13 June 2005

NORA is Now Dressed in Blue...

Now that Jeff Jonas's NORA (Non-Obvious Relationship Awareness) and SRDnet.com have been dressed in IBM Blue, a.k.a., DB2 Entity Analytic Solutions it's anyones guess who or what will be "Connecting the Dots."

DB2 Relationship Resolution answers the question "Who Knows Who?" IBM DB2 Relationship Resolution software begins where most solutions leave off, extending the customer view to identify and include the non-obvious relationships among individuals and organizations. An individual's relationships can provide a more complete view of their risk or value to your organization, whether they're a customer, prospect, or employee - even if an individual is trying to hide or disguise his or her identity.


Industry applications DB2 Relationship Resolution has tremendous application in industries such financial services, insurance, government, law enforcement, health care and life sciences, and hospitality. Organizations in these and other industries can use Relationship Resolution to: Connect insiders to external threats.

> Find high & low value customer relationships.
> Give fraud detection applications x-ray vision.
> Determine "network" value of the customer.
> Protect customers, employees, & national security.

What types of relationships can Relationship Resolution find?

> A potential employee who shares a P.O. Box with a convicted ID thief
> An account holder who shares a cellular account w/ a known money launderer
> An account exec who shares the same address as your hottest prospect
> A customer who lived with a wanted terrorist suspect
> An employee who lists your largest account holder as an emergency contact

DB2 Anonymous Resolution determines "Who is Who and Who Knows Who... Anonymously? It enables multiple organizations to selectively share data and leverage proprietary data in a matter that never exposes sensitive information, while still identifying relationships and developing leads.


"Finding the Needle" is not really the right analogy here. It's more like, let's find the one piece of straw in this haystack that meets this range of parameters. However, false positives and false negatives are always the name of the game when it comes to these kinds of solutions.

In order for this solution to work accurately, first you have to know "Who is Who". If this means that some how you have the same name as someone else, and that someone else has links to other people that are on a "Watch List", then you could become a false positive. The only ways to solve this are to feed the system with more information such as addresses, social security numbers, dates of birth and all the normal ways to more effectively ID people who have the same name. It also allows you to cross check who had an insurance policy, drivers license or any other data that would show up on a credit application such as your mothers maiden name. The other strategy is to make sure that you go "public" with who you are, where you live and what your blood type is so that their starting point will always verify who you are, for certain.

"The seemingly simple questions of 'who is who?' and 'who knows whom?' cut across a wide variety of business problems today," said Janet Perna, general manager, IBM Information Management Software. "The SRD technology provides solutions to these age-old problems with unparalleled speed and accuracy."

SRD software strengthens IBM's middleware portfolio via a multidimensional approach to analytics that dramatically extends the capabilities of identity-based applications. The combination provides value to business partners who deliver business intelligence and other applications that might require a single customer view, fraud detection, or customer relationship management across many industries, such as government, banking, insurance and healthcare.

"The combination of SRD technology with IBM's middleware platform will bring a new era of accuracy, speed and scale to business analytics," said John Slitz, CEO, SRD.


The biggest question now is; how do you find some entity that we don't know we are looking for? That is why it's important to see who is connected to what, a phone number, a bank account, an address, a frequent flyer number or a license plate. These patterns and relationships will ultimately give us the "insight" we need to detect a potential plot to commit fraud, launder money or attack a target.

03 June 2005

Critical Infrastructure Protection: NISAC to the Rescue

The NISAC has a small $20.M budget yet a very important task. Educating the next generation of Robert Oppenheimer proteges. Oppenheimer was the leader of the 20's something team that created nuclear devices known as "Little Boy" and "Fat Man" that helped end WWII with Japan.

In collaboration with Sandia National Laboratories, LANL (Los Alamos National Labs) through CHS (Center for Homeland Security) has also established the National Infrastructure Simulation and Analysis Center, or NISAC, whose contribution to homeland security is to identify infrastructure vulnerabilities to feasible terrorist threats.


NISAC's function is to figure out the answers to some difficult questions or "What if's". A good example might be: Should a dirty bomb make it's way past our detection and defenses in Long Beach and God forbid be detonated, how long can we afford to keep the port closed? The answer has an economic impact and a socially political paradox that requires unbiased thinking. That is where NISAC comes in.

These NISAC students have been selected by the Office of Educational Programs (OEP), which hosts the program for the U.S. Department of Homeland Security (DHS). The Science and Technology Directorate supports the program, which is open to any student interested in pursuing scientific and technological innovations that can be applied to the DHS.

Through the Program, DHS supports the growth and mentoring of the next generation of scientists as they study ways to prevent terrorist attacks within America, reduce America's vulnerability to terrorism and minimize the damage and recovery efforts from attacks that occur.


Given that the policy makers and scientists are now looking at how critical infrastructure has sophisticated interdependencies, it's time to use some of our great computing assets to answer these really hard questions. Seven of Sandia's computers are the fastest supercomputers in the world and even the older models are faster than most corporate or university machines. NISAC can do most of it's modeling on even a cluster of Dell's that have enough muscle to get the answers faster than the 6 week waiting list for time on supercomputers at Los Alamos.

CHS is home for some agent-based modeling projects that are used to help answer really hard questions. Especially about the behavior of humans in the aftermath of such significant business disruptions as closing the port of Long Beach. Or Houston?

The Los Alamos National Laboratory's Center for Homeland Security is evolving into the premier homeland security resource for the nation in the areas of Chemical and Biological Threat Reduction, Nuclear and Radiological Threat Reduction, and Borders, Information, and Infrastructure Protection. As an intramural Laboratory, we are a trusted DHS resource that responds in a continually adaptive, highly responsive manner to all technical requests. Through the steady development of our ReachBack capability the Center has permeated all corners of the Laboratory engaging the full resources of the Los Alamos National Laboratory to be brought to bear on DHS issues, crises, and questions. The Center for Homeland Security is viewed as a valued asset to regional, state, and local homeland security organizations because of our willingness to engage these entities and assist in helping them prepare, train, and if necessary, respond to both terrorist events and natural disasters.


Unfortunatley for the scientists, testing the models is difficult since 85% of the critical infrastructure is owned by the private sector. These corporate giants such as Verizon, Con Edison, Archers Daniel and the major banking institutions all are under the "Liability" constraint to share their precious and proprietary data, maps and diagrams. DHS is helping to smooth the way for more diligent cooperation in the legal discussions.

Let's just hope that we can give the scientist's what they need to do their job, faster and with more accuracy. Only then will we be able to truly understand the matrix of critical infrastructure in our country.

01 June 2005

Hurricane Season 101: Contingency Plan

Now that the Atlantic Hurricane season has now started, it's time for a little review.

Contingency Plan Objective:

To provide individuals with a documented set of actions to perform in the event of a disaster, enabling information processing to be resumed within critical timescales.

Contingency plans should be formulated to ensure that staff are aware of the steps they would be required to take in the event of a disaster affecting the computer installation.

The format and content of contingency plans should comply with enterprise-wide standards / procedures, form part of a wider business continuity plan and be distributed to all individuals who would require them in case of an emergency. Such individuals should be informed of their responsibilities and equipped to fulfil them.

Plans should include:

· conditions for their invocation
· the critical timescales associated with the business applications supported by the installation
· a schedule of key tasks to be carried out, responsibilities for each task and a list of services to be recovered, in priority order
· information security controls applied during the recovery process
· arrangements for processing from last successful back-up to time of disaster and then to resumption of normal service
· provisions for the clearance of any processing back-logs that may have built up during the system outage
· resuming processing using alternative facilities
· procedures specified in sufficient detail to be followed by individuals who do not normally carry them out.


Source: ISF Section IP7 - Service Continuity
If there is a serious interruption to information processing, for example if a disaster occurs, the computer installation may be unavailable for a prolonged period. Considerable forethought is required to enable information processing to continue in these circumstances and to keep the business impact to a minimum. Accordingly, this area covers the development and content of contingency plans, and the coverage and validation of contingency arrangements.

31 May 2005

External Events: Training and Simulation to Mitigate Risk

Every so often you come across a company or technology that is worthy of consideration for your enterprise. With hundreds of vendors products in several categories of Operational Risk, the Reality Response Division of AIS is one for your training and simulation portfolio.

The risk of loss from external events is a growing emphasis by many OPS Risk Officers. Preparedness is a key strategy to mitigating hazards and minimizing the loss of property and life. Imagine for a moment that you have a complete model of your facility, building or mall. A virtual model. One that you can use to train employees, staff and other suppliers about the idiosyncratic nature of your evacuation procedures or shelter-in-place locations. Not only is this method of training smart, it is cost effective and allows for participant interaction directly with the model and the procedures.

Real-time training with people in one room or multiple locations it does not matter. The participants can be exercised without exposure to potentiall hazardous situations until they are ready for a complete and full test of the simulation with a live scenario. The other applications include your physical security teams.

In today's uncertain world, security forces are asked to combat a wide variety of public safety threats - local street crime, terrorist attacks, and international conflicts occur with alarming frequency. At AIS, we understand these threats and have developed an extensive offering of training programs to enhance the performance of security forces on the front lines.

> Judgmental Use-of-Force
> Firearms Training
> Counter-Terrorism
> Chem-bio Response
> Marksmanship Training
> Incident Command
> Tactical Carbine
> Tactical Handgun Skills
> Rifle Instructor
> Behavior Pattern Recognition
> Checkpoint Security


Advanced Interactive Systems, Inc., (www.ais-sim.com) provides comprehensive training solutions for people in positions where lives are on the line, including law enforcement, military, government, security, corrections and emergency responders. AIS manufactures PRISim training simulators that provide lethal and less-lethal weapons handling and judgment skills. The AIS Ltd. group designs and builds anti-terrorist and other special application training facilities for military and special operations groups, with installations in more than 60 countries. The Reality Response Division manufactures interactive simulation systems and synthetic environments that provide reality-based training for CBRNE (chemical, biological, radiological, nuclear, explosive) hazard response tasks. Headquartered in Seattle, Washington, AIS Inc. is a privately-owned company with offices in Washington D.C.; McLean, Virginia; Monterey, California; Orlando, Florida; Abu Dhabi, UAE; Singapore, Malaysia Farnham, England.

27 May 2005

Software Quality Risk Assurance: Feasible or Desireable?

For those of you who have never heard of the Metasploit project, now you have. This could be your worst nightmare or it could be your best ally.

This is the Metasploit Project. The goal is to provide useful information to people who perform penetration testing, IDS signature development, and exploit research. This site was created to fill the gaps in the information publicly available on various exploitation techniques and to create a useful resource for exploit developers. The tools and information on this site are provided for legal penetration testing and research purposes only.


In a recent presentation by Dr. Eric Cole, CTO of the Advanced Technology Research Center at Sytex, Metasploit was highlighted as a tool that could be utilized to attack your own systems. Why?

At the 50,000 ft. level, the logic goes something like this. You have to utilize the same tools that attackers use on your own networks to understand exactly where your vulnerabilities lie. If only the Chief Risk Officer or Chief Information Security Officer only knew what challenges they really face in the next phase of Information Warfare.

The ethics of providing such tools is no different than other debates that are embedded in the US Constitution. The Right to Bear Arms. At some point the topic of regulation will become louder than it is today. What really matters is that the technology companies invest more heavily in software quality assurance and they do more diligent testing. Many have realized the cost of catching a bug or vulnerability after general release costs exponentially more dollars to fix than at an early stage of software development.

And that is exactly why the Metasploit project exists. Six Sigma Software Quality Risk Assurance is neither feasible nor desirable for most companies who choose to develop operating systems and applications for the high technology sector.

25 May 2005

A Risk Strategy for Corporate Business Survival - Lesson 5 - Document

“4D”
A Risk Strategy for Corporate Business Survival
Deter. Detect. Defend. Document.

By Peter L. Higgins

Lesson 4 of a 4 Part Series


The Mission
Document the normal so you know when and where there is an unauthorized result. In order for the attacker to obtain their objective, the target must produce this unauthorized result. These might include:

· Increased Access
· Disclosure of Information
· Corruption of Information
· Denial of Service
· Theft of Resources

In order to understand that an attack is actually occurring, normal results have to be documented and a historical trend has to be established. What is normal? How do you know what normal looks and feels like? You document, store, record and analyze what normal is. If you have done this for long enough and across the potential targets the attacker is trying to exploit, then you will know the second an unauthorized result takes place.

The Take Away
Documenting the behavior of people, processes, systems and external events is a vital component of a complete strategy for risk mitigation. Understanding what normal “is”, begins with effective documentation and analysis. Many organizations begin to document long after it is too late or as a result of a significant business disruption. Documentation remains to be a challenge for many, and a task that attackers know is likely to be left undone or behind schedule.

Conclusion
A “4D” Risk Strategy for Business Survival is only effective if it is operating on a continuous basis. You must create the culture and the due diligence to see that it becomes part of the fabric of the organization internally and with outsourced partners or suppliers. Only then will the attacker realize that this combination to deter, detect, defend and document is alive and growing in your enterprise. This is when attackers become discouraged, afraid, uncertain and ultimately ready for a new and less formidable adversary.

Attackers use tools to exploit a vulnerability to create an action on a target that produces an unauthorized result, to obtain their objective. These “4D” lessons should put you on the way to creating a more survivable business.

Peter L. Higgins is the Managing Director of 1SecureAudit, an Operational Risk Management Solutions firm located in McLean, VA. He can be reached at higginsp@1SecureAudit or 703 245 3020.

24 May 2005

A Risk Strategy for Corporate Business Survival - Lesson 3 - Defend

“4D”
A Risk Strategy for Corporate Business Survival
Deter. Detect. Defend. Document.

By Peter L. Higgins

Lesson 3 of a 4 Part Series


The Mission
Defend the target from any actions by the attackers tools. Targets may include a person, facility, account, process, data, component, computer, Intranet network or Internet. Actions against the target are intended to produce the unauthorized result. Some action categories are labeled:

· Probe
· Scan
· Flood
· Authenticate
· Bypass
· Spoof
· Read
· Copy
· Steal
· Modify
· Delete

The Take Away
In order to understand how to defend your corporate assets, you have to attack them yourself using a continuous combination of tools and tests. Only then will you find out where your single point of failure lies and where the attacker is going to successfully exploit a vulnerability you didn’t know exists.

23 May 2005

A Risk Strategy for Corporate Business Survival - Lesson 2 - Detect

“4D”
A Risk Strategy for Corporate Business Survival
Deter. Detect. Defend. Document.

By Peter L. Higgins

Lesson 2 of a 4 Part Series


The Mission
Detect the use of tools by the attackers. These tools are what they use to assess the vulnerabilities within and throughout the organization. These tools include surveillance, physical attack, information exchange, user commands, scripts or programs, autonomous agents, toolkits, distributed tools or data taps. Some are high tech and most are the craft of social engineers.

The attackers are using a combination of these tools and tactics to exploit corporate vulnerabilities in:

· Design
· Implementation
· Configuration


The Take Away
Just about any significant business disruption can be traced back to the fact that the attacker was able to effectively exploit the organizations defenses using a systematic method and the correct tools. Detection of threats begins by detecting the use of tools. Whether it’s the surveillance of an individual or of a facility. Whether it’s the design of the building or the software code for the E-Commerce system. Whether it’s the implementation of security cameras or the firewall. Whether it’s the configuration of the controls for access to the vault or to the ERP system. You have to continuously detect the use of the attackers tools and their methods to exploit your vulnerabilities.

21 May 2005

A Risk Strategy for Corporate Business Survival - Lesson 1 - Deter

“4D”
A Risk Strategy for Corporate Business Survival
Deter. Detect. Defend. Document.

By Peter L. Higgins


Lesson 1 of a 4 Part Series

Executive Summary
Our corporate assets are under attack by a continuous barrage of new laws, new employees, new competitors and new exploits. Business survival in the next decade will require a more effective and robust risk strategy to deter, detect and defend against a myriad of new threats to the organization.

Modern day attackers include hackers, spies, terrorists, corporate raiders, professional criminals, vandals and voyeurs. Simply said, these attackers use tools to exploit vulnerabilities. They create an action on a target that produces an unauthorized result. They do this to obtain their objective.

Here are four key lessons to create a “4D” risk strategy in your enterprise.

Lesson 1 – Deter

The Mission

Deter the attacker from launching a salvo of new threats to compromise your organizations assets. You first have to understand the value of your corporate assets to determine what are the most valuable in the eyes of your adversary. You must make it increasingly more difficult for these valuable assets to be attacked or you will find yourself under the constant eye of those who wish to create a significant business disruption.

These attackers are individuals who take on these quests or objectives for several key reasons. They include financial gain, political gain, damage or the simple challenge, status or thrill. It’s your job to create deterrence for each one of these objectives.

The Take Away
In order to effectively deter potential risks to your corporate assets, first you have to understand what they are and how valuable they are in the eyes of each kind of attacker. The more valuable the target, the more deterrence it requires.

19 May 2005

Cyber-Crime & E-Forensics...

Companies such as Intelligent Computer Solutions are making the Computer Forensic investigators more effective. In fact, they are making it more difficult for those hackers, attackers and others to steal corporate information and assets, abuse acceptable use policies and to harm the reputation of organizations.

Intelligent Computer Solutions (ICS) is the technology leader in the design and manufacture of high-speed Hard Drive Duplication equipment, Software Cloning Solutions and Diagnostic Systems. Having developed the hard drive duplication technology (and holding a US Patent C,131,141), ICS has gained international name recognition for 14 years of customer service and for providing its customers with cutting edge solutions.

Intelligent Computer Solutions is a prominent supplier of Law Enforcement & Computer Forensic Systems to Law Enforcement personnel ranging from local police departments to Federal and International agencies. ICS units are being used today by government agencies in the US, Canada, Europe, the Middle East, China, Australia and New Zealand.


Online Fraud and other internal mischief is keeping the industry busy working with clients on a number of issues including:

"Consumers and businesses alike must remain constantly vigilant about personal and financial information," said Patricia Kachura, senior vice president for ethics and consumer affairs at The DMA. "E-mail scams are becoming more sophisticated and scammers are becoming more organized, and efficient in exploiting illegally obtained personal information to the fullest extent possible."

Financial fraud, for example, costs consumers and businesses billions of dollars annually. Based on a 2004 poll of 5,000 people in the U.S., the industry analyst firm Gartner calculated that $2 billion a year is lost to banking scams, including online fraud and phishing.

The top five spam scams for April as identified by the NCFTA include:

1. Web Mobs: Web mobs are well organized groups of computer-savvy criminals who form hierarchical networks on the Internet in order to commit identity theft and fraud with personal identification and financial information. After gathering victim information via phishing schemes, the Web mob buys and sells the information among its members or through online auctions. They use Web sites and chat forums to discuss and exchange techniques and tools.

2. Cross-Site Scripting (CSS): CSS vulnerability is caused by the failure of a Web site to validate the intended address of user input, such as personal or financial information supplied to make an online purchase, before returning that data to the client's Web-browser. Instead, that information is sent to another, unauthorized site. This is called cross-site scripting and is caused when an intruder causes a legitimate Web server to unknowingly send a page to a victim's browser that contains malicious script or HTML. The malicious script runs with the privileges of a legitimate script originating from the legitimate Web server and redirects the information to the intruder's Web server. More information on this practice is available at http://www.cert.org/archive/pdf/cross_site_scripting.pdf.

3. Pharming Attacks: Pharming is the redirecting of a Web request to another location entirely. On a computer hijacked by pharmers, for example, a user will type a URL (such as their bank's Web address), but will unknowingly be redirected to a designated phishing site that looks very familiar. Because the user did not click on any obscure link, the site will appear to be legitimate.

4. Phishing: Phishing is by far the most abundant scam witnessed by the NCFTA to-date., Bank and credit card phishing scams are constantly evolving, making it more difficult to identify the forgery. Source codes which have been used to determine where "phished" information was being sent after it was harvested, are now being hidden by phishers. Phishers are also disabling mechanisms such as 'right-click' on the phishing sites for the purpose of masking the compromised URL.

5. Spyware - Trojans & Malicious Code: This is software that surreptitiously performs certain tasks on your computer, typically without the user's consent. This may include collecting personal information about you, or infecting your computer with a Trojan or malicious code. Such instruments can cause your computer to be used for other criminal conduct, such as Denial of Service attacks, or to act as part of a spam relay network.

Spyware and Trojans are downloaded onto a user's computer in two ways. First, the most frequent way is by accessing Web sites containing them. Secondly, such tools can infect a computer through a spam e-mail that includes a link to a site containing spyware or Trojans. In some instances a user need not even open the e-mail attachment for it to execute or load to your computer without one seeing it occur.

These identified spam scams are based solely on limited NCFTA data. However, this information is shared with the FBI, which, with assistance from The DMA's Slam Spam project, provides law enforcement authorities with a much more robust understanding of the top spam scams.

06 May 2005

Offshoring: Audit Processes and Facilities

Thanks to Christopher Koch for his article on "Don't Export Security".

U.S.-based companies routinely underestimate the extra elements of risk introduced into the offshoring equation by issues like poor infrastructure, political instability and legal systems that don't line up with Western practices, says Ken Wheatley, vice president, corporate security of Sony Electronics. "People are so focused on saving money and shifting operations that they don't think about the safeguards that need to be put in place," he says. "They assume that people in different countries have the same mind-set and safeguards and sense of due diligence, and that's just not the case."


Ken Wheatley is correct and more companies need to have offshoring due diligence that makes sense. Here are a few key questions for any organization considering an outside supplier relationship.

What is the importance of the function or process being performed to the mission critical components of our daily operations? If the answer is high, then you know that your first risk mitigation step may be to re examine whether this should ever be outsourced!

If the answer is medium or low, you should ask for the last audit results on these key areas of ISO 17799. And if these haven’t been audited, then why risk handing over any activities to any supplier without thorough due diligence.

A.12.1- Compliance with legal requirements to avoid breaches of any criminal and civil law, statutory, regulatory or contractual obligations and of any security requirements.

A.11.1 - Business continuity management to counteract interruptions to business activities and to protect critical business processes from the effects of major failures and disasters.

A.7.1 - Secure areas to prevent unauthorized physical access, damage and interference to business premises and information.

A.6.1 – Security in job definition and resourcing to reduce the risks of human error, theft, fraud or misuse of facilities.


All the controls and standards don’t mean a thing until someone tests their effectiveness. Sadly, many organizations still have a long way to go to becoming compliant with even their most fundamental security policies

03 May 2005

E-Mail and Digital Discovery: What is Your Policy?

The interpretations of "E-mail Retention" policy is still an issue in managing legal risk and many are still scratching their heads for answers. What is a Chief Compliance Officer(CCO) to do these days to conquer the data and records retention explosion?

The Sarbanes-Oxley Act of 2002
All public companies are required to save records relevant to the audit process, including e-mails, for seven years. The real-time disclosure rule, will force companies to monitor the contents of e-mail for material events.

Securities and Exchange Commission Rule 17A-4
Stemming from the Securities Exchange Act of 1934, this rule requires brokerages to save e-mails in an easily accessible place for two years.

The Health Insurance Portability and Accountability Act of 1996
Privacy rules dictate what information health-care companies can and cannot include in e-mails.

Medicare
Health-care companies are required to retain e-mails that are especially important during audits.

Other legislation
The Can-Spam Act of 2003 for marketers, the Tread Act of 2000 for the automotive industry, the Gramm-Leach-Bliley Act of 1999 and the USA Patriot Act of 2001 all force companies in many industries to change the way they manage e-mail.


The four aspects of good e-mail management: storage, archiving, indexing and policy enforcement are where the CCO, CIO and General Counsel are all converging with their current conversations. What remains to be done, is for the technologies to catch-up and to assist especially in indexing and policy enforcement. You can bet that some organizations are making a copy of every single e-mail sent and putting it into a vault. And others who will retain e-mail only for 30 days before it is deleted forever. The policy is different depending on the type of organization and the number of times you are served with "Discovery" requests from legal counsel.

Jeffrey Schwarz, an Information Technology Partner from McDermott, Will & Emery, was quoted in the January 15 issue of CIO in an article addressing how federal regulations, from HIPAA to Sarbanes-Oxley, have moved e-mail management to a top priority for CIOs. "E-mail has become the primary medium for how we communicate," Mr. Schwarz commented. "Four years ago we used paper and FedEx. Now almost everything is done over e-mail." He continued saying, "We are trying to make a system do something that it wasn't designed to do. E-mail wasn't designed to be a document repository. It was meant to be send, read, delete. But now you can't delete. There are regulations that don't let you do that."


Regulatory Compliance is not a traditional IT training ground until now. It's critical that an information management policy and regulatory procedure fusion take place at the board level to insure against the risks associated with e-mail retention or lack there of. But still, what is the Chief Compliance Officer going to do to mitigate these risks sooner than later?

E-Evidence and Digital Forensics are sought after disciplines these days at large law firms and other specialized consultancies. E-mail litigation is fueling this fire. The "E-Mail Trail" called by some is the "Smoking Gun" that gets juries convinced and plaintiffs huge awards or convictions.

The demand is only likely to increase as the volume of cases with digital evidence increases, according to the Department of Justice.

"Cyber-crime is obviously something that is a national priority," said Steve Bunnell, chief of the criminal division at the U.S. attorney's office in Washington, D.C., which recently established a cyber-crime division.

"Computer crimes are something that crosses borders. ...There is really a premium on getting the right and left hand working together," Bunnell said.

Courtrooms and universities are welcoming more lawyers specializing in electronic crime. They are setting the stage for the evolution of "cyber-law" as the debate over digital evidence -- and what limits may be put on it -- is raging among legal scholars and law enforcement, Brenner said.

27 April 2005

Terrorism Risk...

For a copy of the 2005 Aon Terrorism Risk Map Click here to visit their site. It has their risk ratings for every territory in the world.

The Teorrism Risk Map shows that participation in the US-led Iraq coalition has increased terrorism risk in countries such as Australia, Poland and Estonia. There is concern that Al-Qaida and other international terrorist organizations could take advantage of anti-western sentiment and launch terrorist attacks in these countries in future. Businesses which originate from these countries should also be aware of threats to their operations and personnel abroad as evidenced by incidents such as the terrorist attack on the Australian embassy in Indonesia, the recent bombing of a British theater and school in Qatar and the thwarted plot to blow up the Italian embassy in Lebanon.

"Terrorism is not a new threat and many international businesses have to date been rightly pre-occupied with the risks facing their operations in the Middle East, Africa and the Gulf. Although companies do need to be aware of the global picture, the 2005 map highlights the need for vigilance in so called 'safer' European countries," commented Paul Bassett, executive director in Aon's Crisis Management division.

"Companies must acquire as much knowledge as possible about the risks they face and their exposure to those risks in order to minimize the human and financial impact of such attacks. Businesses can then assess how best to allocate their expenditure on insurance and counter terrorism risk management procedures effectively," he added.


What does all of this mean? It means that now more than ever the insurance industry is going to look more closely at the risk of your people and property being in harms way. And if they are, then what is being done to mitigate those risks. It all comes down to what the insurance companies want from you as a client. To buy more insurance. If that is all you do, then you have missed several other strategic and tactical means for protecting your organizations vital assets.

25 April 2005

CEO's vs. Boards...

There is another interesting perspective in this months Corporate Board Member Magazine regarding the trust factor between the CEO and the Board of Directors.

It seems that there is still a major battle going on here with some companies but the question is why does it exist? More and more the shareholders are upset with performance and other key issues and they are putting the pressure on Directors to act. What is a shareholder to think when the annual shareholders meeting becomes a one-way conversation and the Q & A is herded into the last 15 minutes and there is no longer a live mic on the floor. If there are suspected hostile or threatening entities in the audience then security should do their duty and remove these individuals. However, when the executive management are clearly shutting down a meaningful open dialogue with the shareholders, then the Board of Directors should be questioned on their allegiance.

Of course there are many examples of where the Chairman of the Board is still the CEO and this is one topic for another date. What is interesting in the debate on the anxiety between the executives and the board these days is this:

After nearly three years of fallout from Sarbanes-Oxley, plus the frightening realization that directors may be held financially liable for their oversight failures, boards are no longer looking at their CEOs with wonder. In fact, they’re downright skeptical. “Trust in the CEO is not at the levels it used to be,” says Richard Koppes, a director of Apria Healthcare and Valeant Pharmaceuticals International. Adds Philip Burguieres, chairman emeritus of Weatherford International and a former CEO of Panhandle Eastern Corp. and Cameron Iron Works: “The element of trust seems to be gone. A few guys have done great harm.”

Obviously the vast majority of CEOs are trustworthy, but all have been slimed to some extent by the scandals of recent years. In 2003 a joint BusinessWeek/Harris Poll survey found that nearly 80% of Americans believed that CEOs of large companies put their own interests before those of workers and shareholders.

To say that boards don’t trust the CEO is not to say that they suspect dishonesty. If they did, turnover at the top of the corporate totem pole would be even higher than it is. Last year 663 CEOs decamped to other jobs, retired, or were fired, down from the high-water mark of 1,106 in 2000, according to Challenger Gray & Christmas, an outplacement firm that keeps track of these peregrinations. Rather, what boards fear is that their CEO isn’t leveling with them, that all information that directors receive about the company is filtered through the CEO’s ego.

When McKinsey & Co., a management consulting firm, surveyed 150 directors in 2004, 81% said that the CEO largely or completely controlled and shaped what board members learned about the company. Only 30% said they felt they really knew what was going on. Directors want to take more control of the information they are getting, and that’s a direct challenge to the CEO’s power.


The risks facing organizations today go way beyond the typical issues you hear about in the Board of Directors meeting or the Audit committee conference calls. The risk of a systemic failure of the corporation is at it's roots a failure of the way information is collected, processed and delivered. Think about the simple process of sales forecasting and you begin to see where the root problem is. At each step of the roll-up and the chain of management there is another layer of guess work and sanitization. If a Board member ever got the chance to ride in the field with a seasoned sales rep and also attend a district sales meeting during a pipeline analysis then they would begin to understand why the CEO is guarding the "Corporate Fort" at all costs.

21 April 2005

Here is How to Protect Your Organization...

Rob Norton's cover story on Risk is a great primer to what corporate executives and board members around the globe have known for some time.

Crooked managers. Changing technology. Financial surprises. Who knows what company-killers lie ahead? Here’s how directors can protect themselves.

No single four-letter word is more likely to raise a board’s collective blood pressure these days than risk. The recent parade of corporate scandals can be blamed in part on a lack of effective systems to recognize and manage risk—not just insurance matters but broad operational and financial hazards to the enterprise. Now risk management has risen to the top of the agenda for many directors. Often the job falls under the authority of the audit committee, but some U.S. boards, including that of MCI (formerly WorldCom), have appointed special risk management committees. The boards of several European and Canadian companies have adopted formal processes aimed at alerting directors to the extent to which the outfits are exposed to risk and how it is managed.

The risks that blew up in the faces of boards at companies such as WorldCom, Enron, and Parmalat all come under the general category of operational risk, broadly defined as the danger of loss resulting from inadequate or failed internal processes, people, or systems, or from external events. These can include:

• Unscrupulous managers.
• Business interruptions caused by terrorism, war, or natural disaster.
• Supply-chain breakdowns.
• Changing technology.
• Increased competition.


Fortunately, the article mentions "Supply Chain Risk" as an area that needs more scrutiny as companies continue to increase offshoring and outsourcing to gain competitive advantages. This area of Operational Risk is a growing concern by not only shareholders, but the plaintiffs who follow the aftermath of Eliot Spitzer's investigations.

A significant business disruption (SBD) will occur at your organization each day, week, and month this year. The question remains that of what you are already doing to manage these inevitable incidents. We suggest a "4D" approach:

Deter

Detect

Defend

Document


This "4D" Managed Services approach to managing Operational Risk provides the initial framework for creating a strategic enterprise risk management (ERM) initiative in the organization. Each area has it's own tools, systems and processes yet each is connected to the Risk Nervous System via the 1SecureAudit Operational Risk Enterprise Architecture. (OREA)

OREA utilizes a proven and systematic approach for risk assessment, data capture, risk treatment and reporting. To facilitate efforts to transform the organization into one that has lower volatility of earnings growth and is more secure, 1SecureAudit co-designs the Operational Risk Enterprise Architecture (OREA), a business-based framework for organizational-wide improvement.

People
· Employee Fraud / Malice
· Unauthorized Activity
· Rogue Trading
· Employee Misdeed
· Employment Law
· Loss/lack of personnel

Processes
· Payment / Settlement
· Delivery / Selling
· Documentation / Contract
· Valuation / Pricing
· Internal / External Reporting
· Compliance

Systems
· Technology Investment
· Development
· Access
· Capacity
· Failures
· Security Breach

External
· Legal Liability
· Criminal Activities
· Outsourcing
· Suppliers / Insourcing
· Disasters / Infrastructure
· Regulatory / Political

OREA is constructed through a collection of interrelated “reference meta models” designed to facilitate cross-lines of business analysis and the identification of duplicative processes, departments, gaps, and opportunities for collaboration within and across lines of business (LOB). This OREA and Business Reference Model is intended for use in analyzing investments in Operational Risk projects and other capital assets. It also serves as a foundation for the development of a broader architecture that can serve as the platform for a comprehensive budget and performance reporting system that supports enterprise wide business risk integration and change management initiatives.

20 April 2005

VoIP, WiMAX: Business Resilience

What about the risks of VoIP? In case you haven't seen a presentation from Lucent Technologies recently, you should.

As a witness to their latest presentation in Washington, DC on "How Next Generation Networks Can Impact Business Resilience", there are some very interesting trends and capabilities here now and on the horizon worth exploring.

The Lucent approach to VoIP security is largely based on standards, many of which Lucent and its "innovation engine," Bell Labs, have helped to develop and shape. For instance, the International Organization for Standardization offers ISO 17799,which provides recommendations for information security management and provides a common basis for developing organizational security standards and effective security management practices. Similarly, the International Telecommunications Union's X.805 standard defines a security architecture for systems providing end-to-end communications.And NRIC,the Network Reliability and Interoperability Council, provides best practices guidance in a number of areas that relate to VoIP operations.

Lucent, with its unmatched telecom heritage and broad experience can be a partner in helping develop actionable plans and in implementing successful VoIP security programs based on these standards. Lucent's best practices include security policies that outline expected behavior and security awareness of users, administrators, managers and other employees as well as security assessments to pinpoint security gaps, and to determine what is happening in practice rather than simply what may be documented in policies.


You have to keep in mind who Lucent's customer base really is. The Regional Bell Operating Companies (RBOC), MCI, AT&T as well as all of the major wireless providers make up the majority of their client base. They will have advance notice of what providers are launching new technologies when, and they will have plenty of non-disclosure about who they think is the best vendor. It sure is refreshing to talk with a company who is all about capability and soundness of technologies. How the provider ends of servicing the customer is another topic.

On another front, they predict that by 2008 about 60% of laptops will be shipping with WiMAX.

The WiMAX Forum™ is working to facilitate the deployment of broadband wireless networks based on the IEEE 802.16 standard by helping to ensure the compatibility and inter-operability of broadband wireless access equipment. The organization is a nonprofit association formed in June of 2001by equipment and component suppliers to promote the adoption of IEEE 802.16 compliant equipment by operators of broadband wireless access systems.

Principles:
WiMAX Forum is comprised of industry leaders who are committed to the open interoperability of all products used for broadband wireless access.

Support IEEE 802.16 standard
1. Propose and promote access profiles for their IEEE 802.16 standard
2. Certify interoperability levels both in network and the cell
3. Achieve global acceptance
4. Promote use of broadband wireless access overall

18 April 2005

The Risk Barometer...

The Risk Barometer may be changing if this latest survey is correct:

The most significant issues facing business today, according to respondents to the first Risk Barometer survey, are reputational risk (defined as the threat of any event that can damage a company's reputation) and regulatory risk (defined as problems caused by new or existing regulations). These two risk categories received the highest scores in the Risk Barometer, indicating that they are seen as more significant issues than market risk, foreign exchange risk and country risk by the majority of executives in the survey. The third most significant threat cited by executives is IT network risk, which encompasses network security breaches and IT systems failure.


The natural hazards category is decreasing as a priority in the eyes of these risk managers predominately from the financial services sector as this is being covered primarily by insurance. Also, the frequency of events is a factor here. Reputation and Regulatory Risk are both areas that need attention in the enterprise and managers are finding it more challenging to put the correct controls and measures in place to mitigate these two growing threats to the organization.

12 April 2005

CFO's vs. SOX 404...

The battle lines are heating up as more and more companies delay their reports on performance. The lines are being drawn in the sand over whether the SOX 404 compliance mandates are just too much for some finance and IT departments to handle. And the CFO Executive Board is shouting that this Sarbanes-Oxley Act is the reason we are losing jobs.

Candice S. Miller is now in the hot seat as the Republican from Michigan becomes the new chair of the House Government Reform subcommittee on regulatory affairs. Her first agenda item is the impact of regulation on US manufacturing. The CFO's in America are waving the white flag as they pretend to be drowning in regulatory compliance issues. The question now is whether all of this hard work on SOX 404 and other laws will ultimatley benefit corporate America. The answer is yes.

In the long run not only will the investor's win, so to will the executives who have devoted so much time and energy into regulatory and legal compliance. As stewards of the enterprise and overseers of their own corporate sandbox, they will soon realize the investment in their own organization has been a prudent one.

For more on the CFO Point of View, see this proprietary report by the CFO Executive Board.

The report includes the predictions of a proprietary model the CFO Executive Board built to estimate the impact of Section 404 compliance activities on the US economy.

A key finding reveals that unless senior corporate executives take extraordinary measures to ensure that Section 404 compliance efforts do not crowd out key managerial activities and R&D investments, these requirements threaten both economic growth and job creation. More specifically, the report concludes that Section 404, as implemented, could retard job creation by more than 300,000 jobs and slow GDP growth by nearly 0.5 percent during the next three years.

"When you consider that Sarbanes-Oxley was drafted in only a few months, it's not surprising that companies have experienced serious, unexpected problems and high costs in complying with these new requirements," says Scott Bohannon, executive director of the CFO Executive Board

Of course, not all the news is bad.

08 April 2005

Terrorism Risk Management

In light of the fact that the insurance industry is still immature in their models due to a lack of actuarial data the real estate financiers are considering alternative approaches to risk mitigation and management. For example, tools for the assessment of terrorism vulnerabilities exist today that could be introduced into the cycle of due diligence. As these tools are adopted to assess and help reduce the risk of unknown man-made events, the lenders and the insurers will converge on these new models to help rate structures and critical infrastructure in terms of their exposure to terrorism risk.

Due diligence requires detailed property inspections and audits to provide sound advice to key decision makers on the state of a real estate property. Vulnerability to terrorist attack will become, if it isn’t already, a critical component of due diligence. The individuals and firms that provide these solutions must be multi-faceted in operations, security and building systems in order to provide a comprehensive and fair report. This assessment should include the operational procedures and hazard mitigation programs of the building to determine the overall vulnerability to a combination of both natural and man-made events.

Asset Identification & Valuation
Priorities for protecting both physical and information assets is obtained through a comprehensive process for enterprise risk management. You must identify the relative importance and value of assets whether they are people, processes, systems or facilities. Three primary actions must take place:

1. Identification and Definition of core business processes to sustain the organization in business (sales, customer service, accounting)

2. Identification of critical business infrastructure assets such as:
o Personnel to run the functions and facilities
o Information systems and data
o Life safety systems and safe havens
o Security systems

3. Assign a relative protection priority
o High – Loss or damage would have grave consequences for extended time
o Medium – Loss or damage would have serious consequences for a moderate time
o Low – Loss or damage would have minor consequences for a short period of time

Threat Assessment
Once this is completed a thorough threat assessment must take place. This is a continuous process of information gathering, analysis and testing. There are five key elements associated with threat profiles definition and analysis factors:

1. Existence – who or what are hostile to the assets
2. Capability – who or what weapons or means have been used in the past
3. History – what and how often has this occurred in the past
4. Intention – what outcomes or goals does the threat agent hope to achieve
5. Targeting – what is the likelihood that surveillance is being performed on the assets


Next a set of Event Profiles for the threat scenarios must be created. These detailed profiles describe the mode, duration and extent of an incident event as well as mitigating or exacerbating conditions that may exist.

The output of the threat assessment is the determination of threat rating to each hazard and to each asset in the priorities for protection. Assigning a threat rating could be as easy as using high, medium and low as long as you have specifically defined what each one is and also with the use of expert judgment.

As landlords and other interested real estate finance industry partners move towards new standards to mitigate terrorism risk and protect critical infrastructure, the necessity for state-of-the-art tools and systems to mitigate those risks is paramount. CxO’s in corporate enterprises are ever more concerned about emergency preparedness and the continuity of their enterprises. Now that threats to government and business operations are becoming more prevalent, organizations must plan for every type of business disruption from hardware and communications failures, to natural disasters, to internal or external acts of terrorism.

06 April 2005

Operational Risk: BPO Relationships...

Researchers at the McCombs School of Business are working on empirical studies ("Global Sourcing and Value Chain Unbundling", "An Empirical Analysis of Information Processing Requirements in BPO Relationships") that investigate key decision variables in the choice of BPO relationship structure and form. They argue that the primary questions that managers must address to design and effectively manage a BPO relationship include the following:

1. What are the unique operational risks and challenges associated with outsourcing a particular business process? What demands does the outsourced process place on agent capabilities?

2. What governance model will help the firm address these challenges and architect a sustainable relationship that meets its outsourcing objectives?




If you are like most organizations you rely on a portfolio of 3rd parties to supply you with products, services and labor. These supply chain relationships are a key aspect of effective risk mitigation in your enterprise. Here are a few BS 7799 controls to consider:

Section:10.5.5 Outsourced Software Development
Description: Where software development is outsourced, the following points should be considered:
a. licensing arrangements, code ownership and intellectual property rights (see 12.1.2);
b. certification of the quality and accuracy of the work carried out;
c. escrow arrangements in the event of failure of the third party;
d. rights of access for audit of the quality and accuracy of work done;
e. contractual requirements for quality of code;f. testing before installation to detect Trojan code.

Section:11.1.2 Business Continuity and Impact Analysis
Description:
Business continuity should begin by identifying events that can cause interruptions to business processes, including suppliers, e.g. equipment failure, flood and fire. This should be followed by a risk assessment to determine the impact of those interruptions (both in terms of damage scale and recovery period). Both of these activities should be carried out with full involvement from owners of business resources and processes. This assessment considers all business processes, and is not limited to the information processing facilities.Depending on the results of the risk assessment, a strategy plan should be developed to determine the overall approach to business continuity. Once this plan has been created, it should be endorsed by management.

Section:12.1 Compliance with Legal Requirements
Description:
Objective: To avoid breaches of any criminal and civil law, statutory, regulatory or contractual obligations and of any security requirements.The design, operation, use and management of information systems may be subject to statutory, regulatory and contractual security requirements.Advice on specific legal requirements should be sought from the organization’s legal advisers, or suitably qualified legal practitioners. Legislative requirements vary from country to country and for information created in one country that is transmitted to another country (i.e. trans-border data flow).

Strategic Impact: An important concept that binds the above process attributes is the strategic impact of the outsourced process. It is likely that a strategically important business process shares strong interdependencies with other business processes in the firm and is marked by relatively higher volatility and specificity. A process of strategic importance enables the company to provide a "fundamental customer benefit" and make a contribution to perceived customer value. Such processes in the firm are substantially superior to those of competitors and help the firm create new products, services and process improvements in the future. The risks associated with such information- and knowledge-intensive business processes include information poaching and loss of competitive advantage. This is especially pronounced if the provider services other clients in the same business domain as the outsourcing firm.

04 April 2005

US National Preparedness: TOPOFF 3

Now that DHS has reemphasized the need for the National Preparedness Goal in the U.S., it must be time for the TOPOFF-3 exercise.

The U.S. Department of Homeland Security announced April 1 2005 the publication of the Interim National Preparedness Goal (“Goal”). The Goal will guide federal departments and agencies, state, territorial, local and tribal officials, the private sector, non-government organizations and the public in determining how to most effectively and efficiently strengthen preparedness for terrorist attacks, major disasters, and other emergencies.

“In our complex free society, there is no perfect solution to address every security concern,” said Secretary of Homeland Security Michael Chertoff. “But by working together collectively to analyze threats, understand our capabilities, and apply resources intelligently, we can manage risk. The National Preparedness Goal will help us meet this objective.”


The Top Officials exercise (TOPOFF) will be comprised of local, state and national personnel estimated at around 10,000 people. The price around $16M. will produce real-time scenarios in New Jersey and Connecticut. One will be a biohazard and the other a chemical related incident.

The drills will be monitored by top U.S. Homeland Security officials from a command center in Washington, as well as regional centers in New Jersey and Connecticut.

Although no real weapons or bio-agents will be used, officials will respond as if it's the real thing: flooding the area with investigators and first responders in haz-mat suits, dispatching fleets of ambulances to hospitals across the state, and dealing with throngs of "victims" piling up outside emergency rooms.


The lessons learned will be many. The large businesses in the areas of the drill will soon realize that "Shelter-in-Place" may be a reality soon and should take this time to practice themselves. Remember, it may be hours or days before you can leave your office safely. Now is the time to replenish your supplies, food, water and emergency first aid kits.

Do you think you're spending too much time with your team planning? You haven't. Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things go wrong. The organizations whose team has planned for every possible scenario and trained together in live simulations will become the most successful. Their missions will be accomplished on time and within budget.

Incidents of different severity and frequency are happening around you and your organization every day. Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?

01 April 2005

Is Today April Fools Day?

Now that Corillian is merging with InteliData you can be assured that more banks will see their sales reps. They have also recently partnered with Quova to assist in a more comprehensive and integrated offering for anti-phishing solutions.

As banks continue to try and tackle the ID Theft and Phishing threats to operations, the technology is only a part of the puzzle.

The strategy for monitoring, detection and enforcement must be mult-faceted and involve a combination of technologies. More importantly, you must do as Microsoft has done to find out who is behind these crimes. Let's assume you have very deep pockets.

Microsoft has filed 117 civil lawsuits against alleged phishers trying to scam Microsoft customers out of personal information such as credit card numbers.

The lawsuits, filed in Washington, identify large-scale scam operations and seek damages from so-called phishing operations. Phishers typically send out spam e-mail, made to look like official e-mail from a real e-commerce company, asking recipients to click on a link and update their personal information. The link takes consumers to a website that mimics the look of the real company, but collects personal information for ID thieves to use.

The new lawsuits - Microsoft has previously gone after two other phishing schemes - target unnamed defendants who sent spam e-mail and put up websites targeting Microsoft services such as MSN and Hotmail.

Through them, Microsoft will issue subpoenas and attempt to uncover the names of the people behind them, as well as identify support operations such as Web hosting services and mass e-mail services, said Microsoft lawyer Aaron Kornblum.



Is today April Fools Day? Forget about Phishing. It's time to worry about Pharming.

30 March 2005

Corporate Accountability: The New Era of Governance

“No more easy money for corporate criminals -- just hard time.”

George W. Bush signed the Sarbanes-Oxley Act of 2002, the most far-reaching corporate reform legislation since the New Deal in the 30's. The legislation is the result of billion-dollar corporate accounting scandals like Enron, Tyco, and WorldCom, and is designed to send a message to employees that the American public will no longer tolerate corruption in the companies they invest in. Welcome to the new era of corporate governance, where the stakes for wrongdoers has been raised dramatically.

Now with AIG and Warren Buffet under the latest round of questioning, it's further proof we are in a new era of governance.

Spitzer's office and the Securities and Exchange Commission are investigating the questionable use of a product known as finite reinsurance that can be used to make a company appear stronger financially than it really is. The focus of the investigation is a transaction in late 2000 between General Re, a Berkshire affiliate, and AIG, the world's leading insurance company.

Regulators say that the transaction artificially increased AIG's premium reserves, ultimately helping its stock price and its ability to acquire another company.


As Maurice Greenberg, the former CEO of AIG sits and waits for the story to unfold, he must be asking himself how did this happen? In the "New Era of Corporate Governance" the question should be, why did it take so long for it to happen? As stockholders are paying the price of corporate incivility it becomes clear that the real heros in all of this are those in Eliot Spitzer's office.

Without the continuous oversight of our regulators and the people who represent the common stock holder to enforce the law, we will not achieve what we all seek in any business relationship. The truth.

Sarbanes-Oxley and the other laws being chastised by some business executives as over protective and unjust in the quest to reach compliance will eventually achieve their goal. We are almost at the "Breakpoint" in the bottom of the "S" curve where this corporate biologic system will begin to rise and grow again. Where companies investments in education, technology and processes will turn them towards greater investor confidence and therefore greater levels of investment.

The "New Era of Governance" is just around the corner and the companies who continue to see that the investment will eventually pay off will be the real winners.

27 March 2005

Breaking Down Organizational Walls...

The organizational walls are coming down in the risk management department and we have witnessed what Jeremy Ward is advocating in this article. We agree much has to be done to create a collaborative relationship with OPS Risk, INFOSEC, Internal Audit, Security and Finance.

Until recently organisations were able to put operational risk and information security into separate, watertight compartments. Operational risk sat in the audit department and probably reported to the CFO. While information security (if such a function existed) sat in the IT department and reported to the CIO (eventually).

Today this approach is not a true solution to adequate risk management. Today’s information dependent organisation requires the walls of these separate compartments to be broken down.

The most obvious reasons for breaking down the compartments, and the subsequent consequences of failure to do so, are easy to understand. In recent years we have been bombarded with legislation and regulation; such as Basel II (if you’re a bank), the Turnbull report (if you’re quoted on the London Stock Exchange) or the Sarbanes-Oxley Act (if you’re quoted on the New York Stock Exchange). All of these effectively say that if you do not have in place adequate mechanisms for controlling and auditing the flow of information through your organisation; then your company will lose a lot of money, or someone important in it will go to jail – or both.


Operational Risk has much to learn from IT INFOSEC and they have more to learn about the intersections of risk across all the business units. The goal should continue to be to develop a management system that encompasses the entire enterprise.

The conclusion is obvious. Operational risk and information security cannot afford to engage in a battle for who owns the responsibility for business risk. They must agree to a contract of mutual support. Operational risk needs to know more about the threats to, and vulnerabilities of, those vital networked assets; and information security needs to understand more about how to determine the business criticality of the assets for which they are responsible. In short, they need to meet and shake hands over the level three controls.

21 March 2005

Better INTEL Can Make a Difference...

In case you missed this announcement from the Financial Services ISAC, the sector has finally figured out that it's really about the relevance of the INTEL that makes a difference, namely iDEFENSE.

iDEFENSE and the Financial Services Information Sharing and Analysis Center (FS/ISAC) today announced a partnership to equip financial services organizations with intelligence and proactive countermeasures to combat critical cyber threats.

The agreement represents a major initiative for FS/ISAC as the organization aims to fulfill its mission of providing members with the highest caliber and most timely analysis on information security threats. Sponsored by the Department of the Treasury, FS/ISAC has more than 900 chartered members, including banks, credit unions, insurance firms, credit card companies and securities firms. Its board members include executives from Bank of America, Wells Fargo, Merrill Lynch, Goldman Sachs and Fannie Mae.

"The increasingly sophisticated and aggressive cyber threat landscape requires new solutions and approaches to ensure that our members and their customers are fully protected," said Byron Yancey, FS/ISAC’s executive director. "This partnership is a turning point for the security of America’s financial infrastructure: a new front line of defense against cyber attacks."

iDEFENSE’s "flash" cyber intelligence reports will fuel FS/ISAC’s national "urgent" and "crisis" alerts, the first time the industry group has leveraged proprietary threat data to protect the sector. The company is the leading provider of cyber security intelligence for Global 2000 companies, 8 of the top 10 financial services providers and the U.S. government. It engages 170 analysts to research thousands of new malicious codes, software vulnerabilities and hacker activity in 31 countries and 13 languages.

"Electronic criminals inherently have an advantage against their targets — they have the funding, knowledge, creativity and element of surprise to strike first," said John Watters, president and CEO of iDEFENSE. "The key is to mobilize and share actionable intelligence before attacks strike, combining vigilant intelligence gathering and immediate delivery."


Having first hand knowledge of the iDEFENSE operation and the Archer platform that powers the FSISAC, they are well on their way to having the best possible chance to mitigate risks in their organizations.

18 March 2005

CIO: Head of ERM?

Are CIO's as executives best positioned to champion enterprise risk management? This article by Allan Holmes has some merit. Who should chair the ERM committee?

Steve Randich, CIO with Nasdaq, relies on regular tests of his data center's business continuity plans to remind his staff that ERM is a core principle for the organization. About 3,300 companies are listed on the Nasdaq, which processes about 20,000 transactions a second and receives information from about 350,000 desktops and workstations worldwide. If Nasdaq can't operate its transaction systems, it has to close the market. "We're then out of business," says Randich.

After 9/11, it took four months for Nasdaq to permanently relocate its New York City offices. The data center was able to continue operating (although the government shut down the markets for four days), but Randich realized that the company needed a more detailed risk management plan. Nasdaq's new plan included the extra equipment it would need (such as desktops and Internet access), procedures for communicating with employees and alternative work sites in case of a disaster.


We agree that the CIO should be part of the Enterprise Risk Management Committee although we don't agree they should be the chair. If there is any one person that should be considered, it would be the head of Operational Risk. Think of them as the most capable of knitting together the intersections of the physical and digital world, along with the human aspects of internal and external events.

Savvy Operational Risk Managers understand the intersections of various kinds of risk that the organization is facing. That includes the companies in the supply chain and the "Go-to-Market" plans for new marketing and sales initiatives. While the CIO is a key component and certainly data touches almost every aspect of the organization, the CIO may overlook some key facets of the ERM matrix.

If you don't have someone who is in charge of Operational Risk, maybe it's time to appoint or hire an executive for this vital position.

15 March 2005

Security Governance rivals SOX 404...

All enterprises confront a category of unforeseen risk. Such risks hinge on events that “might happen,” but haven’t been considered by the organization and, therefore, yield too little information to disseminate to stakeholders. However, stakeholders can demand a management system for Security Governance that is comprehensive, proactive and relevant. The management system, as provided by executives, board members and oversight committees, includes organizational structure, policies, planning activities, responsibilities, practices, procedures, processes and resources. The system also incorporates a top management strategic policy that focuses on managing risk for Security Governance while reflecting the location, assets and purpose of the organization, enterprise or entity.

In establishing a process for risk assessment, the organization should consider:

· Impact, in the event the risk event is realized;
· Exposure to the risk on a spectrum from rare to continuous, and
· Probability based upon the current state of management controls.

An organization will encounter dynamic strategic security risks. Its executives must use the management system to identify and assess these risks, develop a strategy for dealing with them to achieve Security Governance.

Security Governance is evolving rapidly and taps the thinking of various standards organizations, including OECD, BSI, NIST, ISSA, GAISP, BSA, ITAA, ASIS and dozens of other bodies of influence and knowledge. However, no matter what best practices an organization attempts to standardize on, it must weight the attitudes of the employees and stakeholders.

Unless these stakeholders fully understand the motivation behind tasks and guidelines, the system will fail. The organization that embraces change and introduces a Security Governance framework that manages not only the foreseen human risks but also the unforeseen will greatly enhance its chance of survival. Culture plays a paramount role in the risk for Security Governance because:

1. Any changes in risk management may require changes in the culture and

2. The current culture is a dramatic influence on current and future security initiatives.


Internal controls can provide reasonable assurance that an organization will meet its intended goals. Yet people (Human Factors) will fail an organization in material errors, losses, fraud and breaches of laws and regulations. People will generate constant change, and this cumulative uncertainty mandates a resilient management system for Security Governance that controls risk.

With the system in place, the board of directors soon realizes that managing risk for Security Governance rivals Section 404 of Sarbanes-Oxley as a key to success. In fact, without Security Governance, rules won’t matter and the stakeholders will again ask: How could this happen to us?

14 March 2005

Business Benefits of BS 7799 Compliance...

Here are several business benefits of implementing BS 7799 as a management system for achieving compliance in organizations that are highly regulated:

BS 7799 brings your organization to compliance with legal, regulatory, and statutory requirements including HIPAA, Gramm-Leach-Bliley (GLBA), Sarbanes-Oxley, California SB1386, CFR21:Part 11, EU-Directive, and many others...

Market differentiation due to positive influence on company prestige, image and external goodwill parameters, as well as a possible effect on the asset or share value of the company

Demonstrates credibility and trust – satisfaction and confidence of stakeholders, partners, and customers

Reduced liability risk; demonstrates due diligence; lower rates on insurance premiums

Increases vendor status of your organization · Increase in overall organizational efficiency

Minimizes internal and external risks to business continuity· Management sets the example for appropriate security/privacy practices


The many sources of significant loss events are changing as we speak. Here are a few that should not be overlooked:

·Public perception
·Unethical dealings
·Regulatory or civil action
·Failure to respond to market changes
·Failure to control industrial espionage
·Failure to take account of widespread disease or illness among the workforce
·Fraud
·Exploitation of the 3rd party suppliers
·Failure to establish a positive culture
·Failure in post employment process to quarantine information assets upon termination of employees

Frankly, corporate directors have their hands full managing risk and continuity on behalf of the shareholders. The risk management process will someday have as big an impact on the enterprise as other key functions because shareholders will be asking more questions about the changing landscape of managing risk for corporate governance.

BS 7799, so what? So what? Boards of Directors have the responsibility to insure the resiliency of the organization. The people, processes, systems and external events that are constantly changing the operational risk landscape become the greatest threat to an enterprise. It’s the shareholders duty to scrutinize which organizations are most adept at “Continuous Continuity” before they invest in their future.

11 March 2005

Get Ready for Section 6302...

In the latest US legislation to help prevent terrorist financing, the Intelligence Reform and Terrorism Prevention Act of 2004 is doing just that. Including Section 6302:

SEC. 6302. REPORTING OF CERTAIN CROSS-BORDER TRANSMITTAL OF
FUNDS.
Section 5318 of title 31, United States Code, is amended by
adding at the end the following new subsection:
‘‘(n) REPORTING OF CERTAIN CROSS-BORDER TRANSMITTALS OF
FUNDS.—
‘‘(1) IN GENERAL.—Subject to paragraphs (3) and (4), the
Secretary shall prescribe regulations requiring such financial
institutions as the Secretary determines to be appropriate to report
to the Financial Crimes Enforcement Network certain
cross-border electronic transmittals of funds, if the Secretary determines that reporting of such transmittals is reasonably necessary
to conduct the efforts of the Secretary against money
laundering and terrorist financing.
‘‘(2) LIMITATION ON REPORTING REQUIREMENTS.—Information
required to be reported by the regulations prescribed under
paragraph (1) shall not exceed the information required to be
retained by the reporting financial institution pursuant to section
21 of the Federal Deposit Insurance Act and the regulations
promulgated thereunder, unless—
‘‘(A) the Board of Governors of the Federal Reserve System
and the Secretary jointly determine that a particular
item or items of information are not currently required to
be retained under such section or such regulations; and
‘‘(B) the Secretary determines, after consultation with
the Board of Governors of the Federal Reserve System, that
the reporting of such information is reasonably necessary to
conduct the efforts of the Secretary to identify cross-border
money laundering and terrorist financing.


Translation please. Get ready for additional reporting to the Financial Crimes Enforcement Network in the near future. See FinCEN

10 March 2005

Offshore Outsourcing Revisited...

The risk of offshoring is a growing concern. If this study by Deloitte is correct, your valuable and private financial information is likely to be off shore already.

Deloitte estimates that $356 billion, or 15 percent, of the financial service industry's current cost base is expected to move offshore within the next five years. Further, the range and number of offshored job functions within individual institutions is expected to increase, with the average number growing from two to four functions per institution. In particular, the traditional focus on IT alone, which accounts for 70 percent of current offshore activity, will change to a business-process emphasis. Competitive pressures are the primary motivator for financial institutions to move higher-risk functions offshore.


The banking industry has a list of Offshoring Risks that is in need of greater care and oversight.

Domestic outsourcing and offshoring share most risk characteristics. However, the more complicated chain of control incurred when offshoring financial services and related data may create new risks when compared to domestic outsourcing. Offshoring also introduces an element of country risk to the outsourcing process. In particular, geographic distance from the function and timing lags in reporting heighten the potential risk exposures. Significant offshoring risk areas include:

Country Risk: political, socio-economic, or other factors may amplify any of the traditional outsourcing risks, including those listed below.

Operations/Transaction Risk: weak controls may affect customer privacy.

Compliance Risk: offshore vendors may not have adequate privacy regulations.

Strategic Risk: different country laws may not protect "trade secrets."

Credit Risk: a vendor may not be able to fulfill its contract due to financial losses.

It is currently standard FFIEC examination procedure for examiners to review outsourcing arrangements during examinations. Part of a standardized procedure should include:

Identifying and reviewing contracts between financial institutions and data service providers that allow for subcontracting or subsequent outsourcing to occur;

Determining whether subsequent outsourcing has in fact occurred as indicated in the contract or outside the terms of the contract;

Determining if the financial institution is aware of the subsequent outsourcing and the location of the outsourcing; and

Determining if the financial institution has procedures for monitoring all outsourcing arrangements to ensure adequate controls are in place or the service provider has proper procedures and controls to monitor their outsourcing arrangements.


We recommend that your CSO, CCO and General counsel revisit your last audit on high risk outsourced relationships such as customer data-base type work, including mortgage servicing and customer-assistance/help-desk services.

08 March 2005

You've Been Indicted: The Most Feared Words in the Board Room...

Lew Platt, Chairman at Boeing has done the right thing.

An explicit e-mail led to the downfall of Boeing chief executive Harry Stonecipher, who had been called from retirement to boost the US aerospace giant’s tainted image, it was revealed today.

And if this article by an anonymous CSO is correct, then "Doing the Right Thing" could only be about the rules and policies set down by the ethics committee. Right?

"Directors and executives now must take an active leadership role for the content and operation of compliance and ethics programs," the U.S. Sentencing Commission's statement reads in part. "Companies that seek reduced criminal fines now must demonstrate that they have identified areas of risk where criminal violations may occur, trained high-level officials as well as employees in relevant legal standards and obligations, and given their compliance officers sufficient authority and resources to carry out their responsibilities."

The commission notably adds: "If companies hope to mitigate criminal fines and penalties, they must also promote an organizational culture that encourages a commitment to compliance with the law and ethical conduct by exercising due diligence in meeting the criteria."


Every Fortune caliber organization from financial services to health care has already implemented a pervasive compliance program to mitigate the risk of ending up with the SEC or US Attorney in the lobby.

The catalyst behind these initiatives is generated from the U.S. Sentencing Commission's Organizational Sentencing Guidelines. They allow for more lenient sentencing if an organization has evidence of an "effective program to prevent and detect violations of law."

The Guidelines contain criteria for establishing an "effective compliance program."

These include oversight by high level officers, effective communication to all employees, and reasonable steps to achieve compliance such as:

· Systems for monitoring and auditing
· Incident response and reporting
· Consistent enforcement including disciplinary actions


Yet the corporate incivility continues. Why is it that we can’t pick up the morning paper or listen to the news on the way to work without hearing about a new indictment of a top ranking officer?

Here lies the question many Board of Directors are scratching their heads about these days. How can we avoid these ethical and legal dilemmas and how can they be addressed without creating a state of fear and panic?

That’s when I really learned that this game of business is just about the human factors. It’s really not about the controls, the monitoring or even the awareness programs. It’s about being a model manager, and a model human being.

The odds are it will be the human factors that are going to be what gets you on the steps of the local federal building. And it all comes back to good old-fashioned management 101.

As indicated, the great manager can impact the lives of tens or hundreds of people in your company. Conversely, the uncivil manager can wreak havoc with a similar numbers of lives. The position of management is every so powerful to influence those around them.

Your company wide compliance initiative has the elements that provide guidance for creating a program that the government is likely to look favorably upon. The problem is that these same criteria inadvertently communicate the message that implies building a program based on this formula is enough. It isn’t.

04 March 2005

Fraud: #1 Operational Risk...

We could not agree more with Ron Hagenbaugh in his article in Corporate Boardmember.

To conduct an effective fraud risk assessment follow these steps:

1. Organize and define the assessment objectives with company management and your internal audit committee. Form a team of fraud and control experts, and get senior management and audit committee buy-in: Ask them to communicate their endorsement and sponsorship of both the process and a strong anti-fraud program to the entire organization.

2. Determine the business and accounting process(es) to be assessed and investigated. Usually, the initial processes selected are those where fraud or abuse has previously occurred or that management has identified as critical business processes that may be susceptible to fraud or abuse.

3. Identify potential schemes and scenarios specific to the process(es) to be examined against current controls. Fraud schemes and scenarios should be selected based on the specific business process, the industry, physical location of the process operation and any known frauds or abuses concerning the process.

4. Determine the likelihood of a fraud occurring within each scheme and scenario. The Public Company Accounting Oversight Board has defined risk levels as remote, more than remote or reasonably possible, and probable. If assessing a public company, assess the risk levels in relation to SOX compliance efforts.

5. After the fraud risks for individual processes have been identified, documented, and rated as to risk level, match the controls within each process to the identified fraud risks. Determine the effectiveness of each control in preventing or providing a means of early detection for the fraud risk. Group the risks as to their probability of occurring within the process.

6. Estimate the probable loss in dollars should the fraud or abuse occur. Try to place a value on loss of reputation if that is a possible outcome.

7. Prepare recommendations for strengthening controls and present to management.


One big question on fraud is this. Has Sarbanes-Oxley been any help? A recent survey by Oversight Systems has some interesting statistics:

Of those surveyed, 79 percent report having stronger internal controls as a result of SOX compliance. Nearly three quarters (74 percent) say their companies realized a benefit from SOX compliance. When asked to identify the benefits from SOX, the survey reports that:

* 46 percent say SOX compliance ensures the accountability of individuals involved in financial reports and operations

* 33 percent say SOX compliance decreases the risk of financial fraud
* 31 percent say they have reduced errors in their financial operations
* 27 percent say SOX improvements in the accuracy of financial reports
* 25 percent say SOX compliance empowers the board audit committee by providing it with deeper information, and

* 20 percent say SOX strengthens investors’ view of the company.

However, the bottom-line benefits of SOX compliance seem fuzzier when the group was asked what impact SOX compliance had on shareholder value. Many, 37 percent, of those surveyed say SOX increased shareholder value because investors know they operate as an ethical business, and 25 percent report that SOX boosts shareholder value by building overall confidence in the market. However, 33 percent say SOX compliance created a cost burden that suppresses stock prices, and 14 percent feel that SOX decreased their ability to pay out dividends because compliance expenses are a significant drain on earnings (respondents could select all that applied).


SOX may be expensive, yet we are confident that as most executives realize that this is not another Y2K exercise, they will invest even more wisely in the years to come.

01 March 2005

DHS - Time to Use The Carrot Instead of the Stick...

The US Department of Homeland Security - PSO (Private Sector Office) has begun it's push to get the private sector to do it's share with the "Carrot" instead of the "Stick."

Homeland Security officials in the Bush administration are considering ways to use the insurance industry as a free-market-friendly vehicle to drive chemical facilities, food companies, utilities, and other businesses to take greater precautions against terrorist attacks without heavy-handed new regulations.

The concept of using insurance to spur companies to spend on counterterrorism measures may solve a vexing homeland security problem: Despite improvements the government has made to upgrade security at public facilities since the 2001 Al Qaeda attacks, 85 percent of American infrastructure is privately owned and underprotected.

Any attack on chemical, ground transportation, banking, food, energy, or utility sectors could cause massive destruction and cripple the economy. But companies have lobbied hard to defeat legislation to force them to upgrade their security practices, finding allies among free-market Republicans in Congress.

Proponents hope the insurance proposal will be a sweeping solution to the impasse. The basic idea would be to have the government or each industry develop a minimum set of security "best practices." Then, insurers would audit companies for compliance with those standards, with the power to reduce premiums for those who comply.


Current Situation

The private sector has a fragmented approach to critical infrastructure preparedness in a new “all hazards” worldview. Each trade association with an interest in protecting commercial buildings, malls, hotels and other soft targets is creating policy and direction for its respective membership based on political agendas and other influences by local government and regional initiatives. Local jurisdictions are equally fragmented and looking for funding to train additional CERT (Corporate Emergency Response Team) volunteers and are still waiting for significant funding to have a real impact on their high profile properties. DHS Private Sector Office (PSO) has launched “Ready Business” and is working closely with critical infrastructure sectors to help coordinate communication between constituents and coalitions such as the National Capital Region. In the mean time, our preparedness level is not increasing at an acceptable pace due to a number of issues.

Desired Situation
The private sector needs a rapid and more effective program to extend the DHS Ready campaign for Business into the nation’s critical infrastructures. One way to do this is to use a combination of 15,000+ “Feet on the Street” InfraGard citizen soldiers and cooperation with key industry groups and the real estate sector would provide the framework for rapid implementation of preparedness training and exercises. A smart approach is a “Train-the-Trainer” methodology to provide key incident command, emergency communications, evacuation, first aid, and shelter-in-place skills and knowledge transfer to selected InfraGard members in major metro areas. Working in concert with local officials, members of the Real Estate ISAC and InfraGard Certified Trainers, building owners, landlords and tenant businesses can be trained to handle an “All Hazards” threat scenario. Each identified soft target building or critical infrastructure facility will have a local plan that is rolled up by geographic proximity to its nearest firehouse or emergency response unit and exercised in tandem.

Frank Cilluffo, who until 2003 served as President Bush's special assistant for homeland security, said he is fascinated by the idea of offering less expensive insurance against terrorism to companies that take appropriate precautions. He said it would constitute "a business case for homeland security to ensure that the private sector is fulfilling its share of their responsibility."

The system would encourage companies to protect against limited threats, such as truck bombs or internal sabotage, and the government would guard against greater threats, such as nuclear terrorism.

"Hopefully, these steps, which will be incentivized and/or mandated, will raise the bar higher and improve our countermeasures against terrorism," said Cilluffo, now head of the Homeland Security Policy Institute at George Washington University. "This is not the panacea. This is not the solution. But it takes us a whole lot closer."


In a recent survey conducted by Robert Half Management Resources the top two areas of potential vulnerability and concern cited by CFOs are disaster recovery (37%) and the security of information systems (24%). A common theme between these exposures is the need to better identify and understand the full range of risks that companies face today and the need for all organizations to develop new ways to more effectively manage these risks. By developing cross-company approaches for addressing all areas of risk, companies will begin to move toward a systematic, enterprise risk management process that most effectively reduces risk and controls cost.

"These two top areas of vulnerability in the eyes of a Chief Financial Officer stem from the perceived weaknesses in the organizations readiness and from the constantly evolving regulatory pressures to comply with new laws," said Peter L. Higgins, Managing Director of 1SecureAudit. "Operational Risks that evolve from inadequate or failed processes, people, systems or from external events are on the CFOs mind, and this includes acts of terrorism."