April 30, 2010 - Linda McGlasson, Managing Editor
Bank Information Security Articles
In a case of insider fraud, a Utah computer consultant was sentenced to five years in prison for stealing nearly $2 million from four Utah credit unions by programming extra deposits for himself.
On April 27, a judge sentenced 43-year-old Zeldon Thomas Morris to 63 months in prison and ordered he pay back over $1.8 million.
Morris pleaded guilty to taking the funds from Deseret First Credit Union, First Credit Union, Alpine Credit Union and Family First Credit Union in 2008. The FBI says they discovered he was hired to help the credit unions with computer upgrades. Instead, he used the passwords to create accounts for himself.
Morris admitted to transferring the money to his joint business account, Lee and Morris Enterprises LLC. He remodeled his home and paid for two cars with the money. He begins his prison sentence June 18. Morris was investigated after a business partner saw something suspicious and reported it.
Friday, April 30, 2010
Tuesday, April 27, 2010
Friday, April 23, 2010
FISMA Compliance
FISMA Background
Federal Information Security Management Act (FISMA) requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.
Safend Data Protection Suite helps you control your endpoints and address data leakage and targeted attack threats.
Federal Information Security Management Act (FISMA) requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.
Safend Data Protection Suite helps you control your endpoints and address data leakage and targeted attack threats.
Wednesday, April 21, 2010
Sunday, April 18, 2010
Sunbelt warns on game console security risks
16 April 2010
Sunbelt Software has warned businesses to be aware of the growing security risks posed by network-connected game consoles in the work environment.
The problem, Sunbelt says, stems from the increased use of network-connected consoles in break and waiting areas, which heightens the chances of distributed denial of service (DDoS) and phishing attacks
Sunbelt has issued its warning after a study of more than 200 senior IT figures in the public and private sector, which reveals that 39% had no idea about any of the documented threats that relate to online console gaming, including DDoS attacks, phishing and social engineering.
The study also found that 80% of those questioned said their organisations keep no record of who uses the game consoles within the workplace, making it almost impossible to track down the source of any data leaks or brand-damaging in-game behaviour that might take place via services such as Xbox Live and Sony PlayStation.
According to Sunbelt, console users participating in online play risk exposing both their IP address, increasing the risk of that address being targeted for DDoS attacks designed to cripple the target's internet connection.
These types of attacks, which can render the organisation's connection unusable, are frequently used by opportunistic criminals and disgruntled players, the company says.
And, the IT security vendor adds, innocent players in the workplace are also potential targets for social engineering and phishing scams intent on extracting usernames, passwords and other sensitive data from users via chat forums, in-game speech and email.
Chris Boyd, a senior threat researcher with the firm, who recently joined Sunbelt from Facetime Communications, said that there are benefits to having game consoles in the workplace, as they can boost morale by providing staff with a fun diversion during lunch and other break periods.
"Consoles, meanwhile, in the lobby and waiting areas help convey a sense of a modern, fun and tech-savvy organisation", he said.
"However, these benefits must be weighed against the business implications of a threat, such as a DDoS attack, which can harm productivity significantly", he added.
"In most cases, the most practical option for an organisation is to disconnect consoles from the internet and use them for offline play only."
This article is featured in:
Application Security • Compliance and Policy • Data Loss • Internet and Network Security • Malware and Hardware Security
Sunbelt Software has warned businesses to be aware of the growing security risks posed by network-connected game consoles in the work environment.
The problem, Sunbelt says, stems from the increased use of network-connected consoles in break and waiting areas, which heightens the chances of distributed denial of service (DDoS) and phishing attacks
Sunbelt has issued its warning after a study of more than 200 senior IT figures in the public and private sector, which reveals that 39% had no idea about any of the documented threats that relate to online console gaming, including DDoS attacks, phishing and social engineering.
The study also found that 80% of those questioned said their organisations keep no record of who uses the game consoles within the workplace, making it almost impossible to track down the source of any data leaks or brand-damaging in-game behaviour that might take place via services such as Xbox Live and Sony PlayStation.
According to Sunbelt, console users participating in online play risk exposing both their IP address, increasing the risk of that address being targeted for DDoS attacks designed to cripple the target's internet connection.
These types of attacks, which can render the organisation's connection unusable, are frequently used by opportunistic criminals and disgruntled players, the company says.
And, the IT security vendor adds, innocent players in the workplace are also potential targets for social engineering and phishing scams intent on extracting usernames, passwords and other sensitive data from users via chat forums, in-game speech and email.
Chris Boyd, a senior threat researcher with the firm, who recently joined Sunbelt from Facetime Communications, said that there are benefits to having game consoles in the workplace, as they can boost morale by providing staff with a fun diversion during lunch and other break periods.
"Consoles, meanwhile, in the lobby and waiting areas help convey a sense of a modern, fun and tech-savvy organisation", he said.
"However, these benefits must be weighed against the business implications of a threat, such as a DDoS attack, which can harm productivity significantly", he added.
"In most cases, the most practical option for an organisation is to disconnect consoles from the internet and use them for offline play only."
This article is featured in:
Application Security • Compliance and Policy • Data Loss • Internet and Network Security • Malware and Hardware Security
Tuesday, April 13, 2010
Missouri's Breach Notification Law
Posted by Stephen Wu, Esq. on Apr 13, 2010 11:06:23 AM
Missouri became the 45th state to enact a breach notification law. Mo. Rev. Stat. §§ 407.1500.1-407.1500.4. Missouri’s governor signed the enabling legislation, H.B. 62, into law last July. It went into effect last August 28. For a copy of H.B. 62, click here.
H.B. 62 covers “personal information” consisting of a name in combination with a driver’s license number, Social Security number, or account number together with an access code. Id. §§ 407.1500.1(9). These are the usual elements of “personal information” seen in California’s SB 1386. In addition, however, the Missouri law also covers personal information in the form of medical information, health insurance information, and identifier and access codes permitting a person to access a financial account. Id.
Businesses must notify Missouri residents if there is unauthorized access to residents’ personal information that the businesses are maintaining. Id. § 407.1500.2(1). No notification is necessary if, following an investigation and consultation with law enforcement, the business “determines that a risk of identity theft or other fraud to any consumer is not reasonably likely to occur as a result of the breach.” Id. § 407.1500.2(5). A business making such a determination must record it in writing and preserve the writing for five years. Id. In addition, a business may delay notification if law enforcement informs the person that notification may impede a criminal investigation. Id. § 407.1500.2(3).
The Missouri law states that the Attorney General has the “exclusive authority” to bring an action for damages or a civil money penalty. The “exclusive authority” phrase implies that there is no private right of action. The maximum penalty the A.G. may seek is $150,000 for one breach or a “series of breaches of a similar nature that are discovered in a single investigation.” Id. § 407.1500.4.
Stephen S. Wu
Parner, Cooke Kobrick & Wu LLP
http://www.ckwlaw.com
swu@ckwlaw.com
28 Views Tags: compliance, data_breach, law, legal, policy_and_government
Missouri became the 45th state to enact a breach notification law. Mo. Rev. Stat. §§ 407.1500.1-407.1500.4. Missouri’s governor signed the enabling legislation, H.B. 62, into law last July. It went into effect last August 28. For a copy of H.B. 62, click here.
H.B. 62 covers “personal information” consisting of a name in combination with a driver’s license number, Social Security number, or account number together with an access code. Id. §§ 407.1500.1(9). These are the usual elements of “personal information” seen in California’s SB 1386. In addition, however, the Missouri law also covers personal information in the form of medical information, health insurance information, and identifier and access codes permitting a person to access a financial account. Id.
Businesses must notify Missouri residents if there is unauthorized access to residents’ personal information that the businesses are maintaining. Id. § 407.1500.2(1). No notification is necessary if, following an investigation and consultation with law enforcement, the business “determines that a risk of identity theft or other fraud to any consumer is not reasonably likely to occur as a result of the breach.” Id. § 407.1500.2(5). A business making such a determination must record it in writing and preserve the writing for five years. Id. In addition, a business may delay notification if law enforcement informs the person that notification may impede a criminal investigation. Id. § 407.1500.2(3).
The Missouri law states that the Attorney General has the “exclusive authority” to bring an action for damages or a civil money penalty. The “exclusive authority” phrase implies that there is no private right of action. The maximum penalty the A.G. may seek is $150,000 for one breach or a “series of breaches of a similar nature that are discovered in a single investigation.” Id. § 407.1500.4.
Stephen S. Wu
Parner, Cooke Kobrick & Wu LLP
http://www.ckwlaw.com
swu@ckwlaw.com
28 Views Tags: compliance, data_breach, law, legal, policy_and_government
Subscribe to:
Posts (Atom)