<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance</title>
	<atom:link href="http://blog.kraasecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 26 May 2010 02:45:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Corporate Reputation Management: Can a company require you register your Social Media Profile with Human Resources?</title>
		<link>http://blog.kraasecurity.com/2010/05/25/corporate-reputation-management-can-a-company-require-you-register-your-social-media-profile-with-human-resources/</link>
		<comments>http://blog.kraasecurity.com/2010/05/25/corporate-reputation-management-can-a-company-require-you-register-your-social-media-profile-with-human-resources/#comments</comments>
		<pubDate>Wed, 26 May 2010 02:43:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[social media]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Dave Carroll]]></category>
		<category><![CDATA[Employment]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Human resources]]></category>
		<category><![CDATA[United Airlines]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=231</guid>
		<description><![CDATA[



Image via CrunchBase



When you join a company, you relinquish certain rights. The workplace is not a democracy. Yet many people still think that their corporate email, their corporate computers and the data they use is &#8220;theirs&#8221;. Who owns that data? Well the answer is the company. Companies are concerned with data loss prevention. A company [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 203px; height: 85px;">
<dt class="wp-caption-dt"><a href="http://www.crunchbase.com/company/facebook"><img title="Image representing Facebook as depicted in Cru..." src="http://www.crunchbase.com/assets/images/resized/0000/4561/4561v1-max-250x250.png" alt="Image representing Facebook as depicted in Cru..." width="216" height="80" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://www.crunchbase.com/">CrunchBase</a></dd>
</dl>
</div>
</div>
<p>When you join a company, you relinquish certain rights. The workplace is not a democracy. Yet many people still think that their corporate email, their corporate computers and the data they use is &#8220;theirs&#8221;. Who owns that data? Well the answer is the company. Companies are concerned with <a title="data loss prevention" href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">data loss prevention</a>. A company can fire you for mis-using company data, that is obvious. A company can fire you for portraying a poor image such as drunkenness, poor behaviour, saying negative or derogative things about your boss or company,  public displays of nudity, well I could go on about why you can be fired.</p>
<p>One example is a young woman who got fired from her job because she said she &#8221; thought her job was boring. So she said so on her <a class="zem_slink freebase/en/facebook" title="Facebook" rel="homepage" href="http://facebook.com/">Facebook</a> page.  Her employer, Ivell Marketing and Logistics of Clacton, U.K., gave her this update: &#8220;Following your comments made on Facebook about your job and the company we feel it is better that, as you are not happy and do not enjoy your work we end your employment with Ivell Marketing &amp; Logistics with immediate effect&#8221; as stated in this <a class="zem_slink freebase/en/cnet" title="NASDAQ: CNET" rel="yahoofinance" href="http://finance.yahoo.com/q?s=CNET">CNET</a> article, <a href="http://news.cnet.com/8301-17852_3-10172931-71.html">http://news.cnet.com/8301-17852_3-10172931-71.html</a></p>
<p>So the question is, can a company can fire you for your out of office activities, should they have the right to monitor your activity? Should an employee be required to register all their social media profiles with their employer so that the reputation of the company can me monitored? It would obviously make it easier to know if an employee is damaging the reputation of the company.</p>
<p>The biggest challenge Social Media plays for a company is damage to reputation. A silly yet powerful example of Social Media affecting a company&#8217;s reputation is <a class="zem_slink freebase/en/united_airlines" title="United Airlines" rel="homepage" href="http://www.united.com/">United Airlines</a> breaking a musician&#8217;s guitar and refusing to pay for it. The musician <a class="zem_slink" title="Dave Carroll" rel="homepage" href="http://www.davecarrollmusic.com/">Dave Carroll</a> had a <a class="zem_slink freebase/en/youtube" title="YouTube" rel="homepage" href="http://www.youtube.com/">YouTube</a> hit with his song about the poor airline response to him (<a href="http://www.boston.com/travel/blog/2009/07/song_over_guita.html">http://www.boston.com/travel/blog/2009/07/song_over_guita.html</a>) This <a class="zem_slink freebase/en/viral_video" title="Viral video" rel="wikipedia" href="http://en.wikipedia.org/wiki/Viral_video">viral video</a> caused reputation damage. So this is a bit different from an employee posting something, but it has the same end result, reputation damage.</p>
<p>So when you start a new job, you have to take a drug test, get a background check, so why not register all your social media profiles? What are the pros and cons? Is it to much &#8220;Big Brother&#8221; or is it becoming a relevant reality of doing business in the Social Media age?</p>
<p>Gary Bahadur</p>
<p>CEO KRAA Security,  <a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><em> </em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p>*FREE Website Security Test</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.gautamblogs.com/2010/05/how-social-media-can-revolutionalise.html">How Social Media Can Revolutionalise Your HR Department</a> (gautamblogs.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.socialmediatoday.com/SMC/198735">Social Media In, Common Sense Out</a> (socialmediatoday.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/f1073208-a83c-499d-9549-1846710d3948/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=f1073208-a83c-499d-9549-1846710d3948" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/05/25/corporate-reputation-management-can-a-company-require-you-register-your-social-media-profile-with-human-resources/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Lifecycle Management: How to reduce risk, Part 2</title>
		<link>http://blog.kraasecurity.com/2010/05/02/data-lifecycle-management-how-to-reduce-risk-part-2/</link>
		<comments>http://blog.kraasecurity.com/2010/05/02/data-lifecycle-management-how-to-reduce-risk-part-2/#comments</comments>
		<pubDate>Sun, 02 May 2010 19:58:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Vendor Risk]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Company]]></category>
		<category><![CDATA[Consultants]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Data Lifecycle Management]]></category>
		<category><![CDATA[General and Freelance]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=225</guid>
		<description><![CDATA[Data Lifecycle Management: How to reduce risk
Part 2
The Data Lifecycle Management (DLM) goes through 5 steps: creation, usage, transport, storage and destruction. Most companies have parts of this lifecycle under control, but that means there are lots of areas for gaps in the control measures that could let a threat affect the data. The multiple [...]]]></description>
			<content:encoded><![CDATA[<h2>Data Lifecycle Management: How to reduce risk</h2>
<p>Part 2<br />
The <strong>Data Lifecycle Management</strong> (DLM) goes through 5 steps: creation, usage, transport, storage and destruction. Most companies have parts of this lifecycle under control, but that means there are lots of areas for gaps in the control measures that could let a threat affect the data. The multiple part blog, (I am not sure how many parts it will take), will walk through the steps of the data lifecycle and what a company can do to implement a good process for all the data management challenges.</p>
<p>In the first part of this series, we covered what it means to say you have or want a data lifecycle management process.  So why do we need something different from what we are already doing around DLM?</p>
<h2>Why does traditional security not work for DLM?</h2>
<p>Users have risky behavior. They will always have risk behavior and we rely on mostly <a class="zem_slink freebase/en/technology" title="Technology" rel="wikinvest" href="http://www.wikinvest.com/industry/Technology">technology</a> controls to keep them in a secure box.  Solutions aimed at the external threats coming in, not the regulation and governance of internal communications going out. Problems we see are typically:</p>
<ul>
<li><strong>Unauthorized application use</strong>: 70% of IT say the use of unauthorized programs result in as many as half of data loss incidents.</li>
<li><strong>Misuse of corporate computers</strong>: 44% of employees share work devices with others without supervision.</li>
<li><strong>Unauthorized access</strong>: 39% of IT said they have dealt with an employee accessing unauthorized parts of a company’s network or facility.</li>
<li><strong>Remote worker security</strong>: 46% of employees transfer files between work and personal computers.</li>
<li><strong>Misuse of passwords</strong>: 18% of employees share passwords with co-workers.</li>
</ul>
<p>The reasons typical technology controls will not work in the full DLM process are:</p>
<ul>
<li>Products are not geared to protect a full life cycle of a customer records</li>
<li>Most solutions and processes are outward facing, based on perimeter security</li>
<li><a title="pgp encryption" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">Encryption</a> can affect data management</li>
<li>Real-time <a title="intrusion detection" href="http://www.kraasecurity.com/managed-services/intrusion-defense/intrusion-detection">intrusion detection</a> and remediation is rare</li>
<li>Context and intent of messages was not analyzed properly</li>
<li>Functional areas in organizations create different policies, monitoring requirements, enforcement priorities and reporting</li>
<li>New technologies can avoid security measures</li>
<li>Technologies look at the network, the operating system or the application not the data across all environments</li>
<li>Not mapped properly to regulations</li>
</ul>
<h2>What risks does customer data loss pose for organizations?</h2>
<p>If we know that security is not working, what are the risks we face? A very recent example of how this can have a practical affect is with the <strong><a title="massachusetts privacy" href="http://www.kraasecurity.com/compliance/201-cmr-1700-massachusetts-privacy-law">Massachusetts Privacy Law 201 CMR 17.00</a>. </strong>Loss of data can have a great financial impact with this law. <strong> </strong>Key things we need to consider include:</p>
<ul>
<li>Penalties: Not complying with regulations can cause civil and financial penalties</li>
<li>Confidence: Loss of customer confidence because of a customer <a title="data loss prevention" href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">data breach </a>can lose customers</li>
<li>Reputation: Damage to reputation will lose customer and damage relationships</li>
<li>Competitive Advantage: Information and customers can move to competitors</li>
<li>Costs: <a class="zem_slink" title="Ponemon Institute" rel="homepage" href="http://www.ponemon.org/">Ponemon Institute</a>’s 2008 annual study, average $6.6 million per breach.</li>
<li>Valuation: Decreased stock prices could result</li>
</ul>
<p>I will continue this process in the next post…</p>
<p>Gary Bahadur<br />
<a title="network security risk assessment" href="http://www.kraasecurity.com">http://www.kraasecurity.com</p>
<p>http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
Address: 200 Se 1st St #601 Miami FL 33131</p>
<p>*Managed Security Services<br />
*Vulnerability Management<br />
*Compliance &amp; Policy Development<br />
*PGP Security<br />
*FREE Website Security Test</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/March2010/10/c8461.html&amp;a=14480228&amp;rid=9695555b-dc62-4f4d-b5f8-8de22da37117&amp;e=bf95a820287a2b52a1b11bb045c269a3">Analyst Study Shows Employees Continue to Put Data at Risk</a> (newswire.ca)</li>
<li class="zemanta-article-ul-li"><a href="http://eon.businesswire.com/news/eon/20100427005421/en">Perception of Data Security at Odds with Reality, Accenture Study Finds</a> (eon.businesswire.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.newstatesman.com/technology/2010/03/data-protection-theft-loss">Data protection a priority for CEOs</a> (newstatesman.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2259432/hsbc-understated-threat">HSBC admits to understating data theft</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2256724/breach-numbers-fall-while-costs">Breach numbers fall while costs rise Ponemon study finds</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.techcrunchit.com/2010/04/29/symantec-shells-out-370-million-for-data-encryption-companies-pgp-and-guardianedge/">Symantec Shells Out $370 Million For Data Encryption Companies PGP and GuardianEdge</a> (techcrunchit.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/60b0d89f-8c7a-413e-b843-f7ff3b827813/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=60b0d89f-8c7a-413e-b843-f7ff3b827813" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/05/02/data-lifecycle-management-how-to-reduce-risk-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Lifecycle Management: How to reduce risk (part1)</title>
		<link>http://blog.kraasecurity.com/2010/04/21/data-lifecycle-management-how-to-reduce-risk-part1/</link>
		<comments>http://blog.kraasecurity.com/2010/04/21/data-lifecycle-management-how-to-reduce-risk-part1/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 01:42:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Supplier Security]]></category>
		<category><![CDATA[Unstructured Data]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[data lifecycle]]></category>
		<category><![CDATA[Data management]]></category>
		<category><![CDATA[risk reduction]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=221</guid>
		<description><![CDATA[The Data Lifecycle goes through 5 steps: creation, usage, transport, storage and destruction. ]]></description>
			<content:encoded><![CDATA[<h1>What is Data Lifecycle Management?</h1>
<p>The Data Lifecycle goes through 5 steps: <strong>creation, usage, transport, storage and destruction</strong>. Most companies have parts of this lifecycle under control, but that means there are lots of areas for gaps in the control measures that could let a threat affect the data. The multiple part blog, (I am not sure how many parts it will take), will walk through the steps of the data lifecycle and what a company can do to implement a good process for all the <a class="zem_slink freebase/en/data_management" title="Data management" rel="wikipedia" href="http://en.wikipedia.org/wiki/Data_management">data management</a> challenges.</p>
<p><strong>Data lifecycle management</strong> (DLM) is a policy and procedure based approach to manage information movement. Data has to be classified and evaluated to properly protect it with the right resources. Ownership is a key factor in managing and maintaining data throughout the lifecycle</p>
<p><strong>The 5 Steps</strong></p>
<ol>
<li>Creation – How does data creation get managed?</li>
<li>Usage – What limitations are on data usage?</li>
<li>Storage – What controls are in place for storage?</li>
<li>Transportation – How is data transmitted between company, customers and business partners?</li>
<li>Destruction – What is the validation and verification process over data destruction?</li>
</ol>
<p><strong>The Data Management Problem</strong></p>
<ul>
<li>Weak processes in place to track creation usage, transportation, storage and destruction</li>
<li>Weak ability to monitor and manage a customer record throughout the lifecycle</li>
<li>Inconsistent processes across each phase of data movement</li>
<li>Lack of enforcement capabilities</li>
</ul>
<p><strong>What should be the goal of data lifecycle management?</strong></p>
<ul>
<li>Provide practical steps to manage each step of the customer record management process</li>
<li>Provide cost effective solution for risk mitigation</li>
<li>Provide framework for data management</li>
<li>Reduce risk of data loss</li>
</ul>
<p><strong>Challenges to Customer Data </strong><a class="zem_slink freebase/en/records_management" title="Records management" rel="wikipedia" href="http://en.wikipedia.org/wiki/Records_management"><strong>Records Management</strong></a></p>
<ul>
<li>Rarely does a company have a centralized process to track controls over data, over management processes around data, over logging and monitoring, and removal</li>
<li>Organizations rely on technology to secure data not processes that drive technology purchases</li>
<li>The 5 steps of data management are not followed by all functional groups in a company</li>
<li>No clear ownership and classification of customer data elements</li>
</ul>
<p><strong>Did you know…</strong></p>
<ul>
<li>1 in 400 emails contains confidential information</li>
<li>1 in 50 network files contains confidential data</li>
<li>4 out of 5 companies have lost confidential data when a laptop was lost</li>
<li>1 in 2 USB drives contains confidential information</li>
<li>Companies that incur a data breach experience a significant increase in customer turnover—as much as 11%</li>
<li>Over 35 states have enacted <a class="zem_slink freebase/en/security" title="Security" rel="wikipedia" href="http://en.wikipedia.org/wiki/Security">security breach</a> notification laws</li>
<li>Can openers were invented 48 years after cans</li>
</ul>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.computing.co.uk/computing/news/2261642/infosec-firms-suffer-integrity">Infosec 2010: A quarter of all firms have seen data integrity attacks</a> (computing.co.uk)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/6fe14c87-353d-4aeb-8f44-bb4cf6dd8e41/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=6fe14c87-353d-4aeb-8f44-bb4cf6dd8e41" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/04/21/data-lifecycle-management-how-to-reduce-risk-part1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What are the features you need a Windows Security Host Diagnostic tool?</title>
		<link>http://blog.kraasecurity.com/2010/04/01/what-are-the-features-you-need-a-windows-security-host-diagnostic-tool/</link>
		<comments>http://blog.kraasecurity.com/2010/04/01/what-are-the-features-you-need-a-windows-security-host-diagnostic-tool/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 00:56:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Could Computing]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Federal Information Security Management Act of 2002]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[Operating system]]></category>
		<category><![CDATA[Policy]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=207</guid>
		<description><![CDATA[



Image via Wikipedia



There is a lot of focus on network security and application security today. Years ago it was operating system security that was all the rage. But with the advent of the strict requirements of some of the regulations such as HIPAA, PCI, SOX, and FISMA, more attention needs to be paid to the [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 83px; height: 29px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Windows_7.png"><img title="Windows 7 is the latest stable Windows operati..." src="http://upload.wikimedia.org/wikipedia/en/thumb/b/bd/Windows_7.png/300px-Windows_7.png" alt="Windows 7 is the latest stable Windows operati..." width="79" height="51" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Windows_7.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>There is a lot of focus on network security and application security today. Years ago it was <strong><a title="host security assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">operating system security</a></strong> that was all the rage. But with the advent of the strict requirements of some of the regulations such as <strong><a title="Hipaa security" href="http://www.kraasecurity.com/compliance/hipaa-assessment">HIPAA</a></strong>, <strong><a title="PCI security" href="http://www.kraasecurity.com/compliance/PCI-Assessment">PCI</a></strong>, SOX, and <a class="zem_slink freebase/en/federal_information_security_management_act_of_2002" title="Federal Information Security Management Act of 2002" rel="wikipedia" href="http://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002">FISMA</a>, more attention needs to be paid to the operating system. As <a class="zem_slink freebase/en/microsoft_windows" title="Windows" rel="homepage" href="http://www.microsoft.com/WINDOWS">Windows</a> is still dominant, what are some of the features you need to be concerned with in an application?</p>
<p>Some key feature of a <a title="windows security assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment"><strong>host security assessment</strong> </a>tool are: </p>
<ol>
<li>Ability to quickly audit</li>
<li>Ability to inventory</li>
<li>Structure for classification of components</li>
<li><strong><a title="patch management" href="http://www.kraasecurity.com/consulting-services/network-solutions/security-architecture-analysis">Patch management</a></strong> of course</li>
<li>Ability to baseline and report against the baseline</li>
<li>Templates of the regulatory requirements</li>
<li>Templates of different levels of security configurations</li>
<li><a title="threat assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment"><strong>Threat identification</strong> </a>and classification</li>
<li>User management</li>
<li>Port security assessment and management</li>
<li>Service and process analysis</li>
</ol>
<p>A baseline configuration for <strong><a title="operating system security" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">operating system security</a></strong>, cover things such as patch levels, ports, services, processes, logging, policy settings and user configuration, should be the first step for any company in host security assessment and diagnostics. If you build from scratch, or don’t use a secure template, you will always be in trouble. Timely updates and reconfiguration of your baseline is necessary.</p>
<p>Your operating system like your <strong><a title="Network security" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">network security</a></strong> should match your corporate business practices and procedures. <strong><a title="policy development" href="http://www.kraasecurity.com/consulting-services/network-solutions/policy-development">Policies</a></strong> should be in place for this of course.  Over time you should be able to benchmark your <strong>host security</strong> problems, solutions and changes.</p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><em><strong>Address</strong></em><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*<strong><a title="PGP " href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">PGP Security</a></strong></p>
<p>*FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.prweb.com/releases/fisma/compliance/prweb3558694.htm">Lumension Highlights Six Critical Elements To Ensure Painless FISMA Compliance</a> (prweb.com)</li>
<li class="zemanta-article-ul-li"><a href="http://web2.sys-con.com/node/1261691">Security vs. Compliance in the Cloud</a> (web2.sys-con.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.technet.com/keithcombs/archive/2010/02/11/security-compliance-manager-beta-signup-now-available.aspx">Security Compliance Manager &#8211; beta signup now available</a> (blogs.technet.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/7e3a67f9-0b1f-4428-8b45-7f4634faec56/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=7e3a67f9-0b1f-4428-8b45-7f4634faec56" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/04/01/what-are-the-features-you-need-a-windows-security-host-diagnostic-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Washington State implements PCI law</title>
		<link>http://blog.kraasecurity.com/2010/03/30/washington-state-implements-pci-law/</link>
		<comments>http://blog.kraasecurity.com/2010/03/30/washington-state-implements-pci-law/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 18:56:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Could Computing]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[Minnesota]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=214</guid>
		<description><![CDATA[



Image via Wikipedia



PCI laws are expanding around the country. Washington State is the latest to add a law to their books. Washington state follows Nevada and Minnesota in implementing Payment Card Industry Data Security Standard (PCI), the law is HB 1149. It changes the breach notification law they already had on the books. The key [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 57px; height: 44px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:The_Washington_State_Capital.jpg"><img title="The Washington State Capitol. Taken from The J..." src="http://upload.wikimedia.org/wikipedia/en/thumb/7/75/The_Washington_State_Capital.jpg/300px-The_Washington_State_Capital.jpg" alt="The Washington State Capitol. Taken from The J..." width="96" height="84" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:The_Washington_State_Capital.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><strong>PCI</strong> laws are expanding around the country. <a class="zem_slink freebase/en/washington" title="Washington" rel="geolocation" href="http://maps.google.com/maps?ll=47.5,-120.5&amp;spn=3.0,3.0&amp;q=47.5,-120.5 (Washington)&amp;t=h">Washington</a> State is the latest to add a law to their books. Washington state follows <a class="zem_slink freebase/en/nevada" title="Nevada" rel="geolocation" href="http://maps.google.com/maps?ll=39.0,-117.0&amp;spn=3.0,3.0&amp;q=39.0,-117.0 (Nevada)&amp;t=h">Nevada</a> and <a class="zem_slink freebase/en/minnesota" title="Minnesota" rel="geolocation" href="http://maps.google.com/maps?ll=46.0,-94.0&amp;spn=3.0,3.0&amp;q=46.0,-94.0 (Minnesota)&amp;t=h">Minnesota</a> in implementing <strong>Payment Card Industry Data Security Standard (PCI)</strong>, the law is <strong>HB 1149</strong>. It changes the <a href="http://apps.leg.wa.gov/Rcw/default.aspx?cite=19.255.010">breach</a> notification law they already had on the books. The key point is that it allows issuing banks a method of collecting the costs to reissue <a class="zem_slink freebase/en/payment_card" title="Payment card" rel="wikipedia" href="http://en.wikipedia.org/wiki/Payment_card">payment cards</a> after a breach.</p>
<h3>Organizations who must abide by the law</h3>
<p>It defines “business(es)” as merchants processing more than six million cards and sell to Washington state residents.  “Processors” manage account information for others and “vendors” sell software or equipment that processes, transmits or store account information.  Account information can is not so clearly defined. It will be interesting to see how companies outside of the state are affected. <a title="pci assessment" href="http://www.kraasecurity.com/compliance/PCI-Assessment">PCI Security Assessments </a>are going to become even more prevelant.</p>
<h3>How is the law implemented?</h3>
<p>Entities that fall under the law are required to provide reasonable security measures. They can be liable for damage and if they have to reimburse their banks for reissuance of card, that can get very expensive.  The law should probably have been more clear on this point</p>
<p>Determining a breach has been defined as “unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business.”  There is the possibility of confusion between account information and personal information. That will probably cause problems in the future lawsuits. <strong><a title="PGP Encrytion" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">Encryption</a></strong> is also going to be a challenge in the implementation and review for compliance requirements.</p>
<p>How this law integrates or conflicts with PCI requirements will news worthy. The different levels of <strong>PCI compliance</strong> and the levels identified by the law are now completely consistent. Can <strong><a title="pci saq assessment" href="http://www.kraasecurity.com/compliance/PCI-Assessment">PCI SAQ assessment</a></strong> be enforced by the law? Can you be PCI compliant and not compliant with the law, or vice versa? I would venture to say yes.</p>
<p>If only we have a National Standard for all of this. Wouldn’t that be a progressive move?</p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p>*Managed Security Services</p>
<p>*<a title="vulnerability assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">Vulnerability Management</a></p>
<p>*Compliance &amp; Policy Development  </p>
<p>*<a title="pgp Security" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">PGP Security</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/22185a3e-5b68-49f6-8c30-3cc025fb0640/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=22185a3e-5b68-49f6-8c30-3cc025fb0640" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/03/30/washington-state-implements-pci-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What are the challenges with protecting electronic documents?</title>
		<link>http://blog.kraasecurity.com/2010/03/29/what-are-the-challenges-with-protecting-electronic-documents/</link>
		<comments>http://blog.kraasecurity.com/2010/03/29/what-are-the-challenges-with-protecting-electronic-documents/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 12:36:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Adobe Systems]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Data loss prevention products]]></category>
		<category><![CDATA[Document management system]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=199</guid>
		<description><![CDATA[



Image via Wikipedia



We have seen a lot of problems with Adobe vulnerabilities. Adobe has been getting beat up with all the negative publicity in the past few months. Apple is restricting access to Adobe on their devices. Has anyone tried their remote desktop sharing? I wonder if some vulnerability will be release in that application. [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 86px; height: 35px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg"><img title="Adobe Systems Incorporated" src="http://upload.wikimedia.org/wikipedia/en/thumb/d/dd/AdobeSystems.svg/300px-AdobeSystems.svg.png" alt="Adobe Systems Incorporated" width="82" height="37" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>We have seen a lot of problems with <strong><a class="zem_slink freebase/en/adobe_creative_team" title="Adobe Systems" rel="homepage" href="http://www.adobe.com/">Adobe</a></strong> vulnerabilities. Adobe has been getting beat up with all the negative publicity in the past few months. <a class="zem_slink freebase/en/apple_inc" title="Apple" rel="homepage" href="http://www.apple.com/">Apple</a> is restricting access to Adobe on their devices. Has anyone tried their <a class="zem_slink freebase/en/remote_desktop_software" title="Remote desktop software" rel="wikipedia" href="http://en.wikipedia.org/wiki/Remote_desktop_software">remote desktop</a> sharing? I wonder if some vulnerability will be release in that application. What is the real problem with <strong>electronic document</strong> sharing and what are some of the solutions? Adobe is just an example; the whole industry of electronic documents is finally coming into its own. </p>
<p><strong>Problems with Electronic Douments</strong></p>
<p>How are people accessing <strong>electronic documents</strong> and how are they signing them and verifying them? Well there are multiple companies out there touting secure signature applications for documents. When do you use these companies?  Some questions to ask include:<br />
1. When and how do you determine the importance of the document?<br />
2. Have you implemented a <strong><a title="Data Classification Policy Development" href="http://www.kraasecurity.com/consulting-services/network-solutions/policy-development" target="_blank">data classification</a></strong> scheme for electronic documents?<br />
3. Who has the right to sign and read these documents?<br />
4. How do you track usage and distribution?<br />
5. Is there a time frame associated with the life of the document?<br />
6. Can you prevent <strong>screen scraping</strong> of the secured document?<br />
7. What is the “hackability” of the secure document?</p>
<p>Signing an electronic document can be a challenge for the technology challenged. Some documents might trigger <strong><a title="Antivirus" href="http://www.kraasecurity.com/managed-services/email-defense/antivirus">antivirus</a></strong> or <strong>malware protection</strong> applications. If some <strong><a title="Intrusion Detection" href="http://www.kraasecurity.com/managed-services/intrusion-defense/intrusion-detection">intrusion detection</a></strong> applications can read a document or <strong><a title="Data loss prevention" href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">data loss prevention</a></strong> applications do not have access, you could be blocked from that document. Convenience of use is a major hurdle for the adoption of secure documents.</p>
<p>Printing, modifying, viewing, and deleting these documents require all kinds of levels of authorization that is probably difficult to manage. If you can have a location based “bomb” in the document for when it left the organization domain, that would be an interesting play on data loss prevention. We know client side options are easily broken, how do we change the mentality of secure document management?</p>
<p>I do not see how secure documents make too much sense in any public forum. Its not worth the effort to worry about secure documents outside of a strictly controlled corporate environment. Different forms of <strong>watermarking</strong> have their place in identification but not much in control.</p>
<p> <br />
The most likely areas are in Research and Development, Legal, Banking and Healthcare. These should be the quickest to adopt a secure framework for electronic documents. Some industry standards need to be followed and a process developed that all companies can follow. This would make it into all the data loss prevention applications eventually and really provide some security.</p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development </p>
<p>*PGP Security</p>
<p>*FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2259973/mcafee-unveils-loss-prevention">McAfee unveils new data loss prevention tools</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/security-central/hackers-used-malicious-pdfs-attack-google-and-adobe-750%3Fsource%3Drss_infoworld_news&amp;a=11542703&amp;rid=2ed30ba5-9503-4cfe-801e-fab10a848370&amp;e=2545d3e4ff74275d83e7057251f484fd">Hackers used malicious PDFs to attack Google and Adobe</a> (infoworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.adobe.com/security/2010/02/certified_document_services_cd.html">Certified Document Services (CDS) Program Grows to Six with Post.Trust Announcement</a> (blogs.adobe.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/2ed30ba5-9503-4cfe-801e-fab10a848370/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=2ed30ba5-9503-4cfe-801e-fab10a848370" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/03/29/what-are-the-challenges-with-protecting-electronic-documents/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Social Media INSecurity?</title>
		<link>http://blog.kraasecurity.com/2010/03/24/what-is-social-media-insecurity/</link>
		<comments>http://blog.kraasecurity.com/2010/03/24/what-is-social-media-insecurity/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 17:30:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Entrepreneur]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Friendster]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[Online Communities]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=196</guid>
		<description><![CDATA[



Image via CrunchBase



 The trends in Social Media are heading towards more sharing of information. But sharing of information has moved beyond your circle of friends and family. Social media is becoming less social and more&#8230; well more corporate. Or more like many people shouting in a bar, you are all in close proximity, but you [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 125px; height: 34px;">
<dt class="wp-caption-dt"><a href="http://www.crunchbase.com/company/facebook"><img title="Image representing Facebook as depicted in Cru..." src="http://www.crunchbase.com/assets/images/resized/0000/4561/4561v1-max-250x250.png" alt="Image representing Facebook as depicted in Cru..." width="132" height="53" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://www.crunchbase.com/">CrunchBase</a></dd>
</dl>
</div>
</div>
<p> The trends in <strong>Social Media</strong> are heading towards more sharing of information. But sharing of information has moved beyond your circle of friends and family. <strong>Social media</strong> is becoming less social and more&#8230; well more corporate. Or more like many people shouting in a bar, you are all in close proximity, but you can&#8217;t distinguish the individual conversations, you can&#8217;t make out who people really are or who is a potential quality relationship.</p>
<p>How many random friend requests do you get now from <a title="Facebook" href="http://facebook.com/">Facebook</a>, <a title="Friendster" href="http://www.friendster.com/">Friendster</a>, <a title="MySpace" href="http://myspace.com/">MySpace</a>, <a title="LinkedIn" href="http://www.linkedin.com/">LinkedIn</a>, etc. <a title="Twitter" href="http://twitter.com/">Twitter</a> is a bit different obviously, but that’s a whole other story. Now you are also getting bombarded with corporate Fanpages, groups and other means of luring you to their sites, brands and social following. This is the erosion of your true social circle.Social Media Security is really more about Insecurity. The distribution of your information across multiple platforms used to be in a restricted circle. This can be true <strong><a title="data loss prevention" href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">data loss</a></strong>.  Now its pretty much everywhere. You can find a person&#8217;s LinkedIn profile with a generic <a title="Google" href="http://google.com/">Google</a> search. This should be restricted to the LinkedIn environment, but it’s not.With the advent of <a title="Location-based service" href="http://en.wikipedia.org/wiki/Location-based_service">location based services</a>, we will see physical insecurity based on <a title="Social media" href="http://www.wikinvest.com/concept/Social_media">social media</a> usage. A recently popular site Please Rob Me <a href="http://pleaserobme.com/">http://pleaserobme.com</a> has already begun taking advantage of the Twitter location feature. Imagine what can be done by a stalker following someone on twitter or a deranged Ex-boyfriend following you based on the events you are attending on <strong>Facebook</strong>? It’s easy to see how you can give away all your personal information without event thinking of it. Trends towards making information available will lead to Insecurity. Insecurity will lead to data breaches and compromise. Compromise will lead to lots of crying, money lost, probably lawsuits and other painful results. How do we get past this <strong>Social Media Insecurity</strong>? </p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development </p>
<p>*PGP Security</p>
<p>*FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.markevanstech.com/2010/03/17/the-seven-deadly-sins-of-social-media/">The Seven Deadly Sins of Social Media</a> (markevanstech.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.briansolis.com/2010/03/the-age-of-social-networks/">The Age of Social Networks</a> (briansolis.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.insidefacebook.com/2010/03/19/facebook-roundup-ftc-design-changes-nestle-urls-and-more/">Facebook Roundup: FTC, Design Changes, Nestlé, URLs and More</a> (insidefacebook.com)</li>
<li class="zemanta-article-ul-li"><a href="http://web2.sys-con.com/node/1335497">Cloud Computing Elasticity Drives Social Media</a> (web2.sys-con.com)</li>
<li class="zemanta-article-ul-li"><a href="http://thecustomercollective.com/TCC/52819">Use Google Analytics to Track Inbound Links from Social Media Profiles</a> (thecustomercollective.com)</li>
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2010/03/25/b2b-marketer-lessons/">13 Essential Social Media Lessons for B2B Marketers from the Masters</a> (mashable.com)</li>
<li class="zemanta-article-ul-li"><a href="http://bettercloser.com/social-media-engagement-starts-with-monitoring/">Social Media Engagement Starts with Monitoring</a> (bettercloser.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/421923ff-d8de-4ddb-a184-1b4b31afe1a4/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=421923ff-d8de-4ddb-a184-1b4b31afe1a4" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/03/24/what-is-social-media-insecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can you protect yourself on Social Media?</title>
		<link>http://blog.kraasecurity.com/2010/03/01/can-you-protect-yourself-on-social-media/</link>
		<comments>http://blog.kraasecurity.com/2010/03/01/can-you-protect-yourself-on-social-media/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 02:44:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Antivirus software]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=189</guid>
		<description><![CDATA[



Image via Wikipedia



One of the greatest challenges to privacy and security in the next several years is Social Networks and Social Media. Sites like Facebook, Twitter, LinkedIn, MySpace and others can be the downfall of valuing information. The ability to share and provide information is completely the opposite of network security requirements.  This is really [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 105px; height: 47px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Facebook.svg"><img title="Facebook, Inc." src="http://upload.wikimedia.org/wikipedia/commons/thumb/0/06/Facebook.svg/266px-Facebook.svg.png" alt="Facebook, Inc." width="89" height="26" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Facebook.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>One of the greatest challenges to privacy and security in the next several years is <strong>Social Networks</strong> and <strong>Social Media</strong>. Sites like <a title="Facebook" href="http://facebook.com/">Facebook</a>, <a class="zem_slink freebase/en/twitter" title="Twitter" rel="homepage" href="http://twitter.com/">Twitter</a>, <a title="LinkedIn" href="http://www.linkedin.com/">LinkedIn</a>, <a title="MySpace" href="http://myspace.com/">MySpace</a> and others can be the downfall of valuing information. The ability to share and provide information is completely the opposite of <strong><a title="Network security" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">network security</a></strong> requirements.  This is really encouraging people to do things that are not security conscious activities. Social media encourages:</p>
<ul>
<li>Lack of privacy</li>
<li>Encouraging information sharing</li>
<li>Giving away answers to security questions</li>
<li>Social engineering</li>
</ul>
<p>As we have seen recently, a lot of spam, <a class="zem_slink freebase/en/spyware" title="Spyware" rel="wikipedia" href="http://en.wikipedia.org/wiki/Spyware">spyware</a> and <a title="Malware" href="http://www.kraasecurity.com/managed-services/email-defense/antivirus">malware</a> is attacking social network. Just in the past week I have probably recieved a 100 requests to be my friend on Facebook from people who I do not know and funny enough, all the message have the exact same personal message. Malicious people are attracted to social networks because of the ease of gaining trust and availability of data for social engineering.  Relationship building is easier through social media which can easily lead to <strong><a title="Phishing malware" href="http://www.kraasecurity.com/managed-services/email-defense/antivirus">phishing</a></strong> attacks.</p>
<p>With these sites, people install applications without knowing what goes on in the background, and its easy to download <strong>malicious code</strong> to your computer. There are no external third party audits of these applications before the make it to your Facebook application. Your computer can be easily infected by a virus or <a title="content filtering" href="http://www.kraasecurity.com/managed-services/email-defense/content-filtering">spyware</a>.</p>
<p>What does the <strong>Social Media</strong> user to protect their information?<br />
No Personal information &#8211; This is anti-social network, but there are things you can limit about what you post. Don&#8217;t post your Birthday! Or your address or your mothers middle name or any really personal data.</p>
<p><strong>Limit who can view and contact you</strong> &#8211; Don&#8217;t let your profile be truly public, restrict to people you know for requested users.  Remember you can&#8217;t retract information you put out there. </p>
<p><strong>Don’t trust strangers</strong> &#8211; Your mother was right, don&#8217;t open the door to strangers. Limit who you accept chat or friend requests from and well as even communicate with.</p>
<p><strong>Trust no Profile</strong> &#8211; People lie, it’s sad but true. So profiles lie, they might say they went to your college or high school.  They might be interested in your groups, so don’t take anyone at their word.</p>
<p><strong>Restrict your privacy</strong> &#8211; There are some configuration setting in all the social media applications that can allow you to turn on some restrictions on your privacy. Take a minute to actually look at them. One easy example is in Facebook you can create groups that you can place friend in; you don&#8217;t want business people seeing what your friends are posting.</p>
<p><strong>Password management</strong> &#8211; An oldie but a goodie, always use a strong password and don&#8217;t share it. And change it periodically.</p>
<p><strong>Layers of protection</strong> &#8211; You should be running a <strong><a title="Firewall management" href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall">personal firewall</a></strong> and <strong>antivirus</strong> software on the machine you are viewing social networks. This will help if a malicious piece of software tries to download something to your machine. Keep your protection software up to date as well and run the patch management software on your machine, this is especially important for you Windows users.</p>
<p><strong>Child protection software</strong> &#8211; You should have some kind of <strong>child protection</strong> software running on machines where children under 13 are using. This will help with all that shady software that is out there.</p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p>*FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://seekingalpha.com/article/191290-half-of-online-adults-use-social-networks-at-least-monthly?source=feed">Half of Online Adults Use Social Networks at Least Monthly</a> (seekingalpha.com)</li>
<li class="zemanta-article-ul-li"><a href="http://arstechnica.com/business/news/2010/02/firms-worry-about-social-networks-but-not-blocking-access.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss">Firms worry about social networks, but don&#8217;t block access</a> (arstechnica.com)</li>
<li class="zemanta-article-ul-li"><a href="http://thewayoftheweb.net/2010/02/google-buzz-proves-problems-with-single-online-identities/">Google Buzz proves problems with single online identities</a> (thewayoftheweb.net)</li>
<li class="zemanta-article-ul-li"><a href="http://www.marketingvox.com/are-consumers-becoming-more-suspicious-of-social-networks-046260/?utm_campaign=rssfeed&amp;utm_source=mv&amp;utm_medium=textlink">Are Consumers Becoming More Suspicious of Social Networks?</a> (marketingvox.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.dominica-weekly.com/ramblings/seven-steps-to-safe-social-networking/">Seven Steps to Safe Social Networking</a> (dominica-weekly.com)</li>
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2010/03/25/b2b-marketer-lessons/">13 Essential Social Media Lessons for B2B Marketers from the Masters</a> (mashable.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.slideshare.net/pr2020/social-media-for-ceos-3542229">Social Media for CEOs</a> (slideshare.net)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/6e138ad0-af9e-40d2-ab77-da1094d4aa21/"><img class="zemanta-pixie-img" style="float: right; border-style: none;" src="http://img.zemanta.com/reblog_e.png?x-id=6e138ad0-af9e-40d2-ab77-da1094d4aa21" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"> <script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/03/01/can-you-protect-yourself-on-social-media/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When will Vendors provide Risk Assessments of their products?</title>
		<link>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/</link>
		<comments>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 04:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Supplier Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Systems]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[CIO.com]]></category>
		<category><![CDATA[Cross-site scripting]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Operating system]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=185</guid>
		<description><![CDATA[



Image via Wikipedia



Vendor risk assessment are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer either. [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 92px; height: 52px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg"><img title="Adobe Systems Incorporated" src="http://upload.wikimedia.org/wikipedia/en/thumb/d/dd/AdobeSystems.svg/300px-AdobeSystems.svg.png" alt="Adobe Systems Incorporated" width="97" height="65" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><a title="vendor risk assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/supplier-security-assessment"><strong>Vendor risk assessment</strong></a> are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer either. So why do we accepts buggy <a class="zem_slink freebase/en/computer_software" title="Computer software" rel="wikipedia" href="http://en.wikipedia.org/wiki/Computer_software">software</a> that is vulnerable to things like cross site scripting attacks, buffer overflows, malware and such? But we do that everyday.</p>
<p>Everything from vulnerable <a class="zem_slink freebase/en/operating_system" title="Operating system security" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">operating systems</a> such as Windows to vulnerable applications such as <a class="zem_slink freebase/en/adobe_creative_team" title="Adobe Systems" rel="homepage" href="http://www.adobe.com/">Adobe</a> and weak website such as Facebook. As stated by <a class="zem_slink" title="CIO.com" rel="homepage" href="http://www.cio.com">CIO.com</a>, &#8220;SANS and Mitre, a Bedford, Mass.-based <a class="zem_slink freebase/en/non-profit_organization" title="Non-profit organization" rel="wikipedia" href="http://en.wikipedia.org/wiki/Non-profit_organization">non-profit</a>, federally funded technology <a class="zem_slink freebase/en/research_and_development" title="Research and development" rel="wikipedia" href="http://en.wikipedia.org/wiki/Research_and_development">research and development</a> organization, today is also releasing its second annual CWE/SANS Top 25 list of the most common programming errors currently being made by software <a class="zem_slink freebase/en/software_developer" title="Software developer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Software_developer">developers</a>. The authors say the errors on the list are responsible nearly every major type of cyber attack, including the recent intrusions at Google (<a class="zem_slink freebase/en/google" title="NASDAQ: GOOG" rel="stockexchange" href="http://finance.yahoo.com/q?s=GOOG">GOOG</a>), and numerous utilities and government agencies.&#8221;  The biggest companies are culprits.</p>
<p>So what are we do to about buggy software? How do you force a <strong>vendor risk assessment</strong> on all yoru vendors? Maybe scream &#8220;I&#8217;m mad as hell and I am not going to take it anymore!&#8221;  Might feel good for a second or two, but not going to solve the almost daily patch process we have to go through for our software. <strong><a title="patch management" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">Patch management</a></strong> is a thriving sector!</p>
<p>As I see it, some theoretical things the end user can do to change the deadly cycle of poor software:</p>
<ol>
<li>Sue! I don&#8217;t know if that&#8217;s possible, but if you bought a car with bad acceleration problems (ahem Toyota) you might just sue the manufacturer if you got into an accident. What can we do that if some hacker breaks in through buggy software?</li>
<li>Stop buying from that vendor! <a class="zem_slink" title="Apple Inc." rel="geolocation" href="http://maps.google.com/maps?ll=37.33187,-122.029669&amp;spn=1.0,1.0&amp;q=37.33187,-122.029669%20%28Apple%20Inc.%29&amp;t=h">Apple</a> seems to be taking this tactic by not allowing Flash on the IPad. But can we all move away from <a class="zem_slink freebase/en/microsoft" title="Microsoft" rel="homepage" href="http://www.microsoft.com">Microsoft</a> tomorrow? Probably not.</li>
<li>Make the vendors conduct <strong><a title="application security assessment" href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">Risk Assessments</a></strong> of their products prior to release. A third party risk assessment is probably a good idea. Something with more teeth than a SAS70 type review.</li>
</ol>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p> *Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p> *FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://seekingalpha.com/article/188591-apple-vs-microsoft-making-platform-enemies-and-friends?source=feed">Apple vs. Microsoft: Making Platform Enemies and Friends</a> (seekingalpha.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/">Adobe Reader And Acrobat Get Yet Another Security Update</a> (ghacks.net)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-13860_3-10447081-56.html?part=rss&amp;subj=BeyondBinary">Microsoft investigates new Internet Explorer flaw</a> (news.cnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/developer-world/adobe-air-20-full-featured-flash-player-coming-smartphones-253&amp;a=13137035&amp;rid=5940a61e-7193-4971-a98b-6547400ef860&amp;e=5d602d8d9add939e9717afe63232605d">Google readies Flash for Android devices</a> (infoworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9162258/IBM_Vulnerabilities_fell_in_09_but_other_risks_abound?source=rss_security">IBM: Vulnerabilities fell in &#8216;09, but other risks abound</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9157558/Update_Adobe_issues_emergency_PDF_patches?source=rss_security">Update: Adobe issues emergency PDF patches</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.theregister.co.uk/2009/12/22/mass_flash_file_vulnerability/">Serious web vuln found in 8 million Flash files</a> (theregister.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/347250/Hold_Vendors_Liable_for_Buggy_Software?source=rss_dev">Hold vendors liable for buggy software, group says</a> (computerworld.com)</li>
</ul>
<p>Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="../">http://blog.kraasecurity.com</a></p>
<p><a onclick="pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
<a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall" target="_blank">Managed Firewall</a><br />
<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning" target="_blank">Managed Vulnerability Scanning</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/5940a61e-7193-4971-a98b-6547400ef860/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=5940a61e-7193-4971-a98b-6547400ef860" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is the value of a Data Breach?</title>
		<link>http://blog.kraasecurity.com/2010/01/27/what-is-the-value-of-a-data-breach/</link>
		<comments>http://blog.kraasecurity.com/2010/01/27/what-is-the-value-of-a-data-breach/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 02:33:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Citibank]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=174</guid>
		<description><![CDATA[



Image by Getty Images via Daylife



SC magazine just reported that the Ponemon Institute has determined the cost of a data breach is $204 per record. &#8220;Data breaches last year cost organizations $204 per exposed record on average, which represents an almost two percent increase over 2008, according to the fifth annual &#8220;Cost of  Data Breach&#8221; [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 160px;">
<dt class="wp-caption-dt"><a href="http://www.daylife.com/image/0fcc5b451yfWd?utm_source=zemanta&amp;utm_medium=p&amp;utm_content=0fcc5b451yfWd&amp;utm_campaign=z1"><img title="NEW YORK - MAY 20:  In this photo illustration..." src="http://cache.daylife.com/imageserve/0fcc5b451yfWd/150x100.jpg" alt="NEW YORK - MAY 20:  In this photo illustration..." width="150" height="100" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image by <a href="http://www.daylife.com/source/Getty_Images">Getty Images</a> via <a href="http://www.daylife.com/">Daylife</a></dd>
</dl>
</div>
</div>
<p>SC magazine just reported that the <a class="zem_slink" title="Ponemon Institute" rel="homepage" href="http://www.ponemon.org/">Ponemon Institute</a> has determined the cost of a <a title="Data breach, data loss prevention" href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">data breach </a>is $204 per record. &#8220;Data breaches last year cost organizations $204 per exposed record on average, which represents an almost two percent increase over 2008, according to the fifth annual &#8220;<strong>Cost of  Data Breach</strong>&#8221; study released on Monday by the Ponemon Institute&#8230;  The study, which examined the experiences of 45 U.S. companies that suffered breaches last year, also found that the number of data breaches that were caused by malicious attacks and botnets doubled from 12 percent in 2008 to 24 percent  in 2009. In addition, data breaches caused by malicious attacks cost organizations 30 to 40 percent more on average than those caused by human negligence or by IT system glitches.&#8221; There are a number of ways to protect your data in transit such as <a title="PGP Encryption, Email Encryption" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products"><strong><span style="color: #888888;">PGP Encryption</span></strong> </a>but when the companies looses data, there isnt much the end user can do to protect themselves.</p>
<p>Thats a lot of money. If we look at the data breach of Heartland, which was over 100 million records, that, well let me do the math, may take a minute. Its $20,400,000,000. Thats a lot of money. Condidering I was a shopper mostlikely of Heartland, I do not recall getting a check from anyone for $204. I will not hold my breath for that. We all asked if the retailers like Heartland and <a class="zem_slink freebase/en/tj_maxx" title="T.J. Maxx" rel="homepage" href="http://www.tjmaxx.com/">TJ Max</a> had a <a title="PCI Audit" href="http://www.kraasecurity.com/compliance/PCI-Assessment">PCI Audit</a> done. Would this have protected our information?</p>
<p>So far, I am pretty sure I recieved a letter offering me free 2 year credit monitoring from Chase, <a class="zem_slink freebase/en/citibank" title="Citibank" rel="homepage" href="http://www.citibank.com/">Citibank</a>, Bank of America and Countrywide because thet lost my records. I am waiting for my check for $204 from each of those companies. Also, over the past few years I have had to have my <a class="zem_slink freebase/en/credit_card" title="Credit card" rel="wikipedia" href="http://en.wikipedia.org/wiki/Credit_card">credit cards</a> replaced with Chase, American Express, and several Visa versions. So I am still waiting for those $204 checks. Maybe in total I am owed about 9x$204=$1,836.  That will be a nice check when I get it.</p>
<h2>Security Requirements</h2>
<p>So what can a company do to help reduce these data breaches? The easy answers, yet not implemented, include:<br />
1) <a title="Encryption, PGP Encryption" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">Encryption</a> of <a title="data backup" href="http://www.kraasecurity.com/products/yotta280">back-up data </a>and tapes<br />
2) Conduct yearly <a title="Vulnerability Assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">Vulnerability Assessments </a><br />
3) Conduct Quarterly or Monthly <a title="Vulnerability Scanning" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">Vulnerability Scanning</a><br />
4) Implement a <a title="Data loss prevention " href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">Data loss prevention solution</a><br />
5) Go through a <a title="PCI Audit" href="http://www.kraasecurity.com/compliance/PCI-Assessment">PCI Audit </a>or <a title="HIPAA Assessment" href="http://www.kraasecurity.com/compliance/hipaa-assessment">HIPAA Security Assessment </a>yearly</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2256886/breach-costs-continue-rise">Data breach costs continue to rise</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-27080_3-10440220-245.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20">Survey: Data breaches from malicious attacks doubled last year</a> (news.cnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2256724/breach-numbers-fall-while-costs">Breach numbers fall while costs rise Ponemon study finds</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://it.slashdot.org/story/10/03/15/1227223/Humans-Continue-To-Be-Weak-Link-In-Data-Security?from=rss">Humans Continue To Be &#8216;Weak Link&#8217; In Data Security</a> (it.slashdot.org)</li>
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/01/cost-of-data-breach-204-per-record.html">Cost of a Data Breach &#8211; $204 per record</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://online.wsj.com/article/SB10001424052748704541004575011113352790040.html">Private Sector Keeps Mum on Cyber Attacks</a> (online.wsj.com)</li>
</ul>
<p>Regards<br />
Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></p>
<p><a onclick="pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
<a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall" target="_blank">Managed Firewall</a><br />
<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning" target="_blank">Managed Vulnerability Scanning</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/f1ed6c34-1f2a-4642-b40c-ac12e03f3b45/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=f1ed6c34-1f2a-4642-b40c-ac12e03f3b45" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/01/27/what-is-the-value-of-a-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ponemon Institute Cyber megatrends &#8211; Some Additions Needed</title>
		<link>http://blog.kraasecurity.com/2009/11/28/ponemon-institute-cyber-megratrends-some-additions-needed/</link>
		<comments>http://blog.kraasecurity.com/2009/11/28/ponemon-institute-cyber-megratrends-some-additions-needed/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 00:17:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Could Computing]]></category>
		<category><![CDATA[Outsourcing]]></category>
		<category><![CDATA[Unstructured Data]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[Cloud computing]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=170</guid>
		<description><![CDATA[Ponemon Institute recently released their  Cyber megratrends as listed below. While I agree with these I think there were a couple that could easily be added to the list. First, I would either add or modify Web 2.0 into Web 3.0. Lets look to what is going to happen versus what is happening. Incremental change [...]]]></description>
			<content:encoded><![CDATA[<p>Ponemon Institute recently released their  Cyber megratrends as listed below. While I agree with these I think there were a couple that could easily be added to the list. First, I would either add or modify Web 2.0 into Web 3.0. Lets look to what is going to happen versus what is happening. Incremental change may not be the trend.  Secondly, I suggest adding <a href="http://www.kraasecurity.com/consulting-services/network-solutions/supplier-security-assessment" target="_blank">Vendor Risk Management</a>. The vendor does not have to be offshore to pose a problem. Vendors are so integrated into companies and business processes that they are like an employee but are not subjected to the same <a href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">Network Security Assessment</a> requirements in many cases.</p>
<p>Its a difficult thing to try and forecast. The good thing about it is that no one really remembers your forecaste anyway.</p>
<p>Regards<br />
Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p style="background: none transparent scroll repeat 0% 0%;"><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></p>
<p style="background: #c0c0c0;"><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
Managed Security Services<br />
<a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall" target="_blank">Managed Firewall</a><br />
<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning" target="_blank">Managed Vulnerability Scanning</a></p>
<p>++++++++++++++++++++++++++++++++++++++++++++++++<br />
<strong>Cyber Security Mega Trends Study<br />
</strong>Prepared by Dr. Larry Ponemon, November 18, 2009</p>
<p>Related articles by Zemanta</p>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.readwriteweb.com/archives/top_web_trends_security_risks.php">Think Tank Study Shows Top Web Trends Are Security Risks</a> (readwriteweb.com)</li>
<li class="zemanta-article-ul-li"><a href="http://myventurepad.com/MVP/78391">The cloud is a powder keg</a> (myventurepad.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/b7fe4b47-d582-49fc-8e62-74349ac6b73d/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=b7fe4b47-d582-49fc-8e62-74349ac6b73d" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/11/28/ponemon-institute-cyber-megratrends-some-additions-needed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Vendor Compromised Healthcare Records</title>
		<link>http://blog.kraasecurity.com/2009/11/12/hipaa-vendor-compromised-healthcare-records/</link>
		<comments>http://blog.kraasecurity.com/2009/11/12/hipaa-vendor-compromised-healthcare-records/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 13:46:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Aetna]]></category>
		<category><![CDATA[Health care]]></category>
		<category><![CDATA[Health insurance]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=167</guid>
		<description><![CDATA[This is story that is several months old, but as I came across it, i thought it would make a good point.  A vendor handling healthcare records has lost social security numbers of people in March of 2009. In this case, Health insurer Aetna, Inc., is reportedly providing 65,000 individuals with free credit monitoring [...]]]></description>
			<content:encoded><![CDATA[<p>This is story that is several months old, but as I came across it, i thought it would make a good point.  A vendor handling healthcare records has lost social security numbers of people in March of 2009. In this case, Health insurer Aetna, Inc., is reportedly providing 65,000 individuals with free credit monitoring for a year after its job application Web site was breached, the Associated Press has reported.</p>
<p>The Web site, which was maintained by an outside vendor, had Social security numbers of current and past employees and individuals who received job offers from the insurer, the AP reported.</p>
<p>The site reportedly held e-mail addresses for about 450,000 individuals who had applied for jobs or submitted resumes to the company and were waiting to be notified about job openings. Spokeswoman Cynthia Michener said Aetna doesn&#8217;t know how many were copied, but the site has been disabled and is undergoing a &#8220;thorough forensic review&#8221; or you can say <a href="http://www.kraasecurity.com/consulting-services/network-solutions">network security audit</a> by an outside company.</p>
<p>So here we have a health insurer compromising personal data. People already recieve so much spam email that their real email is suspect. If your provider Aeata seems to be sending ligitimate emails to you, that can get confusing.</p>
<p>As noted in the article &#8220;This is not the first time the Hartford, Conn.-based insurer has had to provide free credit monitoring services. In April 2006, Aetna notified approximately 38,000 members that an employee&#8217;s laptop computer containing certain personal member information was stolen from a car in a public parking lot.&#8221;</p>
<p>If a compromise occurs once, you would think that a lot of new <a href="http://www.kraasecurity.com/">HIPAA data security</a> protections would be put in place. But as we see in almost all industries, its very  hard for a company to learn from its mistakes. Maybe there will not be a third time after this second breach.</p>
<p>Gary Bahadur<br />
<a href="http://www.blogger.com/mail%20to:baha@kraasecurity.com">baha@kraasecurity.com</a><br />
<a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
Managed Security Services<br />
Managed Firewall<br />
Managed Vulnerability Scanning</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/d25ea83e-d17c-440a-b00c-2001ab64b257/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=d25ea83e-d17c-440a-b00c-2001ab64b257" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/11/12/hipaa-vendor-compromised-healthcare-records/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Compliance Data Breach with a Foreign Supplier</title>
		<link>http://blog.kraasecurity.com/2009/11/03/hipaa-compliance-data-breach-with-a-foreign-supplier/</link>
		<comments>http://blog.kraasecurity.com/2009/11/03/hipaa-compliance-data-breach-with-a-foreign-supplier/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 13:14:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Supplier]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=160</guid>
		<description><![CDATA[Recently, the Economic Times Report in India discussed a successful &#8220;Sting operation by a UK agency in which some health related data was bought from a medical transcription company&#8221; . What this means is all that perosnal and HIPAA confidential data that was being transfered for transcription got stolen in the most likely scenario.  There [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, the Economic Times Report in India discussed a successful &#8220;Sting operation by a UK agency in which some health related data was bought from a <a href="http://www.bloggernews.net/122786">medical transcription company</a>&#8221; . What this means is all that perosnal and HIPAA confidential data that was being transfered for transcription got stolen in the most likely scenario.  There have been few stories of this type of Data Breach so far. The Suppliers to US companies have not made the headlines but this might be just the begining fo that wave. The two components of HIPAA Security are Logical and Physical Security. Remote partners can easily breach your logical security controls.</p>
<p>Is there any real view that the US can export the security laws such as HIPAA Security to all parts of the world that handle US customer data? How do you monitor the activities of your suppliers once the data has left yoru network? In the US, a company can control all the security devices such as Firewalls, Intrusion Detection Systems, Antivirus on Servers and Patch Management of servers hosting confidenial data. There are all parts of most security regulations including PCI, SOX, GLBA and more. But the endpoint of security has left these shores and resides in India, China, South America, Vietname and anywhere else you have a supplier.</p>
<p>As your data now resides in a foreign country, what are the reporting requirements of a breach? <a href="http://www.kraasecurity.com/compliance/hipaa">HIPAA security policy</a> has timeframes, reporting requirements and penalties. The only real penalty a company oversea may face is loss of the contract. Few governments are upt o enforcing security rules outside of actual hacker activity.</p>
<p>So what are some steps you can take to implement Supplier Security?<br />
1) Conduct a Vulnerability Assessment of your connectivity to your Suppliers&#8217; networks<br />
2) Define process and policy controls that the Supplier has to have in place in order to hold your data<br />
3) Assign risk ratings to all data the Supplier handles<br />
4) Conduct an risk assessement of the impact of losing the data<br />
5) Develop a Incident Response plan for the Supplier losing your data<br />
6) Asses the supplier security procedures on a yearly basis</p>
<p>Gary Bahadur<br />
<a href="http://www.kraasecurity.com">http://www.kraasecurity.com</a><br />
<a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a><br />
<a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
*Managed Security Services<br />
*Vulnerability Management<br />
*Compliance &amp; Policy Development<br />
*PGP Security</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/11/03/hipaa-compliance-data-breach-with-a-foreign-supplier/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPhone Apps Every Road Warrior Entrepreneur Needs</title>
		<link>http://blog.kraasecurity.com/2009/10/22/iphone-apps-every-road-warrior-entrepreneur-needs/</link>
		<comments>http://blog.kraasecurity.com/2009/10/22/iphone-apps-every-road-warrior-entrepreneur-needs/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 09:36:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Could Computing]]></category>
		<category><![CDATA[Entrepreneur]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[airport delay]]></category>
		<category><![CDATA[AroundMe]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[FlightAware]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Calendar]]></category>
		<category><![CDATA[Google Map]]></category>
		<category><![CDATA[Google Maps]]></category>
		<category><![CDATA[network solutions]]></category>
		<category><![CDATA[reQall]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=124</guid>
		<description><![CDATA[The Blackberry has been the mainstay of the business world for years. But as we know, the IPhone is eating away at market share. There are over 75,000 apps for the IPhone now and growing steadily. For those who have Blackberry Thumb, you can probably look forward to IPhone Index Finger at some point in [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.blackberry.com/">Blackberry</a> has been the mainstay of the business world for years. But as we know, the IPhone is eating away at market share. There are over 75,000 apps for the <a href="http://www.apple.com/iphone/">IPhone</a> now and growing steadily. For those who have Blackberry Thumb, you can probably look forward to IPhone Index Finger at some point in the future as you switch away from the Blackberry.</p>
<p>Why should you switch from the Blackberry? Well there may not be a good reason. The Blackberry has a number of apps and it is secure, it has <strong><a title="pgp encryption" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">encryption</a></strong> and has been beaten up on the security front like <a href="http://www.kraasecurity.com/consulting-services/network-solutions">network security assessment</a> and application security testing. It’s ingrained in businesses and Blackberry Enterprise Server is well known to many IT administrators.</p>
<p>The Entrepreneur can use both devices. Let’s assume there are at least some people using the IPhone, what apps should they have in their toolkit?  Of the thousands of apps, how can you pick a few that would be beneficial to the Entrepreneur Road Warrior? Well the way I picked them is through word of mouth , that are of benefit to me and comes with <a href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">network security assessment</a> tools. I travel, work in my car, have meetings at all times of day, I am away from the office for days or weeks.</p>
<p>Take these with a grain of salt and do not send any flame emails. But please send in the apps that you think should be shared with the world or at least readers of this Blog.</p>
<p><strong>Urban Spoon </strong></p>
<p>First up is Urban Spoon. You are thinking, well that’s not some kind of spreadsheet or financial app. What is the business purpose? The lifeblood of the Entrepreneur is networking , <a href="http://www.kraasecurity.com/">managed security services</a>, <a href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">application security risk assessment</a> and deal making. Where deal making most of the time involves some kind of meal. Urban Spoon can find you restaurants by cuisine, by neighborhood, by cost, by distance. Everything you need for a meeting is the most random city.</p>
<p style="text-align: center;"><img class="size-medium wp-image-125 aligncenter" title="urbanspoon1" src="http://blog.kraasecurity.com/wp-content/uploads/2009/10/urbanspoon1-159x300.jpg" alt="urbanspoon1" width="159" height="300" /></p>
<p><strong><a class="zem_slink" title="AroundMe" rel="homepage" href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewSoftware?id=290051590&amp;mt=8">AroundMe</a></strong></p>
<p>In the same vein as Urban Spoon, is AroundMe . Say you are on your way to an important lunch you have setup with a restaurant you found on Urban Spoon but you are almost out of gas. Use AroundMe to find the closed gas station. Or if you need cash to pay for that gas because your Amex Card has been cancelled, find the closest bank.</p>
<p style="text-align: center;"><img class="size-full wp-image-126 aligncenter" title="aroundme" src="http://blog.kraasecurity.com/wp-content/uploads/2009/10/aroundme.jpg" alt="aroundme" width="200" height="200" /></p>
<p style="text-align: center;"> </p>
<p><strong>GoogleMaps</strong></p>
<p>Well this is pretty obvious. But when you are traveling and maybe forgot to bring your Garmin GPS and do not feel like paying the rental company an extra $11.99 a day to rent their <a href="http://www.apple.com/iphone/iphone-3gs/maps-compass.html">GPS</a> , this is just as good.</p>
<p><strong><a class="zem_slink" title="reQall" rel="homepage" href="http://www.reqall.com/">ReQall</a></strong></p>
<p>This is a pretty useful app. The developers were one of the www.TiE.org Top 50 companies this year at TiECon. The app captures your voice, translates it to text, organizes your calendar based on your voice messages, integrates into Outlook or <a class="zem_slink freebase/en/google_calendar" title="Google Calendar" rel="homepage" href="http://google.com/calendar">Google Calendar</a> and provides memory assistance. It’s great when you have no pen or driving in a car or need a memory reminder.</p>
<p style="text-align: center;"><img class="size-medium wp-image-127 aligncenter" title="reqall" src="http://blog.kraasecurity.com/wp-content/uploads/2009/10/reqall-169x300.jpg" alt="reqall" width="169" height="300" /></p>
<p><strong><a class="zem_slink freebase/en/flightaware" title="FlightAware" rel="homepage" href="http://flightaware.com/">FlightAware</a> </strong></p>
<p>For the true Road Warrior, there is no road, there is the sky. So when you are rushing to the airport or think you need to rush to the airport, track down what is going on with your flight. Check out FlightAware to get an update and help you plan that trip to the airport.</p>
<p style="text-align: center;"><img class="size-medium wp-image-128 aligncenter" title="flightaware" src="http://blog.kraasecurity.com/wp-content/uploads/2009/10/flightaware-164x300.jpg" alt="flightaware" width="164" height="300" /></p>
<p style="text-align: left;"><strong><a class="zem_slink" title="TweetDeck" rel="homepage" href="http://tweetdeck.com/iphone/">TweetDeck</a></strong></p>
<p style="text-align: left;">Social Media, the latest buzz word, actually has some teeth. Small companies and the Entrepreneur have to be connected to the work whether you like it or not.  <a class="zem_slink freebase/en/twitter" title="Twitter" rel="homepage" href="http://twitter.com/">Twitter</a> is a way of life these days even if people seem to be twittering their lives away. How do you tell your followers that you are stuck in an airport in Baltimore? Try using TweetDeck.</p>
<p style="text-align: center;"><img class="size-medium wp-image-129 aligncenter" title="tweetdeck" src="http://blog.kraasecurity.com/wp-content/uploads/2009/10/tweetdeck-161x300.jpg" alt="tweetdeck" width="161" height="300" /></p>
<p>These Apps don’t seem very business-like, but the Entrepreneur is practical, cheap, requires <a href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">network security audit</a> tools and has to get things done today . These help you achieve your million tasks on a timely basis.</p>
<p>Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com">http://www.kraasecurity.com</a></p>
<p><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></p>
<p><span style="color: #ff0000;">*Managed Security Services</span></p>
<p><span style="color: #ff0000;">*Vulnerability Management</span></p>
<p><span style="color: #ff0000;">*Compliance &amp; Policy Development</span></p>
<p><span style="color: #ff0000;">*PGP Security</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://techcrunch.com/2010/03/23/urbanspoon-half-billion-shakes/">Urbanspoon: Half A Billion Shakes And Counting</a> (techcrunch.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.computerworld.com/15732/will_the_ipad_make_a_great_car_gadget?source=rss_weintraub">Will the iPad make a great car gadget?</a> (blogs.computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://scienceblogs.com/terrasig/2009/12/what_are_your_favorite_iphone.php">What are your favorite iPhone apps?</a> (scienceblogs.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.lenestrada.com/2009/05/09/my-iphone-apps/">My iPhone Apps</a> (lenestrada.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/c11b7e79-5319-48b5-aa18-9890ccf96cfb/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=c11b7e79-5319-48b5-aa18-9890ccf96cfb" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/10/22/iphone-apps-every-road-warrior-entrepreneur-needs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Devaluation Through Phishing</title>
		<link>http://blog.kraasecurity.com/2009/09/25/information-devaluation-through-phishing/</link>
		<comments>http://blog.kraasecurity.com/2009/09/25/information-devaluation-through-phishing/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 20:55:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=121</guid>
		<description><![CDATA[



Image via Wikipedia



Information Devaluation Through Phishing
The value of information has been decreasing over time. How do you see this isn the real world? There are two ways, one can be seen from the user perspective and the other from the attacker/bad guy perspective.
From a user point of view, the most obvious method to see information [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 96px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Facebook.svg"><img title="Facebook, Inc." src="http://upload.wikimedia.org/wikipedia/commons/thumb/0/06/Facebook.svg/266px-Facebook.svg.png" alt="Facebook, Inc." width="86" height="36" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Facebook.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<h2>Information Devaluation Through Phishing</h2>
<p>The value of information has been decreasing over time. How do you see this isn the real world? There are two ways, one can be seen from the user perspective and the other from the attacker/bad guy perspective.</p>
<p>From a user point of view, the most obvious method to see information devaluation is <a href="http://www.facebook.com">Facebook</a>, <a href="http://www.twitter.com">Twitter</a>, <a href="http://www.myspace.com">MySpace</a>, <a href="http://www.linkedin.com">Linkedin</a> etc. These may be seen as good ways to keep in contact, but look at all the personal data stored in these sites. Enough to authenticate to your bank account with such pieces of data as Name of Dog, Elementary School, Parents Lastname. Everything for secret question authentication. There was just a theft from a bank (<a href="http://www.networkworld.com/news/2009/092409-construction-firm-sues-after-588000.html">http://www.networkworld.com/news/2009/092409-construction-firm-sues-after-588000.html</a>) where the challenge questions were successfully answered.There are many <a href="http://www.kraasecurity.com/consulting-services/network-solutions">Network security assessment</a> tools to prevent such  phishing ways to get the answer to these challenge questions.</p>
<p>The attackers are focusing Phishing efforts on Twitter and Facebook much more these days. Its pretty obvious why, so much information is available here. KRAA Security a <a href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">Network security audit</a> tool provider twitters, but we try to keep personal things off there. But many people lives their lives on twitter so much, its a mind boggling concept.</p>
<p>The Washington post just had an article where the list Facebook as the top phished site (<a href="http://voices.washingtonpost.com/securityfix/2009/04/facebook_among_top_phished_web.html">http://voices.washingtonpost.com/securityfix/2009/04/facebook_among_top_phished_web.html</a>). Part of this is the information people post and the Applications developed for it have many ways of phishing your information. Thus a <a href="http://www.kraasecurity.com/">Information security risk assessment</a> is a necessity.</p>
<p>So is there is a solution the phishing problem in Social Media? Probably a <a href="http://www.kraasecurity.com/freewebsitetest">security penetration test</a> for such websites. Even though the phishing problem will probably get such more extensive as Social Media expands, takes over more aspects of our lives and invades every information dissemination media. Doomed I say.</p>
<p>This was a cheerful post.</p>
<p>Gary Bahadur</p>
<p><a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p>*<a href="http://www.kraasecurity.com/managed-services/user-defense">Managed Security Services</a></p>
<p>*<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning">Vulnerability Management</a></p>
<p>*<a href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">PGP Security</a></p>
<p>*<a href="http://www.kraasecurity.com">FREE Website Security Test</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/359ec324-8ddc-4ec6-9b2e-cc633e4a3c18/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=359ec324-8ddc-4ec6-9b2e-cc633e4a3c18" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/09/25/information-devaluation-through-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FTC&#8217;s Additional Rules for HIPAA Security</title>
		<link>http://blog.kraasecurity.com/2009/08/23/additonal-rules-for-hipaa-security/</link>
		<comments>http://blog.kraasecurity.com/2009/08/23/additonal-rules-for-hipaa-security/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 20:24:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Government Security]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Health care]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[security rule]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=114</guid>
		<description><![CDATA[FTC&#8217;s Additonal Rules for HIPAA Security
The Federal Trade Commission (FTC) recently issued a rule which gives more scope to the data breach notification rules as part of the Health Insurance Portability and Accountability Act (HIPAA). The addition targets companies that provide health info in an online storage facitlity. Things like Google Health or Healthvault would [...]]]></description>
			<content:encoded><![CDATA[<h1>FTC&#8217;s Additonal Rules for HIPAA Security</h1>
<p><img src="http://blog.kraasecurity.com/images/hipaa.jpg" alt="Hipaa graphic" width="57" height="94" />The Federal Trade Commission (FTC) recently issued a rule which gives more scope to the data breach notification rules as part of the <strong>Health Insurance Portability and Accountability Act (HIPAA)</strong>. The addition targets companies that provide health info in an online storage facitlity. Things like Google Health or Healthvault would fall under this category.</p>
<p>This seems like it should be an obvious thing to do. Why would you let any entity keep your health information without following strict regulatory requirements?  It is definitely a good thing to force companies that keep your health information to notify consumers following a<a href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment" target="_blank"> data security breach </a>if the breach involves more than 500 people or even 5 people. The question is how do you track down all these companies that store health information and force the the company notify customers? How do you know when a smaller companay has lost information? We still struggle with this question for the hospitals and healthcare organizations that currently have to comply with the HIPAA regulations or the<a href="http://www.kraasecurity.com/compliance/hipaa"> Hipaa Security Rule</a>. CVS recently had to pay $2.5 million in fines. I wonder what that is in comparison to the cost to consumers who have problems with their data being stolen. (I wouldn&#8217;t use the term &#8220;lost&#8221;)</p>
<p>Part of the changes coming from the FTC is the utilization of mobile devices that capture, use, transmit and store data. What are the <a href="http://www.kraasecurity.com/">hospital security</a> requirements of these devices? Does a mobile hand scanner or a mobile device that stores info have to have a built in firewall and antivirus as would a laptop? The only real way to deal with this is to conduct <a href="http://www.kraasecurity.com/compliance/hipaa">Hipaa Risk Assessment</a> but how many companies actually do it properly?</p>
<p>Have you seen the list of breaches on <a href="http://www.privacyrights.org" target="_blank">Privacyrights.org</a>? I like this recent one in particular. You cant find such a list on the FTC site.</p>
<p><em>&#8220; July 31, 2009 Jackson Memorial Hospital: (Miami, FL) A Miami man was charged with buying confidential patient records from a Jackson Memorial Hospital employee over the past two years, and selling them to a lawyer suspected of soliciting the patients to file personal-injury claims.&#8221;</em></p>
<p>Is every company required to do <a href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">network security assessment</a> and register their device if it captures, uses, transmits any kind of health information? Is any website that does the same required to register with the FTC?  But I wonder if you had such as database and hackers got into it, how much more trouble would we be in? Check out our <a href="http://www.kraasecurity.com/HIPAA-Top-5" target="_blank">HIPAA Top 5 Steps </a>to Compliance for some fun reading.</p>
<p>I do not think I came to any real conclusions with this post. Isn&#8217;t blogging wonderful?Gary Bahadur</p>
<p>Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com">http://www.kraasecurity.com</a><br />
<a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a><br />
<a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
Miami, Fl</p>
<p>*Managed Security Services<br />
*Vulnerability Management<br />
*Compliance &amp; Policy Development<br />
*PGP Security<br />
*Website Security Assessment</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/08/23/additonal-rules-for-hipaa-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Credit Card Theft Put Miami on the Map</title>
		<link>http://blog.kraasecurity.com/2009/08/19/credit-card-theft/</link>
		<comments>http://blog.kraasecurity.com/2009/08/19/credit-card-theft/#comments</comments>
		<pubDate>Wed, 19 Aug 2009 15:37:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[credit card theft]]></category>
		<category><![CDATA[Debit card]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Hannaford Bros. Co.]]></category>
		<category><![CDATA[Heartland Payment Systems]]></category>
		<category><![CDATA[Miami]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Social Security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=111</guid>
		<description><![CDATA[Miami is a fun place to live and work (there are actually people who work here). Its a great vacation spot, people enjoy the nightlife and now we have something else to crow about. The largest credit theft ring was based here!
According to Bloomberg, &#8220;Albert Gonzalez, a 28-year-old Miami resident, and two hackers living “in [...]]]></description>
			<content:encoded><![CDATA[<p>Miami is a fun place to live and work (there are actually people who work here). Its a great vacation spot, people enjoy the nightlife and now we have something else to crow about. The largest credit theft ring was based here!</p>
<p>According to Bloomberg, &#8220;Albert Gonzalez, a 28-year-old Miami resident, and two hackers living “in or near Russia” were indicted yesterday by a federal grand jury in Newark, New Jersey, for stealing data from <a href="/apps/quote?ticker=HPY%3AUS">Heartland Payment Systems Inc.</a>, <a href="/apps/quote?ticker=857724Q%3AUS">7-Eleven Inc.</a>, Delhaize Group’s Hannaford Brothers Co. and two unidentified national retailers.&#8221;</p>
<p>It always amazes me when really smart computer folks insist on hacking from the US. Why not just head down the the Caribbean and hack from there, let likely to get caught.</p>
<p>My question about this is whats the value of regulations such as PCI or HIPAA.  A <a href="http://www.kraasecurity.com/compliance/pci">PCI Security Audit </a> and <a href="http://www.kraasecurity.com/compliance/hipaa">Hipaa Security policy</a> are supposed to prevent this type of thing when the companies being hacked usually come out after the fact and say they were compliant?</p>
<p>Privacyrights.org has this list of breaches in the month of August alone. I wonder what the compliance or <a href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">network security audit</a> was like for these companies? I dont suppose there really is a good answer to what to do about compliant companies getting breached. They will just keep giving you a year of free credit monitoring I guess.</p>
<table style="width: 100%;" border="1" cellspacing="0" cellpadding="2" align="center">
<tbody>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Aug. 1, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Williams Cos. Inc.<br />
(Tulsa, OK)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">A laptop containing personal and compensation information for more than 4,400 current and former employees was stolen from a worker&#8217;s vehicle. The computer had names, birth dates, Social Security numbers and compensation data for every Williams employee since Jan. 1, 2007.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">4,400</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Aug. 3, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">National Finance Center<br />
(Washington DC)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">An employee with the National Finance Center mistakenly sent an Excel spreadsheet containing the employees&#8217; personal information to a co-worker via e-mail in an unencrypted form. The names and Social Security numbers of at least 27,000 Commerce Department employees were exposed.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">27,000</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Aug. 4, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">New Hampshire Department of Corrections<br />
(Laconia,NH)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">A 64-page list containing the names and Social Security numbers of about 1,000 employees of the state Department of Corrections ended up under the mattress of a minimum security prisoner. The prison contracts with vendors to shred documents and investigators are trying to find out why documents were not destroyed.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">1,000</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" height="197" valign="top">Aug. 11, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Bank of America Corp.<br />
(Charlotte, NC)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Charlotte-based BofA (NYSE:BAC) and Citigroup (NYSE:C) each recently issued replacement cards to consumers, telling them that their account numbers may have been compromised. Account information from certain Bank of America debit cards may have been compromised at an undisclosed third-party location. Bank officials are not certain if this is a new breach or a previously disclosed one.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Unknown</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" height="217" valign="top">Aug. 11, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Citigroup Inc.<br />
(New York City, NY)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Citigroup (NYSE:C) each recently issued replacement cards to consumers, telling them that their account numbers may have been compromised. Citigroup told credit-card customers in Massachusetts “your account number may have been illegally obtained as a result of a merchant database compromise and could be at risk for unauthorized use.&#8221; Bank officials are not certain if this is a new breach or a previously disclosed one.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Unknown</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Aug. 11, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">University of California-Berkeley School of Journalism<br />
(Berkeley, CA)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Campus officials discovered during a computer security check that a hacker had gained access to the journalism school&#8217;s primary Web server. The server contained much of the same material visible on the public face of the Web site. However, the server also contained a database with Social Security numbers and/or dates of birth belonging to 493 individuals who applied for admission to the journalism school between September 2007 and May 2009.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">493</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Aug. 13, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">National Guard Bureau<br />
(Arlington, VA)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">An Army contractor had a laptop stolen containing personal information on 131,000 soldiers. on the stolen laptop contained personal information on soldiers enrolled in the Army National Guard Bonus and Incentives Program. The data includes names, Social Security numbers, incentive payment amounts and payment dates.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">131,000</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Aug. 14, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">American Express<br />
(New York, NY)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Some American Express card members&#8217; accounts may have been compromised by an employee&#8217;s recent theft of data. The former employee has been arrested and the company is investigating how the data was obtained. American Express declined to disclose any more details about the incident. The company has put additional fraud monitoring and protection controls on the accounts at issue.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Unknown</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" height="228" valign="top">Aug. 14, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Calhoun Area Career Center<br />
(Battle Creek, MI)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Personal information from 455 students at Calhoun Area Career Center during the 2005-2006 school year was available online for more than three years. The information included names, Social Security numbers, 2006 addresses and telephone numbers, birth dates and school information. There were about 1,000 students at the career center during that time, but an investigation by the Calhoun County Intermediate School district found that information for 455 students was available.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">455</td>
</tr>
<tr>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Aug. 15, 2009</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">Northern Kentucky University<br />
(Highland Heights, KY)</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">A Northern Kentucky University employee&#8217;s laptop computer &#8211; which contained personal information about some current and former students &#8212; was stolen from a restricted area. The personal information stored on the employee&#8217;s computer included Social Security numbers of at least 200 current and former students.</td>
<td style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-decoration: none; color: #000000; font-weight: normal;" valign="top">200</td>
</tr>
</tbody>
</table>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p>*FREE Website Security Test</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/35eba444-2f1a-45f5-96c1-29393cdf719c/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=35eba444-2f1a-45f5-96c1-29393cdf719c" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/08/19/credit-card-theft/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Stolen laptop with employee information- yet again</title>
		<link>http://blog.kraasecurity.com/2009/08/07/stolen-laptop/</link>
		<comments>http://blog.kraasecurity.com/2009/08/07/stolen-laptop/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 22:53:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[American International Group]]></category>
		<category><![CDATA[Consultants]]></category>
		<category><![CDATA[HSBC]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=106</guid>
		<description><![CDATA[Stolen laptop with employee information- yet again
The Associated Press reported that a Williams Cos. Inc. laptop containing personal and compensation information was stopen from a workers vehicle. The laptop had over 4,400 current and former employees records. Information like names, birth dates, Social Security numbers and compensation data was on it. How many times have [...]]]></description>
			<content:encoded><![CDATA[<h1>Stolen laptop with employee information- yet again</h1>
<p>The <a class="zem_slink freebase/guid/9202a8c04000641f800000000005ebe2" title="Associated Press" rel="homepage" href="http://www.ap.org/">Associated Press</a> reported that a <a class="zem_slink freebase/guid/9202a8c04000641f80000000007d954b" title="Williams Companies" rel="homepage" href="http://www.williams.com/">Williams Cos.</a> Inc. laptop containing personal and compensation information was stopen from a workers vehicle. The laptop had over 4,400 current and former employees records. Information like names, birth dates, <a class="zem_slink freebase/guid/9202a8c04000641f80000000000600c3" title="Social Security number" rel="wikipedia" href="http://en.wikipedia.org/wiki/Social_Security_number">Social Security numbers</a> and compensation <a class="zem_slink freebase/guid/9202a8c04000641f8000000000011b16" title="Data" rel="wikipedia" href="http://en.wikipedia.org/wiki/Data">data</a> was on it. How many times have wee seen this story?</p>
<p>They said the laptop was password protected. Well then lets not worry eh? A password, run for Ze Hillz! They did not say whether other security measures like <a href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">application security risk assessment</a> and <a href="http://www.kraasecurity.com/consulting-services/network-solutions">network security audit</a> tools were used in place other than the <a class="zem_slink freebase/en/pretty_good_privacy" title="Pretty Good Privacy" rel="wikipedia" href="http://en.wikipedia.org/wiki/Pretty_Good_Privacy">PGP</a> Whole Disk encryption , or of any kind of remote wiping utility was in place or even if a <a class="zem_slink freebase/en/hard_disk" title="Hard disk drive" rel="wikipedia" href="http://en.wikipedia.org/wiki/Hard_disk_drive">hard disk</a> password was used. The people with stolen data can only hope this might be the case.</p>
<p>So not we have the hoke pokey dance of checking credit, getting free one year membership to <a class="zem_slink freebase/guid/9202a8c04000641f80000000048544dc" title="Credit report monitoring" rel="wikipedia" href="http://en.wikipedia.org/wiki/Credit_report_monitoring">credit monitoring</a>, buring down the barn now that the horse was stolen, all that good stuff.</p>
<p>Here is a list fo some recent thefts</p>
<table border="0">
<tbody>
<tr>
<th style="text-align: center;">records</th>
<th style="text-align: center;">date</th>
<th style="text-align: center;">organizations</th>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2260-email-containing-names-and-social-security-numbers-of-1-084-accidentally-sent-to-co-workers">1,084</a></td>
<td style="text-align: center; width: 70px;">2009-08-06</td>
<td style="font-size: 11px;">Colorado Department of Corrections</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2251-stolen-laptop-with-names-and-social-security-numbers-could-affect-over-130-000">131,000</a></td>
<td style="text-align: center; width: 70px;">2009-08-04</td>
<td style="font-size: 11px;">United States Army National Guard</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2243-inmate-found-with-list-of-all-nhdoc-workers-including-names-and-social-security-numbers-of-1000">1,000</a></td>
<td style="text-align: center; width: 70px;">2009-08-04</td>
<td style="font-size: 11px;">New Hampshire Department of Corrections</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2224-stolen-laptop-contains-names-social-security-numbers-and-dates-of-birth-for-4-400">4,400</a></td>
<td style="text-align: center; width: 70px;">2009-07-31</td>
<td style="font-size: 11px;">Williams Companies, Inc.</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2222-stolen-laptop-may-have-contained-personal-information-of-766">766</a></td>
<td style="text-align: center; width: 70px;">2009-07-28</td>
<td style="font-size: 11px;">University of Colorado CO Springs</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2216-breach-exposes-over-500-000-credit-card-accounts">573,928</a></td>
<td style="text-align: center; width: 70px;">2009-07-25</td>
<td style="font-size: 11px;">Network Solutions</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2215-social-security-numbers-of-900-accidentally-sent-via-postal-mail">900</a></td>
<td style="text-align: center; width: 70px;">2009-07-24</td>
<td style="font-size: 11px;">Hampton Redevelopment and Housing Authority</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2209-policyholders-credit-card-details-of-1000-exposed-by-unknown-leak">1,000</a></td>
<td style="text-align: center; width: 70px;">2009-07-23</td>
<td style="font-size: 11px;">American International Group (<a class="zem_slink freebase/en/american_international_group" title="NYSE: AIG" rel="stockexchange" href="http://finance.yahoo.com/q?s=AIG">AIG</a>), American Life Insurance Co Japan</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2205-hsbc-life-lost-a-cd-containing-the-details-of-180-000-policyholders">180,000</a></td>
<td style="text-align: center; width: 70px;">2009-07-22</td>
<td style="font-size: 11px;">HSBC Holdings plc, HSBC Life</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2206-hsbc-actuaries-lost-a-floppy-disk-containing-the-personal-information-of-1-917-pension-scheme-members">1,917</a></td>
<td style="text-align: center; width: 70px;">2009-07-22</td>
<td style="font-size: 11px;">HSBC Holdings plc, HSBC Actuaries</td>
</tr>
</tbody>
</table>
<p>The main problem with these events is that the user is uneducated when it comes to security and don&#8217;t bother to go for a  <a href="http://www.kraasecurity.com/freewebsitetest">security penetration test</a> or <a href="http://www.kraasecurity.com/">information security risk assessment</a>.  No matter what kind of technology you put in place, the user can find a way around it to compromise your security. First educate them, then worry about technology to protect them from their own stupidity.</p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong>o</strong>:888-KRAA-911,  <strong>c</strong>: 917-568-7917, <strong>f</strong>: 866-633-6601</p>
<p><strong><em>Address</em></strong><em>: 20801 Biscayne Blvd, Suite 403, Aventura, FL 33180</em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p>*FREE Website Security Test</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://smarterware.org/3490/what-do-you-do-to-protect-your-laptops-data-on-open-networks-and-in-case-of-theft">What do you do to protect your laptop&#8217;s data on open networks and in case of theft?</a> (smarterware.org)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/a7d51bbc-cded-482e-8325-d419759ee940/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=a7d51bbc-cded-482e-8325-d419759ee940" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/08/07/stolen-laptop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forget Information Security, someone work on airport delays</title>
		<link>http://blog.kraasecurity.com/2009/07/30/forget-information-security-someone-work-on-airport-delays-3/</link>
		<comments>http://blog.kraasecurity.com/2009/07/30/forget-information-security-someone-work-on-airport-delays-3/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 16:08:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Travel]]></category>
		<category><![CDATA[airport delay]]></category>
		<category><![CDATA[bwi]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/2009/07/30/forget-information-security-someone-work-on-airport-delays-3/</guid>
		<description><![CDATA[Forget Information Security, someone work on airport delays
My posts are all usually information security related. Some interesting things on web security, vulnerability assessment, risk assessment, all that good stuff. Well today I cannot blog about that. As much as I love it, get a probably un-natural excitement about it, I can&#8217;t do it.
I have been [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Forget Information Security, someone work on airport delays</strong></p>
<p>My posts are all usually information security related. Some interesting things on web security, vulnerability assessment, risk assessment, all that good stuff. Well today I cannot blog about that. As much as I love it, get a probably un-natural excitement about it, I can&#8217;t do it.</p>
<p>I have been sitting in BWI airport since 7pm. Its about 11pm and I am still waiting for the plane to get here. Or it might be here and we can&#8217;t get on, not v ery clear on that. So there was a light sprinkle of rain in the BWI area. All up and down the east coast there was storms. And Boston got whacked. When Boston has problems, everybody has problems. Something like the Regan trickly down theory.</p>
<p>Its about 11:20pm now and I just heard the announcement that the flight landed from Portland and potentially I might get home to Miami sometime around 3am. I am not a newbie to travel and being stuck in an airport is old hat. I recall being stuck in Amsterdam on Thanksgiving in the airport for about 11 hours. Patience Grasshopper.</p>
<p>So whats so new about this experience? Well I was thinking that the algorithims to route planes around the country were developed 30 or 40 years ago.  So think about all the changes, all the potential of planes these days and not updating how planes are handled. Or maybe I am wrong since I am not an airline expert and they have all new routing plans. Probably. But my view of the world, well I see it as really sucking. So I make the assumption that there needs to be a (cringe) &#8220;paradigm shift&#8221; in how planes are handled. Maybe we need an Airport Czar.</p>
<p>My other problem with the waiting thing is that the Bar closed at 9:30pm!!!! My flight will not leave until about Midnight. When will the hurting stop?!!?!?</p>
<p>This was obviously not of any value to anyone except me to channel my airport anger.</p>
<p>I usually have a list of things in my posts. Here is my list which is pretty much of no value<br />
1) when sitting in the bar in an airport that closes at 9:30, listen for last call<br />
2) Never take the later flight out in the day if you can avoid it<br />
3) Avoid BWI<br />
4) Never believe the monitors about if your flight is on time<br />
5) Actually speak to people at the bar, keeps things entertaining<br />
6) Girls wearing short shorts shouldn&#8217;t lie down, knees akimbo at the airport<br />
7) Never pass up a trip to Vegas to for a trip to Baltimore<br />
 <img src='http://blog.kraasecurity.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> The restaurants close early at BWI, eat early<br />
9) BWI sucks<br />
10) BWI sucks</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/07/30/forget-information-security-someone-work-on-airport-delays-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Loss, this time with Network Solutions</title>
		<link>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/</link>
		<comments>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 16:55:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[network solutions]]></category>
		<category><![CDATA[stolen data]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/</guid>
		<description><![CDATA[Data Loss, this time with Network Solution
Network Solutions, one of the largest domain registrars recently announced a data breach. Malicious code was found on its e-commerce server which may have captured transactions from thousands of websites and capturing half a million or more credit cards. The company said they found the code during a routine [...]]]></description>
			<content:encoded><![CDATA[<h1>Data Loss, this time with Network Solution</h1>
<p>Network Solutions, one of the largest domain registrars recently announced a <strong>data breach</strong>. Malicious code was found on its e-commerce server which may have captured transactions from thousands of websites and capturing half a million or more credit cards. The company said they found the code during a routine check. Since the breach occurred between March 12 and June 8th, how routine was the actual checks? I wonder when their last vulnerability assessment or <a href="http://www.kraasecurity.com/">Information security risk assessment</a> was conducted? Data loss prevention is sorely lacking in just about every industry.</p>
<p>Here is what the company said &#8220;At this point, we have no reports or other reasons to believe that any credit card account information has been misused and, under established practice, credit card issuing companies generally will not hold our merchants’ customers liable for any fraudulent purchases made using their credit card account numbers that are reported in a timely way to the issuer,&#8221; a statement from the company reads. All these statements around <strong>hacker breaches </strong>and <strong>stolen credit cards </strong>read the same.</p>
<p>The process now begins where all the merchants have to be identified, then each merchant has to notify their customers. Their customer then have to work with their banks to stop credit cards, have to get credit monitoring and thus goes the Circle of Life (of data breaches) Here is the list of <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2009">data breaches</a> in 2009 alone. If you recall the breaches of Heartland Payment Systems and RBS WorldPay, the breachescaused them to be removed from the <a href="http://www.kraasecurity.com/compliance/pci">PCI security audit</a> () list . Well that should be obvious, or should they have been rated compliant int he first place. Known non-compliance might be a better than weak compliance.</p>
<p>The basic question is what was Network Solution not doing to have malicious software installed on key servers? Was it a breach through a web application, was it through malicious email, a browser based attack, some insider who didn&#8217;t know enough about security and clicked on the wrong thing? What routine check found it and why wasn&#8217;t this check run on a more routine basis, such as weekly or even daily?</p>
<p>At the end of the day, security is a moving target. We can utilize encryption, vulnerability management, <a href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">application security risk assessment</a>, <strong>email filtering, backup and recovery</strong>, but all will be useless is we follow poor practices or do not have good procedures in place to take into account the human element. Most breaches are insider problems or mis-configurations or plain old stupidity.</p>
<p>Gary Bahadur<br />
<a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p>http://blog.kraasecurity.com</p>
<p>*Managed Security Services<br />
*Vulnerability Management<br />
*Compliance &amp; Policy Development<br />
*PGP Security<br />
*FREE Website Security Test</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/755d6115-051b-8f3d-a5f6-0fd37b657b56/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=755d6115-051b-8f3d-a5f6-0fd37b657b56" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
