software market is set for a takeoff. 'In three to five years, a majority of companies will have some form of board-management system.'

Is This Anything?
The argument is that using IT to enhance board communication is a logical extension of current practice. 'Many CEOs communicate via letter to board members in odd months,' says Jay Lorsch, a professor at Harvard Business School and co-author of Back to the Drawing Board: Designing Corporate Boards for a Complex World. In fact, Lorsch is such a believer that he works with a company that is developing software to enhance board communication. 'Technology can provide a valuable way for board members to stay plugged in,' he says.

'If board members are inclined to communicate with one another, then these platforms will serve a great purpose,' predicts Stuart Robbins, executive director and founder of The CIO Collective, an organization for IT executives, in Oakland, Calif.

But some wonder if board software is more hype than help. Nell Minow, editor of The Corporate Library, a corporate-governance research firm in Portland, Maine, isn't sure the stuff is even necessary. 'There's nothing in this software that can't be accomplished through conventional communication and password-protected Websites,' she says.

Further, the cost of the programs, while cheap by enterprise-software standards, might spook finance chiefs at smaller companies. BoardVantage, for example, charges $2,000 to $4,000 per user per year.

Better communication seems to be the big selling point of board software, experts say. Both Director's Desk and BoardVantage offer secure E-mail and document management in a hosted environment. The feature can come in handy, since labor disputes and takeover bids don't necessarily crop up while board meetings are in session. 'Board members need to respond to issues as they arise,' asserts Tim Hampson, a marketing consultant with Menlo Park, Calif.-based BoardVantage. 'They need to communicate in a secure manner outside those meetings.'

12 July 2004

RealEstateJournal | Landlords and Tenants Disagree on Priorities

RealEstateJournal Landlords and Tenants
Disagree on Priorities
:

By SHEILA MUTO
Staff Reporter of The Wall Street Journal

From The Wall Street Journal Online

Talk about being out of sync with your clientele.

Accounting and advisory firm J.H. Cohn LLP recently surveyed a group of mostly developers and landlords in New York and New Jersey, asking them to, among other things, rank four factors -- technology, life-safety systems, high-end finishes and security -- in the order they believe are important in attracting tenants.

New York respondents ranked building security as the most important factor, while New Jersey respondents put high-end finishes first. Both New York and New Jersey respondents put life-safety systems -- which include fire alarm, sprinkler and communications systems -- at the bottom. Robert DeMeola, the partner in charge of J.H. Cohn's real-estate services group, which conducted the survey, says he was 'so surprised' that all respondents ranked technology and high-end finishes as more important than life-safety systems.

To determine whether the group of 59 respondents were out of touch or simply had 'short memories' of what happened on Sept. 11, 2001, Mr. DeMeola decided to pose the same question in an informal telephone survey to a handful of major tenants that recently leased space in Manhattan. (His group plans to conduct a formal survey of tenants.)

The result: The tenants deemed life-safety systems followed by building security as the most important of the four factors.

There's 'a disconnect between landlords and tenants,' says Mr. DeMeola. The results make clear that 'before landlords put a waterfall in the building, they should be putting in extra security' measures and 'upgrading life-safety systems and emergency lighting,' he says. Landlords are 'precluding a lot of the higher-end tenants' from their buildings if they don't."

Assessing Your Storage and Backup for Regulatory Compliance

Assessing Your Storage and Backup for Regulatory Compliance:

By Ken Barth

The complicated nature of data management makes backups a crucial issue for I.T. In general, users are concerned about protection from data loss and the risk of being non-compliant. Current backup methods leave crucial data at risk, many organizations fear.

Compliance is one of the most talked-about issues in data management in recent years. As deadlines for federally mandated programs loom near, the issue is becoming more and more important.

Yet, despite all of the discussion and buzz, few organizations have actually implemented a compliance plan as part of their business operations. Perhaps the greatest stumbling block to devising and rolling out compliance plans is a widespread and high degree of confusion as to what the various regulations and legislation require, and the actions and activities that organizations must take in order to be in compliance with those regulations.

The challenges facing I.T. managers seem never-ending in the consistently and rapidly changing world of technology. The issue of regulatory compliance adds another murky, albeit important area of concern. The term 'compliance' is an umbrella term that has come to cover the recent spate of federal and state regulatory legislation dictating how organizations must retain and preserve their vast stores of data.

The impact of such legislation is bound to be widespread, affecting most of corporate America. Furthermore, the confusion over compliance initiatives, their cost, and their potential impact stems from the lack of clearly defined guidelines. In fact, the very term itself continues to grow and expand in what it encompasses.

As it stands, regulatory compliance legislation directly affects private and public companies, particularly those in regulated industries such as government, finance, and health care. In addition, many organizations have come to realize the importance of data as an asset for business operations and continuity. The result is I.T. departments facing new and developing compliance requirements for security and data retention set by their own organizations.

Central to the whole issue of regulatory compliance are three questions:

What data types are subject to archiving?

How long does that data need to be stored and accessible?

What do organizations need to do in order to be compliant?

While there are numerous pieces of legislation that deal with data retention, including the Health Insurance Portability and Accountability Act (HIPAA) of 1996, The Gramm-Leach-Bliley Act (GLB) also known as the Financial Modernization Act of 1999, and the Uniform Electronic Transactions Act (UETA) of 1999, probably the most talked-about and anxiety-producing is the Sarbanes-Oxley Act of 2002.

Sarbanes-Oxley was signed into law by the current President Bush following such high-profile corporate scandals as Enron, Tyco and WorldCom as an attempt to correct problems in the way organizations had been reporting their financial information. Sarbanes-Oxley states what records an organization must archive and for how long those records must be stored (all business records must be saved, including electronic messages, for at least five years and possibly longer).

It does not offer a set of business practices or guidelines on how organizations are to store records, leaving I.T. managers to create archiving programs and procedures that both fulfill the requirements of Sarbanes-Oxley and fit within their budgets. Failure to meet the mandated Fall 2004 deadline for compliance carries severe penalties."

09 July 2004

What's under the business continuity umbrella?

What's under the business continuity umbrella?


Although the need to implement business continuity management processes is understood by the majority of organisations, there is much variation in what is actually included under the auspices of 'business continuity'. Continuity Central recently conducted a survey amongst the readers of the website to discover what the trends are in this area.

Respondents were asked to indicate what areas of activity were the responsibility of the business continuity function / department in their organisation. The full results are presented in the table below.

Activity
Percentage saying that this was a business continuity responsibility

Business impact analysis
93.5%

Testing and exercising the business continuity plan
92.1%

Crisis management
84.9%

Training and awareness raising amongst non-business continuity staff
84.9%

Training business continuity staff
78.4%

Crisis team building and development
75.5%

Risk assessment
74.8%

IT disaster recovery planning
71.9%

Crisis communications planning
69.8%

Auditing of own business continuity plan
65.5%

Risk awareness culture development
59.7%

IT disaster recovery solution design
50.4%

Liaison with local authorities
50.4%

Operational risk management
48.2%

Auditing of supplier business continuity plans
46.0%

08 July 2004

AIA: Momentum Grows to Extend Terrorism Insurance Law

AIA: Momentum Grows to Extend Terrorism Insurance Law

New legislation authored by several House Democrats to extend the Terrorism Risk Insurance Act of 2002 (TRIA) demonstrates strong, bipartisan congressional support for keeping TRIA's temporary, yet vital, economic safety net fully in place while long-term solutions are being evaluated, the American Insurance Association (AIA) said Thursday.

TRIA secures virtually every sector of the U.S. economy against catastrophic terrorist attacks by making sure that businesses of all sizes and types can purchase commercial insurance that covers losses resulting from terrorist attacks.

'Momentum is building on both sides of the political aisle and on both sides of Capitol Hill to extend TRIA this year,' Leigh Ann Pusey, AIA's senior vice president of government affairs, said. 'The House majority's 'Terrorism Insurance Backstop Extension Act of 2004' (HR 4634) and the Democrats' bill (HR 4772) clearly show that members of Congress want to devote significant energy to this issue this year.'

According to AIA, TRIA is a three-year, public-private risk sharing mechanism that has worked well, enabling the commercial insurance marketplace to function even though the very real threat of further catastrophic terrorism remains."

COMMENT:
=================================================
While extending TRIA is crucial to get the marketplace stabilized for the long haul, there may be a new risk on the horizon. By purchasing Terrorism Risk Insurance, REIT's and other property owners may think they are off the hook when it comes to hedging this specific type of risk. Nothing could be farther from the truth. Without clear evidence that landlords are preparing their tenants and staff for potential loss events of any magnitude, they face one of the greatest of Operational Risks. Legal Liability and loss of reputation. There is much more to the mosaic of risk management than just purchasing an insurance policy. Let's just hope that those entities involved are encouraging their respective staff and tenants to become more proactive, preventive and relevant when it comes to their critical infrastructures Operational Risk Management.

07 July 2004

Storage: Compliance Cuts Across Industries, Storage Products

Storage: Compliance Cuts Across Industries, Storage Products

By Mark Ferelli
CRM News

Ever since the large corporate scandals involving Enron WorldCom, and the like, new government regulations ar entering the business world. Many in the mass-storag world see many of these regulations as saviors from th business strains created by cuts in capital spending i enterprise IT

It is true that compliance requirements with new federal and state regulations will result in more capital spending in storage hardware, software, automation, architectures and services. More records will be retained than ever before, and the impact will touch both structured data like databases and unstructured data like e-mails and instant messages.

What the Laws Look for

The various regulations are almost never specific on technology; they are more involved with such things as dates. For example, many of the new regulations require companies to retain records for 2 to 10 years or more, and to retrieve records quickly at a regulator's request. Other regulations require systems to keep secure audit trails of changes and deletions or to prevent changes or modifications to archived data. Audit trails will be nothing new for many corporations, since their own auditors demand such safeguards. These rules show immediate requirements for storage hardware that will meet the government's test of time as well as sophisticated software for indexing, tracking, archiving, backup and retrieval.

In point of fact, the demand for reliable storage will increase for a cultural reason as well. Very few end users want to take the time or effort to decide which files to delete, so they save everything. No one gets fired for saving everything, but you take a risk when you decide to press the "delete" key.

Financial Services

The securities trading industry now has some of the most stringent regulatory requirements for record retention and data storage, particularly under SEC Rule 17 for broker-dealer operations. These high-profile requirements have inspired the architectural concept of the "compliance engine."
SEC rules and interpretations were initially focused on the creation and retention of hardcopy records (paper or microfiche). However, hardcopy records and manual processes did not grow the speed and information requirements of today's global markets and trading operations. High-speed, accurate throughput is a requirement instead of an option. Hence the development of a variety of data processing tools, both off-the-shelf and proprietary.

Health Care

The Health Insurance Portability & Accountability Act [HIPAA] (Public Law 104-191, 110 Stat.1936 L1996]) addresses a variety of health care reforms. Title II, subtitle F addresses "administrative simplification" and covers healthcare plans, healthcare clearinghouses that provide healthcare transactions and healthcare providers. Unlike the financial services laws, HIPAA drills down into small medical practices, medical billing areas, pharmaceutical firms and more.

Failure to comply would have the offender face significant financial, legal and business penalties including criminal prosecution. Best security practices require traditional front-end security methods such as physical access controls, data network transport protection, host defenses, system and applications authorization, and security policy. This layered defense model must extend to backend storage preventing unauthorized access to data-at-rest.

But HIPAA impact reaches across key concepts in mass storage and storage management. Storage consolidation, storage pooling on tape media, data stored remotely, data in motion and stored information leveraging third-party services have access vulnerabilities that affects compliance efforts.

PHI controls dictates where and how the data can be stored and used. PHI data protection often has related management, training, data classification and infrastructure costs that can be significant.

There are many different types of regulatory compliance issues facing storage administrators and systems integrators today. The pacing concern is that organizations are in need of a cost-effective solution that provides synchronous levels of protection with no distance limitations and with no application degradation. The hard fact is that compliance issues will be added to everyday storage issues in installations of various sizes from the SMB to the enterprise. And make no mistake, effective management of storage is crucial to meeting compliance issues and day-to-day operations.

06 July 2004

iPod is latest security risk for business, say analysts

iPod is latest security risk for business, say analysts

from Silicon.com on Tuesday, July 06, 2004
Article ID: D149172

Companies should consider banning portable storage devices such as Apple's iPod from corporate networks as they can be used to introduce malware or steal corporate data, according to an analyst.

Small portable storage products can bypass perimeter defenses like firewalls and antivirus at the mailserver, and introduce malware such as Trojans or viruses onto company networks, claimed analyst house Gartner in a report issued this week. Analysts have warned for some time of the dangers of using portable devices, but the report points out these also now include 'disk-based MP3 players, such as Apple's iPod, and digital cameras with smart media cards, memory sticks, compact flash and other memory media.'

Another potential danger is that the devices - that typically make use of USB and FireWire - could be used to steal large amounts of company data as they are faster to download to than CDs. Also the size of the portable devices means they can be easily misplaced or stolen.

Gartner advises that companies should forbid the use of uncontrolled, privately owned devices with corporate PCs and adopt personal firewalls to limit what can be done on USB ports.

'Businesses must ensure that the right procedures and technologies are adopted to securely manage the use of portable storage devices like USB 'keychain' drives. This will help to limit damage from malicious code, loss of proprietary information or intellectual property, and consequent lawsuits and loss of reputation,' the report stated.


Copyright 2004 CNET Networks, Inc."

COMMENT:
==================================================
We hope this message is clear. If not, see the movie "The Recruit".

01 July 2004

Coast Guard to inspect all foreign ships

Coast Guard to inspect all foreign ships

BY THOMAS FRANK
WASHINGTON BUREAU

BAYONNE, N.J. -- The Coast Guard launched an ambitious maritime anti-terrorism program Thursday when it started inspecting every foreign ship coming to a U.S. port to make sure it has taken steps to improve security.

Ships that fall short of international standards could be barred from U.S. ports, or allowed in under Coast Guard escort and forced to hire security guards while docked.

In addition, the Coast Guard will soon begin inspecting ports in 135 countries to evaluate their security. Ships that have docked in ports found to have weak security could be barred from the United States or subject to increased Coast Guard scrutiny that would delay their arrival and add costs.

Experts fear the inspections could isolate nations -- most likely poor ones -- with weak port security by blocking their exports to the United States.

'The Coast Guard can effectively bankrupt a country by barring its ships,' said Kim Petersen, president of SeaSecure Inc., a maritime security consultant, and executive director of the Maritime Security Council, a shipping industry group.

The inspections are tied to an international maritime treaty proposed by the United States shortly after the Sept. 11 attacks to create the first worldwide security standards for ships and ports.

Each of the 147 countries that signed the treaty in 2002 must certify that its ports and the ships registered there comply with the International Ship and Port Facility Security codes.

The codes, which took effect Thursday, require such measures as fencing and security guards at ports to control access. Ships must restrict who gets on and enters areas such as the bridge and engine room, and must have a security officer."

Policy Issues - SAFECOM Program

Policy Issues - SAFECOM Program

What is the problem?
– When public safety personnel cannot talk to each other by radio at the scene of an accident or a disaster, the problem often reflects lack of coordination and partnerships. Public safety agencies sometimes feel reluctant to coordinate or share communications systems because of "turf issues." Elected and appointed officials often do not fully understand the vital role interoperable communications play in protecting life and property. Local, tribal, state, and federal agencies generally lack opportunities to share experiences, develop common approaches, and identify best practices.

What has been done? – Government agencies at all levels are increasingly developing partnerships to support shared communications systems that improve interoperability, lower costs, and feature shared management and control. States are also beginning to establish executive-level committees to lead efforts to address interoperability issues.

What remains to be done?
– Information about the benefits of coordinated communications should be broadly and actively shared at all levels. Local, tribal, state, and federal agencies should form working groups or executive committees to coordinate interoperability activities, and government leaders should work with these groups by issuing appropriate policies or executive orders. Associations that represent government officials or public safety executives should commit themselves to supporting and working for interoperability. All of these groups can use Public Safety WINS: Wireless Interoperability National Strategy to pursue solutions to the technical and policy challenges to improving interoperability.

Public Safety Coordination and Partnerships Awareness Guide