October 29, 2010
M&A Whitepaper Now Available
In order to access the whitepaper, it is necessary to enter a limited amount of information. GraVoc assures your information will remain confidential and will not be disseminated to any third parties.
Also available on the information security page is more detailed information in PDF files detailing the scope of services provided by the GraVoc team. An additional whitepaper addressing operational risk assessment is also available from this page.
GraVoc Associates, Inc, a full-service consulting firm based in Peabody, MA, is dedicated to providing solutions for businesses through the use of technology. To assist clients in an M&A process, GraVoc would leverage the knowledge of its staff spanning several of its practices. GraVoc provides consulting services in the practices of information systems, IT & professional services, information security, and media production. For more general information about the company and the services offered, please visit GraVoc.com.
October 20, 2010
"New Set of Eyes"
Many regulatory examiners encourage financial institutions to perform due diligence on their risk management and audit vendors, essentially encouraging another set of eyes. Obviously, with three ISACA-certified professionals on staff, we would like to be that set of eyes. Furthermore, we find it to be troubling that many audit firms find no problem performing risk management work and then auditing their own work. GraVoc can be there on either side of the equation, providing true impartiality.
GraVoc is aware that many financial institutions are currently feeling pressure to complete certain projects by the end of the year. With ten weeks left before the new year, we strongly encourage firms trying to accomplish such a task to contact us sooner than later so that we can initiate, perform, and complete risk management and information security projects in a timely fashion.
Among the services offered by GraVoc's information security team include testing of your network perimeter, evaluation of controls within your network, risk assessment services, and business continuity plan development and training. The Peabody, MA-based consulting firm, featuring individuals with the CISA, CRISC, and CISM designations from the Information Systems Audit and Controls Association, also has practices dedicated to information systems, professional & IT services, and media production. For more information about GraVoc, we strongly encourage you to contact the offices at 978-538-9055 or visit gravoc.com.
September 29, 2010
GraVoc featured in MassBanker's e-News
June 9, 2010
GraVoc Heads to Las Vegas
GraVoc’s DivergingSoul Media Production practice jumped on a plane to Las Vegas earlier this week for the InfoComm 2010 conference at the Las Vegas Convention Center. Representatives Brian Gravel and Matt Molk are attending the conference to learn about current ideas and stay on the cutting edge of AV communications. Notably, the conference is showcasing advances in digital signage, so it presents an opportunity to share ideas regarding the DS2 digital signage network. The conference lasts through the end of the week, and a recap will likely be posted to this blog shortly upon their return.
GraVoc also made itself available at a more-local tradeshow, attending a conference staged by the Massachusetts Bankers’ Association. The Annual Bank Technology/Retail Banking Conference addressed, among other things, mobile banking and whether it is an inevitable new step that brings with its benefits a slew of risks. GraVoc saw many familiar faces, and got to meet several new people in the industry. GraVoc and other attendees participated in several constructive conversations regarding risk management in the face of the marketplace trending toward mobile banking.
GraVoc Associates, Inc, based in Peabody, MA, has been serving customers in Greater Boston, the North Shore, New England, and beyond. A technology consulting firm, GraVoc specializes in the practices of media production, information security, information systems, and professional services. For more information about the services and products offered by GraVoc, please visit www.gravoc.com or peruse the archives of the GraVoc News Blog.
April 16, 2010
GraVoc to Attend Great New England Credit Union Show
This will be GraVoc's first appearance at the show, and they can be found in booth 70, in between Enterprise Car Sales and FMS (Financial Management Solutions). An estimated 700 attendees from credit unions across the New England region are planning to be at the event, which features thirteen seminars of interest to credit union executives. Additionally, eighty vendors are expected to exhibit.
GraVoc's information security team will be on hand to explain more about their wide range of information security services that can be found both on the gravoc.com website and in past posts of the GraVoc News Blog. The GraVoc booth will feature typical tradeshow fare, such as a video display, candy, and handouts. We hope to see many familiar faces there, as well as new faces.
GraVoc Associates, Inc, founded in 1994, provides a dynamic range of information security services to financial institutions throughout Greater Boston and New England. The Peabody, MA-based company specializes in business continuity planning, LAN/WAN testing, and risk assessments. Lately, among its more popular services have been social engineering testing and services to help clients comply with the Massachusetts Data Security Law. Beyond information security, GraVoc also specializes in the fields of professional services, media production, and information systems. For more information about the services GraVoc provides, please visit http://www.gravoc.com/.
April 1, 2010
GraVoc Holds Compliance Consortium
GraVoc’s information security team would like to extend its gratitude toward North Easton Savings Bank for hosting the first quarterly information security & risk management consortium. The event was held Tuesday morning March 30 at NESB’s new corporate offices in South Easton, and was attended by several GraVoc information security clients and friends.
Led by GraVoc’s Nate Gravel and Dan Vassallo, the meeting was the first of hopefully several where financial service executives both within IT and outside IT can share ideas, concerns, and observations regarding the current compliance landscape for regional financial institutions. Among the many topics discussed this quarter were the changes in Regulation E that require customers and members to opt in for courtesy overdraft payment, challenges brought on by the popularity of social media outlets, and current patterns in regulatory exams.
The GraVoc information security team is grateful that some of its clients braved adverse weather conditions to attend the event, and hopes that all attendees considered the event a conduit for discussion that was worth the drive. If you are interested in attending the next event, most likely to be held in June, please contact either Nate or Dan by calling the GraVoc offices at 978-538-9055.
GraVoc Associates, Inc., based in Peabody, MA, has served clients in greater Boston, New England, and beyond in the practices of information security, information systems, and professional services. Some of the more pertinent services offered in the information security practice include business continuity/disaster recovery planning, Massachusetts General Law 93H/201 CMR 17.00 compliance services, and social engineering simulations. For more information about the services provided by GraVoc, please visit http://www.gravoc.com.
February 19, 2010
93H: There Is A Reason For This
As the deadline for compliance with the Massachusetts Data Security Law approaches (March 1st is now two weeks away), many businesses are undoubtedly looking at the new burdens that are being thrown at them and wondering if it’s necessary. Perhaps the Massachusetts legislature got bored one day and decided to inconvenience businesses by requiring them to write information security policies and implement safeguards. Maybe they have friends in the encryption or consulting industries. But a recent report has given further evidence to what many already knew: Identity theft is a growing problem and businesses that handle people’s sensitive information should make efforts to make sure that if this data is stolen, they are not the ones responsible for it.
A research group concluded there were over 11 million US identity fraud victims in 2010, a 12-percent increase perhaps caused by bad economic times (hat tip to the ISMG). Surprisingly, over two-thirds of this crime was executed using non-technical methods, emphasizing that identity theft prevention is not specifically an IT burden. This growing crime cost victims $54 billion in 2010. By comparison, ID theft victims lost three times what all of Bernie Madoff’s victims lost during Madoff’s entire career.
GraVoc Associates, Inc’s information security team, which has worked primarily with the highly-regulated financial services industry in the past, has begun to work with non-financial clients with Massachusetts Data Security Law (M.G.L. 93H or 201 CMR 17.00) compliance services. A free on-demand webinar has been recorded and distributed to existing GraVoc clients, and will be made available on GraVoc.com later on this week. The standards required by this law, while they are not nearly as aggressive as they were when originally penned, can require a lot of work, and many businesses have gone to GraVoc for advisory and help with compliance with this law.
GraVoc Associates, founded in 1994, provides a wide range of solutions in the fields of information security, information systems, and professional services. The GraVoc News Blog has been following developments regarding the Mass. Data Security Law since the blog’s inception in 2008, and you may find value in perusing the archives for more information. For additional information about GraVoc’s services in all three fields, we strongly encourage you to browse GraVoc.com.
January 7, 2010
Buddy List Blues
In a recent whitepaper issued by MessageLabs, a division of Symantec, security risks surrounding instant messaging within a company are addressed in vivid detail. The document, entitled “Bullet-proofing Instant Messaging,” claims that 80% of “corporate or enterprise users” utilized an instant messaging service. While the practice of instant messaging opens up the possibility of many efficient opportunities in business processes, such as instant file transfer and rapid communication that allows multi-tasking more than the telephone does, users of instant messaging either on a business level or a personal level know that many risks come associated with it as well.
Some of the risks involved include the following:
- Quick spread of worms and malware from clicking links and automatically downloading files.
- Transfer of corrupted/untrusted files.
- Insecure access controls – IM services typically do not require industry-standard authentication procedures in terms of password strength or multifactor authentication.
- Liabilities with file sharing and copyright infringement: If a user’s “buddy” sends, for example, an illegally-downloaded music file to the user, both the user and the company could be liable for copyright infringement.
- Perhaps most importantly, cleartext transfer of potentially confidential data. Unlike internal email, this information typically does travel outside the organization’s firewall.
The document also outlines a variety of solutions to mitigate the risk that comes with instant messaging as a business solution. Predictably (as it is their product), MessageLabs promotes software-as-a-service solutions as a way to secure instant messaging platforms. They also mention options such as internally-developed secure IM platforms so that employees can IM each other from within the network. Perhaps the most practical solution, however, is employee diligence: If employees are careful about their behavior and the behavior of others surrounding their use of instant messaging, or of an organization strongly discourages instant messaging, opting to use email as a comparable mode of communication, many of the risks surrounding this practice can be reduced.
GraVoc Associates, Inc., located in Peabody, MA, is dedicated to providing solutions to its customers in Greater Boston, New England, and beyond through the use of technology. Specializing in the practices of information systems, professional services, and information security, GraVoc occasionally uses the GraVoc News Blog as a way to call customers’ and visitors’ attention to relevant, engaging topics such as this one. For more information on the company, please visit the GraVoc website at http://www.gravoc.com.
September 11, 2009
Social Engineering: Are There Rules?
A very interesting alert came from the National Credit Union Administration last month regarding a fraudulent letter and accompanying CD. The letter and CD were sent to an unnamed credit union, indicating they were from the NCUA when in actuality they were not. An employee of the credit union told the NCUA about it, prompting the alert.
It was very quickly learned that the letter and CD were sent by a consulting firm contracted by the credit union in question to conduct penetration testing and social engineering testing. The consulting firm, MicroSolved, owned up to it and praised the client credit union for doing exactly what they should be doing: Reporting suspicious activity to the appropriate authority. In his blog, MicroSolved CEO Brent Huston expressed his admiration for the whistleblower, the NCUA, and the multiple media and Internet outlets who made this incident into an inadvertent “awareness campaign” regarding the dangers of social engineering.
MicroSolved got a considerable amount of heat for impersonating the NCUA and for using the NCUA’s logos, names, and likenesses. Whether this is ethical or not, it is probably more effective if not necessary to use those likenesses. Are real-life attackers going to be following the rules of “we don’t use logos to impersonate agencies?” Of course not. And the most effective tests are the ones that most closely resemble the real-life scenarios. Unless real fraudsters have the ethics to not use the agency’s likenesses, the people complaining about this firm’s ethics using them should really be complaining about something else. The priority should be keeping businesses’ information safe, not the proper use of names and logos.
Social engineering is a tactic employed by malicious attackers that instead of targeting weaknesses in computer systems, targets human beings as a way to gain unauthorized access to confidential information. Social engineering preys upon trust, curiosity, and authority in a variety of different ways, including bogus emails, phone calls, letters, CDs, or other means.
GraVoc Associates, Inc. is celebrating fifteen years of business serving Greater Boston, New England, and beyond in the fields of information security, information systems, and professional services. With three CISMs on staff, GraVoc brings a high skill level to its information security consulting practice. As a service to its clients, GraVoc posts items of note such as the one above to increase awareness of constant changes in the information security landscape. For more information about GraVoc’s offerings in information security consulting, please visit www.gravoc.com or speak to a representative at 978-538-9055.
August 31, 2009
Mass. Law: No Longer Strongest In Country?
Last week, the Massachusetts Office of Consumer Affairs and Business Regulation decided to issue a revised version of 201 CMR 17.00, the regulation that outlines and enforces compliance to M.G.L. 93H. Not only did the OCABR delay the effective date for a third time, but saying the changes in the language have “softened” the aggressive nature of the law would be an understatement.
While this is good news for the smaller enterprises, such as a business that only stores personal information of its six employees or small businesses that don’t have thousands upon thousands of dollars to spend on some of the physical and technical safeguards prescribed by the old version of the regulation, information security experts (such as the ones who wrote scathing indictments of the changes here and here) argue that this regulation has been softened to the point that is rendered worthless. One of the authors wrote that retail firm TJX would have been compliant with this regulation when they experienced the data breach that inspired it.
Highlights from the changes:
- Perhaps the most significant change is the removal of the personal information inventory piece. This may have been the most cumbersome and unrealistic part of the regulations, but also may have been the most important. It is difficult to protect information if you don’t know where it is. Other states already do require the personal information inventory in their data protection laws.
- Words like “reasonable” and “technically feasible” permeate the new version of the document, while they were used very sparingly in the old version. Information safeguards, including encryption password strength, and the installation of virus definitions, security patches, and firewall protection, previously had specific standards to be in compliance with the law. The new standards use the “reasonable” and “technically feasible” terminology. As it may ease small businesses’ financial burden, these words are certainly vague and open to interpretation.
- The Frequently Asked Questions that accompany the document on the Massachusetts OCABR website further illuminate the problems with the use of these terms. The FAQs state that email messages with personal information do not need to be encrypted if the process is not “technically feasible,” for example. A noncompliant business can readily answer to authorities simply by saying “I did not find this safeguard to be technically feasible.”
- The language of the regulation removes accountability for those who “store or maintain” personal information. This would suggest that if a company keeps its records at a hosted storage facility or with a service bureau, the vendor is no longer responsible for this information. Other provisions regarding vendor management are similarly weakened or taken out completely—a contract including compliance is required but enforcement of a vendor’s compliance is no longer documented.
- Compliance as an ongoing process is also put into question with the changes. There is no longer language regarding assessing risk associated with information, processes, or applications and putting in appropriate safeguards. Language requiring monitoring the effectiveness is also removed.
- Similarly, thorough investigation of any network intrusions were previously mandated by the regulation. They are no longer explicitly required unless unless they result in a data breach. A business no longer has to report or document any unauthorized physical access to computer systems. Restricting access to systems, such as server rooms, is also completely eradicated from the document.
- Language regarding employee access to personal information is substantially less stringent. Language regarding limiting access to those with a “need to know” is eradicated and the word “immediately” has been removed from the part requiring companies to revoke physical and electronic access to records when an employee leaves the organization.
There are six months left before the revised compliance deadline. With the revised provisions in the regulations, compliance is much more achievable. However, compliance with these weakened regulations might not be enough to keep information safe anymore.
GraVoc Associates, Inc, located in Peabody, MA, is celebrating fifteen years in the practices of information security, information systems, and technology and professional consulting. For more information on GraVoc’s compliance services aligned with the Massachusetts Data Protection Law, please contact GraVoc at 978-538-9055 or visit the GraVoc website at http://www.gravoc.com. More information on this law has been covered in the GraVoc News Blog, so by clicking “Massachusetts Data Protection Law” below is also a useful source of information.
August 25, 2009
Data Breach Lessons Learned: Part 2
Continued from Friday’s post, here is more information regarding how the indictment of hacker Albert Gonzalez in connection with the biggest credit card number heist in history is significant to your business and protecting its information assets:
- As difficult as it is to announce a data breach, companies not only have the responsibility to their customers to alert authorities of a data breach, but they will also be helping the efforts of law enforcement to catch criminals like Gonzalez by announcing in a prompt manner. Companies already implicated in highly-publicized breaches have lost immeasurable, irreparable damage to their reputations. However, as this story develops, there has been news that Heartland may have known more about the scope of the breach than what they reported. This may be a serious problem for the company.
- While Gonzalez is the malicious intruder in this case, the corporate victims also take a piece of the blame, whether rightfully so or not. Securing a network is like locking your doors when you leave your house—except it takes a lot more time, effort, and money.
- With so much attention being paid lately to social engineering techniques such as phishing and the threat posed by malicious “insiders” in rough economic times, this massive data breach was executed using somewhat-traditional network hacking. Hackers have not abandoned this tactic.
- As cumbersome as laws like the GLBA, HIPAA, PCI, and the Massachusetts Data Protection Law are, they may very well be necessary to keep individuals safe from identity fraud.
GraVoc Associates, Inc, located in Peabody, MA, serves customers in Greater Boston, New England, and beyond in the practices of information systems, information security, and professional and technological services. The GraVoc News Blog is updated frequently to provide free information and tips to help your company’s bottom line. For more information regarding GraVoc’s services and how they can help your company’s efficiency and security, please visit http://www.gravoc.com.
August 21, 2009
Mass. Data Protection Law Delayed, Softened
Earlier this week, the Massachusetts Office of Consumer Affairs and Business Regulations (OCABR) made the decision to delay the effective date of the Massachusetts Data Protection Law (also known as MGL 93H or 201 CMR 17.00) for the fourth time. Businesses are expected to be in compliance with this law, which is designed to protect Massachusetts residents from identity theft, by March 1, 2010.
The original effective date of this law was January 1, 2009. It was delayed until May 1, 2009 late last year, and in February it was moved back to January 1, 2010.
The provisions and standards of data protection have also been amended. While the law is still perhaps the most aggressive in the country, compliance is much more attainable with the revised provisions. The amended law can be read in PDF format here.
This announcement can be interpreted many ways. A pessimist may look at it in a way that the effective date may never come and that Massachusetts is writing this law for a public relations purpose. Optimists may view the four separate delays and significant amendments to the regulation as a gesture by the state saying that they are listening and they understand the needs and limitations of small businesses. It could possibly be indicative that the state and the OCABR are serious about enforcing compliance, so they are making changes so that compliance is actually a possibility for businesses.
This news will be covered in more depth on the GraVoc News Blog towards the end of next week.
GraVoc Associates, Inc., based in Peabody, MA, is celebrating fifteen years in Greater Boston. GraVoc works with a variety of different clients in several sectors, providing services in the practices of information security, technology and professional services, and information systems. GraVoc’s information security team has several years’ experience serving the highly-regulated financial services industry, and is committed to helping clients from any industry comply with the Massachusetts Data Protection Law. For more information about GraVoc and its M.G.L. 93H compliance services, please visit GraVoc.com.
Lessons Learned in Data Breach Indictment
The indictment of Albert Gonzalez and two other co-conspirators in connection with data breaches resulting in 130 million credit card numbers stolen is massive news. This is the largest breach of credit card numbers ever recorded, and the fact that someone was caught speaks volumes about the efforts of law enforcement officials. However, this indictment doesn’t change the fact that the numbers were still compromised and the corporate victims—the businesses that had data stolen off of their networks—have suffered irreparable damage both in terms of regulatory compliance and corporate reputation. There are many lessons to be learned about this incident. The GraVoc News Blog will outline this information in a two-part series.
- Albert Gonzalez is already currently in prison for his involvement of a previous high-profile data breach involving TJX, Dave & Buster’s, BJ’s, and other companies. In his career as a hacker, he very well may have stolen 200 million credit card numbers! Each of these operations, while certainly sophisticated, were reasonably small. This news shows how readily available credit card numbers can be if a network is violated.
- This attack was well-planned and well-researched. The scope of this group’s “research and development” included driving with a computer to evaluate the security (or lack thereof) of potential victims’ networks using a variety of tools, many of which may also be used by companies like GraVoc to help companies identify vulnerabilities in a network’s perimeter. Potential victims were also qualified by researching the means of payment processing.
- The attack was carried out with a SQL injection and installation of malware, exploiting network vulnerabilities that were previously identified and documented. These attacks typically exploit “poorly-coded” applications, and when these vulnerabilities are initially found, they are documented and resolved in an updated version of the application. In other words, many of these vulnerabilities are the result of a company’s lack of diligence regarding updating software versions.
- Experts agree that despite the diligent preparation for this attack, an SQL injection is not a difficult exploit to execute. While Albert Gonzalez may be behind bars, he is hardly the only hacker in the world who can exploit the same vulnerabilities in this manner.
GraVoc Associates, Inc. of Peabody, MA, is dedicated to ensuring its clients in Greater Boston, New England, and beyond are aware of the ever-changing environment of information security. The GraVoc News Blog will continue documenting four other “lessons learned” early next week. For more information regarding GraVoc’s services in information security, information systems, and technological and professional services, please visit http://www.gravoc.com.
July 13, 2009
Mass. Data Protection Deadline: Less than Six Months Away
The Massachusetts Data Protection Law, sometimes referred to as Massachusetts General Law 93H & I or 201 CMR 17.00, goes into effect on January 1, 2010, and the general consensus is that the effective date is NOT going to be delayed for a third time. This law requires all companies with “personal information” pertaining to a Massachusetts resident to have a comprehensive written information security policy. It also requires companies with any personal information to undergo reasonably-daunting efforts to protect both paper and electronic files to prevent a data breach.
“Personal information” is defined as a person’s name or first initial and last name in conjunction with a social security number, a government issued ID number, a driver’s license number, or a financial account number (including credit and debit card number). This covers both customer information and employee information, so virtually every business in the state will have to comply with this law.
The many provisions required by this aggressive law include procedural controls, physical controls, and technological controls. Among the more challenging measures to be mandated under this law are the following:
- A comprehensive, written information security policy regarding the protection of information both in physical and electronic forms.
- A vendor management program that ensures that all vendors, service providers, and contractors with access to personal information are also taking adequate measures to curb identity theft and data breaches and to become compliant with this law.
- Higher levels of physical information protection, such as the use of locked containers and the employment of locked facilities.
- Challenging standards for electronic data protection, including the encryption of hard drives and portable devices like laptops, PDAs, and flash drives that contain personal information.
As this law sets very high standards and expectations and threatens to levy strict fines against noncompliant businesses, small and midsized businesses may not know where to turn. GraVoc’s information security team has been monitoring the law’s provisions and its evolution over the past year. GraVoc is committed to helping clients comply with this law and proactively quell the risk of data breaches and identity theft.
GraVoc Associates, Inc, a full-service consulting firm based in Peabody, MA, is celebrating 15 years of business in Greater Boston and throughout New England. GraVoc offers a wide range of services in the fields of information security, information systems, and technology and financial services, including Massachusetts Data Protection Law compliance services. For more information on GraVoc’s information security work in the highly-regulated financial industry or more information about 93H compliance services, please visit GraVoc.com.
June 15, 2009
Highlights from Presidential Cybersecurity Plan
Much has been made of President Obama’s “ten-point” information security plan, some good, some bad. It gained front-page news last month as information compromises seem to be spiraling out of control. This initiative has largely been praised by those in the information security community, as the government is placing a high priority at keeping electronic information safe. A few observations from Obama’s plans:
- Perhaps the most celebrated point of this plan is to appoint one person in charge of the national cybersecurity program. This way, there is one so-called “cyber-czar” with chief accountability to ensure that actions are being executed.
- The ten-point plan describes cybersecurity as, in the words of GovInfoSecurity.com, a “key management priority” that will utilize performance metrics. It will be especially interesting to see how the success of this undertaking will be measured.
- The plan prioritizes public awareness and education toward information security over the internet. Currently, many cybercriminals are realizing the easiest way to compromise data is not through the weakness in the technological infrastructure, but the weakness and ignorance by the people using the information systems through social engineering tactics.
An educated and aware populace will ideally be one of the keys to securing data online. For example, this week Australia promoted “Change Your Password Day” with a self-explanatory call to action. It is also notable to add that in a recent study, a high percentage of systems users had very simple passwords for them to remember—and for others to guess. Sixteen percent of users, according to a Cyber-Ark study had the user’s first name as their password.
- The plan also emphasized the United States to reach out internationally for these initiatives, which is important. Several major cyber-fraud plots have been perpetrated overseas, and some Russian and Ukrainian hackers are hailed as heroes for usurping money from wealthy Westerners. This incentive to steal can be counteracted by harsher penalties by their own country. Though they certainly will not completely eliminate the problem, strong global measures against cyber-fraud will help create a disincentive to carry out intricate hacking and social engineering activities.
GraVoc Associates, Inc, celebrating fifteen years of business in Peabody, MA, is committed to serving clients in three areas: Information systems, technology and professional services, and information security. GraVoc occasionally uses the GraVoc News Blog to alert information security clients on certain items of interest. To learn more about GraVoc’s products and services, please visit GraVoc.com.
May 7, 2009
The “Year of the Insider Threat?”
What typically comes to mind when a person thinks of information security breaches is a sophisticated hacker maliciously using his or her technological manipulation skills to gain access to an organization’s information systems. For the banking industry, this is similar to someone putting a mask on and robbing the bank.
However, perhaps partially due to the weakened economy and widespread concerns about job security, the threat of insiders—i.e. employees, vendors, or consultants—is a threat that is growing at an alarming rate. This is similar to an employee pocketing money from a vault or from a cash register.
Statistics indicate that in 2008, the number of insider threats being realized skyrocketed. Endpoint Security reports that out of all data breaches in 2008, insiders were responsible for 15.7% of them. This is more than double the 2007 figure. Logic would indicate that employees or consultants, fearing layoffs or due to other conditions of economic uncertainty, have more of a motive to compromise their own company’s systems and data. BankInfoSecurity wonders if 2009 is the “Year of the Insider Threat” while offering advice on how to prevent insider threats from being realized. In a whitepaper by Kevin Prince of Perimeter eSecurity, malicious insiders are identified as a “rising threat” and the biggest “network security threat of 2009.”
The threats are there and are largely unavoidable. Every organization will have trusted insiders who have access to information and therefore have the capabilities to compromise that information. However, there are many ways to control the risks associated with malicious insiders.
Limiting access to information to those with a clear need-to-know is a generally-accepted best practice, and making sure insiders are following this “need-to-know” as well as information security policies is also a simple but crucial mitigating control. It may be worth considering software that inhibits a user’s ability to use data storage devices such as PDAs, flash drives, or CD-ROMs. But constant attention and diligence towards information systems, including upgrading technologies in a timely manner and monitoring access logs for suspicious activity is necessary.
Preventing insider threats must be an enterprise-wide effort. Background checks should be considered before hiring a person with access to sensitive information, and procedures regarding issuing and removing access should be written and followed. Policies should be drafted about responding to an insider threat. With information more portable than ever, enterprise-wide decisions should consider the feasibility of a data breach caused by a malicious insider, and trying to minimize the likelihood and impact of such an event happening should be a consideration in these decisions.
GraVoc Associates, Inc., based outside of Boston in Peabody, MA, is celebrating fifteen years of providing consulting services in the practices of information security, information systems, and professional and technical services. GraVoc is committed to informing clients about the latest information security threats, and their information security team is willing to help your business achieve your compliance with regulations and keep your information safe. For more information about the company, please visit www.gravoc.com or call the GraVoc offices at 978-538-9055.
March 4, 2009
New MGL 93-H Deadline: January 1, 2010
The Massachusetts Office of Consumer Affairs and Business Regulation (OCABR) has again pushed back the date at which the new Massachusetts General Law 93-H goes into effect. The new date is January 1, 2010.
MGL 93-H is better known as the "Massachusetts Data Protection Law."
A press release from the OCABR is available here.
Massachusetts General Laws 93-H and 93-I are generally considered the toughest laws in the nation regarding identity theft prevention. This law requires businesses containing either paper or electronic files with personal identifiable information to have a comprehensive information security policy. The specification of the information security policy are available in PDF format here.
Governor Deval Patrick announced the impending enforcement of this law last fall and GraVoc Associates, Inc. was one of the first firms to address the law’s tough standards. Starting in November, GraVoc began offering services to help small businesses safeguard its customers’ and employees’ personal information and comply with MGL 93-H. Since, the OCABR has given businesses more time to undertake 93-H compliance efforts, pushing back the January 1, 2009 deadline to May 1, 2009, and now to January 1, 2010.
GraVoc Associates, Inc, a full-service consulting firm based in Peabody, MA, is celebrating 15 years of business in Greater Boston and throughout New England. A versatile business, GraVoc offers a wide range of services in the fields of information systems, information technology, financial services, and information security. For more information on GraVoc, please visit GraVoc.com or call GraVoc’s offices at 978-538-9055.
February 18, 2009
Personal Identifiable Information Defined
Personal identifiable information, as defined in MGL 93-H is a resident's first name and last name or first initial and last name along with:
- The person's social security number.
- The person's driver's license or state-issued identification card number.
- The person's financial account number, with or without any access codes or passwords that provide access to the person's financial account.
In other fields, including forensics, personal identifiable information is defined with a broader scope; this definition is strictly for the purposes of MGL 93-H governance.
The quick link available above describes the range of services GraVoc can provide to help your business comply with MGL 93-H. However, the most popular service as of this point is the personal identifiable information (PII) inventory, where GraVoc professionals conduct interviews with your business's personnel, determining where PII is collected and how it is stored both electronically and physically.
Based in Peabody, Massachusetts, GraVoc Associates, Inc. is celebrating its fifteenth anniversary helping small businesses and financial institutions find solutions in the fields of information security information technology, and beyond. To learn more about GraVoc's services regarding MGL 93-H compliance, please consult the new http://www.gravoc.com/ or call GraVoc's office at 978-538-9055.
January 29, 2009
GraVoc to Host Gary Miliefsky Speech
Gary Miliefsky, founder and CEO of NetClarity and founding member of the U.S. Department of Homeland Security will be speaking at this event, which is free of charge upon RSVP and includes a buffet lunch. He will be addressing the "nine best network security practices of 2009." This speech will surely cover a wide variety of topics that are relevant to the banking industry and beyond, including identity theft and the new stringent laws, such as Massachusetts General Law (MGL) 93H, which have significant implications to businesses throughout the country.
This event, which will take place at the Bay Colony Corporate Center in Waltham, MA, is designed so that attendees from the Greater Boston area will learn about the new information security trends and challenges that will face small businesses and especially financial institutions. GraVoc and NetClarity plan to host similar events, including one in southwestern New England, in the coming weeks.
If you are interested in attending this event or would like more information, please view the Lunch & Learn invitation on the new GraVoc.com.
GraVoc Associates, Inc. is a full-service consulting firm celebrating its fifteenth anniversary in 2009. A Microsoft Gold Certified Partner based in Peabody, MA, GraVoc has been dedicated to providing software solutions, information security, technological services, and professional services to clients in a wide range of industries. Late in 2008, GraVoc partnered with Bedford, MA-based NetClarity, Inc., the developer of the innovative NACWall product that has earned the respect and admiration of many information security professionals and publications.
To learn more about GraVoc visit http://www.gravoc.com/.
To learn more about NetClarity visit http://www.netclarity.net/.
January 8, 2009
GraVoc Partners with NetClarity
Peabody, MA-based GraVoc Associates, Inc. has teamed up with Bedford, MA-based NetClarity as part of their continuing dedication to proving the best information security solutions to their clients. NetClarity’s NACWall takes network access control to a new level.
The innovative NACWall product provides an unprecedented layer of security to your network that firewalls, anti-virus software, and the like do not protect against. In one piece of hardware, the NACWall has the abilities to secure your network in a way that has never previously been possible with one machine, thereby reducing your cost of compliance auditing.
The NACWall:
- Continuously scans your networks for CVEs (“Vulnerabilities” or “Holes”) and reports each hole for prompt rectification.
- Monitors your network for unauthorized devices, such as laptops, wireless devices, or PDAs, and blocks unauthorized devices if desired.
- Runs reports that can prove your compliance to regulations, such as GLBA, Sarbanes-Oxley, and the new Massachusetts General Law (MGL) 93H.
- Is an agent-free, non-invasive solution.
NetClarity prides themselves on their innovative NACWall product and its ability to protect, speed up, and lengthen the life of your company’s tremendous IT investment. Their solutions have been heralded as some of the best in the business, as they have accomplished the following accolades:
- CRN Test Center Product of the Year.
- “One of the top three most innovative network security companies in the world” according to the RSA Conference Innovation Showdown.
- SC Magazine’s perfect 5-star rating and “Best Buy” certification.
- 2009 SC Magazine Award Finalist.
GraVoc Associates’ trusted information technology and information security professionals are in the process of being trained to implement and support this versatile piece of hardware. GraVoc, an IT and information security consulting firm celebrating its 15th anniversary this year, is proud to team up with NetClarity. GraVoc feels that the NACWall product perfectly aligns itself with the company’s commitment to providing clients with long-lasting solutions that boost the security of their IT infrastructure.
Information security customers in the Greater Boston area and throughout New England and the Northeast can now use the NACWall and GraVoc’s services in tandem to cement their confidence in their network, improve their regulatory compliance, and increase their profitability.