25 February 2005

The Modern Day "Bonnie and Clyde"...

As Bank of America now joins ChoicePoint to try and explain the theft of not just thousands but millions of data records, one has to wonder. Does the modern "Bank Robber" need a mask and a weapon to pull off a six figure heist?

Not so according to some of the latest operational risk losses by major financial services institutions. The modern day "Bonnie and Clyde" only needs to purchase one of the latest downloads from the Internet to create a portfolio of bait for a contemporary "Phishing" expedition. Or in the case of B of A, a supplier who seems to have lost a few data tapes on their way to a secure location.

If it isn't apparent already, the real issue here is the lack of controls and auditing of the supply chain of outsourced services or the key lego blocks in the Enterprise Architecture.

Sen. Charles Schumer, a New York Democrat, said he had been informed by the Senate Rules Committee that the data tapes were likely stolen off a commercial plane by baggage handlers.

"Whether it is identity theft, terrorism or other theft, in this new and complicated world, baggage handlers should have background checks and more care should be taken for who is hired for these increasingly sensitive positions," Schumer said.

Bank of America, based in Charlotte, North Carolina, said it will continue to monitor government cardholder accounts included on the data tapes and cardholders would be contacted if unusual activity is detected."


It won't be long before the Privacy Advocates give way to the reality that it's time to seriously revisit authentication beyond today's US norms.

One of the key drivers behind the push to take up biometric technologies is that governments are beginning to mandate that biometric identifiers such as facial images and fingerprints be used in official documents, including passports. And biometrics is also seen as essential for the provision of e-government services to citizens to ensure accurate authentication to prevent fraud.


However, in the long term, biometrics, by their very nature, will compromise privacy in a deep and thorough fashion. If and when face-recognition technology improves to the point where surreptitious cameras can routinely recognise individuals, privacy, as it has existed in the public sphere, will in effect be wiped out. No doubt there will be some benefits: fraud, in particular the persistent and increasingly annoying problem of identity theft, might be substantially reduced if biometric-identification systems, introduced in the form of passports, visas and identity cards, become widespread. But privacy advocates argue that such benefits are not worth the risk of “function creep”—that once biometric passes have been issued by governments, it will be tempting to use them for all sorts of things, from buspasses to logging on to your office PC.
See the Economist to see what the experts were thinking two years ago.

This of course won't have much impact on the savvy baggage handlers who are now becoming this generations equivalent of "Bonnie and Clyde".

23 February 2005

Why just having a Disaster Recovery Plan is not enough!

Association of Contingency Planners | Washington DC Chapter | February Chapter Meeting

Disaster Recovery Plans are only part of the picture! Do not forget your most important asset – your employees! In the fast moving readiness wave of global assurance and operational contingency, there is an important element missing from many plans. They are all predicated on having the key people actually surviving the disaster. Shouldn’t you be just as concerned with getting through the disaster when and as it occurs? Remember, in large-scale disaster, the professional rescuers may be hours or even days away from responding.

"FEMA defines an emergency as related to businesses as “any unplanned event that
can cause deaths or significant injuries to employees, customers or the public; or that can shut down your business, disrupt operations, cause physical or environmental
damage, or threaten the facility’s financial standing or public image.”


Obviously, there are many events that can be classified as emergencies. Of primary importance is creating a plan for dealing with various types of emergencies that may happen to your business. While you may not initially plan for every type of emergency, it is prudent to at least plan the likely scenarios and always try to improve your emergency response to other scenarios over time. This requires an “All Hazards” approach to your preparedness and response. All hazards planning are a clear step in the process of making sure your organization can survive an emergency event. All hazards planning include operational risks dealing with people, processes, systems and external events.

22 February 2005

NFPA 1600: Are you Ready?

NFPA 1600 Included in the Intelligence Reform and Terrorism Prevention Act of 2004 Senate Bill : S.2845

Passed by the U.S. Congress and signed into law by the President on December 17, 2004 (Public Law 108-458)

Intelligence Reform and Terrorism Prevention Act of 2004 (Enrolled as Agreed to or Passed by Both House and Senate) SEC. 7305. PRIVATE SECTOR PREPAREDNESS.

(a) FINDINGS- Consistent with the report of the National Commission on Terrorist Attacks Upon the United States, Congress makes the following findings:

(1) Private sector organizations own 85 percent of the Nation's critical infrastructure and employ the vast majority of the Nation's workers.



(2) Preparedness in the private sector and public sector for rescue, restart and recovery of operations should include, as appropriate--

(A) a plan for evacuation;

(B) adequate communications capabilities; and

(C) a plan for continuity of operations.

(3) The American National Standards Institute recommends a voluntary national preparedness standard for the private sector based on the existing American National Standard on Disaster/Emergency Management and Business Continuity Programs (NFPA 1600), with appropriate modifications. This standard establishes a common set of criteria and terminology for preparedness, disaster management, emergency management, and business continuity programs.

(4) The mandate of the Department of Homeland Security extends to working with the private sector, as well as government entities.

(b) SENSE OF CONGRESS ON PRIVATE SECTOR PREPAREDNESS- It is the sense of Congress that the Secretary of Homeland Security should promote, where appropriate, the adoption of voluntary national preparedness standards such as the private sector preparedness standard developed by the American National Standards Institute and based on the National Fire Protection Association 1600 Standard on Disaster/Emergency Management and Business Continuity Programs.


See NFPA 1600

21 February 2005

ID Theft: SB-1386 on it's way West...

The latest ID Theft scandal with ChoicePoint is just the "Tip of the Iceberg".

The reputational losses will soon be felt as firms like Lexis Nexis pick up accounts from the fall out of this unfortunate criminal act. "Social Engineering" and plain old fraud will continue to haunt the companies who make it there job to know who we are, right down to the places we eat and where we shop.

If you get the warning letter from Choicepoint that you are one of the 145,000 people whose identity could be compromised, what are you going to do?

Disclosure of the incident was required under California's SB-1386,which took effect July 1, 2003. According to the law, any state agency, person, or business that does business in California and owns or licenses electronic data that includes personal information, is required to disclose any data security breach to California residents whose unencrypted personal information may have been accessed by an unauthorized person.


Last year, according to the Federal Trade Commission, consumers reported fraud losses of more than $547 million. Internet-related fraud accounted for 53% of all reported fraud complaints. According to the Better Business Bureau, 9.3 million Americans were victims of identity-theft fraud in 2004.

These are operational risks that not only the financial and health care institutions are responsible for mitigating, but also the Data Information Brokers who sell and share our identities to direct marketing firms. Remember that there really is only one way to keep yourself protected. Constantly monitor your identity and the details that exist in these companies databases. Make sure it is accurate. Put alerts on your account for suspicious activity. Consider using your middle initial or entire middle name when opening new accounts. This will help you differentiate yourself from every one else who shares your same first and last name.

Finally, review the security and privacy policies of your most trusted institutions. You will be amazed at what you have already accepted them to do with your personal information.

17 February 2005

DNI: Gods Speed...

President Bush on Thursday named his top representative in Iraq John Negroponte as the new DNI or director of national intelligence, a position created as part of the investigation into the Sept. 11, 2001 attacks.

The role of national intelligence chief emerged an investigation into lapses before the Sept. 11 attacks prompted Congress to overhaul the nation's intelligence efforts in 50 years. As part of the Intelligence Reform and Terrorism Prevention Bill of 2004 and in response to what members saw as failures in communication between the country's intelligence agencies, Congress called for one position to direct national intelligence.

The new position will oversee 15 agencies including the CIA, according to Reuters, and as its chief Negroponte will be charged with giving the president daily intelligence briefings.

"If we're going to stop the terrorists before they strike, we must ensure that our intelligence agencies work as a single, unified enterprise," the president said.


If we are forecasting a terrorist strike in the US as Porter Goss and company are predicting, then Mr. Negroponte has accepted the job between a "bomb and a hard place."

In a Senate Intelligence Committee hearing, CIA Director Porter Goss said the United States still faces threats from Islamic extremists groups such as al Qaeda, who are using the war in Iraq to recruit terrorists from around the world.


With an annual budget estimated at $4 Billion, we are going to eventually find out why all of the intelligence in the universe will not prevent another attack on the American Homeland. In the mean time, the private sector itself should be spending more time and money on preparing their respective employees, suppliers and stakeholders in the event of another attack on our economy. If business waits for government to protect its assets, critical infrastructure or overall well being, business will again be disappointed if and when an attack occurs.

If you are the CEO or Chairman of the Board, what are you going to do to protect your people, processes, systems and supply chain assets from an event as predictable as the next major earthquake? It's only a matter of when. Not what or how.

As President Bush so kindly stated to John Negroponte today at the press conference podium: "Gods Speed".



16 February 2005

Operational Risk: Outsourcing

BIS has a white paper on outsourcing in the Financial Services Sector

Case study 4: OCC action against a bank and service provider

In 2002, the Office of the Comptroller of the Currency (OCC) in the USA took enforcement action against a Californian bank and a third-party service provider to the bank. The service provider originated, serviced, and collected certain loans booked by the bank in 18 states and the District of Columbia. Among other things, the service provider failed to safeguard customer loan files. The files, which represented loans carried on the books of the bank, were discarded in a trash dumpster in 2002.

The OCC alleged that the improper disposal of loan files resulted in violations of laws and regulations. The OCC also determined that the service provider committed unsafe and unsound practices that included a pattern of following the policies and procedures of the bank and a pattern of mismanagement of the bank's loan files. This case demonstrated the risks national banks expose themselves to when they rent out their charters to third-party vendors and fail to exercise sound oversight.
In the case of the bank, the OCC found that it failed to manage its relationship with the service provider in a safe and sound manner. In addition to violating the Equal Credit Opportunity Act and the Truth in Lending Act, the bank violated safety and soundness standards and also violated the privacy protections of the Gramm-Leach-Bliley Act, which sets standards for safeguarding and
maintaining the confidentiality of customer information. These violations and unsafe and unsound practices led to a cease and desist order against the bank. The order required the bank to pay civil money penalties and to terminate its relationship with
the service provider.

The service provider also paid a sum in penalties and was ordered to not enter into any agreement to provide services to a national bank or its subsidiaries without the approval of the OCC. To protect the privacy rights of consumers, the order also required the bank to notify all applicants whose loan files were lost. This notification was to advise the consumer of any steps they could taketo address potential identity theft.

15 February 2005

Relief for the "A" word...

The thought of the "A" word (Audit) brings shortness of breath to many in executive management these days. As this Audit Agitation continues to occur, many corporate managers are welcoming their next audit. As this anonymous CSO so clearly states:

What do you do when your customers want you to do an independent security audit—and your CEO doesn't?

Whether your CEO is backing any initiative to improve the performance of the enterprise they still want to know what it really means to the organization. In this case, the CSO uses the fact that customers are asking for it. And because the customer is the almighty entity to serve and listen to, then we must have to comply.

While customers do provide the core catalyst for many corporate projects, the first priority is to make sure that you select the correct solution for what your customer is really asking for. In the case of a customer asking for a SAS 70, many uninformed CEO's would respond with a large question mark above their head.

For those who don't know, a SAS 70, or Statement on Auditing Standards No. 70, is an internationally recognized standard developed by the American Institute of Certified Public Accountants. A SAS 70 audit represents that an IT services provider (for example, a financial services organization) has been through an in-depth audit of its control activities, which generally include information technology, security and related processes. The Sarbanes-Oxley Act of 2002 makes SAS 70 audits even more important to the process of reporting on effective internal controls at IT services organizations. That's because the reports signify that a service organization has had its control objectives and control activities examined by an independent accounting and auditing firm, as Section 404 of Sarbanes-Oxley requires.


All of the SAS 70 audits will never change the culture or the skills of the people who are responsible for the areas of the organization that a SAS 70 audits. In many cases, the fear is that there will be so many "red lights" at the end of the examination that they will not get a favorable opinion letter. One way to avoid this potential hazard, is to inject the organization with a management system far in advance of the SAS 70 audit. A good example is the BS 7799 Information Security Code of Practice.

A brief history of BS 7799


In the early 1990s concern was growing about the security of information due to the proliferation of computer networks and the reliance of businesses on electronic data collection and processing. Security threats to organisations include fraud, espionage, sabotage, vandalism, fire, flood, computer hacking and computer viruses. The concern of the UK government’s Department of Industry (DTI) led them to ask BSI to work with businesses and other concerned communities to develop a standard that would increase awareness of security issues and suggest controls to help protect information within all types of organisations in the UK.

BS 7799 was originally published in 1995 to give guidance on implementing Information Security Management and was substantially revised in April 1999 to take account of developments in the application of information processing technology, particularly in the area of networks and communications. It also gave greater emphasis to business involvement in and responsibility for information security. New controls were included in areas such as e-commerce, teleworking, mobile computing and so on but remained technology-independent.

Against this backdrop was the implementation of the revised UK data protection legislation, the 1998 Data Protection Act, which includes increased obligations on organisations to adopt appropriate data security measures. The objective of this is to prevent unauthorised or unlawful processing and accidental loss or damage to data that relates to living individuals. The new legislation has been extended to include non-computerised, or manual, records. Material held in filing cabinets, index cards, microfilm collections and videotape collections are now also subject to the Act. Consequently, BS 7799 also covers security of all types of information, held both electrically and non-electronically.


By implementing a culture of risk management utilizing the published standards of BS 7799 the enterprise is not only becoming more prepared for the SAS 70, they are well on their way to achieving compliance with US and other Global standards. Relief for the "A" word is only a few key strokes away. See BSI

14 February 2005

Operational Risks are Taking Executives by Storm...

Executive Summary

There is a growing threat on the business horizon. The risk of loss from inadequate or failed processes, people, and systems or from external events is taking executives by storm. This definition of Operational Risk also includes legal risk, which is the risk of loss from failure to comply with laws as well as prudent ethical standards and contractual obligations. It also includes exposure to litigation from all aspects of institutions activities. In the course of a single day the organizational exposure to threats ranges from low to severe on the horizontal axis. It isn’t until you put the vertical spectrum into consideration that you arrive at your "Operational Risk Profile" for that particular slice of time. This vertical axis is the range of consequences that would impact the business should the threat event actually occur. It ranges from minor to disastrous. Each day our organizations live in a dynamic spectrum of tolerable and intolerable threats to our most precious corporate assets
.

The Take Away

While you were in the Board of Directors meeting, your Operational Risk Profile changed. When you were asleep last night it changed again. The people, processes, systems and external events are interacting to create a new and dynamic threat matrix for your organization. Who is responsible for Operational Risk Management in your business? Everyone is. You see, if everyone in the organization was able to understand and perform the mission flawlessly, then the business could stay in the lower left quadrant. This is where the threat exposure is low and the consequences are minimal. This is exactly why you are spending less and less time here. Only a guarded few understand the mission of operational risk management in your company. Only a guarded few can do it flawlessly. If you want to protect your corporate assets better than you do today, then turn those guarded few into the mission ready many.

10 February 2005

Why geolocation?

Quova has their act together when it comes to compliance and security issues for e-commerce.

The idea of the Internet as a borderless business realm, free of "real world" rules, has been exposed as a myth. While any company of any size can deploy an economic presence online, true e-commerce success has turned out to be a function of —and dependent on —the same business principles that determine success in the brick-and-mortar world. And one of those principles is geographic knowledge. Geolocation — knowing where the online customer is coming from — is as vital to e-commerce as the location of a store is to offline business operations. Consumers have distinct regional preferences based on where they live, and the online merchant must tailor his products, marketing strategy and messaging content to the customer’s language, currency and cultural priorities to earn his business — and his loyalty. Fraud is significantly higher in cyberspace, and the originating location of the transaction is a key indicator to its fraud risk. And both regulations and digital rights vary by jurisdiction, so the business-critical issue of compliance is heavily dependent on the geographic knowledge that can only be provided by a best-practice geolocation solution.


The knowledge that online fraud is frequently a geographically—based phenomenon, with 60% of fraudulent transactions emanating from just 15 nations, has provided a focal point for combating the problem. Leading companies in a variety of industries have incorporated Quova's GeoPoint as a key element in a "best practices" security solution for online fraud prevention. Quova has leveraged this experience to develop new sources of information and enhanced data analysis services specifically designed to protect against fraud and preserve assets and revenues. See Quova

08 February 2005

OREA: Operational Risk Enterprise Architecture

UBS has their own interpretations of Operational Risk and it's definitions. Of particular note is this:

Operational Risk is the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external causes, whether deliberate, accidental or natural. It is inherent in all our activities, not only in the business we conduct but also from the fact that we are a business – an employer, owning and occupying property, and holding assets, including information, belonging to ourselves and our clients. Our operational risk framework is not designed to eliminate risk per se but, rather, to contain it within acceptable levels, as determined by senior management, and to ensure that we have sufficient information to make informed decisions about additional controls, adjustments to controls, or risk mitigation efforts.


Without an effective Operational Risk Enterprise Architecture (OREA) an institution is driving blind in a blizzard of incidents that increases their potential for losses and diminishes their performance. In order to make certain that you have sufficient information in order to make informed decisions, you must have a system. Not only a management system. But a software system to provide relevant and actionable intelligence.

When operational risk ‘events’ occur – actual failures of processes, people or systems – we assess their causes and the implications for our control framework, because an event such as a virus attack or a customer complaint, even if it does not lead to a direct or indirect financial loss, may indicate that our standards are not being complied with or that they are ineffective, and that remedial action must be taken. --UBS


OREA enables enterprises to establish a cohesive framework for enterprise risk management in their organizations. OREA is a management system supported by an enterprise software platform that enables organizations to automatically collect, manage and distribute real-time operational risk content. This includes homeland security alerts, business continuity policies, emergency response procedures, control standards, facilities and IT assets, baselines, threats/vulnerabilities and delivers education and awareness programs to customers, employees and partners.

In light of new global terrorist threats, government regulation, increasing investor scrutiny, continuous litigation and changing response to risk, the stakes for public companies and complex organizations have never been more extreme. The solutions never more challenging. Today more than ever, it is vital that senior executives and board members have all the information, tools and answers they need to fulfill their fiduciary duties.

07 February 2005

Is Your CIO Getting More Complex?

If this Optimize survey is an indicator, the CIO's job is becoming more complex each day.

The CIO's role continues to evolve, and by all indications the job isn't getting any easier. In addition to overseeing day-to-day technology needs, IT executives increasingly must generate new business opportunities, contribute to regulatory-compliance efforts, bolster information security, reduce risk, and improve supply-chain efficiency.

How well-equipped are CIOs to meet these growing responsibilities and where are they turning to gain additional expertise? Are companies doing enough to help IT support the business and take advantage of new technologies, even as security and regulatory compliance take up more time and resources? This month, Gap Analysis examines the CIO's expanding role.

Multifaceted CIOs Conventional wisdom says the CIO's role is becoming more complex, particularly with the addition of regulatory-compliance and risk-management responsibilities.


More CIO's should make time to have lunch with external partners and the CFO, CRO and CEO than ever before. New regulations such as SOX and other new emphasis on Anti-Money Laundering are keeping everyone on their toes and the CIO needs to understand the big picture to see how they can achieve corporate goals.

And yet only 22% of the business and technology managers surveyed expect their CIO or VP of IT to work more closely with external business partners in supply-chain development during the next 12 months. A greater number (49%) said the CIO will work with external partners on business-process improvements, development of new-business opportunities (46%), information security (46%), regulatory compliance (44%), risk management (42%), and application development (41%).

04 February 2005

U.S. Public Readiness Index...is Business Ready?

The Public Readiness Index is on the way and the question is: Is business ready?

In one of his last public speeches as the head of the U.S. Department of Homeland Security, Secretary Tom Ridge shared his insights about critical next steps for public preparedness, and encourage a ground-breaking "public readiness index" for communities.

Ridge made his remarks at a breakfast event hosted by the Council for Excellence in Government tomorrow, Friday, Jan. 28 at 8 a.m. at the Willard Hotel in Washington.

In conjunction with Ridge's remarks, The Council for Excellence in Government, in partnership with the American Red Cross, the George Washington University Homeland Security Policy Institute, and the U.S. Department of Homeland Security will announce plans to create a Public Readiness Index. The Index will gauge the readiness of citizens, schools, businesses, and other community organizations to respond to emergencies -- from terrorism to public health emergencies and natural disasters -- and allow individual citizens and community leaders to measure, track and address gaps in local preparedness.

More than 100 leaders in the nation's homeland security enterprise have already signed a commitment to work together to create the Public Readiness Index, which will be independent from government.


The "Public Preparedness, A National Imperative" Report is 52 pages of great information from the consortium of "Brain Power" who assembled in July last year. Their conclusion is summed up with the following quote:

“I know no safe depository of the ultimate powers of the
society but the people themselves; and if we think them not enlightened enough to exercise their control with a wholesome discretion, the remedy is not to take it from them, but to inform their discretion.”

—Thomas Jefferson

If we can interpret Mr. Jefferson's and the consortiums conclusion correctly, business is in for a whole lot of readiness exercises. Again, the question remains: Are they ready?

03 February 2005

Terrorism Risk Management for Critical Infrastructure Protection

The process and systems for managing Terrorism Risk are changing as the commercial real estate finance and building owners or developers strive to establish new standards. Critical Infrastructure Protection is a national priority. The key catalysts for change could further motivate implementing new risk reduction programs and measures.

Some of the key catalysts for change are:

Insurance – those institutions that are sharing risks that a building owner faces.

Finance – banks, REIT’s (Real Estate Investment Trusts), and others such as pension funds that provide the capital for investments in commercial infrastructure.

Regulation – Federal, State and Local jurisdictions that regulate building design, construction and operations.

Overall Terrorism Risk Reduction begins with these key catalysts in concert with owners of critical infrastructure, whether that is an office building, a hospital or a hotel. These soft targets are where the risk management decision-making is already taking new directions.

In order to introduce new changes in process or design that impacts the physical or operational aspects of buildings (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. First however, we must understand the character of terrorism risk in critical infrastructure and the tools currently available to help manage that risk.

For more information see 1SecureAudit

01 February 2005

Basel II: Investment Advisors Operational Risks

If Pat McAnally from Sungard is correct, then Information Technology Risk is here to stay especially when it comes to Continuity of Business Operations.

"Basel II represents the first time technology entered the definition of operational risk," McAnally says. "In Basel it’s the first time we’ve seen this enter the lexicon—normally it’s all about credit risk and liquidity and market portfolios. We’re hearing from our clients that it’s trickling down even to institutions that are not top-tier because they believe that eventually, if the big firms will have to adhere to that, then they will, as well. And the whole issue of it coming out of some of the European accords as the market moves more into global outsourcing of business processes means it doesn’t matter if you’re headquartered in the US if your processes are being managed elsewhere."

McAnally sees similar beefed-up business continuity requirements in the SEC’s new mandates for hedge funds and investment advisors.

"From the hedge fund perspective, the SEC’s registration rule follows rules 206 and 38A for registered investment advisors passed last February," she says. "These rules require board approval for a chief compliance officer, and specifically spelling out security and privacy, and they’re specifically spelling out business continuity plans. So if you want to register as an investment advisor with the SEC, if that’s important to your business model, then they’re requiring those things."

For hedge funds with institutional investors and that utilize incubators, ASP providers or other third parties for their business continuity function, McAnally recommends extensive due diligence—fund managers themselves should make sure their providers can duly support any business interruption.

"If institutional investors are not careful, they’re going to be exposed to risks that are not under their control, and smaller hedge funds utilize things like technology incubators," McAnally says. "You’ve got to find out if they did their due diligence to see what the provisions are for availability, for continuity."

25 January 2005

Lessons Learned...

What did the US learn about security from the Presidential Elections and the respective conventions in New York and Boston? Michael Smith and Fred Klapetzky remind us of a few of them:

Lesson 1: Preparation Equals Prevention

Lesson 2: Security Saturation makes an Attack more Difficult

Lesson 3: Heightened Awareness makes all the Difference

Lesson 4: Monitoring News Coverage can be Helpful


All of the companies and organizations in these two metro areas should be better prepared than others in the country, right? A recent study (8/2004) by AT&T entitled, "Disaster Planning in the Private Sector: A Post 9/11 Look at the State of Business Continuity in the U.S., surveyed 1000 executives from 10 large metro areas. The survey indicated, surprisingly, that New York and Washington, DC were among those least prepared. In both cities, nearly 25% of companies lacked a plan. According to the survey, even those with BC plans are failing to test or update them on a regular basis. See BC Study

Let's just hope the convention has changed the stats in NYC.

24 January 2005

Compliance is a Strategic Differentiator...

We have to agree with Simon Moss of Mantas.

Prior to September 11th and the USA PATRIOT Act, financial institutions had a similar outlook and level of investment into their anti-money laundering efforts. "The systemic 'wall' to stop money launderers was generally at the same height," says Moss.

Differences in the size of that wall are beginning to emerge. "Over the last three years, firms have been making decisions that have essentially changed that landscape," notes Moss. "The firms that invest more into a serious culture of awareness, serious technology, serious training, and take this problem seriously, will drive money launderers or fraudsters or employees looking to do malfeasant actions to other institutions."


The feds are coming to an institution near you, and they will most likely be the neighborhood or community regional bank. These unfortunately are the institutions that the OCC and other US federal regulators are concerned about. Their programs are going to be tested for CIP (Customer ID Programs) compliance and other BSA/AML/OFAC related issues.

20 January 2005

ChoicePoint: Your Identity is Big Business...

Why are people getting nervous about companies like ChoicePoint? This article in the Washington Post by Robert O'Harrow comes from his book, "No Place to Hide," published by Free Press, copyright 2005. O'Harrow also received financial assistance from the Center for Investigative Reporting. He outlines the arguments from both sides of the "Big Brother" issues:

Now the little-known information industry giant is transforming itself into a private intelligence service for national security and law enforcement tasks. It is snapping up a host of companies, some of them in the Washington area, that produce sophisticated computer tools for analyzing and sharing records in ChoicePoint's immense storehouses. In financial papers, the company itself says it provides "actionable intelligence.


The question remains whether legislation will ever have as much control over ChoicePoint as they have over companies like Equifax or the other credit reporting agencies. However, everyone must accept that our lives are about full disclosure of who we are and what our historical "Modus Operandi" can tell someone about how we might act into the future.

Public information is there because each one of us has opend a bank account, filled out a credit application, applied for a job and traveled on an airplane. ChoicePoint is there to make sure that risks are managed and losses are mitigated. Period.

One only has to imagine in these times of Identity Theft and Suspicious Activity Reports how important it is for the good and law abiding citizen not to be confused with the person with a questionable history. Frankly, I don't want to be mixed up with the other John Q. Public's on the planet. All the decisions I have made in my life have defined who I am, the zip code I live in, the car I drive and the schools and jobs that I've had.

There is one word of advice for those who don't mind the fact that their information is available to any one who wants to buy it. Make sure that it is accurate. This is where the Fair and Accurate Credit Transactions Act (FACT Act) and other legislation allows the consumer to get access to a majority of the information on file and to see that it is correct. If you can't live with what you are reading, then maybe it's time to make some changes in your life.

17 January 2005

COSO: Operational Risk Standard?

Will COSO become the Operational Risk standard for Basel II? This paper by Patrick McConnell argues:

The wording of Basel II is sufficiently vague that banks are in danger of developing internal ORM systems that run the risk of not complying with interpretations of Basel II by local supervisors.

However, there are mature frameworks2 from other industries upon which the processes of Operational Risk Management could be based.

In particular, there are two risk management standards - AS/NZS 4360/2004 and COSO/ERM – that, alone or in combination, could satisfy the requirements of Basel II for systems that are ‘conceptually sound’; and

The adoption of operational risk management processes that are based on proven, practical and usable standards, should reduce the overall costs to the industry of complying with Basel II.


COSO notes that the ERM Framework is “purposefully broad”, capturing “key concepts fundamental to how companies and other organizations manage risk, and may be applied across “organizations, industries, and sectors.”

13 January 2005

People: Travel Risk Management...

This iJet advertorial explains many of the benefits of having a travel risk management provider for your global corporate executives.

"They were rushing to catch the overnight train and wondered whether that was a secure option. With the train leaving in five minutes, he asked if they should get on? He was advised to take the train only if the meeting was absolutely time-critical. If they took the train, he was cautioned to stay awake for the second half of the trip because people had recently been robbed, removed from the trains and beaten up after crossing into Macedonia."


Combining real-time intelligence with a focused surveillance and threat detection-training program is exactly what savvy corporate executives and Chief Security Officers are looking for from a single source. Personnel threat management is a prudent risk mitigation solution. This combination is one key strategy to mitigate the operational risks associated with key personnel in any global organization.

Without the application of survivability and surveillance skills with relevant intelligence, employees traveling in harms way will continue to be at significant risk. The CSO is responsible for getting the correct INTEL and even more important, making sure those employees can take care of themselves without having to rely on third party executive protection or outsourced security firms. Sometimes you just have to think and act on your own.

10 January 2005

OFAC Compliance in U.S. Financial Institutions...

Foreign Assets Control Regulations for the U.S. Financial Services industry is a vital area of operational risk management in the enterprise. Institutions need to make sure that their employees and not just the compliance officer are enforcing the regulations.

The Office of Foreign Assets Control (OFAC) administers a series of
laws that impose economic sanctions against hostile targets to further
U.S. foreign policy and national security objectives. Economic sanctions
are powerful foreign policy tools. Their success requires the active
participation and support of every financial institution. The use of
sanctions by the U.S. goes back to the earliest days of the Republic
through trade embargoes, blocked assets controls, and other commercial
and financial restrictions. Many of them have been multilateralized
within the global community against pariah countries, as well as being
used against groups, such as narcotics traffickers and terrorists, who
threaten the security, economy, and safety of the United States.
Management of sanctions on the U.S. side is entrusted to the Secretary of
the Treasury.


It is often difficult to balance the demands of Federal and State bank
examiners with limitations on time, resources, and manpower imposed
by bank management. While every financial institution must comply
with the same laws and regulations, no one compliance program can be
prepackaged for everyone in the open marketplace. Every program must
be tailored to meet the needs and structure of individual financial
institutions.


"financial institutions" include:

* banks, including:
o insured
o commercial
o trust companies
o private bankers
o U.S. branches of foreign banks
o credit unions
o thrift institutions
* introducing brokers
* commodities broker dealers
* commodity trading advisors
* commodity pool operators
* securities broker dealers
* futures commission merchants
* issuers, redeemers or cashers of travelers checks, checks, money orders, or similar instruments
* operators of credit card systems
* telegraph companies
* insurance companies
* loan or finance companies
* investment bankers or companies
* persons or companies involved in real estate closings and settlements
* currency exchanges
* casinos, card clubs, and gaming establishments
* money transmitters
* pawnbrokers
* travel agencies
* automobile, airplane and boat dealers
* dealers in precious metals, stones or jewels
* U.S. Postal Service or any agency of U.S., state or local government carrying out a duty or power of business

Under the provisions of the Patriot Act, the Department of Treasury has, or soon will specify anti-money laundering compliance program regulations specific to each above-listed industry. The Patriot Act, at a minimum, requires that these programs include:

1. the development of internal policies, procedures, and controls;
2. the designation of a compliance officer;
3. an ongoing employee training program; and
4. an independent audit function to test programs.

Each financial institution is also required to implement a Customer Identification Program (CIP) that includes reasonable procedures to:

1. collect identifying information about customers opening an account
2. verify that the customers are who they say they are
3. maintain records of the information used to verify their identity
4. determine whether the customer appears on any list of suspected terrorists or terrorist organizations

For more information on how you can tailor your compliance program for your institution contact 1SecureAudit who can provide you with:

Compliance Policies & Procedures Customization

> Employee Training

> Due Diligence & Internal Investigations

> Automated Systems for SDN

> Independent Audits

> Anti-Money Laundering Compliance Programs

06 January 2005

Ops Risk for Tier II Institutions...

Operational Risk is not just for the big banking institutions any longer. The latest research from Financial Insights indicates that the ramifications of Basel II are impacting four key areas of U.S. financial institutions:

1. Integration difficulties. Although most large institutions have robust risk-management processes, there's much to be done to achieve Basel II compliance. Most risk processes and systems that are currently used grew up within the individual silos of particular business units. The systems aren't integrated and may have different data requirements and formats.

2. New competitive pressures. Even small banks that aren't required to comply with Basel II will face peer pressure, and they may need to comply anyway. If they don't comply, they'll be at a competitive disadvantage.

3. Consistent methodologies for different risks. Regulators require that different risks be treated the same. Institutions using the advanced internal-ratings-based approach for credit and market risk must also use the advanced-measurement approach for operational risk. This poses problems since credit and market risk are well-established practices in most firms, but operational risk is not.

4. Continuing presence of silos.
Silos between business units and systems must be removed for effective risk management. This task is especially daunting for larger institutions, since there are more people and systems involved.

04 January 2005

What is your 2005 Corporate Resolution?

If you don't have one yet, consider this one:

A Model 2005 Operational Risk Resolution

The organization shall develop, implement, maintain and continually improve a documented risk management system. Identify a method of risk assessment that is suited for the organizations business information to be protected, regulatory requirements and corporate goverance guidelines. Identify the assets and the owners of these assets. Identify the threats to those assets. Identify the vulnerabilities that might be exploited by the threats. Identify the impacts that losses of confidentiality, integrity and availability may have on the assets. Assess the risks. Identify and evaluate options for the treatment of risks. Select control objectives and controls for treatment of risks. Implement and operate the system. Monitor and review the system. Maintain and improve the system.


If you can agree with this then you are already a candidate for implementing a management system and becoming a BS 7799 compliant organization.

For more info see: BSI Management Systems

03 January 2005

Tsunami Contingency Planning and Early Warning...

The latest catastrophic Tsunami natural disaster as a result of a huge undersea earthquake reminds us of the need for effective contingency planning and preparedness. The warning signs and detection devices can only go so far in helping with the potential threats that our planet throws our way.

This article by Beldeu Singh compares the sequence of events and makes the point for a more effective early warning system.

Firstly, it is common knowledge that undersea earthquakes cause tsunamis and these waves can come ashore within minutes of nearby earthquakes. An undersea earthquake must have been picked up by some seismic center in the region but it failed to issue. This inaction exacerbated the death toll because most people in this region do no know what to do in the event of a "felt" earthquake in low lying coastal areas. There was little or no preparation by the Governments in the region for catastrophic calamities caused by convulsions of nature with the exception of an incipient disaster relief systems more suitable for monsoon floods. Typical in Asian management culture is the lack of contingency planning or planning for the uncertain outcomes of events or worst case scenario planning. Structured long term models with comprehensive plans, strategies, systems, logistics and training is also not a norm. The management speaks more of tactical responses and reactions after the tragedy.


On a planet continually being challenged by all types of natural catastrophic events there seems to be only one real way to mitigate the potential losses. Intelligence from early warning systems are only a part of the answer. Emergency Preparedness and Response is the other proactive strategy for dealing with the risk of future threats of this magnitude by mother nature.

Beldeu makes the comparison of this event to the Japanese attack on Pearl Harbor in 1941.

Half a century later, in spite of advances in seismic science and a vast network of modern communications supported by satellite technology, the world relives another day of infamy in the month of December that bears some semblance to the attack on Pearl Harbour. Only this time, it was not failure of collection or analysis of data but one of communication and proper response. In fact, the situation as it unfolded in the region devastated by the tsunami shows that there was no organized response to protect people from the impending impact of the tsunami.

22 December 2004

Whistle-blower laws go global...

As the U.S. recovers from yet another accounting scandal at Fannie Mae, other countries are getting on board with the Sarbanes-Oxley Act.

Japan is considering a new whistle-blower law if a local worker has his way in court.

A JAPANESE executive allegedly forced to weed the company car park for 30 years is at the centre of a major shake-up in corporate whistle-blowing law.

Tomorrow a district court in Toyama will hand down a verdict that could shape Japanese business practice for years to come. If Hiroaki Kushioka is successful in his suit against his employer, Tonami Transportation, the way could be open for startling revelations from within corporate Japan. If he fails, the culture of bullying and cover-ups will be given a tacit vote of support. The Kushioka case comes as Japan is preparing a massive overhaul of its legal treatment of whistle-blowers.


Fannie Mae executives may be some of the first to be successfully prosecuted under the laws in the U.S. that require companies to set up a whistle-blower program. It seems that Mr. Kushioka is finally getting his revenge for ratting on workers over 30 years ago thanks to the trend in improving corporate governance across the globe.

20 December 2004

External Events: Legal Liability

Pfizer has 10% of it's revenues coming to a halt as a result of the Celebrex Warnings about it's link to greater risk of Heart Attacks.

Pfizer Inc. said it would immediately stop advertising arthritis drug Celebrex to consumers after a study showed that high doses were associated with an increased risk of heart attacks, according to a published report.

The suspension of advertising is indefinite and includes television, radio, newspaper and magazine ads and other promotions to consumers, The New York Times reported on its Web site Relevant Products/Services from Verisign -- Free E-Commerce Start-up Kit, citing Pfizer spokeswoman, Mariann Caprino. Some magazine ads may appear for a few more weeks because of the long lead time of magazine advertising, she said.


If the Merck scenario with Vioxx is any indicator of the legal implications then Pfizer can also expect a series of class action suits to follow.

17 December 2004

Who is the right choice for the US DHS Secretary?

In the rush to get someone into the job, most high level qualified candidates have already said no and the current US administration is scrambling after the Kerik affair. So who is the best candidate for the next US Secretary of the Department of Homeland Security?

What the country needs is a career CEO. Not a cop, a lawyer or a politician. Think about what this job is all about and you can see that with over 170,000 employees and warring business units over a finite budget it's going to take someone from private sector business who also understands security.

The kind of security that we have been focused on for the past three years is on the physical aspects of homeland security more so than the intelligence side of the equation. And now with the new Intelligence Act signed and sealed, it's about time we hired someone who truly understands the fusion of data, information, and knowledge to gain "wisdom" aspects of the job.

We already have plenty of cops on the streets keeping their eyes and ears open. What we need now is someone who can get all of the DHS business units working in "concert" and more importantly with the DOD. Homeland Defense is gearing up more than you know and Northern Command is now expanding it's reach beyond it's traditional borders.

Our prediction is that someone will emerge from the ranks of the private sector to take on this enourmous task of getting all of the pieces of the "Homeland Security" puzzle put together. Let's also pray that they understand the difference between Phishing and Fishing. In that case, look hard in the financial services sector.

15 December 2004

Tower Group Study: $362.B for Financial Services IT

The latest Tower Group Study says spending will be up to $362.B with 72% in North America and the EU.

Tower said consumer banking will dominate spending globally. The firm predicted that consumer spending will continue to represent the largest share of IT spending while wholesale banking will experience a continued recovery during the year.

As for the securities and investment industry, TowerGroup projects IT spending in the segment will grow four percent during 2005, partially driven by a return to markets by investors who were burned by declining stock markets a few years ago.

14 December 2004

People Risk: Avian Flu

The Gartner Group has determined that their clients need to prepare for the upcoming Avian Flu pandemic that is being discussed among the World Health Organization (WHO)as a possibility.

On 13 December 2004, health leaders from around the world met in Geneva to discuss the potential threat posed by the predicted future mutation of avian influenza into a highly contagious and virulent form that could quickly pass from person to person. The World Health Organization (WHO) has warned that avian flu variant H5N1 ("bird flu") could combine with an influenza strain already contagious in humans to cause a pandemic that might kill millions of people. H5N1 has been found in poultry in 11 Asian countries. Attempts to eradicate the disease have not succeeded, despite the destruction of 100 million birds. To date, 44 human cases of avian influenza have been reported, all in Thailand and Vietnam. Most of the victims had direct contact with birds; 32 of the victims died.


The difference with this virus and the digital type is that this one can take out key personnel and requires a whole different contingency planning mindset.

Recommendations:

* Use scenario planning to understand and prepare for the possible impact on your business.
* Make your workforce aware of the avian flu threat and the steps you are taking to prepare for it.
* Assess your business continuity preparedness and try to improve it.
* Assign someone in your business to track biological threats such as avian flu. He or she should regularly review business continuity plans and update them in response to new information.
* Establish or expand policies and tools that enable employees to work from home, with broadband access, appropriate security and network access to applications.
* Expand online transaction and self-service options for customers and partners.
* Work with customers and partners to minimize disruption by developing coordinated crisis response capabilities.


While these are great recommendation from Gartner, I think most savvy contingency planners might have a big yawn reading these over.

13 December 2004

ORM: Systems Integration Challenges

In Deloitte's 2004 Risk Management Survey more than half of the respondents say integration of systems to handle Operational Risk is a big concern. More Chief Risk Officers (CRO)have been hired and are reporting directly to the CEO or the Board of Directors.

Operational risk management - according to the survey, operational risk management (ORM) continues to be a relatively new and developing field compared to the more established risk management disciplines, with the majority of respondents still in the beginning stages of implementation. However, the survey shows an increase over 2002 in the number of firms that have established ORM programs. The capability of ORM systems continues to be a challenge for a substantial majority of respondents who indicated that at least some improvement in functionality is needed.

Risk systems and technology - while information technology is considered to be the key enabler of a risk management architecture, respondents report a host of continuing challenges in developing adequate risk systems. More than half (52 percent) cited a lack of integration among systems as a major concern and 42 percent cited it as a minor concern. Lack of flexibility and scalability as well as performance issues were also noted as key challenges. Improving regulatory related systems capabilities and implementing operational risk management and advanced credit risk systems were the three highest priority items cited by respondents in the systems development and technology area.


"Financial institutions are recognizing the need for strong risk management governance, now more than ever," said Jack Ribeiro, managing partner of Deloitte's Global Financial Services Industry practice. "They are responding to increased expectations from regulators, counterparties, the public, and others to ensure sound governance of their risk management programs."

09 December 2004

The Most Feared Words in the Boardroom...

You have been indicted. This Boardmember article by Peter Higgins of 1SecureAudit articulates the essence of an effective OPS Risk compliance program. Even today it is a great reminder of why ethics and education are a key component of an effective system.

Every Fortune caliber organization from financial services to health care has already implemented a pervasive compliance program to mitigate the risk of ending up with the SEC or US Attorney in the lobby.

The catalyst behind these initiatives is generated from the U.S. Sentencing Commission's Organizational Sentencing Guidelines. They allow for more lenient sentencing if an organization has evidence of an "effective program to prevent and detect violations of law."

The Guidelines contain criteria for establishing an "effective compliance program."

These include oversight by high level officers, effective communication to all employees, and reasonable steps to achieve compliance such as:

* Systems for monitoring and auditing
* Incident response and reporting
* Consistent enforcement including disciplinary actions


Yet the corporate incivility continues. Why is it that we can’t pick up the morning paper or listen to the news on the way to work without hearing about a new indictment of a top ranking officer?

Here lies the question many Board of Directors are scratching their heads about these days. How can we avoid these ethical and legal dilemmas and how can they be addressed without creating a state of fear and panic?

The answer lies in the human factors of what motivates people’s behavior. This requires programs, controls and good old fashioned vocational counseling. However, the real facts are that all of these alone will not be able to stem the tides of corporate malfeasance.


07 December 2004

ERM: Here to stay...

Last summer Scott Berinato penned this article. It sums up the many facets of Enterprise Risk Management (ERM) and the challenges for the CIO. As a CIO, he should know right?

Are you on board with enterprise risk management? You had better be. It's the future of how businesses will be run.

What would you do if, two months after your company went public, one of the two major markets you sell products to simply vanished? If, in the span of seven days, $500 million in sales just disappeared?

Would you throw your hands up and say, No one could have foreseen the events of 9/11, and then just stand by as the company tore off a half-dozen bad quarters? Would you just absorb the discomfiting cuts to your budget and your staff, and eschew any strategic plans you had set up to help the business grow, because, well, no one could have been prepared for such a catastrophe?


ERM is hard work. Not to sound too much like the last GOP campaign who had a similar sound bite, "We are workin hard", but Enterprise Risk Management is a culture shift and also one found in an old project managers tool kit called "Change Management".

So Why Now?

Just why ERM is important now is complex, but the reasons include IT as a primary risk to operations.

First, several macro-trends have accrued to expose operational risks to the business from IT that in the past were blissfully ignored. Start with Y2K - the realization that IT systems we depended on were vulnerable. Then came 9/11 and the (literally) thousands of risks to businesses that it exposed. Computer viruses have continually interrupted work, illuminating the risks of using bad software. More recently, the risks to a corporation's reputation have announced themselves in the form of massive thefts of personal data. There is, of course, terrorism, political unrest, war and weather, among other global risks to consider.

The reason these risks are suddenly being accounted for is because the systems are becoming ever more critical. Today, one bad IT decision can severely hamper - or even take down - a company.

The second factor driving ERM now is the regulatory environment
, along with efforts within some industries to protect companies from the volatile global business environment.

For example, the Basel II Accord, an effort spearheaded by the Group of 10 countries' leading financial services stakeholders, dictates that by year-end 2006, a financial services company must carry a predetermined amount of capital to offset the level of risk found in the company, as determined by guidelines in the Accord. Unlike the first version of this regulation from 1988, Basel II addresses not just capital risk, but also operational risk, including the risks IT systems create for the company. In other words, it mandates some form of enterprise risk management.

Likewise, the Treadway Commission's Committee on Sponsoring Organizations (COSO), a voluntary private-sector organization formed in 1985 to combat fraudulent financial reporting, produced an enterprise risk management framework. The Information Systems Audit and Control Association (Isaca) developed Cobit (the Control Objective for Information and related Technology), a document that also lays out how to set up an enterprise risk management framework. Both are efforts designed to jump-start the use of ERM in corporations.

Of course, there's Sarbanes-Oxley too. While not the engine driving ERM, Sarbox might be the spark plug. CEOs, after all, don't want to go to gaol. Says David Weymouth, CIO of Barclays, the UK-based financial services company: "We've spent something like £136 million on a regulatory program. Non-compliance is a huge risk we need to manage."


The bottom line is this. Operational Risk is old and it is new. It is not something to be ignored and underfunded. It's constantly changing and requires exceptional people, processes, systems and technology to make it work.

06 December 2004

Phishing moving to prime time...

With an estimated 4.5 million "Phishing" attacks last month now being reported by Messagelabs our customers and clients need to be even more aware of this growing threat. This is especially true since the Phishers have figured out how to extract valuable information without someone clicking on a hyperlink in the email itself.

The boom in phishing attacks -- spam that masquerades as messages from legitimate companies that tries to dupe users into divulging confidential information, such as bank or credit card account numbers -- has been phenomenal. MessageLabs tracked a mere 279 phishing e-mails in September 2003, but a year later, monitored over two million in the same month. During November 2004, MessageLabs tallied a whopping 4.52 million phishing-related messages.

And if you think that's bad, wait until next year, said Natasha Staley, an information security analyst with U.K.-based MessageLabs. "Phishing is really only 12 to 18 months old. It's not even in its prime."

Phishers, who are believed to be composed primarily of organized criminal gangs, many of them based in central and eastern Europe, including the republics of the former Soviet Union, are quickly refining their techniques, added Staley, to make their bogus messages even more enticing or effective.


You have to have diligent awareness campaigns for your customers, members and clients if you are going to mitigate the risks of operational losses. Banks, e-commerce sites and any other big brand on the net is being targeted by a growing criminal element.

03 December 2004

H.R. 4830 - Private Sector Preparedness Act of 2004

What is H.R. 4830?

A bill introduced last summer in the U.S. House of Representatives to amend the Homeland Security Act of 2002 to direct the Secretary of Homeland Security to develop and implement a program to enhance private sector preparedness for emergencies and disasters.

Program Elements- In carrying out the program, the Secretary shall develop guidance and identify best practices to assist or foster action by the private sector in--

`(1) identifying hazards and assessing risks and impacts;

`(2) mitigating the impacts of a wide variety of hazards, including weapons of mass destruction;

`(3) managing necessary emergency preparedness and response resources;

`(4) developing mutual aid agreements;

`(5) developing and maintaining emergency preparedness and response plans, as well as associated operational procedures;

`(6) developing and maintaining communications and warning systems;

`(7) developing and conducting training and exercises to support and evaluate emergency preparedness and response plans and operational procedures;

`(8) developing and conducting training programs for security guards to implement emergency preparedness and response plans and operations procedures; and

`(9) developing procedures to respond to external requests for information from the media and the public.


Congress has found out the following:


Identifying standards and best practices is necessary to promote emergency preparedness by private sector organizations, in addition to educational activities to effectively communicate such standards and best practices.


As business waits for this bill to get out of committee, business leaders around the country are not standing around. They realize that contingency planning and continuity of operations is imperative for their business survival. We can only hope that no one is waiting around for what the standards body or best practices authority will be. Let's pray that the private sector has gone beyond developing plans and now is exercising Corporate Emergency Response Team (CERT)training in all the facilities deemed to be soft targets. Without this, we will certainly not be as ready as we could be. And once we have trained and tested numerous times, we will know what to improve and how to change the procedures accordingly.

01 December 2004

Some SOX relief for smaller firms...

US companies with a market cap between $75 and $700 Million will get a 45 day extension for compliance with SOX (Sarbanes-Oxley Act of 2002). According to the SEC Statement:

The online statement quoted SEC Chief Accountant Donald Nicolaisen, saying: "The Commission is sensitive to resource constraints at accounting firms and at smaller public companies, and is taking this step to facilitate the successful and effective implementation of the Section 404 internal control requirements." Alan Beller, director of the Division of Corporation Finance, added that the exemption should "encourage companies to file important information for investors, including audited financial statements, on a timely basis, while providing an appropriate accommodation for internal control reports."

Eligible companies now have 45 days after the expiration of their 75-day reporting window to add the required management reports on internal controls, along with auditors' comments, the SEC said. The PCAOB's ruling allows auditors to sign off of internal reports at a later date than financial reports. The temporary rule is expected to be in effect until July 15, 2005.

30 November 2004

People Risk: Whistleblowers are winning...

This article from Charles Baldwin highlights the recent rulings under the Whistleblower provisions under the Sarbanes-Oxley Act of 2002. If this is the trend, then employers need to spend more time educating employees and making sure they are in compliance with the letter of the law.

Of major significance to the employer-employee relationship, the Act requires the newly mandated audit committees of corporate boards of directors to establish procedures for the anonymous, confidential submission of employee concerns relating to improper corporate financial, accounting, or auditing practices and creates new civil and criminal liabilities relating to informants. In addition to requiring internal complaint procedures, Section 806 of the Act created a new federal civil claim under the title "Whistleblower Protection for Employees of Publicly Traded Companies." The nature of the claim is broader and imposes fewer burdens on a claimant than other federal whistleblower laws; thus, employers should expect to encounter more claims and litigation arising from the Act.


Recent rulings by the U.S. Department of Labor include:

Getman v. Southwest Securities Inc, No. 2003- SOX-00008, DOL ALJ
Welch v. Cardinal Bankshares Corp., 2003-SOX-15, DOL ALJ
Morefield v. Exelon Servs. Inc., DOL ALJ, No. 2004-SOX-2


In addition to complying with all of Sarbanes-Oxley’s requirements regarding financial reporting controls and corporate governance, prudent employers—whether public or private—must be proactive in implementing policies and procedures to navigate the post-Sarbanes-Oxley landscape. We recommend that employers first conduct a top-to-bottom review of existing policies and practices, ideally in a manner that will maintain all available legal privileges and protections. A review of insurance coverage, including but not limited to Directors’ and Officers’ liability coverage, must be a part of that review. Following that review and follow-up, employers should be in a position to show, at a minimum:

* A code of conduct that spells out specifically the duties of all employees;
* A code of ethics for senior financial officers;
* Establishment and a clear publication of a hotline and other avenues for confidential, anonymous complaints;
* Personnel policies and procedures that comply with the law’s requirements on handling of complaints, document handling and retention, and non-retaliation;
* A clear designation and publication of those persons within the company who have the authority to investigate, discover, or terminate financial misconduct;
* Personnel policies clearly addressing inappropriate conduct, e.g., prohibited conduct regarding media contact, removal of documents, destruction of documents, refusing to participate in investigations;
* Benefit plans and practices that comply with all requirements and prohibitions;
* Procurement practices and procedures to ensure proper screening of human resources consultants and auditors;
* Hiring practices and procedures to ensure proper screening of executives; and
* Comprehensive and documented training programs for all employees that implement the requirements of Sarbanes-Oxley.

24 November 2004

Managing Operational Risk in Banking...

This latest article by McKinsey may have some interesting insight:

Banks are increasing their coverage against operational risk to comply with new international banking rules, but they may be underestimating the extent of the risks they face. The declines in market value of financial institutions that experienced an operational crisis—such as an embezzlement or breach of regulations—were much greater than the actual financial loss caused by the event, our research found.

The take-away

Banks that understand the true scale of the operational risk they face can take a more realistic approach to controlling it.


This article includes the following exhibits:

* Exhibit 1: Impact of operational crises on market returns
* Exhibit 2: The five most harmful kinds of operational crises

23 November 2004

UK: Civil Contingencies Act...

The UK's Civil Contingencies Act is on the door step and David Honor of Continuity Central has the following observations:

No UK organisation can afford to ignore the Civil Contingencies Act. The category one and two organisations which will be directly impacted will receive information, advice and support from the Cabinet Office on how and when to implement measures. Other organisations would be well-advised to do the following:


• Get a copy of the Act and read it
• Assess your current business continuity plan against the Act’s provisions. Does the Act make any difference to the scenarios you have planned for?
• Redevelop the business continuity plan where necessary and re-test it.
• Liaise with your local authority emergency planning department. This is good practice which is listed as one of the BCI’s Ten Key Disciplines of Business Continuity, but now becomes even more important since local authorities will become one of the key sources of local business continuity information and advice.

19 November 2004

OSAC 19th Annual Briefing...

The topics of the annual Overseas Security Advisory Council Briefings and 8th Annual Transnational Crime Seminar indicate what's on the minds of most CSO's across America and the globe. See if you can see the common thread:

"Managing Risks and Threats in Challenging Environments" - Bureau of Diplomatic Security

"From Suppliers to Satellites: Balancing Business and Security" - Delphi Corporation

"Coping with Istanbul" - HSBC Holdings, PLC

"Managing World Security Trends"

"Communicating with Employees under Heightened Threat Conditions"

"What do Employees Expect, What do They Need"

"Perception of Bio-security Dangers and the True Vulnerabilities"

"International Kidnapping and Hostage Taking"

"Emergency Preparedness and Business Continuity"


After two days of hearing presentations by some of the most informed individuals on the topics and issues of global security, one individual made a very interesting point:

On the topic of Practice Preparedness and Training Programs for employees he asked, "What do your people do in the event of [Pick a Diaster Scenario]?" The point is, you won't know what they do unless you exercise, drill and experiment with different scenarios. He went on to say that we need to be Leaders of Safety, Health and Operations and that the likes of SARS and Avian Flu will not be stopped by more guards, gates and guns.

Invisible contagious agents that are autonomous will be something we encounter on a mass scale sooner than we think. As professionals paid to worry, this is the one that we don't ever want to encounter and don't know much about how to mitigate the threat to our organizations.

Another vital topic on Abduction Prevention and Hostage Survival promoted the thinking about training to detect surveillance and to make rational and tactical decisions to prevent from being kidnapped. However, in the event of abduction, there are only four outcomes:

1. Negotiate
2. Rescue
3. Escape
4. Death

The point here is that you must maximize survivability and minimize exploitability. Finally, employees and organizations need to have a Personnel Recovery Architecture that includes a continuum for guideance and a crisis management framework.

Operational Risk and Continuity Management is what this 1.5 day briefing was all about. If there was one thing that stands out from all the presentations and the conversations is that our employees are looking for people they can "TRUST". It's our duty to make sure that we do everything in our power to make this a reality.

Perception drives Attitude that drives Behavior.

18 November 2004

ID Theft: Banks vs. Consumers...

The banks have a different perspective on ID Theft and privacy than consumers. As this Bank Tech article points out.

Late last month, four servers containing names, addresses and Social Security numbers of thousands of Wells Fargo & Co. mortgage and student-loan customers were stolen from an Atlanta company that prints loan statements. There's no indication the information has been misused, the bank says, but it's advising affected customers to monitor their accounts for suspicious activity. It's also offering a free one-year credit-protection program and has established a toll-free hotline.

The incident was the latest reminder of how pervasive the threat of identity theft has become, as well as how much of a risk it is for banks and credit-card issuers and their customers. According to the Federal Trade Commission, 9.9 million Americans were identity-theft victims last year. Of those, 6.6 million reported fraudulent use of existing accounts while more than 3 million reported new accounts opened in their names. That cost businesses $48 billion and consumers $5 billion in economic losses.


As banks and other financial institutions outsource operations such as printing statements and sending out direct mail they are going to be continually subjected to incidents like this. What is commonly the case, and astonishing to say the least is that these 3rd parties are not always as "buttoned-up" as they should be with their risk detection, prevention and protection programs. If the consumer has anything to fear, it is that their bank is not taking the time to effectively audit and monitor their outsourced service providers.

16 November 2004

NIMS set to be approved...

The National Incident Management System is soon to be approved.

An integrated national plan for response to terrorist attacks and other national emergencies is likely to be approved by Cabinet secretaries by the end of this week, Deputy Homeland Security Secretary James Loy said Tuesday.

By this time next year, the final National Response Plan will have replaced the disparate plans now in effect at federal agencies that work terrorism response, the former Coast Guard commandant said at a maritime-security conference in Washington organized by Defense Today and held at George Washington University.

A February 2003 directive by President Bush required the fledgling Homeland Security Department to design and implement the National Response Plan and the associated National Incident Management System in a bid to "establish a single, comprehensive approach" to managing terrorist attacks, natural disasters and other large-scale emergencies.


The system establishes "standardized incident management processes, protocols and procedures" for incident command organization, communications and preparedness, Homeland Security said in a March fact sheet. The effort is intended to allow first responders from different jurisdictions and disciplines to better coordinate responses to natural and unnatural disasters.

15 November 2004

SOX 404 Deadline today...

The long anticpated compliance date with Sarbanes-Oxley Section 404 arrived today and many organizations are not ready.

Although many companies are reportedly not ready for it, the era of internal-controls compliance begins in earnest today. That's when Section 404 of the Sarbanes-Oxley Act goes into effect for all companies whose fiscal year ends after today.

There will be nothing to file on Tuesday. But by early next year, the vast majority of companies that report on a calendar-year will have to assess the effectiveness of their internal controls over financial reporting and state in their annual reports whether the controls are operating effectively. The companies' outside auditors also must evaluate the in-house assessment and render an independent report on it.


The average cost to a organization to get in compliance is estimated at $5M and rising for a Fortune caliber public company.

12 November 2004

Global Assurance Office...

As the corporate risk management factions realize that they need to converge in their coordination, global assurance management will take hold.

Soon enough the global 500 will realize the requirement for a more consolidated, coordinated and cohesive entity within the organization for risk management, information security, business continuity, crisis management and emergency response.

The combined expertise in finance, compliance, legal, IT, internal audit, operations, security, human resources and purchasing will all be working together to create the organizations single global assurance office.


This will be the team and staff that manages an "All Hazards" approach to mitigating the threats to the organization. They will be responsible for the single task of making sure that the business is running no matter what event or incident may try and bring it down.

A few savvy organizations have already moved this direction and even those that thought they had a single responsible team are now adding new dimensions and capabilities to the team.

11 November 2004

1SecureAudit Prepares WTG Properties Tenants For All Hazards And Catastrophic Incidents

Risk mitigation training solution delivers greater confidence, lower costs, and increased peace of mind for this Washington, D.C. commercial real estate firm

For Immediate Release

MCLEAN, Va./EWORLDWIRE/Nov. 10, 2004 --- 1SecureAudit LLC, an emerging leader in operational risk management solutions, today announced a client success story for WTG Properties in Washington, D.C.

Many companies throughout the Washington, D.C. area are asking the same important question, especially since Sept. 11, Hurricane Isabel and the Northeast blackout. That is: How can businesses be better prepared in the case of serious hazards, incidents and emergencies?

The residents of WTG's N Street property were no exception. "My tenants were asking what we were doing to be better prepared in case of another attack," said John Lane, president of WTG Properties Inc. "Which was logical, given their proximity to the White House.

"But I wanted a proactive and preventative all-hazards program that would cover everything," continued Lane. "I wasn't just worried about terrorists, but also about serious incidents like floods, fires, and hurricanes. That's when I started my conversations with Peter Higgins of 1SecureAudit."


1SecureAudit is a risk management solutions firm that worked with Lane and the residents of the property to teach them how to better cope with emergency situations that may arise.

Higgins explained: "You've heard the term first responders. Well, the fire fighters, police and EMTs are actually the second responders. Employees and tenants are the first responders in a crisis, and they need to be competent, confident and as prepared as possible to handle the situation until the emergency personnel get there - whether it's minutes, hours or days."


Think all hazards. Think convergence of BCCM, ISMS and Corporate Governance. That equals total Global Assurance. The future is here now.

09 November 2004

Business Process Outsourcing: A Real Threat to Security or IP Theft?

Business Process Outsourcing is a hot issue and as this article by The Heritage Foundation so clearly states:

Defending the nation against terrorists, promoting economic growth, and protecting constitutional lib­erties are all prerequisites for a sound homeland security strategy. At one time or another, outsourc­ing[1] has been labeled a threat to all three. These crit­icisms are simply overblown. In fact, if the U.S. partners with nations that share a commitment to the rule of law, transparency, and open competition, it can use sensible outsourcing to enhance the protec­tion of the privacy of American citizens, promote better security practices, and contribute to economic prosperity. Effective outsourcing can provide both cost-effective services and appropriate protections for government and commercial activities supported by overseas vendors.


Now if you talk with the major U.S. technology companies who have outsourced operations in India and China they will tell you their nightmares. Intellectual Property theft is running rampant and the laws and trade representative sanctions will be hard pressed to make major changes in the near term. The security of the nation is not going to be compromised by these organizations and the real loss events will occur when their source code is posted on the Internet.

Conclusion

The goal of increasing domestic security and protecting the privacy of U.S. citizens should not be an obstacle to strengthening economic ties with the developing world. Rather, market forces and sensible outsourcing can be used both to promote better global security practices and to encourage economic growth.

08 November 2004

Judgment Calls...

Regulations such as Sarbanes-Oxley are sending auditors to the pencil sharpener. CSOs must learn to cooperate and share expertise, without getting too close to these empowered examiners.


Malcolm Wheatley is a freelance writer in England. And this "Judgment Calls" article was dead on with good advice especially number four:

Strategy No. 4: Teach Them Security Heim’s mention of a back-and-forth negotiation between auditors and security executives carries with it an important conclusion: Security-savvy auditors are a must.

Communicating with auditors as part of a cooperative process is one way of educating them about the security function. Another solution, according to Radianz’s Hession, is to obtain the requisite combination of skills and separation by turning security folks into auditors.


How can you have an effective Information Security Management System without auditors who know “Risk Management” from an IT perspective? The answer is, you can’t. And you can’t have an effective audit for legal compliance issues without IT security professionals who understand the intent of the law. To do this you must have a cooperative team who thinks like a criminal and that is not easy to create.”

“The reciprocity between CSO, CIO, CRO, CFO and General Counsel is imperative if any sizeable company is going to mitigate the threats from internal and external attackers. And as this article clearly points out, a healthy set of objectivity and anxiety is imperative if you are going to have professionals on the front lines do their jobs within the intent of the law.

03 November 2004

Bush defeats Kerry for US Presidency...

George W. Bush won his Second Term as President of the United States today.

"To make this nation stronger and better, I will need your support and I will work to earn it," Bush, referring to Democratic supporters who bitterly oppose his presidency and re-election, said in a speech at the Reagan Center to a cheering partisan crowd.

"I will do all I can do to earn your trust ... we have one country, one constitution and one future that binds us."


The risks have not changed and the way we detect, deter and defend our precious assets will continue to gain momentum for the next four years.

02 November 2004

Advanced Citizenship in Critical Infrastructure Protection...

The dialogue from a recent CSO Conference that focused on information sharing keeps coming back to why it is so hard to accomplish.

Only Bill Boni from Motorola was bold enough to tell the real reason why the cyber world is still not getting the attention it deserves.

Boni: I think the real driving issue here, if you go back and look at [how sprinkler systems came to be in factories], such safeguards come out of the experience of factories burning down and people dying. And until we see mass-casualty events that are critical to information security failures, I don't think you're going to have that same sense of urgency. And, probably, as a society we shouldn't. But, the challenge is to make sure that organizations are doing their reasonable best to not be the cause of part of that event. But my belief is that until we see mass casualty situations that arise from information security, we won't make that transition, and we shouldn't. Unfortunately, I think that it is going to happen at some point. Whether that's before or after I retire from my current employment is a very important deliverable.


It's amazing to find out that even as we speak there are people who are still unprepared to handle the zero day exploit or the next catastrophic incident. Even when they are considered a "soft target" they still have not exercised and tested to the degree necessary to improve their defense and to plan for the various outcomes possible. Boni is right, if it doesn't happen to me then why should I spend the time and resources to prepare? For the same reason you pray at your place of worship. You know it's inevitable and yet you don't know when it is going to happen to you.

29 October 2004

Threat Detection & Management...

Robert Young Pelton's Travel Tips may be common sense. These are also the type of tips you get from those expensive executive seminars where no one ever gets out of their seat for two days.

If you are going to take an attitude of really protecting your organizations most valuable assets then you have to train your people in real life scenarios. The goal is to overcome the panic modes and replace them with smart actions to save your life and your companies precious information.

For those who travel on business into regions of political or religious instability it should be company policy that each individual travel with at least an experienced partner. Also essential is that both have gone through extensive hands on training to detect surveillance as well as manage emergency situations with smart decisions. For more on this visit: Threat Detection & Management

27 October 2004

Compliance and outsourcing: Oil and water or fine vinaigrette?

John and Stan could not have said it any better....

By John Van Decker and Stan Lepeak
10 May 2004 | Meta Group

One common misperception that still survives in the market is that existing outsourcing audit mechanisms, primarily the SAS 70 audit, are adequate for SOX compliance. The growing consensus is that even an SAS 70 Type 2 audit may not prove enough for SOX. The SAS 70 standard was developed long before SOX regulations and was not designed to focus on the type of controls that SOX addresses. In addition, there have been no requirements for users to request an SAS 70 audit, and many have not. One SAS 70 audit could potentially suffice for multiple clients of an outsourcer, whereas with SOX compliance, this is likely unacceptable. We are seeing more cases where aggressive/thorough clients are demanding additional controls and documentation beyond an SAS 70 Type 2 audit to enable what they estimate is "good enough" SOX compliance. It is not expected that the PCAOB will define requirements above and beyond an SAS 70 for SOX compliance until later this year.

A final challenge to SOX compliance that affects outsourcers is interenterprise compliance. Users must approach process compliance holistically, covering insourced and outsourced processes, as well as intersection points and continuums of processes that span supply and service chains. For example, how can a user's controls account for the breakdown in a supplier's financial controls that could lead to a parts shortage, which could impact revenue/profits that would then require a timely disclosure? Clearly, organizations cannot address SOX compliance in an isolated fashion. Outsourcers have the added dimension of being intertwined in multiple-clients compliance efforts across multiple process areas. This in itself increases the outsourcer's risk and demands greater focus on enabling compliance, for its own sake as much as its clients'.

Bottom Line: Business process and IT outsourcing currently do not mix well with SOX and related compliance requirements. However, outsourcers and their clients cannot wait for regulatory clarification and must define, document, and rationalize interim best-faith efforts for gaining and evidencing SOX compliance for affected outsourced functions and processes.