<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>InfoRiskToday.com  RSS Syndication</title>
<link>http://www.inforisktoday.com/rssFeeds.php?type=main</link>
<description>InfoRiskToday.com RSS News Feeds on info risk today news, regulations, blogs and education</description>
<pubDate>Mon, 28 May 2012 06:57:50 -0500</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/inforisktoday/com" /><feedburner:info uri="inforisktoday/com" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>Preparing for IPv6</title>
			<link>http://www.inforisktoday.com/preparing-for-ipv6-a-4804</link>
			<guid>http://www.inforisktoday.com/preparing-for-ipv6-a-4804</guid>
			<description>&lt;img src="http://docs.inforisktoday.com/files/images_articles/4804_curran_john_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;What You Need to Know for Secure Implementation&lt;/b&gt;&lt;br&gt;IPv4 - the protocol the Internet originally was built on - is quickly running out of addresses, and organizations must prepare for IPv6. What should they consider, and what steps can they take now?</description>
			</item>
			<item>
			<title>White House Pushes Blue Button</title>
			<link>http://www.inforisktoday.com/white-house-pushes-blue-button-a-4802</link>
			<guid>http://www.inforisktoday.com/white-house-pushes-blue-button-a-4802</guid>
			<description>&lt;img src="http://docs.inforisktoday.com/files/images_articles/4802_4424_3927_3866_3008_artid_2903_1_.jpg" align=right hspace=4&gt;&lt;b&gt;Broader Adoption of Secure Records Downloads Sought&lt;/b&gt;&lt;br&gt;A new presidential fellowship program, which seeks developers for short-term technology assignments, includes a project designed to spread the use of the Blue Button medical records secure download function.</description>
			</item>
			<item>
			<title>Attack Highlights Third-Party Risks</title>
			<link>http://www.inforisktoday.com/attack-highlights-third-party-risks-a-4801</link>
			<guid>http://www.inforisktoday.com/attack-highlights-third-party-risks-a-4801</guid>
			<description>&lt;img src="http://docs.inforisktoday.com/files/images_articles/4801_artid_4801_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Hack of Online Billing Provider May Have Exposed 500,000 Cards&lt;/b&gt;&lt;br&gt;The hack of online billing provider WHMCS may have exposed 500,000 payment cards. Experts say the incident highlights the persistent risks third parties pose in cardholder data security.</description>
			</item>
			<item>
			<title>What Are the Hidden Costs of Fraud?</title>
			<link>http://www.inforisktoday.com/what-are-hidden-costs-fraud-a-4799</link>
			<guid>http://www.inforisktoday.com/what-are-hidden-costs-fraud-a-4799</guid>
			<description>&lt;img src="http://docs.inforisktoday.com/files/images_articles/4799_austin_terry.jpg" align=right hspace=4&gt;&lt;b&gt;Hard to Put a Price on Reputation Loss, Productivity&lt;/b&gt;&lt;br&gt;One measure of an incident's impact is dollars lost of fraud. But the "soft" costs - loss of reputation and productivity - are the ones that most get the attention of Terry Austin of Guardian Analytics.</description>
			</item>
			<item>
			<title>OCC Issues Volcker Rule Proposal for Public Comment</title>
			<link>http://www.inforisktoday.com/agency-releases/occ-issues-volcker-rule-proposal-for-public-comment-r-2566</link>
			<guid>http://www.inforisktoday.com/agency-releases/occ-issues-volcker-rule-proposal-for-public-comment-r-2566</guid>
			<description>The Office of the Comptroller of the Currency requested public comment on a proposed regulation implementing the so-called "Volcker Rule" requirements of section 619 of the Dodd-Frank Wall Street Reform and Consumer Protection Act.</description>
			</item>
			<item>
			<title>FDIC: Sun Security Bank, Ellington, Mo., Closes</title>
			<link>http://www.inforisktoday.com/agency-releases/fdic-sun-security-bank-ellington-mo-closes-r-2562</link>
			<guid>http://www.inforisktoday.com/agency-releases/fdic-sun-security-bank-ellington-mo-closes-r-2562</guid>
			<description>Sun Security Bank, Ellington, Mo., was closed by the Missouri Division of Finance, which appointed the Federal Deposit Insurance Corp. as receiver.</description>
			</item>
			<item>
			<title>FDIC: The RiverBank, Wyoming, Minn., Closes</title>
			<link>http://www.inforisktoday.com/agency-releases/fdic-riverbank-wyoming-minn-closes-r-2561</link>
			<guid>http://www.inforisktoday.com/agency-releases/fdic-riverbank-wyoming-minn-closes-r-2561</guid>
			<description>The RiverBank, Wyoming, Minn., was closed by the Minnesota Department of Commerce, which appointed the Federal Deposit Insurance Corp. as receiver.</description>
			</item>
			<item>
			<title>NAFCU's Comments to Federal Reserve on Interchange Fraud Adjustment</title>
			<link>http://www.inforisktoday.com/agency-releases/nafcus-comments-to-federal-reserve-on-interchange-fraud-r-2560</link>
			<guid>http://www.inforisktoday.com/agency-releases/nafcus-comments-to-federal-reserve-on-interchange-fraud-r-2560</guid>
			<description>Fred. R. Becker Jr., president and CEO of the National Association of Federal Credit Unions, on Sept. 28, 2011, submitted comments to the Federal Reserve Board's Jennifer Johnson on its interim final rule on the fraud adjustment for debit card interchange fees.</description>
			</item>
			<item>
			<title>Synovus Bank Eliminates Cybercrime - A Case Study</title>
			<link>http://www.inforisktoday.com/webinars/synovus-bank-eliminates-cybercrime-case-study-w-277</link>
			<guid>http://www.inforisktoday.com/webinars/synovus-bank-eliminates-cybercrime-case-study-w-277</guid>
			<description>Synovus Bank, one of the largest community banks in the southeast, offers Online Cash Management services to its commercial clients with a simple pledge: "The freedom to manage your cash position anytime, anywhere." After witnessing relentless cyber-attacks on the endpoints of end users, Synovus Bank knew that meeting this pledge required them to take action. The bank's Product Development team carefully selected an endpoint security solution that met their requirements:&lt;p&gt;&lt;ul&gt;
&lt;li&gt;Satisfying FFIEC Guidelines&lt;/li&gt;
&lt;li&gt;Low customer impact/Ease of installation&lt;/li&gt;
&lt;li&gt;Proven effective, quick to implement and easy to manage&lt;/li&gt;
&lt;li&gt;Complement the bank's two tier security architecture&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;
Hear how Synovus Bank proactively prevents fraud. Kevin Gibson, Director of Product Development at Synovus Bank, explains the challenges they faced, why Trusteer Rapport was the right fit, and its ease-of-deployment. He also discusses how Trusteer's layered security helps them protect against cybercrime, as well as Trusteer's role in enabling compliance with the latest FFIEC guidance. Trusteer's Director of Product Marketing, Oren Kedem will describe Trusteer's Cybercrime Prevention Architecture and how it stops online banking fraud.</description>
			</item>
			<item>
			<title>2012 Cloud Security Agenda: Expert Insights on Security and Privacy in the Cloud</title>
			<link>http://www.inforisktoday.com/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</link>
			<guid>http://www.inforisktoday.com/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</guid>
			<description>What are organizations' top cloud security concerns, and how are security leaders addressing these concerns through policy, technology and improved vendor management?
&lt;p&gt;&lt;p&gt;
This is the key question posed by the 2012 Cloud Security Survey.
&lt;p&gt;
No longer just an emerging technology practice, cloud computing today is embraced globally as a means of gaining efficient access to critical applications, processes and storage. It's now common for organizations to rely on cloud service providers for functions and business applications such as customer relationship management, messaging or storage via a public, private or hybrid cloud. Further, industry-specific cloud-based applications such as electronic health records or mobile banking and payment applications are emerging at an unprecedented pace.
&lt;p&gt;
But these engagements come with questions about risks:
&lt;ul&gt;
&lt;li&gt;What are your cloud service provider's security and privacy measures, and have they been audited?&lt;/li&gt;
&lt;li&gt;Where geographically is cloud data being stored, and how do operational practices comply with government, industry and organizational privacy regulations?&lt;/li&gt;
&lt;li&gt;How is a multi-tenant cloud environment managed, and in the event of system compromise - what will be the incident response escalation process?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Yes, cloud computing is about efficiencies and new technologies, but it's also about security, privacy and an organization's reputation.
&lt;p&gt;
The 2012 Cloud Security Survey was crafted with assistance from leading experts in cloud computing, security and privacy, with a mission to:
&lt;ul&gt;
&lt;li&gt;Chart the latest cloud trends, including types of cloud implementations most common by industry and region;&lt;/li&gt;
&lt;li&gt;Gauge organizations' top cloud security concerns, from vendor security to data governance and breach preparedness;&lt;/li&gt;
&lt;li&gt;Predict the top areas of investment for organizations most concerned about cloud security.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
This webinar will draw upon survey results and expert insight from a special roundtable panel to discuss:
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Top Security Concerns&lt;/b&gt; - Are organizations more concerned about where their data is stored, or whether a malicious insider might be a threat to it?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Success Factors&lt;/b&gt; - On a scale with cost savings and availability of services, how does security now rank among elements critical to a successful cloud computing implementation?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Protective Measures&lt;/b&gt; - What are some of the practices organizations are employing, from instituting more stringent contracts to enforcing third-party audits and even participating in mock security exercises with cloud service providers?&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Hacktivists, BotNets and More: Top Security Trends and Threats from the HP Enterprise Security 2011 Cyber Risk Report</title>
			<link>http://www.inforisktoday.com/webinars/hacktivists-botnets-more-top-security-trends-threats-from-hp-w-274</link>
			<guid>http://www.inforisktoday.com/webinars/hacktivists-botnets-more-top-security-trends-threats-from-hp-w-274</guid>
			<description>Organizations have been under security attacks for the past decade, but the security events in 2011 have created a ripple effect that will be felt for years to come and will actually start to shift the way enterprise organizations view security. For example, 2011 saw a significant increase in activity from "hacktivist" groups Anonymous and Lulz Security (LulzSec). The motivation for these groups' organized, systematic attacks on businesses or individuals - retaliation for perceived wrongdoing - brings new visibility to a security threat that has been looming for years and highlights a new era of security risk that must be addressed. In addition, highly publicized attacks on major corporations such as Sony, RSA, and the United States Postal Service demonstrated the significant financial loss that can result from a vulnerable system. 
&lt;p&gt;&lt;p&gt;
Because unplugging the business from the Internet is not a viable security option, the question becomes: What is the best way to minimize risk to the most critical assets of the organization without interrupting or impeding business operations? Prioritization of assets and risk is essential, but so is prioritizing how and where to deploy security protection. 
&lt;p&gt;
In the 2011 top cyber security risks report, HP Enterprise Security provides a broad view of the vulnerability threat landscape, as well as in-depth research and analysis on security attacks and trends. The aim of this report is to highlight the biggest risks that enterprise organizations face today - and to help prioritize mitigation strategies. Key findings from this report include the following: 
&lt;ul&gt;
&lt;li&gt;Continued decline of new, disclosed vulnerabilities in commercial applications The report notes the decline in commercial vulnerability reporting, and it discusses the key trends in the vulnerability disclosure market that may be hiding a deeper issue. The report also highlights the growing market for private sharing of vulnerabilities, the increased expertise required to uncover complex vulnerabilities, and the price these can fetch in various markets. Data from HP Fortify will also highlight the increasing number of vulnerabilities that are being discovered in custom applications - vulnerabilities that can be devastating to the security posture of an organization.&lt;/li&gt;
&lt;li&gt;Changes in attack motivation are increasing security risk While security attackers have always sought glory and/or financial gain from their activities, the formation of hacktivist groups, like Anonymous, has added not only a purpose behind security attacks, but a level of organization as well. This shift in motivation and subsequent organization has given rise to newer and more severe security attacks. This report will highlight the motivations of today's security attack community - and the implications for security defense techniques.&lt;/li&gt;
&lt;li&gt;Increase in the number of attacks against a "smaller" set of known vulnerabilities Despite the shrinking number of known vulnerabilities in commercial applications, the report will use real data - pulled from the HP TippingPoint Intrusion Prevention System (IPS) and HP Fortify - to highlight an increase in severe attacks against both client/server and Web applications. The data is broken down by attacks, vulnerability category, source information, and severity to provide a snapshot of the attack landscape. This section also features an actual case study of the Web application risks at one large corporation.&lt;/li&gt;
&lt;li&gt;Improved techniques for executing security attacks While many targeted attacks leverage zero-day vulnerabilities, the average cyber criminal generally exploits existing vulnerabilities. Data from the report breaks down several techniques, including obfuscation, used to successfully exploit existing vulnerabilities. The report also includes an in-depth look at the Blackhole exploit toolkit, which uses many of the techniques highlighted.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Protect IBM i Data from FTP, ODBC and Remote Command</title>
			<link>http://www.inforisktoday.com/webinars/protect-ibm-i-data-from-ftp-odbc-remote-command-w-272</link>
			<guid>http://www.inforisktoday.com/webinars/protect-ibm-i-data-from-ftp-odbc-remote-command-w-272</guid>
			<description>Each year, PowerTech releases its "State of IBM i Security" study, documenting how well organizations manage their security. And, each year, the  study shows that the vast majority of organizations still rely on menu security to protect their data. Unfortunately, today's users have access to interfaces (such as FTP, ODBC, JDBC, and remote command) that completely bypass these controls and make it easy to view, update, and delete data in the database. If you need to comply with government or industry regulations, or if you simply want to ensure the integrity of your application data, understanding these interfaces is critical. 
&lt;p&gt;
In this webinar, Robin Tatam, Director of Security Technologies for PowerTech, discusses: 
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;What you need to know about IBM i security&lt;/li&gt;
&lt;li&gt;How to close the "back doors" not covered by traditional menu security schemes&lt;/li&gt;
&lt;li&gt;How to implement policies that restrict access to only those users who need it&lt;/li&gt;
&lt;/ul&gt;
Tatam also demonstrates PowerTech's Network Security, the exit point monitoring and access control software that can help you secure your system.</description>
			</item>
			<item>
			<title>Why Boards of Directors Don't Get It</title>
			<link>http://www.inforisktoday.com/interviews/boards-directors-dont-get-it-i-1569</link>
			<guid>http://www.inforisktoday.com/interviews/boards-directors-dont-get-it-i-1569</guid>
			<description>IT risk management, cyber insurance, privacy - these are hot topics for security leaders, but not for their boards of directors. Why do senior executives still fail to see IT risks as business risks?</description>
			</item>
			<item>
			<title>How to Respond to Hacktivism</title>
			<link>http://www.inforisktoday.com/interviews/how-to-respond-to-hacktivism-i-1568</link>
			<guid>http://www.inforisktoday.com/interviews/how-to-respond-to-hacktivism-i-1568</guid>
			<description>Hacktivist attacks will increase, and researcher Gregory Nowak says organizations can take proactive steps to reduce exposure and protect brand reputation. Why, then, are many organizations failing?</description>
			</item>
			<item>
			<title>4 Security Priorities for Banks</title>
			<link>http://www.inforisktoday.com/interviews/4-security-priorities-for-banks-i-1566</link>
			<guid>http://www.inforisktoday.com/interviews/4-security-priorities-for-banks-i-1566</guid>
			<description>From mobile and the cloud to DDoS attacks and risks surrounding big data, what should banks and credit unions do now to mitigate exposure? Gartner's Anton Chuvakin offers his top recommendations.</description>
			</item>
			<item>
			<title>Intelligent Defense Against Intruders</title>
			<link>http://www.inforisktoday.com/interviews/intelligent-defense-against-intruders-i-1565</link>
			<guid>http://www.inforisktoday.com/interviews/intelligent-defense-against-intruders-i-1565</guid>
			<description>Imagine a computer network that can fool intruders into seeing configurations that in reality don't exist, making it hard for them to invade the system. That's what Scott DeLoach is trying to figure out how to do.</description>
			</item>
			<item>
			<title>The Facts on Occupational Fraud</title>
			<link>http://www.inforisktoday.com/blogs/facts-on-occupational-fraud-p-1276</link>
			<guid>http://www.inforisktoday.com/blogs/facts-on-occupational-fraud-p-1276</guid>
			<description>&lt;b&gt;How to Detect and Prevent Insider Crime&lt;/b&gt;&lt;br /&gt;The statistics revealed in the ACFE's new 2012 Report on Occupational Fraud and Abuse are all very real. Here are my insights on occupational fraud and steps leaders can take to detect these crimes.</description>
			</item>
			<item>
			<title>Court Clarifies HIPAA's Criminal Rules</title>
			<link>http://www.inforisktoday.com/blogs/court-clarifies-hipaas-criminal-rules-p-1274</link>
			<guid>http://www.inforisktoday.com/blogs/court-clarifies-hipaas-criminal-rules-p-1274</guid>
			<description>&lt;b&gt;When Can You Get Prison Time?&lt;/b&gt;&lt;br /&gt;A U.S. appellate court decision in a case involving a jail term for a HIPAA violator offers an important reminder of the potential consequences for accessing patient records without a valid reason.</description>
			</item>
			<item>
			<title>The Business Case for Continuity Planning</title>
			<link>http://www.inforisktoday.com/blogs/business-case-for-continuity-planning-p-1272</link>
			<guid>http://www.inforisktoday.com/blogs/business-case-for-continuity-planning-p-1272</guid>
			<description>&lt;b&gt;Small, Mid-Size Enterprises Especially Need to Develop Strategy&lt;/b&gt;&lt;br /&gt;Why do so many small and mid-sized enterprises continue to believe that business continuity planning is just for the big guys? And how do we go about convincing them otherwise? Here are some tips.</description>
			</item>
			<item>
			<title>Measuring the Immeasurable: IT Security</title>
			<link>http://www.inforisktoday.com/blogs/measuring-immeasurable-security-p-1271</link>
			<guid>http://www.inforisktoday.com/blogs/measuring-immeasurable-security-p-1271</guid>
			<description>&lt;b&gt;A Year After Its Debut, Index of Cybersecurity Rises by 30 Percent&lt;/b&gt;&lt;br /&gt;Factors driving up the index vary from month to monthly, but the clear takeaway of the survey of IT security practitioners is that they're getting more apprehensive about safeguarding IT.</description>
			</item></channel></rss>

