Monday, January 26, 2009
Privacy Pro Picked for Obama Post
Friday, January 23, 2009
Draft Guidelines for Data Protection
Our federal government is now considering a national policy to mandate certain business practices and procedures that will take into account all of the recommendations of current rules, and add a national breach reporting component to assure that potential victims are notified in a timely manner that their information may be at an increased risk of identity theft. The NIST report has concluded that government agencies and private businesses that provide goods and services to the government also adhere to the same set of rules. This seems to make very clear that businesses that have government contract arrangements will have their information security practices scrutinized for compliance or face losing that contract. This is also outlined in the Red Flags Rule as a compliance component. Oversight of the practices of all outsourced work to contractors and 3rd party service providers is critical to a sound program. All you government contractors watch your mail for updated RFIs coming your way soon!
NIST releases draft guidelines for data protection
Angela Moscaritolo SC Magazine
January 15 2009
The National Institute of Standards and Technology (NIST) this month released preliminary recommendations that federal agencies -- and their contractors -- should follow to protect the confidentially of personally identifiable information (PII). U.S. government agencies should take a number of precautions when dealing with personal information residing in their organizations, according to the NIST document. The recommendations are intended to be for U.S. federal government agencies, and companies with which they work, but NIST said that other verticals may also find value in it.The report states that organizations should store only PII necessary to conduct business, develop an incident response plan for the event of a breach and encourage coordination for data-loss incidents among CIOs, information security officers and legal counsel.Scott Larson, executive managing director of computer forensic consulting firm Stroz Friedberg, told SCMagazineUS.com on Thursday that he thinks the guidelines are timely and that there will be an increased focus on privacy protection once President-elect Obama takes office next week.“I think with a change in administration, a lot of these data privacy issues will be re-examined,” Larson said. There has been increased concern how federal agencies are storing, accessing and mining for data, he said.PII can include things such as names, personal identification numbers (Social Security number, passport number, driver's license number, credit card number), address information, and other personal characteristics (photos, fingerprints, retina scans).The report also recommends that organizations create policies for handling PII, with clearly defined consequences if they are not followed. Entities should provide education, training, and awareness to employees on protecting PII. The document contains exercises with scenarios involving PII and questions to build skills and teach employees how to handle it.Larson said organizations may struggle with one of the recommendations, which asks them to categorize data based on its level of confidentiality. Agencies simply may be unable to accomplish this because they don't have enough employees.“Sometimes it comes down to resources,” Larson said.Larson said encryption or obfuscation are the most effective ways to protect data.The draft report is open to public comment until March 13. The final version will be released after the authors have reviewed the public feedback and made changes to the report based on the number and type of comments received, Erika McCallister, a computer scientist at NIST who co-authored the report, said in an email to SCMagazineUS.com Thursday
Saturday, January 17, 2009
Compliance
The cost to government and business is astronomical. In 2007 OMB and FTC estimates show at least $48 billion in lost business revenue, fines, investigative costs, law suits, etc. As a result states are looking to control their costs as police departments, and county and state attorneys' offices are inundated with identity theft complaints that add a large burden on their offices. This brings me to the point of this column. We have had guidelines now for several years, and now certain compliance regulations that clearly show the steps every business, non-profit, school system, and local municipality should follow to reduce breaches and identity theft episodes. These guidelines are defined in the 1999 Gramm Leach Bliley Act or GLB, the 2003 and 2005 provisions of the FACT Act, and again by way of the Red Flags rules of 2008.
Massachusetts has now stepped in and announced that these very guidelines are law of the Commonwealth. Any organization that does business in Massachusetts or has any client that resides in Massachusetts must adhere to the regulations that go into effect May 1st of 2009. This not only applies to the business in question but also includes mandatory oversight of the data security practices of all business that are 3rd party service providers and contractors. Massachusetts has gone so far as to announce that if any other state enacts more stringent regulations than these they will adopt the more stringent terms. Surely other states will follow, it is simply a matter of when. A unifying federal regulation is on the horizon. With the inauguration of the first U.S. President who is expected to appoint a Chief Information Security Officer a federal regulation will come from Congress sooner than later, perhaps as soon as this year.
And it will probably come from Senator Diane Feinstein, the incoming Chair of the Senate Select Intelligence Committee. Sen. Feinstein has long been an advocate of personal privacy oversight, and identity theft law. Below is a great article on the new Mass. legislation.
Massachusetts Gets Tough on Data SecurityJan 15, 2009
By Maria Bruno-BritzBank Systems & Technology
As if banks didn't have enough on their plates with compliance and regulation on the federal front, come May 1, they will have to be mindful of strict new rules coming from the Commonwealth of Massachusetts around data security.
The Massachusetts Data Security Regulations are perhaps like no other in terms of their depth and scope. During a teleconference, attorneys from the privacy and data security practice of the law firm Goodwin Procter (Boston) described this very detailed, all-encompassing set of rules designed to keep consumers' personal data safe. They go beyond the rules of other states and the federal government that simply require companies to notify their customers of theft of their personal information. "Personal information," for the purposes of the regulation, is described as someones first and last name or first initial and last name, in combination with Social Security Number, driver's license number or financial account number.
At its core, the regulation states that companies, including banks, that handle the personal data of a Massachusetts resident must show they have in place a comprehensive, written information security program with heightened security procedures around how this information is handled.
The rules also extend to entities' service providers and the degree to which they too must show they comply with the Massachusetts rules of handling data on residents. Companies have until May 1 to amend their vendor contracts to reflect this and until Jan. 1, 2010 to certify their vendors comply. Furthermore, companies must comply with these rules even if they do not have a single office in the Bay State or if they are in an already heavily regulated industry, like financial services. As long as customers in businesses' databases reside in Massachusetts, those companies are affected by the rules.
According to partner Deborah Birnbach, this is some of the most intrusive legislation as it relates to the operation of businesses. "It requires changes in your physical access, changes in your relationships with your vendors, changes to your training programs, and changes in the type of information stored and how you store it," Birnbach explained to attendees. "This is not business as usual as it relates to the personal information of Massachusetts residents."
Under the rules, companies have a duty to monitor their security programs on an ongoing basis. The size and type of company will be taken into account by lawmakers, however. Partner David Goldstone said businesses are required to develop, implement, maintain and monitor a "comprehensive" written information security program. "They expect the information security program to be a living and breathing information security program," he said.
The safeguards in the program must be administrative, technical and physical in nature. Entities will be required to identify all records used to store personal information. Although companies won't be expected to keep an inventory of this data per se, they are expected to know where it is, Goldstone noted. One of the suggestions to facilitate this process is to create an information flow map that shows where information is stored and transmitted.
Businesses must also identify and assess both internal and external risks to the organization. Once these steps are completed, they must then evaluate (and improve, if necessary) the safeguards in place around such areas as employee training and physical security.
In addition to all this, companies will be obligated to limit the collection and use of personal information. They must identify the purposes for which they collect this kind of information and identify how long the wish to keep it and who can access it.
Another big component of the regulation is around the protection of data in transit and data on portable devices, like laptops, Blackberrys and thumb drives. Companies will be required to encrypt data that is not only stored but also when it is being transmitted over networks or physically moved as when an employees take a laptop home.
Properly educating and handling employees will also be key to compliance. The rules state, for example, that companies must be vigilant when dealing with terminated employees so that their access to data is "immediately" denied.
"Massachusetts may be the first with such detailed regulations, but it is not likely to be the last," predicted Lynne Barr, a partner with the firm.
Thursday, January 8, 2009
Small and medium sized business will spend more on security in '09
A Forrester Research report finds that small and medium-sized businesses will spend more on security in 2009, and will zero in on data protection, reports SearchCIO. Forrester surveyed the business and IT leaders of 1,206 SMBs--businesses with fewer than 1,000 employees--and 942 enterprise companies, finding that the number one priority for both groups in the year ahead will be the protection of data assets.
The report goes on to say..
Nearly 20% of the respondents plan to pilot or adopt a host intrusion prevention system (HIPS), file-level encryption, full disk/desktop encryption, endpoint control and data leak prevention in the next 12 months. The moves will almost double the use of these security technologies at SMBs.
For me though this was the most puzzling part of this piece...
One area that isn't on the security radar for many SMBs -- but probably should be -- is access rights and the larger issue of identity management. Data assets must be protected against insiders, too, said Jonathan Penn, author of Forrester Research's security report.
"There are people who are authorized users who may inappropriately use information to the detriment of the company, or there are unauthorized users who in previous roles may have needed access to information but no longer do. Those kinds of processes in SMBs tend to be pretty poorly implemented," Penn said.
Part of the reason for this security shortcoming is that the technology for automating these processes can be expensive. But the bigger issue for SMBs is the process-intensive nature of keeping up with the rights employees should and shouldn't have.
"If it was a matter of just getting a tool to streamline onboarding, they could do that if they saw the cost benefit of that. But SMBs have tended to shy away from how they manage people's rights throughout the lifecycle of employment," Penn said. Coordinating among IT, business departments and human resources to sort out the employee rights and keeping the policies up to date is tough, and not easily outsourced.
A high caliber Identity Theft Risk trainer can partner with the HR management to get all of the employees through a comprehensive awareness training in 1 hour or less in group settings. Once that is done a schedule of update sessions will keep the company current with the changing legislation on an as needed basis. The FACTA Red flags legislation calls for staff training of the company identity theft policy as a compliance piece. This comes under the heading of company policy and needs to be part of not only the onboarding of new hires but also for existing staff.
That really is the essence of good ongoing education for employees. Not only does the company get the advantage of expert trainers to keep everyone current in protecting the company's data assets but also having a better prepared staff who will act in a more proactive manner both on the job and with their personal identity. A significant area of concern when an individual is experiencing an identity theft episode is being distracted on the job, taking time off, and being under extra stress at work.
In any case it seems business is moving (somewhat) in the right direction.
Tuesday, January 6, 2009
2008 Breach Numbers Nearly Double
Given the reality of this report what would motivate a company to concentrate its efforts on company server and internet security? Mis-information.It has long been known that the vast majority of breaches are not the result of hacking or "cyber crime" of any kind. As this report has found it's almost always either an inside job or gross error in judgement. This is what makes employee awareness training an absolute necessity in an information security program. If a business doesn't tell the entire staff how to handle personal information how are they going to expect them to do the right thing? Certified identity theft risk management experts who have studied the many forms of identity theft and methods of prevention should always conduct the training.
We have established that most all data breaches occur at business and public databases, and are the fuel for the illicit worldwide trade in identities. The profits from the sale of identity data have surpassed the entire international illicit drug trade. As I mentioned in my previous column it is very difficult to trace any given episode of identity theft to a single source as the data is sold many times and divided up along the way splitting one persons' information in many directions. As this occurs the information is used for a myriad of purposes. This is where it gets very sticky. While this misuse is going on different public and private databases are corrupted with false entries and may take years to surface. A person my not discover until years later that an event has taken place that has altered their Social Security records, medical records, insurance records, employment records, and so on. Often by then it is nearly impossible to correct these false records.Since we are literally judged by the entries in these databases wouldn't it be clever if they were accurate?
As long as data has value it will be stolen, sold, and misused. Until we can remove the value of the information itself we need to concentrate on prevention programs of businesses and public records keepers. A simple program of policy training and awareness of the nature of the crimes can go a long way to stem the tide of identity theft. This is not necessarily a difficult or expensive process. Often it can be done at little or no direct cost to the business other than the training time, which frankly is purely an investment. And if insurance companies are listening, should lower the rates of proactive clients just as their risk is lowered.
Monday, January 5, 2009
New Proposals in Iowa
"Iowa governments would have greater authority to black out personal information from public records under proposals recommended by a legislative committee.Advocates say the proposals would protect citizens from identity theft.But opponents say the unintended results could be alarming, particularly if the public is unable to differentiate between, for example, a convicted sex offender and another citizen with the same name."The public has more to fear from government records containing information about them of which they are unaware than the release of information pertaining to them," said Bill Monroe, executive director of the Iowa Newspaper Association.
Lawmakers formed the Identity Theft Prevention Study Committee, which met in November, to consider how the release of personal information in Iowa could make residents vulnerable to identity theft. Public concern heightened this year when privacy advocates complained about a land records site, IowaLandRecords.org. The Social Security numbers of thousands of Iowans from all 99 counties were listed on the site, including those of Gov. Chet Culver and Secretary of State Michael Mauro.
Administrators of the site quickly shut down the ability to view details of the records after the advocates pointed out the problem. The group says removing personal information from all the records - called redaction - will cost the state as much as $2.3 million, which includes $500,000 to update its computer programs. Culver said in an interview this week that he agrees steps should be taken to redact personal information from public records that can be used to steal Iowans' identities.
However, he said he was not sure how the state would pay for such efforts. County recorders, for example, have proposed increasing an electronic filing fee from $1 to $3 to pay for the redaction effort.
"I think protecting individuals' identity is important," Culver said. "Once it gets to the level of security risk, we should take steps to limit how far we go in terms of disclosing things like Social Security numbers."
The committee made 11 recommendations, several of which would give governments more power to remove Social Security or bank account numbers.
Sen. Steve Kettering, R-Lake View, a member of the study committee, said there is no simple answer to the problem. Lawmakers must find the appropriate balance between protecting identities and maintaining public records that protect the public through transparent government.
"There isn't an easy solution, and that's the hard part," said Kettering, who noted that detailed records are critical in his profession as president of Farmers State Bank in Lake View.
Open-records advocates generally agree that some sensitive information like credit card numbers should not be released. The problem arises if governments redact information such as dates of birth, addresses or other unique identifiers, said Kathleen Richardson of the Iowa Freedom of Information Council. Richardson said lawmakers need to establish how frequently identity theft occurs through public records. She believes the problem is rare.
"I think there needs to be a demonstrated need of why we need to vacuum public records," Richardson said. "We also have to carefully consider what our definition of personal information is and make sure it's not so broad that it wipes out too much information."
Sen. Steve Warnstadt, D-Sioux City, said the committee has tried to be sensitive to the concerns brought forward by open records advocates when making its recommendations. The recommendations will likely be used to help draft proposals during the 2009 legislative session, which begins Jan. 12.
"The point of this is not to restrict access. The point is to prevent identity theft and personal information from being disclosed from people who don't have a legitimate reason to have that information," said Warnstadt, the committee co-chairman."
Iowa is tackling this issue head on and should be a model for other states to follow. Notice how Kathleen Richardson is addressing the central question by saying that the committee needs to assess the definition of personal information. Once a written policy including that crucial component has been established it becomes relatively easy to put a real plan into motion.
I would also counsel so-called "open records" advocates that while the concept of easy access is attractive, it has one fatal flaw. Data has value. The proponents are not the ones who determine what is valuable data and what is not. That is in the hands of the information black market. As I have said time and again. "As long as the data has value it will be stolen , sold, and used by thieves." As to public record theft incidents there were in excess of 15 million combined records lost or stolen from counties, cities, states, state universities, and school districts across the U.S. in 2008 alone. Those are public records databases. In my links area is a link to dataloss, http://datalossdb.org/ . You can see there how much is lost and stolen on a regular basis. But how much is acceptable? According to FTC and other sources there have been between 8 and 10 million domestic identity theft victims in each of the past three years. Due in part to the sale and resale of stolen information it can be difficult and even impossible to trace identity theft victims to a single incident, which skews statistics. This is particularly true with mass database theft such as with public records.
If the figure of $2.3M to update software and to redact records is correct the investment the state will have made will offset the upfront hard costs of a data breach, the liability of a large or even moderate breach, and any subsequent lawsuits resulting from identity theft. Good Risk Managers will tell you that the potential loss is far greater than the investment in a reasonable program.
Identity theft is on the rise at an alarming rate. As our economy unravels and becomes more fragile every day data sales becomes a very attractive activity with very low risk. As the businesses and local governments cut back on security budgets a lot more opportunities occur to steal information, and a lot more people are desperate to cash in on the market in personal information.
Monday, December 29, 2008
Let's Pretend May 1st is Just Another Day in the Life of a Business.
Businesses in the U.S. have until May 1st, 2009 to initiate an Identity Theft program.
With the enactment of the 2008 FACTA Red Flags Rule comes a responsibility for all businesses, non-profits, schools and universities, utilities, and local governments to,
- Adopt a written identity theft policy that will address the responsibilities of employees who can have access to personally identifiable information (PII), and including a response plan in the event of PII breaches,
- Provide ongoing awareness training for all affected staff.
It is generally understood that the training of all staff is more effective and serves to further protect the employer from loss. - It also requires an oversight of the security practices of all service providers and 3rd party contractors who might have access to the non-public data you hold on clients, customers, and employees alike.
The Federal Trade Commission extended the original November 1st, 2008 deadline until May 1st to give businesses more time to implement their individual programs. The FTC has oversight of the Fair and Accurate Credit Transactions Act (FACTA). The extension was granted only to non-banking businesses.
Not to be confused with a privacy policy, this legislation requires an Identity Theft specific policy to be implemented and approved by ownership or a Board of Directors as company policy. After the May 1st date breach cases involving non-compliant organizations will result in increased fines, federal audits, and will allow more victims’ lawsuits to go forward. Neither a business’ sector nor its’ size is a factor regarding this legislation.
“Have in place and implement a breach response plan.. Ask every new employee to sign an agreement to follow your company's confidentiality and security standards for handling sensitive data... Create a culture of security by implementing a regular schedule of employee training. Make sure training includes employees at satellite offices, temporary help, and seasonal workers.
Before you outsource any of your business functions – payroll, web hosting, consumer call center operations, data processing or the like- investigate the company’s data security practices and compare their standards to yours.”
From the FTC publication, Protecting Personal Information, a guide for business.
With only 5 months remaining now is the time to get your identity theft program in place. No organization can afford the fallout from litigation, fines, and the loss of business resulting from a breach and subsequent identity theft episodes.
Happy New Year!

