<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The Garland Group Blog</title>
	
	<link>http://www.thegarlandgroup.net</link>
	<description>We try to stay very transparent with our company so this blog discussed topics from things going on in the company to topics on the services we provide which are IT security, compliance, banking, and web application development.</description>
	<lastBuildDate>Wed, 11 Nov 2009 13:00:21 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<geo:lat>33.011975</geo:lat><geo:long>-96.536072</geo:long><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/thegarlandgroup" type="application/rss+xml" /><feedburner:emailServiceId>thegarlandgroup</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>Security Buzz Words | Money Mules</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/yD-0HA1-MgM/</link>
		<comments>http://www.thegarlandgroup.net/2009/11/11/security-buzz-words-money-mules/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 13:00:21 +0000</pubDate>
		<dc:creator>eric</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA["multi-factor authentication"]]></category>
		<category><![CDATA[Online Banking]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1105</guid>
		<description><![CDATA[
An interesting article in Wired drew my attention to this post on the Internet Crime Complaint Center (IC3) website.  Here&#8217;s the Cliff Notes version:   Bad people put malware consisting of remote control software and key loggers on a targeted business user&#8217;s computer.  They gather ID&#8217;s and passwords and other authentication data. The bad people [...]]]></description>
			<content:encoded><![CDATA[<p><img align=right width=300 height=182 hspace=5 vspace=5 src="http://www.newrider.com/Library/How_it_Was/mules2.jpg" alt="" /></p>
<p>An interesting article in Wired drew my attention to <a href="http://www.ic3.gov/media/2009/091103-1.aspx">this post</a> on the I<span style="font-style: normal">nternet Crime Complaint Center</span> (<abbr title="Internet Crime Complaint Center"><span style="font-style: normal">IC3</span></abbr>) website.  Here&#8217;s the Cliff Notes version:   Bad people put malware consisting of remote control software and key loggers on a targeted business user&#8217;s computer.  They gather ID&#8217;s and passwords and other authentication data. The bad people then use the backdoor into the customers machine to initiate wire transfers and ACH transactions to (here&#8217;s that new buzz word) <em>Money Mules </em>who have been duped into &#8220;work at home&#8221; schemes and are tasked with transferring funds received to the offshore accounts of the aforementioned bad people.</p>
<p>Unfortunately we&#8217;ve seen this before.  In fact, the only forms of fraud or security breaches we&#8217;ve seen has been with this sort of activity where the end user&#8217;s machine has been compromised and used to initiate wire transfer or ACH originations.  Equally as unfortunate, the recommendation from the IC3 and guidance from federal and state regulators leave a huge gap that makes financial institutions and their customers vulnerable.</p>
<p>In the security biz we call that <strong>&#8220;residual risk&#8221;</strong> &#8211;  that is, the risk or danger of something occurring, after mitigating steps are applied.  Here the mitigating steps suggested are <em>Signature-Based Intrusion Detection and Anti-Virus Systems </em>(IC3) and  <em>financial institutions should implement multi-factor authentication, layered security, or other controls reasonably calculated to mitigate those risks </em>(FFIEC).  Those both sound great, the trouble though is 1) effective IDS hard to implement and usually expensive and 2) the multi-factor authentication mechanisms provided by online banking vendors are woefully lacking in any reasonable means to authenticate users.</p>
<p>I hear the rebuttal from financial institutions all the time: &#8220;customers hate it&#8221; &#8220;we have challenge questions and certificates placed on the users machine&#8221;, &#8220;we have a picture the user chooses&#8221; and &#8221;we&#8217;re using everything that vendor provides&#8221;.  I&#8217;ll focus on the 2nd and 3rd first; neither of these options mitigate the vulnerabilities identified.  Certificates, challenge questions and site identification pictures have been in place were this type of fraudulent activity has occurred.  The bottom line is this: if an attacker has access to a users machine those types of authentication measures are easily defeated.</p>
<p>The first and last comments we hear (customer acceptance and vendor supplied options) rely on education of your customers: explaining that authentication measures are imposed for their protection; and taking ownership of risks presented by the offerings you present to customers.</p>
<p>So what&#8217;s the mitigation strategy that bridges the gap?  Evaluating true 2nd factor authentication for high risk transactions.  In every instance we&#8217;ve come across, the use of RSA style tokens for authentication would have prevented the attacker from gaining access to the customers online banking accounts.  Does your financial institution have business customers that initiate wires and ACH transactions from their workstations? Are you prepared to assume the risk of lost funds and the resources required to address such a breach?  If you don&#8217;t offer true 2nd factor authentication for high risk clients maybe it&#8217;s time to address that residual risk.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=yD-0HA1-MgM:mGDHckom0TE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=yD-0HA1-MgM:mGDHckom0TE:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=yD-0HA1-MgM:mGDHckom0TE:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/11/11/security-buzz-words-money-mules/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/11/11/security-buzz-words-money-mules/</feedburner:origLink></item>
		<item>
		<title>Compliance lessons from Kobe Bryant?</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/t5u3j4XLSTY/</link>
		<comments>http://www.thegarlandgroup.net/2009/11/09/compliance-lessons-from-kobe-bryant/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 15:16:24 +0000</pubDate>
		<dc:creator>natasha</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[basketball]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[proactive]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1094</guid>
		<description><![CDATA[
Despite my disdain for Kobe Bryant (it has nothing to do with him and everything to do with his team; sorry I am not a Laker fan) I learned something about compliance from him this past week.  Kobe is a great basket ball player, an MVP with four championship rings, yet he is always looking [...]]]></description>
			<content:encoded><![CDATA[<p><img align=right height=250 width=210 hspace=5 vspace=5 src="http://images.smarter.com/blogs/kobe24.jpg" alt="MVP" /><code></p>
<p>Despite my disdain for Kobe Bryant (it has nothing to do with him and everything to do with his team; sorry I am not a Laker fan) I learned something about compliance from him this past week.  Kobe is a great basket ball player, an MVP with four championship rings, yet he is always looking to improve his game.  Instead of becoming complacent, with his rings and MVP title, this past summer he sought the help of another great, Hakeem Olajuwon, to help him with his game.   Wow, what passion, humility and drive.</p>
<p>I immediately thought of the stamp of approval we get from regulatory auditors. <strong>Compliant!</strong> That’s our MVP title – FFIEC compliant, PCI complaint, HIPAA Compliant.  Unfortunately as soon as the auditor leaves a new season starts and that title becomes obsolete.  As a result organizations must make security a priority and strive to be compliant not just during audit ‘season’, but <strong>EVERYDAY</strong>. There is always a new threat, a new virus and a new scam. Let’s take a page from Kobe’s book and approach our security initiatives with passion, drive and diligence. Let’s not get complacent with ‘titles’ and check marks but use them to challenge us to keep our customer data safe. Let’s make security and compliance continuous.  </p>
<p>Perhaps I don’t dislike Kobe as much after all….hmmm</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=t5u3j4XLSTY:pPpoUEwxlvc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=t5u3j4XLSTY:pPpoUEwxlvc:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=t5u3j4XLSTY:pPpoUEwxlvc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/11/09/compliance-lessons-from-kobe-bryant/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/11/09/compliance-lessons-from-kobe-bryant/</feedburner:origLink></item>
		<item>
		<title>Facebook/Myspace: Being Social via Security Holes</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/N8i-Pt3tvZA/</link>
		<comments>http://www.thegarlandgroup.net/2009/11/09/facebookmyspace-being-social-via-security-holes/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 14:00:29 +0000</pubDate>
		<dc:creator>court</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[ajax]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1078</guid>
		<description><![CDATA[
The short of this article is that allowing flash applications in facebook/myspace is similar to the security issues we see with running &#8220;ajax&#8221; in browsers.
The long of the article is that an application is allowed to execute code within the flash environment.  Normally, this behavior is limited to the local flash environment so the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.sickfacebook.com/images/facebook_Confidential.jpg" alt="Facebook Security" /></p>
<p>The short of <a href="http://www.yvoschaap.com/index.php/weblog/facebook_myspace_accounts_hijacked/">this article</a> is that allowing flash applications in facebook/myspace is similar to the security issues we see with running &#8220;ajax&#8221; in browsers.</p>
<p>The long of the article is that an application is allowed to execute code within the flash environment.  Normally, this behavior is limited to the local flash environment so the threat is limited.  However, it has recently been discovered that there are ways to reach outside of the environment and access other domains.  Aside from the obvious risk, there is the side effect that any attacks executed this way would appear to be perpetrated by the victim&#8217;s account rather than the attacker.  Myspace and Facebook appear to be acting quickly to resolve the issue.</p>
<p>This brings into question once again the security versus productivity debate. You can prevent access to these sites and thereby sidestep the security risks.  However, locking the sites down may result in losing talented individuals to other companies that do allow access to these sites.  The only right answer is the answer your organization comes to after appropriate risk assessment.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=N8i-Pt3tvZA:anK4P02aoB0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=N8i-Pt3tvZA:anK4P02aoB0:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=N8i-Pt3tvZA:anK4P02aoB0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/11/09/facebookmyspace-being-social-via-security-holes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/11/09/facebookmyspace-being-social-via-security-holes/</feedburner:origLink></item>
		<item>
		<title>Sponsored Post: What is OFM?</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/qkx_mENRDn0/</link>
		<comments>http://www.thegarlandgroup.net/2009/11/05/sponsored-post-what-is-ofm/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 20:26:43 +0000</pubDate>
		<dc:creator>The Community</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[financeworks]]></category>
		<category><![CDATA[intuit]]></category>
		<category><![CDATA[ofm]]></category>
		<category><![CDATA[pfm]]></category>
		<category><![CDATA[sponsor]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1081</guid>
		<description><![CDATA[
OFM — Online Financial Management — applications are the next step beyond PFM (personal financial management) programs. For community and mid-market banks and credit unions trying to compete with top-5 national institutions, offering an OFM application on their online banking site can be a huge differentiator. According to Digital Insight’s 2nd Annual Online Financial Management [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.thegarlandgroup.net/assets//2009/11/eu_top_logo.jpg" alt="eu_top_logo" title="eu_top_logo" width="181" height="23" class="alignnone size-full wp-image-1082" /></p>
<p>OFM — <em>Online Financial Management</em> — applications are the next step beyond PFM (personal financial management) programs. For community and mid-market banks and credit unions trying to compete with top-5 national institutions, offering an OFM application on their online banking site can be a huge differentiator. According to Digital Insight’s 2nd Annual <a href="http://bit.ly/OFMsurvey">Online Financial Management survey</a>, 80% of consumers want to manage their own finances online with their financial institution, an increase from 68% in 2008.</p>
<p>At Digital Insight, we define OFM as applications that expand the PFM concept to also include programs for small business owners such as invoicing, payroll, and preparation of legal forms. This is particularly attractive to the nearly 23 million US small businesses that have less than 5 employees and to the 41% of Americans who run a small business in addition to their main job.<em>[1] </em></p>
<p>For consumers and small business owners, the key attractions of OFM include aggregation — the ability to manage all their finances and many of their business functions on one Web site with one log in — as well as greater control of their finances with planning and budget management features, and the security of using a site hosted by their financial institution.</p>
<p>In our research with our own OFM products, <a href="http://ofm.financeworks.com/fw_0.php?u=di4af23724299e6&#038;c=bai">FinanceWorks<sup>TM</sup></a> and Small Business <a href="http://ofm.financeworks.com/sbfw_0.php?u=di4af23724299e6&#038;c=bai">FinanceWorks<sup>TM</sup></a>, we’ve seen nearly 80% of FW users say the product has made them more likely to stay with their bank or credit union and recommend it to others. FinanceWorks users are 4x more profitable than the average customer, and they hold 30% more outstanding loans. So we view OFM offerings as delivering a significant competitive advantage, especially for mid-market financial institutions trying to compete with huge national firms. </p>
<p>We’re interested in the community’s thoughts on this subject and what your experiences with OFM, if any, have been.  For those that offer OFM products to their customers, what are the trends you&#8217;re seeing? What motivated you to offer these products? If you’re not offering OFM, are you considering it? If so, how is the evaluation process going? At the BAI Retail Delivery conference? Stop by booth #801 to learn more or visit <a href="http://financeworks.com/banktastic">ofm.financeworks.com</a>.</p>
<p><em>[1] <a href="http://www.digitalinsight.com/home/media/press#2009">Digital Insight February 10, 2009 Press Release</a></em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=qkx_mENRDn0:3-pmj_rXZTI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=qkx_mENRDn0:3-pmj_rXZTI:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=qkx_mENRDn0:3-pmj_rXZTI:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/11/05/sponsored-post-what-is-ofm/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/11/05/sponsored-post-what-is-ofm/</feedburner:origLink></item>
		<item>
		<title>Collaboration Is Key To Increased Efficiency In Manufacturing</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/upTngEsBM34/</link>
		<comments>http://www.thegarlandgroup.net/2009/11/05/collaboration-is-key-to-increased-efficiency-in-manufacturing/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 15:20:05 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[collaboration]]></category>
		<category><![CDATA[informationweek]]></category>
		<category><![CDATA[maufacturing]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/2009/11/05/collaboration-is-key-to-increased-efficiency-in-manufacturing/</guid>
		<description><![CDATA[This article from InformationWeek is about Manufactoring. But, the principles apply to any organization attempting to increase their effectiveness with customers, vendors, partners, and other internal business units According to this article by Mary Hayes Weier, Manufactoring is ahead of the game.
 But , any organization that recognizes the reduce costs that come from a [...]]]></description>
			<content:encoded><![CDATA[<p>This article from InformationWeek is about Manufactoring. But, the principles apply to any organization attempting to increase their effectiveness with customers, vendors, partners, and other internal business units According to this article by Mary Hayes Weier, Manufactoring is ahead of the game.
<p /> But , any organization that recognizes the reduce costs that come from a Central Risk Management Program should also recognize that Continuous Compliance is achieved by installing collaboration into the culture.<br /><a href="http://bit.ly/c21iy">http://bit.ly/c21iy</a>
<p style="font-size: 10px;">  Posted via email  </p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=upTngEsBM34:d3sEP6-ZIlU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=upTngEsBM34:d3sEP6-ZIlU:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=upTngEsBM34:d3sEP6-ZIlU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/11/05/collaboration-is-key-to-increased-efficiency-in-manufacturing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/11/05/collaboration-is-key-to-increased-efficiency-in-manufacturing/</feedburner:origLink></item>
		<item>
		<title>Live Science: How to Avoid the FDIC Email Scam</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/XE3FOAwF0Fs/</link>
		<comments>http://www.thegarlandgroup.net/2009/11/05/live-science-how-to-avoid-the-fdic-email-scam/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 15:18:03 +0000</pubDate>
		<dc:creator>natasha</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[fdic]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1051</guid>
		<description><![CDATA[By Leslie Meredith
&#8220;Stop, think, delete &#38; play hard to get&#8221; &#8211; This makes it sound so very easy yet many are sucked in by phishing scams &#8211; daily.  No matter how tech savvy we are none of us are immune! The &#8220;hard to get&#8221; email address advice in the article is quite interesting.  The thing [...]]]></description>
			<content:encoded><![CDATA[<p>By Leslie Meredith</p>
<p><strong><a href="http://bit.ly/2SANNl">&#8220;Stop, think, delete &amp; play hard to get&#8221;</a></strong> &#8211; This makes it sound so very easy yet many are sucked in by phishing scams &#8211; daily.  No matter how tech savvy we are none of us are immune! The &#8220;hard to get&#8221; email address advice in the article is quite interesting.  The thing is, I have had my email address since college (a longgggg time ago) and changing it now doesn&#8217;t sit well with me. Hmmmph&#8230;. food for thought. Would love to hear any other great tips!</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=XE3FOAwF0Fs:4Ts8wOba_pY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=XE3FOAwF0Fs:4Ts8wOba_pY:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=XE3FOAwF0Fs:4Ts8wOba_pY:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/11/05/live-science-how-to-avoid-the-fdic-email-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/11/05/live-science-how-to-avoid-the-fdic-email-scam/</feedburner:origLink></item>
		<item>
		<title>Hello, this is Chuck.  Can I have your PIN and Debit Card Number?</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/w1YW9eUqGU0/</link>
		<comments>http://www.thegarlandgroup.net/2009/11/04/hello-this-is-chuck-can-i-have-your-pin-and-debit-card-number/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 15:04:53 +0000</pubDate>
		<dc:creator>Heath</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[BankInfoSecurity]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[PIN]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1070</guid>
		<description><![CDATA[
Ran across this article today on BankInfoSecurity.com and reminded me that we have seen this simple scam recently too.  At banks where we have seen this it looks like the phishers are just finding phone numbers in the phone book or local directories, picking a financial institution and calling all the people in the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm3.static.flickr.com/2078/1620195364_13c578022a_o_d.png" alt="" /></p>
<p>Ran across <a href="http://www.bankinfosecurity.com/articles.php?art_id=1901">this article</a> today on BankInfoSecurity.com and reminded me that we have seen this simple scam recently too.  At banks where we have seen this it looks like the phishers are just finding phone numbers in the phone book or local directories, picking a financial institution and calling all the people in the phone book, even if they aren&#8217;t the bank&#8217;s customers.  The call is automated and sounds something like this&#8230;</p>
<blockquote><p><em>&#8220;Hello, we are calling on behalf of (Insert FI Name Here) and want to confirm some recent purchases posted to your account.  Will you please type in your PIN and Debit Card number with the 10 Digit keypad&#8230;..&#8221;</em></p></blockquote>
<p>This doesn&#8217;t work for many accounts, but all they need to do is have two successful hits and it pays for itself.  The calls come from a hosted data center, and can be shut down fairly easily by the FBI, but are rarely tracked back to the fraudsters. The calls are usually shut down within a few hours at no cost to the financial institution, unless some customers fell for it.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=w1YW9eUqGU0:KQRhVQ-u180:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=w1YW9eUqGU0:KQRhVQ-u180:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=w1YW9eUqGU0:KQRhVQ-u180:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/11/04/hello-this-is-chuck-can-i-have-your-pin-and-debit-card-number/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/11/04/hello-this-is-chuck-can-i-have-your-pin-and-debit-card-number/</feedburner:origLink></item>
		<item>
		<title>RiskKey – Better Notifications and Private Messages</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/x6QCRA703JU/</link>
		<comments>http://www.thegarlandgroup.net/2009/11/02/riskkey-better-notifications-and-private-messages/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 12:00:41 +0000</pubDate>
		<dc:creator>Brad</dc:creator>
				<category><![CDATA[RiskKey]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[features]]></category>
		<category><![CDATA[messages]]></category>
		<category><![CDATA[notifications]]></category>
		<category><![CDATA[private]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1064</guid>
		<description><![CDATA[Since our new release at the beginning of October we&#8217;ve been working hard on getting the features you requested done.  Two of the most asked for features we are happy to announce are now live.
1) Private Messages

In our messages section you always had a way to post a message to anyone that had access [...]]]></description>
			<content:encoded><![CDATA[<p>Since <a href="http://www.thegarlandgroup.net/2009/10/06/continuous-compliance-riskkey-platform-launch/">our new release</a> at the beginning of October we&#8217;ve been working hard on getting the features you requested done.  Two of the most asked for features we are happy to announce are now live.</p>
<p><strong>1) Private Messages</strong></p>
<p><img src="http://img.skitch.com/20091103-j7r3b294f2smksihcrm1ebrcgb.png" alt="IT Compliance (for demo purposes) | Messages - (Build 20091016081620)"/></p>
<p>In our messages section you always had a way to post a message to anyone that had access to the project but now we have a &#8216;private&#8217; message feature that will allow you to post just to the people that are apart of your company only.  We want it to be easy for you to share both public and private documents with your company and clients.  Now you can do both!</p>
<p><strong>2)Detailed Email Notifications</strong></p>
<p>We first built email notification to be very cautious of privacy and security with very limited information. But the community has spoken and you told us that you wanted a wee bit more information in those emails so we now give you both abilities.  All you have to do is go to the Settings tab of the project your in and check this box.  After that all your messages, resolutions, notifications will come with more detailed emails.  </p>
<p><img src="http://img.skitch.com/20091103-p4sngan53xrj4a1g1ni6rtr92n.png" alt="IT Compliance (for demo purposes) | IT Compliance (for demo purposes) - (Build 20091016081620)"/></p>
<p>We aim to please so please continue to <a href="https://thegarlandgroup.uservoice.com/pages/25474-general">submit your feedback and features</a>!</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=x6QCRA703JU:sYvKHxu4YQc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=x6QCRA703JU:sYvKHxu4YQc:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=x6QCRA703JU:sYvKHxu4YQc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/11/02/riskkey-better-notifications-and-private-messages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/11/02/riskkey-better-notifications-and-private-messages/</feedburner:origLink></item>
		<item>
		<title>Continuous Compliance FAQ’s</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/rw_P9h8ZKIA/</link>
		<comments>http://www.thegarlandgroup.net/2009/10/29/continuous-compliance-faqs/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 17:54:04 +0000</pubDate>
		<dc:creator>Heath</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Audit Schedule]]></category>
		<category><![CDATA[continuous compliance]]></category>
		<category><![CDATA[Pricing]]></category>
		<category><![CDATA[Technology Committee]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1053</guid>
		<description><![CDATA[Thanks to a successful launch and well developed program, we now have eight Continuous Compliance clients and several more pending approval from Audit Committees.  When I am explaining our new service to clients and their committees I hear the same questions regularly&#8230;.
1)  How much more does this cost? SAME PRICE. Our Continuous Compliance process is just [...]]]></description>
			<content:encoded><![CDATA[<p>Thanks to a successful launch and well developed program, we now have eight <a href="http://www.thegarlandgroup.net/services/continuous-compliance-service/">Continuous Compliance</a> clients and several more pending approval from Audit Committees.  When I am explaining our new service to clients and their committees I hear the same questions regularly&#8230;.</p>
<p>1)  How much more does this cost? <strong>SAME PRICE.</strong> Our Continuous Compliance process is just a methodology change.  We are able to keep the process the same cost by proactively addressing risk in Technology Committee Meetings, reviewing low risk areas less than annually and regularly following up with findings (this process usually takes up quite a bit of time during a one week engagement.</p>
<p>2)  Why do you want to be in on Technology Committee meetings?  We would like to participate in these meetings to know what is happening within the environment and proactively address potential risk areas.  For example, if you are going to rollout remote deposit for commercial customers, we can be sure a risk assessment has been conducted, policies approved, etc. before they become ‘findings’.</p>
<p>3)  What do the examiners think about Continuous Compliance?  I’ve spoken with several examiners and a couple of them actually, prefer this process to what we currently do.  They always say the disclaimer, as long as everything that needs to be reviewed annually is done, then they are fine with it.  That is why we will always do the Information Security section and ensuring your policy/procedures are approved annually.</p>
<p>4)  What about reports?  Two things here, we’ll be using <a href="http://thegarlandgroup.net/riskkey">RiskKey</a> to manage this process so all of our reports will come out of here.  So we will provide regular reports out of RiskKey to discuss in Technology or Audit Committees.  Next, since we are regularly interacting with clients, all you need to do is just let us know you would like some formal reports for examiners and we can put together the most up-to-date reports,  so if you have addressed risk areas recently, they won’t show up as risk areas in the most up to date reports.</p>
<p>5)  How did you develop the <a href="http://content.screencast.com/users/lachazzz/folders/Jing/media/a57e2f9b-f365-48f3-8aab-24783793d6ab/00000006.png" rel="lightbox[1053]">Technology Audit Schedule</a>?  We risk rated the sections based on our last full week type of audit.  This is where we currently see your risk structure as.  We also base it off of industry trends and overall risk structure of the section for <em>all</em> financial institutions.  If you think it is different then let us know.  The timelines to complete audits are negotiable, but risk ratings are not.  For example, we have one client that wants their Website audited annually, even though we said it was a low risk which means it only needs to be reviewed every 18 months. No problem!  We’ll also review sections that have major updates or conversions, so if you change wire systems, we’ll do a wire audit after conversion.</p>
<p>Those are the questions I answer most frequently, but let us know if you have anymore.  We&#8217;re here to help!</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=rw_P9h8ZKIA:hCcPX2ISwzY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=rw_P9h8ZKIA:hCcPX2ISwzY:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=rw_P9h8ZKIA:hCcPX2ISwzY:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/10/29/continuous-compliance-faqs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/10/29/continuous-compliance-faqs/</feedburner:origLink></item>
		<item>
		<title>ABA Commends the FTC for efforts to protect consumers</title>
		<link>http://feedproxy.google.com/~r/thegarlandgroup/~3/yUOdBBd85pA/</link>
		<comments>http://www.thegarlandgroup.net/2009/10/27/aba-commends-the-ftc-for-efforts-to-protect-consumers/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 00:12:44 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[ABA]]></category>
		<category><![CDATA[consumer]]></category>
		<category><![CDATA[ftc]]></category>
		<category><![CDATA[protection]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/2009/10/27/aba-commends-the-ftc-for-efforts-to-protect-consumers/</guid>
		<description><![CDATA[The ABA commends the FTC for its continuing efforts to protect consumers from unscrupulous debt relief service providers through enforcement actions, consumer education initiatives, and the proposed amendment of the TSR.  The ABA support using  FTC’s proposed application of its targeted TSR authority to regulate the for-profit debt settlement industry. http://bit.ly/1CfrHd
  Posted via [...]]]></description>
			<content:encoded><![CDATA[<p>The ABA commends the FTC for its continuing efforts to protect consumers from <br />unscrupulous debt relief service providers through enforcement actions, consumer <br />education initiatives, and the proposed amendment of the TSR.  The ABA support using <br /> FTC’s proposed application of its targeted TSR authority to regulate the for-profit <br />debt settlement industry. <br /><a href="http://bit.ly/1CfrHd">http://bit.ly/1CfrHd</a>
<p style="font-size: 10px;">  Posted via email  </p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=yUOdBBd85pA:NS5NYGyNuic:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=yUOdBBd85pA:NS5NYGyNuic:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/thegarlandgroup?a=yUOdBBd85pA:NS5NYGyNuic:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/thegarlandgroup?d=7Q72WNTAKBA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2009/10/27/aba-commends-the-ftc-for-efforts-to-protect-consumers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thegarlandgroup.net/2009/10/27/aba-commends-the-ftc-for-efforts-to-protect-consumers/</feedburner:origLink></item>
	</channel>
</rss>
