<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>BankInfoSecurity.com  RSS Syndication</title>
<link>http://www.bankinfosecurity.com/rssFeeds.php?type=main</link>
<description>BankInfoSecurity.com RSS News Feeds on bank information security news, regulations, blogs and education</description>
<pubDate>Sun, 26 Feb 2012 11:53:46 -0600</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/bankinfosecurity/com" /><feedburner:info uri="bankinfosecurity/com" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>ATM Crime Boss Sentenced</title>
			<link>http://www.bankinfosecurity.com/articles.php?art_id=4532</link>
			<guid>http://www.bankinfosecurity.com/articles.php?art_id=4532</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4532_artid_4448_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Bulgarian Crime Head Pleads Guilty to Skimming Scheme&lt;/b&gt;&lt;br&gt;The FBI says Bulgarian fraudster Dimitar Dimitrov led ATM skimming rings that ranged from New York to Las Vegas, and now a federal judge has sentenced him to prison. Is the sentence appropriate?</description>
			</item>
			<item>
			<title>Cybersecurity for the C-Suite</title>
			<link>http://www.bankinfosecurity.com/articles.php?art_id=4526</link>
			<guid>http://www.bankinfosecurity.com/articles.php?art_id=4526</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4526_Tsamitis_Dena_Haritos_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;CMU Launches Executive Master's in Information Assurance&lt;/b&gt;&lt;br&gt;"This is a unique program that fits the specific needs for upcoming and current IT security leaders and adds high enrichment to peer support and the learning experience," says Dena Haritos Tsamitis.</description>
			</item>
			<item>
			<title>Tips to Fight Debit Fraud</title>
			<link>http://www.bankinfosecurity.com/articles.php?art_id=4525</link>
			<guid>http://www.bankinfosecurity.com/articles.php?art_id=4525</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4525_yao_jane_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;ABA Says Better Detection Tools, More Education Needed&lt;/b&gt;&lt;br&gt;Losses linked to debit fraud are increasing, says Jane Yao of the American Bankers Association, and the industry is in a perpetual state of catch-up. A new study tells how institutions can fight back.</description>
			</item>
			<item>
			<title>Cybersecurity Center of Excellence Launched</title>
			<link>http://www.bankinfosecurity.com/articles.php?art_id=4523</link>
			<guid>http://www.bankinfosecurity.com/articles.php?art_id=4523</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4523_NIST_Center_of_Excellence_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Promoting Quick Adoption of Information Technology Tools&lt;/b&gt;&lt;br&gt;The National Institute of Standards and Technology is establishing the National Cybersecurity Center of Excellence, a public-private collaboration aimed at accelerating the widespread adoption of integrated cybersecurity tools and technologies.</description>
			</item>
			<item>
			<title>NCUA: A M Community Credit Union, Kenosha, Wis., Placed Under Conservatorship</title>
			<link>http://www.bankinfosecurity.com/regulations.php?reg_id=2645</link>
			<guid>http://www.bankinfosecurity.com/regulations.php?reg_id=2645</guid>
			<description>The National Credit Union Administration, working cooperatively with the Wisconsin Office of Credit Unions, assumed control of service and operations at A M Community Credit Union headquartered in Kenosha, Wis.</description>
			</item>
			<item>
			<title>FinCEN: Guidance to Financial Institutions on Providing Services to Foreign-Located Money Services Businesses</title>
			<link>http://www.bankinfosecurity.com/regulations.php?reg_id=2644</link>
			<guid>http://www.bankinfosecurity.com/regulations.php?reg_id=2644</guid>
			<description>FinCEN is issuing an advisory to financial institutions regarding their obligations under the Bank Secrecy Act when providing financial services to foreign-located money services businesses.</description>
			</item>
			<item>
			<title>OCC: Deadline to Request Review under Independent Foreclosure Review Extended to July 31</title>
			<link>http://www.bankinfosecurity.com/regulations.php?reg_id=2643</link>
			<guid>http://www.bankinfosecurity.com/regulations.php?reg_id=2643</guid>
			<description>Office of the Comptroller of the Currency and the Board of Governors of the Federal Reserve System announced that the deadline for submitting requests for review under the Independent Foreclosure Review has been extended.</description>
			</item>
			<item>
			<title>FDIC: SCB Bank, Shelbyville, Ind., Closes</title>
			<link>http://www.bankinfosecurity.com/regulations.php?reg_id=2642</link>
			<guid>http://www.bankinfosecurity.com/regulations.php?reg_id=2642</guid>
			<description>SCB Bank, Shelbyville, Ind., was closed by the Office of the Comptroller of the Currency, which appointed the Federal Deposit Insurance Corporation as receiver.</description>
			</item>
			<item>
			<title>The Great Application Security Debate: Static vs. Dynamic vs. Manual Penetration Testing</title>
			<link>http://www.bankinfosecurity.com/webinars.php?webinarID=268</link>
			<guid>http://www.bankinfosecurity.com/webinars.php?webinarID=268</guid>
			<description>Software applications are an integral part of 21st century business processes. The majority  of  software  is  still  installed  in-house,  either  as  specially  developed custom applications or commercially acquired packages. However, the proportion of software procured as a service is on the rise, as is the use of mobile apps and open source components. In addition, more and more in-house applications are being web-enabled and exposed to the outside world. 
&lt;p&gt;
&lt;p&gt;
Regardless of its origin, the vast majority of software will contain flaws which can constitute a security risk, especially for those applications that are web-enabled. The cost of fixing a flaw increases the later that they are found in the development, acquisition and deployment life-cycle. There are a number of measures that can be taken to mitigate the problem and reduce the overall cost of managing software whilst ensuring better security. Increasingly, businesses are recognizing the benefits of outsourcing at least some of the effort through the use of on-demand software testing services. 
&lt;p&gt; 
This webinar explores how businesses are deploying software and what measures are in place for checking the security of applications. This webinar will present new research conducted amongst US and UK enterprises from a range of industries and assesses the scale of the software security problem, the ways in which it can be mitigated, the extent to which this is being achieved, the costs involved and how these can be minimized.
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;2011 was the Year of the Breach. Some of the world's best companies and brands were attacked making securing your enterprise applications a key information security imperative.&lt;/li&gt;
&lt;li&gt;As applications become more mission critical to the enterprise, so too does the need to secure them.&lt;/li&gt;
&lt;li&gt;Learn how enterprises can leverage the various application testing approaches in their application security programs.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>The Fraud Dilemma: How to Prioritize Anti-Fraud Investments</title>
			<link>http://www.bankinfosecurity.com/webinars.php?webinarID=267</link>
			<guid>http://www.bankinfosecurity.com/webinars.php?webinarID=267</guid>
			<description>In light of increasingly sophisticated fraud techniques - everything from account takeover attempts to ATM skimming and increasingly sophisticated phishing attacks -- financial institutions are under constant pressure to protect customer assets.
&lt;p&gt;
Further, embodied by the FFIEC Authentication Guidance, they face heightened regulatory pressure to assess risks, deploy layered security controls and to improve customer awareness of  this ever-evolving threat landscape.
&lt;p&gt;
And a single misstep could result in a data breach that carries heavy financial, regulatory, customer, shareholder and reputational implications.
&lt;p&gt;
Among the anti-fraud options available to banks:  
&lt;ul&gt;
&lt;li&gt;Device authentication/identification, which has a wide spectrum of approaches, some better than others.&lt;/li&gt;
&lt;li&gt;Malware detection and mitigation, operating either from the cloud or on a user's device to reduce Man-in-the-Browser fraud from compromised endpoints.&lt;/li&gt;
&lt;li&gt;Anomaly detection, which can take the form of simple rules to complex cross-channel behavioral analysis.&lt;/li&gt;
&lt;li&gt;Transaction verification, which can be rules-based or triggered by anomaly detection and can then take several forms (token, SMS, phone verification, dual authorization).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
So, how does an institution go about evaluating all of these options and deciding which fits its own risk profile best?
&lt;p&gt;
In this panel discussion, banking/fraud expert George Tubin will lead a lively discussion of today's top fraud threats and solutions. Among the topics to be tackled:
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Regulatory Requirements&lt;/b&gt; - What are the basic expectations for assessing and mitigating fraud risks?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Investment Planning&lt;/b&gt; - What is your institution's fraud loss profile, and how can you best match mitigation approaches to your identified risks?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Selling the Solution&lt;/b&gt; - Once you've identified your anti-fraud solutions, how do you demonstrate value to stakeholders, and then win support for a prioritized investment plan?&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>BYOD: Manage the Risks and Opportunities</title>
			<link>http://www.bankinfosecurity.com/webinars.php?webinarID=266</link>
			<guid>http://www.bankinfosecurity.com/webinars.php?webinarID=266</guid>
			<description>From home computers and laptops to cellphones and PDAs, employees have always lobbied to introduce consumer technologies in the workplace.
&lt;p&gt;
&lt;p&gt;
But with the advent of smart phones, tablets, portable storage and a variety of laptops - powerful computing devices that often rely on unsecured wireless networks - the push today is even greater. Example: Intel, the global computer technologies manufacturer, reports that connected mobile devices grew from 10,000 to 30,000 over the first 10 months of 2011. And by 2014, Intel expects 70% of its employees to use personal devices for some aspect of their job.
&lt;p&gt;
So, it's no longer a question of whether to allow employees to use their own devices - no corporate policy can stem the tide of consumerization. The questions now are about:
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Inventory&lt;/b&gt; - How do you properly account for all of the consumer devices introduced by your employees? Know how to lock down your corporate wireless networks and desktop computers, so you'll also know when employees are trying to access corporate resources via connecting new devices.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Security&lt;/b&gt; - How do you protect your systems and data from unauthorized access - and in the event of lost or stolen devices? From identification to proper authentication, appropriate access control, data storage and detecting un-authorized activities - all controls implemented by an organization on 'corporate-owned' resources over the last decade can potentially be rendered useless on an employee-owned device. Learn the importance of each control and the implementation challenges in a large-scale environment.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Privacy&lt;/b&gt; - The controls you place on an employee-owned device could potentially compromise the individual's privacy (knowing which sites they visit, or whom they e-mail in their off-hours, for instance). How do you achieve the right balance to protect the enterprise's security and the employee's privacy?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Compliance&lt;/b&gt; - Certain international regulations and standards spell out standards for how data is collected and stored, as well as how it must be made available for legal requests. Are you prepared to address these and other top-level compliance issues when it comes to employees storing enterprise data on their own devices? Learn how to weigh the risks and benefits.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Policy&lt;/b&gt; - Beyond making employees aware of your policy, how do you enforce it? Awareness is key - make sure employees understand your policies around device usage, access, software licensing and other critical issues. But you also need to articulate specific areas of non-compliance and then monitor appropriately for violations subject to disciplinary action, including termination.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Opportunity&lt;/b&gt; - Beyond securing devices, BYOD is an opportunity to improve data and access security in the enterprise, web, mobile, and SaaS applications. The opportunity is for organizations to still have strong security and authentication, but in a way that is "outsourced" to the device owner for all of their applications. This outsourcing can save the company IT budget, as well as reduce help desk support.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
In this session, mobile security experts will discuss these topics and more, sharing insights on how today's leading-edge organizations are embracing BYOD as a means of improving employee productivity and creating new business value.</description>
			</item>
			<item>
			<title>Fundamental Security: The Power of GLBA and FFIEC Compliance</title>
			<link>http://www.bankinfosecurity.com/webinars.php?webinarID=265</link>
			<guid>http://www.bankinfosecurity.com/webinars.php?webinarID=265</guid>
			<description>The adage "Compliance doesn't ensure good security, but good security almost always ensures compliance" continues to ring true in 2012, as financial institutions seek to comply with the updated FFIEC guidance on online banking.
&lt;p&gt;
&lt;p&gt;
"Layered security" is a requirement of the new guidance released in 2011, but what does that really mean to banks and credit unions that are preparing for examinations? While financial institutions with an establised GLBA information security program and culture most likely were compliant with the new requirements before they were published, many banks and credit unions are still ill prepared to meet the examiners - and as a result, may lack fundamental security controls. 
&lt;p&gt;
Consider the core requirements of GLBA's Safeguards Rule, which requires institutions to:
&lt;ul&gt;
&lt;li&gt;Develop a written information security plan;&lt;/li&gt;
&lt;li&gt;Appoint at least one employee to manage the safeguards;&lt;/li&gt;
&lt;li&gt;Conduct a risk assessment of on each department handling private information;&lt;/li&gt;
&lt;li&gt;Develop, monitor, and test the information security program;&lt;/li&gt;
&lt;li&gt;Amend safeguards as necessary with changes in how information is collected, stored and used.&lt;/li&gt;
&lt;/ul&gt;
Risk assessments, security controls and monitoring all are core components of the updated FFIEC Authentication Guidance, as well.
&lt;p&gt;
&lt;p&gt;
In this session, George Tubin, noted expert in banking security, fraud and compliance, will discuss the key elements of GLBA and the FFIEC guidance with an eye toward offering new insights on:
&lt;ul&gt;
&lt;li&gt;Strategies for ensuring both security and compliance;&lt;/li&gt;
&lt;li&gt;A practical approach to layered security;&lt;/li&gt;
&lt;li&gt;Regulatory trends - what to expect next for guidance.&lt;/li&gt;
&lt;/ul&gt;
Following Tubin's presentation, Jeff Multz, Director of North America Midmarket Sales for Dell SecureWorks, will discuss the banking and security trends Dell SecureWorks is seeing and how institutions can respond to them.</description>
			</item>
			<item>
			<title>Privacy Bill of Rights: Not Be-All, End-All</title>
			<link>http://www.bankinfosecurity.com/interviews.php?interviewID=1405</link>
			<guid>http://www.bankinfosecurity.com/interviews.php?interviewID=1405</guid>
			<description>The Obama administration's Consumer Privacy Bill of Rights should be seen as a vital document to help shape an expansive and globally accepted privacy framework in the United States, privacy and data security lawyer Lisa Sotto says.</description>
			</item>
			<item>
			<title>What to Expect at RSA Conference</title>
			<link>http://www.bankinfosecurity.com/interviews.php?interviewID=1404</link>
			<guid>http://www.bankinfosecurity.com/interviews.php?interviewID=1404</guid>
			<description>This is the first &lt;a href='http://www.bankinfosecurity.com/pages.php?pageID=rsa2012'&gt;&lt;b&gt;RSA Conference&lt;/b&gt;&lt;/a&gt; since 2011's high-profile &lt;a href='http://www.inforisktoday.com/articles.php?art_id=4161'&gt;&lt;b&gt;security breaches&lt;/b&gt;&lt;/a&gt;. How did those incidents influence this year's agenda? Hugh Thompson explains in an exclusive event preview.</description>
			</item>
			<item>
			<title>Mobile Security: Enabling BYOD</title>
			<link>http://www.bankinfosecurity.com/interviews.php?interviewID=1399</link>
			<guid>http://www.bankinfosecurity.com/interviews.php?interviewID=1399</guid>
			<description>Mobile security is a new discussion track at &lt;a href='http://www.bankinfosecurity.com/pages.php?pageID=rsa2012'&gt;&lt;b&gt;RSA Conference&lt;/b&gt;&lt;/a&gt;, but it's long been a hot topic for CISOs. Entrust's Dave Rockvam discusses &lt;a href='http://www.bankinfosecurity.com/categories.php?catID=325'&gt;&lt;b&gt;BYOD &lt;/b&gt;&lt;/a&gt;and how organizations are securing personally-owned devices.</description>
			</item>
			<item>
			<title>The Book on Insider Threats</title>
			<link>http://www.bankinfosecurity.com/interviews.php?interviewID=1396</link>
			<guid>http://www.bankinfosecurity.com/interviews.php?interviewID=1396</guid>
			<description>The &lt;a href='http://www.bankinfosecurity.com/categories.php?catID=247'&gt;&lt;b&gt;insider threat&lt;/b&gt;&lt;/a&gt;: It's a top challenge for any organization, and it's a hot topic for &lt;a href='http://www.bankinfosecurity.com/pages.php?pageID=rsa2012'&gt;&lt;b&gt;RSA Conference&lt;/b&gt;&lt;/a&gt; attendees. Dawn Cappelli and Randy Trzeciak preview their new book, The CERT Guide to Insider Threats.</description>
			</item>
			<item>
			<title>7 Levels of Hackers</title>
			<link>http://www.bankinfosecurity.com/blogs.php?postID=1206</link>
			<guid>http://www.bankinfosecurity.com/blogs.php?postID=1206</guid>
			<description>&lt;b&gt;Applying An Ancient Chinese Lesson: Know Your Enemies&lt;/b&gt;&lt;br /&gt;Not all hackers are the same, and that presents problems in defending against them. Understanding each type of hacker can help organizations better prepare for digital assaults.</description>
			</item>
			<item>
			<title>Anonymous Set to Do Real Damage?</title>
			<link>http://www.bankinfosecurity.com/blogs.php?postID=1203</link>
			<guid>http://www.bankinfosecurity.com/blogs.php?postID=1203</guid>
			<description>&lt;b&gt;Report: Gen. Keith Alexander Fears Attack on Electric Grid&lt;/b&gt;&lt;br /&gt;Concerns expressed by the National Security Agency director come at a time when Congress is split over the role government should perform in determining the security of the mostly privately owned national critical IT infrastructure.</description>
			</item>
			<item>
			<title>How Encrypted Keys Can Leave Bad Taste</title>
			<link>http://www.bankinfosecurity.com/blogs.php?postID=1201</link>
			<guid>http://www.bankinfosecurity.com/blogs.php?postID=1201</guid>
			<description>&lt;b&gt;RSA Challenges Conclusion of Number Generation Study&lt;/b&gt;&lt;br /&gt;RSA Chief Technologist Sam Curry defends the company's approach to public-key cryptography after researchers suggest a flaw in its encryption algorithm, contending the problem exists elsewhere in the security chain.</description>
			</item>
			<item>
			<title>Low-Tech Fraud Targets Banks, CUs</title>
			<link>http://www.bankinfosecurity.com/blogs.php?postID=1200</link>
			<guid>http://www.bankinfosecurity.com/blogs.php?postID=1200</guid>
			<description>&lt;b&gt;Prelim Survey Results Reveal Startling Fraud Trends&lt;/b&gt;&lt;br /&gt;What are the top two fraud schemes hitting banks and credits unions the hardest? The early responses from our ongoing 2012 Faces of Fraud Survey just might surprise you.</description>
			</item></channel></rss>

