<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Israeli Software &#187; Anti-Fraud</title>
	<atom:link href="http://www.software.co.il/wordpress/category/anti-fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.software.co.il/wordpress</link>
	<description>Data security by a software developer and musician</description>
	<lastBuildDate>Fri, 30 Jul 2010 15:14:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Database activity monitoring</title>
		<link>http://www.software.co.il/wordpress/2010/06/database-activity-monitoring/</link>
		<comments>http://www.software.co.il/wordpress/2010/06/database-activity-monitoring/#comments</comments>
		<pubDate>Wed, 16 Jun 2010 19:53:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data leakage]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Internal security]]></category>
		<category><![CDATA[database security]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[DOM]]></category>
		<category><![CDATA[ethics]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2417</guid>
		<description><![CDATA[If you deploy or are considering data security technology from Websense, Fidelis, Verdasys , Guardium, Imperva or Sentrigo &#8211; do you give a DAM ? It seems that DLP (data loss prevention)  vendors are moving up the food chain into DAM (database activity monitoring)? As customers deploy two products in parallel (for example Imperva and [...]]]></description>
			<content:encoded><![CDATA[<p>If you deploy or are considering data security technology from Websense, Fidelis, Verdasys , Guardium, Imperva or Sentrigo &#8211; do you give a DAM ?</p>
<p>It seems that DLP (data loss prevention)  vendors are moving up the food chain into DAM (database activity monitoring)? As customers deploy two products in parallel (for example Imperva and Fidelis) for DLP and DAM &#8211; the opportunity for reducing TCO (total cost of ownership) seems to be a clear imperative.</p>
<p>Both Websense and Fidelis Security  provide DLP functionality for structured data in databases (Fidelis calls it internal DLP) and Websense provides fairly granular fingerprinting of combinations of relational table columns using their PreciseID technology.</p>
<p>Although Websense focuses on deep content analysis and stays away from application security, Verdasys provides application logging at the end point and Fidelis provides application analysis via the network session in addition to the deep content inspection. Both are functions strongly related to database activity monitoring.</p>
<p>Here are the goals I would put down for database activity monitoring, due to the high level of interaction with client/sever and Web applications</p>
<div>
<ul>
<li>Perform  monitoring of ERP, CRM, HR, BI/data warehouse, financial application access to the data model  in order to detect irregular patterns indicative of fraud (for example &#8211; repetitive access to celebrity account numbers)</li>
<li>Audit  database segregation of duties (SOD) &#8211; for example, detecting select all statements by the database administration on schema involving customer data.</li>
<li>Measure the extent of  database vulnerabilities in order to quantify probability of occurrence</li>
<li>Do it without having to touch the database management system software &#8211; for example, by  sniffing of database network traffic and decoding the protocols &#8211; like Oracle OCI.</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/06/database-activity-monitoring/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>2010 FIFA world cup game and software piracy</title>
		<link>http://www.software.co.il/wordpress/2010/06/2010-fifa-world-cup-game-and-software-piracy/</link>
		<comments>http://www.software.co.il/wordpress/2010/06/2010-fifa-world-cup-game-and-software-piracy/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 14:08:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Digital media]]></category>
		<category><![CDATA[ethics]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Software piracy]]></category>
		<category><![CDATA[World cup]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2395</guid>
		<description><![CDATA[It&#8217;s World Cup season and Mondial fever will probably put a lot of regional conflicts on the back burner for the next month &#8211; not to mention put a dent in a lot of family budgets (husbands buying the latest 60 inch Sony Bravia and wives on retail therapy while the guys are watching football) [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s World Cup season and Mondial fever will probably put a lot of regional conflicts on the back burner for the next month &#8211; not to mention put a dent in a lot of family budgets (husbands buying the latest <a title="Sont Bravia" href="http://www.sonystyle.com/webapp/wcs/stores/servlet/ProductDisplay?catalogId=10551&amp;storeId=10151&amp;langId=-1&amp;productId=8198552921666077668" target="_blank">60 inch Sony Bravia</a> and wives on retail therapy while the guys are watching football)</p>
<p>I  wanted to write a review of the <a title="2010 FIFA World Cup South Africa (video game)" href="http://en.wikipedia.org/wiki/2010_FIFA_World_Cup_South_Africa_(video_game)" target="_blank">2010 FIFA World Cup South Africa video game</a> (it would have been a great excuse for my wife) but I don&#8217;t have the right platform &#8211; I use Ubuntu and I have neither an Xbox 360 nor a Playstation 3.</p>
<p>It&#8217;s ironic that the South African  World cup game doesn&#8217;t run on Ubuntu.  It would have been a huge marketing coup and poetic justice if the game software was released for Ubuntu in a GPL license.</p>
<p>That got me thinking about open source licensing and it&#8217;s advantages for developing countries, which really got my hackles up  after reading the <a title="Software Theft Remains Significant Issue Around the World" href="http://portal.bsa.org/globalpiracy2009/index.html" target="_blank">Seventh Annual BSA and IDC Global Software Piracy Study</a> &#8211; that screams:  <em>Software Theft Remains Significant Issue Around the World</em></p>
<blockquote><p>The rate of global software piracy climbed to 43 percent in 2009. This increase was fueled in large part by expanding PC sales in fast-growing, high-piracy countries and increasing sales to consumers — two market segments that traditionally have higher incidents of software theft. In 2009, for every $100 worth of legitimate software sold, an additional $75 worth of unlicensed software made its way onto the market. There was some progress in 2009 — software rates actually dropped in almost half of the countries examined in this year’s study.</p>
<p>Given the global recession, the software piracy picture could have taken a dramatic turn for the worse. But progress is being outstripped by the overall increases in piracy globally — and highlights the need for governments, law enforcement and industry to work together to address this vital economic issue.<br />
Below are key findings from this year’s study:</p>
<ul>
<li><strong>Commercial value of software theft exceeds $50 billion: </strong>the commercial value of unlicensed software put into the market in 2009 totalled $51.4 billion.</li>
<li><strong>Progress on piracy held through the recession: </strong>the rate of PC software piracy dropped in nearly half (49%) of the 111 economies studied, remained the same in 34% and rose in 17%.</li>
<li><strong>Piracy continues to rise on a global basis: </strong>the worldwide piracy rate increased from 41% in 2008 to 43% in 2009; largely a result of exponential growth in the PC and software markets in higher piracy, fast growing markets such as Brazil, India and China.</li>
</ul>
</blockquote>
<p>I would not take the numbers IDC and BSA bring at face value. The IDC/BSA estimates are guesses multiplied several times. They start off by assuming that each unit of copied software represents a direct loss of sale for software vendor &#8211; patently a false assertion.</p>
<p>If it <strong>were</strong> true, then the demand for software would be independent of price and perfectly inelastic.</p>
<p>A drop in price usually results in an increase in the quantity demanded by consumers. That&#8217;s called price elasticity of demand. The demand for a product becomes inelastic when the demand doesn&#8217;t change with price. A product with no competing alternative is generally inelastic. Demand for a unique antibiotic, for example is highly inelastic. A patient will pay any price to buy the only drug that will kill their infection.</p>
<p><strong>If</strong> software demand was perfectly inelastic, then everyone would pay in order to avoid the BSA enforcement tax. The rate of software piracy would be 0. Since piracy rate is non-zero, that proves that the original assertion is false. (Argument courtesy of the <a href="http://en.wikipedia.org/wiki/Price_elasticity_of_demand">Wikipedia article on price elasticity of demand</a> )</p>
<p>Back when I ran Bynet Software Systems &#8211; we were the first Microsoft Back Office/Windows NT distributor in Israel. I had just left Intel &#8211; where we had negotiated a deal with Microsoft that allowed every employee to make a copy of MS Office for home usage. Back in 1997 &#8211; after the Windows NT launch, the demand for NT was almost totally inelastic &#8211; Not There, Nice Try, WNT is VMS + 1 etc. We could not give the stuff away in the first year. Customers were telling us that they would never leave Novell Netware. Never. But, NT got better from release to release and the big Microsoft marketing machine got behind the product. After two years of struggle and selling retail boxes and MLP for NT, demand picked up. Realizing that there IS price elasticity of demand for software &#8211; Microsoft dropped retail packaging and moved to OEM licensing, initially distributing OEM licenses via their two tier distribution channel and later totally cutting out the channel and dealing directly with the computer vendors like HP, Dell and IBM for OEM licenses of NT, XP and 2000, 2003 etc. Vista continued with this marketing strategy and most Vista sales were not retail boxes but pre-installed hardware. After Windows 7 released &#8211; users have been upgrading en-masse, proving once again the elasticity of demand for a good product.</p>
<p>Microsoft (who are a major stakeholder in BSA) probably don&#8217;t have a major piracy problem with operating system sales. Let&#8217;s run some numbers. In 2008 &#8211;  Microsoft <a href="http://www.vnunet.com/vnunet/news/2208182/vista-tops-100-million-mark">Windows Vista sales </a>were at about a 9 million unit/quarter run rate. Microsoft <a href="http://finance.google.com/finance?q=msft">June 2008 quarterly revenue</a> was $15.8 BN. Single unit OEM pricing for a Windows operating system  is about $80 and in a volume deal &#8211; maybe $20. Let&#8217;s assume an average of $50/OEM license. This means that the operating system  accounts for about 50*3*9/15800 = 8.5% of Microsoft revenue.</p>
<p>The <a href="http://w3.bsa.org/globalstudy//upload/2007-Global-Piracy-Study-EN.pdf">BSA Global Piracy Study</a> states that the &#8220;median piracy rate in is down one percentage point from last year&#8221; &#8211; 1 percent of 8.5 percent is meaningless for Microsoft &#8211; in dollar terms &#8211; BSA work to reduce piracy is less meaningful than a 7 percent drop in the US Dollar rate in 2009.</p>
<p>Microsoft might have a problem with their cash cow &#8211; Microsoft Office. Microsoft Office 2007 retails for $450 but is available in an academic license for less than $100. Open Office 2.4 runs just fine on Windows 7 and XP and retails for $0. At those prices, sizable numbers of users are just sliding down the elasticity curve &#8211; calling into serious question the IDC/BSA statistics on software piracy.</p>
<p>But there is more to software piracy than providing software at a reasonable price. In poor areas of the world &#8211; assuming that the BSA efforts at combating software piracy are successful - <a href="http://www.acm.org/ubiquity/views/v5i20_jezsik.html">only the very rich would have access</a> to applications like Microsoft Office. The middle and lower class people won&#8217;t have the opportunity to become MS Office-literate because the prices would be too high. For that I only have three words -<a href="http://www.openoffice.org/">download Open Office</a> &#8211; the free and open productivity suite.</p>
<p>Finally &#8211; I can only anonymously quote a senior Microsoft executive who told me a number of years ago that off the record, Microsoft didn&#8217;t mind people copying the software and using a crack because it was a good way of introducing new users to the technology and inducing them to buy the new, improved and supported release a year or two later.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/06/2010-fifa-world-cup-game-and-software-piracy/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The next generation of risk analysis</title>
		<link>http://www.software.co.il/wordpress/2010/06/the-next-generation-of-risk-analysis/</link>
		<comments>http://www.software.co.il/wordpress/2010/06/the-next-generation-of-risk-analysis/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 07:34:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[ethics]]></category>
		<category><![CDATA[Risk management]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2382</guid>
		<description><![CDATA[&#8220;What me worry &#8211; I&#8217;ve got a regulatory check list and an enterprise risk management system to manage the process&#8221;. I want to talk about under-thinking the risk analysis and over-spending on the solution. I believe that there is a fundamental flaw in  enterprise risk management systems &#8211;  they don&#8217;t really tell the organization something [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p><a href="http://www.software.co.il/wordpress/wp-content/uploads/2010/06/alfred_e_neuman1.jpg"><img class="alignleft size-medium wp-image-2387" title="what me worry" src="http://www.software.co.il/wordpress/wp-content/uploads/2010/06/alfred_e_neuman1-231x300.jpg" alt="" width="231" height="300" /></a>&#8220;What me worry &#8211; I&#8217;ve got a regulatory check list and an enterprise risk management system to manage the process&#8221;.</p>
<p>I want to talk about under-thinking the risk analysis and over-spending on the solution.</p>
<p>I believe that there is a fundamental flaw in  enterprise risk management systems &#8211;  they don&#8217;t really tell the organization something it doesn&#8217;t already know and if  we don&#8217;t bring some fresh input and new risk intelligence to the board room,we are not going to be very effective at mitigating new threats.</p>
<p>The  problem with  enterprise risk management systems starts with a   focus on managing internal business processes, as if mitigating threats to intellectual property is like producing a purchase requisition.</p>
<p>Systems like <a title="Oracle Enterprise Risk Management" href="http://www.oracle.com/us/industries/financial-services/046748.html" target="_blank">Oracle ERM</a> help <em>&#8220;assess risk for a portfolio across multiple parameters&#8221;</em> and provide a powerful way of collecting data from users by asking them how &#8216;risky&#8217; is their part of a business process and then roll up the total risk in the business process. This approach of self-assessments may actually be a very bad idea for an effective risk mitigation program, since users can answer  self-guided questionnaires any way they feel like. It&#8217;s called GIGO, garbage in garbage out &#8211; i.e. a system that rolls up a bunch of arbitrary answers will give an arbitrary result which might help the auditor rack up billable hours but may not help the management anticipate and mitigate threats in a cost-effective way.</p>
<p>Most of these systems seem to try to satisfy one kind of compliance regulation or another. Asking a bunch of people how risky their part of the business process whether they care about it or not is not a good way of ensuring quality data collection.  This sort of risk assessment doesn&#8217;t  help people do their job better and doesn&#8217;t help a business protect customer data more effectively.</p>
<p>Another vulnerability of enterprise risk management stems from a standardized check list approach which encourages under-thinking the analysis and over-spending on the solution.  Check lists like PCI DSS 1.2 were outdated the moment they were publicized and comprehensive checklists like ISO27001 are lacking security metrics and prioritization of control implementation &#8211; although, I will grant that ISO is moving in that direction.</p>
<p>While checklist applications are important for the customer and the auditor in order to prove compliance &#8211; sticking blindly to a checklist doesn&#8217;t help an organization find cost-effective security controls, respond to new threats or sustain a consistent level of security.</p>
<p>There are a few things that I&#8217;d like to see in a next generation risk management system that might help organizations get out from under their rock and discover new threats and new ways of implementing countermeasures:</p>
</div>
<div id="more">
<ul>
<li>Believe it or not &#8211; a totally different user interface &#8211; like maybe Facebook for risk assessment. If risk assessment was a must-have business resource like general ledger, then the user interface might not matter but I suspect that a social-networking application of  risk data collection and collaboration between analysts, attackers, vendors and managers might go a long way. SMS and email, for example, were hard to use when they were first introduced, but the network connectivity value that users got out of it was so high that people used it anyway and then the  applications took off like sky rockets.</li>
<li>Global catalog of risk model classes &amp; entities &#8211; like a Wikipedia of risk</li>
<li>Multiple language support (let&#8217;s face it, most of  the world doesn&#8217;t speak English)</li>
<li>Open source plugin  risk models and model inheritance &#8211; that would enable a threat analyst in India to build a risk model base class and have an analyst in San Francisco be able to inherit the model and add new functionality</li>
<li>Risk model authoring and entitlement &#8211; this would help risk analysts monetize their efforts.</li>
</ul>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/06/the-next-generation-of-risk-analysis/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Standardized screening for data security risk</title>
		<link>http://www.software.co.il/wordpress/2010/05/standardized-screening-for-data-security-risk/</link>
		<comments>http://www.software.co.il/wordpress/2010/05/standardized-screening-for-data-security-risk/#comments</comments>
		<pubDate>Sun, 09 May 2010 08:07:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data leakage]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Internal security]]></category>
		<category><![CDATA[business threat modeling]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data loss]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DLP]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2356</guid>
		<description><![CDATA[Best practices for data security are still evolving &#8211; as there are no industry-standard data security metrics and a confusing array of regulatory compliance and industry standards &#8211; PCI DSS 1.2, Sarbanes-Oxley, FISMA, ISO2700x &#8211; just to name a few. Organizations (government included) currently use a combination of tactics &#8211; penetration testing, vulnerability analysis (usually [...]]]></description>
			<content:encoded><![CDATA[<p>Best practices for data security are still evolving &#8211; as there are no industry-standard data security metrics and a confusing array of regulatory compliance and industry standards &#8211; PCI DSS 1.2, Sarbanes-Oxley, FISMA, ISO2700x &#8211; just to name a few.</p>
<p>Organizations (government included) currently use a combination of tactics &#8211; penetration testing, vulnerability analysis (usually at the network and sometimes at the application software layer), &#8220;fire and forget&#8221; compliance exercises and technology countermeasures such as IPS/IDS, network DLP, agent DLP, database firewalls, encryption on demand, Web application firewalls.</p>
<p>The one countermeasure I have never seen is standardized screening.  Borrowing an approach from health-care, consider the following:</p>
<blockquote><p>Standardized screening for suicide risk in primary care can detect adolescents with suicidal ideation, allowing referral to a behavioral healthcare center before a fatal or serious suicide attempt is made, according to the results of a study reported online April 12 and published in the May print issue of <em>Pediatrics</em>.</p>
<p>&#8220;Several associations and federal agencies have called for depression screening in pediatric primary care,&#8221; writes Matthew B. Wintersteen, PhD, from Thomas Jefferson University in Philadelphia, Pennsylvania. &#8220;Screening for suicide risk is a natural adjunct to this call&#8230;.To our knowledge, this is the first study to prospectively examine the impact of standardized screening for suicide risk on detection and referral rates in pediatric primary care.&#8221;</p>
<p>The goals of the study were to evaluate whether brief standardized screening for suicide risk in pediatric primary care practices could improve detection of youth with suicidal ideation, maintain improved rates of detection and referral, and be<em> duplicated in other practices</em>.</p></blockquote>
<p>It seems to me that duplicating brief standardized screening to data security practice is eminently possible.   A possible approach would involve using a standard threat model based on a comprehensive set of security controls &#8211; (ISO 27001 would work fine for this purpose).  The process would start with a pre-screening preparation exercise that an organization could do in the office in 1-2 hours.   After the preparation exercise, a group of 3-5 people from a business unit would meet with a data security specialist for the standardized screening that would walk through the threat model and gauge probability of occurrence of vulnerabilities and  percent damage to assets by threats.  Based on my experience, this sort of walk-through would take 2-3 hours using the structured threat model.  The result of the threat analysis would be a level of value at risk to the organization for data security and indeed a 1/2 day qualifies as brief enough.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/05/standardized-screening-for-data-security-risk/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The 4 questions</title>
		<link>http://www.software.co.il/wordpress/2010/04/the-4-questions/</link>
		<comments>http://www.software.co.il/wordpress/2010/04/the-4-questions/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 21:01:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data leakage]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Internal security]]></category>
		<category><![CDATA[business threat modeling]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[Verdasys]]></category>
		<category><![CDATA[Websense]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2306</guid>
		<description><![CDATA[One of the famous canons in the Jewish Passover &#8220;seder&#8221; ritual is 4 questions from 4 sons &#8211; the son who is wise, the son who is wicked, the son who is innocent and the son who doesn&#8217;t know enough to ask. I sometimes have this feeling of Deja vu when considering data security technology [...]]]></description>
			<content:encoded><![CDATA[<p>One of the famous canons in the Jewish Passover &#8220;seder&#8221; ritual is 4 questions from 4 sons &#8211; the son who is wise, the son who is wicked, the son who is innocent and the son who doesn&#8217;t know enough to ask.</p>
<p>I sometimes have this feeling of <em>Deja vu </em>when considering data security technology solutions. Although the analogy is not at all parallel &#8211; I have written a list of 4 questions to be asked when considering a DLP solution &#8211; these questions require clear, authoritative answers just like in the Passover seder (להבדיל).</p>
<ol>
<li>What is the key threat scenario?</li>
<li>How much Value at Risk is on the table?</li>
<li>Who owns the project?</li>
<li>Does the DLP technology fit the threat scenario?</li>
</ol>
<h3 dir="ltr">1 &#8211; What is the key threat scenario?</h3>
<p dir="ltr">Here are some typical threat scenarios – the key threat scenario should keep a C-level executive awake at night.</p>
<table border="1" cellspacing="0" cellpadding="0" width="619">
<tbody>
<tr>
<td width="174" valign="top">
<p dir="ltr"><strong>Threat Scenario</strong></p>
</td>
<td width="97" valign="top">
<p dir="ltr"><strong>Sample Asset(s)</strong></p>
</td>
<td width="78" valign="top">
<p dir="ltr"><strong>Threat(s)</strong></p>
</td>
<td width="138" valign="top">
<p dir="ltr"><strong>Vulnerabilities</strong></p>
</td>
<td width="132" valign="top">
<p dir="ltr"><strong>Countermeasures</strong></p>
</td>
</tr>
<tr>
<td width="174" valign="top">
<p dir="ltr"><strong>Leakage or theft of PII (personally identifiable information)</strong></p>
</td>
<td width="97" valign="top">
<p dir="ltr">Customer data and/or credit cards</p>
</td>
<td width="78" valign="top">
<p dir="ltr">Insiders</p>
<p dir="ltr">Resellers</p>
<p dir="ltr">Criminals</p>
<p dir="ltr">Hackers</p>
<p dir="ltr">Terrorists</p>
</td>
<td width="138" valign="top">
<p dir="ltr">Employees may be bribed or exploited</p>
<p dir="ltr">Weak passwords</p>
<p dir="ltr">Wi-Fi networks</p>
<p dir="ltr">Temporary files</p>
<p dir="ltr">Firewalls</p>
<p dir="ltr">Proxy bypass</p>
<p dir="ltr">Web services</p>
<p dir="ltr">FTP services</p>
<p dir="ltr">Operating systems</p>
</td>
<td width="132" valign="top">
<p dir="ltr">Network DLP</p>
<p dir="ltr">Database DLP</p>
<p dir="ltr">Encryption</p>
<p dir="ltr">Policies</p>
<p dir="ltr">Procedures</p>
<p dir="ltr">Software security assessments</p>
<p dir="ltr">Patching</p>
</td>
</tr>
<tr>
<td width="174" valign="top">
<p dir="ltr"><strong>Loss of IP on servers</strong></p>
</td>
<td width="97" valign="top">
<p dir="ltr">Designs</p>
</td>
<td width="78" valign="top">
<p dir="ltr">Insiders</p>
<p dir="ltr">Competitors</p>
</td>
<td width="138" valign="top">
<p dir="ltr">Same</p>
<p dir="ltr">
</td>
<td width="132" valign="top">
<p dir="ltr">Network DLP</p>
</td>
</tr>
<tr>
<td width="174" valign="top">
<p dir="ltr"><strong>Loss of IP in the cloud</strong></p>
</td>
<td width="97" valign="top">
<p dir="ltr">Designs</p>
</td>
<td width="78" valign="top">
<p dir="ltr">Insiders</p>
<p dir="ltr">Competitors</p>
<p dir="ltr">Vendor employee</p>
</td>
<td width="138" valign="top">
<p dir="ltr">Same +</p>
<p dir="ltr">Unreliable cloud vendor</p>
</td>
<td width="132" valign="top">
<p dir="ltr">Network DLP at provider</p>
</td>
</tr>
<tr>
<td width="174" valign="top">
<p dir="ltr"><strong>Loss of IP on notebooks</strong></p>
</td>
<td width="97" valign="top">
<p dir="ltr">Designs</p>
</td>
<td width="78" valign="top">
<p dir="ltr">Employees</p>
<p dir="ltr">Theft</p>
<p dir="ltr">Loss</p>
</td>
<td width="138" valign="top">
<p dir="ltr">Employees in airports</p>
<p dir="ltr">
</td>
<td width="132" valign="top">
<p dir="ltr">Agent DLP</p>
<p dir="ltr">Encryption</p>
</td>
</tr>
<tr>
<td width="174" valign="top">
<p dir="ltr"><strong>Loss of data from business partners</strong></p>
</td>
<td width="97" valign="top">
<p dir="ltr">Customer data, IP</p>
</td>
<td width="78" valign="top">
<p dir="ltr">May steal the data</p>
</td>
<td width="138" valign="top">
<p dir="ltr">Partner systems</p>
<p dir="ltr">Web based links</p>
<p dir="ltr">Firewalls</p>
</td>
<td width="132" valign="top">
<p dir="ltr">Network DLP</p>
<p dir="ltr">Agent DRM or</p>
<p dir="ltr">Agent DLP</p>
</td>
</tr>
</tbody>
</table>
<p dir="ltr">See <a href="http://www.software.co.il/wordpress/2010/02/is-there-a-business-need-for-dlp/">http://www.software.co.il/wordpress/2010/02/is-there-a-business-need-for-dlp/</a></p>
<p dir="ltr">
<h3 dir="ltr">2 &#8211; What is your value at risk?</h3>
<p dir="ltr">Once you have identified the key threat scenario, you must know how much value at risk is generated when a threat exploits vulnerabilities to cause damage to assets. The basis for measuring VaR (value at risk) is the asset value (generally determined by the CFO) -</p>
<blockquote>
<p dir="ltr">VaR = asset value x threat probability x estimated damage to asset value in a percentage</p>
</blockquote>
<p dir="ltr">The VaR is reduced by a set of security countermeasures that also have a cost. VaR is best calculated in a <strong>data security based risk assessment</strong> that uses DLP technology to measure frequencies of threat occurrence and a calculative threat model to derive VaR.</p>
<p dir="ltr">Most companies are not at a sufficient level of security maturity to do this exercise themselves – and will need an independent consultant with specific data security expertise and the ability to do analytical threat modeling.</p>
<p dir="ltr">Within a couple weeks, you should be able to get a picture of your current data security events, know your data value at risk in Euro and build a prioritized program for cost-effective DLP countermeasures.</p>
<p dir="ltr">See <a href="http://www.software.co.il/wordpress/2010/01/building-a-business-case-for-dlp/">http://www.software.co.il/wordpress/2010/01/building-a-business-case-for-dlp/</a></p>
<h3 dir="ltr"></h3>
<h3 dir="ltr">3 &#8211; Who owns the project?</h3>
<p dir="ltr">Beware of organizational politics and silos and conflicting agendas.  Need I say more?</p>
<h3 dir="ltr"></h3>
<h3 dir="ltr">4 &#8211; Does the DLP technology fit the threat scenario?</h3>
<p dir="ltr">Just because the vendor sold you an anti-virus product doesn&#8217;t mean that his DLP technology is a good fit (even if it&#8217;s free)</p>
<p dir="ltr"><strong>Example A</strong>:  A network DLP solution may be required with 1GB throughput, if the technology saturates at 200MB/S then the solution is not a good fit.</p>
<p dir="ltr"><strong>Example B</strong>:  An agent DLP solution may be required that is capable of identifying IP in AutoCAD files; if the content analysis software is incapable of decoding AutoCAD, then the countermeasure does not mitigate the vulnerability.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/04/the-4-questions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Content protection and plagiarism</title>
		<link>http://www.software.co.il/wordpress/2010/02/content-protection-and-plagiarism/</link>
		<comments>http://www.software.co.il/wordpress/2010/02/content-protection-and-plagiarism/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 06:36:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Risk management]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2254</guid>
		<description><![CDATA[Most people tend to view content protection as a recording industry or corporate espionage  issue.   We have forgotten that people who plagiarize original content are also violating content security &#8211; someone else&#8217;s security in this case. My colleague Anthony Freed (who runs Information Security Resources) recently got an email from computer scientist and mathematician, Aaron Krowne.  Aaron got [...]]]></description>
			<content:encoded><![CDATA[<p>Most people tend to view content protection as a recording industry or corporate espionage  issue.   We have forgotten that people who plagiarize original content are also violating content security &#8211; someone else&#8217;s security in this case.</p>
<p>My colleague Anthony Freed (who runs <a title="Information security resources" href="http://www.information-security-resources.com/" target="_blank">Information Security Resources</a>) recently got an email from computer scientist and mathematician, Aaron Krowne.  Aaron got plagiarized by no less than the the NY Times. The original story that Aaron reported is here &#8211; <a title="NY Times Caught Lifting Implode-O-Meter, Other Online Pubs' Material" href="http://ml-implode.com/viewnews/2010-02-16_NYTimesCaughtLiftingImplodeOMeterOtherOnlinePubsMaterial.html" target="_blank">NY Times Caught Lifting Implode-O-Meter, Other Online Pubs&#8217; Material</a></p>
<p><a title="NY Times Caught Lifting Implode-O-Meter, Other Online Pubs' Material" href="http://ml-implode.com/viewnews/2010-02-16_NYTimesCaughtLiftingImplodeOMeterOtherOnlinePubsMaterial.html" target="_blank"></a>With Aaron&#8217;s kind permission, I&#8217;ve decided to republish  the original article verbatim as a public service to my data security clients in the tech, bio-pharma and telecom industries &#8211; because it could happen to you also. Paraphrasing and proper citations are the kind of thing they teach you in elementary school and this is a blunt reminder to remember what Ms. Bates, your third grade teacher taught you.</p>
<blockquote><p>We knew it was happening, but it looks like it was more extensive and systematic than we first thought:</p>
<p><a title="How long did New York Times editors know of Kouwe’s story copying?" href="http://blog.ctnews.com/teribuhl/2010/02/16/how-long-did-new-york-times-editors-know-of-kouwes-story-copying/" target="_blank">How long did New York Times editors know of Kouwe’s story copying?</a></p></blockquote>
<div>On Dec. 26, 2008, an online publication covering the housing market, Mortgage Implode-O-Meter, published an exclusive news report that a group of financial services firms, led by Steven Mnuchin of Dune Capital, would be buying failed IndyMac Bank from the FDIC. IndyMac was one of the first large thrift banks to be seized by the FDIC at the start of the financial crisis.</p>
<p>A day later, Kouwe reported for the NYT’s Dealbook that Dune Capital was expected to buy IndyMac and added two other names of buyers, JC Flowers and John Paulson, to the story. Kouwe’s report did not credit Mortgage Implode-O-Meter for first breaking the fact that 1) a private equity group was buying IndyMac 2) Dune Capital was involved.</p>
<p>Wire services picked up the NYT’s story and the rest of the business press ended up sourcing Kouwe for breaking the news on the sale of IndyMac to a private equity group.</p>
</div>
<p>Shockingly, Kouwe wrote the below, justifying his plagiarism and failures to attribute (my bold, and comments in italics):</p>
<div>I don’t know what to tell you. Things move so quickly on the Web that <strong>citing who had it first is something that is likely going away, especially in the age of blogs<em> [except of course amongst blogs themselves, which give attribution religiously.]</em></strong><br />
<span id="more-2254"></span><br />
For instance Dealbreaker and other blogs report on a lot of stories, but<strong> I don’t think anybody has ever cited them as being first with a particular scoop <em>[even if no one else were doing it, would more wrongs make a right?]</em></strong>. I’ve had it happen to me a bunch of times at The Post and it really didn’t bother me because most <strong>readers just don’t care. They don’t read bylines and they don’t care about whether one paper cited a website or another paper in their stories<em>[I am a reader and I can attest that I care.  The idea of attribution is to provide it for sophisticated readers and other journalists who want, nay, who NEED to see the sourcing]</em>.<span style="font-weight: normal;">much as you can; the mainstream media MUST be held accountable.</span></strong></div>
<p>Also noteworthy, the NY Times may have lifted material from one of my other sites, IamFacingForeclosure.com, back in 2007, when we were reporting on Judge Boyko in Ohio throwing out foreclosures for failure to produce the note:</p>
<p><a href="http://iamfacingforeclosure.com/blog/2007/11/16/true-sale-false-securitizations/" target="_blank">http://iamfacingforeclosure.com/blog/2007/11/16/true-sale-false-securitizations/</a></p>
<p>Back then I assumed the similar (even verbatim, in parts) coverage was just a coincedence.    Now I&#8217;m not so sure.  The &#8220;similarities&#8221; in the NY Times story led some to comment back then:</p>
<div>“It may be a Casey [Serin, former blogger at IamFacingForeclosure.com] fantasy, but it is true in real life.<strong> I Am Facing Foreclosure broke a story that was respected enough and accurate enough to be stolen by the New York Times.”</strong></div>
<p>In a final irony, the NY Times has not taken interest in any of our significant free speech &#8220;SLAPP&#8221; suits (despite my <em>dozens</em> of emails to prior contacts there).    While both challenge freedom of the press, in one of them, a New Hampshire Superior Court judge <em>specifically threw out the Pentagon Papers rationale</em> (which conferred to the NYTimes&#8217; benefit in the 70&#8242;s), bringing the whole &#8220;let&#8217;s shirk the blogs&#8221; mindset full circle.   Who will cry for the NY Times when they are gagged on the next &#8220;Pentagon Papers&#8221; issue by today&#8217;s far more authoritarian courts, because they let their blog &#8220;competitors&#8221; get savaged by the omnipresent enemies of free speech?</p>
<p>(More info on the suits can be found at these URLs:</p>
<p><a href="http://www.citmedialaw.org/blog/2009/sam-bayard/new-hampshire-court-tramples-constitution-reporters-privilege-section-230-what-have-you" target="_blank">http://www.citmedialaw.org/blog/2009/sam-bayard/new-hampshire-court-tramples-constitution-reporters-privilege-section-230-what-have-you</a><br />
<a href="http://ml-implode.com/viewnews/2008-10-09_FHASellerFundedDownpaymentOutfitSuesMLImplodeInEffortToSilenceCr.html" target="_blank">http://ml-implode.com/viewnews/2008-10-09_FHASellerFundedDownpaymentOutfitSuesMLImplodeInEffortToSilenceCr.html</a> )<br />
<span style="color: #888888;"><br />
-Aaron<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/02/content-protection-and-plagiarism/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Do you have a business need for DLP?</title>
		<link>http://www.software.co.il/wordpress/2010/02/is-there-a-business-need-for-dlp/</link>
		<comments>http://www.software.co.il/wordpress/2010/02/is-there-a-business-need-for-dlp/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 10:56:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data leakage]]></category>
		<category><![CDATA[Risk mitigation]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Threat modeling]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data loss]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[Verdasys]]></category>
		<category><![CDATA[Websense]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2228</guid>
		<description><![CDATA[To be able to do something before it exists, sense before it becomes active, and see before it sprouts. The Book of Balance and Harmony (Chung-ho chi). A medieval Taoist book Will security vendors, large to small  (Symantec, Mcafee, nexTier, ANBsys and others..) succeed in restoring balance and harmony to their customers by relabeling their product suites as unified content [...]]]></description>
			<content:encoded><![CDATA[<p id="first_paragraph"><em><a href="http://www.software.co.il/wordpress/wp-content/uploads/2010/02/kit-harmony2.jpg"><img class="alignleft size-full wp-image-2231" title="Balance and Harmony" src="http://www.software.co.il/wordpress/wp-content/uploads/2010/02/kit-harmony2.jpg" alt="" width="200" height="228" /></a></em></p>
<p><em>To be able to do something before it exists,<br />
sense before it becomes active,<br />
and see before it sprouts.</em></p>
<p><em> </em><br />
<strong>The Book of Balance and Harmony </strong></p>
<p><strong>(Chung-ho chi)</strong>.<br />
<em>A medieval Taoist book</em></p>
<p>Will security vendors, large to small  (<a title="Symantec" href="http://www.symantec.com" target="_blank">Symantec</a>, <a title="Mcafee" href="http://www.mcafee.com" target="_blank">Mcafee</a>, <a title="Nextier Networks DLP" href="http://www.nextiernetworks.com/" target="_blank">nexTier</a>, <a title="DataNforcer " href="http://www.anbsys.com/" target="_blank">ANBsys</a> and others..) succeed in restoring balance and harmony to their customers by relabeling their product suites as <em>unified content security (</em><a title="Websense unified content security" href="http://www.websense.com" target="_blank">Websense</a>) or <em>enterprise information protection (<a title="Verdasys" href="http://www.verdasys.com" target="_blank"><span style="font-style: normal;">Verdasys</span></a>)?</em></p>
<p>I don&#8217;t think so.</p>
<p>Unfortunately &#8211; data security is not an enterprise suite kind of problem like ERP. You don&#8217;t have harmony, synergy and control over business process; you have <em>orthogonal attack vectors:</em></p>
<ul>
<li><strong>Human error</strong> &#8211; cc&#8217;ing a supplier by mistake on a classified RFP document</li>
<li><strong>System vulnerabilities</strong> &#8211; Production servers with anonymous file transfer protocol (FTP) turned on</li>
<li><strong>Criminal activity</strong> &#8211; Break-ins, bribes and double agents (workers who spy for other groups or companies)</li>
<li><strong>Industrial competition</strong>/breach of non-disclosure agreements &#8211; the actuary who went to work for the competition</li>
</ul>
<p>After 5 years of hype, most  customers have a high awareness of DLP products but fewer (especially outside the US) are buying DLP technologies  and even fewer are succeeding with their DLP implementations. This stems from the customer and vendors&#8217; inability to answer two simple questions:</p>
<ol>
<li><strong>Who is the buyer?</strong></li>
<li><strong>What is her motivation to protect information?</strong></li>
</ol>
<p>A common question I hear from my clients, is, &#8220;Who should &#8216;own&#8217; data security technology?&#8221; Is it the vice president, internal auditor, chief financial officer, CIO or CSO, our security consultants or our IT outsourcing vendor; IBM Global Services?</p>
<blockquote><p>If there is no clear business need for information protection (the kind that a CEO can enunciate in a  sentence) &#8211; the company is not going to buy DLP technology.</p>
<p>The business need for data security derives directly from  the CEO and his management team. In firms with outsourced IT infrastructure, the need for data security becomes more acute as more people are involved with less allegiance to the firm.</p></blockquote>
<p>To help qualify an organization&#8217;s business need for DLP technology, let&#8217;s examine the <strong><em>decision drivers</em></strong>, or what compels companies to buy data security products, and the decision-makers, or those who sign off on the products. Let&#8217;s look at seven industries: banking, credit card issuing, insurance, pharmaceuticals, telecommunications, health care and technology.</p>
<table cellspacing="2" cellpadding="2" width="100%">
<tbody>
<tr>
<td width="30%" align="center" bgcolor="#cc9900"><strong>INDUSTRY</strong></td>
<td width="50%" align="center" bgcolor="#cc9900"><strong>TYPICAL DATA SECURITY DRIVERS</strong></td>
<td width="20%" align="center" bgcolor="#cc9900"><strong>DECISION &#8211; MAKERS</strong></td>
</tr>
<tr>
<td width="30%" valign="top" bgcolor="#ffcc66"><strong>BANKING</strong></td>
<td width="50%" valign="top" bgcolor="#cccccc"><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> A real event, such as theft of confidential customer account information by trusted insiders</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Privacy regulations such as the Gramm-Leach-Bliley Act, HIPAA</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> The Sarbanes-Oxley Act, for transparency and timeliness in reporting of significant events</td>
<td width="20%" valign="top" bgcolor="#cccccc">CSO or CIO</td>
</tr>
<tr>
<td width="30%" valign="top" bgcolor="#ffcc66"><strong>CREDIT CARD ISSUERS</strong></td>
<td width="50%" bgcolor="#cccccc"><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Ongoing theft of customer transactional information by customer service reps</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Data breach threat to credit card numbers that haven&#8217;t yet been printed on plastic cards and issued to card holders</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Privacy regulations, Sarbanes-Oxley , nondisclosure agreements with business partners</td>
<td width="20%" valign="top" bgcolor="#cccccc">The security officer or information security officer (many issuers have separate functions for physical and information security)</td>
</tr>
<tr>
<td width="30%" valign="top" bgcolor="#ffcc66"><strong>INSURANCE</strong></td>
<td width="50%" bgcolor="#cccccc"><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> A real event, such as theft of customer lists by competitors</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Fear of losing actuarial data</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Exposure to data leakage of credit card numbers in online systems</td>
<td width="20%" valign="top" bgcolor="#cccccc">General counsel, VP of internal audit, CFO</td>
</tr>
<tr>
<td width="30%" valign="top" bgcolor="#ffcc66"><strong>PHARMACEUTICALS</strong></td>
<td width="50%" bgcolor="#cccccc"><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Theft of chemistry, manufacturing and control information, product formulation and genome data by trusted insiders</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Difficulty in preserving secrecy of sensitive intellectual property prior to patent filings</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Sensitivity of company records during due diligence processes</td>
<td width="20%" valign="top" bgcolor="#cccccc">General counsel, CFO, chief compliance officer</td>
</tr>
<tr>
<td width="30%" valign="top" bgcolor="#ffcc66"><strong>TELECOM/ONLINE BUSINESS<br />
</strong>(Telecom service providers and large online operations such as Yahoo collect and aggregate huge quantities of data, and the higher up the value chain you go with data aggregation, the more valuable and vulnerable the asset.)</td>
<td width="50%" valign="top" bgcolor="#cccccc"><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Prepaid code files</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Pricing data</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Strategic marketing plans</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Call detail records (analogous to credit card transaction records, these are extrusions by customer service representatives to private investigators and difficult to detect)</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Customer credit card records</td>
<td width="20%" valign="top" bgcolor="#cccccc">VP of internal audit, VP of technologies</td>
</tr>
<tr>
<td width="30%" valign="top" bgcolor="#ffcc66"><strong>HEALTH CARE</strong></td>
<td width="50%" bgcolor="#cccccc"><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Privacy regulations/HIPAA</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Need to protect pricing data of drugs and supplies purchased by the health care organization</td>
<td width="20%" valign="top" bgcolor="#cccccc">CSO, VP of internal audit</td>
</tr>
<tr>
<td width="30%" valign="top" bgcolor="#ffcc66"><strong>TECHNOLOGY COMPANIES</strong></td>
<td width="50%" bgcolor="#cccccc">Theft of:</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Source code</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Designs, pictures and plans of proprietary equipment</p>
<p><img src="http://www.computerworld.com/computerworld/records/images/site/black_bullet.gif" alt="" width="5" height="5" align="absmiddle" /> Strategic marketing plans</td>
<td width="20%" valign="top" bgcolor="#cccccc">CEO, CTO</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/02/is-there-a-business-need-for-dlp/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Data security and compliance  &#8211; Best practices</title>
		<link>http://www.software.co.il/wordpress/2010/01/data-security-and-compliance-beyond-vendor-hype/</link>
		<comments>http://www.software.co.il/wordpress/2010/01/data-security-and-compliance-beyond-vendor-hype/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 16:38:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data leakage]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[business threat modeling]]></category>
		<category><![CDATA[Data loss]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DLP]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2191</guid>
		<description><![CDATA[Compliance is about enforcing business process &#8211; for example, PCI DSS is about getting the transaction authorized without getting the data stolen. SOX is about sufficiency of internal controls for financial reporting and HIPAA is about being able to disclose PHI to patients without leaks to unauthorized parties. So where and how does DLP fit into the compliance [...]]]></description>
			<content:encoded><![CDATA[<p>Compliance is about enforcing business process &#8211; for example, PCI DSS is about getting the transaction authorized without getting the data stolen. SOX is about sufficiency of internal controls for financial reporting and HIPAA is about being able to disclose PHI to patients without leaks to unauthorized parties.</p>
<p>So where and how does DLP fit into the compliance equation?</p>
<p>Let&#8217;s start with COSO recommendations for internal controls:</p>
<blockquote>
<div id="_mcePaste">“If the internal control system is implemented only to prevent fraud and comply with laws and regulations, then an important opportunity is missed&#8230;The same internal controls can also be used to systematically improve businesses, particularly in regard to effectiveness and efficiency.”</div>
</blockquote>
<div id="_mcePaste">In the attached presentation &#8211; we review data security requirements in compliance regulation, we discuss provable security and show how DLP can serve both as an invaluable measurement tool of security metrics of inbound and outbound business transactions and when required &#8211; as a last line of defense for personal account numbers.</div>
<div>
<div id="__ss_3016001" style="width: 425px; text-align: left;"><a style="font: 14px Helvetica,Arial,Sans-serif; display: block; margin: 12px 0 3px 0; text-decoration: underline;" title="Data Security For Compliance 2" href="http://www.slideshare.net/dannyl50/data-security-for-compliance-2">Data Security For Compliance 2</a><object style="margin: 0px;" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=datasecurityforcompliance-2-100128102316-phpapp02&amp;rel=0&amp;stripped_title=data-security-for-compliance-2" /><param name="allowfullscreen" value="true" /><embed style="margin: 0px;" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=datasecurityforcompliance-2-100128102316-phpapp02&amp;rel=0&amp;stripped_title=data-security-for-compliance-2" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View more <a style="text-decoration: underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration: underline;" href="http://www.slideshare.net/dannyl50">dannyl50</a>.</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/01/data-security-and-compliance-beyond-vendor-hype/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Building a business case for DLP</title>
		<link>http://www.software.co.il/wordpress/2010/01/building-a-business-case-for-dlp/</link>
		<comments>http://www.software.co.il/wordpress/2010/01/building-a-business-case-for-dlp/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 12:34:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data leakage]]></category>
		<category><![CDATA[Data loss]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DLP]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2181</guid>
		<description><![CDATA[At a meeting with one of our clients last week &#8211; the question of business case for data loss prevention came up quite strongly.   It started with the client saying that they were hearing that while vendors like Symantec and Websense were getting a lot of customers to buy their DLP products &#8211; many [...]]]></description>
			<content:encoded><![CDATA[<p>At a meeting with one of our clients last week &#8211; the question of business case for data loss prevention came up quite strongly.   It started with the client saying that they were hearing that while vendors like Symantec and Websense were getting a lot of customers to<strong><em> buy</em></strong> their DLP products &#8211; many of these customers were <strong><em>failing</em></strong> at their attempt to <strong><em>implement</em></strong> DLP.</p>
<p>The detailed reasons why people fail at DLP implementations merits a separate post &#8211;  but it&#8217;s a lot like why over 50% of the content management implementation from vendors like Vignette never made it to production in the 90s &#8211; the root cause was that there was no real business case for the technology.</p>
<p>I want to talk about why  building a business case for Data security is critical to the success of your data security/data loss prevention/fraud prevention project.</p>
<p>If you run a business or business unit &#8211; you must ask yourself two questions</p>
<p><strong>Is data security a major operational risk for your business?</strong></p>
<p>Could be.</p>
<p>Unlike a computer virus &#8211; internally launched attacks on data  that result in data leaks, breach of  integrity, loss of data availability and non-compliance are your problem, not someone elses.</p>
<p>Unlike business processes – data risk cannot be outsourced.</p>
<p>Unlike balance sheet assets &#8211; companies don&#8217;t know their current financial exposure to data security threats.</p>
<p>The next question is <strong>should you invest in DLP technologies</strong>? Any one with only a nickel in their pocket (and in this market &#8211; that&#8217;s a lot of companies&#8230;) will say &#8220;Why should we when we don&#8217;t know the return on investment?  In order to answer your questions, you must measure your value at risk using a data security based risk assessment This is a simple, almost obvious notion &#8211; you measure risk of asbestos poisoning by checking your building insulation and you measure risk of fire damage by checking the building itself and various policies, procedures and equipment related to fire prevention.</p>
<p><strong>Think about smoke detectors. </strong>You can&#8217;t put up an office building without smoke detectors (in Israel &#8211; the regulator has set a minimum density per square meter and the prices are low enough that the contractors will basically put in as many as you want). Why would you think of managing your data without the comparable data breach security monitoring equipment?</p>
<p><strong>Data security based risk assessment</strong> uses DLP technology (the test equipment) and a best practices analytical risk model to measure the value of your data and your value at risk. Within a couple weeks, you should be able to get a picture of your current data security events, know your data value at risk in Euro and build a prioritized program for cost-effective data security controls in the people, process and technology planes. What you do then – is up to you.</p>
<p>Most companies I know in Europe and Israel are not at a sufficient level of security maturity to do this kind of thing themselves &#8211; and will need an independent consultant &#8211; one with specific domain expertise in their industry vertical,  specific data security expertise and ability to do analytical threat modeling &#8211; installing Checkpoint firewalls doesn&#8217;t count and you really want someone who is vendor neutral.</p>
<div>Advantages of a data security-focussed risk assessment</div>
<div>
<ul>
<li>Invaluable tool for obtaining visibility of  inbound and outbound business transactions.</li>
<li>Monitoring that provides input into the risk analysis process required by compliance regulation like SOX, PCI DSS and European privacy laws.</li>
<li>Lays the basis for provable compliance to standards like PCI DSS 1.2 and ISO 27001/2/4.</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2010/01/building-a-business-case-for-dlp/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>UK gets serious in the war on corruption</title>
		<link>http://www.software.co.il/wordpress/2009/11/uk-gets-serious-in-the-war-on-corruption/</link>
		<comments>http://www.software.co.il/wordpress/2009/11/uk-gets-serious-in-the-war-on-corruption/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 08:31:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corruption]]></category>
		<category><![CDATA[Fraud]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2158</guid>
		<description><![CDATA[David Benyon from Op Risk and Compliance magazine reports A new bribery and corruption legislation will be put before the UK parliament. Doing business using bribery would mean jail for a decade under the bill. &#8220;The new Bribery Bill will make it far easier for companies and senior management to be prosecuted where bribes have [...]]]></description>
			<content:encoded><![CDATA[<p>David Benyon from <a title="UK Bribery bill" href="http://www.risk.net/oprisk-and-compliance/news/1562590/new-uk-bribery-strengthen-anti-corruption-laws" target="_blank">Op Risk and Compliance magazine</a> reports</p>
<p>A new bribery and corruption legislation will be put before the UK parliament. Doing business using bribery would mean jail for a decade under the bill.</p>
<blockquote><p>&#8220;The new Bribery Bill will make it far easier for companies and senior management to be prosecuted where bribes have been offered, paid or received. The new legislation will be even wider than the US <em>Foreign Corrupt Practices Act</em>, because it covers business-to-business transactions as well as business transactions with government or state-owned bodies,” says Neill Blundell, partner and head of the fraud group at law firm Eversheds&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2009/11/uk-gets-serious-in-the-war-on-corruption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
