Archives

FISMA: The Federal Information Security Management Act

The E-Government Acts of 2002 involved a large number of new regulations to implement and control the use of electronic technologies by the U.S. Government. Title III of this Act, called the Federal Information Security Management Act required all Government agencies to develop extensive information security [...]

UK's secret spies nix huge covert operation after loss of USB memory stick

Last week, the British Security Service and Secret Intelligence Services, better known as MI5 and MI6, showed exactly how expensive information security procedures really can be. Details unveiled last week show MI6 scrapped a 2006 undercover drug raid operation in Columbia for fear that a lost USB stick containing covert agents and informants may have fallen into the wrong [...]

Hundreds of millions of private credit card records stolen from PCI card processor

Credit card payment processor Heartland Payment Systems announced this week that hundreds of millions of credit card transactions were stolen last year. This latest hack far eclipsed the 45 Million TJX Companies records lost from 2004-2007. The stolen data includes names, credit/debit card numbers and expiration [...]

NY Police Sergeant admits making unauthorized accesses to the FBI's National Crime Information Center database

Last week, a NY Police Sergeant admitted he made unauthorized accesses to the FBI’s National Crime Information Center database in December [...]

Decade old MD5 flaw will likely still result in numerous privacy breaches

It took over a decade, but two German researchers found an application for a flaw in the MD5 hash widely used throughout the Internet for [...]

Privacy and Messaging through Postini

Postini is Google’s 2006 acquisition for secure messaging, and a direct competitor to IronPort. All of their offerings surround Software As A Service (SAAS), matching directly with Google’s overall technology strategy. They provide several services, including web security, anti-spam/malware, mail filtering, and archival with indexing. The Data Leakage Prevention capabilities provide privacy protections through outbound communication filters. Additionally, there are management tools and continuity procedures appropriate for enterprise use.

Postini’s background technology stems from threat assessment and message parsing capabilities, grown through several years as a primary mail provider. There are two major patents, with a variety of [...]

CSI and Information Security – searching for the perfect evidence?

Eveyone’s either watched or at least heard of CSI – Crime Scene Investigation. With the spin-offs, there are three out of five nights a week in Prime Time where you may learn about trace evidence, bullet trajectories, and splatter patterns. It’s been such a phenomenon that Criminal Justice is the most popular/fastest growing new major in colleges.

One thing that comes up every now and again on the show surrounds evidence and collection; someone kicks a gun out of position, forgets to wear gloves while picking something up, or there was a fire due to someone’s carelessness. During the trial, while [...]

Upcoming interview w/ Barbra Symonds, CIPP/G

An interview with the Barbra Symonds, Associate Partner with IBM, and former IRS Director of Privacy & Information Protection, and before that project manager for the Veteran’s Administration’s Privacy policy will appear on the site within the next 7 – 10 days, pending approval. Barbra was part of the original group that defined the Certified Information Privacy Professional for Government (CIPP/G). It was a great interview, with some timely comments on the state of information security and information privacy.

Password hacking with chocolate: Are women more susceptible to social engineering?

The Mitnick attack. The 10 attack. Social Engineering. Each of these emphasize how readily people part with valuable information to someone posing as an IT staffer, a very attractive member of the opposite sex, or someone friendly. You may now add candy bars and women…

No matter how you slice it, the weakest point in any security program ends up being the end user. User training seems to work with frequency of message, but without hearing the importance of security it seems quickly forgotten.

That is of course, unless the message starts at the top with a strong corporate policy, well understood [...]

eDiscovery – Could the obvious approach put too much private information into one spot?

Electronic Discovery, or eDiscovery, is the digital analog to a court request for documents and files pertaining to a proceeding. As with anything digital, the courts expect discovery times in days and weeks, versus the months (years) given for paper files. Punishments for failure to produce could be regulatory, legislative, or may even include court based consequences such as contempt charges. In a recent survey by Information Security Magazine, only 28 percent of respondents knew how they would handle an eDiscovery request. Even knowing where to look seems a daunting task. I have trouble at [...]