<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>IT Compliance and Controls</title>
	<atom:link href="http://www.itcomplianceandcontrols.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.itcomplianceandcontrols.com</link>
	<description>Converging Business, Information, and Controls</description>
	<pubDate>Tue, 13 Jul 2010 17:03:29 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Clarity on Security and Privacy, HIPAA &amp; HITECH for Medical Providers</title>
		<link>http://www.itcomplianceandcontrols.com/2010/07/13/clarity-on-security-and-privacy-hipaa-hitech-for-medical-providers/</link>
		<comments>http://www.itcomplianceandcontrols.com/2010/07/13/clarity-on-security-and-privacy-hipaa-hitech-for-medical-providers/#comments</comments>
		<pubDate>Tue, 13 Jul 2010 17:03:29 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2010]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[data management]]></category>

		<category><![CDATA[federal register]]></category>

		<category><![CDATA[hipaa]]></category>

		<category><![CDATA[hitech]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=79</guid>
		<description><![CDATA[HITECH and HIPAA Security and Privacy safeguards have been evolving over the past 14 years.  Today a large amount of information has been provided outlining guidance for Medical providers.  Specifically 2 rules outling how to qualify for the federal  incentive program for electronic health records was released today (July 13, 2010) (though not in [...]]]></description>
			<content:encoded><![CDATA[<p>HITECH and HIPAA Security and Privacy safeguards have been evolving over the past 14 years.  Today a large amount of information has been provided outlining guidance for Medical providers.  Specifically 2 rules outling how to qualify for the federal  incentive program for electronic health records was released today (July 13, 2010) (though not in effect until 60 days after publication date 7/28/2010).   They equally touch upon security and privacy concerns.  In total the two documents roll up to 1,092 pages.  After I finish going through these I will post applicable details here and of course here.</p>
<p>Download each from the Federal Register <a href="http://www.ofr.gov/inspection.aspx" target="_blank"><strong>public  inspection desk</strong></a></p>
<p>Alternatively, download the documents (PDF) directly:</p>
<ol>
<li><a href="http://www.ofr.gov/OFRUpload/OFRData/2010-17207_PI.pdf">Medicare and Medicaid  Programs: Electronic Health Record Incentive Program</a></li>
<li><a href="http://www.ofr.gov/OFRUpload/OFRData/2010-17210_PI.pdf">Health Information Technology:  Initial Set of Standards, Implementation Specifications, and  Certification Criteria for Electronic Health Record Technology</a></li>
</ol>
<p>Comments and insights welcomed,</p>
<p>James DeLuccia</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2010/07/13/clarity-on-security-and-privacy-hipaa-hitech-for-medical-providers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What does coordinated Phishing attacks mean to your organization?</title>
		<link>http://www.itcomplianceandcontrols.com/2010/05/28/what-does-coordinated-phishing-attacks-mean-to-your-organization/</link>
		<comments>http://www.itcomplianceandcontrols.com/2010/05/28/what-does-coordinated-phishing-attacks-mean-to-your-organization/#comments</comments>
		<pubDate>Fri, 28 May 2010 17:41:51 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2010]]></category>

		<category><![CDATA[botnet]]></category>

		<category><![CDATA[cloud computing]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[cost of impact]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=76</guid>
		<description><![CDATA[A report released this month has identified one single group that is responsible for 2/3 of ALL global phishing attacks.  This is a tremendous task and requires a exceedingly large amount of sophistication.  A telling quote from the report (available here) gives a bit of background:
Central to Avalanche’s success is its use of fast-flux botnets [...]]]></description>
			<content:encoded><![CDATA[<p>A report released this month has identified one single group that is responsible for 2/3 of ALL global phishing attacks.  This is a tremendous task and requires a exceedingly large amount of sophistication.  A telling quote from the report (<a href="http://www.antiphishing.org/reports/APWG_GlobalPhishingSurvey_2H2009.pdf">available here</a>) gives a bit of background:</p>
<blockquote><p>Central to Avalanche’s success is its use of fast-flux botnets to host phishing sites. The use of peer-to-peer communications makes it impossible for a single ISP or hosting provider to to pull the plug on the infrastructure. The gang also excels at launching attacks from a relatively small number of domain names that often appear confusingly identical to each other, such as 11f1iili.com and 11t1jtiil.com. Those abilities also fuel the success.<br />
There were 126,697 phishing attacks during the second half of 2009, more than double the number in the first half of the year or from July through December of 2008, the APWG report said. Avalanche, which was first identified in December of 2008, was responsible for 24 percent of phishing attacks in the first half of 2009 and for 66 percent in the second half. From July through the end of the year, Avalanche targeted the more than 40 major financial institutions, online services, and job search providers.</p></blockquote>
<p>In addition, the domains / IP addresses hosting these malicious sites break down in the following manner (demonstrating how important global controls are important):</p>
<blockquote><p>Of the 28,775 phishing domains, we identified 6,372 that we believe were registered maliciously, by the phishers. Of those, 4,141 (66%) were registered by Avalanche. Virtually all of the other 22,403 domains were hacked or compromised on vulnerable Web hosting. Malicious registrations apparently took place in just 51 TLDs.</p></blockquote>
<p>The takeaways here are the following (please comment on other perspectives):</p>
<ol>
<li>By centralizing / controlling the Phishing attacks Avalanche is gaining rapid knowledge of target infrastructures; security defenses; and massive amounts of intellectual property that can be re-deployed in future attacks against other parties (or for sale).</li>
<li>Expansion of these attacks resulting from the accumulation of such knowledge combined with the 700 million + records of sensitive data on consumers creates the opportunity for a massive spear-phishing campaign</li>
<li>The leveraging of dynamic hosts and botnets is introducing a frontier whereby we can no longer have black lists / white lists as a simple solution.  In addition, the idea of perimeter defenses and trusted site-to-site open VPNs is drawn into question.</li>
</ol>
<p>The evolution of these attacks is expanding, as the evolution of worms demonstrated.  Malware artists generally go from proof of concept -&gt; proof of distribution -&gt; proof of non-detection -&gt; proof of percision.  It is the crossing from distribution to non-detection and then precision that has the highest rewards for attackers.  Safeguards for companies should consider social approaches.  People are the target here, and technology cannot block every attack.  Organizations could consider process and people as their main line of defense.  This in partnership with mature detection and response capabilities will limit the impact of any embedded threat.</p>
<p>Thoughts?</p>
<p>James DeLuccia</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2010/05/28/what-does-coordinated-phishing-attacks-mean-to-your-organization/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Federal Government centralizing Cloud certifications</title>
		<link>http://www.itcomplianceandcontrols.com/2010/04/19/federal-government-centralizing-cloud-certifications/</link>
		<comments>http://www.itcomplianceandcontrols.com/2010/04/19/federal-government-centralizing-cloud-certifications/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 19:33:05 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2010]]></category>

		<category><![CDATA[cio]]></category>

		<category><![CDATA[cloud computing]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=74</guid>
		<description><![CDATA[A great  amount of efficiencies exist in the Cloud solution model, but the  savings can be wasted through management waste, lax business support  services, and insufficient information  technology controls.  Vivek Kundra (United States Government Federal CIO) gave a presentation to the Brookings Institution on  how Clouds will be a central [...]]]></description>
			<content:encoded><![CDATA[<p>A great  amount of efficiencies exist in the Cloud solution model, but the  savings can be wasted through management waste, lax business support  services, and insufficient <span id="lw_1271445779_3" class="yshortcuts" style="border-bottom: 1px dashed #0066cc; cursor: pointer; background: none repeat scroll 0% 0% transparent;">information  technology controls</span>.  <span id="lw_1271445779_4" class="yshortcuts" style="border-bottom: 1px dashed #0066cc; cursor: pointer; background: none repeat scroll 0% 0% transparent;">Vivek Kundra</span> (United States Government Federal CIO) gave a presentation to the <span id="lw_1271445779_5" class="yshortcuts">Brookings Institution</span> on  how Clouds will be a central focus of all <span id="lw_1271445779_6" class="yshortcuts" style="cursor: pointer; background: none repeat scroll 0% 0% transparent;">government information systems</span>.  In addition  he presented a method of consolidating all certifications within NIST.   This would greatly remove the waste that would exist if every  institution was required to certify every vendor.  A couple of interesting points to consider:<br />
Today organizations already rely upon NIST as their accrediting provider  for many solutions, and it is foreseeable that this will extend to these  cloud certifications.  The certifications will likely encompass all of  the risks and required controls demanded by all government agencies, so  it is reasonable to conclude these will be adequate certifications for  the <span id="lw_1271445779_7" class="yshortcuts" style="border-bottom: 1px dashed #0066cc; cursor: pointer; background: none repeat scroll 0% 0% transparent;">private sector</span>.  Thus <a href="www.nist.gov/"> NIST</a> certifications will carry massive weight in the private sector, and  will equally reduce the costs of adoption by such businesses.<br />
A repeated theme within the Cloud discussion is the ability to focus on  the customer.  Similar to the thinking in how the iphone was not just a  phone and the <span id="lw_1271445779_8" class="yshortcuts">ipad</span> is not just a tablet - Clouds provide a canvas for businesses to serve  the customer.  This is achieved by the greatest benefit of Cloud  solutions - the ability to fail and correct rapidly.  Extreme <span id="lw_1271445779_9" class="yshortcuts">unit testing</span> is the  greatest opportunity and through prudent information technology  controls, such employment shall be with sufficient operational  integrity.</p>
<ul>
<li>Here is a link to the <a href="http://blogs.forrester.com/nigel_fenwick/10-04-12-fed_cio_looks_cloud_should_you">nice summation of the presentation</a> at <a href="http://blogs.forrester.com/">Forrester</a></li>
<li> Here is a <a href="http://gcn.com/articles/2010/04/07/prepared-remarks-by-federal-cio-vivek-kundra-at-brookings-on-cloud-computing.aspx">link to the remarks online</a></li>
<li> Here is a link to <a href="http://www.brookings.edu/%7E/media/Files/events/2010/0407_cloud_computing/0407_cloud_computing_kundra_presentation.pdf">the slides (pdf)</a>:</li>
</ul>
<p><a rel="nofollow" href="http://www.brookings.edu/%7E/media/Files/events/2010/0407_cloud_computing/0407_cloud_computing_kundra_presentation.pdf" target="_blank"></a>Thoughts?</p>
<p>James DeLuccia</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2010/04/19/federal-government-centralizing-cloud-certifications/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ISACA is seeking feedback on COBIT 5.0 Design Draft</title>
		<link>http://www.itcomplianceandcontrols.com/2010/03/23/isaca-is-seeking-feedback-on-cobit-50-design-draft/</link>
		<comments>http://www.itcomplianceandcontrols.com/2010/03/23/isaca-is-seeking-feedback-on-cobit-50-design-draft/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 21:34:12 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Change Control]]></category>

		<category><![CDATA[Direcitonal Alignment]]></category>

		<category><![CDATA[Life Cycle Management]]></category>

		<category><![CDATA[Monitoring and Performance Reviews]]></category>

		<category><![CDATA[Physical Access]]></category>

		<category><![CDATA[Risk Awareness]]></category>

		<category><![CDATA[SDLC]]></category>

		<category><![CDATA[Trusted Communications and Network]]></category>

		<category><![CDATA[Trusted Computing Platform Systems]]></category>

		<category><![CDATA[2010]]></category>

		<category><![CDATA[cobit 5]]></category>

		<category><![CDATA[cobit 5.0]]></category>

		<category><![CDATA[isaca]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=71</guid>
		<description><![CDATA[COBIT 5 exposure draft is out for review, so sharpen those pencils, order that Grande with an add shot, and find someplace quiet and dig into this design document (note this is NOT Cobit 5.0 but instead the plan at which will be employed to create it.  It is critical to review and provide feedback [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.isaca.org/Template.cfm?Section=home&amp;CONTENTID=56398&amp;TEMPLATE=/ContentManagement/ContentDisplay.cfm">COBIT 5 exposure draft</a> is out for review, so sharpen those pencils, order that Grande with an add shot, and find someplace quiet and dig into this design document (note this is NOT Cobit 5.0 but instead the plan at which will be employed to create it.  It is critical to review and provide feedback for this document, as it&#8217;s influence is extremely broad and far reaching.  The COBIT components are interwoven throughout the world&#8217;s Information Technology Control Frameworks, global regulations, and industry best practices.  Therefore ensuring this exposure draft is thoroughly vetted, commented, and improved must be a top priority for all professionals.</p>
<p>Given that - here is the <a href="http://www.isaca.org/AMTemplate.cfm?Section=Deliverables&amp;Template=/ContentManagement/ContentDisplay.cfm&amp;ContentID=56411">direct link to download the Design Exposure Draft for COBIT 5.0</a>, and <a href="http://www.surveymonkey.com/s/7VR8SHR">here is the questionnaire for you to fill out afterwards</a>.  It is a short 16 pages in length (compared to the hundreds the final iteration will possess), but it is exceptionally important that this document reflect the correct direction.</p>
<p>Best,</p>
<p>James DeLuccia</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2010/03/23/isaca-is-seeking-feedback-on-cobit-50-design-draft/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Deloitte: Business &#8216;Value&#8217; Metrics are Needed &#8230;</title>
		<link>http://www.itcomplianceandcontrols.com/2010/02/24/deloitte-business-value-metrics-are-needed/</link>
		<comments>http://www.itcomplianceandcontrols.com/2010/02/24/deloitte-business-value-metrics-are-needed/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 16:37:42 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[cio]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[cost of impact]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[Executive]]></category>

		<category><![CDATA[governance]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=68</guid>
		<description><![CDATA[A web cast by Deloitte accompanied with a poll has provided some interesting data points on the state of data governance within businesses.  On the heels of this web cast and poll results I have also added some insight from my field experience and general personal impressions.  Interesting facts include:

The definition of Data Governance is [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://www.deloitte.com/view/en_US/us/Insights/Browse-by-Content-Type/dbriefs-webcasts/technology-executives/event/d72b259f73315210VgnVCM200000bb42f00aRCRD.htm">web cast by Deloitte</a> accompanied with <a href="http://www.prnewswire.com/news-releases/business-value-metrics-are-needed-to-gauge-data-management-and-governance-success-deloitte-poll-84952002.html">a poll</a> has provided some interesting data points on the state of data governance within businesses.  On the heels of this web cast and poll results I have also added some insight from my field experience and general personal impressions.  Interesting facts include:</p>
<ul>
<li>The definition of Data Governance is often different for different people throughout the organization</li>
</ul>
<blockquote><p>Creating a great opportunity to establish relative context and personal ownership across the myriad divisions and geographies of the business</p></blockquote>
<ul>
<li>36.4% think the chief information officer (CIO) should be the sponsor and accountable for data governance in an organization</li>
</ul>
<blockquote><p>Full accountability I accept, but responsibility must be across those that have personal and business concerns directly related to Data Governance</p></blockquote>
<ul>
<li>15.5% consider data asset specification optimization as a top problem</li>
</ul>
<p>Reading these findings I cannot help but hear a certain management guru seeking to hear the contrarian position.  This is not to say that Data Governance is bad or good, but perhaps provide supplemental support to a very difficult challenge.<br />
A great challenge of Data Governance is shifting culture and human behavior to instill control around the data in question.  An interesting approach would be to seek to find what is already being done within the business operations that can provide a control and monitor with some form of natural feedback.  This would allow for data governance to occur naturally relative to every organization, while allowing for a broad adoption across the board with low cost impact.</p>
<p>Such controls can be found in the manner in which data is accessed from the databases and file servers.  Controls can be pulled from how the desktop / laptops are deployed and supported.  This approach looks at the entire business as a system, and can allow for controls to be recorded.  In essence, the objective is to (at least partially) establish data governance and spot level controls without labeling a new server / gadget / process as data governance.<br />
Again, this is not an argument against a mature and prudent data governance program across an enterprise, but simply an identification of possible supplemental avenues that can bring those greatly desired early wins.</p>
<p>Other contrary native controls?</p>
<p>Reflectively,</p>
<p>James DeLuccia</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2010/02/24/deloitte-business-value-metrics-are-needed/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Widespread Data Breach Evidence found on P2P Environments</title>
		<link>http://www.itcomplianceandcontrols.com/2010/02/22/widespread-data-breach-evidence-found-on-p2p-environments/</link>
		<comments>http://www.itcomplianceandcontrols.com/2010/02/22/widespread-data-breach-evidence-found-on-p2p-environments/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 18:25:44 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2010]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[corporate integrity]]></category>

		<category><![CDATA[data breach]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[FTC]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[p2p]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=65</guid>
		<description><![CDATA[The FTC sent out letters to nearly 100 organizations advising that customer and / or employee data that is protected by United States&#8217; laws were widely available online.  The release of such information is not new to most - given the early days of Napster when entire hard drives were shared and Quickbook files and [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.ftc.gov">FTC</a> sent out letters to nearly <a href="http://www.ftc.gov/opa/2010/02/p2palert.shtm">100 organizations advising</a> that customer and / or employee data that is protected by United States&#8217; laws were widely available online.  The release of such information is not new to most - given the early days of Napster when entire hard drives were shared and Quickbook files and more were available to every person with the curiosity to look for them.</p>
<p>The notice stated that personal health records; financial account information; data protected by PCI DSS, HIPAA, and HITECH; and other PII data records were available and discovered by the FTC to be exposed.</p>
<p>These notifications are a great step however, as they provide business with awareness and guidelines on reducing the threat and provide guidance on how to minimize the impact of these data breaches.  Unfortunately, as these file sharing systems go - the data is likely released permanently and the owners of this information will need to establish monitoring and preventive measures moving forward.</p>
<p>A few <a href="http://www.ftc.gov/bcp/edu/pubs/business/idtheft/bus46.shtm">things suggested by the FTC</a> on protecting sensitive information from being exposed to P2P networks include:</p>
<ul>
<li>Delete sensitive information you don’t need, and restrict where files with sensitive information can be saved.</li>
<li>Minimize or eliminate the use of P2P file sharing programs on computers used to store or access sensitive information.</li>
<li>Use appropriate file-naming conventions.</li>
<li>Monitor your network to detect unapproved P2P file sharing programs.</li>
<li>Block traffic associated with unapproved P2P file sharing programs at the network perimeter or network firewalls.</li>
<li>Train employees and others who access your network about the security risks inherent in using P2P file sharing programs.</li>
</ul>
<p>In addition, the use of personal computers and smart devices (PDA, Ipod Touch, Iphone, Android device, iPad, etc&#8230;) should be carefully reviewed and their use defined.  The velocity of data creates a need for DLP at multiple points.  As the utility of such devices increases, the need for managing this information and protecting it will also increase.</p>
<p>Thoughts on how to minimize the release to P2P networks?</p>
<p>- James DeLuccia</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2010/02/22/widespread-data-breach-evidence-found-on-p2p-environments/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Lessons from Financial Crisis for CIO and Executive Technology Leadership, pulled from Senior Supervisors Group</title>
		<link>http://www.itcomplianceandcontrols.com/2009/11/09/lessons-from-financial-crisis-for-cio-and-executive-technology-leadership-pulled-from-senior-supervisors-group/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/11/09/lessons-from-financial-crisis-for-cio-and-executive-technology-leadership-pulled-from-senior-supervisors-group/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 15:16:38 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2009]]></category>

		<category><![CDATA[cio]]></category>

		<category><![CDATA[ciso]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[corporate integrity]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[Executive]]></category>

		<category><![CDATA[Financial Crisis]]></category>

		<category><![CDATA[governance]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[Peter Drucker]]></category>

		<category><![CDATA[Senior Supervisors Group]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=63</guid>
		<description><![CDATA[According to a recent examination by global professionals relating to the failure of risk management controls with respect to financial exposures many of the failures can be attributed to very specific technology failures.  This does not excuse the vast amount of other shortfalls, and apply blame as you see fit arguments.  It does highlight that [...]]]></description>
			<content:encoded><![CDATA[<p>According to a <a href="http://www.newyorkfed.org/newsevents/news/banking/2008/rp080306.html">recent examination</a> by global professionals relating to the failure of risk management controls with respect to financial exposures many of the failures can be attributed to very specific technology failures.  This does not excuse the vast amount of other shortfalls, and apply blame as you see fit arguments.  It does highlight that these did certainly not help the situation any, and in fact exasperated it to some degree.  A few cogent points highlighted in the 36 page report are eerily applicable to all organizations, and should be a flare to all audit, security, risk managers, and compliance personnel.  <a href="http://www.newyorkfed.org/newsevents/news/banking/2008/SSG_Risk_Mgt_doc_final.pdf">PDF Report can be downloaded here</a>.</p>
<p><em>Points that should be carefully considered:</em></p>
<blockquote><p>&#8220;One challenge to improving risk management systems has been poor integration resulting from multiple mergers and acquisitions&#8221;</p></blockquote>
<p>This is especially dangerous considering that many businesses choose to operate separately initially to insulate interruptions to the business at large.  Information systems are generally incompatible at the beginning of any integration.  This is due to the lack of pre-planning and enterprise M&amp;A integration methodologies within the acquiring firms.  Organizations should take immediate action if they have acquired entities without consolidating these technology systems, or at the very least routing ALL traffic, logs, compliance controls, and processes through the acquiriing entity.  This creates both friction and a need for efficiency - two very powerful forces that will result in immediate transformation of these information technology environments, in the right direction.</p>
<blockquote><p>&#8220;&#8230;acquisitions over the years have produced an environment in which static data are largely disaggregated&#8221;</p></blockquote>
<p>This effects the ability to ensure daily consistent delivery of data and information technology services.  In addition, historic activity is just as important in managing current data environments.  Lacking such clarity and statistics requires executives to manage blindly without any context and sensible barometer of delivery and achievable commitments.</p>
<blockquote><p>&#8220;&#8230;certain products and lines of business have not been included in data aggregation and analysis processes&#8221;</p></blockquote>
<p>Technology historically has been disconnected from the business delivery objectives, and actual exclusion of specific products and businesses only ensures budgets will be misplaced; service will be inappropriate; and risks will not be addressed properly (if at all)</p>
<blockquote><p>&#8220;&#8230;two systems for the same business results in duplication of processes&#8221;</p></blockquote>
<p>This finding simply highlights waste - waste in resources; talent; time; bandwidth; budget, and brainpower.  In an age of interconnected capabilities such requirements for dual systems should becoming sparse and rare.</p>
<p>An interesting message echoes throughout the report was risk managements lack of complete visibility into the firms&#8217; risks.  A point that is both similar in nature and impact to CIO and Technology executives alike.  How well do we professionals truly understand what is happening and has happened within the business information systems?  Is all the data that is pertinent provided and managed?  <a href="http://harvardbusiness.org/search/drucker/">Peter Drucker</a> would certainly ask - Are you fully aware of the system (not the one computer or the e-transactions, but the technology system as a whole)?  Are you making choices based on all the right information, or based on the information you have (right or wrong)?</p>
<p>The crossovers from professional risk management and technology leadership are clear, striking, and very relevant.  It is prudent that today&#8217;s leadership is aware and armed with the skills across many trades - risk management in particular - to truly leverage the centuries of experience that exist within arms reach.</p>
<p>Additional perspective - please leave a comment,</p>
<p>James DeLuccia IV</p>
<p>Check out my other thoughts here on <a href="http://pcidss.wordpress.com">IT Controls and PCI DSS</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/11/09/lessons-from-financial-crisis-for-cio-and-executive-technology-leadership-pulled-from-senior-supervisors-group/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Hard valuations and real world returns for IT GRC</title>
		<link>http://www.itcomplianceandcontrols.com/2009/11/05/hard-valuations-and-real-world-returns-for-it-grc/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/11/05/hard-valuations-and-real-world-returns-for-it-grc/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 14:26:14 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2009]]></category>

		<category><![CDATA[Aberdeen Group]]></category>

		<category><![CDATA[Analyst report]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[cost of impact]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[governance]]></category>

		<category><![CDATA[GRC]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[IT GRC]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=60</guid>
		<description><![CDATA[In the past five years of delivering work that has been focused on aligning and enhancing corporations against contractual agreements, operational requirements, and risks - today officially classified as Governance, Risk and Compliance (or GRC) through technology I have seen real returns for my clients.  While these improvements happen immediately, the real rewards are realized [...]]]></description>
			<content:encoded><![CDATA[<p>In the past five years of delivering work that has been focused on aligning and enhancing corporations against contractual agreements, operational requirements, and risks - today officially classified as Governance, Risk and Compliance (or GRC) through technology I have seen real returns for my clients.  While these improvements happen immediately, the real rewards are realized through embedding the efforts over the long haul.  I have been quite pleased with the results of my own GRC activities, and based the book on highlighting these core success criteria.</p>
<p>A recent survey, albeit funded by a GRC vendor, conducted by the Aberdeen Group reinforces the returns corporations receive through adopting GRC into their organizations.  I find these results to be in-line with my own personal experience.  The link to the press release is <a href="http://www.businesswire.com/portal/site/home/permalink/?ndmViewId=news_view&amp;newsId=20091021006549&amp;newsLang=en">here</a>.  A quick bit of the numbers they highlight include:</p>
<blockquote><p>Some of the main results pointed out by the research shows that        Best-in-Class companies:</p>
<p><strong>1.</strong> estimated that business-critical decisions are made 10%        faster, based on improved management visibility into current risks.</p>
<p><strong>2.</strong> eliminated redundant risk management activities and processes,        with a reduction of 8.5%.</p>
<p><strong>3.</strong> improved efficiency of their compliance tracking and reporting        processes by 12% and their ability to provide clear, timely        communication of risks and compliance status to shareholders and board        of directors.</p>
<p><strong>4.</strong> increased their flexibility to adjust to new or updated        regulatory requirements by 11.5%.</p></blockquote>
<p>I strongly encourage organizations to develop a culturally correct IT Governance process and create an ongoing GRC initiative.  Only when technology, business risk, and innovation are moved together can organizations truly capitalize on the benefits of their existing assets.</p>
<p>A separate report, <a href="http://www.preventia.co.uk/resources/white%20papers/lumension/NIT-GRC-Aberdeen-Lumension.pdf">Managing Risk, Improving Visibility, and Reducing Operating Costs</a> was released in May 2009 which is also quite good and highlights the IT GRC benefits.  As with any industry report, be aware of the samples, scope, sources, funding for report, and how your organization differs and is similar in nature.</p>
<p>Other considerations?</p>
<p>James DeLuccia IV</p>
<p><em>(Please note, I was unable to locate the actual report beyond the broken link in the press releases.  I will check periodically and see if I can locate it when it becomes available.  If you find it, please post a comment and I will update here)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/11/05/hard-valuations-and-real-world-returns-for-it-grc/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Beware Outsourcing Savings from oDesk and others&#8230;</title>
		<link>http://www.itcomplianceandcontrols.com/2009/08/13/beware-outsourcing-savings-from-odesk-and-others/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/08/13/beware-outsourcing-savings-from-odesk-and-others/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 20:33:12 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[audit]]></category>

		<category><![CDATA[cio]]></category>

		<category><![CDATA[ciso]]></category>

		<category><![CDATA[cloud computing]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[corporate integrity]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[Executive]]></category>

		<category><![CDATA[governance]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=57</guid>
		<description><![CDATA[An incredible trend is happening in the &#8220;for contract&#8221; market  - specifically the for hire programmers.  oDesk and eLance both show dramatic upticks in the amount of work being posted and delivered on the site (nice article here on the growth).  oDesk alone is tracking about 100,000 hours a week of work, or nearly $65 [...]]]></description>
			<content:encoded><![CDATA[<p>An incredible trend is happening in the &#8220;for contract&#8221; market  - specifically the <em>for hire</em> programmers.  <a href="http://www.odesk.com/community/oconomy">oDesk</a> and <a href="http://www.elance.com/skills_central">eLance</a> both show dramatic upticks in the amount of work being posted and delivered on the site (<a href="http://www.techcrunch.com/2009/08/13/in-a-tight-economy-outsourced-developers-on-odesk-work-100000-hours-a-week/">nice article here on the growth</a>).  oDesk alone is tracking about 100,000 hours a week of work, or nearly $65 million dollars worth.  This massive increase in outsourced projects to independents and for hire groups is an indicator of the need for businesses to find affordable development, but at what cost?<br />
The trend is perfect for highlighting how businesses can shift to deliver services required - in any economy.  The trend also equally shows that the practices and methods equally shift.  The challenge is making this shift securely and with the correct safeguards.  (This is highlighted nicely from a macro risk perspective by Mike Nolan here in <a href="http://kpmg.com/Global/IssuesAndInsights/ArticlesAndPublications/Pages/The-need-for-alignment.aspx">The Need for Alignment</a>.)  Leveraging contractors has always required specific validation techniques:</p>
<ul>
<li>Right to Audit clauses to ensure operations meet marketing materials</li>
<li>Background check summaries on contractors</li>
<li>AV and Malware running on contractor systems (<a href="http://www.cio.com/article/498629/P_P_Ban_Plan_for_Government_Gets_Mixed_Response">or in the U.S. government, no p2p</a>)</li>
<li>Vendor management procurement procedures</li>
</ul>
<p>Awareness is necessary for when these jobs begin to be sourced through open market places.  The fidelity of the business providing the services, protection of intellectual property, and the proper review of software against best practices is only the beginning of the new and expanded risks that must be considered.<br />
Businesses and leaders should certainly embrace these open markets that allow greater access and better price transparency, but it must be done in a manner that reflects the risk capability of the business to ensure a balanced operating environment.</p>
<p>Additional thoughts and ideas on best practices for vetting outsourcing vendors?</p>
<p>James DeLuccia IV</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/08/13/beware-outsourcing-savings-from-odesk-and-others/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Third Party Fraud - Breaking down Trust</title>
		<link>http://www.itcomplianceandcontrols.com/2009/08/04/third-party-fraud-breaking-down-trust/</link>
		<comments>http://www.itcomplianceandcontrols.com/2009/08/04/third-party-fraud-breaking-down-trust/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 21:29:35 +0000</pubDate>
		<dc:creator>James</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[2009]]></category>

		<category><![CDATA[acfe]]></category>

		<category><![CDATA[audit]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[corporate integrity]]></category>

		<category><![CDATA[data security]]></category>

		<category><![CDATA[forensic]]></category>

		<category><![CDATA[Fraud]]></category>

		<category><![CDATA[IT Compliance and Controls]]></category>

		<category><![CDATA[kpmg]]></category>

		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=54</guid>
		<description><![CDATA[As the economies around the world remain challenged by the economic environment, the propensity for fraud is significantly higher.  One may speculate that fraud is consistent but only our sensitivity shifts between good and bad times.  Whichever school of thought you support is a matter of risk perspective, and quite irrelevant today.
Fraud is up on [...]]]></description>
			<content:encoded><![CDATA[<p>As the economies around the world remain challenged by the economic environment, the propensity for fraud is significantly higher.  One may speculate that fraud is consistent but only our sensitivity shifts between good and bad times.  Whichever school of thought you support is a matter of risk perspective, and quite irrelevant today.</p>
<p>Fraud is up on a worldwide basis.  The attacks and scams are increasing, and it is occurring across all sectors.  An excellent breakdown the &#8220;<a href="http://kpmg.co.uk/news/detail.cfm?pr=3334">KPMG Forensic Fraud Barometer</a>&#8221; states that <a href="http://www.cimaglobal.com/cps/rde/xchg/live/root.xsl/1630_11502.htm?itemid=19274631&amp;categoryname=Legislation">fraud</a> for the <a href="http://kpmg.co.uk/news/detail.cfm?pr=3541">UK and areas that over 1.1 billion Pounds of fraud have come to court in 2008.</a></p>
<p>The Association of Certified Fraud Examiners (ACFE) has a great amount of detailed <a href="http://www.acfe.com/about/statistics.asp">statistics here</a>, a <a href="http://www.acfe.com/documents/press-kit/acfe-small-business-fraud.pdf">nice simple guide for small businesses seeking to minimize/prevent fraud</a>, and a nice bit of information on the <a href="http://www.fraudconference.com/20th-recap.asp">past ACFE fraud conference</a> (highly recommended)</p>
<p>We are definitely seeing these frauds perpetrated in common channels - such as in Las Vegas at Conferences (below are several links to articles referring to two ATMs found during the DefCon 17 Conference - very interesting read):</p>
<ul>
<li><a href="http://hackaday.com/2009/08/04/malicious-atm-found-at-defcon-17/">Hack a Day Article</a></li>
<li><a href="http://www.engadget.com/2009/08/03/atm-scam-at-defcon-clearly-the-work-of-ironic-criminals/">Engadget Article</a></li>
<li><a href="http://it.slashdot.org/story/09/08/02/2151247/Scammer-Plants-a-Fake-ATM-At-Defcon-17?from=rss">Slashdot Article</a></li>
<li><a href="http://www.computerworld.com/s/article/9136179/Fake_ATM_doesn_t_last_long_at_hacker_meet">Computerworld Article</a></li>
<li><a href="http://www.wired.com/threatlevel/2009/08/malicious-atm-catches-hackers/">Wired Article</a></li>
</ul>
<p>In addition organized crime groups are also leveraging the technologies of today (Facebook, twitter, SMS) - and the attack vectors (i.e., phishing).</p>
<p><strong>Protection; Prevention; Detection:</strong></p>
<ol>
<li>Being aware of trends is vital to erecting current and appropriate (even if temporary) safeguards - such as required by the FTC Red Flag</li>
<li>Communicate with peers and collaborate - that may be accomplished by being a part of message boards; Twitter Groups, and attending Conferences.</li>
<li>Evaluate your fraud programs and determine the current success rate, and implement corrections.</li>
</ol>
<p>These are simply single high level areas to consider - review your fraud programs seriously and consider the resources available by the above referenced parties.</p>
<p>As mentioned by <a href="http://www.yhff.co.uk/Fraud%20Barometer%20-%20Feb%202009%20_2_.pdf">Vivien Osborne of KPMG UK in the KPMG Forensic Fraud Report</a>:</p>
<blockquote><p>&#8220;In these harsh economic times, internal fraud could become the tipping point between the survival and demise of an organisation.  Companies need to be rigorous about re-enforcing their anti-fraud measures.  By reviewing their high risk and key operations, having effective reporting channels and deploying detection mechanisms such as data analytics they may give themselves a better chance to fight fraud.&#8221;</p></blockquote>
<p>Additional Fraud Resources, please add below in comments.</p>
<p>Best,</p>
<p>James DeLuccia IV</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2009/08/04/third-party-fraud-breaking-down-trust/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
