<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Rook Consulting</title>
	
	<link>http://www.rookconsulting.com</link>
	<description>Simplified IT Risk Management Services</description>
	<lastBuildDate>Wed, 17 Feb 2010 20:11:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/rookconsulting/insight" /><feedburner:info uri="rookconsulting/insight" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>rookconsulting/insight</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Whiteboard Ad – Security Assessments</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/6dYXrickcP4/whiteboard-ad-security-assessments</link>
		<comments>http://www.rookconsulting.com/ads/whiteboard-ad-security-assessments#comments</comments>
		<pubDate>Wed, 17 Feb 2010 14:16:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Ads]]></category>
		<category><![CDATA[whiteboard ad]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=234</guid>
		<description><![CDATA[
Continuing our Ad Spoof series, the team thought it would be good to highlight what many of our clients consider to be the initial way we stood out to them. They tell us that before they met our team, they constantly struggled to obtain Security and Risk Assessments that were useful to BOTH IT and [...]


Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/hitech-privacy-provisions-extend-hipaa-security-rule' rel='bookmark' title='Permanent Link: HITECH Privacy Provisions Extend HIPAA Security Rule'>HITECH Privacy Provisions Extend HIPAA Security Rule</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><object width="575" height="323"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=8918913&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=ffffff&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=8918913&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=ffffff&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="575" height="323"></embed></object></p>
<p>Continuing our Ad Spoof series, the team thought it would be good to highlight what many of our clients consider to be the initial way we stood out to them. They tell us that before they met our team, they constantly struggled to obtain Security and Risk Assessments that were useful to BOTH IT and the business unit. The challenge was that most firms either provided a report that was too technical, or too focused on process and high level controls. Our reports are actionable for both IT and the business as we provide high level of technical detail in the section tailored to IT teams and we provide business risk and IT risk management decision support in the section tailored to e-staff. The result, a report that is eye opening, cost effective, actionable, and useful to both parties. </p>


<p>Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/hitech-privacy-provisions-extend-hipaa-security-rule' rel='bookmark' title='Permanent Link: HITECH Privacy Provisions Extend HIPAA Security Rule'>HITECH Privacy Provisions Extend HIPAA Security Rule</a></li>
</ol></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=6dYXrickcP4:KRgQZ3RKWyI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=6dYXrickcP4:KRgQZ3RKWyI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=6dYXrickcP4:KRgQZ3RKWyI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=6dYXrickcP4:KRgQZ3RKWyI:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/6dYXrickcP4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/ads/whiteboard-ad-security-assessments/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/ads/whiteboard-ad-security-assessments</feedburner:origLink></item>
		<item>
		<title>Urgent: New ACH and Wire Payment Trojan Facilities 100K+ Transfers From Small to Mid-Sized Banks</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/b0ZBUMApKzg/urgent-new-ach-and-wire-payment-trojan-facilities-100k-transfers-from-small-to-mid-sized-banks</link>
		<comments>http://www.rookconsulting.com/insight/urgent-new-ach-and-wire-payment-trojan-facilities-100k-transfers-from-small-to-mid-sized-banks#comments</comments>
		<pubDate>Wed, 10 Feb 2010 18:08:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Insight]]></category>
		<category><![CDATA[ACH threat]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[urgent]]></category>
		<category><![CDATA[wire fraud]]></category>
		<category><![CDATA[wire transfer threat]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=214</guid>
		<description><![CDATA[This alert is intended for small to mid-sized businesses and banks who may realize $100K plus losses associated with unauthorized external wire transfers originating within the bank from known workstations with valid user credentials. Call us at 888.712.9531 for immediate assistance.
In the past few months, we have noticed an increase in targeted attacks towards our [...]


Related posts:<ol><li><a href='http://www.rookconsulting.com/successes/over-100k-saved-for-sap-controls' rel='bookmark' title='Permanent Link: Over $100K Saved for SAP Controls'>Over $100K Saved for SAP Controls</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<blockquote><p>This alert is intended for small to mid-sized businesses and banks who may realize $100K plus losses associated with unauthorized external wire transfers originating within the bank<span id="more-214"></span> from known workstations with valid user credentials. Call us at 888.712.9531 for immediate assistance.</p></blockquote>
<p>In the past few months, we have noticed an increase in targeted attacks towards our small to mid sized banking clients using attack vectors identified in early 2009. As these attacks have increased and attackers are utilizing a new trojan that is more effective, we want to increase the awareness around this threat and provide identification and remediation options.</p>
<p><strong>Synopsis</strong><br />
The tools of choice were often from the Zeus or Clampi malware varieties. The new variant is being called Bugat (or Bredolab) and other various names by different vendors. In mid-January, the installer had moderate coverage (20/40) according to VirusTotal. The runtime behavior of the installed mspdb30.dll file did not match the normal signature, resulting in next to no AV recognition (2/41). Additionally, the AppInit_DLLs registry key setting changes made by the installer instruct Windows to load the Bugat DLL into any program that also loads user32.dll, which is commonly used by malware to infiltrate browser and email clients.</p>
<p><strong>Secureworks Description of Bugat Functionality</strong>:<br />
•	Internet Explorer (IE) and Firefox form grabbing<br />
•	Scrape or modify HTML for targeted sites<br />
•	Steal and delete IE, Firefox, and Flash cookies<br />
•	Steal FTP and POP credentials<br />
•	SOCKS proxy server (v4 and v5)<br />
•	Browse and upload files from the infected computer<br />
•	Download and execute programs<br />
•	Upload list of running processes<br />
•	Delete system files and render Windows unable to boot</p>
<p>Bugat communicates with a remote command and control web server to receive commands and to exfiltrate stolen information. As part of this process, the malware also receives a list of URL target strings used to monitor the victim’s web browser activity. These target strings indicate a strong interest in websites used for business banking and wire transfers. Bugat may also use HTTPS in an attempt to secure its command and control communications.</p>
<p><strong>Are You At Risk? </strong><br />
Rook provides the Banking community with several free and paid options for support to prevent, detect, and remove this threat from your environment.</p>
<p><strong>Free Email Based Support</strong><br />
Email team6@rookconsulting.com with a subject of &#8220;Bugat tips&#8221; to receive information on identification of the threat through known paths, and other attributes as well as high level information around determining how to collect forensic evidence to use with local law and federal law enforcement should you detect wire fraud.</p>
<p><strong>Bugat Scan &amp; Removal</strong><br />
Email team6@rookconsulting.com or call 888.712.9531 and talk to our team about our quick, cost-effective service to identify and remove the threat from your environment. For an environment with less than 100 IPs, this can be done for under $5,000 and can be charged to your corporate card.</p>
<p><strong>Holistic Security Posture Assessment</strong><br />
Identify this and other threats to your environment and receive a report providing you with a holistic view into the IT Risks associated with Policies &amp; Procedures, Network &amp; Host Based Vulnerabilities, Security Architecture and Web Application Vulnerabilities. Pricing is dependent upon a variety of factors, so please call J.J. Thompson directly at 415.695.4700 to find out the most cost effective and actionable option for your environment.</p>
<p><strong>Free Web Briefing</strong><br />
Email team6@rookconsulting.com with a subject of &#8220;bugat web briefing&#8221; and we will notify you when our web briefing schedule is finalized for sometime towards the end of this week or the beginning of next.</p>
<p>For years, the Rook team has provided clients with insight around the residual risks associated with accepting risks and audit carry forwards associated with non-standard attacks targeting banks. Unfortunately, many commodity technical security scanning providers offering ineffective &#8220;security assessments&#8221; or &#8220;penetration tests&#8221;. These vendors are well versed in technology, but are missing critical applied experience in helping clients identify, understand, and manage residual risks associated with areas of analysis that are non-technical in nature.</p>
<p>The Rook Security Posture Assessment identifies these non-standard risks and provides management with risk based decision support to maximize risk deduction through strategically precise solutions.</p>
<p>Take a moment, pick up the phone, and call us at 888.712.9531 to understand how we can help you with identifying and removing this and other IT Risks inside your organization.</p>


<p>Related posts:<ol><li><a href='http://www.rookconsulting.com/successes/over-100k-saved-for-sap-controls' rel='bookmark' title='Permanent Link: Over $100K Saved for SAP Controls'>Over $100K Saved for SAP Controls</a></li>
</ol></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=b0ZBUMApKzg:oLYMwFByCEw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=b0ZBUMApKzg:oLYMwFByCEw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=b0ZBUMApKzg:oLYMwFByCEw:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=b0ZBUMApKzg:oLYMwFByCEw:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/b0ZBUMApKzg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/insight/urgent-new-ach-and-wire-payment-trojan-facilities-100k-transfers-from-small-to-mid-sized-banks/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/insight/urgent-new-ach-and-wire-payment-trojan-facilities-100k-transfers-from-small-to-mid-sized-banks</feedburner:origLink></item>
		<item>
		<title>Whiteboard Ad – IP Football</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/l78LF1BiCo0/whiteboard-ad-ip-football</link>
		<comments>http://www.rookconsulting.com/ads/whiteboard-ad-ip-football#comments</comments>
		<pubDate>Thu, 28 Jan 2010 23:39:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Ads]]></category>
		<category><![CDATA[whiteboard ad]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=221</guid>
		<description><![CDATA[
Entering into 2010, our team decided to step up our marketing efforts yet again, and instead of the traditional letters, post cards, and direct emails, we wanted to so something that would inject a bit of fun into a somewhat less than fun subject matter. The result: the beginnings of our 2010 Ad Spoof campaign. [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p><object width="575" height="323"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=8911200&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=ffffff&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=8911200&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=ffffff&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="575" height="323"></embed></object></p>
<p>Entering into 2010, our team decided to step up our marketing efforts yet again, and instead of the traditional letters, post cards, and direct emails, we wanted to so something that would inject a bit of fun into a somewhat less than fun subject matter. The result: the beginnings of our 2010 Ad Spoof campaign. We figured the best way to kick it off would be with a football themed ad just in time for the Super Bowl. Make no mistake, we know our ads aren&#8217;t ready for t.v., but we sure did enjoy closing our laptops to brainstorm new and creative ways to share who we are and what we do with you.  This is the first in a series of many, so stay tuned! </p>
<p>We hope you enjoy! Please leave comments and ideas for future spoofs! </p>


<p>No related posts.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=l78LF1BiCo0:zOHcs5V30f8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=l78LF1BiCo0:zOHcs5V30f8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=l78LF1BiCo0:zOHcs5V30f8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=l78LF1BiCo0:zOHcs5V30f8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/l78LF1BiCo0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/ads/whiteboard-ad-ip-football/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/ads/whiteboard-ad-ip-football</feedburner:origLink></item>
		<item>
		<title>JUNOS Kernel Crash Exploit Released</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/6KQEs4H9Bfc/junos-kernel-crash-exploit-released</link>
		<comments>http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released#comments</comments>
		<pubDate>Fri, 08 Jan 2010 17:09:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Insight]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=193</guid>
		<description><![CDATA[Urgency is now increased as an exploit has been released regarding a report has been received from Juniper under bulletin PSN-2010-01-623 that a crafted malformed TCP field option in the TCP header of a packet will cause the JUNOS kernel to core (crash). In other words the kernel on the network device (gateway router) will [...]


Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/2010-outlook-coming-soon' rel='bookmark' title='Permanent Link: 2010 IT Risk Outlook Coming Soon'>2010 IT Risk Outlook Coming Soon</a></li>
<li><a href='http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable' rel='bookmark' title='Permanent Link: 3 AES-256 USB Thumb Drives Vulnerable'>3 AES-256 USB Thumb Drives Vulnerable</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Urgency is now increased as an exploit has been released regarding a report has been received from Juniper under bulletin PSN-2010-01-623 <span id="more-193"></span>that a crafted malformed TCP field option in the TCP header of a packet will cause the JUNOS kernel to core (crash). In other words the kernel on the network device (gateway router) will crash and reboot if a packet containing this crafted option is received on a listening TCP port.</p>
<blockquote><p>While our team does not usually release vulnerability alerts, this one caught our attention and as we have a large number of clients with devices running JUNOS, we felt this insight would be appropriate.</p></blockquote>
<p>The JUNOS kernel will crash (i.e. core) when a specifically crafted TCP option is received on a listening TCP port. The packet cannot be filtered with JUNOS&#8217;s firewall filter. A router receiving this specific TCP packet will crash and reboot. [CVS base score of 7.8]</p>
<p><strong>Affected Devices</strong></p>
<p>It is basically all of them save the more recent version. If you’ve installed a device with a JUNOS release version released later then 1/28/09, this issue is already corrected. Apparently the original issue and its correction did not conceive of this problem as a security vulnerability, and thus the criticality of applying the patch was not initially understood until this week.<br />
•    JUNOS 9.x<br />
•    JUNOS 7.x<br />
•    JUNOS 8.x</p>
<p>Please note the versions below were removed from the bulletin today, 01/07/09. This is likely because, as Juniper states, these are end of life versions of the OS (meaning likely still vulnerable if you happen to be running them, but out of scope for Juniper because from their standpoint these should already have been upgraded).<br />
•    JUNOS 6.x<br />
•    JUNOS 5.x<br />
•    JUNOS 3.x<br />
•    JUNOS 4.x</p>
<p><strong>The Fix </strong></p>
<p>All JUNOS software releases built on or after January 28, 2009 have fixed this specific issue. This specifically includes 8.1S2, 8.5-20090227-SR, 9.0-20090612-SR,  9.1R4, 9.2-20090130-SR, 9.2R4, , 9.3-20090227-SR, 9.3-20090212-SR, 9.3R3, 9.4R1, and all subsequent releases.</p>
<p>There are no totally effective workarounds for this specifically crafted TCP packet.  Risk can be minimized by using best common practices (BCPs) which limit TCP packets which are destined to the JUNOS device. The crafted TCP packet is spoofable, requiring <a href="http://www.ietf.org/mail-archive/web-old/ietf-announce-old/current/msg07755.html" target="_blank">IETF BCP 38 &#8220;anti-spoofing&#8221; techniques</a> to prevent a spoofed packet from entering a network. Note: If IETF BCP 38 style anti-spoofing is not feasible for all traffic, focus on anti-spoofing for the IP addresses used for the control plane, management plane, and link addresses. Packets transiting the router have no impact. The packet must be destined for an interface on the router which is listening to TCP.</p>
<p><strong>Conclusion </strong></p>
<p>Until yesterday, and exploit had not been released. Thanks to the &#8220;security firm&#8221; praetorianperfect, there is now a proof of concept exploit as well as a detailed video demonstrating the attack. Now that every high school student in America knows how to exploit this vulnerability, you may want to move this higher on your priority list.</p>
<blockquote><p>If you need assistance, please don&#8217;t hesitate to <strong>call us or reach out to the Rook partner </strong>who distributed this Rook Insight release to you.</p>
<p>Call us at 888.712.9531, email info[at]rookconsulting.net, or keep up-to-date on critical issues, alerts, and intelligence by <a href="http://www.twitter.com/rookconsulting" target="_blank">following us on Twitter</a> and subscribe to Rook Insight to receive real-time <a href="http://feedburner.google.com/fb/a/mailverify?uri=rookconsulting/insight&amp;loc=en_US">Insight Intelligence Alerts</a> via email.</p></blockquote>


<p>Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/2010-outlook-coming-soon' rel='bookmark' title='Permanent Link: 2010 IT Risk Outlook Coming Soon'>2010 IT Risk Outlook Coming Soon</a></li>
<li><a href='http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable' rel='bookmark' title='Permanent Link: 3 AES-256 USB Thumb Drives Vulnerable'>3 AES-256 USB Thumb Drives Vulnerable</a></li>
</ol></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=6KQEs4H9Bfc:SdBI61qAeiY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=6KQEs4H9Bfc:SdBI61qAeiY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=6KQEs4H9Bfc:SdBI61qAeiY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=6KQEs4H9Bfc:SdBI61qAeiY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/6KQEs4H9Bfc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released</feedburner:origLink></item>
		<item>
		<title>3 AES-256 USB Thumb Drives Vulnerable</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/3fG4bXcmH6g/3-nist-certified-thumb-drives-vulnerable</link>
		<comments>http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable#comments</comments>
		<pubDate>Fri, 08 Jan 2010 00:42:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Insight]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=186</guid>
		<description><![CDATA[Did your management team opt for a less expensive alternative to IronKeys? If so, its unfortunately time to re-visit that decision. Kingston, SanDisk, and Verbatim all have a vulnerability that allows unauthorized access to password protected, FIPS certified, AES 256-bit encrypted data on their USB thumb drives.
&#8220;Cracking the drives is therefore quite simple. The SySS [...]


Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/2010-outlook-coming-soon' rel='bookmark' title='Permanent Link: 2010 IT Risk Outlook Coming Soon'>2010 IT Risk Outlook Coming Soon</a></li>
<li><a href='http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released' rel='bookmark' title='Permanent Link: JUNOS Kernel Crash Exploit Released'>JUNOS Kernel Crash Exploit Released</a></li>
<li><a href='http://www.rookconsulting.com/insight/emc-archer-pave-way-for-2010-consolidation' rel='bookmark' title='Permanent Link: EMC &#038; Archer Pave Way for 2010 Consolidation'>EMC &#038; Archer Pave Way for 2010 Consolidation</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Did your management team opt for a less expensive alternative to IronKeys? If so, its unfortunately time to re-visit that decision. Kingston, SanDisk, and Verbatim all have a vulnerability<span id="more-186"></span> that allows unauthorized access to password protected, FIPS certified, AES 256-bit encrypted data on their USB thumb drives.</p>
<p>&#8220;Cracking the drives is therefore quite simple. The SySS experts wrote a small tool for the active password entry program&#8217;s RAM which always made sure that the appropriate string was sent to the drive, irrespective of the password entered and as a result gained immediate access to all the data on the drive. The vulnerable devices include the Kingston DataTraveler BlackBox, the SanDisk Cruzer Enterprise FIPS Edition and the Verbatim Corporate Secure FIPS Edition.&#8221; &#8211; <a href="http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html" target="_blank">H-online</a></p>
<p>The good news is that IronKey is not vulnerable. IronKey will host a webinar on this topic on Wednesday, January 13, 2010 at 10:00am PST, and Rook team members have been accessible 24/7 to address current and future client concerns about this issue. Please don&#8217;t hesitate to call us at 888.712.9531.</p>
<p>IronKey&#8217;s responses:</p>
<p>Youtube:</p>
<p><a href="http://www.youtube.com/watch?v=vVVQUnaEqpY" target="_blank">IronKey responds to encrypted USB hack</a></p>
<p>Webinar: <a>https://ironkeyevent.webex.com/ironkeyevent/onstage/g.php?d=665879884&amp;</a></p>
<blockquote><p>Call us at 888.712.9531, email info[at]rookconsulting.net, or keep up-to-date on critical issues, alerts, and intelligence by <a href="http://www.twitter.com/rookconsulting" target="_blank">following us on Twitter</a> and subscribe to Rook Insight to receive real-time <a href="http://feedburner.google.com/fb/a/mailverify?uri=rookconsulting/insight&amp;loc=en_US">Insight Intelligence Alerts</a> via email.</p></blockquote>


<p>Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/2010-outlook-coming-soon' rel='bookmark' title='Permanent Link: 2010 IT Risk Outlook Coming Soon'>2010 IT Risk Outlook Coming Soon</a></li>
<li><a href='http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released' rel='bookmark' title='Permanent Link: JUNOS Kernel Crash Exploit Released'>JUNOS Kernel Crash Exploit Released</a></li>
<li><a href='http://www.rookconsulting.com/insight/emc-archer-pave-way-for-2010-consolidation' rel='bookmark' title='Permanent Link: EMC &#038; Archer Pave Way for 2010 Consolidation'>EMC &#038; Archer Pave Way for 2010 Consolidation</a></li>
</ol></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=3fG4bXcmH6g:rPge0xddX90:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=3fG4bXcmH6g:rPge0xddX90:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=3fG4bXcmH6g:rPge0xddX90:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=3fG4bXcmH6g:rPge0xddX90:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/3fG4bXcmH6g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable</feedburner:origLink></item>
		<item>
		<title>2010 IT Risk Outlook Coming Soon</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/1f9MO_rM5nM/2010-outlook-coming-soon</link>
		<comments>http://www.rookconsulting.com/insight/2010-outlook-coming-soon#comments</comments>
		<pubDate>Tue, 05 Jan 2010 06:01:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Insight]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=177</guid>
		<description><![CDATA[Before the end of Q1 2010, Rook will release a 2010 preview that will highlight proprietary survey data on the top challenges faced in our industry as we launch the new year as well as a behind the scenes look at the movers and shakers to watch as we enter into what will likely become [...]


Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/emc-archer-pave-way-for-2010-consolidation' rel='bookmark' title='Permanent Link: EMC &#038; Archer Pave Way for 2010 Consolidation'>EMC &#038; Archer Pave Way for 2010 Consolidation</a></li>
<li><a href='http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable' rel='bookmark' title='Permanent Link: 3 AES-256 USB Thumb Drives Vulnerable'>3 AES-256 USB Thumb Drives Vulnerable</a></li>
<li><a href='http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released' rel='bookmark' title='Permanent Link: JUNOS Kernel Crash Exploit Released'>JUNOS Kernel Crash Exploit Released</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Before the end of Q1 2010, Rook will release a 2010 preview that will highlight proprietary survey data on the top challenges faced in our industry <span id="more-177"></span>as we launch the new year as well as a behind the scenes look at the movers and shakers to watch as we enter into what will likely become an exciting year.</p>
<blockquote><p>Keep up-to-date on critical issues, alerts, and intelligence by <a href="http://www.twitter.com/rookconsulting" target="_blank">following us on Twitter</a> and subscribe to Rook Insight to receive real-time <a href="http://feedburner.google.com/fb/a/mailverify?uri=rookconsulting/insight&amp;loc=en_US">Insight Intelligence Alerts</a> via email.</p></blockquote>


<p>Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/emc-archer-pave-way-for-2010-consolidation' rel='bookmark' title='Permanent Link: EMC &#038; Archer Pave Way for 2010 Consolidation'>EMC &#038; Archer Pave Way for 2010 Consolidation</a></li>
<li><a href='http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable' rel='bookmark' title='Permanent Link: 3 AES-256 USB Thumb Drives Vulnerable'>3 AES-256 USB Thumb Drives Vulnerable</a></li>
<li><a href='http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released' rel='bookmark' title='Permanent Link: JUNOS Kernel Crash Exploit Released'>JUNOS Kernel Crash Exploit Released</a></li>
</ol></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=1f9MO_rM5nM:Rwa2FdzReRI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=1f9MO_rM5nM:Rwa2FdzReRI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=1f9MO_rM5nM:Rwa2FdzReRI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=1f9MO_rM5nM:Rwa2FdzReRI:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/1f9MO_rM5nM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/insight/2010-outlook-coming-soon/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/insight/2010-outlook-coming-soon</feedburner:origLink></item>
		<item>
		<title>EMC &amp; Archer Pave Way for 2010 Consolidation</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/EOVmfYrR0fw/emc-archer-pave-way-for-2010-consolidation</link>
		<comments>http://www.rookconsulting.com/insight/emc-archer-pave-way-for-2010-consolidation#comments</comments>
		<pubDate>Tue, 05 Jan 2010 05:59:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Insight]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=175</guid>
		<description><![CDATA[Since 2001, EMC has been sitting on cash and slowly but surely playing the ultimate game of chess &#8211; working towards a checkmate in the IT solutions space. After acquiring Documentum, VMWare, RSA, Iomega, Datadomain, and now Archer, EMC is positioning to accomplish what Symantec has all but failed to do&#8230; leverage complimentary emerging leaders [...]


Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/2010-outlook-coming-soon' rel='bookmark' title='Permanent Link: 2010 IT Risk Outlook Coming Soon'>2010 IT Risk Outlook Coming Soon</a></li>
<li><a href='http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable' rel='bookmark' title='Permanent Link: 3 AES-256 USB Thumb Drives Vulnerable'>3 AES-256 USB Thumb Drives Vulnerable</a></li>
<li><a href='http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released' rel='bookmark' title='Permanent Link: JUNOS Kernel Crash Exploit Released'>JUNOS Kernel Crash Exploit Released</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Since 2001, EMC has been sitting on cash and slowly but surely playing the ultimate game of chess &#8211; working towards a checkmate in the IT solutions space. After acquiring <span id="more-175"></span>Documentum, VMWare, RSA, Iomega, Datadomain, and now Archer, EMC is positioning to accomplish what Symantec has all but failed to do&#8230; leverage complimentary emerging leaders and provide enterprises with a single vendor for IT automation, storage, and security.</p>
<p>It is possible that their latest move could be a game changer in the ITRM space with the acquisition of Archer, assuming that they will be able to overcome potential human capital, and content &amp; licensing challenges. We&#8217;ll update you with more on this potential hiccup and it&#8217;s potential impact to you once we can publicly do so.</p>
<p><a href="http://www.conference-board.org/economics/consumerConfidence.cfm" target="_blank">Consumer confidence</a> is up in December, <a href="http://online.wsj.com/article/SB124878477560186517.html" target="_blank">home prices</a> are up for the 5th month in a row, F100 CEO&#8217;s <a href="http://online.wsj.com/article/SB10001424052748704152804574627660662969326.html" target="_blank">see a light at the end of the tunnel</a>, and Indianapolis based ExactTarget has <a href="http://www.ibj.com/exacttarget-lands-another-75m-in-funding/PARAMS/article/14899" target="_blank">received $75 M in funding</a> since October. Budgets are expected to oh-so-slightly increase to <a href="http://www.cfo.com/article.cfm/14463281/?f=rsspage" target="_blank">2.5% gains, and 39% expect to add IT positions</a>.</p>
<p>It sounds like its time for us to begin seeing cash hungry industry giants make a move. Sure enough, we now have.</p>
<p>Article on EMC and Archer <a href="http://www.prnewswire.com/news-releases/emc-to-acquire-archer-technologies-leading-provider-of-it-governance-risk-and-compliance-software-80630982.html" target="_blank">here</a></p>
<blockquote><p>Call us at 888.712.9531, email info[at]rookconsulting.net, or keep up-to-date on critical issues, alerts, and intelligence by <a href="http://www.twitter.com/rookconsulting" target="_blank">following us on Twitter</a> and subscribe to Rook Insight to receive real-time <a href="http://feedburner.google.com/fb/a/mailverify?uri=rookconsulting/insight&amp;loc=en_US">Insight Intelligence Alerts</a> via email.</p></blockquote>


<p>Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/2010-outlook-coming-soon' rel='bookmark' title='Permanent Link: 2010 IT Risk Outlook Coming Soon'>2010 IT Risk Outlook Coming Soon</a></li>
<li><a href='http://www.rookconsulting.com/insight/3-nist-certified-thumb-drives-vulnerable' rel='bookmark' title='Permanent Link: 3 AES-256 USB Thumb Drives Vulnerable'>3 AES-256 USB Thumb Drives Vulnerable</a></li>
<li><a href='http://www.rookconsulting.com/insight/junos-kernel-crash-exploit-released' rel='bookmark' title='Permanent Link: JUNOS Kernel Crash Exploit Released'>JUNOS Kernel Crash Exploit Released</a></li>
</ol></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=EOVmfYrR0fw:WtxPWKf5yw4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=EOVmfYrR0fw:WtxPWKf5yw4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=EOVmfYrR0fw:WtxPWKf5yw4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=EOVmfYrR0fw:WtxPWKf5yw4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/EOVmfYrR0fw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/insight/emc-archer-pave-way-for-2010-consolidation/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/insight/emc-archer-pave-way-for-2010-consolidation</feedburner:origLink></item>
		<item>
		<title>ISC2 SecureIndianapolis</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/GPIuByZyj5Q/isc2-secureindianapolis</link>
		<comments>http://www.rookconsulting.com/newsandevents/isc2-secureindianapolis#comments</comments>
		<pubDate>Fri, 09 Oct 2009 03:34:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News-Events]]></category>
		<category><![CDATA[isc2]]></category>
		<category><![CDATA[secureindianapolis]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=147</guid>
		<description><![CDATA[Thank you, Indianapolis, for a great event! Rook practice lead J.J. Thompson sat on a panel to discuss compliance strategy &#38; managing P&#38;L for security teams along with other local thought leaders. The panel, moderated by ISC2 featured speaker Brandon Dunlap of Brightfly, discussed industry trends such as:
+ an increase in demand for security professionals [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Thank you, Indianapolis, for a great event! Rook practice lead J.J. Thompson sat on a panel to discuss compliance strategy &amp; managing P&amp;L for security teams along with <span id="more-147"></span>other local thought leaders. The panel, moderated by ISC2 featured speaker <a href="http://www.brightfly.com" target="_blank" rel="nofollow">Brandon Dunlap of Brightfly</a>, discussed industry trends such as:</p>
<p>+ an increase in demand for security professionals with marketing &amp; finance skills<br />
+ differences between West Coast and Midwest leading practices<br />
+ the impact of cloud security on outsourcing and local jobs</p>
<p>Several handouts were offered to attendees and due to an increase in follow-up requests, we will make them available practitioners who email info@rookconsulting.net with a request.</p>


<p>No related posts.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=GPIuByZyj5Q:IXaEiyd_wPc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=GPIuByZyj5Q:IXaEiyd_wPc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=GPIuByZyj5Q:IXaEiyd_wPc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=GPIuByZyj5Q:IXaEiyd_wPc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/GPIuByZyj5Q" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/newsandevents/isc2-secureindianapolis/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/newsandevents/isc2-secureindianapolis</feedburner:origLink></item>
		<item>
		<title>Cornerstones of Trust</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/Edu6030zZ3g/cornerstones-of-trust</link>
		<comments>http://www.rookconsulting.com/newsandevents/cornerstones-of-trust#comments</comments>
		<pubDate>Fri, 09 Oct 2009 03:26:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News-Events]]></category>
		<category><![CDATA[Anderson]]></category>
		<category><![CDATA[Cornerstones of Trust]]></category>
		<category><![CDATA[Dunlap]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Thompson]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/?p=144</guid>
		<description><![CDATA[Thank you for joining us for the Cornerstones of Trust conference as Rook team members and top industry thought leaders such as Niall Browne, J.J. Thompson, Brandon Dunlap, Jim Anderson, Irfan Saif, Kim Getgen, Gene Schultz and others presented on the latest and greats in IT Risk Management, Compliance, and Security. 


No related posts.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Thank you for joining us for the Cornerstones of Trust conference as Rook team members and <span id="more-144"></span>top industry thought leaders such as Niall Browne, J.J. Thompson, Brandon Dunlap, Jim Anderson, Irfan Saif, Kim Getgen, Gene Schultz and others presented on the latest and greats in IT Risk Management, Compliance, and Security. </p>


<p>No related posts.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=Edu6030zZ3g:1ui8pKyJWC4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=Edu6030zZ3g:1ui8pKyJWC4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=Edu6030zZ3g:1ui8pKyJWC4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=Edu6030zZ3g:1ui8pKyJWC4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/Edu6030zZ3g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/newsandevents/cornerstones-of-trust/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/newsandevents/cornerstones-of-trust</feedburner:origLink></item>
		<item>
		<title>Are the 26 Red Flags a Rx for Compliance?</title>
		<link>http://feedproxy.google.com/~r/rookconsulting/insight/~3/GsMvtFtHeoM/are-the-26-red-flags-a-rx-for-compliance-2</link>
		<comments>http://www.rookconsulting.com/insight/are-the-26-red-flags-a-rx-for-compliance-2#comments</comments>
		<pubDate>Mon, 14 Sep 2009 20:56:50 +0000</pubDate>
		<dc:creator>janderson</dc:creator>
				<category><![CDATA[Insight]]></category>
		<category><![CDATA[Red Flags Identity Theft Prevention Regulation]]></category>

		<guid isPermaLink="false">http://www.rookconsulting.com/uncategorized/are-the-26-red-flags-a-rx-for-compliance-2</guid>
		<description><![CDATA[Some have argued against overly focusing on the 26 Red Flags, citing the fact that the Red Flags are not prescriptive nor are they a checklist.  I have to agree with this point.  Following the 26 Red Flags myopically does not give “special protection” from regulatory enforcement.  Covered entities must conduct a self [...]


Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/identity-theft-red-flags-for-medical-providers' rel='bookmark' title='Permanent Link: Identity Theft Red Flags for Medical Providers'>Identity Theft Red Flags for Medical Providers</a></li>
<li><a href='http://www.rookconsulting.com/insight/%e2%80%98red-flag%e2%80%99-requirements-for-financial-institutions-and-creditors' rel='bookmark' title='Permanent Link: ‘Red Flag’ Requirements for Financial Institutions and Creditors'>‘Red Flag’ Requirements for Financial Institutions and Creditors</a></li>
<li><a href='http://www.rookconsulting.com/insight/ftc-red-flags-primer-screen-cast' rel='bookmark' title='Permanent Link: FTC Red Flags Primer (Screen Cast)'>FTC Red Flags Primer (Screen Cast)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Some have argued against overly focusing on the 26 Red Flags, citing the fact that the Red Flags are not prescriptive nor are they a checklist.  I have to agree with this point.  Following the 26 Red Flags myopically does not give<span id="more-128"></span> “special protection” from regulatory enforcement.  Covered entities must conduct a self assessment and incorporate their previous experiences with identity theft.  Yet, covered institutions still have a lot of flexibility in addressing the requirements of Red Flags.  In my view a prescriptive approach is without question the best place<em> to start</em> in achieving good faith compliance with Red Flags.</p>
<p>The 59-page Federal Register regulation can be broken down as follows: 2 pages of title and signature pages, 35 pages of background and discussion of earlier proposals; 22 pages of rules, which is itself 6 virtually identical sets of rules, one for each of the agencies whose regulations are being modified or amended: CofC, NCUA, OTS, FRB, FRB and FTC.  So the rules themselves are about 3.5 pages or so.  Within each rule are 3 sets of rules and an appendix.  The rules deal with (1) notices of address discrepancy, (2) id theft, and (3) changes of address.  Within these three sections are found the “must do” language of the regulations.  Analyzing the FTC section, within the address discrepancy section are 3 “musts;” within id theft are 11 “musts;” and within change of address, 2 “musts.”  Everything else is “should do” or “may do” language.  The appendix matters because at the end of the id theft section is stated: “each [covered entity]…must consider the guidelines in Appendix A of this part and include in its Program those guidelines that are appropriate.”  The seven guidelines sections contain the categories of red flags but don’t even contain the “26 Red Flags” yet.  Those are left for to a supplement of “may include examples” at the end of the appendix.</p>
<p>As with virtually all governmental regulations in our society, there are those who view these regulations as intrusive, illegal, too costly, bad policy or an ineffectual waste of time.  This is evident from the extensive commentary discussed in the preamble.  Besides good faith compliance with the rules, other coping mechanisms include malicious compliance, myopia (too narrow application of checklist), and cost minimization (just doing the barest minimum to create the illusion of compliance).  While it is quite correct to observe that the 26 Red Flags are not a checklist nor are they prescriptive (meaning that once you’ve included them you’ve done enough), under the regulation, however, covered entities “must…identify the relevant Red Flags for the covered accounts.”</p>
<p>Assuming the covered entity has selected good faith compliance rather than the other coping mechanisms, each covered entity must “consider the guidelines in [the] appendix.”  The word “consider” implies some sort of deliberation or analysis, which in order to demonstrate compliance should be documented to support definitive decisions.  Within the supplement are offered the 26 Red Flags, which entities “may consider incorporating into its program.”  I argue that given the list of Red Flags was once proposed by the regulators to be included as mandatory – based upon the identity theft experience as of 2007 – it would be far easier, faster and less costly to start with the 26, reject any that are clearly inappropriate for that organization, add any others that that institution considers necessary, and close the list until the next review.</p>
<p>An additional benefit of this approach is in dealings with third party providers.  The regulation requires covered entities to “exercise appropriate and effective oversight of service provider arrangements.”  The 26 Red Flags are the only reasonable place to start in enforcing relevant controls on service providers (in addition, of course, to the rules about address discrepancies and changes of address).  Covered entities are responsible for the compliance of the service providers who process their covered accounts.  This means service providers must know the Red Flags and have appropriate procedures to detect and respond to the red flags when they come up.  Service providers might, in theory, have a separate custom list of Red Flags for each customer they service, which would be an untenable situation for any real confrontation of identity theft.  Service providers have to have a common list (or nearly common), and covered entities should expect to pay extra if they levy additional custom Red Flags on their service providers.<br />
While the 26 Red Flags are certainly not a checklist or prescriptive, they should be regarded as a highly effective “over the counter” inoculation against a red flags violation, torturing a metaphor.  Covered entities should start with the 26 Red Flags but should also review their operations for other red flags, and include their own experience with identity theft to complete their Identity Theft Prevention Program.</p>
<p>&#8212;-</p>
<p>(This is a virtually identical post to a post made on the LinkedIn Red Flags Forum on Saturday the 12th. It is included here because many Rook clients are following Red Flags but not everyone has access to the other forum, which is for customers of LinkedIn.)</p>


<p>Related posts:<ol><li><a href='http://www.rookconsulting.com/insight/identity-theft-red-flags-for-medical-providers' rel='bookmark' title='Permanent Link: Identity Theft Red Flags for Medical Providers'>Identity Theft Red Flags for Medical Providers</a></li>
<li><a href='http://www.rookconsulting.com/insight/%e2%80%98red-flag%e2%80%99-requirements-for-financial-institutions-and-creditors' rel='bookmark' title='Permanent Link: ‘Red Flag’ Requirements for Financial Institutions and Creditors'>‘Red Flag’ Requirements for Financial Institutions and Creditors</a></li>
<li><a href='http://www.rookconsulting.com/insight/ftc-red-flags-primer-screen-cast' rel='bookmark' title='Permanent Link: FTC Red Flags Primer (Screen Cast)'>FTC Red Flags Primer (Screen Cast)</a></li>
</ol></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=GsMvtFtHeoM:pTPnk70MKcU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=GsMvtFtHeoM:pTPnk70MKcU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?i=GsMvtFtHeoM:pTPnk70MKcU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/rookconsulting/insight?a=GsMvtFtHeoM:pTPnk70MKcU:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/rookconsulting/insight?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/rookconsulting/insight/~4/GsMvtFtHeoM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.rookconsulting.com/insight/are-the-26-red-flags-a-rx-for-compliance-2/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.rookconsulting.com/insight/are-the-26-red-flags-a-rx-for-compliance-2</feedburner:origLink></item>
	</channel>
</rss>
