What is it that corporate management and the US Navy have in common? Corporations can learn ORM from the US Navy principles to earn top safety honors and contribute to mission success.
This is just one example of how the US miltary is using the effectiveness of Operational Risk Management to mitigate the risk of hazards on the job and to ensure the safety of fellow team mates on the job.
“It was evident the first time I came on board and saw the crew’s attention to detail and dedication to their work,” said Capt. Mike D. Budney, commanding officer, Emory S. Land. “But it’s remarkable to note that with the tremendous day-to-day operations, no serious safety mishaps occurred.”
“With a crew this size and the never-ending upkeep that takes place, safety is and will always be our number one priority,” Budney added. “Our Sailors know that and are living proof. I am extremely proud of them!”
While safety is paramount on every ship and submarine in the fleet, these submariners know that safety is not about winning awards, it’s about managing risk to avoid injuries and possible loss of life.
Monday, August 30, 2004
Friday, August 27, 2004
The next very long war...Cyber Terror
"The Internet is the bold new frontier of crime, but we're the new sheriff in town. For cyber criminals who operate out of Los Angeles or any location around the globe, this posse will bring you to justice," said United States Attorney Debra Wang.
The Six Cyber Terrorists arrested by the US DOJ have set the stage for a long and evasive war. The hope is that the private sector will begin to share more information with the feds to get to the big fish, but this will take time, money and lot's of cooperation with our global partners. China, Korea(s) and the Russian states are the sources of many of our DoS attacks and while we know who they are it is difficult to navigate international laws and jurisdictions.
The good news is that the private sector is working more closely with InfraGard and the 12,000+ members who are helping to protect our critical infrastructures. Money is being allocated to specialized enforcement teams to assist the US Attorney's in doing their jobs more effectively.
It's just going to be a very long war that has to be fought every single day.
The Six Cyber Terrorists arrested by the US DOJ have set the stage for a long and evasive war. The hope is that the private sector will begin to share more information with the feds to get to the big fish, but this will take time, money and lot's of cooperation with our global partners. China, Korea(s) and the Russian states are the sources of many of our DoS attacks and while we know who they are it is difficult to navigate international laws and jurisdictions.
The good news is that the private sector is working more closely with InfraGard and the 12,000+ members who are helping to protect our critical infrastructures. Money is being allocated to specialized enforcement teams to assist the US Attorney's in doing their jobs more effectively.
It's just going to be a very long war that has to be fought every single day.
Wednesday, August 25, 2004
Share Price: A Factor of Corporate Governance?
Corporate Governance is good for the bottom line but even Google hasn't found this out...yet. Their recent coporate governance quotient is 0.2 out of 100.
But, as Ric Marshall, chief analyst for the Corporate Library, notes, it's not necessarily a bad thing. "There is this tendency to dumb things down by making all boards look the same,'' Marshall told the San Francisco Chronicle. "By doing something different and unconventional -- in terms of how the IPO has gone, the multiple share classes, the makeup of the board -- Google is creating something that is different and unusual. Good corporate governance is the creative interaction between directors on the board. What concerns me is the ethics of the people involved and their ability to be creative."
But, as Ric Marshall, chief analyst for the Corporate Library, notes, it's not necessarily a bad thing. "There is this tendency to dumb things down by making all boards look the same,'' Marshall told the San Francisco Chronicle. "By doing something different and unconventional -- in terms of how the IPO has gone, the multiple share classes, the makeup of the board -- Google is creating something that is different and unusual. Good corporate governance is the creative interaction between directors on the board. What concerns me is the ethics of the people involved and their ability to be creative."
Tuesday, August 24, 2004
Real Esate: Antiterrorism Laws
Is the commercial real esate industry subject to our latest antiterrorism laws?
See the viewpoints of two legal eagles from Holland & Knight in the DC area on this very topic.
Executive Order 13224 and the prohibited parties list of the Office of Foreign Assets Control (OFAC) is in effect now. It has civil and criminal penalties.
The Money Laundering Control Act, a criminal statute, is in effect now.
The USA PATRIOT Act/Bank Secrecy Act, which requires certain anti-money laundering compliance activities, will result in regulations directly affecting the real estate industry within a matter of months.
See the viewpoints of two legal eagles from Holland & Knight in the DC area on this very topic.
Wednesday, August 18, 2004
H.R. 1731 Identity Theft Law
The identity theft penalty enhancement act expands the capabilities of the Justice Department to investigate I.D. theft. See the synopsis here at CSO Online. I.D. theft is one way for the terrorists to keep themselves hidden in the US for a long period of time. It will also help in credit card fraud cases.
Tuesday, August 17, 2004
Increased Regulatory Scrutiny for Bank INFOSEC
Banks INFOSEC departments have increasing roles in audits. The Information Security departments must have a systematic program for managing risk in their day to day operations as regulatory requirements for business overlap.
Comprehensive risk management programs are being broadened to encompass operational risk in many banking institutions. This is due to the increasing prevalence of legislation such as Gramm-Leach-Bliley (GLBA) and even sections of Sarbanes-Oxley. The convergence of information security and business is finally making it apparent that the two are very much inseparable.
Comprehensive risk management programs are being broadened to encompass operational risk in many banking institutions. This is due to the increasing prevalence of legislation such as Gramm-Leach-Bliley (GLBA) and even sections of Sarbanes-Oxley. The convergence of information security and business is finally making it apparent that the two are very much inseparable.
Friday, August 13, 2004
Survey identifies main stumbling blocks to successful operational risk management
Survey identifies main stumbling blocks to successful operational risk management:
Difficulties in collating clean data and poor awareness among staff are the major obstacles to effective operational risk management, according to a recent survey by Risk Waters Group and SAS.
The survey of more than 250 financial institutions and regulators identified managing data quality as the number one issue, with respondents reporting difficulties in collating sufficient volumes of historical data and in ensuring reliable data. The second most pressing issue was the poor overall awareness of operational risk issues by staff, due largely to lack of clear education programs in operational risk, lack of communication and limited knowledge sharing.
Regulations such as Basel II place a growing emphasis on operational risk management within financial institutions. Banks are compelled to gather data that they do not currently collect; they are also required to bring that data together from a host of disparate systems into one pool for analysis.
'The two key barriers to financial institutions achieving success relate to basic issues such as data quality and awareness amongst staff. A basic lack of awareness amongst staff often results in insufficient data being collected,' said Peyman Mestchian, head of the risk management practice, SAS UK.
'Employees may not always report losses and therefore impact the accuracy of data available. They need to be educated to a level where they are providing consistent information therefore improving data accuracy. Organisations can use the most sophisticated analytical tools in the world, however if they are not working with comprehensive, real-world data they will miss the real dangers. Inconsistent and inaccurate data will only provide problems and create disagreements. These issues need to be addressed as a matter of some urgency, particularly with latest draft of the New Basel Accord (Basel II) published in June,' continued Mestchian.
To comply with new regulations, organisations require systems that are both scalable and flexible. Systems need to combine qualitative and quantitative data and be able to link external data with internal data. Yet for many having the correct systems in place is still a major challenge.
Survey respondents ranked IT systems failure as the main source of operational risk. An area of growing importance was identified as customer relationship risk, with regulatory and compliance issues (including taxation) third."
Difficulties in collating clean data and poor awareness among staff are the major obstacles to effective operational risk management, according to a recent survey by Risk Waters Group and SAS.
The survey of more than 250 financial institutions and regulators identified managing data quality as the number one issue, with respondents reporting difficulties in collating sufficient volumes of historical data and in ensuring reliable data. The second most pressing issue was the poor overall awareness of operational risk issues by staff, due largely to lack of clear education programs in operational risk, lack of communication and limited knowledge sharing.
Regulations such as Basel II place a growing emphasis on operational risk management within financial institutions. Banks are compelled to gather data that they do not currently collect; they are also required to bring that data together from a host of disparate systems into one pool for analysis.
'The two key barriers to financial institutions achieving success relate to basic issues such as data quality and awareness amongst staff. A basic lack of awareness amongst staff often results in insufficient data being collected,' said Peyman Mestchian, head of the risk management practice, SAS UK.
'Employees may not always report losses and therefore impact the accuracy of data available. They need to be educated to a level where they are providing consistent information therefore improving data accuracy. Organisations can use the most sophisticated analytical tools in the world, however if they are not working with comprehensive, real-world data they will miss the real dangers. Inconsistent and inaccurate data will only provide problems and create disagreements. These issues need to be addressed as a matter of some urgency, particularly with latest draft of the New Basel Accord (Basel II) published in June,' continued Mestchian.
To comply with new regulations, organisations require systems that are both scalable and flexible. Systems need to combine qualitative and quantitative data and be able to link external data with internal data. Yet for many having the correct systems in place is still a major challenge.
Survey respondents ranked IT systems failure as the main source of operational risk. An area of growing importance was identified as customer relationship risk, with regulatory and compliance issues (including taxation) third."
Wednesday, August 11, 2004
Summer in the City: Unconventional Insurance and Olympian Security in Age of Terrorism Risk
Summer in the City: Unconventional Insurance and Olympian Security in Age of Terrorism Risk:
By Andrew G. Simpson, Jr.
A little more than a year ago, Britain's Prince William celebrated his 21st birthday with a costume party at Windsor Castle. While William was addressing the partying crowd, a stranger wearing a black beard, white turban and pink dress and looking a lot like Osama bin Laden bounded onto the stage, grabbed the microphone, spoke to the crowd and then planted a kiss on Prince William's cheek.
Despite the fact that the Osama look-alike was a comedian, few thought it a laughing matter. If the intruder had been a suicide bomber he could have killed all the senior members of the royal family who were onstage with William. British security forces were promptly taken to task for allowing the stranger to get so close. Immediate steps were taken to beef up security surrounding the royal family.
Summer Security
This summer, while the world is watching the Democratic National Convention (DNC) in Boston, the Republican National Convention (RNC) in New York City and the 2004 Olympic Games in Athens, security forces will be on full alert to prevent breaches like the one that concerned British security a year ago. In Boston, New York and Athens, officials maintain that every precaution is being taken to protect the participants and properties at these events from a close encounter with terrorism."
By Andrew G. Simpson, Jr.
A little more than a year ago, Britain's Prince William celebrated his 21st birthday with a costume party at Windsor Castle. While William was addressing the partying crowd, a stranger wearing a black beard, white turban and pink dress and looking a lot like Osama bin Laden bounded onto the stage, grabbed the microphone, spoke to the crowd and then planted a kiss on Prince William's cheek.
Despite the fact that the Osama look-alike was a comedian, few thought it a laughing matter. If the intruder had been a suicide bomber he could have killed all the senior members of the royal family who were onstage with William. British security forces were promptly taken to task for allowing the stranger to get so close. Immediate steps were taken to beef up security surrounding the royal family.
Summer Security
This summer, while the world is watching the Democratic National Convention (DNC) in Boston, the Republican National Convention (RNC) in New York City and the 2004 Olympic Games in Athens, security forces will be on full alert to prevent breaches like the one that concerned British security a year ago. In Boston, New York and Athens, officials maintain that every precaution is being taken to protect the participants and properties at these events from a close encounter with terrorism."
Monday, August 09, 2004
The Radical Leap in trust...A Security Lesson
The other day I received a package in the mail from Fast Company Magazine. I opened the brown padded envelope with the "Security Radar" that this looked like a questionable package. You know, the kind that they warn you about these days. The label looks like it was created by a 4th grader and the package is about a half inch thick and weighs in at about a pound and a half. Could this be the work of a clever "Social Engineer" who knows my modus operandi?
So I held my breath and opened it with great anticipation and fear at the same time. I had no idea it was coming. It's contents was not surprising. A book. A note. And a business card. The card was that of Heath Row, Fast Company Editorial and Community Director. Former Social Capitalist before the uprising. The Book was entitled The Radical Leap, by Steve Farber. The note from the publisher offering 40% off the retail price with orders of ten or more.
The real radical leap on this day was my faith in the label Fast Company. My vulnerability had been exploited by someone known to me. My trust in FC and the brand prompted me to forget everything I have been taught about suspicious packages like this one. Now I'm practicing LEAP every day. Cultivate Love. Generate Energy. Inspire Audacity, and Provide Proof. The lesson here is simple. A radical leap in trust can sometimes blind us from clear thinking. Be careful out there.
So I held my breath and opened it with great anticipation and fear at the same time. I had no idea it was coming. It's contents was not surprising. A book. A note. And a business card. The card was that of Heath Row, Fast Company Editorial and Community Director. Former Social Capitalist before the uprising. The Book was entitled The Radical Leap, by Steve Farber. The note from the publisher offering 40% off the retail price with orders of ten or more.
The real radical leap on this day was my faith in the label Fast Company. My vulnerability had been exploited by someone known to me. My trust in FC and the brand prompted me to forget everything I have been taught about suspicious packages like this one. Now I'm practicing LEAP every day. Cultivate Love. Generate Energy. Inspire Audacity, and Provide Proof. The lesson here is simple. A radical leap in trust can sometimes blind us from clear thinking. Be careful out there.
Friday, August 06, 2004
Dangerous Waters
Dangerous Waters: "
Distributed denial-of-service attacks may reshape the way courts evaluate liability for network security breaches.
BY WILLIAM COOK
Distributed denial-of-service (DDOS) attacks—the creation of a hostile computer network used to remotely shut down another network or website—continue to plague the Internet. In the past two years the Internet has experienced a 2,000 percent increase in worm-driven DDOS attacks. Some e-commerce websites have been completely shut down by the attacks and have reported as much as $250,000 in lost sales per half hour that they were down. But the damage doesn't stop there. The users of a victimized system can also suffer significant reputational loss from being unable to conduct business.
However, the legal response to DDOS attacks has been mixed. In the U.S. legal system, civil liability can arise from contract law, tort law or regulation. If one party breaches its contractual obligations, the law provides a remedy to the aggrieved party. Contract law, however, often fails to cover damage to third parties. Suppose a hacker breaks into Company A's inadequately secured network and then uses that network to attack Company B. The attack against Company B disables its networks, causing it to fail to deliver promised services to its customers. Although Company B has no contractual relationship with Company A, can B sue A for losses?
From a tort standpoint, many legal scholars, major law firms and a National Research Council Committee assert that the downstream victim can bring civil action for negligence against the upstream systems that were used as part of the DDOS attack. Reasoning that civil law intends to deter undesirable or wrongful conduct and to compensate those harmed by such conduct, legal theory posits that victims should be allowed to recover losses from third parties that were negligent if that negligence was the direct cause of the loss. In the Internet environment, negligent third parties may be the only source of loss recovery, since criminal law offers no compensation to the victim if the computer criminal cannot be identified. Furthermore, establishing the legal precedent to impose civil damages on a third party, such as a service provider that is proven to be negligent, could motivate companies to invest the necessary resources in improving security.
Distributed denial-of-service attacks may reshape the way courts evaluate liability for network security breaches.
BY WILLIAM COOK
Distributed denial-of-service (DDOS) attacks—the creation of a hostile computer network used to remotely shut down another network or website—continue to plague the Internet. In the past two years the Internet has experienced a 2,000 percent increase in worm-driven DDOS attacks. Some e-commerce websites have been completely shut down by the attacks and have reported as much as $250,000 in lost sales per half hour that they were down. But the damage doesn't stop there. The users of a victimized system can also suffer significant reputational loss from being unable to conduct business.
However, the legal response to DDOS attacks has been mixed. In the U.S. legal system, civil liability can arise from contract law, tort law or regulation. If one party breaches its contractual obligations, the law provides a remedy to the aggrieved party. Contract law, however, often fails to cover damage to third parties. Suppose a hacker breaks into Company A's inadequately secured network and then uses that network to attack Company B. The attack against Company B disables its networks, causing it to fail to deliver promised services to its customers. Although Company B has no contractual relationship with Company A, can B sue A for losses?
From a tort standpoint, many legal scholars, major law firms and a National Research Council Committee assert that the downstream victim can bring civil action for negligence against the upstream systems that were used as part of the DDOS attack. Reasoning that civil law intends to deter undesirable or wrongful conduct and to compensate those harmed by such conduct, legal theory posits that victims should be allowed to recover losses from third parties that were negligent if that negligence was the direct cause of the loss. In the Internet environment, negligent third parties may be the only source of loss recovery, since criminal law offers no compensation to the victim if the computer criminal cannot be identified. Furthermore, establishing the legal precedent to impose civil damages on a third party, such as a service provider that is proven to be negligent, could motivate companies to invest the necessary resources in improving security.
Wednesday, August 04, 2004
IT Spending for Compliance: From SOX 404 to Comprehensive Compliance
IT Spending for Compliance: From SOX 404 to Comprehensive Compliance:
Financial Insights estimates that North American financial institutions spent over $100 million on enterprise performance management solutions in the U.S. and Canada in 2003. This number will grow to $174 million in 2004 and will reach $450 million 2008.
Beyond Sarbanes-Oxley, Comprehensive Compliance
Given the similarities in the applications and infrastructure components required to comply with new regulations impacting financial services firms, including the PATRIOT Act and Basel II, we estimate that a key long-term trend in the market for compliance solutions will be application and infrastructure integration.
On the infrastructure side, we foresee that the data infrastructure supporting compliance activities will become more and more integrated through data warehouses or through applications that can connect to disparate sources. On the application side, we are already seeing firms invest in solutions that meet both anti-money laundering requirements prescribed by the PATRIOT Act as well as SEC and Sarbanes-Oxley-related requirements to monitor for internal fraud and for compliance breaches with securities laws. Investments in such AML/Surveillance solutions have been particularly strong among securities firms.
Specific to Sarbanes-Oxley compliance, we estimate that SOX 404 solutions will become more and more integrated with enterprise performance management applications to facilitate the regulatory reporting process.
Integration will take time. Technologically, it is already here today and IT vendors have been ready with partnerships and attractive solutions. Culturally and organizationally, it is not. Financial services firms have much internal work to do before they can begin to combine disparate compliance processes. Until this time, investments in IT for compliance will continue to remain focused on specific regulations. "
Financial Insights estimates that North American financial institutions spent over $100 million on enterprise performance management solutions in the U.S. and Canada in 2003. This number will grow to $174 million in 2004 and will reach $450 million 2008.
Beyond Sarbanes-Oxley, Comprehensive Compliance
Given the similarities in the applications and infrastructure components required to comply with new regulations impacting financial services firms, including the PATRIOT Act and Basel II, we estimate that a key long-term trend in the market for compliance solutions will be application and infrastructure integration.
On the infrastructure side, we foresee that the data infrastructure supporting compliance activities will become more and more integrated through data warehouses or through applications that can connect to disparate sources. On the application side, we are already seeing firms invest in solutions that meet both anti-money laundering requirements prescribed by the PATRIOT Act as well as SEC and Sarbanes-Oxley-related requirements to monitor for internal fraud and for compliance breaches with securities laws. Investments in such AML/Surveillance solutions have been particularly strong among securities firms.
Specific to Sarbanes-Oxley compliance, we estimate that SOX 404 solutions will become more and more integrated with enterprise performance management applications to facilitate the regulatory reporting process.
Integration will take time. Technologically, it is already here today and IT vendors have been ready with partnerships and attractive solutions. Culturally and organizationally, it is not. Financial services firms have much internal work to do before they can begin to combine disparate compliance processes. Until this time, investments in IT for compliance will continue to remain focused on specific regulations. "
Tuesday, August 03, 2004
Recovery Point provides comprehensive, availability end-user hotsite recovery services
Recovery Point
Recovery Point Systems provides comprehensive, availability end-user hotsite recovery services for mission critical, business continuity conscious clients to implement disaster recovery plans including server mirroring, serverhosting, electronic vaulting, workgroup recovery, off-site storage and co-location.
"The replacement facilities on which you stake your organization's ability to survive during a crisis must function smoothly and reliably. We've built redundancy and durability into every critical component of the site so you can rely on our high availability services every day.
* Secure facility with CCTV, access control and 365-day staffing 100 acoustical workspaces with locking storage, expandable to 200
* Owner-occupied site with private parking
* Convenient to major highway, rail and air transportation
* All weather, voice/data 'hitching post' for connectivity to mobile technologies
* Dual diverse fiber feeds via SONET self-healing ring to redundant central offices
* Full UPS support for entire recovery center
* Secure server and telecommunications facilities
* Redundant generator power, ATS and seven-day fuel supply
* Redundant HVAC services
* Full truck loading facilities to support client re-supply during occupancy
* Conference room with satellite TV feed and video-conferencing
* kitchenette, strategy room and six semi-private offices
* UL master building label for lightning protection
Recovery Point Systems is an affiliate of First Federal Corporation, the Baltimore-Washington DC region's leading provider of secure, off-site data storage services for over 20 years. We have the experience, the staff and the resources to meet your recovery requirements in today's complex environment."
Recovery Point Systems provides comprehensive, availability end-user hotsite recovery services for mission critical, business continuity conscious clients to implement disaster recovery plans including server mirroring, serverhosting, electronic vaulting, workgroup recovery, off-site storage and co-location.
"The replacement facilities on which you stake your organization's ability to survive during a crisis must function smoothly and reliably. We've built redundancy and durability into every critical component of the site so you can rely on our high availability services every day.
* Secure facility with CCTV, access control and 365-day staffing 100 acoustical workspaces with locking storage, expandable to 200
* Owner-occupied site with private parking
* Convenient to major highway, rail and air transportation
* All weather, voice/data 'hitching post' for connectivity to mobile technologies
* Dual diverse fiber feeds via SONET self-healing ring to redundant central offices
* Full UPS support for entire recovery center
* Secure server and telecommunications facilities
* Redundant generator power, ATS and seven-day fuel supply
* Redundant HVAC services
* Full truck loading facilities to support client re-supply during occupancy
* Conference room with satellite TV feed and video-conferencing
* kitchenette, strategy room and six semi-private offices
* UL master building label for lightning protection
Recovery Point Systems is an affiliate of First Federal Corporation, the Baltimore-Washington DC region's leading provider of secure, off-site data storage services for over 20 years. We have the experience, the staff and the resources to meet your recovery requirements in today's complex environment."
Monday, August 02, 2004
Bush Backs Creating U.S. Antiterrorism Chief
Bush Backs Creating U.S. Antiterrorism Chief
By Frank Csongos
The United States is planning to undertake new measures to fight the Al-Qaeda network and its allies.
Washington, 2 August 2004 (RFE/RL) -- U.S. President George W. Bush has endorsed creating the position of a national intelligence director to oversea the United States' domestic- and foreign-intelligence operations in combating terrorism.
Bush, speaking at the White House today, said the new intelligence chief would be appointed by the president and subject to confirmation by the U.S. Senate.
'The national intelligence director will serve as the president's principal intelligence adviser and will oversee and coordinate the foreign and domestic activities of the intelligence community,' Bush said.
The president said the reorganization of U.S. intelligence services is aimed at creating a better integrated, thoroughly united, and more efficient antiterrorism operation.
The new post was among the recommendations of the official commission that investigated lapses in intelligence that left the United States vulnerable to the 11 September 2001 terrorist attacks.
'The best way to protect the American homeland is to stay on the offense.' -- Bush
'Oversight of intelligence and of...homeland security must be restructured and made more effective,' Bush said. 'There are too many committees with overlapping jurisdiction, which wastes time and makes it difficult for meaningful oversight and reform.'
Bush also adopted another key recommendation of the 9-11 commission -- that of creating a National Counterterrorism Center.
'This new center will build on the analytical work -- the really good analytical work -- of the Terrorist Threat Integration Center and will become our government's knowledge bank for information about known and suspected terrorists,' Bush said. 'The new center will coordinate and monitor counterterrorism plans and activities of all government agencies and departments.'
Leaders of the bipartisan 9-11 commission have insisted that the center and the position of national-intelligence director be placed in the executive office of the president. But Bush said he wants them to be set up outside the White House.
The president said the director and the center should be a 'stand- alone group' to better coordinate.
Bush also dismissed critics who said the war on Iraq has detracted U.S. efforts to fight terrorism.
'The best way to protect the American homeland is to stay on the offense. It is a ridiculous notion to assert that because the United States is on the offense, more people want to hurt us,' Bush said.
Under the reorganization, the Central Intelligence Agency would be managed by a separate director. The national-intelligence director would assume greater responsibility for leading and coordinating intelligence operations both inside and outside the United States.
The president's endorsement for the new post came after U.S. law enforcement authorities strengthened security at financial institutions in New York City; Washington, D.C.; and Newark, New Jersey, following what the U.S. government called extraordinary specific terror threats."
By Frank Csongos
The United States is planning to undertake new measures to fight the Al-Qaeda network and its allies.
Washington, 2 August 2004 (RFE/RL) -- U.S. President George W. Bush has endorsed creating the position of a national intelligence director to oversea the United States' domestic- and foreign-intelligence operations in combating terrorism.
Bush, speaking at the White House today, said the new intelligence chief would be appointed by the president and subject to confirmation by the U.S. Senate.
'The national intelligence director will serve as the president's principal intelligence adviser and will oversee and coordinate the foreign and domestic activities of the intelligence community,' Bush said.
The president said the reorganization of U.S. intelligence services is aimed at creating a better integrated, thoroughly united, and more efficient antiterrorism operation.
The new post was among the recommendations of the official commission that investigated lapses in intelligence that left the United States vulnerable to the 11 September 2001 terrorist attacks.
'The best way to protect the American homeland is to stay on the offense.' -- Bush
'Oversight of intelligence and of...homeland security must be restructured and made more effective,' Bush said. 'There are too many committees with overlapping jurisdiction, which wastes time and makes it difficult for meaningful oversight and reform.'
Bush also adopted another key recommendation of the 9-11 commission -- that of creating a National Counterterrorism Center.
'This new center will build on the analytical work -- the really good analytical work -- of the Terrorist Threat Integration Center and will become our government's knowledge bank for information about known and suspected terrorists,' Bush said. 'The new center will coordinate and monitor counterterrorism plans and activities of all government agencies and departments.'
Leaders of the bipartisan 9-11 commission have insisted that the center and the position of national-intelligence director be placed in the executive office of the president. But Bush said he wants them to be set up outside the White House.
The president said the director and the center should be a 'stand- alone group' to better coordinate.
Bush also dismissed critics who said the war on Iraq has detracted U.S. efforts to fight terrorism.
'The best way to protect the American homeland is to stay on the offense. It is a ridiculous notion to assert that because the United States is on the offense, more people want to hurt us,' Bush said.
Under the reorganization, the Central Intelligence Agency would be managed by a separate director. The national-intelligence director would assume greater responsibility for leading and coordinating intelligence operations both inside and outside the United States.
The president's endorsement for the new post came after U.S. law enforcement authorities strengthened security at financial institutions in New York City; Washington, D.C.; and Newark, New Jersey, following what the U.S. government called extraordinary specific terror threats."
Sunday, August 01, 2004
Secretary Ridge Announces Threat Level Code Orange for Financial Sector in New York City, Northern New Jersey and Washington, D.C.
DHS | Department of Homeland Security | DHS Home Page:
August 1, 2004 - Good afternoon. President Bush has told you, and I have told you, when we have specific credible information, we will share it.
This afternoon, we do have new and unusually specific information about where al Qaida would like to attack. As a result, today, the United States Government is raising the threat level to Code Orange for the financial services sector in New York City, Northern New Jersey and Washington, D.C.
Since September 11th, 2001, leaders of our commercial financial institutions have demonstrated exceptional leadership in improving its security. However, in light of new intelligence information, we have made the decision to raise the threat level for this sector, in these communities, to bring protective resources to their highest capacity. This will allow us to increase protection in and around those buildings that require it and also raise awareness for employees, residents, customers and visitors. We know from experience that increased physical protection and added vigilance from citizens can thwart a terrorist attack. And that is our goal.
This is the first time we have chosen to use the Homeland Security Advisory System in such a targeted way. Compared to previous threat reporting, these intelligence reports have provided a level of detail that is very specific. The quality of this intelligence, based on multiple reporting streams in multiple locations, is rarely seen and is alarming in both the amount and specificity of the information.
While we are providing you with this immediate information, we will continue to update you as the situation unfolds. As of now, this is what we know: reports indicate that al Qaida is targeting several specific buildings, including the International Monetary Fund and World Bank in D.C.; Prudential Financial in Northern New Jersey; and Citigroup buildings and the New York Stock Exchange in New York. Let me assure you, actions to further strengthen security around these buildings are already underway. Additionally, we’re concerned about targets beyond these and are working to get more information."
August 1, 2004 - Good afternoon. President Bush has told you, and I have told you, when we have specific credible information, we will share it.
This afternoon, we do have new and unusually specific information about where al Qaida would like to attack. As a result, today, the United States Government is raising the threat level to Code Orange for the financial services sector in New York City, Northern New Jersey and Washington, D.C.
Since September 11th, 2001, leaders of our commercial financial institutions have demonstrated exceptional leadership in improving its security. However, in light of new intelligence information, we have made the decision to raise the threat level for this sector, in these communities, to bring protective resources to their highest capacity. This will allow us to increase protection in and around those buildings that require it and also raise awareness for employees, residents, customers and visitors. We know from experience that increased physical protection and added vigilance from citizens can thwart a terrorist attack. And that is our goal.
This is the first time we have chosen to use the Homeland Security Advisory System in such a targeted way. Compared to previous threat reporting, these intelligence reports have provided a level of detail that is very specific. The quality of this intelligence, based on multiple reporting streams in multiple locations, is rarely seen and is alarming in both the amount and specificity of the information.
While we are providing you with this immediate information, we will continue to update you as the situation unfolds. As of now, this is what we know: reports indicate that al Qaida is targeting several specific buildings, including the International Monetary Fund and World Bank in D.C.; Prudential Financial in Northern New Jersey; and Citigroup buildings and the New York Stock Exchange in New York. Let me assure you, actions to further strengthen security around these buildings are already underway. Additionally, we’re concerned about targets beyond these and are working to get more information."
Friday, July 30, 2004
Terrorism Risk Management...
Over the past few months’ 1SecureAudit LLC has conducted an independent online poll to determine the areas of Operational Risk that are the largest focus of organizations right now. The results are as follows:
People - 22%
Processes - 31%
Systems - 28%
External Events - 19%
Processes (31%) and Systems (28%) are the two areas that CxO’s have the most control over and are the two main areas that they are working on right now to help mitigate risks.
This means that they have transferred or accepted the risk in the other two areas of Operational Risk Management, People (22%) and External events (19%). The key mechanism for the transfer of risk of people (fraud) and external events (natural disaster) is through insurance. There is a tremendous amount of existing data that the insurance industry understands and therefore they can create the economical products to effectively serve the interests of the corporate organization to hedge these areas of risk, except one. Terrorism Risk.
Terrorism Risk Management
Terrorism Risk includes the risk from attackers both internal and external to the organization. These attackers are using conventional (incendiary explosive devices) and unconventional (digital worms) methods to disrupt the operations and economic well being of corporate organizations, the real estate finance industry and of our critical infrastructures.
The process and systems for managing Terrorism Risk are rapidly changing as the commercial real estate finance and building owners strive to establish new standards. Critical Infrastructure Protection is now a national priority. The key catalysts for change could further motivate infrastructure owners to implement new risk reduction programs and measures.
Some of the key catalysts for change are:
· Insurance – those institutions that are sharing risks that a building owner faces.
· Finance – banks, REIT’s (Real Estate Investment Trusts), and others such as pension funds that provide the capital for investments in commercial infrastructure.
· Regulation – Federal, State and Local jurisdictions that regulate building design, construction and operations.
Overall Terrorism Risk reduction begins with these key catalysts in concert with owners of critical infrastructure, whether that is a corporate office building, a hospital, subway, or a hotel. These soft targets are where the risk management decision-making is already taking new directions.
In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen. Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future. First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.
The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures. The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure. In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles. These need to be exercised on a continuous timetable with extensive documentation, training and reporting.
People - 22%
Processes - 31%
Systems - 28%
External Events - 19%
Processes (31%) and Systems (28%) are the two areas that CxO’s have the most control over and are the two main areas that they are working on right now to help mitigate risks.
This means that they have transferred or accepted the risk in the other two areas of Operational Risk Management, People (22%) and External events (19%). The key mechanism for the transfer of risk of people (fraud) and external events (natural disaster) is through insurance. There is a tremendous amount of existing data that the insurance industry understands and therefore they can create the economical products to effectively serve the interests of the corporate organization to hedge these areas of risk, except one. Terrorism Risk.
Terrorism Risk Management
Terrorism Risk includes the risk from attackers both internal and external to the organization. These attackers are using conventional (incendiary explosive devices) and unconventional (digital worms) methods to disrupt the operations and economic well being of corporate organizations, the real estate finance industry and of our critical infrastructures.
The process and systems for managing Terrorism Risk are rapidly changing as the commercial real estate finance and building owners strive to establish new standards. Critical Infrastructure Protection is now a national priority. The key catalysts for change could further motivate infrastructure owners to implement new risk reduction programs and measures.
Some of the key catalysts for change are:
· Insurance – those institutions that are sharing risks that a building owner faces.
· Finance – banks, REIT’s (Real Estate Investment Trusts), and others such as pension funds that provide the capital for investments in commercial infrastructure.
· Regulation – Federal, State and Local jurisdictions that regulate building design, construction and operations.
Overall Terrorism Risk reduction begins with these key catalysts in concert with owners of critical infrastructure, whether that is a corporate office building, a hospital, subway, or a hotel. These soft targets are where the risk management decision-making is already taking new directions.
In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen. Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future. First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.
The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures. The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure. In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles. These need to be exercised on a continuous timetable with extensive documentation, training and reporting.
Thursday, July 29, 2004
Sarbanes-Oxley Readiness...
Following are sample questions from the Sections 302 and 404 Readiness Assessment by Deloitte.
Has your company:
1. Adopted a formal implementation plan (including a timetable) to address the requirements of Sections 302 and 404 of Sarbanes-Oxley?
2. Established communication channels among management, the board of directors, and the audit committee to ensure a timely discussion of the status and issues related to Sections 302 and 404 of Sarbanes-Oxley?
3. Incorporated steps within its implementation plan to address all five elements (control environment, risk assessment, control activities, information and communication and monitoring) of the COSO internal control framework?
4. Established an enterprise-wide control and risk management program in which controls and procedures are documented and continually reevaluated in response to major process or organizational changes?
Has your company:
1. Adopted a formal implementation plan (including a timetable) to address the requirements of Sections 302 and 404 of Sarbanes-Oxley?
2. Established communication channels among management, the board of directors, and the audit committee to ensure a timely discussion of the status and issues related to Sections 302 and 404 of Sarbanes-Oxley?
3. Incorporated steps within its implementation plan to address all five elements (control environment, risk assessment, control activities, information and communication and monitoring) of the COSO internal control framework?
4. Established an enterprise-wide control and risk management program in which controls and procedures are documented and continually reevaluated in response to major process or organizational changes?
Wednesday, July 28, 2004
Top 10 Most Effective Cybercrime Policies
Top 10 Most Effective Cybercrime Policies
CSO recently partnered with Carnegie Mellon's CERT Coordination Center and the U.S. Secret Service to survey the cybercrime landscape. Here are the methods that our 500 respondents identified as the most effective to fight e-crime.
1. Engage in internal employee monitoring.
2. Have a written inappropriate-use policy.
3. Require employees and contractors to sign acceptable-use policies.
4. Monitor Internet connections.
5. Require internal reporting to management of insider misuse and abuse.
6. Host employee education and awareness programs.
7. Develop a corporate security policy.
8. Conduct new employee security training.
9. Do periodic risk assessments.
10. Conduct regular security audits."
CSO recently partnered with Carnegie Mellon's CERT Coordination Center and the U.S. Secret Service to survey the cybercrime landscape. Here are the methods that our 500 respondents identified as the most effective to fight e-crime.
1. Engage in internal employee monitoring.
2. Have a written inappropriate-use policy.
3. Require employees and contractors to sign acceptable-use policies.
4. Monitor Internet connections.
5. Require internal reporting to management of insider misuse and abuse.
6. Host employee education and awareness programs.
7. Develop a corporate security policy.
8. Conduct new employee security training.
9. Do periodic risk assessments.
10. Conduct regular security audits."
Tuesday, July 27, 2004
64% of Companies Have Dedicated Regulatory Compliance Budgets
64% of Companies Have Dedicated Regulatory Compliance Budgets
By: SmartPros Editorial Staff
-- Sixty-four percent of companies currently have budgets dedicated to financial regulatory compliance, with the average budget projected to be $7.2 million in 2005. Among those companies without a current budget, more than half (54 percent) plan to allocate money for compliance initiatives within the next 12 months.
META Group Inc. released its study, 'Organizational Trends in Sarbanes-Oxley and Regulatory Compliance Issues,' which found that companies are dispersing compliance-related spending across a wide range of financial and accounting regulations:
* 56 percent of companies surveyed have allocated resources for compliance with Sarbanes-Oxley (SOX) and the Health Insurance Portability and Accountability Act (HIPAA) regulations
* 48 percent are reserving a portion of compliance spending for USA PATRIOT Act-related initiatives.
* 35 percent have earmarked money for compliance with Financial Modernization Act and 33 percent for Basel II requirements.
* 28 percent have allocated budget for SEC Rule 17a-4, and 27 percent for International Accounting Standards initiatives.
Despite the broad range of funding, the study found one dominant compliance driver: 'SOX has had a significant impact on how regulatory compliance has been viewed and managed,' said Jon Van Decker, vice president with META Group's Enterprise Application Strategies. 'What makes SOX different is the heightened level of security around non-compliance. CIOs as well as other officers of a company can be liable for inaccurate information or insufficient controls, with the possibility of fines or prison sentences.'
Although the severity of non-compliance has elevated SOX management to the highest executive levels within organizations, the study found that most compliance stakeholders are unclear as to where they fit in the compliance plan, relative to their peers. Moreover, those executives presumed to be in charge of compliance may be taking a much more limited role than previously thought.
Less than one-third of study respondents indicated reliance on the CFO as the primary role within compliance. In addition, only 16 percent of companies have tasked the CFO with supervision of the chief compliance officer (CCO) position. Similarly, while many compliance solutions are initially perceived as services solutions, the CIO is often not involved in the final decision-making stages. As a result, only 14 percent of CCOs report into the CIO position."
By: SmartPros Editorial Staff
-- Sixty-four percent of companies currently have budgets dedicated to financial regulatory compliance, with the average budget projected to be $7.2 million in 2005. Among those companies without a current budget, more than half (54 percent) plan to allocate money for compliance initiatives within the next 12 months.
META Group Inc. released its study, 'Organizational Trends in Sarbanes-Oxley and Regulatory Compliance Issues,' which found that companies are dispersing compliance-related spending across a wide range of financial and accounting regulations:
* 56 percent of companies surveyed have allocated resources for compliance with Sarbanes-Oxley (SOX) and the Health Insurance Portability and Accountability Act (HIPAA) regulations
* 48 percent are reserving a portion of compliance spending for USA PATRIOT Act-related initiatives.
* 35 percent have earmarked money for compliance with Financial Modernization Act and 33 percent for Basel II requirements.
* 28 percent have allocated budget for SEC Rule 17a-4, and 27 percent for International Accounting Standards initiatives.
Despite the broad range of funding, the study found one dominant compliance driver: 'SOX has had a significant impact on how regulatory compliance has been viewed and managed,' said Jon Van Decker, vice president with META Group's Enterprise Application Strategies. 'What makes SOX different is the heightened level of security around non-compliance. CIOs as well as other officers of a company can be liable for inaccurate information or insufficient controls, with the possibility of fines or prison sentences.'
Although the severity of non-compliance has elevated SOX management to the highest executive levels within organizations, the study found that most compliance stakeholders are unclear as to where they fit in the compliance plan, relative to their peers. Moreover, those executives presumed to be in charge of compliance may be taking a much more limited role than previously thought.
Less than one-third of study respondents indicated reliance on the CFO as the primary role within compliance. In addition, only 16 percent of companies have tasked the CFO with supervision of the chief compliance officer (CCO) position. Similarly, while many compliance solutions are initially perceived as services solutions, the CIO is often not involved in the final decision-making stages. As a result, only 14 percent of CCOs report into the CIO position."
Monday, July 26, 2004
eEye Digital Security - Vulnerability Management Solutions
eEye Digital Security - Vulnerability Management Solutions: "
Why Does the Industry Need Blink?
Unknown vulnerabilities represent the greatest threat to enterprises’ digital assets. Contrary to popular belief, many hackers do not wish for worms to be released, as this galvanizes enterprises to patch machines that could otherwise be used as doors into a network. This will continue to be a growing issue as enterprises become more successful at proactive vulnerability assessment and remediation – hackers will focus on ways to compromise systems in a “zero-day” fashion. Since Blink operates by stopping the activity that results from an attack rather than the signature of the attack itself, this technology is able to stop even unknown vulnerabilities from being exploited.
Additionally, as the window continues to shrink between the time vulnerabilities are announced and when enterprises are able to patch their systems, the costs incurred by companies through patch management will continue to grow. A company with thousands of machines in its network can expect to experience millions of dollars in lost productivity and business disruption when patching is immediately required. As a result, enterprises need the ability to defer patching to scheduled maintenance cycles, as well as intermediate protection from attacks that intend to leverage the unpatched vulnerability. By protecting individual machines, Blink allows corporations to patch their systems on a less disruptive, more cost-effective schedule.
Likewise, although the vast majority of enterprises have network-level security elements in place (e.g., firewalls, IDS/IPS, etc.), many remote workers, such as mobile workers, teleworkers, contractors and others, unintentionally acquire vulnerabilities “in the wild” and introduce these vulnerabilities to the corporate network once they reconnect. This internal attack vector is becoming a frequent cause of worms and virus outbreaks. Blink provides the means to isolate and evaluate each machine prior to its reconnection to the network. If any of Blink’s security mechanisms detect unusual behavior, the machine is isolated via its application and system-level firewalls, and the attack is prevented.
Blink also helps enterprises enforce policy compliance by constantly auditing corporate security standard configurations to reduce the risk of compromise. Finally, traditional security measures offer no defense against socially engineered security threats that attack from inside the organization. Even if a user unwittingly downloads a virus or worm, Blink is able to recognize the harmful activity, shut down the offending application, and isolate the machine from the rest of the network.
Why Does the Industry Need Blink?
Unknown vulnerabilities represent the greatest threat to enterprises’ digital assets. Contrary to popular belief, many hackers do not wish for worms to be released, as this galvanizes enterprises to patch machines that could otherwise be used as doors into a network. This will continue to be a growing issue as enterprises become more successful at proactive vulnerability assessment and remediation – hackers will focus on ways to compromise systems in a “zero-day” fashion. Since Blink operates by stopping the activity that results from an attack rather than the signature of the attack itself, this technology is able to stop even unknown vulnerabilities from being exploited.
Additionally, as the window continues to shrink between the time vulnerabilities are announced and when enterprises are able to patch their systems, the costs incurred by companies through patch management will continue to grow. A company with thousands of machines in its network can expect to experience millions of dollars in lost productivity and business disruption when patching is immediately required. As a result, enterprises need the ability to defer patching to scheduled maintenance cycles, as well as intermediate protection from attacks that intend to leverage the unpatched vulnerability. By protecting individual machines, Blink allows corporations to patch their systems on a less disruptive, more cost-effective schedule.
Likewise, although the vast majority of enterprises have network-level security elements in place (e.g., firewalls, IDS/IPS, etc.), many remote workers, such as mobile workers, teleworkers, contractors and others, unintentionally acquire vulnerabilities “in the wild” and introduce these vulnerabilities to the corporate network once they reconnect. This internal attack vector is becoming a frequent cause of worms and virus outbreaks. Blink provides the means to isolate and evaluate each machine prior to its reconnection to the network. If any of Blink’s security mechanisms detect unusual behavior, the machine is isolated via its application and system-level firewalls, and the attack is prevented.
Blink also helps enterprises enforce policy compliance by constantly auditing corporate security standard configurations to reduce the risk of compromise. Finally, traditional security measures offer no defense against socially engineered security threats that attack from inside the organization. Even if a user unwittingly downloads a virus or worm, Blink is able to recognize the harmful activity, shut down the offending application, and isolate the machine from the rest of the network.
Friday, July 23, 2004
Experts laud U.S. program to counter bioterror attack
Experts laud U.S. program to counter bioterror attack:
Matthew B. Stannard, Chronicle Staff
San Diego -- Fast action and the right medicines can save tens of thousands of lives in the event of a bioterror attack, a Stanford expert told a bioweapons conference just hours after President Bush announced Project BioShield, a $5.6 billion program to develop stockpiles of vaccines and antidotes for chemical and biological weapons.
'The most important thing for saving people is ... treating people before they become symptomatic,' said Dean Wilkening, director of science at Stanford's Center for International Security and Cooperation.
Bioweapons, which require days or weeks of incubation to become deadly, provide a crucial window of opportunity to treat those at risk, Wilkening said at a program Wednesday on public policy and biological threats for the Institute on Global Conflict and Cooperation at UC San Diego.
'You have to detect the event and get medicine into people's mouths within this window of opportunity,' he said. 'If enough people become symptomatic ... you've lost the game.'
In the case of anthrax, for example, which has a 2- to 4-day incubation period, if exposed people are treated before that window closes, as many as 95 percent may be saved, Wilkening estimated. But if it takes two weeks to procure the antidote, that figure could drop to 20 percent.
Project BioShield, which Bush signed into law on Wednesday, provides incentives to the drug industry to research and develop bioterror countermeasures, speeds up the approval process for antidotes and lets the government distribute treatments in an emergency, even before they receive Food and Drug Administration approval.
In signing the legislation, Bush said, 'We refuse to remain idle while modern technology might be turned against us,' and promised to enlist American science to 'confront the greatest danger of our time.' He noted that many of the legislators who passed it had 'experienced bioterror firsthand when anthrax and ricin were found on Capitol Hill.''"
Matthew B. Stannard, Chronicle Staff
San Diego -- Fast action and the right medicines can save tens of thousands of lives in the event of a bioterror attack, a Stanford expert told a bioweapons conference just hours after President Bush announced Project BioShield, a $5.6 billion program to develop stockpiles of vaccines and antidotes for chemical and biological weapons.
'The most important thing for saving people is ... treating people before they become symptomatic,' said Dean Wilkening, director of science at Stanford's Center for International Security and Cooperation.
Bioweapons, which require days or weeks of incubation to become deadly, provide a crucial window of opportunity to treat those at risk, Wilkening said at a program Wednesday on public policy and biological threats for the Institute on Global Conflict and Cooperation at UC San Diego.
'You have to detect the event and get medicine into people's mouths within this window of opportunity,' he said. 'If enough people become symptomatic ... you've lost the game.'
In the case of anthrax, for example, which has a 2- to 4-day incubation period, if exposed people are treated before that window closes, as many as 95 percent may be saved, Wilkening estimated. But if it takes two weeks to procure the antidote, that figure could drop to 20 percent.
Project BioShield, which Bush signed into law on Wednesday, provides incentives to the drug industry to research and develop bioterror countermeasures, speeds up the approval process for antidotes and lets the government distribute treatments in an emergency, even before they receive Food and Drug Administration approval.
In signing the legislation, Bush said, 'We refuse to remain idle while modern technology might be turned against us,' and promised to enlist American science to 'confront the greatest danger of our time.' He noted that many of the legislators who passed it had 'experienced bioterror firsthand when anthrax and ricin were found on Capitol Hill.''"
Thursday, July 22, 2004
Phishing Attacks Linked To Organized Crime
Bank Systems & Technology > Phishing Attacks Linked To Organized Crime:
Michael Cohn, Security Pipeline
'There's a lot of activity in the former Soviet bloc, the Eastern bloc, Latvia and Ukraine,' says John Curran, supervisory special agent with the Federal Bureau of Investigation's Internet Crime Complaint Center. 'It definitely looks like there are organized groups.'
Phishing involves sending fraudulent e-mails that appears to be from a legitimate organization -- such as a bank, credit card company, online merchant or Internet service provider -- asking the recipient to divulge personal and financial information like birth dates, Social Security numbers and PIN codes. Unlucky victims are then subject to identity theft, monetary losses and credit card fraud.
While Curran notes that a broad array of criminals appears to be involved in phishing attacks, ranging from teenagers to grandmothers, the FBI is investigating links to organized crime. So far, Curran hasn't seen any indication that crime syndicates with ties to the Mafia are involved.
The U.S. Secret Service has also noted an increase in organized crime involvement in phishing. At AIT Global's Annual InfoSec Meeting at the United Nations in June, Robert Caltabiano, assistant to the special agent in charge in the New York Field Office of the U.S. Secret Service, pointed to the increasing presence of organized crime in phishing attacks. Although Caltabiano recommended that victims first go to local law enforcement for help, he noted, 'With phishing attacks, the information goes global.'"
Michael Cohn, Security Pipeline
'There's a lot of activity in the former Soviet bloc, the Eastern bloc, Latvia and Ukraine,' says John Curran, supervisory special agent with the Federal Bureau of Investigation's Internet Crime Complaint Center. 'It definitely looks like there are organized groups.'
Phishing involves sending fraudulent e-mails that appears to be from a legitimate organization -- such as a bank, credit card company, online merchant or Internet service provider -- asking the recipient to divulge personal and financial information like birth dates, Social Security numbers and PIN codes. Unlucky victims are then subject to identity theft, monetary losses and credit card fraud.
While Curran notes that a broad array of criminals appears to be involved in phishing attacks, ranging from teenagers to grandmothers, the FBI is investigating links to organized crime. So far, Curran hasn't seen any indication that crime syndicates with ties to the Mafia are involved.
The U.S. Secret Service has also noted an increase in organized crime involvement in phishing. At AIT Global's Annual InfoSec Meeting at the United Nations in June, Robert Caltabiano, assistant to the special agent in charge in the New York Field Office of the U.S. Secret Service, pointed to the increasing presence of organized crime in phishing attacks. Although Caltabiano recommended that victims first go to local law enforcement for help, he noted, 'With phishing attacks, the information goes global.'"
Wednesday, July 21, 2004
Operational Risk Enterprise Architecture (OREA)
The operational risks facing corporate organizations today are found across a wide spectrum:
Now take this and multiply by the number of business units or lines of business in your organization. Now multiply this by the industry environments you operate in, the countries you operate in and the number of transactions you do on an annual basis. This will give you an idea of all of the places you have the potential to experience a "Loss Event." These add up over the course of a day, week, month and quarter to erode your earnings, performance and competitive position.
The only way to come close to managing such a dynamically changing foe is to first understand how the architecture of your business is interdependent or dependent on various components that make up it's structure. Only then can you begin to understand why certain loss events happen and what environment or characteristics make it more probable that they will occur.
Recently, a new law in the US called the Identity Theft Penalty Enhancement Act was signed by President Bush. What is interesting about this fact is that it wasn't until Phishing victims lost $1.2 Billion to identity theft related fraud between 2003 and 2004 that the banking industry, the FTC and our legislators understood one of the important facts in accelerating the mitigation of these loss events. Make the penalties for getting caught more severe, if they ever get caught. The law also allows the US Sentencing Commission to potentially increase the penalties for employees who steal sensitive information from their employers. Watch for more on this in the months to come.
The speed of change in the connected economy has finally subjected modern criminal organizations to finally be acknowledged that they are a larger target for law enforcement and our justice system. Only through effective operational risk architecture will our institutions be able to detect, deter and defend against the next wave of threats to our people, processes, systems and critical infrastructures.
- People
- Processes
- Systems
- External Events
Now take this and multiply by the number of business units or lines of business in your organization. Now multiply this by the industry environments you operate in, the countries you operate in and the number of transactions you do on an annual basis. This will give you an idea of all of the places you have the potential to experience a "Loss Event." These add up over the course of a day, week, month and quarter to erode your earnings, performance and competitive position.
The only way to come close to managing such a dynamically changing foe is to first understand how the architecture of your business is interdependent or dependent on various components that make up it's structure. Only then can you begin to understand why certain loss events happen and what environment or characteristics make it more probable that they will occur.
Recently, a new law in the US called the Identity Theft Penalty Enhancement Act was signed by President Bush. What is interesting about this fact is that it wasn't until Phishing victims lost $1.2 Billion to identity theft related fraud between 2003 and 2004 that the banking industry, the FTC and our legislators understood one of the important facts in accelerating the mitigation of these loss events. Make the penalties for getting caught more severe, if they ever get caught. The law also allows the US Sentencing Commission to potentially increase the penalties for employees who steal sensitive information from their employers. Watch for more on this in the months to come.
The speed of change in the connected economy has finally subjected modern criminal organizations to finally be acknowledged that they are a larger target for law enforcement and our justice system. Only through effective operational risk architecture will our institutions be able to detect, deter and defend against the next wave of threats to our people, processes, systems and critical infrastructures.
Tuesday, July 20, 2004
Fact Sheet: A Better Prepared America: A Year in Review
DHS | Department of Homeland Security | Fact Sheet: A Better Prepared America: A Year in Review:
Fact Sheet: A Better Prepared America: A Year in Review
“Much like homeland security in general, America’s preparedness requires everyone’s help. That’s why we’ve called you together – to continue building an important partnership – one that will result in an enduring and successful strategy for emergency preparedness across the country.”
– Secretary of Homeland Security Tom Ridge
Today, the Department of Homeland Security, the American Red Cross, the George Washington University Homeland Security Policy Institute and the Council for Excellence in Government brought together leaders in disaster preparedness, and response and recovery as part of the “Public Preparedness – A National Imperative” Symposium. Working together, leaders identified certain challenges and barriers to citizen preparedness as well as specific recommendations that will support the Department of Homeland Security’s National Strategy for all Hazards Preparedness to be released later this year.
Preparedness is the responsibility of every American. At the Department of Homeland Security, we are hard at work creating and implementing preparedness plans; developing procedures and policies that will guide our actions in the event of a terrorist attack; conducting training and exercises to ensure that our first responders possess a necessary level of preparedness; enhancing partnerships with state and local governments, private sector institutions and other organizations; and funding the purchase of much-needed equipment for first responders, states, cities, and towns. These activities, along with an active American community, contribute to a level of national preparedness that is critical to achieving our goal of a better prepared America."
COMMENT:
==================================================
Some enlightened citizen soldiers have already been busy preparing Americans for a spectrum of incidents. For more information see:
Risk Mitigation for the Commercial Real Estate Industry
Fact Sheet: A Better Prepared America: A Year in Review
“Much like homeland security in general, America’s preparedness requires everyone’s help. That’s why we’ve called you together – to continue building an important partnership – one that will result in an enduring and successful strategy for emergency preparedness across the country.”
– Secretary of Homeland Security Tom Ridge
Today, the Department of Homeland Security, the American Red Cross, the George Washington University Homeland Security Policy Institute and the Council for Excellence in Government brought together leaders in disaster preparedness, and response and recovery as part of the “Public Preparedness – A National Imperative” Symposium. Working together, leaders identified certain challenges and barriers to citizen preparedness as well as specific recommendations that will support the Department of Homeland Security’s National Strategy for all Hazards Preparedness to be released later this year.
Preparedness is the responsibility of every American. At the Department of Homeland Security, we are hard at work creating and implementing preparedness plans; developing procedures and policies that will guide our actions in the event of a terrorist attack; conducting training and exercises to ensure that our first responders possess a necessary level of preparedness; enhancing partnerships with state and local governments, private sector institutions and other organizations; and funding the purchase of much-needed equipment for first responders, states, cities, and towns. These activities, along with an active American community, contribute to a level of national preparedness that is critical to achieving our goal of a better prepared America."
COMMENT:
==================================================
Some enlightened citizen soldiers have already been busy preparing Americans for a spectrum of incidents. For more information see:
Risk Mitigation for the Commercial Real Estate Industry
Monday, July 19, 2004
Carpe Diem
Carpe Diem:
Yesterday's balkanized approach isn't going to get you where you want to go—or reduce your company's risk. CSOs need to seize the opportunities now to centralize security or pay the price later.
BY ANONYMOUS
CSO Magazine
IT'S BECOMING CLEARER and clearer to me that members of the information security community are enamored with the CSO title and have taken it for their own. And apparently there's nobody to challenge them or to correct this overstatement of responsibilities.
In fact, this very magazine recently ran an article noting the creation of the Global Council of CSOs comprising highly regarded information risk management professionals. In it, Howard Schmidt was asked to comment on the apparent lack of inclusion of physical security in the Council's scope. Schmidt confessed that he's "been forgetting to do that." Unfortunately, such oversight sums up the current landscape where we CSOs are unable even to define the elements of corporate protection within our scope of responsibility. (I'm just as dismayed, by the way, at the prospect of a CSO who owns only physical security and investigations as I am by one who is the sole proprietor of information security.)
Why does this balkanized viewpoint bother me? Because security is fundamentally about risk. The business imperative is sponsored by broader, deeper and more immediate risk, and the consequences potentially include corporate and executive survival. Board members and senior executives can no longer think simplistically about securing their corporation with antivirus software and a physical security program comprising a low-bid guard contract and an access control system. CSOs need a business model that clearly defines the scope of security responsibilities and a job description that includes oversight of securing every aspect of the organization.
Yesterday's balkanized approach isn't going to get you where you want to go—or reduce your company's risk. CSOs need to seize the opportunities now to centralize security or pay the price later.
BY ANONYMOUS
CSO Magazine
IT'S BECOMING CLEARER and clearer to me that members of the information security community are enamored with the CSO title and have taken it for their own. And apparently there's nobody to challenge them or to correct this overstatement of responsibilities.
In fact, this very magazine recently ran an article noting the creation of the Global Council of CSOs comprising highly regarded information risk management professionals. In it, Howard Schmidt was asked to comment on the apparent lack of inclusion of physical security in the Council's scope. Schmidt confessed that he's "been forgetting to do that." Unfortunately, such oversight sums up the current landscape where we CSOs are unable even to define the elements of corporate protection within our scope of responsibility. (I'm just as dismayed, by the way, at the prospect of a CSO who owns only physical security and investigations as I am by one who is the sole proprietor of information security.)
Why does this balkanized viewpoint bother me? Because security is fundamentally about risk. The business imperative is sponsored by broader, deeper and more immediate risk, and the consequences potentially include corporate and executive survival. Board members and senior executives can no longer think simplistically about securing their corporation with antivirus software and a physical security program comprising a low-bid guard contract and an access control system. CSOs need a business model that clearly defines the scope of security responsibilities and a job description that includes oversight of securing every aspect of the organization.
Friday, July 16, 2004
Congress approves 'Bioshield' legislation
Congress approves 'Bioshield' legislation:
By Joe Fiorill, Global Security Newswire
Congress approved legislation that would guarantee a government market for medical countermeasures against a biological, chemical, radiological or nuclear attack.
The chamber voted 414-2 in favor of a bill to implement Project Bioshield, which President George W. Bush first proposed in January of last year. The Senate passed identical legislation May 19. Bush is expected within a week or two to sign the bill, which is intended primarily to spur production of drugs that manufacturers would otherwise find unprofitable.
Select Committee on Homeland Security Chairman Christopher Cox, R-Calif., called the passage 'a watershed in our mission to defend America against bioterrorism, establishing our first line of defense against biological weapons.'
'This is the most significant first-responder program in our nation's history. It will ensure that we have treatments immediately on hand to save lives,' Cox said.
Besides authorizing the government to spend $5.6 billion over the next decade on countermeasures produced by private drugmakers, the act would speed National Institutes of Health countermeasure research and development, as well as allow the Food and Drug Administration to approve new drugs more quickly during emergencies.
A $700 million contract for a new anthrax vaccine, the first contract under the new law, is likely to be awarded 'as soon as next month,' said Rep. Jim Turner, D-Texas, the top Democrat on the House committee.
'By bringing researchers, medical experts and the biomedical industry together in new and innovative ways,' Bush said in a statement today, 'we will not only help protect the homeland but also gain insights into other diseases. This will break new ground in the search for treatments and cures while strengthening our overall biotechnology infrastructure.'"
By Joe Fiorill, Global Security Newswire
Congress approved legislation that would guarantee a government market for medical countermeasures against a biological, chemical, radiological or nuclear attack.
The chamber voted 414-2 in favor of a bill to implement Project Bioshield, which President George W. Bush first proposed in January of last year. The Senate passed identical legislation May 19. Bush is expected within a week or two to sign the bill, which is intended primarily to spur production of drugs that manufacturers would otherwise find unprofitable.
Select Committee on Homeland Security Chairman Christopher Cox, R-Calif., called the passage 'a watershed in our mission to defend America against bioterrorism, establishing our first line of defense against biological weapons.'
'This is the most significant first-responder program in our nation's history. It will ensure that we have treatments immediately on hand to save lives,' Cox said.
Besides authorizing the government to spend $5.6 billion over the next decade on countermeasures produced by private drugmakers, the act would speed National Institutes of Health countermeasure research and development, as well as allow the Food and Drug Administration to approve new drugs more quickly during emergencies.
A $700 million contract for a new anthrax vaccine, the first contract under the new law, is likely to be awarded 'as soon as next month,' said Rep. Jim Turner, D-Texas, the top Democrat on the House committee.
'By bringing researchers, medical experts and the biomedical industry together in new and innovative ways,' Bush said in a statement today, 'we will not only help protect the homeland but also gain insights into other diseases. This will break new ground in the search for treatments and cures while strengthening our overall biotechnology infrastructure.'"
Thursday, July 15, 2004
Most Large Companies See Sarbanes-Oxley Compliance As Part of Broader Corporate Governance Initiative
Most Large Companies See Sarbanes-Oxley Compliance As Part of Broader Corporate Governance Initiative:
Majority Do Not Measure Cost of Regulation, PricewaterhouseCoopers Finds
NEW YORK, July 14 /PRNewswire/ -- By a margin of nearly two to one, large U.S. companies have made compliance with the Sarbanes-Oxley Act part of their regular corporate governance approach and have integrated it with other regulatory activities, according to PricewaterhouseCoopers' Management Barometer.
The survey of senior executives at U.S.-based multinational companies found that:
-- 64 percent say their company's senior management and board of
directors see Sarbanes-Oxley as one of many steps in a larger
corporate governance initiative, while 30 percent say it is simply a
goal to be achieved. Six percent are uncertain.
-- 62 percent report Sarbanes-Oxley is integrated with their other
corporate regulatory compliance processes, but 34 percent say it is
not. Four percent are uncertain.
'Integrating the requirements of Sarbanes-Oxley compliance into ongoing corporate governance and regulatory activities, rather than managing compliance with the law as a separate task, offers the potential for improved business performance in both the short and long term,' said Dan DiFilippo, Partner and U.S. Practice Leader, Governance, Risk and Compliance, at PricewaterhouseCoopers.
Tracking Costs of Compliance
Despite complaints by some companies about the increased costs and regulatory burden imposed by Sarbanes-Oxley, most respondents, 56 percent, said their company does not track and report internally on the costs of Sarbanes-Oxley and other compliance programs. Forty-one percent do track such costs.
'Given the early outcry about Sarbanes-Oxley's added costs, it's surprising that most companies do not document and track this expense,' said DiFilippo. 'However, many companies have only recently begun to understand the types of costs and value associated with compliance efforts. We expect more aggressive monitoring as companies examine the effectiveness of their compliance approach.'
Remediation Efforts Expected
According to the survey, 79 percent of surveyed executives say their company must make improvements in order to comply with Section 404 of Sarbanes-Oxley, which requires companies to file a management assertion and auditor attestation on the effectiveness of internal controls over financial reporting. Among areas needing remediation:
-- Financial processes ......................... 55%
-- Computer controls ......................... 48%
-- Internal audit effectiveness ................. 37%
-- Security controls..................... 35%
-- Audit committee oversight................ 26%
-- Fraud programs.................... 24%
Process Improvements for Future Compliance
Looking ahead, 93 percent of executives expect their company to launch process improvement initiatives to streamline future Sarbanes-Oxley compliance. Among areas cited:
-- Financial reporting..................................63%
-- Risk identification and assessment...........61%
-- Risk mitigation.......................................55%
-- IT security strategy and implementation...55%
-- Internal audit.........................................55%
-- Compliance management........................54%
-- IT oversight and operations.................... 45%
'Companies recognize the need to make improvements in order to comply with the requirements of Sarbanes-Oxley,' said DiFilippo. 'When executives are confident that they are in compliance, many will want to find ways to streamline business processes and make future compliance less difficult.'"
Majority Do Not Measure Cost of Regulation, PricewaterhouseCoopers Finds
NEW YORK, July 14 /PRNewswire/ -- By a margin of nearly two to one, large U.S. companies have made compliance with the Sarbanes-Oxley Act part of their regular corporate governance approach and have integrated it with other regulatory activities, according to PricewaterhouseCoopers' Management Barometer.
The survey of senior executives at U.S.-based multinational companies found that:
-- 64 percent say their company's senior management and board of
directors see Sarbanes-Oxley as one of many steps in a larger
corporate governance initiative, while 30 percent say it is simply a
goal to be achieved. Six percent are uncertain.
-- 62 percent report Sarbanes-Oxley is integrated with their other
corporate regulatory compliance processes, but 34 percent say it is
not. Four percent are uncertain.
'Integrating the requirements of Sarbanes-Oxley compliance into ongoing corporate governance and regulatory activities, rather than managing compliance with the law as a separate task, offers the potential for improved business performance in both the short and long term,' said Dan DiFilippo, Partner and U.S. Practice Leader, Governance, Risk and Compliance, at PricewaterhouseCoopers.
Tracking Costs of Compliance
Despite complaints by some companies about the increased costs and regulatory burden imposed by Sarbanes-Oxley, most respondents, 56 percent, said their company does not track and report internally on the costs of Sarbanes-Oxley and other compliance programs. Forty-one percent do track such costs.
'Given the early outcry about Sarbanes-Oxley's added costs, it's surprising that most companies do not document and track this expense,' said DiFilippo. 'However, many companies have only recently begun to understand the types of costs and value associated with compliance efforts. We expect more aggressive monitoring as companies examine the effectiveness of their compliance approach.'
Remediation Efforts Expected
According to the survey, 79 percent of surveyed executives say their company must make improvements in order to comply with Section 404 of Sarbanes-Oxley, which requires companies to file a management assertion and auditor attestation on the effectiveness of internal controls over financial reporting. Among areas needing remediation:
-- Financial processes ......................... 55%
-- Computer controls ......................... 48%
-- Internal audit effectiveness ................. 37%
-- Security controls..................... 35%
-- Audit committee oversight................ 26%
-- Fraud programs.................... 24%
Process Improvements for Future Compliance
Looking ahead, 93 percent of executives expect their company to launch process improvement initiatives to streamline future Sarbanes-Oxley compliance. Among areas cited:
-- Financial reporting..................................63%
-- Risk identification and assessment...........61%
-- Risk mitigation.......................................55%
-- IT security strategy and implementation...55%
-- Internal audit.........................................55%
-- Compliance management........................54%
-- IT oversight and operations.................... 45%
'Companies recognize the need to make improvements in order to comply with the requirements of Sarbanes-Oxley,' said DiFilippo. 'When executives are confident that they are in compliance, many will want to find ways to streamline business processes and make future compliance less difficult.'"
Wednesday, July 14, 2004
Keeping Data Under Lock & Key
Keeping Data Under Lock & Key:
By Gregory J. Millman
July/Aug. 2004 (Financial Executive) -- In the fall of 2003, discount airline JetBlue hit heavy weather when a group of passengers filed a class action suit charging breach of contract, invasion of privacy and fraudulent misrepresentation. The reason? The airline had shared passenger information with a government contractor who was preparing a risk assessment study for the Department of Homeland Security.
'In the wake of the Sept. 11 attacks, and as New York's hometown airline, all of us at JetBlue were very anxious to support our government's efforts to improve security,' JetBlue CEO David Neeleman said in an apology posted on the company's Web site.
But JetBlue wasn't alone -- Northwest Airlines and American Airlines faced similar lawsuits. 'There are some indications that the law may not treat handing over that information as a violation of privacy, but these companies have already suffered a fair amount of loss of brand value from the flap,' says Stewart Baker, a Washington, D.C.-based partner in the law firm Steptoe & Johnson.
Only in America, perhaps, can a company get in trouble for sharing information with the government itself. But as the memory of 9/11 recedes, privacy rights and suspicion of the government once again seem to trump security concerns in the minds of many Americans. And companies are finding that privacy laws are confusing, frequently costly and ripe for misinterpretation.
A 2003 Privacy Trust Survey by The CIO Institute of Carnegie Mellon University and the Ponemon Institute asked Americans to rank various institutions, companies and professions in terms of their trustworthiness with personal information. Respondents ranked the Department of Homeland Security second from the bottom -- just ahead of grocery stores, but behind other retailers. What's more, hundreds of lawsuits have been filed against companies that allegedly violated privacy rights while obtaining, using or sharing information. 'The latest figure is $125 million recovered in lawsuits from companies,' says Dr. Alan Westin, Professor of Public Law & Government Emeritus at Columbia University and President and Publisher of Privacy & American Business.
Many companies are struggling just to keep up with the proliferation of privacy-protection measures. 'We have scores, maybe thousands, of laws in the United States on the federal and state level, as well as millions of contracts and as many if not more informal or administrative requirements based on letters from government agencies,' notes Alan S. Goldberg, a Washington-based attorney and former president of the National Health Lawyers Association. A study by IBM and the Ponemon Institute found that some companies spend over $22 million annually on privacy. "
By Gregory J. Millman
July/Aug. 2004 (Financial Executive) -- In the fall of 2003, discount airline JetBlue hit heavy weather when a group of passengers filed a class action suit charging breach of contract, invasion of privacy and fraudulent misrepresentation. The reason? The airline had shared passenger information with a government contractor who was preparing a risk assessment study for the Department of Homeland Security.
'In the wake of the Sept. 11 attacks, and as New York's hometown airline, all of us at JetBlue were very anxious to support our government's efforts to improve security,' JetBlue CEO David Neeleman said in an apology posted on the company's Web site.
But JetBlue wasn't alone -- Northwest Airlines and American Airlines faced similar lawsuits. 'There are some indications that the law may not treat handing over that information as a violation of privacy, but these companies have already suffered a fair amount of loss of brand value from the flap,' says Stewart Baker, a Washington, D.C.-based partner in the law firm Steptoe & Johnson.
Only in America, perhaps, can a company get in trouble for sharing information with the government itself. But as the memory of 9/11 recedes, privacy rights and suspicion of the government once again seem to trump security concerns in the minds of many Americans. And companies are finding that privacy laws are confusing, frequently costly and ripe for misinterpretation.
A 2003 Privacy Trust Survey by The CIO Institute of Carnegie Mellon University and the Ponemon Institute asked Americans to rank various institutions, companies and professions in terms of their trustworthiness with personal information. Respondents ranked the Department of Homeland Security second from the bottom -- just ahead of grocery stores, but behind other retailers. What's more, hundreds of lawsuits have been filed against companies that allegedly violated privacy rights while obtaining, using or sharing information. 'The latest figure is $125 million recovered in lawsuits from companies,' says Dr. Alan Westin, Professor of Public Law & Government Emeritus at Columbia University and President and Publisher of Privacy & American Business.
Many companies are struggling just to keep up with the proliferation of privacy-protection measures. 'We have scores, maybe thousands, of laws in the United States on the federal and state level, as well as millions of contracts and as many if not more informal or administrative requirements based on letters from government agencies,' notes Alan S. Goldberg, a Washington-based attorney and former president of the National Health Lawyers Association. A study by IBM and the Ponemon Institute found that some companies spend over $22 million annually on privacy. "
Tripwire_21_CFR11
Tripwire_21_CFR11
The U.S. Food and Drug Administration (FDA) has issued a set of regulations, collectively called 21 CFR11, that provide criteria for acceptance of electronic records and electronic signatures as equivalent to paper records and handwritten signatures executed on paper. These regulations, which apply to all FDA program areas, are intended to permit the widest possible use of electronic technology, compatible with the FDA’s responsibility to promote and protect public health.
Though electronic submissions are currently optional, the FDA is paving the way, with 21 CFR11, for routine and eventually mandatory submission of clinical trial records electronically. The 21 CFR11 provides in-depth guidelines and criteria for ensuring authenticity and integrity of digital records, and for documenting and validating authorized change processes to systems and software involved in the creation of digital records. The common goal is the ability to discern invalid or altered
records and, conversely, to assure accuracy, reliability and validity of electronic records and signatures. Typical FDA regulated activities that can accept 21 CFR11-compliant validated electronic records and signatures include new drug applications (NDAs), medical product license applications (PLAs) and biologics license applications (BLAs).
Tripwire® Integrity Management solutions are a natural fit for organizations that want to use electronic submissions and signatures in compliance with 21 CFR11. Tripwire software enables trust in information technology (IT) and data validation by establishing a baseline of your systems and data in their known good state, and detecting any change from that trusted state.
The trust and validation of electronic data enabled by Tripwire software is so fundamental that it transcends specific industries and regulations, and, yet, satisfies several key comments found in 21 CFR11. In this paper, we will detail which guidelines of the 21 CFR11 are supported by Tripwire software, and how Tripwire software takes a snapshot of what data looks like in its desired state. The software then monitors for differences from the baseline snapshot to see if anything has changed. If change is detected, the administrator is quickly notified and an auditable record is kept. Tripwire software then reports details on which files were added, deleted or changed.
The U.S. Food and Drug Administration (FDA) has issued a set of regulations, collectively called 21 CFR11, that provide criteria for acceptance of electronic records and electronic signatures as equivalent to paper records and handwritten signatures executed on paper. These regulations, which apply to all FDA program areas, are intended to permit the widest possible use of electronic technology, compatible with the FDA’s responsibility to promote and protect public health.
Though electronic submissions are currently optional, the FDA is paving the way, with 21 CFR11, for routine and eventually mandatory submission of clinical trial records electronically. The 21 CFR11 provides in-depth guidelines and criteria for ensuring authenticity and integrity of digital records, and for documenting and validating authorized change processes to systems and software involved in the creation of digital records. The common goal is the ability to discern invalid or altered
records and, conversely, to assure accuracy, reliability and validity of electronic records and signatures. Typical FDA regulated activities that can accept 21 CFR11-compliant validated electronic records and signatures include new drug applications (NDAs), medical product license applications (PLAs) and biologics license applications (BLAs).
Tripwire® Integrity Management solutions are a natural fit for organizations that want to use electronic submissions and signatures in compliance with 21 CFR11. Tripwire software enables trust in information technology (IT) and data validation by establishing a baseline of your systems and data in their known good state, and detecting any change from that trusted state.
The trust and validation of electronic data enabled by Tripwire software is so fundamental that it transcends specific industries and regulations, and, yet, satisfies several key comments found in 21 CFR11. In this paper, we will detail which guidelines of the 21 CFR11 are supported by Tripwire software, and how Tripwire software takes a snapshot of what data looks like in its desired state. The software then monitors for differences from the baseline snapshot to see if anything has changed. If change is detected, the administrator is quickly notified and an auditable record is kept. Tripwire software then reports details on which files were added, deleted or changed.
Tuesday, July 13, 2004
Director's Cut
Director's Cut:
Board members are turning to specialized software to help manage their affairs.
John P. Mello Jr.,
CFO Magazine
Board membership may have its privileges, but in this era of increased regulatory scrutiny, it also has its risks. This is not to say that sitting on a board of directors is a bad gig. Serving on a board remains one of the most effective ways for executives to network. It can offer rewarding work to those who have decided to step back from full-time jobs. And despite the hue and cry over executive compensation, board members get paid handsomely for their efforts: directors at larger companies typically rake in more than $100,000 in annual total compensation.
Still, these days they earn it. The Enron scandal initiated a new level of liability concerns; the Sarbanes-Oxley Act of 2002 (Sarbox) effectively multiplied the workload for any director willing to take on the job. Meetings are longer and more frequent. And it's arguably toughest for CFOs, who almost inevitably end up on the audit committee of the boards they join.
Longer meetings and heftier reading loads can create real headaches for directors. In some instances, just coordinating the topics for committee meetings can be a pain. Tom Lienhard, who serves on two boards, knows the problem only too well. 'Everyone is very busy, so our work carries over from month to month,' he says. 'Every month we have the same thing on our agenda. It drives me nuts.'
To address this vexation, Lienhard's boards (including the Ronald McDonald House Charities of Spokane, Wash.) recently installed an online software package called Director's Desk. The program, which is designed specifically for board and committee members, is intended to solve many of the logistical problems directors encounter. Using the software, for example, executive-committee members can conduct meetings online. Says Lienhard: 'We've actually been able to get a lot more done in less time.'
Director's Desk is one entry in an emerging category of software aimed at streamlining board communication and increasing board interaction. Some of these programs, including BoardVantage as well as Director's Desk, provide virtual meeting places for board members, along with specialized document management and communication tools. Others, like the suite from The Board Institute, based in Phoenix, help directors assess their own performance. Bret Beresford-Wood, CEO of Director's Desk Corporate Governance Services, in Post Falls, Idaho, believes the board-software market is set for a takeoff. 'In three to five years, a majority of companies will have some form of board-management system.'
Is This Anything?
The argument is that using IT to enhance board communication is a logical extension of current practice. 'Many CEOs communicate via letter to board members in odd months,' says Jay Lorsch, a professor at Harvard Business School and co-author of Back to the Drawing Board: Designing Corporate Boards for a Complex World. In fact, Lorsch is such a believer that he works with a company that is developing software to enhance board communication. 'Technology can provide a valuable way for board members to stay plugged in,' he says.
'If board members are inclined to communicate with one another, then these platforms will serve a great purpose,' predicts Stuart Robbins, executive director and founder of The CIO Collective, an organization for IT executives, in Oakland, Calif.
But some wonder if board software is more hype than help. Nell Minow, editor of The Corporate Library, a corporate-governance research firm in Portland, Maine, isn't sure the stuff is even necessary. 'There's nothing in this software that can't be accomplished through conventional communication and password-protected Websites,' she says.
Further, the cost of the programs, while cheap by enterprise-software standards, might spook finance chiefs at smaller companies. BoardVantage, for example, charges $2,000 to $4,000 per user per year.
Better communication seems to be the big selling point of board software, experts say. Both Director's Desk and BoardVantage offer secure E-mail and document management in a hosted environment. The feature can come in handy, since labor disputes and takeover bids don't necessarily crop up while board meetings are in session. 'Board members need to respond to issues as they arise,' asserts Tim Hampson, a marketing consultant with Menlo Park, Calif.-based BoardVantage. 'They need to communicate in a secure manner outside those meetings.'
Board members are turning to specialized software to help manage their affairs.
John P. Mello Jr.,
CFO Magazine
Board membership may have its privileges, but in this era of increased regulatory scrutiny, it also has its risks. This is not to say that sitting on a board of directors is a bad gig. Serving on a board remains one of the most effective ways for executives to network. It can offer rewarding work to those who have decided to step back from full-time jobs. And despite the hue and cry over executive compensation, board members get paid handsomely for their efforts: directors at larger companies typically rake in more than $100,000 in annual total compensation.
Still, these days they earn it. The Enron scandal initiated a new level of liability concerns; the Sarbanes-Oxley Act of 2002 (Sarbox) effectively multiplied the workload for any director willing to take on the job. Meetings are longer and more frequent. And it's arguably toughest for CFOs, who almost inevitably end up on the audit committee of the boards they join.
Longer meetings and heftier reading loads can create real headaches for directors. In some instances, just coordinating the topics for committee meetings can be a pain. Tom Lienhard, who serves on two boards, knows the problem only too well. 'Everyone is very busy, so our work carries over from month to month,' he says. 'Every month we have the same thing on our agenda. It drives me nuts.'
To address this vexation, Lienhard's boards (including the Ronald McDonald House Charities of Spokane, Wash.) recently installed an online software package called Director's Desk. The program, which is designed specifically for board and committee members, is intended to solve many of the logistical problems directors encounter. Using the software, for example, executive-committee members can conduct meetings online. Says Lienhard: 'We've actually been able to get a lot more done in less time.'
Director's Desk is one entry in an emerging category of software aimed at streamlining board communication and increasing board interaction. Some of these programs, including BoardVantage as well as Director's Desk, provide virtual meeting places for board members, along with specialized document management and communication tools. Others, like the suite from The Board Institute, based in Phoenix, help directors assess their own performance. Bret Beresford-Wood, CEO of Director's Desk Corporate Governance Services, in Post Falls, Idaho, believes the board-software market is set for a takeoff. 'In three to five years, a majority of companies will have some form of board-management system.'
Is This Anything?
The argument is that using IT to enhance board communication is a logical extension of current practice. 'Many CEOs communicate via letter to board members in odd months,' says Jay Lorsch, a professor at Harvard Business School and co-author of Back to the Drawing Board: Designing Corporate Boards for a Complex World. In fact, Lorsch is such a believer that he works with a company that is developing software to enhance board communication. 'Technology can provide a valuable way for board members to stay plugged in,' he says.
'If board members are inclined to communicate with one another, then these platforms will serve a great purpose,' predicts Stuart Robbins, executive director and founder of The CIO Collective, an organization for IT executives, in Oakland, Calif.
But some wonder if board software is more hype than help. Nell Minow, editor of The Corporate Library, a corporate-governance research firm in Portland, Maine, isn't sure the stuff is even necessary. 'There's nothing in this software that can't be accomplished through conventional communication and password-protected Websites,' she says.
Further, the cost of the programs, while cheap by enterprise-software standards, might spook finance chiefs at smaller companies. BoardVantage, for example, charges $2,000 to $4,000 per user per year.
Better communication seems to be the big selling point of board software, experts say. Both Director's Desk and BoardVantage offer secure E-mail and document management in a hosted environment. The feature can come in handy, since labor disputes and takeover bids don't necessarily crop up while board meetings are in session. 'Board members need to respond to issues as they arise,' asserts Tim Hampson, a marketing consultant with Menlo Park, Calif.-based BoardVantage. 'They need to communicate in a secure manner outside those meetings.'
Monday, July 12, 2004
RealEstateJournal Landlords and Tenants Disagree on Priorities
RealEstateJournal Landlords and Tenants Disagree on Priorities:
By SHEILA MUTO
Staff Reporter of The Wall Street Journal
From The Wall Street Journal Online
Talk about being out of sync with your clientele.
Accounting and advisory firm J.H. Cohn LLP recently surveyed a group of mostly developers and landlords in New York and New Jersey, asking them to, among other things, rank four factors -- technology, life-safety systems, high-end finishes and security -- in the order they believe are important in attracting tenants.
New York respondents ranked building security as the most important factor, while New Jersey respondents put high-end finishes first. Both New York and New Jersey respondents put life-safety systems -- which include fire alarm, sprinkler and communications systems -- at the bottom. Robert DeMeola, the partner in charge of J.H. Cohn's real-estate services group, which conducted the survey, says he was 'so surprised' that all respondents ranked technology and high-end finishes as more important than life-safety systems.
To determine whether the group of 59 respondents were out of touch or simply had 'short memories' of what happened on Sept. 11, 2001, Mr. DeMeola decided to pose the same question in an informal telephone survey to a handful of major tenants that recently leased space in Manhattan. (His group plans to conduct a formal survey of tenants.)
The result: The tenants deemed life-safety systems followed by building security as the most important of the four factors.
There's 'a disconnect between landlords and tenants,' says Mr. DeMeola. The results make clear that 'before landlords put a waterfall in the building, they should be putting in extra security' measures and 'upgrading life-safety systems and emergency lighting,' he says. Landlords are 'precluding a lot of the higher-end tenants' from their buildings if they don't."
By SHEILA MUTO
Staff Reporter of The Wall Street Journal
From The Wall Street Journal Online
Talk about being out of sync with your clientele.
Accounting and advisory firm J.H. Cohn LLP recently surveyed a group of mostly developers and landlords in New York and New Jersey, asking them to, among other things, rank four factors -- technology, life-safety systems, high-end finishes and security -- in the order they believe are important in attracting tenants.
New York respondents ranked building security as the most important factor, while New Jersey respondents put high-end finishes first. Both New York and New Jersey respondents put life-safety systems -- which include fire alarm, sprinkler and communications systems -- at the bottom. Robert DeMeola, the partner in charge of J.H. Cohn's real-estate services group, which conducted the survey, says he was 'so surprised' that all respondents ranked technology and high-end finishes as more important than life-safety systems.
To determine whether the group of 59 respondents were out of touch or simply had 'short memories' of what happened on Sept. 11, 2001, Mr. DeMeola decided to pose the same question in an informal telephone survey to a handful of major tenants that recently leased space in Manhattan. (His group plans to conduct a formal survey of tenants.)
The result: The tenants deemed life-safety systems followed by building security as the most important of the four factors.
There's 'a disconnect between landlords and tenants,' says Mr. DeMeola. The results make clear that 'before landlords put a waterfall in the building, they should be putting in extra security' measures and 'upgrading life-safety systems and emergency lighting,' he says. Landlords are 'precluding a lot of the higher-end tenants' from their buildings if they don't."
Assessing Your Storage and Backup for Regulatory Compliance
Assessing Your Storage and Backup for Regulatory Compliance:
By Ken Barth
The complicated nature of data management makes backups a crucial issue for I.T. In general, users are concerned about protection from data loss and the risk of being non-compliant. Current backup methods leave crucial data at risk, many organizations fear.
Compliance is one of the most talked-about issues in data management in recent years. As deadlines for federally mandated programs loom near, the issue is becoming more and more important.
Yet, despite all of the discussion and buzz, few organizations have actually implemented a compliance plan as part of their business operations. Perhaps the greatest stumbling block to devising and rolling out compliance plans is a widespread and high degree of confusion as to what the various regulations and legislation require, and the actions and activities that organizations must take in order to be in compliance with those regulations.
The challenges facing I.T. managers seem never-ending in the consistently and rapidly changing world of technology. The issue of regulatory compliance adds another murky, albeit important area of concern. The term 'compliance' is an umbrella term that has come to cover the recent spate of federal and state regulatory legislation dictating how organizations must retain and preserve their vast stores of data.
The impact of such legislation is bound to be widespread, affecting most of corporate America. Furthermore, the confusion over compliance initiatives, their cost, and their potential impact stems from the lack of clearly defined guidelines. In fact, the very term itself continues to grow and expand in what it encompasses.
As it stands, regulatory compliance legislation directly affects private and public companies, particularly those in regulated industries such as government, finance, and health care. In addition, many organizations have come to realize the importance of data as an asset for business operations and continuity. The result is I.T. departments facing new and developing compliance requirements for security and data retention set by their own organizations.
Central to the whole issue of regulatory compliance are three questions:
What data types are subject to archiving?
How long does that data need to be stored and accessible?
What do organizations need to do in order to be compliant?
While there are numerous pieces of legislation that deal with data retention, including the Health Insurance Portability and Accountability Act (HIPAA) of 1996, The Gramm-Leach-Bliley Act (GLB) also known as the Financial Modernization Act of 1999, and the Uniform Electronic Transactions Act (UETA) of 1999, probably the most talked-about and anxiety-producing is the Sarbanes-Oxley Act of 2002.
Sarbanes-Oxley was signed into law by the current President Bush following such high-profile corporate scandals as Enron, Tyco and WorldCom as an attempt to correct problems in the way organizations had been reporting their financial information. Sarbanes-Oxley states what records an organization must archive and for how long those records must be stored (all business records must be saved, including electronic messages, for at least five years and possibly longer).
It does not offer a set of business practices or guidelines on how organizations are to store records, leaving I.T. managers to create archiving programs and procedures that both fulfill the requirements of Sarbanes-Oxley and fit within their budgets. Failure to meet the mandated Fall 2004 deadline for compliance carries severe penalties."
By Ken Barth
The complicated nature of data management makes backups a crucial issue for I.T. In general, users are concerned about protection from data loss and the risk of being non-compliant. Current backup methods leave crucial data at risk, many organizations fear.
Compliance is one of the most talked-about issues in data management in recent years. As deadlines for federally mandated programs loom near, the issue is becoming more and more important.
Yet, despite all of the discussion and buzz, few organizations have actually implemented a compliance plan as part of their business operations. Perhaps the greatest stumbling block to devising and rolling out compliance plans is a widespread and high degree of confusion as to what the various regulations and legislation require, and the actions and activities that organizations must take in order to be in compliance with those regulations.
The challenges facing I.T. managers seem never-ending in the consistently and rapidly changing world of technology. The issue of regulatory compliance adds another murky, albeit important area of concern. The term 'compliance' is an umbrella term that has come to cover the recent spate of federal and state regulatory legislation dictating how organizations must retain and preserve their vast stores of data.
The impact of such legislation is bound to be widespread, affecting most of corporate America. Furthermore, the confusion over compliance initiatives, their cost, and their potential impact stems from the lack of clearly defined guidelines. In fact, the very term itself continues to grow and expand in what it encompasses.
As it stands, regulatory compliance legislation directly affects private and public companies, particularly those in regulated industries such as government, finance, and health care. In addition, many organizations have come to realize the importance of data as an asset for business operations and continuity. The result is I.T. departments facing new and developing compliance requirements for security and data retention set by their own organizations.
Central to the whole issue of regulatory compliance are three questions:
What data types are subject to archiving?
How long does that data need to be stored and accessible?
What do organizations need to do in order to be compliant?
While there are numerous pieces of legislation that deal with data retention, including the Health Insurance Portability and Accountability Act (HIPAA) of 1996, The Gramm-Leach-Bliley Act (GLB) also known as the Financial Modernization Act of 1999, and the Uniform Electronic Transactions Act (UETA) of 1999, probably the most talked-about and anxiety-producing is the Sarbanes-Oxley Act of 2002.
Sarbanes-Oxley was signed into law by the current President Bush following such high-profile corporate scandals as Enron, Tyco and WorldCom as an attempt to correct problems in the way organizations had been reporting their financial information. Sarbanes-Oxley states what records an organization must archive and for how long those records must be stored (all business records must be saved, including electronic messages, for at least five years and possibly longer).
It does not offer a set of business practices or guidelines on how organizations are to store records, leaving I.T. managers to create archiving programs and procedures that both fulfill the requirements of Sarbanes-Oxley and fit within their budgets. Failure to meet the mandated Fall 2004 deadline for compliance carries severe penalties."
Friday, July 09, 2004
What's under the business continuity umbrella?
What's under the business continuity umbrella?
Although the need to implement business continuity management processes is understood by the majority of organisations, there is much variation in what is actually included under the auspices of 'business continuity'. Continuity Central recently conducted a survey amongst the readers of the website to discover what the trends are in this area.
Respondents were asked to indicate what areas of activity were the responsibility of the business continuity function / department in their organisation. The full results are presented in the table below.
Activity
Percentage saying that this was a business continuity responsibility
Business impact analysis
93.5%
Testing and exercising the business continuity plan
92.1%
Crisis management
84.9%
Training and awareness raising amongst non-business continuity staff
84.9%
Training business continuity staff
78.4%
Crisis team building and development
75.5%
Risk assessment
74.8%
IT disaster recovery planning
71.9%
Crisis communications planning
69.8%
Auditing of own business continuity plan
65.5%
Risk awareness culture development
59.7%
IT disaster recovery solution design
50.4%
Liaison with local authorities
50.4%
Operational risk management
48.2%
Auditing of supplier business continuity plans
46.0%
Although the need to implement business continuity management processes is understood by the majority of organisations, there is much variation in what is actually included under the auspices of 'business continuity'. Continuity Central recently conducted a survey amongst the readers of the website to discover what the trends are in this area.
Respondents were asked to indicate what areas of activity were the responsibility of the business continuity function / department in their organisation. The full results are presented in the table below.
Activity
Percentage saying that this was a business continuity responsibility
Business impact analysis
93.5%
Testing and exercising the business continuity plan
92.1%
Crisis management
84.9%
Training and awareness raising amongst non-business continuity staff
84.9%
Training business continuity staff
78.4%
Crisis team building and development
75.5%
Risk assessment
74.8%
IT disaster recovery planning
71.9%
Crisis communications planning
69.8%
Auditing of own business continuity plan
65.5%
Risk awareness culture development
59.7%
IT disaster recovery solution design
50.4%
Liaison with local authorities
50.4%
Operational risk management
48.2%
Auditing of supplier business continuity plans
46.0%
Thursday, July 08, 2004
AIA: Momentum Grows to Extend Terrorism Insurance Law
AIA: Momentum Grows to Extend Terrorism Insurance Law
New legislation authored by several House Democrats to extend the Terrorism Risk Insurance Act of 2002 (TRIA) demonstrates strong, bipartisan congressional support for keeping TRIA's temporary, yet vital, economic safety net fully in place while long-term solutions are being evaluated, the American Insurance Association (AIA) said Thursday.
TRIA secures virtually every sector of the U.S. economy against catastrophic terrorist attacks by making sure that businesses of all sizes and types can purchase commercial insurance that covers losses resulting from terrorist attacks.
'Momentum is building on both sides of the political aisle and on both sides of Capitol Hill to extend TRIA this year,' Leigh Ann Pusey, AIA's senior vice president of government affairs, said. 'The House majority's 'Terrorism Insurance Backstop Extension Act of 2004' (HR 4634) and the Democrats' bill (HR 4772) clearly show that members of Congress want to devote significant energy to this issue this year.'
According to AIA, TRIA is a three-year, public-private risk sharing mechanism that has worked well, enabling the commercial insurance marketplace to function even though the very real threat of further catastrophic terrorism remains."
COMMENT:
=================================================
While extending TRIA is crucial to get the marketplace stabilized for the long haul, there may be a new risk on the horizon. By purchasing Terrorism Risk Insurance, REIT's and other property owners may think they are off the hook when it comes to hedging this specific type of risk. Nothing could be farther from the truth. Without clear evidence that landlords are preparing their tenants and staff for potential loss events of any magnitude, they face one of the greatest of Operational Risks. Legal Liability and loss of reputation. There is much more to the mosaic of risk management than just purchasing an insurance policy. Let's just hope that those entities involved are encouraging their respective staff and tenants to become more proactive, preventive and relevant when it comes to their critical infrastructures Operational Risk Management.
New legislation authored by several House Democrats to extend the Terrorism Risk Insurance Act of 2002 (TRIA) demonstrates strong, bipartisan congressional support for keeping TRIA's temporary, yet vital, economic safety net fully in place while long-term solutions are being evaluated, the American Insurance Association (AIA) said Thursday.
TRIA secures virtually every sector of the U.S. economy against catastrophic terrorist attacks by making sure that businesses of all sizes and types can purchase commercial insurance that covers losses resulting from terrorist attacks.
'Momentum is building on both sides of the political aisle and on both sides of Capitol Hill to extend TRIA this year,' Leigh Ann Pusey, AIA's senior vice president of government affairs, said. 'The House majority's 'Terrorism Insurance Backstop Extension Act of 2004' (HR 4634) and the Democrats' bill (HR 4772) clearly show that members of Congress want to devote significant energy to this issue this year.'
According to AIA, TRIA is a three-year, public-private risk sharing mechanism that has worked well, enabling the commercial insurance marketplace to function even though the very real threat of further catastrophic terrorism remains."
COMMENT:
=================================================
While extending TRIA is crucial to get the marketplace stabilized for the long haul, there may be a new risk on the horizon. By purchasing Terrorism Risk Insurance, REIT's and other property owners may think they are off the hook when it comes to hedging this specific type of risk. Nothing could be farther from the truth. Without clear evidence that landlords are preparing their tenants and staff for potential loss events of any magnitude, they face one of the greatest of Operational Risks. Legal Liability and loss of reputation. There is much more to the mosaic of risk management than just purchasing an insurance policy. Let's just hope that those entities involved are encouraging their respective staff and tenants to become more proactive, preventive and relevant when it comes to their critical infrastructures Operational Risk Management.
Wednesday, July 07, 2004
Storage: Compliance Cuts Across Industries, Storage Products
Storage: Compliance Cuts Across Industries, Storage Products
By Mark Ferelli
CRM News
Ever since the large corporate scandals involving Enron WorldCom, and the like, new government regulations ar entering the business world. Many in the mass-storag world see many of these regulations as saviors from th business strains created by cuts in capital spending i enterprise IT
It is true that compliance requirements with new federal and state regulations will result in more capital spending in storage hardware, software, automation, architectures and services. More records will be retained than ever before, and the impact will touch both structured data like databases and unstructured data like e-mails and instant messages.
What the Laws Look for
The various regulations are almost never specific on technology; they are more involved with such things as dates. For example, many of the new regulations require companies to retain records for 2 to 10 years or more, and to retrieve records quickly at a regulator's request. Other regulations require systems to keep secure audit trails of changes and deletions or to prevent changes or modifications to archived data. Audit trails will be nothing new for many corporations, since their own auditors demand such safeguards. These rules show immediate requirements for storage hardware that will meet the government's test of time as well as sophisticated software for indexing, tracking, archiving, backup and retrieval.
In point of fact, the demand for reliable storage will increase for a cultural reason as well. Very few end users want to take the time or effort to decide which files to delete, so they save everything. No one gets fired for saving everything, but you take a risk when you decide to press the "delete" key.
Financial Services
The securities trading industry now has some of the most stringent regulatory requirements for record retention and data storage, particularly under SEC Rule 17 for broker-dealer operations. These high-profile requirements have inspired the architectural concept of the "compliance engine."
SEC rules and interpretations were initially focused on the creation and retention of hardcopy records (paper or microfiche). However, hardcopy records and manual processes did not grow the speed and information requirements of today's global markets and trading operations. High-speed, accurate throughput is a requirement instead of an option. Hence the development of a variety of data processing tools, both off-the-shelf and proprietary.
Health Care
The Health Insurance Portability & Accountability Act [HIPAA] (Public Law 104-191, 110 Stat.1936 L1996]) addresses a variety of health care reforms. Title II, subtitle F addresses "administrative simplification" and covers healthcare plans, healthcare clearinghouses that provide healthcare transactions and healthcare providers. Unlike the financial services laws, HIPAA drills down into small medical practices, medical billing areas, pharmaceutical firms and more.
Failure to comply would have the offender face significant financial, legal and business penalties including criminal prosecution. Best security practices require traditional front-end security methods such as physical access controls, data network transport protection, host defenses, system and applications authorization, and security policy. This layered defense model must extend to backend storage preventing unauthorized access to data-at-rest.
But HIPAA impact reaches across key concepts in mass storage and storage management. Storage consolidation, storage pooling on tape media, data stored remotely, data in motion and stored information leveraging third-party services have access vulnerabilities that affects compliance efforts.
PHI controls dictates where and how the data can be stored and used. PHI data protection often has related management, training, data classification and infrastructure costs that can be significant.
There are many different types of regulatory compliance issues facing storage administrators and systems integrators today. The pacing concern is that organizations are in need of a cost-effective solution that provides synchronous levels of protection with no distance limitations and with no application degradation. The hard fact is that compliance issues will be added to everyday storage issues in installations of various sizes from the SMB to the enterprise. And make no mistake, effective management of storage is crucial to meeting compliance issues and day-to-day operations.
By Mark Ferelli
CRM News
Ever since the large corporate scandals involving Enron WorldCom, and the like, new government regulations ar entering the business world. Many in the mass-storag world see many of these regulations as saviors from th business strains created by cuts in capital spending i enterprise IT
It is true that compliance requirements with new federal and state regulations will result in more capital spending in storage hardware, software, automation, architectures and services. More records will be retained than ever before, and the impact will touch both structured data like databases and unstructured data like e-mails and instant messages.
What the Laws Look for
The various regulations are almost never specific on technology; they are more involved with such things as dates. For example, many of the new regulations require companies to retain records for 2 to 10 years or more, and to retrieve records quickly at a regulator's request. Other regulations require systems to keep secure audit trails of changes and deletions or to prevent changes or modifications to archived data. Audit trails will be nothing new for many corporations, since their own auditors demand such safeguards. These rules show immediate requirements for storage hardware that will meet the government's test of time as well as sophisticated software for indexing, tracking, archiving, backup and retrieval.
In point of fact, the demand for reliable storage will increase for a cultural reason as well. Very few end users want to take the time or effort to decide which files to delete, so they save everything. No one gets fired for saving everything, but you take a risk when you decide to press the "delete" key.
Financial Services
The securities trading industry now has some of the most stringent regulatory requirements for record retention and data storage, particularly under SEC Rule 17 for broker-dealer operations. These high-profile requirements have inspired the architectural concept of the "compliance engine."
SEC rules and interpretations were initially focused on the creation and retention of hardcopy records (paper or microfiche). However, hardcopy records and manual processes did not grow the speed and information requirements of today's global markets and trading operations. High-speed, accurate throughput is a requirement instead of an option. Hence the development of a variety of data processing tools, both off-the-shelf and proprietary.
Health Care
The Health Insurance Portability & Accountability Act [HIPAA] (Public Law 104-191, 110 Stat.1936 L1996]) addresses a variety of health care reforms. Title II, subtitle F addresses "administrative simplification" and covers healthcare plans, healthcare clearinghouses that provide healthcare transactions and healthcare providers. Unlike the financial services laws, HIPAA drills down into small medical practices, medical billing areas, pharmaceutical firms and more.
Failure to comply would have the offender face significant financial, legal and business penalties including criminal prosecution. Best security practices require traditional front-end security methods such as physical access controls, data network transport protection, host defenses, system and applications authorization, and security policy. This layered defense model must extend to backend storage preventing unauthorized access to data-at-rest.
But HIPAA impact reaches across key concepts in mass storage and storage management. Storage consolidation, storage pooling on tape media, data stored remotely, data in motion and stored information leveraging third-party services have access vulnerabilities that affects compliance efforts.
PHI controls dictates where and how the data can be stored and used. PHI data protection often has related management, training, data classification and infrastructure costs that can be significant.
There are many different types of regulatory compliance issues facing storage administrators and systems integrators today. The pacing concern is that organizations are in need of a cost-effective solution that provides synchronous levels of protection with no distance limitations and with no application degradation. The hard fact is that compliance issues will be added to everyday storage issues in installations of various sizes from the SMB to the enterprise. And make no mistake, effective management of storage is crucial to meeting compliance issues and day-to-day operations.
Tuesday, July 06, 2004
iPod is latest security risk for business, say analysts
iPod is latest security risk for business, say analysts
from Silicon.com on Tuesday, July 06, 2004
Article ID: D149172
Companies should consider banning portable storage devices such as Apple's iPod from corporate networks as they can be used to introduce malware or steal corporate data, according to an analyst.
Small portable storage products can bypass perimeter defenses like firewalls and antivirus at the mailserver, and introduce malware such as Trojans or viruses onto company networks, claimed analyst house Gartner in a report issued this week. Analysts have warned for some time of the dangers of using portable devices, but the report points out these also now include 'disk-based MP3 players, such as Apple's iPod, and digital cameras with smart media cards, memory sticks, compact flash and other memory media.'
Another potential danger is that the devices - that typically make use of USB and FireWire - could be used to steal large amounts of company data as they are faster to download to than CDs. Also the size of the portable devices means they can be easily misplaced or stolen.
Gartner advises that companies should forbid the use of uncontrolled, privately owned devices with corporate PCs and adopt personal firewalls to limit what can be done on USB ports.
'Businesses must ensure that the right procedures and technologies are adopted to securely manage the use of portable storage devices like USB 'keychain' drives. This will help to limit damage from malicious code, loss of proprietary information or intellectual property, and consequent lawsuits and loss of reputation,' the report stated.
Copyright 2004 CNET Networks, Inc."
COMMENT:
==================================================
We hope this message is clear. If not, see the movie "The Recruit".
from Silicon.com on Tuesday, July 06, 2004
Article ID: D149172
Companies should consider banning portable storage devices such as Apple's iPod from corporate networks as they can be used to introduce malware or steal corporate data, according to an analyst.
Small portable storage products can bypass perimeter defenses like firewalls and antivirus at the mailserver, and introduce malware such as Trojans or viruses onto company networks, claimed analyst house Gartner in a report issued this week. Analysts have warned for some time of the dangers of using portable devices, but the report points out these also now include 'disk-based MP3 players, such as Apple's iPod, and digital cameras with smart media cards, memory sticks, compact flash and other memory media.'
Another potential danger is that the devices - that typically make use of USB and FireWire - could be used to steal large amounts of company data as they are faster to download to than CDs. Also the size of the portable devices means they can be easily misplaced or stolen.
Gartner advises that companies should forbid the use of uncontrolled, privately owned devices with corporate PCs and adopt personal firewalls to limit what can be done on USB ports.
'Businesses must ensure that the right procedures and technologies are adopted to securely manage the use of portable storage devices like USB 'keychain' drives. This will help to limit damage from malicious code, loss of proprietary information or intellectual property, and consequent lawsuits and loss of reputation,' the report stated.
Copyright 2004 CNET Networks, Inc."
COMMENT:
==================================================
We hope this message is clear. If not, see the movie "The Recruit".
Friday, July 02, 2004
"Managing Risk for Corporate Governance" - A 1SecureAudit Education Series
By Peter L. Higgins
Corporate Directors are responsible for Continuous Continuity of the Enterprise
The modern enterprise today that understands the myriad of potential threats to its people, processes, systems and structures stands to be better equipped for sustained continuity. A Business Crisis and Continuity Management (BCCM) program is a dynamic change management initiative that requires dedicated resources, funding and auditing.
Since effective BCCM analysis is a 24/7 operation, it takes a combination of factors across the organization to provide what one might call C², or “Continuous Continuity”. A one-time threat or risk assessment or even an annual look at what has changed across the enterprise is opening the door for a Board of Directors worst nightmare. These nightmares are “Loss Events” that could have been prevented or mitigated all together.
According to the best practices from several sources, the Board of Directors is responsible for the BCCM of an organization. The following testing techniques must be used to ensure the continuity plan can be executed in a real-life emergency:
· Table-top testing: Discussing how business recovery arrangements would react by using example interruptions
· Simulations: Training individuals by simulating a crisis and rehearsing their post-incident/crisis management roles
· Technical recovery testing: Testing to ensure information systems can be restored effectively
· Testing recovery at an alternate site: Running business processes in parallel with recovery operations at an off-site location
· Test of supplier facilities and services: Ensuring externally provided services and products will meet the contract requirements in the case of interruptions
· Complete rehearsals: Testing to ensure the organization, employees, equipment, facilities and processes can cope with interruptions
The best practices talk about a BCCM that will be periodically updated. Periodic is not continuous. Change is the key factor here. What changes take place in your organization between these periodic updates? How could any organization accurately account for all the changes to the organization in between BCCM updates? The fact is that they can’t.
This will change over time as organizations figure out that this is now as vital a business component as Accounts Receivable. The BCCM will become a core process of the organization if it is not already, dynamically evolving by the minute as new change-based factors take place in the enterprise. As new or terminated employees, suppliers and partners come and go into the BCCM process, the threat profile is updated in real-time. This takes the operational management that much closer to C², or “Continuous Continuity”.
Having survived several large quakes in Southern California in years past, I’m not sure that all of the testing in the world can prepare people for human behaviors that come from within. People literally lose all sense of common sense when you are on the 42nd of the 50+ skyscraper and without any warning it physically sways a couple feet to the left and a few more feet to the right. Believe me, the issue is not the testing itself, it’s how to create a real enough scenario that you get similar behaviors out of unsuspecting people.
Certainly the largest organizations realize that the threats are taking on different forms than the standard fire, flood, earthquake and twister scenarios. These large catastrophic external loss events have been insured against and the premiums are substantial. What it is less easy to analyze from a threat perspective are the constantly changing landscapes and continuity postures of the many facets of the organization having to do with people, processes and systems.
Visit: 1SecureAudit
Corporate Directors are responsible for Continuous Continuity of the Enterprise
The modern enterprise today that understands the myriad of potential threats to its people, processes, systems and structures stands to be better equipped for sustained continuity. A Business Crisis and Continuity Management (BCCM) program is a dynamic change management initiative that requires dedicated resources, funding and auditing.
Since effective BCCM analysis is a 24/7 operation, it takes a combination of factors across the organization to provide what one might call C², or “Continuous Continuity”. A one-time threat or risk assessment or even an annual look at what has changed across the enterprise is opening the door for a Board of Directors worst nightmare. These nightmares are “Loss Events” that could have been prevented or mitigated all together.
According to the best practices from several sources, the Board of Directors is responsible for the BCCM of an organization. The following testing techniques must be used to ensure the continuity plan can be executed in a real-life emergency:
· Table-top testing: Discussing how business recovery arrangements would react by using example interruptions
· Simulations: Training individuals by simulating a crisis and rehearsing their post-incident/crisis management roles
· Technical recovery testing: Testing to ensure information systems can be restored effectively
· Testing recovery at an alternate site: Running business processes in parallel with recovery operations at an off-site location
· Test of supplier facilities and services: Ensuring externally provided services and products will meet the contract requirements in the case of interruptions
· Complete rehearsals: Testing to ensure the organization, employees, equipment, facilities and processes can cope with interruptions
The best practices talk about a BCCM that will be periodically updated. Periodic is not continuous. Change is the key factor here. What changes take place in your organization between these periodic updates? How could any organization accurately account for all the changes to the organization in between BCCM updates? The fact is that they can’t.
This will change over time as organizations figure out that this is now as vital a business component as Accounts Receivable. The BCCM will become a core process of the organization if it is not already, dynamically evolving by the minute as new change-based factors take place in the enterprise. As new or terminated employees, suppliers and partners come and go into the BCCM process, the threat profile is updated in real-time. This takes the operational management that much closer to C², or “Continuous Continuity”.
Having survived several large quakes in Southern California in years past, I’m not sure that all of the testing in the world can prepare people for human behaviors that come from within. People literally lose all sense of common sense when you are on the 42nd of the 50+ skyscraper and without any warning it physically sways a couple feet to the left and a few more feet to the right. Believe me, the issue is not the testing itself, it’s how to create a real enough scenario that you get similar behaviors out of unsuspecting people.
Certainly the largest organizations realize that the threats are taking on different forms than the standard fire, flood, earthquake and twister scenarios. These large catastrophic external loss events have been insured against and the premiums are substantial. What it is less easy to analyze from a threat perspective are the constantly changing landscapes and continuity postures of the many facets of the organization having to do with people, processes and systems.
Visit: 1SecureAudit
Thursday, July 01, 2004
Coast Guard to inspect all foreign ships
Coast Guard to inspect all foreign ships
BY THOMAS FRANK
WASHINGTON BUREAU
BAYONNE, N.J. -- The Coast Guard launched an ambitious maritime anti-terrorism program Thursday when it started inspecting every foreign ship coming to a U.S. port to make sure it has taken steps to improve security.
Ships that fall short of international standards could be barred from U.S. ports, or allowed in under Coast Guard escort and forced to hire security guards while docked.
In addition, the Coast Guard will soon begin inspecting ports in 135 countries to evaluate their security. Ships that have docked in ports found to have weak security could be barred from the United States or subject to increased Coast Guard scrutiny that would delay their arrival and add costs.
Experts fear the inspections could isolate nations -- most likely poor ones -- with weak port security by blocking their exports to the United States.
'The Coast Guard can effectively bankrupt a country by barring its ships,' said Kim Petersen, president of SeaSecure Inc., a maritime security consultant, and executive director of the Maritime Security Council, a shipping industry group.
The inspections are tied to an international maritime treaty proposed by the United States shortly after the Sept. 11 attacks to create the first worldwide security standards for ships and ports.
Each of the 147 countries that signed the treaty in 2002 must certify that its ports and the ships registered there comply with the International Ship and Port Facility Security codes.
The codes, which took effect Thursday, require such measures as fencing and security guards at ports to control access. Ships must restrict who gets on and enters areas such as the bridge and engine room, and must have a security officer."
BY THOMAS FRANK
WASHINGTON BUREAU
BAYONNE, N.J. -- The Coast Guard launched an ambitious maritime anti-terrorism program Thursday when it started inspecting every foreign ship coming to a U.S. port to make sure it has taken steps to improve security.
Ships that fall short of international standards could be barred from U.S. ports, or allowed in under Coast Guard escort and forced to hire security guards while docked.
In addition, the Coast Guard will soon begin inspecting ports in 135 countries to evaluate their security. Ships that have docked in ports found to have weak security could be barred from the United States or subject to increased Coast Guard scrutiny that would delay their arrival and add costs.
Experts fear the inspections could isolate nations -- most likely poor ones -- with weak port security by blocking their exports to the United States.
'The Coast Guard can effectively bankrupt a country by barring its ships,' said Kim Petersen, president of SeaSecure Inc., a maritime security consultant, and executive director of the Maritime Security Council, a shipping industry group.
The inspections are tied to an international maritime treaty proposed by the United States shortly after the Sept. 11 attacks to create the first worldwide security standards for ships and ports.
Each of the 147 countries that signed the treaty in 2002 must certify that its ports and the ships registered there comply with the International Ship and Port Facility Security codes.
The codes, which took effect Thursday, require such measures as fencing and security guards at ports to control access. Ships must restrict who gets on and enters areas such as the bridge and engine room, and must have a security officer."
Policy Issues - SAFECOM Program
Policy Issues - SAFECOM Program
What is the problem? – When public safety personnel cannot talk to each other by radio at the scene of an accident or a disaster, the problem often reflects lack of coordination and partnerships. Public safety agencies sometimes feel reluctant to coordinate or share communications systems because of "turf issues." Elected and appointed officials often do not fully understand the vital role interoperable communications play in protecting life and property. Local, tribal, state, and federal agencies generally lack opportunities to share experiences, develop common approaches, and identify best practices.
What has been done? – Government agencies at all levels are increasingly developing partnerships to support shared communications systems that improve interoperability, lower costs, and feature shared management and control. States are also beginning to establish executive-level committees to lead efforts to address interoperability issues.
What remains to be done? – Information about the benefits of coordinated communications should be broadly and actively shared at all levels. Local, tribal, state, and federal agencies should form working groups or executive committees to coordinate interoperability activities, and government leaders should work with these groups by issuing appropriate policies or executive orders. Associations that represent government officials or public safety executives should commit themselves to supporting and working for interoperability. All of these groups can use Public Safety WINS: Wireless Interoperability National Strategy to pursue solutions to the technical and policy challenges to improving interoperability.
Public Safety Coordination and Partnerships Awareness Guide
What is the problem? – When public safety personnel cannot talk to each other by radio at the scene of an accident or a disaster, the problem often reflects lack of coordination and partnerships. Public safety agencies sometimes feel reluctant to coordinate or share communications systems because of "turf issues." Elected and appointed officials often do not fully understand the vital role interoperable communications play in protecting life and property. Local, tribal, state, and federal agencies generally lack opportunities to share experiences, develop common approaches, and identify best practices.
What has been done? – Government agencies at all levels are increasingly developing partnerships to support shared communications systems that improve interoperability, lower costs, and feature shared management and control. States are also beginning to establish executive-level committees to lead efforts to address interoperability issues.
What remains to be done? – Information about the benefits of coordinated communications should be broadly and actively shared at all levels. Local, tribal, state, and federal agencies should form working groups or executive committees to coordinate interoperability activities, and government leaders should work with these groups by issuing appropriate policies or executive orders. Associations that represent government officials or public safety executives should commit themselves to supporting and working for interoperability. All of these groups can use Public Safety WINS: Wireless Interoperability National Strategy to pursue solutions to the technical and policy challenges to improving interoperability.
Public Safety Coordination and Partnerships Awareness Guide
Wednesday, June 30, 2004
Saving E-Mail
Saving E-Mail
Thomas Claburn and Steven Marlin, InformationWeek
Evidence that the Internet's killer app is seriously ill can be seen in the frantic efforts to resuscitate it. The past two weeks have witnessed a flurry of activity aimed at restoring trust in e-mail as a business-consumer communication tool that has been eroded by spam and e-mail-related online fraud.
How worrisome have the problems become to businesses? Bad enough that MasterCard International last week said it has created a system for round-the-clock monitoring to inform 25,000 financial-institution members worldwide within four hours of when such a scam starts. Bad enough that fierce rivals in the e-mail business -- America Online, EarthLink, Microsoft and Yahoo -- agreed last week to support each other's e-mail-authentication standards. It's also prompting a consortium of the 100 largest financial institutions to develop a common database to share reports of attacks and responses, and forcing some banks to reconsider how they use e-mail to communicate with customers.
MasterCard is using digital fraud-detection technology from NameProtect as part of a more-proactive approach to online fraud that lets the company detect scams as they unfold and work with police to block them before losses occur. 'We're concerned that somebody step up to the plate because consumer confidence is at stake,' says Sergio Pinon, senior VP of MasterCard's global security and risk services.
Research firm Gartner estimates that 57 million Americans in the past year received phishing e-mails -- messages sent to lure people to phony Web sites asking for financial information. During a two-week period in December, 60 million phishing messages were sent, according to the Anti-Phishing Working Group, of which both MasterCard and NameProtect are members. Identity theft is the endgame for many phishing schemes and has been the No. 1 consumer complaint to the Federal Trade Commission in the past four years. Gartner estimates that phishing-related fraud cost banks and credit-card companies about $1.2 billion in direct losses in the past 12 months."
Thomas Claburn and Steven Marlin, InformationWeek
Evidence that the Internet's killer app is seriously ill can be seen in the frantic efforts to resuscitate it. The past two weeks have witnessed a flurry of activity aimed at restoring trust in e-mail as a business-consumer communication tool that has been eroded by spam and e-mail-related online fraud.
How worrisome have the problems become to businesses? Bad enough that MasterCard International last week said it has created a system for round-the-clock monitoring to inform 25,000 financial-institution members worldwide within four hours of when such a scam starts. Bad enough that fierce rivals in the e-mail business -- America Online, EarthLink, Microsoft and Yahoo -- agreed last week to support each other's e-mail-authentication standards. It's also prompting a consortium of the 100 largest financial institutions to develop a common database to share reports of attacks and responses, and forcing some banks to reconsider how they use e-mail to communicate with customers.
MasterCard is using digital fraud-detection technology from NameProtect as part of a more-proactive approach to online fraud that lets the company detect scams as they unfold and work with police to block them before losses occur. 'We're concerned that somebody step up to the plate because consumer confidence is at stake,' says Sergio Pinon, senior VP of MasterCard's global security and risk services.
Research firm Gartner estimates that 57 million Americans in the past year received phishing e-mails -- messages sent to lure people to phony Web sites asking for financial information. During a two-week period in December, 60 million phishing messages were sent, according to the Anti-Phishing Working Group, of which both MasterCard and NameProtect are members. Identity theft is the endgame for many phishing schemes and has been the No. 1 consumer complaint to the Federal Trade Commission in the past four years. Gartner estimates that phishing-related fraud cost banks and credit-card companies about $1.2 billion in direct losses in the past 12 months."
Tuesday, June 29, 2004
More Board Independence, Less Fraud?
More Board Independence, Less Fraud? - - CFO.com:
A new study finds that ''a higher proportion of independent outside directors is associated with less likelihood of corporate wrongdoing.''
Stephen Taub, CFO.com
The more independent directors on a company's board, the less likely it is to be accused of fraud, according to a study published in the June issue of Financial Analysts Journal, a publication of the CFA Institute.
Three professors — Hatice Uzun of Long Island University, Samuel Szewczyk of Drexel University, and Raj Varma of the University of Delaware, Newark — examined 133 companies accused of fraud between 1978 and 2001. The researchers matched them with 133 companies — of similar size and in the same industries — that had not been accused of fraud, then compared the two groups for statistically significant differences in board member independence, board size, frequency of board meetings, and other variables.
Compared with the control group, companies that had been accused of fraud had a lower percentage of independent directors (that is, board members with no business or personal ties to the company) and lower percentage of outside (that is, non-executive) directors.
The boards of companies accused of fraud were also less likely to have an audit committee. In addition, their audit, compensation, and nominating committees also had a lower percentage of independent directors.
A new study finds that ''a higher proportion of independent outside directors is associated with less likelihood of corporate wrongdoing.''
Stephen Taub, CFO.com
The more independent directors on a company's board, the less likely it is to be accused of fraud, according to a study published in the June issue of Financial Analysts Journal, a publication of the CFA Institute.
Three professors — Hatice Uzun of Long Island University, Samuel Szewczyk of Drexel University, and Raj Varma of the University of Delaware, Newark — examined 133 companies accused of fraud between 1978 and 2001. The researchers matched them with 133 companies — of similar size and in the same industries — that had not been accused of fraud, then compared the two groups for statistically significant differences in board member independence, board size, frequency of board meetings, and other variables.
Compared with the control group, companies that had been accused of fraud had a lower percentage of independent directors (that is, board members with no business or personal ties to the company) and lower percentage of outside (that is, non-executive) directors.
The boards of companies accused of fraud were also less likely to have an audit committee. In addition, their audit, compensation, and nominating committees also had a lower percentage of independent directors.
Monday, June 28, 2004
Banks Report Widespread Challenges Remain in Their Basel II Preparations, According to Global Survey
Banks Report Widespread Challenges Remain in Their Basel II Preparations, According to Global Survey
Survey by Accenture, Mercer Oliver Wyman and SAP Shows Areas of Concern and Significant Regional Differences in Preparation for Basel
LONDON, June 28 /PRNewswire-FirstCall/ -- Many of the world's largest banks see significant challenges remaining in their preparations to implement the Basel II Capital Accord, according to a global survey of banks sponsored by Accenture, Mercer Oliver Wyman and SAP.
Substantial numbers of banks surveyed remain uncertain over budgets, a lack of confidence in risk-management frameworks and economic capital systems, and insufficient progress in implementation of the credit-risk measurement tools required to meet the new regulation. Survey results indicate that U.S. and Asia-Pacific banks lag behind their European counterparts in several key areas of preparation for Basel II.
The survey of executives responsible for Basel II compliance at 97 of the world's 200 largest banks in April and May was designed to gauge how major banks worldwide are responding to the challenges of the Basel II Accord just before the announcement of final rules in late June. Basel II updates and expands 1988 capital rules for risk-management practices that align capital more closely with operational, credit and market risks for banks operating internationally.
Other major survey findings include:
-- Uncertainty on the total cost of compliance is broad, with nearly a
third of survey respondents saying they remain unsure of the total cost
of their Basel II program. Of those banks providing estimates, most
banks with assets under US$100 billion expect price tags of euro 50
million or less while nearly two-thirds of larger banks project costs
of more than euro 50 million.
-- The majority of banks said they see significant benefits from Basel II,
especially in improved capital allocation and better risk-based
pricing.
-- More than 70 percent of banks surveyed are planning to adopt Basel II's
advanced regulatory approaches on both the credit risk and operational
risk sides.
-- Common expectations of increased competition in retail and small-and-
medium-enterprise (SME) lending, consolidation among corporate and
specialized lenders, and more selective approaches to emerging-market
credit.
Concerns remain
The survey indicates that many banks have significant work remaining to satisfy the requirements of two of the three major elements of Basel II: setting up a risk-based supervisory structure within the bank and increasing market discipline through expanded disclosure. Nearly two-thirds (63 percent) of banks surveyed described their enterprise-wide risk management framework as poor or average. Just over 60 percent of respondents described their economic capital systems as poor or average.
Basel II will also require banks to make significant changes to their business practices. Nearly 90 percent of survey respondents say change is likely in their operational risk management processes. In addition, almost 8 in 10 bank executives say that their credit risk management processes are likely to change."
Survey by Accenture, Mercer Oliver Wyman and SAP Shows Areas of Concern and Significant Regional Differences in Preparation for Basel
LONDON, June 28 /PRNewswire-FirstCall/ -- Many of the world's largest banks see significant challenges remaining in their preparations to implement the Basel II Capital Accord, according to a global survey of banks sponsored by Accenture, Mercer Oliver Wyman and SAP.
Substantial numbers of banks surveyed remain uncertain over budgets, a lack of confidence in risk-management frameworks and economic capital systems, and insufficient progress in implementation of the credit-risk measurement tools required to meet the new regulation. Survey results indicate that U.S. and Asia-Pacific banks lag behind their European counterparts in several key areas of preparation for Basel II.
The survey of executives responsible for Basel II compliance at 97 of the world's 200 largest banks in April and May was designed to gauge how major banks worldwide are responding to the challenges of the Basel II Accord just before the announcement of final rules in late June. Basel II updates and expands 1988 capital rules for risk-management practices that align capital more closely with operational, credit and market risks for banks operating internationally.
Other major survey findings include:
-- Uncertainty on the total cost of compliance is broad, with nearly a
third of survey respondents saying they remain unsure of the total cost
of their Basel II program. Of those banks providing estimates, most
banks with assets under US$100 billion expect price tags of euro 50
million or less while nearly two-thirds of larger banks project costs
of more than euro 50 million.
-- The majority of banks said they see significant benefits from Basel II,
especially in improved capital allocation and better risk-based
pricing.
-- More than 70 percent of banks surveyed are planning to adopt Basel II's
advanced regulatory approaches on both the credit risk and operational
risk sides.
-- Common expectations of increased competition in retail and small-and-
medium-enterprise (SME) lending, consolidation among corporate and
specialized lenders, and more selective approaches to emerging-market
credit.
Concerns remain
The survey indicates that many banks have significant work remaining to satisfy the requirements of two of the three major elements of Basel II: setting up a risk-based supervisory structure within the bank and increasing market discipline through expanded disclosure. Nearly two-thirds (63 percent) of banks surveyed described their enterprise-wide risk management framework as poor or average. Just over 60 percent of respondents described their economic capital systems as poor or average.
Basel II will also require banks to make significant changes to their business practices. Nearly 90 percent of survey respondents say change is likely in their operational risk management processes. In addition, almost 8 in 10 bank executives say that their credit risk management processes are likely to change."
Friday, June 25, 2004
Homeland Security Launches Critical Infrastructure Pilot Program to Bolster Private Sector Security
DHS | Department of Homeland Security | Homeland Security Launches Critical Infrastructure Pilot Program to Bolster Private Sector Security:
Press Releases
Homeland Security Launches Critical Infrastructure Pilot Program to Bolster Private Sector Security - Dallas First of Four Pilot Communities Sharing Targeted Threat Information
For Immediate Release
Office of the Press Secretary
Contact: 202-282-8010
June 23, 2004
Homeland Security Information Network - Critical Infrastructure
The U.S. Department of Homeland Security in partnership with local private sector and the Federal Bureau of Investigation, today launched the first Homeland Security Information Network-Critical Infrastructure (HSIN-CI) Pilot Program in Dallas, Texas with locally operated pilot programs in Seattle, Indianapolis and Atlanta to follow. The pilot program will operate throughout the course of this year to determine the feasibility of using this model for other cities across the country.
The HSIN-CI pilot program, modeled after the FBI Dallas Emergency Response Network expands the reach of the Department’s Homeland Security Information Network (HSIN) initiative--a counterterrorism communications tool that connects 50 states, five territories, Washington, D.C., and 50 major urban areas to strengthen the exchange of threat information--to critical infrastructure owners and operators in a variety of industries and locations, first responders and local officials. As part of the HSIN-CI pilot program, more than 25,000 members of the network will have access to unclassified sector specific information and alert notifications on a 24/7 basis.
“The Homeland is more secure when each hometown is more secure,” said Secretary of Homeland Security Tom Ridge. “HSIN-CI connects our communities – the government community to the private sector community to the law enforcement community -- the better we share information between our partners, the more quickly we are able to implement security measures where necessary.”
The HSIN-CI network allows local and regional areas to receive targeted alerts and notifications in real-time from Department’s Homeland Security Operations Center (HSOC) using standard communication devices including wired and wireless telephones, email, facsimile and text pagers. The network requires no additional hardware or software for federal, state, or local participants. The technical capacity of the network includes the ability to send 10,000 outbound voice calls per minute, 30,000 simultaneous inbound calls through an information “hotline,” 5,000 simultaneous email messages and 3,000 simultaneous facsimile transmissions in the event that information needs to be communicated. In addition, HSIN-CI network, in partnership with the FBI, provides a reporting feature that allows the public to submit information about suspicious activities through the FBI Tips Program that is then shared with the Department’s HSOC."
Press Releases
Homeland Security Launches Critical Infrastructure Pilot Program to Bolster Private Sector Security - Dallas First of Four Pilot Communities Sharing Targeted Threat Information
For Immediate Release
Office of the Press Secretary
Contact: 202-282-8010
June 23, 2004
Homeland Security Information Network - Critical Infrastructure
The U.S. Department of Homeland Security in partnership with local private sector and the Federal Bureau of Investigation, today launched the first Homeland Security Information Network-Critical Infrastructure (HSIN-CI) Pilot Program in Dallas, Texas with locally operated pilot programs in Seattle, Indianapolis and Atlanta to follow. The pilot program will operate throughout the course of this year to determine the feasibility of using this model for other cities across the country.
The HSIN-CI pilot program, modeled after the FBI Dallas Emergency Response Network expands the reach of the Department’s Homeland Security Information Network (HSIN) initiative--a counterterrorism communications tool that connects 50 states, five territories, Washington, D.C., and 50 major urban areas to strengthen the exchange of threat information--to critical infrastructure owners and operators in a variety of industries and locations, first responders and local officials. As part of the HSIN-CI pilot program, more than 25,000 members of the network will have access to unclassified sector specific information and alert notifications on a 24/7 basis.
“The Homeland is more secure when each hometown is more secure,” said Secretary of Homeland Security Tom Ridge. “HSIN-CI connects our communities – the government community to the private sector community to the law enforcement community -- the better we share information between our partners, the more quickly we are able to implement security measures where necessary.”
The HSIN-CI network allows local and regional areas to receive targeted alerts and notifications in real-time from Department’s Homeland Security Operations Center (HSOC) using standard communication devices including wired and wireless telephones, email, facsimile and text pagers. The network requires no additional hardware or software for federal, state, or local participants. The technical capacity of the network includes the ability to send 10,000 outbound voice calls per minute, 30,000 simultaneous inbound calls through an information “hotline,” 5,000 simultaneous email messages and 3,000 simultaneous facsimile transmissions in the event that information needs to be communicated. In addition, HSIN-CI network, in partnership with the FBI, provides a reporting feature that allows the public to submit information about suspicious activities through the FBI Tips Program that is then shared with the Department’s HSOC."
Thursday, June 24, 2004
Secure, or Just Paranoid?
Secure, or Just Paranoid? | BankInfoSecurity.com:
By John Irving
Today's business is increasingly dependant on information systems in one shape or another. As with most things there's good and bad - easy access (good), and security threats (bad). Lets not get into the political aspects of the information revolution, but let's examine the commercial implications, and some of the inherent risks.
Most companies are making little progress in countering rising information security threats. Many business systems aren't designed with information security in mind, but for efficiency, transparency - but are these two objectives incompatible? It's not just a big company issue. Information security affects SME's as much as multi-nationals. No one is immune; even if you don't run your own IT systems anymore, it's still an issue. It's increasingly common, that outsourcing contracts include information security clauses.
Threats come from cracking, intrusion, and virus software to name just a few. Counter measures are often hardware based as software based encryption can be cracked quite easily (ask Microsoft) - but it takes time and effort to implement and maintain an effective information security system. We're talking Deep Packet Inspection firewalls, hardware based intrusion prevention, data storage encryption, data integrity, and biometric identity verification devices to name just a few.
Not all cracking activity and viruses are malevolent, some only aim to obtain email directories using addresses to replicate elsewhere, but even this seemingly innocuous activity creates major issues - the resulting increase in network traffic can clog up systems, hindering legitimate communications, with huge cost implications.
Damage to systems, and data isn't the only issue - that's mostly repairable, but the damage to a company's reputation can have huge consequences, and be difficult to put right. Financial Institutions and other organisations trade on trust. If integrity is compromised it can take years to recover, that's why many information security breaches are quietly brushed under the corporate carpet.
There's another aspect to consider. In the US the Sarbanes-Oxley Act is the latest hard-hitting piece of legislation driving IT direction and spending, and may influence UK Subsidiaries.
The UK has at least nine Acts of Parliament and industry specific regulations impacting information security including The Data Protection Act; The Turnbull Report; Basel II; and The Computer Misuse Act. Some of these statutory requirements have real teeth, and shouldn't be dismissed. Directors are increasingly been held personally responsible for corporate actions, including information security. Large fines, or worse, may await those Directors who are found lacking by the Courts seeking to enforce information security laws.
IT Directors now face a simple choice - defensively sit still and react only when something happens, or pro-actively plan to implement new IT security policies and procedures that can deliver demonstrable bottom line benefits. It's the ones that do something that will be appearing on the front pages of IT magazines in a few years time, whilst the 'do nothings' may instead be looking at a P45, or even a court summons"
By John Irving
Today's business is increasingly dependant on information systems in one shape or another. As with most things there's good and bad - easy access (good), and security threats (bad). Lets not get into the political aspects of the information revolution, but let's examine the commercial implications, and some of the inherent risks.
Most companies are making little progress in countering rising information security threats. Many business systems aren't designed with information security in mind, but for efficiency, transparency - but are these two objectives incompatible? It's not just a big company issue. Information security affects SME's as much as multi-nationals. No one is immune; even if you don't run your own IT systems anymore, it's still an issue. It's increasingly common, that outsourcing contracts include information security clauses.
Threats come from cracking, intrusion, and virus software to name just a few. Counter measures are often hardware based as software based encryption can be cracked quite easily (ask Microsoft) - but it takes time and effort to implement and maintain an effective information security system. We're talking Deep Packet Inspection firewalls, hardware based intrusion prevention, data storage encryption, data integrity, and biometric identity verification devices to name just a few.
Not all cracking activity and viruses are malevolent, some only aim to obtain email directories using addresses to replicate elsewhere, but even this seemingly innocuous activity creates major issues - the resulting increase in network traffic can clog up systems, hindering legitimate communications, with huge cost implications.
Damage to systems, and data isn't the only issue - that's mostly repairable, but the damage to a company's reputation can have huge consequences, and be difficult to put right. Financial Institutions and other organisations trade on trust. If integrity is compromised it can take years to recover, that's why many information security breaches are quietly brushed under the corporate carpet.
There's another aspect to consider. In the US the Sarbanes-Oxley Act is the latest hard-hitting piece of legislation driving IT direction and spending, and may influence UK Subsidiaries.
The UK has at least nine Acts of Parliament and industry specific regulations impacting information security including The Data Protection Act; The Turnbull Report; Basel II; and The Computer Misuse Act. Some of these statutory requirements have real teeth, and shouldn't be dismissed. Directors are increasingly been held personally responsible for corporate actions, including information security. Large fines, or worse, may await those Directors who are found lacking by the Courts seeking to enforce information security laws.
IT Directors now face a simple choice - defensively sit still and react only when something happens, or pro-actively plan to implement new IT security policies and procedures that can deliver demonstrable bottom line benefits. It's the ones that do something that will be appearing on the front pages of IT magazines in a few years time, whilst the 'do nothings' may instead be looking at a P45, or even a court summons"
Subscribe to:
Posts (Atom)