Tuesday, January 29, 2013

Banks Transitional move towards Unique Customer Identification Code( UCIC)

The increasing complexity and volume of financial transactions leads to customers having multiple identities within a bank, across the banking system and across the financial system.

Reserve Bank of India has enforced strict guidelines (Know Your Customer (KYC)/Anti-Money Laundering (AML)/Combating of Financing of Terrorism (CFT) Guidelines) to maintain and consolidate single login credential  for transaction operations.

The objective is to provide simple mechanism to track customer information across various channels. Using Unique Customer Identification Code( UCIC), customer can view and track all accounts/relationships with the bank. This will facilitate bank to perform audits and also enhance user ease. 

In this regard, a Working Group constituted by the Government of India has proposed the introduction of unique identifiers for customers across different banks and Financial Institutions for setting up a centralized KYC Registry. While setting up such a system for the entire financial system is likely to take quite some time, banks can make an immediate beginning in this regard by having such identification code for their own customers. HDFC bank has started the transitional move towards having consolidated identify across their customer.

Mapping and maintaining Unique Customer Identification Code will drive solutions like Identity & Access management. Similar, solution will facilitate bank to easily transform the business alignment with regards to upcoming guidelines from RBI.

Friday, May 25, 2012

Security Technology Marathon (Rise/Fall)

As we see more and more businesses are becoming internet-enabled with basic security mechanism in place. The year 2011 was one of the landmark years for high-profile cyber attacks. As the trend is said to continue in 2012 with more sophisticated and targeted attacks, security is a major concern for the IT users of all the segments from Home Users to SMB to Enterprise. Business needs to realign security strategies keeping upcoming security incident in near future. 

The number of data thefts has tripled in the past five years and the graph tends to rise with every passing year. Right from the Government, corporate, data centers and small to medium-sized companies all have been targeted. With the introduction of IT consumerization, issues such as managing and supporting consumer devices and securing data from criminals, malware, and other threats have emerged. Mobility in enterprise sector brings new challenges for managing data, as well as the wide range of devices in the network.

Let’s analyze the technology which may be refined to address the future needs and solutions which may be replaced. The analysis is carried based on various discussions with customer addressing the security challenges and Forrester's predictions.

Technology Rise

1. Risk-based predictive Access mechanism

Profiling of user authentication based on previous accesses and actions will be enforced on the security solution. The solution will perform Predictive threat modeling before providing accesses to data. The solution should be integrated with data encryption technology for all internet-enabled communication. The rise of such solution may be seen in next 3-5 years.

2. Mobile Security

Today organizations are facing major concerns around prevent security incident happening from mobile devices. Mobile devices are the backbone of any industry and hence employees may not be restricted from their use.
Mobile devices theft is alone should be reason enough for businesses to take a more rigorous approach to securing mobile devices, including tracking them when they go missing, and ensuring that remote-wipe capabilities are in place should it be too difficult or expensive to recover the devices. With the "bring your own device to work"--a.k.a. BYOD, or the consumerization of IT-- a trend in full force, expect to see more organizations attempt to add better security to their employees' mobile devices, including smartphones.
The other issues which should be tracked are stealing information from Smartphone using advanced malware and virus attempts. It is often hard to detect the presence and hence neglected for years.

3. Advanced auditing tools

To address the increase in a number of data breaches and current regulatory requirement, there may be a huge demand for sophisticated auditing and correlation tools. The solution will "have the potential to become ubiquitous in enterprise security organizations."Solution like SIEM may be redefined to address SMB

4. Malware analysis

An integrated solution may be required to analyze incidents with the vulnerability present in the system. The solution should identify hidden super malware, monitor basic operations and fight with Ransomware(an infection that holds a device “hostage” until a “ransom” payment is delivered). The rise of such solution may be seen in next 3-5 years. The technology should be flexible for Enterprises, SMB, and home users since attackers are trying to bypass the basic fundamentals of user operations.
The solutions should address the below concerns
  • SSL is safe(Myth), SSL Not So Safe- When you see the padlock icon in your browser's toolbar, you might think that your data is safe, but hackers have found ways to get at your information before you send it securely on the internet. These new forms of malware can identify when you've visited sites protected with SSL--the encryption technology used to keep data safe from prying eyes as it travels across the Internet--and it can grab your username and password before the encryption kicks in. In addition, these sorts of attacks, according to security software vendors, will ignore all Web traffic except encrypted sites to filter out information that it isn't interested in.
  • Super malware-Some malware can access your browser history, and will only infect you if it sees that you've visited certain sites. For instance, a piece of malware designed to steal online banking login information might check to see if you visited a particular bank's website. Expect more malware that goes after certain groups of people or specific bits of information.
  • New Malware Harder to Spot and Remove: You may be infected with malware and not even realize it. While older malware used to make itself known on your PC, newer forms of malware may not even have an interface, and they may not seriously impact your PC's performance. Instead, it all runs in the background, seemingly invisible to you. This hard-to-spot malware can also be hard to remove. For example, a relatively new rootkit called ZeroAccess buries itself deep into your system, and it's extremely difficult to disable since it effectively kills any program that tries to access it (hence the name ZeroAccess).
  • Malware Holds Your PC for Ransom: Ransomware is nothing new--it's been around for a few years in various forms, including fake antivirus software that won't go away unless you pay up. The company pointed to one example where a piece of malware would lock you out of your computer entirely unless you pay up.

5. Network encryption

Although network encryption exists in infrastructure devices such as routers and switches, demand for stand-alone appliances is just starting. In one to three years this could reach the next phase, though, without compliance pressures, this technology will be adopted by only the most stringent and largest of enterprises.

6. Predictive threat modeling

This relatively new concept calls for analyzing how to properly protect important data by proactively modeling threats. In three to five years it could hit the next phase, although the "costs and complexity of current threat modeling tools work as a barrier to adoption of this new technology."

7. DDoS (distributed denial of service) mitigation controls

Due to the increase in hacktivism, "the market for DDoS protection is poised for growth" within one to three years.

8. Storage security and DLP Integration

Storage security requirement may rise due to cloud-based technology adoption. Also, DLP enabled solutions may be redefined to address complex business requirements.

Security technologies may not survive next few years.

1. Network access control

Forrester believes the market for stand-alone NAC offerings will likely be phased out over the next five to 10 years. (Though Forrester suggests there's a bit more hope for "packaging NAC" in security software suites or infrastructure security.) Why is it bad news for NAC? Forrester says only 10% of technology decision-makers will implement it over the next 12 months because "solutions are complex to deploy, scale and manage." There are several NAC architectures, plus hardware and software approaches, and "all the approaches require integration with network infrastructure components." "NAC won't stop a malicious insider who wants to commit a security breach for financial or other reasons.

2. Secure file transfer (as an on-premise appliance)

The need to securely transfer and share files between business partners is high but in three to five years it's going to be done more and more with cloud-based services rather than appliances, according to Forrester.

3. Unified threat management

Though widely deployed in small and branch offices for DSL wide-area network implementations, UTMs face dislocation from new security gateways with more integrated firewall and intrusion features that make UTM look "antiquated.UTM technology may last one to three years to meet competitive challenges and be more "enterprise-ready," though it also acknowledges UTM is likely to be "moderately successful over the long run" in retail stores.

4. Network intrusion prevention (stand-alone)

The market for stand-alone intrusion-prevention systems (IPS), despite its success being deployed by the world's largest companies, is in decline and "will likely phase out in the next 5 to 10 years" as multi-function gateways and firewalls, especially NGFW, include IPS and are used instead of stand-alone IPS equipment.




Thursday, October 27, 2011

Technology Intersection = SMART SECURITY SERVICES

Every Object(Product or Services) has a defined lifecycle and trend associated. It’s often seen, object reaches its maturity which we call as a Peak point before dying or conversing to other technology stack. This is to develop more productive object to cater today’s demand.

Let’s take an example of TV…Traditionally; TV was the only source of entertainment for watching movies and other entertainment program. Later, Internet was picked up to perform business; day to day tasks along with other entertainment enabled services…In the beow diagram “PP” represent Peak point of maturity. Now, People started losing interest and deviating from TV as a product.

Now what???? Do we foresee lesser TV demand?

Please click on the below image for better resolution and display.....



Technology interaction between TV and Internet, which we call as “SMART TV “has developed a new curve out of its dying phase …

SMART TV= TV + Day-to-Day internet enabled Task.
The similar cycle will continue after SMART TV ….Please carefully review both the curves

The above concept will also be applicable to Technology services…If you closely assess the 2nd curve, which produce “SMART IT SERVICES” due to intersection of Internet with Technology services. This intersection has produced cloud enabled services. 

SMART IT SERVICES:  Less expensive (in comparison with traditional form)+ Easy Rollout + Easy Transition+ Pay As You Use+  Highly Available + Best bread Technology Stack + Many More ..

The initial intersection phase is called as acceptance phase, where it’s   been evaluated and truly accepted before it is taken and developed for maturity.

SMART SECURITY SERVICES –Let’s align SMART IT SERVICES for Security enabled offering.
  • Identity as a Service
  • Authentication as a Service
  • VAPT as a service
  • Managed Security as a Service
  • Other security as a service 

Monday, October 24, 2011

Global Password Management Best Practices

In continuation with recent post “5-Which of Password Management”, I thought to drill down on best practices of Global password management. We are calling “Global”, since it is not confined to any entity and even user doesn’t have control on to the application practices. Each application has different password policies and hence password expiration would be different….
Many Username, Many password !!!!!!

Please click on the below image for better resolution and display.....


Using this approach User will only need to remember 4 passwords for Username & Password File.
Please note these are my view and many of you may differ with this approach; however the objective is to provide simplicity using existing tool, Easy Remote management and high security

Thursday, October 6, 2011

Safeguard Enterprise Data during Employee Separation

There have been cases of data loss, where employees were part of such acts during the transition to the new job. A report by “Bnet” shows that 45 percent of employees take data when they change jobs. Such is the case with a former HP employee, who had allegedly sent copies of IBM confidential documents to his Vice President at HP. Prior to joining HP, he was employed by IBM and had access to this information.

Before we drill down, let's analyze the reasons which can be multiple- 

  • Identity & Access Management (IAM) solution not correctly in place or may not be designed effectively-It is often observed that enterprise doesn't develop correct boundaries for IAM. The most important question every CISO or CIO concern about is optimization and efficiency around processes with minimal security incident (to make close to zero). This often leads to comparison with peers on-

          -How we are doing as an organization?

          -What is the next step for building our secure Environment using 

           IAM infrastructure?
          -How to develop IAM maturity model

  • Data Loss Prevention system is missing or may not be developed correctly.
  • A vendor has not captured all the scenarios (happy & unhappy) while developing the system.
  • The vendor is not equipped with SME and domain expertise to understand Technology trends.
  • Periodic system and process review mechanism not in place.
Let's define the best practice approach to avoid such scenarios in Enterprise-

  • Identity & Access Management(IAM) solution-Developing a Strong Enterprise processes-Separation Process should be in place to handle employee resignation scenario and removing access rights to critical systems during Employee Notice period.HR system should be designed to provide user resignation information to the IDM system for de-provisioning of critical systems. However, the above process can be modified/realigned keeping the Business objective in mind.
  • Enforcing Periodic System and process review 
  • Enterprise needs to align with vendors who understand the Subject and can translate business processes keeping domain and business objective in mind.
  • Missing Data Loss Prevention system-A Proper implementation of DLP would have marked this data as sensitive and rated it highly critical. Common exit points of this type of data breach are corporate email, webmail, FTP, removable drives, and printing. At any of these exit points, DLP would have flagged this activity. Let's explore the effectiveness of DLP in the enterprise-There has been misleading information of DLP being able to identify 370 plus file formats. File type identification does not translate into content inspection. It is roughly about 180 file types that this technology can interpret and inspect the contents. In order for DLP to do its job effectively, content inspection is important. Customers tend to get sold on the sheer number of 370, when in fact DLP is equipped to tear down the file on less than half of them.

Wednesday, August 10, 2011

Fingerprint breakthrough offers new forensic evidence

A technology to extract fingerprints from a crime scene could show if a criminal suspect has taken drugs or been in contact with explosives.

Fingerprint breakthrough offers new forensic evidence

Tuesday, July 12, 2011

War between computers & Humans- To wipe out traumatic memories

The computer is designed to reciprocate Human behavior. It is so specialized in computing advance task which human machine may or may not able to compute in a fraction. I understand, there are many differences which make human apart from computers like senses, emotions etc. But the one thing which makes apart is removing unwanted data from memory…The computer is the clever device, which can erase data as per the instruction.   

Just imagine, you are Soldiers haunted by scenes of war and victims scarred by violence or terrified by some instance or any past emotional break thru and may wish they could wipe the memories from their minds. Researchers at the Johns Hopkins University say that may someday be possible.

Is it possible to erase traumatic memories?
A commercial drug remains far off — and its use would be subject to many ethical and practical questions. But scientists have laid a foundation with their discovery that proteins can be removed from the brain's fear center to erase memories forever.

"When a traumatic event occurs, it creates a fearful memory that can last a lifetime and have a debilitating effect on a person's life," says Richard L. Huganir, professor and chair of neuroscience in the Hopkins School of Medicine. He said his finding on the molecular process "raises the possibility of manipulating those mechanisms with drugs to enhance behavioral therapy for such conditions as post-traumatic stress disorder."

In future, If we get this method we may cure several diseases (mental disorder).   

Thursday, July 7, 2011

Enterprise security posture needs to align with Identity and Access Management (IAM) Trends

The most important question every CISO or CIO concerns about optimization and efficiency around process with minimal security incident (to make a close to zero). This often leads to comparison with peers on how we are doing as an organization?”, “What is the next step for us as we build our secure environment using IAM infrastructure?” and “how to develop IAM maturity model?”
The survey revealed following drift-    

  1. Security is still the top driver behind the use of identity and access management tools
  2. IT administration efficiency is now the second most common motivator, with 30% of respondents from a recent Forrester survey weighting this efficiency above regulatory compliance.
  3. Business agility is also a new factor, as business owners increasingly look to security professionals to solve business problems.

With the increasing sophistication of fraud rings and security attacks, coupled with the rapid adoption of various mobile and post-PC devices and the changing business environment, it will be important to consider various questions when selecting your organization's next IAM product.For example,

1. Does the product recognize risk and patterns, making fraudulent activity easily identifiable? Or, more simply, does the product work from a mobile device? While mobile browser support is a minimum requirement, mechanisms for secure PKI certificate management and centralized access auditing should also be expected. Does the product support geographic patterns and provide detection and prevention defense mechanism.
2.  Most importantly, does the product help improve business agility and demonstrate value? By proving to budget holders that substantial savings are achievable, it will be much easier to sell the product internally.
3.   Future product Strategies
4.  User Friendliness and Integration support for 3rd party COTS-based solution and homegrown application.
5.    Integration with Service oriented environment.

To understand the facts lets analyze the Identity and access management predictions from Forrester-Despite increased spending, security and risk professionals continue to face tough vendor selection decisions.

  • Prediction 1: Business agility will continue to rise in importance
  • Prediction 2: Data security will come to depend on IAM
  • Prediction 3: Mobile devices will need to be managed via IAM systems
  • Prediction 4: IAM in the cloud will provide more than just access control

Tuesday, July 5, 2011

Prized Patient information open to Web-Highest Number of Security Breaches in Healthcare - Medical Providers


The below chart represent the highest number of security breaches happing in Healthcare sector of US. The immediate question arise to everyone mind; is it because of low-security standard or control available? This is not True!!!  There are strong controls like HIPPA to address security requirement, but it also depends on how and where these controls are implemented. A strategic initiative needs to be developed, involving management commitment with right tools and strong business processes.   


Type of breaches analyzed:
  1. Unintended disclosure (DISC) - Sensitive information posted publicly on a website, mishandled or sent to the wrong party via email, fax or mail.
  2. Hacking or malware (HACK) - Electronic entry by an outside party, malware, and spyware.
  3. Payment Card Fraud (CARD) - Fraud involving debit and credit cards that are not accomplished via hacking. For example, skimming devices at point-of-service terminals.
  4. Insider ( INSD) - Someone with legitimate access intentionally breaches information - such as an employee or contractor.
  5. Physical loss (PHYS) - Lost, discarded or stolen non-electronic records, such as paper documents
  6. Portable device (PORT) - Lost, discarded or stolen laptop, PDA, smartphone, portable memory device, CD, hard drive, data tape, etc
  7. Stationary device (STAT) - Lost, discarded or stolen stationary electronic device such as a computer or server not designed for mobility.
  8. Unknown or other (UNKN)

Organization type(s) analyzed: BSO - Businesses – Other, BSF - Businesses - Financial and Insurance Services, BSR - Businesses - Retail/Merchant, EDU - Educational Institutions, GOV - Government and Military, MED - Healthcare - Medical Providers, NGO - Nonprofit Organizations

Few examples of breaches are -

Barnes-Jewish Hospital, The Siteman Cancer Center, Washington University Saint Louis, Montana
A laptop containing unencrypted patient information was stolen during the weekend of December 4, 2010.  It contained the names, Social Security numbers, dates of birth, addresses, phone numbers, email addresses, medical records, diagnoses, lab results, insurance information and employment information

Boulder Community Hospital Boulder, Colorado
A contract nurse is accused of accessing patient information without authorization.  He faces a 90-count felony indictment.  He allegedly used the Social Security numbers and other private information found in patient files to open credit cards in patients' names. 

The VA Caribbean Healthcare System San Juan, Puerto Rico
Veterans and staff had their personal information left unsecured in an open area in the San Juan VA Medical Center. Some of the information included patient care assignment documents with names and Social Security numbers a counseling letters.  It is not clear what type of staff information was exposed.  The information was supposed to have been shredded.

Healthcare Partners Long Beach, California
Nineteen computers were stolen during an office burglary on Monday, April 18.  Administrative information such as names, addresses, dates of birth, medical record numbers, and health insurance plan ID numbers was exposed.  Sensitive medical information such as treating physician names, diagnoses, treatment plans, progress notes, prescriptions, referrals, and authorizations were also exposed. A safe with 16 patient checks and 60 patient credit card receipts was also stolen.

Indiana Regional Medical Center Indiana, Pennsylvania
A former employee stole more than 500 patient records for the purpose of using them as evidence in a legal dispute with a physician.  The theft occurred in September of 2010 and included the medical information of three or four patients, as well as administrative information related to hundreds of other patients.

Trinity Medical Center (Montclair Baptist Medical Center) Birmingham, Alabama
A former employee was caught stealing patient information for the purpose of identity theft.  Hundreds of pages of information with patient names, Social Security numbers, dates of birth and some medical information such as scheduled procedure were found at the employee's residential address