<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance &#187; Identity theft</title>
	<atom:link href="http://blog.kraasecurity.com/tag/identity-theft/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 06 Jul 2011 01:12:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Pleasant Grove man sentenced to 6 years in federal prison for role in prescription fraud case</title>
		<link>http://blog.kraasecurity.com/2011/05/27/pleasant-grove-man-sentenced-to-6-years-in-federal-prison-for-role-in-prescription-fraud-case/</link>
		<comments>http://blog.kraasecurity.com/2011/05/27/pleasant-grove-man-sentenced-to-6-years-in-federal-prison-for-role-in-prescription-fraud-case/#comments</comments>
		<pubDate>Fri, 27 May 2011 20:06:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[Credit card]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[Theft]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=321</guid>
		<description><![CDATA[Healthcare HIPAA Identity Theft]]></description>
			<content:encoded><![CDATA[<p><a class="zem_slink" title="The Birmingham News" rel="homepage" href="http://www.al.com/birmingham/">The Birmingham news</a> (http://blog.al.com/spotnews/2011/05/pleasant_grove_man_sentenced_t.html)  reported that a Pleasant Grove man received six years in prison for HIPAA violations. Included in his crimes was aggravated <a class="zem_slink" title="Identity Theft" rel="wikinvest" href="http://www.wikinvest.com/concept/Identity_Theft">identity theft</a> and disclosures. These violate the HIPAA regulations.</p>
<p>Identity theft with regards to healthcare information is on the rise. There is a lot of value in stealing an identity to get healthcare. If you could do that for someone under 18, then you might have several years before they actually notice. Kids generally do not need to check their credit ratings until they get that first credit card in college. BY then the thief could have racked up a lot of charges on that identity.</p>
<p>Using healthcare access can allow the thief access to drugs which are then resold. In this case the thief used the stolen identity to cause the prescription drug plan to pay for $72,746 in drugs.</p>
<p>The Obama Administration announced a cyber security plan recently. Does it take into account the rise in identity theft? Are government agencies actively trying to find solutions? So far the answer seems to be No.</p>
<p>Regards</p>
<p>Gary Bahadur</p>
<p><a href="http://www.kraa.security.com/">www.kraasecurity.com</a></p>
<p>blog.kraasecrity.com</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/223325/id_thief_sentenced_to_more_than_16_years_in_prison.html">ID Thief Sentenced to More Than 16 Years in Prison</a> (pcworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://personalfinancenewsandtips.wordpress.com/2011/06/13/identity-theft-protection-guide/">Identity Theft Protection Guide</a> (personalfinancenewsandtips.wordpress.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=d11735f7-362d-4886-a0e1-a44d8dce2630" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2011/05/27/pleasant-grove-man-sentenced-to-6-years-in-federal-prison-for-role-in-prescription-fraud-case/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vanguard Security Conference &#8211; Supplier Security</title>
		<link>http://blog.kraasecurity.com/2009/06/02/supplier-security/</link>
		<comments>http://blog.kraasecurity.com/2009/06/02/supplier-security/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 15:44:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Supplier Security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Code review]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Managed Vulnerability Scanning]]></category>
		<category><![CDATA[web security]]></category>
		<category><![CDATA[Website security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=48</guid>
		<description><![CDATA[I spoke yesterday at the Vanguard Security Conference (http://www.go2vanguard.com) Vanguard has been doing this conference for a number of years. The focus is on Mainframe security. Most security professionals these days have never worked on MF security. I am proud to say I have back in the mid-90&#8242;s. We perhaps I shouldnt be do happy, [...]]]></description>
			<content:encoded><![CDATA[<p>I spoke yesterday at the Vanguard Security Conference (<a href="http://www.go2vanguard.com">http://www.go2vanguard.com</a>) Vanguard has been doing this conference for a number of years. The focus is on Mainframe security. Most security professionals these days have never worked on MF security. I am proud to say I have back in the mid-90&#8242;s. We perhaps I shouldnt be do happy, it was over a decade ago.</p>
<p>The point being, that there are so many areas of security out there that most of us will never touch yet there is a dire need for professionals. The conference was less attended, as are most conferences this year, but I found the folks here are REALLY interested in learning and excited about the classes.</p>
<p>My topic was on <strong>Supplier Risk Management</strong> processe. You are asking yourself, what is that? I asked myself that same question in coming up with some good processes to target Supplier security. We have to go way beyond a SAS70 if you want real security over the hundreds or thousands of vendors that a large company may work with.</p>
<p>The Problem:</p>
<ol>
<li>No framework for managing <strong>vendor risk</strong></li>
<li>Inconsistent processes for tracking vendors</li>
<li>Lack of enforcement capabilities</li>
</ol>
<p>The Opportunity:</p>
<ol>
<li>Provide practical steps to manage vendor access/management</li>
<li>Provide cost effective solution for risk mitigation</li>
<li>Provide numerical risk analysis of vendor/partner security issues</li>
<li>Risk reduction or risk acceptance</li>
<li>Documented exposure</li>
<li>Iterative process for <strong>risk management</strong></li>
<li>Happy CIO</li>
</ol>
<p>So a Supplier Security assessment follow 4 main steps:</p>
<ol>
<li>Analyze current vendor database, catageorize each</li>
<li>determine risk of each supplier, determine threats posed by each supplier</li>
<li>Perform assessment tests of each supplier, their processes of interaction, and data access</li>
<li>develop risk mitigation plan, update processed, monitoring processes</li>
</ol>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">Gary Bahadur</span></span></span></p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p>*FREE Website Security Test</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/06/02/supplier-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Healthcare Security- Identity Theft and Hacker ransom</title>
		<link>http://blog.kraasecurity.com/2009/05/07/healthcare/</link>
		<comments>http://blog.kraasecurity.com/2009/05/07/healthcare/#comments</comments>
		<pubDate>Thu, 07 May 2009 22:57:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=34</guid>
		<description><![CDATA[I hope no one is actually shocked by this story. Records are stolen everyday. Typically, the hackers will sell the information in the underground somewhere is Eastern Europe or Asia. The fact that someone is asking for ransom, and so publicly it actually a good thing in my opinion. Why is it good you ask? (I [...]]]></description>
			<content:encoded><![CDATA[<p>I hope no one is actually shocked by this story. Records are stolen everyday. Typically, the hackers will sell the information in the underground somewhere is Eastern Europe or Asia. The fact that someone is asking for ransom, and so publicly it actually a good thing in my opinion. Why is it good you ask? (I assume you are asking that, vulcan mind meld and all that..) Maybe the industry (meaning all industries) need a sensational story to get real change in their IT Security environments.</p>
<p>When the <strong>Heartland data breach</strong> happened, it was interesting but the general public didnt find it sexy enough. A ransom note, publicly done makes for good drama. Equate it to the Somali pirates. They really broke in the news because of the weapons they captured. This might be the &#8220;weapons&#8221; story that gets the general public asking about security of the places they use on the Internet.</p>
<p>Identity theft is on the rise. Most companies never do a web application security assessment. They almost never do a database security review. If the hacker can break in through your web portal but your database of customer data is encrypted, well your last line of defense can save your hide.</p>
<p>So what are some things you can do to protect your website?</p>
<p>1) Conduct a <strong>web application security assessment</strong>. You should probably do this twice a year or anytime you make any significant changes to the application.</p>
<p>2) Conduct an <strong>architecture review</strong>. If your network architecture has holes in it, a hacker can find away around the application and perhaps get to the data through a different port.</p>
<p>3) Conduct a <strong>host security diagnostic review</strong>. If the hacker can get on the system and take advantage of an operating system weakness, you will still be compromised</p>
<p>4) Conduct a <strong>database security review</strong>. Your last line of defense, make sure the data in encrypted, access is completely authenticated and IDS on the database to flag and stop inappropriate access</p>
<p>5) Hire someone smart to do your <strong>security assessment</strong>.</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">Gary Bahadur</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><a href="http://www.kraasecurity.com/"><span style="color: blue;"><span style="font-size: small; font-family: Calibri;">http://www.kraasecurity.com</span></span></a></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Managed Security Services</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Vulnerability Management</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Compliance &amp; Policy Development</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*PGP Security</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*FREE Website Security Test</span></span></span></p>
<p>+++++++++++++++++++++++++++++++++++++++++++++++</p>
<div id="blogstitle">The Channel Wire</div>
<div id="blogsdate">May 06, 2009</div>
<div id="blogsheadline2"><a href="http://blog.kraasecurity.com/security/217300538"><strong><span style="color: #0b2795;">Hacker Holding Health Records Hostage Demands Ransom</span></strong></a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/05/07/healthcare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

