<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.csoboard.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.csoboard.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
<channel>
<title>Jaime Chanaga, CISSP, CISA</title>
<link>http://blog.csoboard.com/cso/</link>
<description>Jaime Chanaga, is CEO of The CSO Board LLC, a management consulting firm dedicated to helping leaders and organizations solve critical strategic issues and make lasting substantial improvements in their performance.  Mr. Chanaga is a Certified Information Systems Security Professional (CISSP) and a Certified Information Systems Auditor (CISA).
</description>
<language>en-US</language>
<lastBuildDate>Thu, 13 Mar 2008 23:08:36 -0500</lastBuildDate>
<generator>http://www.typepad.com/</generator>

<docs>http://www.rssboard.org/rss-specification</docs>
<meta xmlns="http://pipes.yahoo.com" name="pipes" content="noprocess" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.csoboard.com/chiefsecurityofficer" type="application/rss+xml" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">1618419</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://www.feedburner.com</feedburner:feedburnerHostname><item>
<title>Harvard Hacker Breach Exposes Information On 10,000 Graduates Students And Applicants</title>
<link>http://blog.csoboard.com/cso/2008/03/harvard-hacker.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/03/harvard-hacker.html</guid>
<description>The Associated Press is reporting (link) that Harvard University has suffered a serious data breach. Harvard has acknowledged that a hacker breached on of their computer servers. The server contained the personal information on approximately 10,000 graduate school applicants. The...</description>
<content:encoded><![CDATA[<p>The Associated Press is reporting (<a href="http://ap.google.com/article/ALeqM5gDAp9foc9QjlClu331bCMJr3xwDAD8VCI0VO0">link</a>) that Harvard University has suffered a serious data breach.&nbsp; Harvard has acknowledged that a hacker breached on of their computer servers. The server contained the personal information on approximately <strong>10,000</strong> graduate school applicants.&nbsp; &nbsp;<strong>The data contained approximately 6,600 social security numbers of some of the applicants and students.</strong></p>

<p><strong>Harvard Graduate School of Arts and Sciences</strong><br /><a href="http://www.news.harvard.edu/gazette/2008/03.13/99-hacked.html">http://www.news.harvard.edu/gazette/2008/03.13/99-hacked.html</a></p>

<p><strong>Boston Globe - Harvard student, applicant files breached</strong><br /><a href="http://www.boston.com/news/education/higher/articles/2008/03/13/harvard_student_applicant_files_breached/">http://www.boston.com/news/education/higher/articles/2008/03/13/harvard_student_applicant_files_breached/</a></p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=Ma97RnF"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=Ma97RnF" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=59qbGYf"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=59qbGYf" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=A5DPhjf"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=A5DPhjf" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/251170173" height="1" width="1"/>]]></content:encoded>


<category>Current Affairs</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Thu, 13 Mar 2008 23:08:36 -0500</pubDate>

</item>
<item>
<title>Tenet Healthcare Corp (NYSE: THC) Identity Theft By Ex-Employee May Affect 40,000 Patients </title>
<link>http://blog.csoboard.com/cso/2008/02/tenet-healthcar.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/02/tenet-healthcar.html</guid>
<description>Tenet Healthcare Corporation (NYSE: THC) has mailed letters to 40,000 patients at 54 hospitals nationwide that their personal information including social security numbers may have been stolen by an ex-employee, Terrance Brooks, at Tenet's billing center in Frisco, Texas. Terrance...</description>
<content:encoded><![CDATA[<p>Tenet Healthcare Corporation (NYSE: THC) has mailed letters to 40,000 patients at 54 hospitals nationwide that their personal information including social security numbers may have been stolen by an ex-employee, Terrance Brooks, at Tenet's billing center in Frisco, Texas.&nbsp; </p>

<p>Terrance Brooks, convicted of this identity theft crime had access to Tenet's billing systems which stored patient's personal data including birth data and social security numbers.&nbsp; According to some news reports, the Brooks was arrested on November 25 after attempting to open a credit card account at a Costco store.&nbsp; In his possession were data records on 90 patients.&nbsp; Tenet called those patients immediately and has taken the precautionary step of informing the 40,000 patients who's data could have been accessed by Brooks during his employment.</p>

<p>No company can prevent 100% of insider attacks on their information systems or data by employees.&nbsp; However, companies can do more and increase their employee education, monitoring, and implement stronger policies and controls to ensure that these types of incidents are minimized.</p>

<p><strong><br />South Florida Sun-Sentinel</strong><br /><a href="http://www.sun-sentinel.com/news/local/palmbeach/sfl-flpfraud0214sbfeb14,0,42801.story">http://www.sun-sentinel.com/news/local/palmbeach/sfl-flpfraud0214sbfeb14,0,42801.story</a></p>

<p><strong>Darkreading</strong><br /><a href="http://www.darkreading.com/document.asp?doc_id=146095">http://www.darkreading.com/document.asp?doc_id=146095</a></p>

<div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=IHscT8E"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=IHscT8E" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=lFzfiFe"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=lFzfiFe" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=IWXf2de"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=IWXf2de" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/236829471" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Mon, 18 Feb 2008 00:34:49 -0600</pubDate>

</item>
<item>
<title>Google, Inc. (NASDAQ: GOOG) Launches E-mail Security Services For Business</title>
<link>http://blog.csoboard.com/cso/2008/02/google-inc-nasd.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/02/google-inc-nasd.html</guid>
<description>Google, Inc. (NASDAQ: GOOG) announced (http://www.google.com/intl/en/press/pressrel/20080205_securityservices.html) several new security services for e-mail powered by Postini™. The new services provide inbound and outbound message filtering, encryption, and message archiving capabilities for business. Services start at $3 per user per year. Providing...</description>
<content:encoded><![CDATA[<p>Google, Inc. (NASDAQ: GOOG) announced (<a href="http://www.google.com/intl/en/press/pressrel/20080205_securityservices.html">http://www.google.com/intl/en/press/pressrel/20080205_securityservices.html</a>) several new security services for e-mail powered by Postini™. The new services provide inbound and outbound message filtering, encryption, and message archiving capabilities for business.</p>

<p>Services start at $3 per user per year.&nbsp; Providing enterprise level security products at affordable prices for small businesses is a major benefit of these service offerings by Google.&nbsp; </p>

<p>For more information see: <a href="http://www.google.com/a/security">http://www.google.com/a/security</a></p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=iZ9tLeE"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=iZ9tLeE" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=haRCqbe"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=haRCqbe" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=6MoRKHe"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=6MoRKHe" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/229840374" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Tue, 05 Feb 2008 15:16:24 -0600</pubDate>

</item>
<item>
<title>Georgetown University Data Loss Affects 38,000 Students, Faculty, and Staff</title>
<link>http://blog.csoboard.com/cso/2008/01/georgetown-univ.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/01/georgetown-univ.html</guid>
<description>Georgetown University in Washington, D.C. has alerted the public via a press release (http://explore.georgetown.edu/news/?ID=30979) of a data breach incident stemming from the loss of an external computer hard drive. The lost hard drive contained the personally identifiable information including names...</description>
<content:encoded><![CDATA[<p><strong>Georgetown University in Washington, D.C.</strong> has alerted the public via a press release (<a href="http://explore.georgetown.edu/news/?ID=30979">http://explore.georgetown.edu/news/?ID=30979</a>) of a data breach incident stemming from the loss of an external computer hard drive.&nbsp; The lost hard drive contained the personally identifiable information including names and social security numbers for approximately 38,000 current and former students, faculty, and staff.</p>

<p>Georgetown is offering free credit monitoring for those affected by this data loss incident.&nbsp; A toll-free telephone number (<strong>866-740-2458</strong>) has been setup to handle questions by those who may be affected by this information security breach.&nbsp; &nbsp;Georgetown is taking the correct steps in recovering from this incident.&nbsp; </p>

<p>However, it is still amazing to me with the current proliferation of portable storage devices such as external hard drives and USB memory sticks, that organizations don't put into place and enforce stronger IT policies to prevent storage of such sensitive data without any encryption on removable disks and/or memory media.</p>

<p>When will organizations learn to better protect the personally identifiable information they have been entrusted with by their clients, business partners, and employees?&nbsp; It is my hope this lesson is learned and these types of data loss incidents don't keep occurring.</p>

<div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=SwEehvD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=SwEehvD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=LC1kSKd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=LC1kSKd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=XLhduYd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=XLhduYd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/226012910" height="1" width="1"/>]]></content:encoded>


<category>Data Breach</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Wed, 30 Jan 2008 11:29:12 -0600</pubDate>

</item>
<item>
<title>ChoicePoint Inc. (NYSE: CPS) Pays $10M to Settle Data Breach Lawsuit</title>
<link>http://blog.csoboard.com/cso/2008/01/choicepoint-inc.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/01/choicepoint-inc.html</guid>
<description>ChoicePoint Inc. (NYSE: CPS) is paying $10 million to settle a class-action lawsuit related to a data breach incident from 2005. In the related data breach, the personal information of 160,000 consumers was put at risk. The $10 million payment...</description>
<content:encoded><![CDATA[<p>ChoicePoint Inc. (NYSE: CPS) is paying $10 million to settle a class-action lawsuit related to a data breach incident from 2005.&nbsp; &nbsp;In the related data breach, the personal information of 160,000 consumers was put at risk.&nbsp; </p>

<p>The $10 million payment if approved by the U.S. District Court in Georgia, would settle the lawsuit brought by shareholders against named defendants ChoicePoint and certain of its officers.&nbsp; As part of the settlement, ChoicePoint will admit no liability in the data breach incident.</p>

<p>Score one for big business and shareholders.&nbsp; However, consumers today still don't have comprehensive federal legislation to protect their data privacy allow impose stiff financial penalties on companies that put their personal information at risk.</p>

<p><strong><br />Computerworld</strong><br /><a href="http://computerworld.com/action/article.do?command=printArticleBasic&amp;articleId=9059659">http://computerworld.com/action/article.do?command=printArticleBasic&amp;articleId=9059659</a></p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=xT1LzID"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=xT1LzID" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=NilK7Od"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=NilK7Od" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=95dChod"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=95dChod" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287894" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Mon, 28 Jan 2008 18:57:49 -0600</pubDate>

</item>
<item>
<title>Data Breach of Credit Card Details for 650,000 Consumers Including 150,000 Social Security Numbers</title>
<link>http://blog.csoboard.com/cso/2008/01/data-breach-cre.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/01/data-breach-cre.html</guid>
<description>GE Money USA, a company that provides credit card processing services for retailers, has suffered a data breach potentially affecting the credit card details for approximately 650,000 consumers. A backup tape has been missing since October from an Iron Mountain...</description>
<content:encoded><![CDATA[<p>GE Money USA, a company that provides credit card processing services for retailers, has suffered a data breach potentially affecting the credit card details for approximately 650,000 consumers.&nbsp; A backup tape has been missing since October from an Iron Mountain Inc. (NYSE: IRM) secure storage facility.</p>

<p>GE Money has publicly only identified one retailer, J.C. Penny Co. (NYSE: JCP) as being one of the affected retailers whose data was compromised on the lost backup tape.&nbsp; &nbsp;In addition GE Money has stated that approximately 150,000 social security numbers for customers of retailers were stored on the backup tape. </p>

<p>GE Money is providing free credit monitoring for one year to those consumers affected and has informed consumers via letters mailed starting in early December 2007.</p>

<p><strong></strong></p>

<p><strong><br />Data Breach Affects 650k Customers of 230 Retailers</strong><br /><a href="http://www.computerworld.com/action/article.do?command=printArticleBasic&amp;articleId=311724">http://www.computerworld.com/action/article.do?command=printArticleBasic&amp;articleId=311724</a></p>

<p><strong>GE Money Backup Tape With 650,000 Records Missing At Iron Mountain<br /></strong><a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=205901244"><span face="Arial">http://www.informationweek.com/story/showArticle.jhtml?articleID=205901244 </span></a></p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=kwFdWyD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=kwFdWyD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=jWQtrqd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=jWQtrqd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=S1u1STd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=S1u1STd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287895" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Mon, 28 Jan 2008 09:52:58 -0600</pubDate>

</item>
<item>
<title>Thoughts On Blog and Domain Name Marketing</title>
<link>http://blog.csoboard.com/cso/2008/01/thoughts-on-blo.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/01/thoughts-on-blo.html</guid>
<description>Recently a friend suggested that I consider renaming this blog and its associated domain name. In considering this suggestion, I ran across an interesting service on-line--PickyDomains.com. PickyDomains.com, a domain naming company, has added an interesting twist to what has been...</description>
<content:encoded><![CDATA[<p>Recently a friend suggested that I consider renaming this blog and its associated domain name.&nbsp; In considering this suggestion, I ran across an interesting service on-line--PickyDomains.com.&nbsp; </p>

<p>PickyDomains.com, a domain naming company, has added an interesting twist to what has been a traditional marketing discipline.&nbsp; I will try their services and report back at a later date on the results of this exercise in weblog and domain naming.</p>

<p>If you my readers have any recommendations on a new blog and domain name for this blog, your suggestions are welcome!&nbsp; &nbsp;Thank you in advance for any suggestions.</p>

<div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=ez1K8gD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=ez1K8gD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=0ZpbAod"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=0ZpbAod" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=3MYY6cd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=3MYY6cd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287896" height="1" width="1"/>]]></content:encoded>


<category>Weblogs</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Mon, 28 Jan 2008 08:47:55 -0600</pubDate>

</item>
<item>
<title>Bush Orders Intelligence Cyber Security Monitoring Of Federal Agencies</title>
<link>http://blog.csoboard.com/cso/2008/01/bush-orders-int.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/01/bush-orders-int.html</guid>
<description>Concerned about cyber security threats to our national security, President Bush has signed (on January 8, 2008) a classified executive order (the "National Security Presidential Directive 54/Homeland Security Presidential Directive 23") directing the U.S. National Security Agency (NSA), Central Intelligence...</description>
<content:encoded><![CDATA[<p>Concerned about cyber security threats to our national security, President Bush has signed (on January 8, 2008) a classified executive order (the &quot;<em>National Security Presidential Directive 54/Homeland Security Presidential Directive 23</em>&quot;) directing the U.S. National Security Agency (NSA), Central Intelligence Agency (CIA), and the Federal Bureau of Investigation's (FBI) Cyber Division to monitor the computer networks of all federal agencies.</p>

<p>The task force will be coordinated by the Office of the Director of National Intelligence (ODNI).&nbsp; Under the auspices of the ODNI, the Department of Homeland Security (DHS) will coordinate protection efforts for the cyber security of the computer networks for all federal agencies.&nbsp; The Pentagon will be in charge of coordinating strategic defensive and offensive responses to cyber attacks.</p>

<p>Although this order attempts to centralize the federal efforts to protect our federal agencies from cyber security threats both foreign and domestic, it falls short on one key element.&nbsp; That element is the inclusion of the public sector industries that are part of our national critical infrastructure such as energy companies, telecommunications providers, and health care organizations such as hospitals, etc.&nbsp; Failure to include the money and resources for these industries to better protect their critical information networks and assets is detrimental to our national security posture.&nbsp; </p>

<p>I'm in agreement we need to protect federal agencies from cyber security threats.&nbsp; However the Federal government must do more than pay lip service to private sector and provide some real economic incentives, technology transfers, research, and coordination efforts with private sector to protect industries critical to our national infrastructure and security.</p>

<p>&nbsp;</p>

<p><strong>Washington Post<br /></strong><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/01/25/AR2008012503261.html?hpid=moreheadlines">Bush Order Expands Network Monitoring</a></p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=SYNQ9yD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=SYNQ9yD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=45aGm1d"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=45aGm1d" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=V9cltFd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=V9cltFd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287897" height="1" width="1"/>]]></content:encoded>


<category>Current Affairs</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Sat, 26 Jan 2008 10:02:25 -0600</pubDate>

</item>
<item>
<title>U.S. Federal Energy Regulatory Commission Issues Cyber Security Standards</title>
<link>http://blog.csoboard.com/cso/2008/01/us-federal-ener.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/01/us-federal-ener.html</guid>
<description>On January 17, 2008, the U.S. Federal Energy Regulatory Commission approved eight mandatory reliability standards for cyber security designed to help guard the United States national power grid from cyber security threats and attacks. The new standards were developed by...</description>
<content:encoded><![CDATA[<p>On January 17, 2008, the U.S. Federal Energy Regulatory Commission approved eight mandatory reliability standards for cyber security designed to help guard the United States national power grid from cyber security threats and attacks.</p>

<p>The new standards were developed by the North American Electric Reliability Corporation (NERC).&nbsp; However NERC is charged to manage future development of these standards and also follow the guidance of the National Institute of Standards and Technology (NIST) on issues of cyber security.&nbsp; This move is a particularly smart move on the part of FERC to ensure that future cyber security standards developed and maintained by NERC are relevant and current to changes in technology and the field of cyber security research.</p>

<p>According to a FERC press release (See: <a href="http://www.ferc.gov/news/news-releases/2008/2008-1/01-17-08-E-2.asp">http://www.ferc.gov/news/news-releases/2008/2008-1/01-17-08-E-2.asp</a>) the eight new cyber security standards address the following topics:</p>

<ul><li>Critical Cyber Asset Identification; </li>

<li>Security Management Controls; </li>

<li>Personnel and Training; </li>

<li>Electronic Security Perimeters; </li>

<li>Physical Security of Critical Cyber Assets; </li>

<li>Systems Security Management; </li>

<li>Incident Reporting and Response Planning; and </li>

<li>Recovery Plans for Critical Cyber Assets. </li></ul>

<p>Recently we have seen news reports about other countries like China enhance their cyber security and warfare capabilities within their own government and military forces.&nbsp; &nbsp;However, I'm glad FERC is creating these standards for critical infrastructure protection (CIP) of our nation's power grid to counter the potential threats from other governments and those who would choose to do our country harm.</p>

<p>I hope the power grid operators and electric utility companies quickly implement these standards and help contribute more investment dollars towards the protection of our critical infrastructure assets from cyber and physical security threats.</p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=rBCma7D"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=rBCma7D" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=nSe1iZd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=nSe1iZd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=ApDIc1d"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=ApDIc1d" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287898" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Fri, 18 Jan 2008 23:40:28 -0600</pubDate>

</item>
<item>
<title>Pa. Government Website Compromised By Chinese Hackers</title>
<link>http://blog.csoboard.com/cso/2008/01/pa-government-w.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2008/01/pa-government-w.html</guid>
<description>Early morning on Friday, January 4, 2008, the Commonwealth of Pennsylvania government website was infected with a computer virus. In order to prevent the spread of the computer virus, system administrators began a coordinated effort to shutdown other commonwealth agency...</description>
<content:encoded><![CDATA[<p>Early morning on Friday, January 4, 2008, the Commonwealth of Pennsylvania government website was infected with a computer virus.&nbsp; In order to prevent the spread of the computer virus, system administrators began a coordinated effort to shutdown other commonwealth agency websites in order to prevent the spread of the computer virus infection.&nbsp; System administrators and IT security staff were able to preliminary identify the source of the data breach--a domain name registered in China.</p>

<p>The fact that this attack may have originated in China is not surprising.&nbsp; &nbsp;As early as 2006, the U.S.-China Economic and Security Review Commission (USCC), a U.S. Congressional Commission, warned about China's cyber threat capabilities.&nbsp; According to the 2006 USCC annual report (<a href="http://www.uscc.gov/annual_report/2006/chapter3_sec1.pdf">http://www.uscc.gov/annual_report/2006/chapter3_sec1.pdf</a>), China is creating military information warfare units and shifting its cyberwarefare to become offensive in an effort to disrupt enemy networks and information systems.</p>

<p>The U.S. Government is not alone in its assessment that China poses a major threat in terms of cyberwarefare capabilities.&nbsp; Recently the United Kingdom's counter-intelligence and security service, MI5, warned that China is sponsoring cyber espionage against key industries in the British economy.</p>

<p>When nations with unlimited resources, like China, decide to integrate cyberwarefare capabilities into their military forces, this fact should cause both private industry and governments around the world to take notice and rethink their views about cyber security.&nbsp; In the next few years, we will see that state sponsored cyberwarefare will increasingly become a major threat of national security importance.&nbsp; In order to effectively counter this threat, there must be better cooperation and research between private industry and government.</p>

<p><strong><br />State Web sites back after hack attack</strong><br /><a href="http://www.mcall.com/news/local/all-a1_5web.6214422jan05,0,2068262.story">http://www.mcall.com/news/local/all-a1_5web.6214422jan05,0,2068262.story</a></p>

<p><strong>Hackers Force Pa. to Shut State Web Site</strong><br /><a href="http://ap.google.com/article/ALeqM5iGKgY3SpKw7_p7A8MGHpTfSpN8mAD8TVE5SG0">http://ap.google.com/article/ALeqM5iGKgY3SpKw7_p7A8MGHpTfSpN8mAD8TVE5SG0</a></p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=JFTsTID"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=JFTsTID" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=zO4PPXd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=zO4PPXd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=CFH1Mdd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=CFH1Mdd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287899" height="1" width="1"/>]]></content:encoded>


<category>Current Affairs</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Sat, 05 Jan 2008 06:55:20 -0600</pubDate>

</item>
<item>
<title>Chinese Hackers Breach Rolls Royce and Royal Dutch Shell Computer Networks, MI5 Warns UK Firms</title>
<link>http://blog.csoboard.com/cso/2007/12/chinese-hackers.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/12/chinese-hackers.html</guid>
<description>Recently Chinese state sponsored hackers managed to penetrate the computer networks of Rolls Royce and Royal Dutch Shell in the UK (See article: Secrets of Shell and Rolls-Royce come under attack from China’s spies). The seriousness of the Rolls Royce...</description>
<content:encoded><![CDATA[<p>Recently Chinese state sponsored hackers managed to penetrate the computer networks of Rolls Royce and Royal Dutch Shell in the UK (See article:&nbsp; <em><a href="http://business.timesonline.co.uk/tol/business/markets/china/article2988228.ece">Secrets of Shell and Rolls-Royce come under attack from China’s spies</a>)</em>.&nbsp; &nbsp;</p>

<p>The seriousness of the Rolls Royce and Royal Dutch Shell incidents and the increased level of state sponsored hacker attacks have prompted <a href="http://www.mi5.gov.uk/">MI5</a>, the United Kingdom's counter-intelligence and security service, to warn other companies to be vigilant against this type of industrial espionage. </p>

<p><strong>State sponsored cyber espionage is a serious threat to the national security of all nations.</strong></p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=X34jXMD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=X34jXMD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=CFLt7cd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=CFLt7cd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=AVPJYGd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=AVPJYGd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287901" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Tue, 04 Dec 2007 00:41:54 -0600</pubDate>

</item>
<item>
<title>TJX (NYSE: TJX) Pays $40.9 Million In Restitution To Visa Inc. For Data Breach</title>
<link>http://blog.csoboard.com/cso/2007/12/tjx-nyse-tjx-pa.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/12/tjx-nyse-tjx-pa.html</guid>
<description>TJX (NYSE: TJX) has paid $40.9 million in restitution to Visa Inc. to settle all claims related to the data breach that compromised nearly 46 million credit cards. Visa Inc. has also recently settled fines against Fifth Third Bancorp (NASDAQ:...</description>
<content:encoded><![CDATA[<p>TJX (NYSE: TJX) has paid $40.9 million in restitution to Visa Inc. to settle all claims related to the data breach that compromised nearly 46 million credit cards.&nbsp; Visa Inc. has also recently settled fines against Fifth Third Bancorp (NASDAQ: FITB) - (See: <a href="http://blog.csoboard.com/cso/2007/11/fifth-third-ban.html">http://blog.csoboard.com/cso/2007/11/fifth-third-ban.html</a>).</p>

<p>Retail merchants and financial institutions are waking up to the reality that they must work together to better protect the integrity, security, and privacy of their customers' financial information.&nbsp; &nbsp;Let's all hope as consumers that industry can achieve those lofty goals.</p>

<p>For more information see:</p>

<ul><li><a href="http://www.boston.com/business/globe/articles/2007/12/01/tjx_agrees_to_reimburse_banks/">Boston Globe - TJX agrees to reimburse banks</a> </li>

<li><a href="http://www.nytimes.com/2007/12/01/business/01biztoday-003.html?ref=business">New York Times - Retailer to Pay $40 Million</a></li></ul><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=ZrvQaVD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=ZrvQaVD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=he2aa9d"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=he2aa9d" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=ar1cP1d"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=ar1cP1d" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287902" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Sun, 02 Dec 2007 01:18:10 -0600</pubDate>

</item>
<item>
<title>Botnets Suspected Of Generating Over $20 Million In Economic Loses Disrupted by FBI</title>
<link>http://blog.csoboard.com/cso/2007/11/botnets-suspect.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/11/botnets-suspect.html</guid>
<description>Computer "botnets" estimated of generating over $20 million in economic loses for businesses and consumers are disrupted by the U.S. Federal Bureau of Investigation (FBI), U.S. Secret Service, U.S. Immigrations Customs Enforcement and New Zealand Police. (FBI Press Release: http://www.fbi.gov/pressrel/pressrel07/botroast112907.htm)...</description>
<content:encoded><![CDATA[<p>Computer &quot;botnets&quot; estimated of generating over $20 million in economic loses for businesses and consumers are disrupted by the U.S. Federal Bureau of Investigation (FBI), U.S. Secret Service, U.S. Immigrations Customs Enforcement and New Zealand Police.&nbsp; (FBI Press Release: <a href="http://www.fbi.gov/pressrel/pressrel07/botroast112907.htm">http://www.fbi.gov/pressrel/pressrel07/botroast112907.htm</a>)</p>

<p>&quot;Operation Bot Roast II&quot; is an excellent example of interagency cooperation by U.S. Federal and international law enforcement agencies in the fight against cyber crime.</p>

<p>While the law enforcement community has done their part, it is time for us as consumers to do our part prevent cyber crime.&nbsp; If you have not already done so, please install anti-virus, anti-spyware, firewall, and wireless encryption defenses to protect your personal computer and networks.&nbsp; &nbsp;In doing so, each of us can do our part to prevent cyber crime by following basic computer security precautions.</p>

<p>For more information:</p>

<ul><li>OnGuardOnline.gov<br /><a href="http://onguardonline.gov/botnet.html">http://onguardonline.gov/botnet.html</a></li>

<li>See my June 13, 2007 blog post<br /><a href="http://blog.csoboard.com/cso/2007/06/1_million_compu.html">1 Million Computers Affected by Botnet; FBI Announces</a></li></ul><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=VHeQiQD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=VHeQiQD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=ggFfhqd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=ggFfhqd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=QFrNI4d"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=QFrNI4d" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287903" height="1" width="1"/>]]></content:encoded>


<category>Current Affairs</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Fri, 30 Nov 2007 00:51:31 -0600</pubDate>

</item>
<item>
<title>Tips for Safe Holiday Shopping Online</title>
<link>http://blog.csoboard.com/cso/2007/11/tips-for-safe-h.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/11/tips-for-safe-h.html</guid>
<description>This holiday season, some of us may do some of our shopping online. Before doing our shopping online, we should follow basic security steps to guard our personal and financial information from fraud and identity theft. Here are some tips...</description>
<content:encoded><![CDATA[<p>This holiday season, some of us may do some of our shopping online.&nbsp; Before doing our shopping online, we should follow basic security steps to guard our personal and financial information from fraud and identity theft.</p>

<p>Here are some tips for safe holiday shopping online:</p>

<ol><li><strong>Make sure your security software is up-to-date.</strong>&nbsp; Update your anti-virus, anti-spyware, and firewall software to minimize the risk of falling victim to malicious threats like trojans or computer viruses that could attempt to steal your personal information or provide hackers access to your computer.</li>

<li><strong>Don't conduct any online shopping on public computers such as those found at cybercafes, public libraries, etc.</strong>&nbsp; &nbsp; The public computer you use, could have spyware or other malicious software installed that in turn could compromise your personal and financial information.</li>

<li><strong>When in doubt about a retailer, check them out.</strong>&nbsp; Do an online search on a retailer and read comments from other customers.&nbsp; Contact the <a href="http://welcome.bbb.org/">Better Business Bureau</a> and find any additional information they may have on the company.</li>

<li><strong>Monitor your credit.</strong>&nbsp; Make it a habit to monitor your credit regularly with the major credit bureaus.</li></ol>

<p>Here are some additional resources for safe online shopping this holiday season.</p>

<ul><li>The National Cyber Security Alliance<br /><a href="http://www.staysafeonline.info/basics/shoppingTips.html">http://www.staysafeonline.info/basics/shoppingTips.html</a></li>

<li>Yahoo! Shopping<br /><a href="http://docs.yahoo.com/docs/info/consumertips.html">http://docs.yahoo.com/docs/info/consumertips.html</a></li></ul><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=KEcSuuD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=KEcSuuD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=IR6twUd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=IR6twUd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=tZENPpd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=tZENPpd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287904" height="1" width="1"/>]]></content:encoded>


<category>Web/Tech</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Mon, 26 Nov 2007 21:20:48 -0600</pubDate>

</item>
<item>
<title>Fifth Third Bancorp (NASDAQ: FITB) Fined $880,000 by Visa Inc. For Role In TJX (NYSE: TJX) Data Breach</title>
<link>http://blog.csoboard.com/cso/2007/11/fifth-third-ban.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/11/fifth-third-ban.html</guid>
<description>Fifth Third Bancorp (NASDAQ: FITB) has been fined $880,000 by Visa Inc. for FITB's role in the data breach at TJX Companies Inc. (NYSE: TJX). (Click here for article by Boston Globe) In recent years, banks, merchants, and credit card...</description>
<content:encoded><![CDATA[<p>Fifth Third Bancorp (NASDAQ: FITB) has been fined $880,000 by Visa Inc. for FITB's role in the data breach at TJX Companies Inc. (NYSE: TJX).&nbsp; (<a href="http://www.boston.com/business/globe/articles/2007/11/24/visa_fines_ohio_bank_in_tjx_data_breach/">Click here</a> for article by Boston Globe)&nbsp; In recent years, banks, merchants, and credit card issuers have been at odds over who should be responsible for protecting credit card data.&nbsp; &nbsp; </p>

<p>Thanks in part to the collaboration by credit card issuers like Visa and MasterCard, today the <a href="https://www.pcisecuritystandards.org/">PCI (Payment Card Industry) Security Standards Council</a>, an independent organization, is leading efforts and developing industry standards for data security that banks, merchants, and credit card issuers can all agree to adopt as baseline for the protection of consumers' credit card data.&nbsp; Despite all of these efforts data breaches have occurred because of the reluctance by organizations to implement appropriate data security measures.</p>

<p>It is my hope that the motivation for banks and merchants to act to protect consumers' personal and financial information is not only driven by self-regulatory industry actions.</p>





<div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=QhkMdTD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=QhkMdTD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=m6gXj3d"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=m6gXj3d" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=GETOPCd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=GETOPCd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287905" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Sun, 25 Nov 2007 10:22:04 -0600</pubDate>

</item>
<item>
<title>CD's Containing Social Security Numbers and Payroll Data For State Employees Missing in Nevada</title>
<link>http://blog.csoboard.com/cso/2007/11/cds-containing-.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/11/cds-containing-.html</guid>
<description>The Associated Press (AP) is reporting the Personnel Department of the State of Nevada has lost track of at least 470 compact discs (CDs) containing the social security numbers and payroll information for state employees during the past three years....</description>
<content:encoded><![CDATA[<p>The Associated Press (AP) is <a href="http://www.kren.com/global/story.asp?s=7344727&amp;ClientType=Printable">reporting</a> the Personnel Department of the State of Nevada has lost track of at least 470 compact discs (CDs) containing the social security numbers and payroll information for state employees during the past three years.&nbsp; The Personnel Department has sent more than 13,000 CDs to 80 agencies for processing every-two week pay period during the past three years.</p>

<p>The State of Nevada is enacting changes to ensure this type of data loss does not happen again including: </p>

<ul><li>Discs will be signed for and returned to the Personnel Department after every pay period</li>

<li>Passwords will be required to read data stored on CDs</li>

<li>State employee information will be correlated to unique employee ID numbers instead of social security numbers</li></ul>

<p><strong>In my opinion</strong>, these public relation driven policy changes are window dressing rather than substantive data security, access, and audit controls to prevent the misuse of sensitive personal and financial information for state employees.</p>

<p><strong>It is time government agencies do a better job of protecting our personal and financial information.</strong></p>

<div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=0p5WYmD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=0p5WYmD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=5F32yHd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=5F32yHd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=4xWrXld"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=4xWrXld" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287906" height="1" width="1"/>]]></content:encoded>


<category>Current Affairs</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Sun, 11 Nov 2007 22:11:43 -0600</pubDate>

</item>
<item>
<title>Salesforce.com (NYSE: CRM) Suffers Data Breach</title>
<link>http://blog.csoboard.com/cso/2007/11/salesforcecom-n.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/11/salesforcecom-n.html</guid>
<description>Australian IT is reporting (to see article click here) that on-line CRM services company Salesforce.com (NYSE: CRM) suffered an IT security breach. Salesforce has admitted the cause of the incident as being attributed to an employee being duped by a...</description>
<content:encoded><![CDATA[<p>Australian IT is reporting (to see article <a href="http://www.australianit.news.com.au/story/0,24897,22724319-5013044,00.html">click here</a>) that on-line CRM services company Salesforce.com (NYSE: CRM) suffered an IT security breach.&nbsp; &nbsp;Salesforce has admitted the cause of the incident as being attributed to an employee being duped by a &quot;phishing scam&quot;.</p>

<p>The company has admitted customer account information including passwords may have been compromised by non-authorized parties.&nbsp; According to the article by Australian IT there are more than 1,000 subscribers to Salesforce.com may have been affected in Australia alone.</p>

<div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=d2DIcpD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=d2DIcpD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=fGCGdTd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=fGCGdTd" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=pAip8xd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=pAip8xd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287907" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Thu, 08 Nov 2007 01:19:10 -0600</pubDate>

</item>
<item>
<title>Administaff, Inc. (NYSE: ASF): 159,000 Employees At Risk for Identity (ID) Theft</title>
<link>http://blog.csoboard.com/cso/2007/10/administaff-inc.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/10/administaff-inc.html</guid>
<description>Here we go again. This time Administaff, Inc. is reporting the theft of a laptop containing the names, addresses and social security numbers for 96,000 former and 63,000 current employees. For more information go to: http://www.administaff.com/idprotection/ When will organizations get...</description>
<content:encoded><![CDATA[<p>Here we go again.&nbsp; This time Administaff, Inc. is reporting the theft of a laptop containing the names, addresses and social security numbers for 96,000 former and 63,000 current employees.</p>

<p>For more information go to: <a href="http://www.administaff.com/idprotection/">http://www.administaff.com/idprotection/</a></p>

<p>When will organizations get serious and do something about the lax policies and procedures in their corporate culture to prevent incidents like these?&nbsp; </p>

<p>Technology solutions such as data encryption and password protection are only a part of the solution in protecting confidential information.&nbsp; Organizations must do a better job at defining good corporate policies and procedures for ensuring that confidential information is protected appropriately.&nbsp; Organizations must do a better job at educating their workforce on the policies, procedures, and risks faced in protecting confidential information.</p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=6bPH7kD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=6bPH7kD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=6ZJ3had"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=6ZJ3had" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=xcmUR3d"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=xcmUR3d" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287908" height="1" width="1"/>]]></content:encoded>


<category>Business</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Fri, 19 Oct 2007 06:41:13 -0500</pubDate>

</item>
<item>
<title>Comcast (NASDAQ: CMCSA) Law Enforcement Surveillance Practices</title>
<link>http://blog.csoboard.com/cso/2007/10/comcast-nasdaq-.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/10/comcast-nasdaq-.html</guid>
<description>The Federation of American Scientists (www.fas.org) Project on Government Secrecy has recently commented regarding Comcast's (NASDAQ: CMCSA) support for law enforcement investigation and domestic surveillance activities. The "Comcast Cable Law Enforcement Handbook," (download PDF at: http://www.fas.org/blog/secrecy/docs/handbook.pdf) while supportive of U.S....</description>
<content:encoded><![CDATA[<p>The Federation of American Scientists (<a href="http://www.fas.org/">www.fas.org</a>) Project on Government Secrecy has recently commented regarding Comcast's (NASDAQ: CMCSA) support for law enforcement investigation and domestic surveillance activities.</p>

<p>The &quot;Comcast Cable Law Enforcement Handbook,&quot; (download PDF at: <a href="http://www.fas.org/blog/secrecy/docs/handbook.pdf">http://www.fas.org/blog/secrecy/docs/handbook.pdf</a>) while supportive of U.S. law enforcement community, sets clear guidelines for protecting the privacy of Comcast customers.&nbsp; Comcast is also requiring $1,000.00 as a setup fee and an ongoing $750.00 monthly fee, to install any device to comply with law enforcement surveillance requests that are authorized under the Foreign Intelligence Surveillance Act (FISA).</p>

<p>The FAS comments: </p><blockquote dir="ltr"><p>&quot;The role of telecommunications companies in intelligence surveillance is under increased scrutiny as the Bush Administration seeks to shield the companies from any liability associated with their cooperation in what may be illegal warrantless surveillance.&quot; (see blog: <a href="http://www.fas.org/blog/secrecy/2007/10/implementing_domestic_intellig.html">http://www.fas.org/blog/secrecy/2007/10/implementing_domestic_intellig.html</a>)</p></blockquote><p>As a law abiding U.S. Citizen, I find it encouraging to see Comcast follow the law in requiring the law enforcement community to adhere to the letter of the law when fulfilling investigative requests, instead of blindly following the U.S. executive branch in support of any warrantless surveillance programs.</p>

<p>For more information see:</p>

<ul><li><a href="http://www.eff.org/issues/nsa-spying">Electronic Frontier Foundation - NSA Spying</a></li>

<li><a href="http://www.aclu.org/safefree/nsaspying/index.html">American Civil Liberties Union v. NSA</a> </li>

<li><a href="http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_controversy">Wikipedia - NSA Warrantless Surveillance Controversy</a></li></ul><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=REFo2VD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=REFo2VD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=jmW1G8d"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=jmW1G8d" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=pvTjYhd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=pvTjYhd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287909" height="1" width="1"/>]]></content:encoded>


<category>Current Affairs</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Tue, 16 Oct 2007 11:53:09 -0500</pubDate>

</item>
<item>
<title>Data Breach at Montana State University: 1,400 People Affected</title>
<link>http://blog.csoboard.com/cso/2007/10/data-breach-at-.html</link>
<guid isPermaLink="true">http://blog.csoboard.com/cso/2007/10/data-breach-at-.html</guid>
<description>Montana State University issued a press release on October 12, 2007 regarding a data security breach possibly affecting 1,400 people "who enrolled online for MSU Extended University courses during the last two years." MSU states they have encryption technology controls...</description>
<content:encoded><![CDATA[<p dir="ltr" style="MARGIN-RIGHT: 0px">Montana State University issued a <a href="http://www.montana.edu/cpa/news/nwview.php?article=5235"><strong>press release</strong></a> on October 12, 2007 regarding a data security breach possibly affecting 1,400 people &quot;who enrolled online for MSU Extended University courses during the last two years.&quot;</p>

<p dir="ltr" style="MARGIN-RIGHT: 0px">MSU states they have encryption technology controls on the stored data which may have been exposed.&nbsp; The exposed data may include credit card and social security numbers.&nbsp; </p>

<p dir="ltr" style="MARGIN-RIGHT: 0px">MSU has setup a dedicated web site with more information on this incident at: <a href="http://eu.montana.edu/security/">http://eu.montana.edu/security/</a></p>

<p dir="ltr" style="MARGIN-RIGHT: 0px"></p><div class="feedflare">
<a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=AbtH8gD"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=AbtH8gD" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=OzSzfad"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=OzSzfad" border="0"></img></a> <a href="http://feeds.csoboard.com/~f/chiefsecurityofficer?a=Fd7w2bd"><img src="http://feeds.csoboard.com/~f/chiefsecurityofficer?i=Fd7w2bd" border="0"></img></a>
</div><img src="http://feeds.csoboard.com/~r/chiefsecurityofficer/~4/225287910" height="1" width="1"/>]]></content:encoded>


<category>Current Affairs</category>


<dc:creator>Jaime Chanaga</dc:creator>
<pubDate>Sun, 14 Oct 2007 23:48:05 -0500</pubDate>

</item>

</channel>
</rss><!-- ph=1 -->
