<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.solidcore.com/public/" version="2.0"><!--

MySmartChannels™ RSS Feed

MySmartChannels is a service of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters.

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)

  enhanced=true|false (default=false)

  limit=n (default=15)

  score=none|emoticon|simple|stars|text (default=text)

  smartPoints=true|false (default=true)

  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)

  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>What's New | Solidcore Blog</title><link>http://blog.solidcore.com/public/blog/183014</link><description>The Latest Postings for Solidcore Blog</description><language>en-us</language><copyright>Copyright (C) 2008 Solidcore--All Rights Reserved -- This channel is part of the Solidcore Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 13 Sep 2007 23:45:19 -0400</pubDate><lastBuildDate>Tue, 22 Jul 2008 12:51:41 -0400</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V5.00.0717)</generator><image><url>http://blog.solidcore.com/styles/blogsite/SolidCore/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.solidcore.com/public/blog/183014</link><title>What's New | Solidcore Blog</title><description>Solidcore: Change Management and Change Control Solutions</description></image>
       <category>latest news</category><category>recent posts</category><category>Solidcore Blog</category>
       
       
      
    
     <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/WhatsNewSolidcoreBlog" type="application/rss+xml" /><item><title>ATB Financial prevents change related outages</title><link>http://blog.solidcore.com/public/item/209511</link><description>Taps Solidcore S3 Control to enforce change policy&lt;p&gt;&lt;a title="ATB Financial Web site" href="http://www.atb.com" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;ATB Financial&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;, one of the largest financial institutions in Canada and the fastest growing bank in Canada, is implementing Solidcore&amp;rsquo;s S3 Control software to gain visibility over changes across its IT environment and prevent change related outages.&amp;nbsp; ATB is standardizing on Solidcore to increase its IT service availability and streamline change processes.&lt;/p&gt;&lt;p&gt;According to Michael Redeker, vice president and chief technology officer for ATB Financial, &amp;ldquo;Our IT infrastructure is at the heart of providing exceptional customer service, and as a leading financial institution we cannot afford to have unauthorized change compromise the availability of the network and systems that propel our financial services.&amp;nbsp;Solidcore is the key to managing change across our IT environment, and we look forward to using the S3 Control product to verify that our IT change management best-practices are followed and unauthorized change is not allowed to occur on our critical systems.&amp;rdquo;&lt;/p&gt;&lt;p&gt;Solidcore's David Walker noted, &amp;ldquo;Rigorous demands are often placed on the IT group of a financial institution, which often translates into an increased number of file and configuration changes across the infrastructure, and a greater risk for unwanted change.&amp;nbsp; If you are not using Solidcore to detect and stop unwanted change, you are playing Russian Roulette with your IT infrastructure.&amp;nbsp; We are excited to see ATB Financial join a rapidly growing portfolio of customers that are eliminating change-related risks and outages with Solidcore&amp;rsquo;s real-time &lt;a title="Solidcore S3 Control product page" href="http://www.solidcore.com/products/s3control.html" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;change control&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;rdquo;&lt;/p&gt;&lt;p&gt;Tony Thompson&lt;br /&gt;Corporate Marketing &amp;amp; Communications&lt;br /&gt;&lt;a href="mailto:tthompson@solidcore.com"&gt;tthompson@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.atb.com" target=%quot;_blank%quot;&gt;ATB Financial&lt;/a&gt;&lt;br/&gt;ATB Financial web site&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.solidcore.com/products/s3control.html" target=%quot;_blank%quot;&gt;Leading change control technology&lt;/a&gt;&lt;br/&gt;Solidcore S3 Control product web page&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/209511</guid><pubDate>Tue, 22 Jul 2008 12:51:41 -0400</pubDate>
        <category>ATB Financial</category><category>change control</category><category>change management</category><category>outages</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Insider IT Sabotage - Super Villain of the Digital World?</title><link>http://blog.solidcore.com/public/item/209449</link><description>San Francisco network sabotage leaves administrators feeling helpless&lt;p&gt;&lt;img style="WIDTH: 69px; HEIGHT: 97px" height="97" alt="Hancock mirrors IT sabotage as super villain" hspace="0" src="http://larryfire.files.wordpress.com/2008/04/hancock1.jpg" width="69" align="baseline" border="0" /&gt;It's still &amp;quot;dark&amp;quot; within the city of &lt;a title="ChannelWeb story on San Francisco network lock-out" href="http://www.crn.com/security/209101383?cid=ChannelWebBreakingNews" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;San Francisco's network&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and IT organization after it was determined one of its own&amp;nbsp;network administrators went rogue and changed passwords and allegedly enabled lock-out code preventing any others from accessing the key components. He is still&amp;nbsp;holding the master password for ransom.&lt;/p&gt;&lt;p&gt;According to Insider &lt;a href="www.cert.org/insider_threat"&gt;&lt;strong&gt;&lt;u&gt;Threat Research&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; from CERT there most likely would have been pre-cursory warning signs:&lt;/p&gt;&lt;p&gt;Summary of Observations made within a study conducted by CERT, US Secret Service and the National Threat Assessment Center&lt;/p&gt;&lt;p&gt;- 90% of Insiders were granted system administrator or privileged system access when hired by the organization&lt;/p&gt;&lt;p&gt;- 57% of Insiders were perceived as being disgruntled due to unmet expectations&lt;/p&gt;&lt;p&gt;- 92% of Insiders attacked following&amp;nbsp;a negative work-related situation such as termination, dispute with employer, demotion or transfer&lt;/p&gt;&lt;p&gt;- 87% of Insiders performed technical precursors prior to the attack that were undetected by the organization&lt;/p&gt;&lt;p&gt;- 75% of Insiders created access paths unknown to the organization, 57% did not have authorized system access at the time of the attack&lt;/p&gt;&lt;p&gt;- 93% of Insiders exploited insufficient access controls&lt;/p&gt;&lt;p&gt;This should be chapter one in the &amp;quot;Worst Case Scenario&amp;quot; book for CIOs and corporate boards.&lt;/p&gt;&lt;p&gt;Ensure that controls are in place to allow IT administrators (role) to perform their duties (responsibilities) within their job function and scope (segmentation). However monitor, track and alert on all password changes to ensure that the keys to the digital foundation of your organization are not enabling IT Sabotage and or malicious hi-jinks.&lt;/p&gt;&lt;p&gt;This type of drama is unfolding like a comic book, similar to the Marvel comic character Rogue, who at times is good, at times is evil but shares one trait with today's Digital Super Villain&amp;nbsp;- the ability to absorb the powers of others. This could even be exemplifed by the modern day boxoffice thriller &lt;a title="Sony pictures Hancock official site" href="http://www.sonypictures.com/movies/hancock/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Hancock&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Bottom line: Don't let your controls only be policies on paper.&amp;nbsp;Make sure you have the power of enforcement!&lt;/p&gt;&lt;p&gt;&lt;b&gt;Kim Singletary&lt;br /&gt;&lt;/b&gt;Director of Embedded Solutions&lt;br /&gt;&lt;a href="mailto:ksingletary@solidcore.com"&gt;ksingletary@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Rajesh Rajamani&lt;br /&gt;&lt;/b&gt;Product Manager&lt;br /&gt;&lt;a href="mailto:raj@solidcore.com"&gt;raj@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.crn.com/security/209101383?cid=ChannelWebBreakingNews" target=%quot;_blank%quot;&gt;San Francisco Network Hijack&lt;/a&gt;&lt;br/&gt;ChannelWeb news story on the San Francisco network lock-out&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cert.org/insider_threat/" target=%quot;_blank%quot;&gt;CERT Research on Insider Threat&lt;/a&gt;&lt;br/&gt;Insider threat research from CERT&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.sonypictures.com/movies/hancock/" target=%quot;_blank%quot;&gt;Hancock&lt;/a&gt;&lt;br/&gt;Sony pictures Hancock page&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/209449</guid><pubDate>Mon, 21 Jul 2008 14:29:13 -0400</pubDate>
        <category>change control</category><category>Hancock</category><category>network hijack</category><category>San Francisco hack</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Credit Card Theft Blame Game</title><link>http://blog.solidcore.com/public/item/208877</link><description>Cardtronics owned 7-Eleven ATMs uncover a new blame game for who is responsible for credit card thefts&lt;p&gt;&lt;img style="WIDTH: 161px; HEIGHT: 186px" height="186" alt="Solidcore is locking down more than 60,000 ATMs worldwide and growing" hspace="0" src="http://www.freewebs.com/ballbustersrus/atm.jpg" width="161" align="baseline" border="0" /&gt;The &lt;a href="http://blog.wired.com/27bstroke6/2008/07/atm-owner-cardt.html"&gt;&lt;strong&gt;&lt;u&gt;7-Eleven/Citibank ATM breach&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; points out the complexity of field deployed self-service kiosks and ATMS. They may be convenient but transactions take a very different path versus a bank-based ATM on the outside of their branch, securely connected on the corporate network.&lt;/p&gt;&lt;p&gt;Using networking lingo, how many &amp;quot;hops&amp;quot; does it take to get a single transaction processed from the remote ATM?&lt;/p&gt;&lt;p&gt;My hypothesis is the following steps:&lt;/p&gt;&lt;p&gt;1- Local processing at the ATM itself &lt;/p&gt;&lt;p&gt;2- Network transport provided by regional and local players to give connectivity&lt;/p&gt;&lt;p&gt;3- Transaction processing of several remote ATMs to aggregate back-end servers within 7-Eleven or Cardtronics &amp;quot;vcom&amp;quot; &lt;/p&gt;&lt;p&gt;4- Connectivity to the third party payment acquirer contracted by 7-Eleven or Cardtronics to provide settlement services&lt;/p&gt;&lt;p&gt;5- Payment Acquirer connectivity and settlement services with Citibank&lt;/p&gt;&lt;p&gt;This is a good example of semi-trusted cooperative networking at its best.&amp;nbsp;The Payment Card Industry Data Security Standard (&lt;a title="Web page for the PCI DSS" href="http://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PCI DSS&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;)&amp;nbsp;expects that compliance is upheld with all those that touch a payment network. However compliance takes people, process and technology, and it is only&amp;nbsp;a baseline for security. The PCI&amp;nbsp;core strategy is know who is accessing&amp;nbsp;the network and log activity, and to monitor for exceptions. When you outsource or trust a service provider, then who is to blame? With all of the hops listed above, can you believe that a single piece of malware went unoticed at some point in this scenario?&lt;/p&gt;&lt;p&gt;Trust and Faith in partners and suppliers is appropriate. But I also like &lt;a title="Solidcore web site on ATM lock down" href="http://www.solidcore.com/solutions/atm.html" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Control and&amp;nbsp;Prevention&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;. Like many of our current customers, they know that Preventing and Detecting Change is important, that's why Solidcore is used today in over 60,000 ATMs worldwide!&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Kim Singletary&lt;br /&gt;&lt;/strong&gt;Director of Embedded Solutions&lt;br /&gt;&lt;a href="mailto:ksingletary@solidcore.com"&gt;ksingletary@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.wired.com/27bstroke6/2008/07/atm-owner-cardt.html" target=%quot;_blank%quot;&gt;ATM-Owner Cardtronics Issues Non-Denial Denial in Citibank Breach&lt;/a&gt;&lt;br/&gt;Wired blog on 7-Eleven Citibank hack&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target=%quot;_blank%quot;&gt;Payment Card Industry Data Security Standard&lt;/a&gt;&lt;br/&gt;Web site containing the PCI DSS&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.solidcore.com/solutions/atm.html" target=%quot;_blank%quot;&gt;The ATM Security Solutions&lt;/a&gt;&lt;br/&gt;Solidcore web page highlighting how to lock down ATMs&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/208877</guid><pubDate>Thu, 10 Jul 2008 20:58:19 -0400</pubDate>
        <category>7-Eleven</category><category>ATM</category><category>Citibank</category><category>PCI</category><category>PCI DSS</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>
