<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>BankInfoSecurity.asia  RSS Syndication</title>
<link>http://www.bankinfosecurity.asia/rssFeeds.php?type=main</link>
<description>BankInfoSecurity.asia RSS News Feeds on bank information security news, regulations, blogs and education</description>
<pubDate>Mon, 28 May 2012 18:26:36 -0500</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/bankinfosecurity/asia" /><feedburner:info uri="bankinfosecurity/asia" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>Attack Highlights Third-Party Risks</title>
			<link>http://www.bankinfosecurity.asia/attack-highlights-third-party-risks-a-4801</link>
			<guid>http://www.bankinfosecurity.asia/attack-highlights-third-party-risks-a-4801</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4801_artid_4801_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Hack of Online Billing Provider May Have Exposed 500,000 Cards&lt;/b&gt;&lt;br&gt;The hack of online billing provider WHMCS may have exposed 500,000 payment cards. Experts say the incident highlights the persistent risks third parties pose in cardholder data security.</description>
			</item>
			<item>
			<title>Insider Case Exposes Security Lapses</title>
			<link>http://www.bankinfosecurity.asia/insider-case-exposes-security-lapses-a-4798</link>
			<guid>http://www.bankinfosecurity.asia/insider-case-exposes-security-lapses-a-4798</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4798_artid_4798_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Bank Manager Pleads Guilty to Theft&lt;/b&gt;&lt;br&gt;A former PNC Bank manager has pleaded guilty to bank theft - a charge that could lead to 10 years in prison and a $250,000 fine. What common security flaws allow such insider schemes to flourish?</description>
			</item>
			<item>
			<title>Social Engineering: Mitigating Risks</title>
			<link>http://www.bankinfosecurity.asia/social-engineering-mitigating-risks-a-4795</link>
			<guid>http://www.bankinfosecurity.asia/social-engineering-mitigating-risks-a-4795</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4795_omurchu_liam_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Symantec Recommends Mix of Tech, Education&lt;/b&gt;&lt;br&gt;Why are socially engineered schemes causing so many headaches? Symantec's new Internet Security Threat Report shows attacks are growing. Here's a list of Symantec's recommendations to thwart risks.</description>
			</item>
			<item>
			<title>Anonymous Hacks Justice Dept. Database</title>
			<link>http://www.bankinfosecurity.asia/anonymous-hacks-justice-dept-database-a-4794</link>
			<guid>http://www.bankinfosecurity.asia/anonymous-hacks-justice-dept-database-a-4794</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4794_anonymous_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Bureau of Justice Statistics Information Leaked&lt;/b&gt;&lt;br&gt;The hacktivist group Anonymous says it has stolen 1.76 GB of data from a United States Bureau of Justice Statistics server and posted it online for download. What's the rationale behind this latest attack?</description>
			</item>
			<item>
			<title>HKMA: United Nations Sanctions Ordinance</title>
			<link>http://www.bankinfosecurity.asia/agency-releases/hkma-united-nations-sanctions-ordinance-r-2666</link>
			<guid>http://www.bankinfosecurity.asia/agency-releases/hkma-united-nations-sanctions-ordinance-r-2666</guid>
			<description>&lt;p&gt;The Hong Kong Monetary Authority has issued a statement on the Chief Executive-in-Council approving United Nations sanctions on Libya and Afghanistan.&lt;/p&gt;</description>
			</item>
			<item>
			<title>HKMA: Banking (Amendment) Ordinance 2012</title>
			<link>http://www.bankinfosecurity.asia/agency-releases/hkma-banking-amendment-ordinance-2012-r-2665</link>
			<guid>http://www.bankinfosecurity.asia/agency-releases/hkma-banking-amendment-ordinance-2012-r-2665</guid>
			<description>The Hong Kong Monetary Authority is informing authorized institutions that on Feb. 29, 2012, the Banking (Amendment) Ordinance 2012 bill was passed by the Legislative Council.</description>
			</item>
			<item>
			<title>HKMA: Statements Issued by Financial Action Task Force on Money Laundering</title>
			<link>http://www.bankinfosecurity.asia/agency-releases/hkma-statements-issued-by-financial-action-task-force-on-money-r-2664</link>
			<guid>http://www.bankinfosecurity.asia/agency-releases/hkma-statements-issued-by-financial-action-task-force-on-money-r-2664</guid>
			<description>The Hong Kong Monetary Authority has issued an announcement regarding two updated statements by the Financial Action Task Force on Money Laundering.</description>
			</item>
			<item>
			<title>ENISA: App-Store Security - The Five Lines of Defense</title>
			<link>http://www.bankinfosecurity.asia/agency-releases/enisa-app-store-security-five-lines-defense-r-2543</link>
			<guid>http://www.bankinfosecurity.asia/agency-releases/enisa-app-store-security-five-lines-defense-r-2543</guid>
			<description>The European Network and Information Security Agency published a new report on app-store security where it advocates for a baseline set of "five lines of defense" against malware.</description>
			</item>
			<item>
			<title>2012 Cloud Security Agenda: Expert Insights on Security and Privacy in the Cloud</title>
			<link>http://www.bankinfosecurity.asia/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</link>
			<guid>http://www.bankinfosecurity.asia/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</guid>
			<description>What are organizations' top cloud security concerns, and how are security leaders addressing these concerns through policy, technology and improved vendor management?
&lt;p&gt;&lt;p&gt;
This is the key question posed by the 2012 Cloud Security Survey.
&lt;p&gt;
No longer just an emerging technology practice, cloud computing today is embraced globally as a means of gaining efficient access to critical applications, processes and storage. It's now common for organizations to rely on cloud service providers for functions and business applications such as customer relationship management, messaging or storage via a public, private or hybrid cloud. Further, industry-specific cloud-based applications such as electronic health records or mobile banking and payment applications are emerging at an unprecedented pace.
&lt;p&gt;
But these engagements come with questions about risks:
&lt;ul&gt;
&lt;li&gt;What are your cloud service provider's security and privacy measures, and have they been audited?&lt;/li&gt;
&lt;li&gt;Where geographically is cloud data being stored, and how do operational practices comply with government, industry and organizational privacy regulations?&lt;/li&gt;
&lt;li&gt;How is a multi-tenant cloud environment managed, and in the event of system compromise - what will be the incident response escalation process?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Yes, cloud computing is about efficiencies and new technologies, but it's also about security, privacy and an organization's reputation.
&lt;p&gt;
The 2012 Cloud Security Survey was crafted with assistance from leading experts in cloud computing, security and privacy, with a mission to:
&lt;ul&gt;
&lt;li&gt;Chart the latest cloud trends, including types of cloud implementations most common by industry and region;&lt;/li&gt;
&lt;li&gt;Gauge organizations' top cloud security concerns, from vendor security to data governance and breach preparedness;&lt;/li&gt;
&lt;li&gt;Predict the top areas of investment for organizations most concerned about cloud security.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
This webinar will draw upon survey results and expert insight from a special roundtable panel to discuss:
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Top Security Concerns&lt;/b&gt; - Are organizations more concerned about where their data is stored, or whether a malicious insider might be a threat to it?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Success Factors&lt;/b&gt; - On a scale with cost savings and availability of services, how does security now rank among elements critical to a successful cloud computing implementation?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Protective Measures&lt;/b&gt; - What are some of the practices organizations are employing, from instituting more stringent contracts to enforcing third-party audits and even participating in mock security exercises with cloud service providers?&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>2012 Faces of Fraud Survey: Complying with the FFIEC Guidance</title>
			<link>http://www.bankinfosecurity.asia/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</link>
			<guid>http://www.bankinfosecurity.asia/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</guid>
			<description>A follow-up to ISMG's 2011 Faces of Fraud Survey, this webinar looks not only at the latest fraud trends and how institutions are fighting back, but also at their progress in putting together layered security controls in conformance with the FFIEC Authentication Guidance.
&lt;p&gt;
&lt;p&gt;
Given the persistence of fraud threats and the demands of the FFIEC Authentication Guidance, the 2012 Faces of Fraud Survey is crafted with assistance from leading experts in fraud detection and prevention, with a mission to: 
&lt;ul&gt;
&lt;li&gt;Chart the latest fraud trends, including account takeover, skimming and payment card breaches;&lt;/li&gt;
&lt;li&gt;Gauge institutions' preparedness to conform to the FFIEC Authentication Guidance, including where they are prioritizing their efforts;&lt;/li&gt;
&lt;li&gt;Predict the top areas of focus for 2012, from real-time fraud monitoring tools to new layered security controls.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Mobile: Learn from Intel's CISO on Securing Employee-Owned Devices</title>
			<link>http://www.bankinfosecurity.asia/webinars/mobile-learn-from-intels-ciso-on-securing-employee-owned-devices-w-264</link>
			<guid>http://www.bankinfosecurity.asia/webinars/mobile-learn-from-intels-ciso-on-securing-employee-owned-devices-w-264</guid>
			<description>At Intel, the BYOD trend started in 2009, when employees began using their own smart phones, tablets and mobile storage devices on the job. Rather than reject the trend, as many organizations initially attempted, Intel's senior leaders were quick to embrace it as a means to cut costs and improve productivity.
&lt;p&gt;
&lt;p&gt;
Since Jan. 2010, the number of employee-owned mobile devices on the job has tripled from 10,000 to 30,000, and by 2014 Intel CISO Malcolm Harkins expects that 70 percent of Intel's 80,000 employees will be using their own devices for at least part of their job.
&lt;p&gt;
The payback so far: 
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Better Productivity&lt;/b&gt; - Employees who use their own devices respond faster to communication and over a greater percentage of the day;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Improved Security&lt;/b&gt; - Mobility improves Intel's time to respond, contain and recover from incidents;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Greater Control&lt;/b&gt; - Because personally-owned devices are encouraged, Intel now has markedly fewer unauthorized devices on its network.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
And while there are heightened risks that come with having employees carry sensitive data on their personal devices, Harkins says organizations must tackle these risks head-on. "Doing nothing is not an option" when it comes to BYOD, he says. "Employees will work around and unknowingly expose the enterprise."
&lt;p&gt;&lt;p&gt;
In this presentation, Harkins tells how Intel came to embrace and benefit from the BYOD trend, including insights on:
&lt;p&gt;
&lt;b&gt;Bottom-up Approach&lt;/b&gt; - Intel from the outset involved employees in mobile policy creation, making the process open to input and constructive criticism. The result: an effective Employee Service Agreement for personally-owned devices.
&lt;p&gt;
&lt;b&gt;Risk Management&lt;/b&gt; - There is no 'one size fits all' so Intel developed a five-tier risk management model that provides enhanced security capabilities depending on the employee's access to sensitive data such as line of business applications, filtered e-mail and the corporate intranet.
&lt;p&gt;
&lt;b&gt;Beyond Technology&lt;/b&gt; - Intel quickly discovered that BYOD impacts more than the IT and security groups. HR and legal play huge roles in helping to define policy, enforce compliance and ensure adequate attention is paid to details regarding privacy, appropriate use and software licensing.
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Using the NIST HIPAA Security Rule Toolkit for Risk Assessments</title>
			<link>http://www.bankinfosecurity.asia/webinars/using-nist-hipaa-security-rule-toolkit-for-risk-assessments-w-262</link>
			<guid>http://www.bankinfosecurity.asia/webinars/using-nist-hipaa-security-rule-toolkit-for-risk-assessments-w-262</guid>
			<description>The National Institute of Standards and Technology, a non-regulatory agency of the Department of Commerce, is responsible for providing standards and technology to protect against threats to the confidentiality, integrity and availability of information and information systems. NIST's Computer Security Division is positioned to ensure that new technologies are selected, deployed and operated in a manner that reduces risk.
&lt;p&gt;&lt;p&gt;
The Health Insurance Portability and Accountability Act Security Rule establishes national standards to protect individuals' electronic personal health information that is created, received, used or maintained by a covered entity. Covered entities include hospitals, physician groups, health plans and claims clearinghouses. Soon, the rule also will apply to business associates - business partners that have access to sensitive patient information. The Security Rule requires appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity and security of electronic protected health information. 
&lt;p&gt;
To help organizations better understand the requirements of the HIPAA Security Rule, implement those requirements, and assess those implementations in their operational environments, NIST has developed a HIPAA Security Rule Self Assessment Toolkit.
&lt;p&gt;
In this session, Kevin Stine, manager of the Security Outreach and Integration Group within NIST's Computer Security Division, will:
&lt;ul&gt;
&lt;li&gt;Introduce participants to NIST and its role in information security;&lt;/li&gt;
&lt;li&gt;Provide a detailed overview of the toolkit application;&lt;/li&gt;
&lt;li&gt;Discuss how the toolkit can be used to support an organization's risk management process, help improve security safeguards and aid security assessment and compliance activities; and &lt;/li&gt;
&lt;li&gt;Identify additional NIST information security resources, such as risk assessment and security control guidelines, which can help organizations to manage risk and safeguard health information.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Why Boards of Directors Don't Get It</title>
			<link>http://www.bankinfosecurity.asia/interviews/boards-directors-dont-get-it-i-1569</link>
			<guid>http://www.bankinfosecurity.asia/interviews/boards-directors-dont-get-it-i-1569</guid>
			<description>IT risk management, cyber insurance, privacy - these are hot topics for security leaders, but not for their boards of directors. Why do senior executives still fail to see IT risks as business risks?</description>
			</item>
			<item>
			<title>How to Respond to Hacktivism</title>
			<link>http://www.bankinfosecurity.asia/interviews/how-to-respond-to-hacktivism-i-1568</link>
			<guid>http://www.bankinfosecurity.asia/interviews/how-to-respond-to-hacktivism-i-1568</guid>
			<description>Hacktivist attacks will increase, and researcher Gregory Nowak says organizations can take proactive steps to reduce exposure and protect brand reputation. Why, then, are many organizations failing?</description>
			</item>
			<item>
			<title>4 Security Priorities for Banks</title>
			<link>http://www.bankinfosecurity.asia/interviews/4-security-priorities-for-banks-i-1566</link>
			<guid>http://www.bankinfosecurity.asia/interviews/4-security-priorities-for-banks-i-1566</guid>
			<description>From mobile and the cloud to DDoS attacks and risks surrounding big data, what should banks and credit unions do now to mitigate exposure? Gartner's Anton Chuvakin offers his top recommendations.</description>
			</item>
			<item>
			<title>Understanding 'Big Data'</title>
			<link>http://www.bankinfosecurity.asia/interviews/understanding-big-data-i-1563</link>
			<guid>http://www.bankinfosecurity.asia/interviews/understanding-big-data-i-1563</guid>
			<description>Banks have a lot of data, but how well is it integrated? How much are institutions gleaning from the data they house? State Street Corp's chief scientist says financial services could be doing more.</description>
			</item>
			<item>
			<title>Fighting Hackers With Public Relations</title>
			<link>http://www.bankinfosecurity.asia/blogs/fighting-hackers-public-relations-p-1278</link>
			<guid>http://www.bankinfosecurity.asia/blogs/fighting-hackers-public-relations-p-1278</guid>
			<description>&lt;b&gt;Understanding Hacktivists' Goals is Key to Thwarting Attacks&lt;/b&gt;&lt;br /&gt;By understanding the motivations behind hacktivism, companies can learn why good public relations can play an important role in thwarting attacks or minimizing their impact.</description>
			</item>
			<item>
			<title>Global: A Lack of Breach Transparency</title>
			<link>http://www.bankinfosecurity.asia/blogs/global-lack-breach-transparency-p-1275</link>
			<guid>http://www.bankinfosecurity.asia/blogs/global-lack-breach-transparency-p-1275</guid>
			<description>&lt;b&gt;Processor Promised Updates, But We've Heard Little&lt;/b&gt;&lt;br /&gt;Global Payments has been less than forthcoming with information about its data breach. How could this lack of transparency hurt the processor, and what's the lesson for others?</description>
			</item>
			<item>
			<title>The Business Case for Continuity Planning</title>
			<link>http://www.bankinfosecurity.asia/blogs/business-case-for-continuity-planning-p-1272</link>
			<guid>http://www.bankinfosecurity.asia/blogs/business-case-for-continuity-planning-p-1272</guid>
			<description>&lt;b&gt;Small, Mid-Size Enterprises Especially Need to Develop Strategy&lt;/b&gt;&lt;br /&gt;Why do so many small and mid-sized enterprises continue to believe that business continuity planning is just for the big guys? And how do we go about convincing them otherwise? Here are some tips.</description>
			</item>
			<item>
			<title>Big Data for Fraud Prevention?</title>
			<link>http://www.bankinfosecurity.asia/blogs/big-data-for-fraud-prevention-p-1270</link>
			<guid>http://www.bankinfosecurity.asia/blogs/big-data-for-fraud-prevention-p-1270</guid>
			<description>&lt;b&gt;Tracking Customers, Not Accounts, Could Reduce Fraud&lt;/b&gt;&lt;br /&gt;Do banks and credit unions use all the data they collect? One credit reporting bureau says they could be doing more with their data to track and prevent fraud.</description>
			</item></channel></rss>

