<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7720555211888761111</id><updated>2011-12-15T12:47:59.863-08:00</updated><title type='text'>Innate Security</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7720555211888761111.post-8501855831499396799</id><published>2010-10-13T09:31:00.000-07:00</published><updated>2010-10-13T09:47:12.718-07:00</updated><title type='text'>When a Patch is not a Patch?</title><content type='html'>When does turning off IIS' ASP.NET 2.0 Web Service Extension considered a patch? However, in at least one of Microsoft's Patch Tuesday releases, this is exactly what happened (KB953300).&lt;br /&gt;&lt;br /&gt;Really, Microsoft?&lt;br /&gt;&lt;br /&gt;Actually, I believe it was a flawed fix that disabled the feature in the process of installing the updated dll.&lt;br /&gt;&lt;br /&gt;Some references:&lt;br /&gt;&lt;br /&gt;http://power-programming.co.uk/post/2009/10/21/ASPNET-stopped-working-after-installing-Microsoft-NET-Framework-20-Service-Pack-1-Update-KB953300-.aspx&lt;br /&gt;&lt;br /&gt;http://www.asp.net/learn/whitepapers/ms03-32-issue&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720555211888761111-8501855831499396799?l=innatesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/8501855831499396799/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://innatesecurity.blogspot.com/2010/10/when-patch-is-not-patch.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/8501855831499396799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/8501855831499396799'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/2010/10/when-patch-is-not-patch.html' title='When a Patch is not a Patch?'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7720555211888761111.post-5469396859818021176</id><published>2010-07-05T19:39:00.000-07:00</published><updated>2010-07-05T19:53:28.026-07:00</updated><title type='text'>Security is not a concern for Web RIA? Really?</title><content type='html'>Ok, so I am a bit peeved these past few months... no, these past few years. In my few experiences as a developer of Rich Internet Application (RIA) interfaces&lt;br /&gt;&lt;br /&gt;Why is it the two most prominent RIA platforms do not sufficiently support cryptography?  For the &lt;span style="font-style:italic;"&gt;hundreds of thousands&lt;/span&gt; of dollars spent by Adobe on its Creative Suites (Flash/Flex/Air/Actionscript), and the &lt;span style="font-style:italic;"&gt;millions &lt;/span&gt;of dollars spent by Microsoft on Silverlight; why is security such a non-issue?&lt;br /&gt;&lt;br /&gt;Java, whose applet UI has always had a poor user experience, has supported full cryptography and security since 1.3 (or 1.2 with the separate JSE package).&lt;br /&gt;&lt;br /&gt;Yet, for the overwhelming majority of the market in rich user interfaces owned by Adobe and Microsoft, there is no security - unless you rely on SSL. Granted, Actionscript has some great contributors for some crypto; but where are the big boys?&lt;br /&gt;&lt;br /&gt;There is a plethora of publicity surrounding enterprises that have allowed security breaches against their consumers; I feel the same onus should be put on the manufacturers of software development interfaces.  If a company plans to sell a web-supported UI; it should be required to support [X] level of encryption; security data at rest (in memory) and in transit (beyond just SSL).&lt;br /&gt;&lt;br /&gt;What do you think? Do organizations like OWASP have the backing to induce such changes?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720555211888761111-5469396859818021176?l=innatesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/5469396859818021176/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://innatesecurity.blogspot.com/2010/07/security-is-not-concern-for-web-ria.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/5469396859818021176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/5469396859818021176'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/2010/07/security-is-not-concern-for-web-ria.html' title='Security is not a concern for Web RIA? Really?'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7720555211888761111.post-8254413149174024789</id><published>2009-10-15T13:12:00.000-07:00</published><updated>2009-10-15T13:14:51.653-07:00</updated><title type='text'>Contextual Security: Access Control to the Nth Power</title><content type='html'>&lt;o:smarttagtype namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="place"&gt;&lt;/o:smarttagtype&gt;&lt;o:smarttagtype namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="country-region"&gt;&lt;/o:smarttagtype&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:officedocumentsettings&gt;   &lt;o:relyonvml/&gt;   &lt;o:allowpng/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="0" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="0" name="footnote text"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="0" name="footnote reference"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="0" name="Hyperlink"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if !mso]&gt;&lt;object classid="clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id="ieooui"&gt;&lt;/object&gt; &lt;style&gt; st1\:*{behavior:url(#ieooui) } &lt;/style&gt; &lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face  {font-family:"Cambria Math";  panose-1:2 4 5 3 5 4 6 3 2 4;  mso-font-charset:1;  mso-generic-font-family:roman;  mso-font-format:other;  mso-font-pitch:variable;  mso-font-signature:0 0 0 0 0 0;} @font-face  {font-family:Calibri;  panose-1:2 15 5 2 2 2 4 3 2 4;  mso-font-charset:0;  mso-generic-font-family:swiss;  mso-font-pitch:variable;  mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-unhide:no;  mso-style-qformat:yes;  mso-style-parent:"";  margin:0in;  margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman","serif";  mso-fareast-font-family:"Times New Roman";} h3  {mso-style-unhide:no;  mso-style-qformat:yes;  mso-style-link:"Heading 3 Char";  mso-style-next:Normal;  margin-top:12.0pt;  margin-right:0in;  margin-bottom:3.0pt;  margin-left:0in;  mso-pagination:widow-orphan;  page-break-after:avoid;  mso-outline-level:3;  font-size:13.0pt;  font-family:"Arial","sans-serif";} p.MsoFootnoteText, li.MsoFootnoteText, div.MsoFootnoteText  {mso-style-noshow:yes;  mso-style-unhide:no;  mso-style-link:"Footnote Text Char";  margin:0in;  margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman","serif";  mso-fareast-font-family:"Times New Roman";} span.MsoFootnoteReference  {mso-style-noshow:yes;  mso-style-unhide:no;  vertical-align:super;} a:link, span.MsoHyperlink  {mso-style-unhide:no;  color:blue;  text-decoration:underline;  text-underline:single;} a:visited, span.MsoHyperlinkFollowed  {mso-style-noshow:yes;  mso-style-priority:99;  color:purple;  mso-themecolor:followedhyperlink;  text-decoration:underline;  text-underline:single;} span.Heading3Char  {mso-style-name:"Heading 3 Char";  mso-style-unhide:no;  mso-style-locked:yes;  mso-style-link:"Heading 3";  mso-ansi-font-size:13.0pt;  mso-bidi-font-size:13.0pt;  font-family:"Arial","sans-serif";  mso-ascii-font-family:Arial;  mso-hansi-font-family:Arial;  mso-bidi-font-family:Arial;  font-weight:bold;} span.FootnoteTextChar  {mso-style-name:"Footnote Text Char";  mso-style-noshow:yes;  mso-style-unhide:no;  mso-style-locked:yes;  mso-style-link:"Footnote Text";} .MsoChpDefault  {mso-style-type:export-only;  mso-default-props:yes;  font-size:10.0pt;  mso-ansi-font-size:10.0pt;  mso-bidi-font-size:10.0pt;}  /* Page Definitions */  @page  {mso-footnote-separator:url("file:///c:/temp/default/msohtmlclip1/01/clip_header.htm") fs;  mso-footnote-continuation-separator:url("file:///c:/temp/default/msohtmlclip1/01/clip_header.htm") fcs;  mso-endnote-separator:url("file:///c:/temp/default/msohtmlclip1/01/clip_header.htm") es;  mso-endnote-continuation-separator:url("file:///c:/temp/default/msohtmlclip1/01/clip_header.htm") ecs;} @page Section1  {size:8.5in 11.0in;  margin:1.0in .75in .75in .75in;  mso-header-margin:.25in;  mso-footer-margin:1.0in;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin:0in;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;In the 1990’s, the touch screen had its place on some niche markets, such as restaurant consoles, and other businesses that lend themselves to this type of user interface.&lt;span style=""&gt;  &lt;/span&gt;Yet it was the Smartphone interface that garnered the first real breakthrough in touch screen usability, since reduced real estate forced innovative and efficient workflow designs. The next breakthrough had been inclusion of gesturing, made possible with new technologies in multi-touch sensing screens.&lt;span style=""&gt;  &lt;/span&gt;In 2006, NYU research scientist Jeff Han&lt;a style="" href="#_ftn1" name="_ftnref1" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;[1]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; allowed the user interface to change lanes from “tasks defining user behavior” to “user gestures defining tasks”. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;The innovative use of technology ushers in an astounding array of new input patterns.&lt;span style=""&gt;  &lt;/span&gt;Input is no longer tethered to keypads, keyboards, smartcards or biometrics devices; rather it has become 4-dimensional – assimilating codes, gestures, motions and timing into a complex representation of user behavior.&lt;span style=""&gt;  &lt;/span&gt;The time is ripe for new security paradigm to grow from these patterns.&lt;span style=""&gt;  &lt;/span&gt;Security will not longer be defined by users following security access rules, but by devices “listening” to what the user wants [as security] and learning user behavior in context.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Security can be enhanced in three distinct ways: multi-modal, multi-factor, and cooperative extensions.&lt;span style=""&gt;  &lt;/span&gt;Multi-modal enhancements increase security by introducing new inputs into an existing system, mathematically increasing its uniqueness.&lt;span style=""&gt;  &lt;/span&gt;Multi-factor enhancements add additional dimensions of security – i.e. not just what a user knows, but what a user possesses. Finally, cooperative extensions allow security to use external (out-of-band) knowledge about a user to augment the security context in which the user operates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;h3&gt;Increasing Security with Simple Math&lt;/h3&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Shortly after reading how Synaptics has now introduced a multi-touch screen capable of ten-finger touch&lt;a style="" href="#_ftn2" name="_ftnref2" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;[2]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; for normal mobile phones, the thought of N&lt;sup&gt;th&lt;/sup&gt; level security came to mind.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Why? Simple math, of course… if a single keypad requires a password of 4 numeric digits, the possible combinations are 0000 to 9999, mathematically a combination of 10 items taken 4 at a time, or 10&lt;sup&gt;4&lt;/sup&gt; power.&lt;span style=""&gt;  &lt;/span&gt;Imagine if each press of the keypad was replaced by a dual-key press.&lt;span style=""&gt;  &lt;/span&gt;The combinatorial limit jumps to a staggering 65,610,000 – 90 items (00…99, minus 10 sets of duplicate digits) taken 4 at a time, or 90&lt;sup&gt;4&lt;/sup&gt; power.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Allowing single and double key-press codes, the 10K combinatorial security of a 4 digit pin is matched with just 2 combinations, 100 items taken 2 at a time, or 100&lt;sup&gt;2&lt;/sup&gt;. Add any number of gestures and the combinatorial limits jumps another factor.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;This type of security does not just apply to computers and mobile devices, but everyday security such as home alarm keypads and car security systems.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;h3&gt;Increasing Security through User-Defined Behavior&lt;/h3&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;These new interface elements allows us to have better security through behavior.&lt;span style=""&gt;  &lt;/span&gt;My expertise is in the keystroke dynamics world where behavioral biometrics is assessed from the rhythm of one’s typing pattern; specifically flight time and dwell time. This creates a pretty robust, albeit single faceted, behavioral mapping of a user.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Having multi-touch screens and gestures, incorporating the characteristics of the user input – not only timings from the keystroke dynamics realm but stroke patterns, angles and pressures from the handwriting recognition realm –the idea of security really becomes an unfettered medium.&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Imagine allowing the user to set their security access method to be any behavior combination the user decides is appropriate for them.&lt;span style=""&gt;  &lt;/span&gt;It could be as simple as allowing a multi-touch code of the keypad.&lt;span style=""&gt;  &lt;/span&gt;Or perhaps it is the user drawing a custom gesture on the screen of the touch-based interface.&lt;span style=""&gt;  &lt;/span&gt;On mobile phones with motion sensors, security can even be as natural as doing the Macarena (while holding the phone in one hand)!&lt;span style=""&gt;  &lt;/span&gt;These phones can even detect if it is not in the pocket of the normal owner by calculating the innate stride and gait of the user from its gyroscopic sensors.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;h3&gt;Increase Security utilizing Cooperative Information&lt;/h3&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Security through user behavior is not a novel concept. Behavioral biometrics has been studied at various times throughout modern history, as far back as WW-II with the &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;U.S.&lt;/st1:place&gt;&lt;/st1:country-region&gt; government research on the “Fist of the Sender”.&lt;span style=""&gt;  &lt;/span&gt;The most limiting factor of utilizing behavioral biometrics is the restriction of the input technology available on the device (or network) being protected.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Ideal security is reached when internal measures can be augmented by external factors. In Bruce Shneier’s security blog (and in his book “Beyond Fear”), there is a great anecdote about the lima bean plant’s natural defense mechanism&lt;a style="" href="#_ftn3" name="_ftnref3" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;[3]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;. To paraphrase this story, when the lima bean plant is attacked by a certain bug, it emits a pheromone that attracts the bug’s own predator.&lt;span style=""&gt;  &lt;/span&gt;The unique characteristic here is that once one lima bean plants emits this pheromone, all surrounding lima bean plants are triggered to emit this chemical; thus proactively protecting the entire lime bean patch.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;This “cooperative security” mechanism provides us with a novel approach to access security.&lt;span style=""&gt;  &lt;/span&gt;In fact, there exists this same paradigm in some of the newer IPS’s (intrusion prevention systems) such as LayerX Technology&lt;a style="" href="#_ftn4" name="_ftnref4" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;[4]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;, whereby a confirmed breach attempt on one edge device will share this information with other edge devices in that community, so that they may be aware and proactively prevent the same attempt across the enterprise.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;With the advent in BlueTooth seamless connectivity, other devices can lend themselves to promoting access security by sharing their access meta-information with surrounding devices.&lt;span style=""&gt;  &lt;/span&gt;For example, in an office where a rogue user has failed to access John Q’s mobile device several times, it may send out a distress signal to other listening devices (such as workstations or laptops) to beware of accessing the network as John Q.&lt;span style=""&gt;  &lt;/span&gt;This can, in turn, trigger a notification to a security office to investigate this more closely – even so far as tracking which door access pads have used John Q’s access code for entry and exit. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;h3&gt;Security in Context&lt;/h3&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Can we get better security by simply replacing passwords with gestures? Yes, for a period of time. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;In the end, we must concede that all this technology leads us to understand that security is a process, not a product.&lt;span style=""&gt;  &lt;/span&gt;There are no absolute safeguards for access control; but the methods presented here allow us to increase the capabilities of where security can grow.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;We can no longer force security onto the user in an isolated medium; or expect security from a single dimension to be sufficient.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;The shift presented here is to elicit security methods the user behavior and their surroundings. Like human to human communication, context is imperative to comprehension.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;div style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;br /&gt;  &lt;hr align="left" size="1" width="33%"&gt;  &lt;!--[endif]--&gt;  &lt;div style="" id="ftn1"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="#_ftnref1" name="_ftn1" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;[1]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; Reference. &lt;a href="http://www.ted.com/talks/jeff_han_demos_his_breakthrough_touchscreen.html"&gt;http://www.ted.com/talks/jeff_han_demos_his_breakthrough_touchscreen.html&lt;/a&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn2"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="#_ftnref2" name="_ftn2" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;[2]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; Reference. &lt;a href="http://www.betanews.com/article/Tenfinger-multitouch-headed-to-mobile-gadgets-this-year/1248280076"&gt;http://www.betanews.com/article/Tenfinger-multitouch-headed-to-mobile-gadgets-this-year/1248280076&lt;/a&gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn3"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="#_ftnref3" name="_ftn3" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;[3]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; Reference: http://www.schneier.com/news-063.html&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn4"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="#_ftnref4" name="_ftn4" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;[4]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; We do not promote LayerX above any other IPS, but use it as a reference point for illustration purposes only.&lt;/p&gt;  &lt;/div&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720555211888761111-8254413149174024789?l=innatesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/8254413149174024789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://innatesecurity.blogspot.com/2009/10/contextual-security-access-control-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/8254413149174024789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/8254413149174024789'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/2009/10/contextual-security-access-control-to.html' title='Contextual Security: Access Control to the Nth Power'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7720555211888761111.post-1232263260799464493</id><published>2009-09-17T11:05:00.000-07:00</published><updated>2009-09-17T11:22:31.571-07:00</updated><title type='text'>Microsoft Search Branding "Faux Pah"</title><content type='html'>&lt;span style="font-family:verdana;"&gt;Here is an interesting tidbit:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Microsoft has just rebranded its "Live Search" as "Bing", right?  Well, I opened a Chinese fortune cookie that gave the definition of "Bing" to mean "disease"....  Of course, this sounds too good to be true, so I looked it up on several sites -- here is the best explanation of the chinese word "bing": &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.zhongwen.com/d/175/x102.htm"&gt;http://www.zhongwen.com/d/175/x102.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;----&lt;br /&gt;&lt;br /&gt;I admit it, I am late to the party... see the explanations given at &lt;a href="http://liveside.net/main/archive/2009/05/29/some-quick-takes-on-bing.aspx"&gt;http://liveside.net/main/archive/2009/05/29/some-quick-takes-on-bing.aspx&lt;/a&gt;...&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;blockquote&gt;"The actual Chinese characters are two characters, 'Bi' and 'Ing' and combined these two characters mean 'very certain to respond' and 'very certain to answer'," Dr Lu said. "That's a terrific representation of what our brand stands for in the Chinese language."&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720555211888761111-1232263260799464493?l=innatesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/1232263260799464493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://innatesecurity.blogspot.com/2009/09/microsoft-search-branding-faux-pah.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/1232263260799464493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/1232263260799464493'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/2009/09/microsoft-search-branding-faux-pah.html' title='Microsoft Search Branding &quot;Faux Pah&quot;'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7720555211888761111.post-4178551068578900019</id><published>2009-07-01T07:59:00.000-07:00</published><updated>2009-07-01T08:06:44.094-07:00</updated><title type='text'>What Happens After the Lights Go Out?</title><content type='html'>&lt;span style="font-family:Calibri;"&gt;2008 was not a good year by any standard. As many of us try to rebuild our careers, our finances and some semblance of normality&lt;span class="msoIns"&gt;&lt;ins cite="mailto:%20" datetime="2009-04-22T09:26"&gt;,&lt;/ins&gt;&lt;/span&gt;; data privacy and information security is probably farthest from any company’s (or any individual’s) objectives for 2009.&lt;span style=""&gt;  &lt;/span&gt;And that’s when information theft becomes most opportunistic.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;As companies fold, merge or experience massive reorganizations, there emerges an excess of unsupervised personally identifiable information (PII) – whether it be through former employees, surplus equipment or forgotten databases. Although every company has a legal obligation to destroy any sensitive data as part of their exit strategy, by the time an information leak has been discovered there may no contact information for the defunct company.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Consider the following distinct cases:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;1)&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family:Calibri;"&gt;It was reported in January of 2009 that patients’ records for [now-defunct] Houston “Express EMS Services” was found in a parking lot and dumpster.&lt;span style="font-size:78%;"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn1" name="_ftnref1" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[1]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;2)&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family:Calibri;"&gt;Former employees of [now-defunct] L.G. Defelice Inc. had their Social Security Numbers posted on the web from improperly sanitized data retrieved from the DOT about the former company.&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn2" name="_ftnref2" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[2]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;3)&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family:Calibri;"&gt;The former NY United Hospital offered to make its records available to patients for six months while it was executing its closing procedure.&lt;span style=""&gt;  &lt;/span&gt;As part of its exit process, the hospital prepaid a third party to store any remaining records for a period of seven years; upon which they will be destroyed.&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn3" name="_ftnref3" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[3]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; The records are retrievable, but the only requirement for authorization is a signature; the verification of which is impractical.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;4)&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family:Calibri;"&gt;Client records from a mortgage broker “Seaview Financial of Corona del Mar” were found in a recycling bin during the company relocation in February of 2009.&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn4" name="_ftnref4" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[4]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;5)&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family:Calibri;"&gt;A large consumer electronics firm, upon exercising its exit strategy, considered two alternatives for data disposal: electronic wiping or physical destruction of storage.&lt;span style=""&gt;  &lt;/span&gt;(It was found more cost effective to physically destroy the disk drives.)&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn5" name="_ftnref5" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[5]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;And the list goes on and on… perusing “DataLossDB.org” will give one nightmares on the inefficacy of data protection in the real world.&lt;span style=""&gt;  &lt;/span&gt;The fact that the volume of incidents is large enough to be aggregated by industry, breach type, and information type is a disturbing indication on how extensive the problem of information leakage is.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;The Perfect Storm&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;This economy has created a “perfect storm” for identity fraud to thrive and grow. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Given three straight fiscal quarters of economic downsizing, the probability increases that companies which succumbed to the economic crisis will inadvertently fail to properly dispose of their sensitive data. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;As the unemployment rate reaches record proportions, the propensity of identity misuse – even something as simple as parents using their children’s SSN to get more credit – increases as well. (A study in 2008 found approximately 5% of families surveyed had children with compromised identity information&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn6" name="_ftnref6" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[6]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;From a market perspective, higher unemployment means the &lt;i style=""&gt;quality&lt;/i&gt; of current identity data decreases, poisoning the supply chain.&lt;span style=""&gt;  &lt;/span&gt;As a consequence, the price of PII drops dramatically, so &lt;i style=""&gt;quantity&lt;/i&gt; needs to increase to maintain the present market levels.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;Law and Responsibility&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;There are many regulations and guidelines specifying the protection and proper destruction of sensitive information. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;  &lt;v:stroke joinstyle="miter"&gt;  &lt;v:formulas&gt;   &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;   &lt;v:f eqn="sum @0 1 0"&gt;   &lt;v:f eqn="sum 0 0 @1"&gt;   &lt;v:f eqn="prod @2 1 2"&gt;   &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;   &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @0 0 1"&gt;   &lt;v:f eqn="prod @6 1 2"&gt;   &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;   &lt;v:f eqn="sum @8 21600 0"&gt;   &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @10 21600 0"&gt;  &lt;/v:f&gt;  &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;  &lt;o:lock ext="edit" aspectratio="t"&gt; &lt;/o:lock&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style="width: 12.75pt; height: 16.5pt;"&gt;&lt;span style=""&gt; &lt;/span&gt;HIPAA has long been criticized for its overly broad requirements prone to ambiguous and sometimes contradictory interpretation. Yet, this is one of the few regulations that mandates organizations &lt;span class="msoIns"&gt;&lt;ins cite="mailto:%20" datetime="2009-04-22T09:26"&gt;to &lt;/ins&gt;&lt;/span&gt;make accommodations for the proper storage and disposal of information for six years, even after an organization’s operations ceases&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn7" name="_ftnref7" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[7]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/v:shape&gt;&lt;/v:path&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;/v:stroke&gt;&lt;/v:shapetype&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;v:shape id="_x0000_i1026" type="#_x0000_t75" style="width: 12.75pt; height: 16.5pt;" bullet="t"&gt;  &lt;span style=""&gt; &lt;/span&gt;There are several &lt;st1:place st="on"&gt;&lt;st1:placename st="on"&gt;New York&lt;/st1:placename&gt; &lt;st1:placetype st="on"&gt;State&lt;/st1:placetype&gt;&lt;/st1:place&gt; laws that require businesses to follow a data retention schedule for information&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn8" name="_ftnref8" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[8]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;. Although these retention and disposal requirements are subject to legal interpretation, conservative legal council should follow the path of least risk and provision for post-operational protection.&lt;o:p&gt;&lt;/o:p&gt;&lt;/v:shape&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;v:shape id="_x0000_i1027" type="#_x0000_t75" style="width: 12.75pt; height: 15.75pt;"&gt;  &lt;span style=""&gt; &lt;/span&gt;The Fair and Accurate Credit Transaction Act of 2003 (FACTA)&lt;span class="msoIns"&gt;&lt;ins cite="mailto:%20" datetime="2009-04-22T09:26"&gt; &lt;/ins&gt;&lt;/span&gt;Disposal Rule “requires disposal practices that are reasonable and appropriate to prevent the unauthorized access to – or use of – information in a consumer report”&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn9" name="_ftnref9" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[9]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;, but it fails to explicitly specify if “reasonable” includes contingency plans if the responsible party ceases operations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/v:shape&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;v:shape id="_x0000_i1028" type="#_x0000_t75" style="width: 12.75pt; height: 15.75pt;"&gt;  &lt;span style=""&gt; &lt;/span&gt;The Gramm-Leach-Bliley Act Safeguards Rule is also quite specific about information protection with U.S.C. Title 15, Chapter 94, “Subchapter I: DISCLOSURE OF NONPUBLIC PERSONAL INFORMATION” and “Subchapter II: FRAUDULENT ACCESS TO FINANCIAL INFORMATION “&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn10" name="_ftnref10" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[10]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;.&lt;span style=""&gt;  &lt;/span&gt;There are specific rules for safeguarding nonpublic personal information as well as the communication of privacy protection practices. Yet, even in GLBA there is an interpretation loophole.&lt;span style=""&gt;  &lt;/span&gt;Although the protection of PII extends to “information of those no longer consumers of the financial institution,&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn11" name="_ftnref11" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[11]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;” it is unclear if it the responsibility applies if the “broken relationship” is caused by the company’s demise.&lt;o:p&gt;&lt;/o:p&gt;&lt;/v:shape&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;v:shape id="_x0000_i1029" type="#_x0000_t75" style="width: 12.75pt; height: 15.75pt;"&gt;  &lt;span style=""&gt; &lt;/span&gt;The reference to “internal controls” of Sarbanes-Oxley section 302 cannot be interpreted purely in the accounting sense; it pertains to information leakage if the lack of (or management overriding&lt;span class="msoIns"&gt;&lt;ins cite="mailto:%20" datetime="2009-04-22T09:26"&gt; of&lt;/ins&gt;&lt;/span&gt;) controls can lead to fraudulent activity or non-compliance. In Seaview Financial’s case above, there is a clear violation; but what about the similar situation with Express EMS Services? Do internal controls cease to be in effect if the company is no longer operating? &lt;o:p&gt;&lt;/o:p&gt;&lt;/v:shape&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Some legal experts believe more specific regulations are detrimental and that bankruptcy courts should address the interpretation of existing regulations with regard to data protection extensions.&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn12" name="_ftnref12" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[12]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;The Sedona Conference – a consortium of legal experts – has created “Best Practice Guidelines &amp;amp; Commentary for Managing Information &amp;amp; Records in the Electronic Age”&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn13" name="_ftnref13" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[13]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;. This guideline is followed by many legal professionals; and provides an ideal platform to specifically address these post-mortem data protection issues from a legal perspective. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;The Reality&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Most of the executives interviewed were not aware of any regulatory requirements for post-operational retention/disposal of data in their industries; although some were aware that their companies do have such plans and others have even exercised such plans with former employers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Looking into the problem more deeply, the root cause comes down to human error in three distinct ways:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;1)&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family:Calibri;"&gt;Lack of awareness or identification of sensitive information by employers, employees, vendors, clients and end users.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;2)&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family:Calibri;"&gt;Explicit negligence to follow proper information protection and disposal procedures; where operational efficiency outweighs privacy rules and regulations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;3)&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family:Calibri;"&gt;Failure of technology to classify and protect electronic information by both technology developers as well as users.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;We need to be aware of how information affects each and every one of us:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;u&gt;&lt;span style="font-family:Calibri;"&gt;As keepers of the information&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family:Calibri;"&gt;: The information protection priority for every CIO (or CPO) should always be effectiveness before efficiency.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;u&gt;&lt;span style="font-family:Calibri;"&gt;As users of the information:&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family:Calibri;"&gt; Every employee has an obligation to protect client information as well as ensuring their own PII is well protected and supervised.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;u&gt;&lt;span style="font-family:Calibri;"&gt;As owners of the information:&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family:Calibri;"&gt; As vested clients of various financial, medical and other institutions, we need to reach out and request the formal policies for data retention and destruction.&lt;span style=""&gt;  &lt;/span&gt;As with the case of &lt;st1:place st="on"&gt;&lt;st1:placename st="on"&gt;United&lt;/st1:placename&gt; &lt;st1:placetype st="on"&gt;Hospital&lt;/st1:placetype&gt;&lt;/st1:place&gt; above, there was a court-approved plan in place for proper handling and disposal of client data.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;The National Association for Information Destruction (NAID) provides a checklist for ensuring your company complies with the maximum set of regulatory requirements&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftn14" name="_ftnref14" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;[14]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;In Summary&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Although very few regulations explicitly address post-operational conditions, there is an interpretative factor with any regulation that defines specific schedules for data retention and disposal: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;i style=""&gt;&lt;span style="font-family:Calibri;"&gt;Are records retention/disposal requirements in effect beyond the life of the organization?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;There is no clear answer to this question.&lt;span style=""&gt;  &lt;/span&gt;For records that transcend a company’s purpose – medical record being the most obvious example – there needs to be better data retention policies.&lt;span style=""&gt;  &lt;/span&gt;Conversely, for consumer data that is only relevant to the operations of a company, common sense dictates the disposal of this information at the proper time. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Hence&lt;span class="msoIns"&gt;&lt;ins cite="mailto:%20" datetime="2009-04-22T09:26"&gt;, we&lt;/ins&gt;&lt;/span&gt; need a robust Information Lifecycle Management (ILM) initiative.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;span style=";font-family:Calibri;font-size:12pt;"  &gt;Information privacy, protection and governance are more difficult, more expensive and more costly in times of instability. Considering the frequency of information leaks in active companies; the exposure of PII gets exponentially greater once a company ceases operations.&lt;span style=""&gt;  &lt;/span&gt;It is imperative that your enterprise’s protection plans outlive the company.&lt;/span&gt;  &lt;div style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;br /&gt; &lt;hr align="left" size="1" width="33%"&gt;  &lt;!--[endif]--&gt;  &lt;div style="" id="ftn1"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref1" name="_ftn1" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[1]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; References:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;&lt;a href="http://datalossdb.org/incidents/1495-medical-records-of-defunct-ambulance-company-s-patients-found-in-parking-lot-and-dumpster"&gt;http://datalossdb.org/incidents/1495-medical-records-of-defunct-ambulance-company-s-patients-found-in-parking-lot-and-dumpster&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;&lt;a href="http://abclocal.go.com/ktrk/story?section=news/local&amp;amp;id=6605230"&gt;http://abclocal.go.com/ktrk/story?section=news/local&amp;amp;id=6605230&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;span style="font-size:9pt;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn2"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref2" name="_ftn2" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[2]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; References:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;&lt;a href="http://datalossdb.org/incidents/734-social-security-numbers-of-300-former-employees-of-defunct-l-g-defelice-inc-posted-on-ct-transportation-committee-website"&gt;http://datalossdb.org/incidents/734-social-security-numbers-of-300-former-employees-of-defunct-l-g-defelice-inc-posted-on-ct-transportation-committee-website&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;&lt;a href="http://attrition.org/dataloss/2007/07/conngatc01.html"&gt;http://attrition.org/dataloss/2007/07/conngatc01.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.25in;"&gt;&lt;span style="font-size:9pt;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn3"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref3" name="_ftn3" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[3]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; References:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;&lt;a href="http://www.allbusiness.com/health-care/health-care-facilities-nursing/10635002-1.html"&gt;http://www.allbusiness.com/health-care/health-care-facilities-nursing/10635002-1.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;&lt;a href="http://www.ironmountain.com/records/release/NYunited.asp"&gt;http://www.ironmountain.com/records/release/NYunited.asp&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;Interview with &lt;st1:place st="on"&gt;&lt;st1:placename st="on"&gt;Iron&lt;/st1:placename&gt; &lt;st1:placetype st="on"&gt;Mountain&lt;/st1:placetype&gt;&lt;/st1:place&gt; records release specialist for NY United Hospital&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn4"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref4" name="_ftn4" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[4]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; References:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;&lt;a href="http://datalossdb.org/incidents/1791-mortgage-broker-dumps-files-containing-clients-names-address-tax-forms-and-ssn-in-trash"&gt;http://datalossdb.org/incidents/1791-mortgage-broker-dumps-files-containing-clients-names-address-tax-forms-and-ssn-in-trash&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoFootnoteText" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7pt;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size:9pt;"&gt;&lt;a href="http://www.ocregister.com/articles/information-seaview-files-2316272-center-recycling"&gt;http://www.ocregister.com/articles/information-seaview-files-2316272-center-recycling&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn5"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref5" name="_ftn5" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[5]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Interview with CTO [person’s name removed by request] from [company name removed by request].&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn6"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref6" name="_ftn6" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[6]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: &lt;a href="http://www.debix.com/docs/Child_ID_Theft_Study_2008.10.pdf"&gt;http://www.debix.com/docs/Child_ID_Theft_Study_2008.10.pdf&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn7"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref7" name="_ftn7" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[7]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: &lt;a href="http://www.glrm-online.com/pdfs/HIPAA%20Record%20Retention%20Periods%202006.pdf"&gt;http://www.glrm-online.com/pdfs/HIPAA Record Retention Periods 2006.pdf&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn8"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref8" name="_ftn8" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[8]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: &lt;a href="http://www.archives.nysed.gov/a/records/mr_retention.shtml"&gt;http://www.archives.nysed.gov/a/records/mr_retention.shtml&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn9"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref9" name="_ftn9" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[9]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: &lt;a href="http://www.ftc.gov/opa/2005/06/disposal.shtm"&gt;http://www.ftc.gov/opa/2005/06/disposal.shtm&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn10"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref10" name="_ftn10" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[10]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: &lt;a href="http://www.law.cornell.edu/uscode/uscode15/usc_sup_01_15_10_94.html"&gt;http://www.law.cornell.edu/uscode/uscode15/usc_sup_01_15_10_94.html&lt;/a&gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn11"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref11" name="_ftn11" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[11]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: &lt;a href="http://en.wikipedia.org/wiki/Gramm-Leach-Bliley_Act#Safeguards_Rule"&gt;http://en.wikipedia.org/wiki/Gramm-Leach-Bliley_Act#Safeguards_Rule&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn12"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref12" name="_ftn12" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[12]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: Interview with legal experts [names withheld by request].&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn13"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref13" name="_ftn13" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[13]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: &lt;a href="http://www.thesedonaconference.org/dltForm?did=Guidelines.pdf"&gt;http://www.thesedonaconference.org/dltForm?did=Guidelines.pdf&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="ftn14"&gt;  &lt;p class="MsoFootnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-edit.do#_ftnref14" name="_ftn14" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:9pt;"  &gt;[14]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:9pt;"&gt; Reference: &lt;a href="http://www.naidonline.org/facts.html"&gt;http://www.naidonline.org/facts.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720555211888761111-4178551068578900019?l=innatesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/4178551068578900019/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://innatesecurity.blogspot.com/2009/07/what-happens-after-lights-go-out.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/4178551068578900019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/4178551068578900019'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/2009/07/what-happens-after-lights-go-out.html' title='What Happens After the Lights Go Out?'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7720555211888761111.post-2870675729708164959</id><published>2009-05-02T07:21:00.000-07:00</published><updated>2009-05-02T07:27:21.724-07:00</updated><title type='text'>Responsibilities of the Federal CTO and CIO</title><content type='html'>&lt;span style="font-family:Calibri;"&gt;I applaud the new president for his awareness that information technology is as important as any other infrastructure in the government. By creating Federal level Chief Technology Officer (CTO) and Chief Information Officer (CIO) positions, there exists the opportunity to create a long-term direction among the myriad of existing systems and processes within the government.&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Many articles have already dissected the proposed responsibilities of the Federal CTO and CIO.&lt;span style=""&gt;  &lt;/span&gt;In the Feb 16&lt;sup&gt;th&lt;/sup&gt; issue of InformationWeek&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_ftn1" name="_ftnref1" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;, for instance, twenty-six (26) business leaders in technology weighed in on the most pressing issues for the Federal CTO.&lt;span style=""&gt;  &lt;/span&gt;As diverse as the expert opinions are, they all have merit.&lt;span style=""&gt;  &lt;/span&gt;Congruent to the myriad of other articles covering this topic, this is indicative of how widespread the problems are that need attention.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;All these issues can be extrapolated to three (3) ideals that should be addressed by the current administration with regard to the CTO and CIO:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;1.&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;Focus on the Organization &lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;Mission&lt;/st1:city&gt;&lt;/st1:place&gt; and Workflow, not Technology:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;A CTO cannot possibly assume all of the responsibilities needed to lead an organization focus on technology alone. They must take into consideration the business value of the information issues that technology is trying to solve. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Conversely, the CIO must focus on the accuracy, confidentiality and security of information.&lt;span style=""&gt;  &lt;/span&gt;But they cannot do so without in-depth knowledge of technology solutions used for the capturing, classification and dissemination of information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;To be an effective leader means to know what the organizations goals are, past efforts, and its current operations.&lt;span style=""&gt;  &lt;/span&gt;Many times, the operations do not match the goals of the organization, and the technology matches neither the operations nor assists in attaining the goals’ objectives.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;The Federal CTO and CIO must align themselves with the missions of the various organizations, their goals and objectives; and affect the strategies pursued to achieve these objectives in a way that fosters cooperation and effectiveness, which eventually leads to efficiencies.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;For the Federal CTO and CIO, their customers are the agencies they support, not the OMB.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;2.&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;Synergies between the CTO and CIO:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;The CTO’s responsibilities are not the same as the CIO’s. [We have yet to see the ramifications of the Obama Administration selecting a former CTO for the position of CIO.]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;The CTO and CIO both start from the same basic question: “What information does each agency (or business unit) need to operate effectively?”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;The goals of the CIO:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="1" type="1"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Identify essential information needed for      proper business unit / agency operations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Verify the accuracy of all data points.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Apply an Information Lifecycle Management      (ILM) process for determining when information is the most useful and      when/how it should be discarded.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Organize, normalize, aggregate, analyze and      disseminate information to the appropriate operational entities.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Classify, protect and track usage of business      critical information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Contrary to popular practice, it should be the CTO supporting the CIO, not the other way around. The goal of the CTO is to effectively support the CIO’s objectives:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="1" type="1"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Design usable business processes and workflows      to support data capture.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Provide solutions to minimize duplication of      data; thereby minimizing overlap and extraneous work efforts by business      operations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Create effective and unambiguous views of      information for each level of audience.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style="font-family:Calibri;"&gt;Support feedback channels for refining      business processes and workflows.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Both need to focus on the business processes and workflows. Does the unit/agency garner the appropriate information? Do they properly store, organize and protect this data?&lt;span style=""&gt;  &lt;/span&gt;How do they interoperate and share information?&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Although the CTO and CIO may hold distinct views to such questions, they should eventually arrive at a complementary set of goals. This is one place where segregation and specialization can positively affect government operations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;&lt;span style=""&gt;3.&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;Stimulus Investment in Technology Infrastructure:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;During the 1930’s, the Federal plan to pull America out of the Great Depression was the creation of jobs through Federally-sponsored infrastructure expansion – specifically through the construction of bridges and roadways.&lt;span style=""&gt;  &lt;/span&gt;&lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;America&lt;/st1:place&gt;&lt;/st1:country-region&gt; was primarily an industrial society and this plan answered two key problems: (a) the country lacked a viable transportation infrastructure to support industrial growth and (b) these projects needed the same (or similar) skills of our unemployed workforce at that time.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Post WWII saw the expansion of the housing, education and auto industries as a response to the multitude of military forces migrating back to peace-time.&lt;span style=""&gt;  &lt;/span&gt;Again, this economic cycle took advantage of characteristics in our population – a mix of engineering and service-oriented demographics and a need for supporting the population explosion.&lt;span style=""&gt;  &lt;/span&gt;However, it also recognized the need for retraining of &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;America&lt;/st1:place&gt;&lt;/st1:country-region&gt;’s workforce, so education became a priority.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Today’s crisis consists of more complex problems.&lt;span style=""&gt;  &lt;/span&gt;&lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;America&lt;/st1:place&gt;&lt;/st1:country-region&gt; can no longer be characterized as an industrial society, an engineering society or even a service society.&lt;span style=""&gt;  &lt;/span&gt;We have become a society of deferment – managing and outsourcing our skills away. But there exists the opportunity to create a recovery effort that parallels those post-war times past.&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Our government needs to rebuild its infrastructure; not its public works infrastructure but its information and technology infrastructure.&lt;span style=""&gt;  &lt;/span&gt;The handling of information at the government level has grown and expanded haphazardly into a complex web of processing silos.&lt;span style=""&gt;  &lt;/span&gt;Consider the lack of communication (electronic and human) between agencies such as the CIA and FBI.&lt;span style=""&gt;  &lt;/span&gt;The creation of DHS simply places a wrapper on these problems and allows some cursory cooperation, but internal silos still exist.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;The stimulus plans that have been implemented by both the Bush and Obama administrations are misguided; either they try to boost lending among a population that cannot repay its existing debt, buy off toxic debt to allow financial firms to operate with impunity, or try to create jobs through legacy public works projects.&lt;span style=""&gt;  &lt;/span&gt;None of these approaches can have any long-term success.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;To rebuild our economy with strength and longevity means to address our needs as a country and as a society. &lt;span style=""&gt; &lt;/span&gt;The stimulus packages should create large public infrastructure projects – but it should be focused on the information and technology infrastructure.&lt;span style=""&gt;  &lt;/span&gt;This will employ the many Americans educated and skilled in technology (but unemployed due to off-shoring), increase the demand for higher education in technology areas and allow the government itself to be streamlined and efficient for the future.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Yes, it means the government will be paying more for technology services than the corporate world. The purpose here is to employ Americans, to stimulate the higher education of the population, and to launch the cycle of economic growth based on a solid foundation. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family:Calibri;"&gt;In Summary:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;The CTO/CIO are first and foremost a strategic thinkers, thought leaders that can extrapolate needs from desires, and prioritize goals into tactical strategies.&lt;span style=""&gt;  &lt;/span&gt;Secondly, they are business analysts which must address the realities of an organization against its objectives, understand where the gaps lie, and the mitigation options.&lt;span style=""&gt;  &lt;/span&gt;Thirdly, they are enablers, knowing where change is needed and disseminate authority to the “natural leaders” in the organization to affect that change.&lt;span style=""&gt;  &lt;/span&gt;Finally, the CTO/CIO must be accountable – to both those below them as well as to those above; they must provide the metrics, the ways and means to measure success.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;My hope is that our new Federal CTO and CIO will have the foresight to envision the feasible future, the qualities needed to chart a course, the leadership needed to promote their strategies both up and down the chain of command, and the authority to make a difference.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Calibri;"&gt;Or perhaps printing another $800B will do the trick.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;div style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720555211888761111-2870675729708164959?l=innatesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/2870675729708164959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://innatesecurity.blogspot.com/2009/05/responsibilities-of-federal-cto-and-cio.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/2870675729708164959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/2870675729708164959'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/2009/05/responsibilities-of-federal-cto-and-cio.html' title='Responsibilities of the Federal CTO and CIO'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7720555211888761111.post-7851010667235658270</id><published>2009-04-02T06:31:00.000-07:00</published><updated>2009-04-02T06:38:40.843-07:00</updated><title type='text'>Offshore Outsourcing and Intellectual Property Protection</title><content type='html'>Entering into the world of IT some decades ago, the typical employment process consisted of a written comprehension exam, two days of interviews, drug screening and even fingerprint registration with local authorities.  My most bizarre experience included a multi-task evaluation, where the candidate was enclosed in a small room with a written exam while new-age music was piped through room speakers at extraordinary levels, broken intermittently by verbal instructions to do some really odd tasks (i.e. “…put six pencils and two pens in the coffee mug labeled ‘Bob’ and place it in the bottom left-hand drawer, but only if you answered ‘yes’ to question 35…”).  All this effort to ensure that as an employee, a candidate was proficient for the needs at hand as well as loyal to the employer; how times have changed!&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;“Offshore business process outsourcing (BPO) is expected to reach $3 billion in 2004, a 65 percent increase from the 2003 total of $1.3 billion. In 2004, offshore BPO is expected to represent 2.3 percent of the total BPO market.” &lt;span style="font-style: italic;"&gt;- Gartner Research, May 18, 2004.&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Given the exponential rise of IT outsourcing by U.S. corporations, it is easily justified to promote offshore outsourcing within your company for several well-known reasons, the majority being:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Breadth of knowledge can be adjusted dynamically to the needs of each project, so the technologies utilized merely become another variable to accomplish a business goal.&lt;/li&gt;&lt;li&gt;Cost of development moves from overhead budgets (full-time head-count) to operational budgets. This expense can now be justified by showing greater flexibility to increase/decrease manpower over the short-term.&lt;/li&gt;&lt;li&gt;Offshore manpower costs are often substantially lower than domestic rates.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;For all inherent benefits of offshore outsourcing, there exists a powerful liability that, when left untreated, can have disastrous results.  The dissemination of intellectual property occurs every time one business outsources another -- whether for payroll, advertising and especially IT development. &lt;br /&gt;&lt;br /&gt;Consider these statistics.  From the “2003 CSI/FBI Survey on Computer Crime and Security”, 61 of 398 respondents acknowledged theft of proprietary information which resulted in financial loss totaling $70M . In the “2003 BSI Computer Theft Survey” of 676 participants, 9.2% of respondents who acknowledged theft of proprietary information stated the financial loss at $1M and 2.3% valued the loss at $10M .  Would any company hand over intellectual property to an unmitigated risk?  Yet, it happens, as exemplified by the source code leaks for both Microsoft and Cisco. Could they have been avoided? Not completely, but it should serve as a wake-up call to all businesses to review their IP protection policies with all their partners, especially those which exist outside a company’s base operating country.&lt;br /&gt;&lt;br /&gt;How one approaches intellectual property protection (IPP) can affect the overall effectiveness and efficiency of any outsourcing effort.  A traditional project manager will start with a baseline savings of efficiency (time, expenses, et al) and reduce each benefit by applying the cost of risk factors in the 80/20 fashion.  A security professional will always start with a baseline cost of protection planning and overlay the benefits to assess a spectrum of “best-case” to “worst-case” scenarios.  From these scenarios, a risk / remediation analysis is presented to management, whereby the business can make an informed decision on the amount of risk it is willing to expose. Given the extra up-front planning efforts needed by multiple business branches to implement the security professional’s method, which would in reality get the most support from the decision-makers in your company?&lt;br /&gt;&lt;br /&gt;IPP assessments for outsourcing can be daunting, but by breaking the effort down into the risk areas below, much of the assessment needs to be done only once, and can be re-used for subsequent outsourcing projects. Following is a pared-down checklist that can assist in the planning effort for IPP and outsourcing:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Business Assessment&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;(What are the official host company’s security policies for IPP?)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Where is the company's base of operation?&lt;/li&gt;&lt;li&gt;Does the company have international offices with legal representation?&lt;/li&gt;&lt;li&gt;Does the company currently outsource IT development efforts?&lt;/li&gt;&lt;li&gt;Within those countries with international offices?&lt;/li&gt;&lt;li&gt;In countries without the company’s international presence?&lt;/li&gt;&lt;li&gt;How does the current project rely on trade secrets or other intellectual property?&lt;/li&gt;&lt;li&gt;Are these IP assets considered tangible or intangible?&lt;/li&gt;&lt;li&gt;What amounts of risk are attached to these IP assets?&lt;/li&gt;&lt;li&gt;What methods of assessment were applied to arrive at these figures?&lt;/li&gt;&lt;li&gt;What existing policies are in place to protect IP during development?&lt;/li&gt;&lt;li&gt;Does your company specifically address IP protection and outsourcing?&lt;/li&gt;&lt;li&gt;What IPP compliance does the company require from outsourcing companies and other partners? (bonding, et al)&lt;/li&gt;&lt;li&gt;What is the cost of creating/supporting such policies?&lt;/li&gt;&lt;li&gt;What existing experiences with IPP can be drawn upon?&lt;/li&gt;&lt;li&gt;Are these experiences formally documented?&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Legal Assessment &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;(What legal tools support international protection of IP?)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;What types of legal agreements are in place for:&lt;/li&gt;&lt;li&gt;Opening IP to outside parties? (NDA, et al)&lt;/li&gt;&lt;li&gt;Doing sensitive business internationally?&lt;/li&gt;&lt;li&gt;What legal options are available for non-compliance or breach of these agreements?&lt;/li&gt;&lt;li&gt;What international laws are provided to pursue non-compliance?&lt;/li&gt;&lt;li&gt;What protections does the outsourcing company’s host government provide?&lt;/li&gt;&lt;li&gt;In what venue must legal proceedings occur?&lt;/li&gt;&lt;li&gt;Have there ever been any accusations of breach or threat of legal action?&lt;/li&gt;&lt;li&gt;If so, how was it handled?&lt;/li&gt;&lt;li&gt;What internal actions were taken as a result (change of policy, et al)?&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Outsourcing Assessment &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;(What are the official outsourcing company’s security policies for IPP?)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;How does the outsourcing company approach the topic of IP-based contracts?&lt;/li&gt;&lt;li&gt;What internal policies are in place to protect their clients' IP?&lt;/li&gt;&lt;li&gt;How do the outsourcing company’s protection policies compare to those of the host company?&lt;/li&gt;&lt;li&gt;Where do the policies go above and beyond your policies?&lt;/li&gt;&lt;li&gt;What specific points do the policies lack?&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Accountability Issues&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Accountability, as a management tool, is necessary to measure project flow, define remediation procedures for any fallout, and provide root cause analysis for future prevention.  Accountability methods work best within controlled environments (i.e. within the enterprise).  When uncontrolled factors are introduced, normal accountability methods can actually create a false sense of completeness. Two major issues exist when an accountability matrix includes outsourced personnel.&lt;br /&gt;&lt;br /&gt;The first issue with accountability is the lack of host company presence at outsourced work offices. Much of traditional compliance validation comes implicitly from direct (formal and informal) contact with employees. Since the loss of intellectual property can cause irreparable damage to your company, careful planning is needed to validate compliance early and often, especially in the absence of direct contact with the outsourced employees.  Scheduled as well as unscheduled onsite visits are crucial even if other travel budgets are frozen. First-hand documentation of compliance is a necessity.  To highlight this point, the New York State Department of Environmental Protection relies almost solely on company-generated reports for water pollution control compliance; whereas in another realm, the Department of Defense has inspectors sent to every vendor facility to ensure spec compliance on each batch of materials purchased. Which method of compliance validation matches the needs of your project? (I personally avoid swimming in NYS waterways.)&lt;br /&gt;&lt;br /&gt;The other major issue with accountability is remediation. An IT manager has not only the power but also the responsibility to enforce all company policies with respect to protecting company property.  An IT manager may even have the power to choose outsourcing companies based on their policies and past experience.  But once a contract is determined to be out of compliance, an IT manager may need to turn to the legal staff to enforce remediation.  In other words, even if an offshore outsourcing firm has identical IPP guidelines as the host company, compliance is ultimately determined by the laws in the country of arbitration defined in the outsourcing contract.  Accountability is no longer an issue of meeting deadlines, but rather a basis for possible legal action.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What Are the Next Steps?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;(Document, Document, Document)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Modify your accountability methods to ensure compliance by focusing on three areas:  validate formally, validate consistently and validate often.&lt;/li&gt;&lt;li&gt;Determine the measurement criteria that would positively identify an intellectual property breach.  This cannot be overstated.  These criteria become the pinnacle for any investigation or legal actions.  Too ambiguous: no legal case can use them.  Too detailed: a breach may not be caught because all the identifiers were not triggered.&lt;/li&gt;&lt;li&gt;Ensure that these findings are well communicated with all decision-making parties.  &lt;/li&gt;&lt;li&gt;Ensure the legal support staff includes these aspects with all written contracts. The legal department will most likely define the company’s host country as the point for arbitration.&lt;/li&gt;&lt;li&gt;Ensure the outsourcing parties understand these aspects. This is most effectively accomplished by having the outside parties present a formal document on how they comply with your IPP guidelines.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Creating your “IPP Guideline for Outsourcing” now can save many troubles years down the road.  Regardless of any business partners’ guidelines and procedures for IPP, it is still your company that is held liable for compliance with SOX and HIPAA.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;John C. Checco, CISSP (john.checco@checco.com) is a member of the American Society for Industrial Security (ASIS) NYC Chapter and president of bioChecTM (www.biochec.com), a division of Checco Services, Inc.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720555211888761111-7851010667235658270?l=innatesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/7851010667235658270/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://innatesecurity.blogspot.com/2009/04/offshore-outsourcing-and-intellectual.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/7851010667235658270'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/7851010667235658270'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/2009/04/offshore-outsourcing-and-intellectual.html' title='Offshore Outsourcing and Intellectual Property Protection'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7720555211888761111.post-8232718507569921945</id><published>2009-03-25T11:00:00.000-07:00</published><updated>2009-04-02T06:30:48.682-07:00</updated><title type='text'>Information Crisis Management</title><content type='html'>&lt;p class="MsoNormal"&gt;Information Crisis Management defines the SOP used when proprietary information assets are compromised, either by network breaches or employee breaches.&lt;span style=""&gt;  &lt;/span&gt;According to ASIS, “Fortune 1000 companies lost more than $45B from the theft of proprietary information” in a single year&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_edn1" name="_ednref1" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:12;"  &gt;[i]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;h2&gt;Cockpit Resource Management?&lt;/h2&gt;    &lt;p class="MsoNormal"&gt;The FAA, in response to the avoidable crash of United Airlines Flight 173 on &lt;st1:date year="1978" day="28" month="12" st="on"&gt;Dec.  28, 1978&lt;/st1:date&gt;, developed one of the first “critical thinking” guidelines for crisis management.&lt;span style=""&gt;  &lt;/span&gt;Originally known as “Cockpit Resource Management” (and later changed to “Crew Resource Management”), this process is integrated by many emergency services into their Incident Command System.&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_edn2" name="_ednref2" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:12;"  &gt;[ii]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; One particular aspect of this guideline that applies to any group of decision-makers is the use of the three “&lt;i&gt;decision outcome avenues&lt;/i&gt;.”&lt;/p&gt;    &lt;ol style="margin-top: 0in;" start="1" type="1"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;b style=""&gt;Avoid&lt;/b&gt;: plan to prevent      possibilities of a crisis.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;b style=""&gt;Trap&lt;/b&gt;: recognize bad decisions and      fix potential problems before a crisis.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;b style=""&gt;Mitigate:&lt;/b&gt; minimize the negative      effect during a crisis and investigate post-crisis.  &lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The concept of “decision outcome avenues” applies directly to information security planning.&lt;span style=""&gt;  &lt;/span&gt;Many organizations spend sufficient effort on plans to avoid and trap breaches, but mitigation is usually not a well pre-planned effort.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;h2&gt;Pre-Planning for Mitigation&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/h2&gt;    &lt;p class="MsoNormal"&gt;To plan for an effective post-crisis investigation, an organization needs to plan pre-crisis. &lt;i&gt;Content-specific planning&lt;/i&gt; addresses the mitigation of direct breaches, intentionally accessing information for dissemination outside its intended audience.&lt;span style=""&gt;  &lt;/span&gt;&lt;i&gt;Access-specific planning&lt;/i&gt; addresses the mitigation of indirect breaches, hijacking legitimate information access.&lt;span style=""&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;At the heart of this plan lies the explicit determination of informational risk.&lt;span style=""&gt;  &lt;/span&gt;The organization must first evaluate any information that is considered proprietary.&lt;span style=""&gt;  &lt;/span&gt;This may mean a substantial effort in collecting information that is subject to scrutiny, but it is a necessary task for every organization.&lt;span style=""&gt;  &lt;/span&gt;Second, it must classify information according to damage control needed: i.e. source code needs to be under version control, sensitive documents need to be centrally managed, etc. Information that is considered paramount should be in lock-down mode – inaccessible except through physical means, even if it means having a standalone workstation holding the information in a locked room.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;h3&gt;Content-Specific Planning&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/h3&gt;    &lt;p class="MsoNormal"&gt;For documents that are considered confidential, companies need to institute a central document repository.&lt;span style=""&gt;  &lt;/span&gt;Companies that are ISO-9001 compliant should already have this in place.&lt;span style=""&gt;  &lt;/span&gt;However, additional precautions should be taken.&lt;span style=""&gt;  &lt;/span&gt;&lt;/p&gt;    &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;The      repository should have strict entitlement rules for each user.&lt;span style=""&gt;  &lt;/span&gt;Proper licensing should be in place for      the document management system to allow each user access, rather than a      set of shared userids.&lt;/li&gt;&lt;/ul&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Classification      is necessary for all new documents being submitted to the central      repository.&lt;span style=""&gt;  &lt;/span&gt;This need not be a      committee review, just a second authority to ensure documents are properly      protected.&lt;/li&gt;&lt;/ul&gt;    &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Document      server storage should be encrypted.&lt;/li&gt;&lt;/ul&gt;    &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Authors      can request a document in editable form; all others MUST get the document      in read-only form.&lt;span style=""&gt;  &lt;/span&gt;Software      utilities, such as Win2PDF, can accomplish this task dynamically as an      extension to most document management systems.&lt;/li&gt;&lt;/ul&gt;    &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Tracking      of highly-sensitive documents, already done on the server side through      audit logs, should be augmented with steganography.&lt;span style=""&gt;  &lt;/span&gt;Steganography is a technique to embed      requester information (who, what, where and when) into a document when it      is downloaded from the server.&lt;span style=""&gt;  &lt;/span&gt;A      recovered document now provides forensic evidence for post-crisis      investigations.&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Source code can be similarly managed via a variety of version-control systems.&lt;span style=""&gt;  &lt;/span&gt;Extensions, such as read-only access and steganography, cannot apply here because of the working nature of source code.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;h3&gt;Access-Specific Planning&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/h3&gt;    &lt;p class="MsoNormal"&gt;Of 503 corporations and government agencies polled, 33% cited their internal systems as a frequent point of attack.&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_edn3" name="_ednref3" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:12;"  &gt;[iii]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=""&gt;  &lt;/span&gt;Intranet-specific safety is comprised of two parts: access and information flow.&lt;span style=""&gt;  &lt;/span&gt;&lt;/p&gt;    &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;b style=""&gt;Access&lt;/b&gt; refers to both &lt;i&gt;ingress&lt;/i&gt;      and &lt;i&gt;egress&lt;/i&gt; of information systems as well as critical information      applications. A plethora of secure login systems are available from smart      cards to polymorphic password tokens and biometric devices. &lt;i&gt;Other      factors, such as &lt;b&gt;auditing&lt;/b&gt;, &lt;b&gt;actual vs. intended usage&lt;/b&gt; and &lt;b&gt;ensuring      logoff&lt;/b&gt;, are just as important.&lt;/i&gt;&lt;span style=""&gt;       &lt;/span&gt;Proximity badges, which use short-range RF devices to communicate authorization      information to nearby computers, are finding their way into many businesses      as a means to provide more security while maximizing user acceptance. Proximity      badges are highly recommended as a secondary means of login authorization and      for ensuring unattended logoff, although they tend to be misused. In one      case, a hospital equipped all personnel with proximity badges for      automatic login. “Doctors didn’t like always having to type in a password.&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_edn4" name="_ednref4" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:12;"  &gt;[iv]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;”&lt;span style=""&gt;  &lt;/span&gt;This particular use of proximity access      control systems is troublesome because gives a false sense of security,      yet the hospital is considered fully compliant with HIPAA&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_edn5" name="_ednref5" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:12;"  &gt;[v]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;      regulations. &lt;/li&gt;&lt;/ul&gt;    &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;b style=""&gt;Information flow&lt;/b&gt; refers to ad-hoc      documents and messages exchanged within and/or outside of an      organization’s network.&lt;span style=""&gt;  &lt;/span&gt;The      popularity of IM and document swapping via email are two prime areas for security      review.&lt;span style=""&gt;  &lt;/span&gt;Companies should augment      employees with their own custom IM packages that have the controls to:      transmit using a secure protocol and track/log access between outside      persons or large transfers.&lt;span style=""&gt;  &lt;/span&gt;For      emailing of documents, encryption is desired, but many times too difficult      to use.&lt;span style=""&gt;  &lt;/span&gt;Solution providers, such as      Sigaba, provide enterprise-wide encryption proxies on top of standard      internet services.&lt;span style=""&gt;  &lt;/span&gt;Another promising      technology touted by magiQ Technologies, is the use of quantum      cryptography as a method to ensure “a message has been securely delivered      between two parties – and that no copy exists.”&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_edn6" name="_ednref6" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:12;"  &gt;[vi]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;h2&gt;&lt;br /&gt;&lt;/h2&gt;&lt;h2&gt;Conclusion&lt;/h2&gt;    &lt;p class="MsoNormal"&gt;It is important to assess your organization’s mitigation SOP for informational losses.&lt;span style=""&gt;  &lt;/span&gt;The mitigation pre-planning process allows an organization to assess its information liability and decisively take risk. And most importantly, it provides a solid foundation for any post-crisis investigation.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;i style=""&gt;&lt;span style="font-size:10;"&gt;*** The author is not associated in any way, does not exclusively endorse, nor receives any fees from any of the products/companies mentioned in the article.&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:10;"&gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;div style=""&gt;&lt;!--[if !supportEndnotes]--&gt;&lt;br /&gt; &lt;hr size="1" width="33%" align="left"&gt;  &lt;!--[endif]--&gt;  &lt;div style="" id="edn1"&gt;  &lt;p class="MsoEndnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_ednref1" name="_edn1" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:10;"  &gt;[i]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; American Society for Industrial Security, 2000.&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="edn2"&gt;  &lt;p class="MsoEndnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_ednref2" name="_edn2" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:10;"  &gt;[ii]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; “Crew Resource Management,” Dennis L. Rubin, Firehouse Magazine, July 2002.&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="edn3"&gt;  &lt;p class="MsoEndnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_ednref3" name="_edn3" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:10;"  &gt;[iii]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; “2002 Computer Crime and Security Survey,” Computer Security Institute.&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="edn4"&gt;  &lt;p class="MsoEndnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_ednref4" name="_edn4" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:10;"  &gt;[iv]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; “Security Goes the Distance,” George V. Hulme, Information Week, &lt;st1:date year="2003" day="13" month="1" st="on"&gt;January 13, 2003&lt;/st1:date&gt;.&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="edn5"&gt;  &lt;p class="MsoEndnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_ednref5" name="_edn5" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:10;"  &gt;[v]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; The Health Insurance Portability and Accountability Act of 1996&lt;/p&gt;  &lt;/div&gt;  &lt;div style="" id="edn6"&gt;  &lt;p class="MsoEndnoteText"&gt;&lt;a style="" href="http://www.blogger.com/post-create.g?blogID=7720555211888761111#_ednref6" name="_edn6" title=""&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=""&gt;&lt;!--[if !supportFootnotes]--&gt;&lt;span class="MsoEndnoteReference"&gt;&lt;span style=";font-family:&amp;quot;;font-size:10;"  &gt;[vi]&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; “Security’s Next Steps,” Brian Fonseca, InfoWorld, &lt;st1:date year="2003" day="13" month="1" st="on"&gt;January 13, 2003&lt;/st1:date&gt;.&lt;/p&gt;  &lt;/div&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720555211888761111-8232718507569921945?l=innatesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://innatesecurity.blogspot.com/feeds/8232718507569921945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://innatesecurity.blogspot.com/2009/03/information-crisis-management.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/8232718507569921945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720555211888761111/posts/default/8232718507569921945'/><link rel='alternate' type='text/html' href='http://innatesecurity.blogspot.com/2009/03/information-crisis-management.html' title='Information Crisis Management'/><author><name>John C. Checco, CISSP CSSLP CCSK</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
