<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RisknCompliance Consulting Group</title>
	<atom:link href="http://rnc2.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://rnc2.com</link>
	<description>Pragmatic Information Risk Management through Thought Leadership</description>
	<lastBuildDate>Wed, 30 Nov 2011 04:27:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Compliance obligations need not stand in the way of better information security and risk management</title>
		<link>http://rnc2.com/regulatory-compliance/pcidss/compliance-obligations-neednt-stand-in-the-way-of-better-information-security-and-risk-management/</link>
		<comments>http://rnc2.com/regulatory-compliance/pcidss/compliance-obligations-neednt-stand-in-the-way-of-better-information-security-and-risk-management/#comments</comments>
		<pubDate>Sun, 31 Jul 2011 17:38:00 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[Information Risk]]></category>
		<category><![CDATA[PCI DSS Compliance]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Assessment]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://rnc2.com/regulatory-compliance/pcidss/compliance-obligations-neednt-stand-in-the-way-of-better-information-security-and-risk-management/</guid>
		<description><![CDATA[I couldn’t help write this post when I noticed this press release based on an IDC Insights Survey of Oil &#38; Gas Companies. I don’t have access to the full report so I am basing my comments solely on the contents of the press release. I found the following two findings (copied from the press [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">I couldn’t help write this post when I noticed <strong><a href="http://www.idc-ei.com/getdoc.jsp?containerId=prIT22956611" target="_blank"><span style="color: #000080;">this press release</span></a></strong> based on an IDC Insights Survey of Oil &amp; Gas Companies. I don’t have access to the full report so I am basing my comments solely on the contents of the press release.</span></p>
<p><span style="color: #000080;">I found the following two findings (copied from the press release) to be of interest :</span></p>
<blockquote>
<ul>
<li><span style="color: #000080;"><strong>Security investments are not compliance driven. </strong>Only 10% of the respondents indicated that they are using regulatory compliance as a requirement to justify budgets.</span></li>
</ul>
<ul>
<li><span style="color: #000080;"><strong>Tough regulatory compliance and threat sophistication are the biggest barriers. </strong>Almost 25% of respondents indicated<strong> </strong>regulatory environment as a barrier to ensuring security. In<strong> </strong>addition, 20% of respondents acknowledged the increasing<strong> </strong>threat landscape.</span></li>
</ul>
</blockquote>
<p><span style="color: #000080;">The good news here is that only 10% of the respondents used Regulatory Compliance needs to justify budgets. What that tells me (I hope it is the case) is that the remaining 90% make budgetary decisions based solely on the information security risks that their  businesses face and not on the risks of not complying with regulations or audits. I would commend them for it&#8230; and I don’t think any good auditor (regulatory or internal/external) would have a problem with it either if the organization was able to “demonstrate” that the risk of not complying with a particular regulatory requirement was very low. Agreed.. you still need to be able to “demonstrate” which isn’t easy if one hasn’t been diligent with risk assessments.</span></p>
<p><span style="color: #000080;">The not-so-good news to me is the 25% number (I realize it might be low enough for some people)..  that of folks indicating that regulatory compliance is a barrier to ensuring security. For those folks, I say “It really doesn’t need to be a barrier”, not if you have good   information risk management governance and processes. I don’t know a single regulation that would force you to implement specific controls no matter what. Even if you are faced with an <strong><a href="http://rnc2.com/regulatory-compliance/pcidss/may-we-suggest-some-priority-adjustments-to-your-pci-dss-compliance-program/" target="_blank"><span style="color: #000080;">all-or-nothing regulation</span></a></strong> like PCI DSS, you can resort to using compensating controls (see <strong><a href="https://www.brandenwilliams.com/brwpubs/TheArtoftheCompensatingControl.pdf" target="_blank">here</a></strong> and <strong><a href="http://pciguru.wordpress.com/2010/09/02/writing-a-compensating-control/" target="_blank">here</a></strong> for some coverage of PCI DSS Compensating controls) to comply with a specific mandatory requirement.  To repeat my argument in the previous paragraph, an auditor would be hard-pressed to fault you if you were able to clearly articulate that you went about the compliance program  methodically by performing a risk assessment and prioritizing (by risk level) the need for specific controls required by the regulation. If you did that, you would focus on ”ensuring security” and not ignoring it for the sake of compliance.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/regulatory-compliance/pcidss/compliance-obligations-neednt-stand-in-the-way-of-better-information-security-and-risk-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do we have a wake-up call in the OIG HHS Report on HIPAA Security Rule Compliance &amp; Enforcement?</title>
		<link>http://rnc2.com/regulatory-compliance/hipaahhitech/do-we-have-a-wake-up-call-in-the-oig-hhs-report-on-hipaa-security-rule-compliance-enforcement/</link>
		<comments>http://rnc2.com/regulatory-compliance/hipaahhitech/do-we-have-a-wake-up-call-in-the-oig-hhs-report-on-hipaa-security-rule-compliance-enforcement/#comments</comments>
		<pubDate>Tue, 24 May 2011 03:02:00 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[Access Governance]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[HIPAA/HITECH Compliance]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=420</guid>
		<description><![CDATA[If you didn’t notice already, the Office of Inspector General  (OIG) in the Department of Health and Human Services (HHS) published a  report on the oversight by the Center for Medicare and Medicaid Services (CMS) in the enforcement of the HIPAA Security Rule. The report is available to the public here.   As we know, CMS [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">If you didn’t notice already, the Office of Inspector General  (OIG) in the Department of Health and Human Services (HHS) published a  report on the oversight by the Center for Medicare and Medicaid Services (CMS) in the enforcement of the HIPAA Security Rule. The report is available to the public </span><strong><a href="http://oig.hhs.gov/oas/reports/region4/40805069.pdf" target="_blank"><span style="color: #000080;">here</span></a></strong>.   <span style="color: #000080;">As we know, CMS was responsible for enforcement of the HIPAA Security Rule until the HHS  Secretary transferred that responsibility over to the Office of Civil Rights (OCR) back in 2009.</span></p>
<p><span style="color: #000080;">To quote from the report, the OIG conducted audits at seven covered entities (hospitals) in California, Georgia, Illinois, Massachusetts, Missouri, New York, and Texas in addition to an audit of CMS oversight and enforcement actions.  These audits focused primarily on the hospitals’ implementation of the following:</span></p>
<ul>
<li><span style="color: #000080;">The wireless electronic communications network or security measures the security management staff implemented in its computerized information systems (technical safeguards);</span></li>
<li><span style="color: #000080;">The physical access to electronic information systems and the facilities in which they are housed (physical safeguards); and,</span></li>
<li><span style="color: #000080;">The policies and procedures developed and implemented for the security measures to protect the confidentiality, integrity, and availability of ePHI (administrative safeguards).</span></li>
</ul>
<p><span style="color: #000080;">These audits were spread over three years (2008, 2009 and 2010) with the last couple of audits happening in March 2010. The report doesn’t mention  the criteria by which these hospitals were selected for audit except that these  hospitals were not selected because they had a breach of Protected Health Information(PHI) .</span></p>
<p><span style="color: #000080;">It wouldn’t necessarily be wise to extrapolate the findings in the report to the larger healthcare space in general without knowing how these hospitals were selected for audit. All one can say is that the findings would paint a worrisome picture if these hospitals were selected truly in a random manner.  For example, if one were to look at ”High Impact” causing  technical vulnerabilities, all 7 audited hospitals seem to have had vulnerabilities related to Access and Integrity Controls, 5 out of  7 had vulnerabilities related to Wireless and Audit Controls and  4 out 7 had vulnerabilities related to Authentication and Transmission Security Controls.</span></p>
<p><a href="http://rnc2.com/wp-content/uploads/2011/05/image1.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" title="image" src="http://rnc2.com/wp-content/uploads/2011/05/image_thumb1.png" border="0" alt="image" width="652" height="646" /></a><span style="color: #000080;"><br />
</span></p>
<p><span style="color: #000080;">What might be particularly concerning is that the highest number of vulnerabilities were in the Access and Integrity Controls categories.  These are typically the vulnerabilities that are exploited most by hackers as evidenced (for instance) by the highlight in this quote from the </span><strong><a href="http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2011_en_xg.pdf" target="_blank"><span style="color: #000080;">2011 Verizon Data Breach Investigation Report</span></a></strong><span style="color: #000080;"> &#8211; “<em>The top three threat action categories were Hacking, Malware, and Social. The most common types of hacking actions used were the use of <span style="background-color: #00ff00;">stolen login credentials, exploiting backdoors</span>, and man-in-the-middle attacks</em>”.</span></p>
<p><span style="color: #000080;">Wake-up call or not, healthcare entities should perhaps take a cue from these findings and look to implement robust security and privacy  controls. A diligent effort should help protect organizations from the well publicized consequences of a potential data breach.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/regulatory-compliance/hipaahhitech/do-we-have-a-wake-up-call-in-the-oig-hhs-report-on-hipaa-security-rule-compliance-enforcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Next time you do a Risk Assessment or Analysis, make sure you have Risk Intelligence on board</title>
		<link>http://rnc2.com/privacy/next-time-you-do-a-risk-assessment-or-analysis-make-sure-you-have-risk-intelligence-on-board/</link>
		<comments>http://rnc2.com/privacy/next-time-you-do-a-risk-assessment-or-analysis-make-sure-you-have-risk-intelligence-on-board/#comments</comments>
		<pubDate>Fri, 19 Nov 2010 16:09:56 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[Information Risk]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Assessment]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=406</guid>
		<description><![CDATA[I was prompted to write this quick post this morning when I read this article. I think it is a good example of what some (actually many, in my experience) risk management programs may be lacking, which is a good quality of Risk Intelligence. In this particular case, I think the original article failed to [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">I was prompted to write this quick post this morning when I read </span><a href="http://www.networkworld.com/news/2010/111810-expert-rebuts-dirty-dozen.html?hpg1=bn" target="_blank"><span style="color: #004080;"><strong><span style="color: #000080;">this article</span></strong></span></a><span style="color: #000080;">. </span></p>
<p><span style="color: #000080;">I think it is a good example of what some (actually many, in my experience) risk management programs may be lacking, which is a good quality of Risk Intelligence. In this particular case, I think the original article failed to emphasize that vulnerabilities by themselves may not mean much unless there is a good likelihood of them being exploited, resulting in <em>real</em> risk.  We discussed some details regarding the quality of risk assessments in </span><a href="http://rnc2.com/regulatory-compliance/pcidss/verizon-2010-data-breach-investigations-report-key-takeaways-for-security-assessors-or-auditors/" target="_blank"><span style="color: #004080;"><strong><span style="color: #000080;">a previous post</span></strong></span></a><span style="color: #000080;">.</span></p>
<p><span style="color: #000080;">A good understanding of information risks and their prioritization needs to be the first and arguably the most important step in any information risk management program. Yet, we often see risk assessment initiatives not being done right or at the right quality. We think it is critical that a risk analysis or assessment is headed by someone or performed by a team that has or does the following:</span></p>
<ol>
<li><span style="color: #000080;">A very good understanding of your environment from people, process and technology perspectives</span></li>
<li><span style="color: #000080;">A very good and up-to-date intelligence on the current threats out there (both internal and external) and is able to objectively define those threats</span></li>
<li><span style="color: #000080;">Is able to clearly list and define the vulnerabilities in your environment. It will often require  process or technology specialists to do a good job of defining the vulnerabilities </span></li>
<li><span style="color: #000080;">Is able to make an unbiased and objective determination of the the likelihood that the vulnerabilities (from Step 3) can be exploited by one or more threats (from Step 2) </span></li>
<li><span style="color: #000080;">A very good understanding of the impact to the business if each vulnerability were to be exploited by one or more threats. Impact is largely a function of the organization’s characteristics including various </span><a href="http://www.owasp.org/index.php/OWASP_Risk_Rating_Methodology#Technical_Impact_Factors" target="_blank"><span style="color: #004080;"><strong><span style="color: #000080;">business and technical factors</span></strong></span></a><span style="color: #000080;">, so it is important that you involve your relevant business and  technology Subject  Matter Experts.</span></li>
<li><span style="color: #000080;">Based on the likelihood (Step 4) and impacts (Step 5), estimate risks and then rank them by magnitude.</span></li>
</ol>
<p><span style="color: #000080;">We just can’t stress the importance of steps 1-5 enough. We think it takes “Risk Intelligence” to do these steps well. Without good Risk Intelligence on your team, you may well be wasting precious time, money and resources on your risk assessments.  More importantly, you may not be protecting your business to the extent that you should, with the same budget and resources.</span></p>
<p>======================================</p>
<p><strong>Important Disclaimer</strong></p>
<p><span style="color: #339966;">The guidance and content we provide in our blogs including this one is based on our experience and understanding of best practices. Readers must always exercise due diligence and obtain professional advice before applying the guidance within their environments.</span></p>
<p><span style="color: #004080;"> </span></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/privacy/next-time-you-do-a-risk-assessment-or-analysis-make-sure-you-have-risk-intelligence-on-board/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Providers &#8211; Is HIPAA Security Risk Analysis in your plan over the next few months?</title>
		<link>http://rnc2.com/regulatory-compliance/hipaahhitech/providers-is-hipaa-security-risk-analysis-in-your-plan-over-the-next-few-months/</link>
		<comments>http://rnc2.com/regulatory-compliance/hipaahhitech/providers-is-hipaa-security-risk-analysis-in-your-plan-over-the-next-few-months/#comments</comments>
		<pubDate>Wed, 22 Sep 2010 17:40:38 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[HIPAA/HITECH Compliance]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Assessment]]></category>
		<category><![CDATA[EHRs]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[Meaningful Use]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=317</guid>
		<description><![CDATA[Security Risk Analysis is something that we recommend all organizations conduct periodically or before a  significant process or technology change. After all, threats, vulnerabilities and impact (three components of risk, see my other post here) often change or evolve over time which means that risk analysis results can soon become outdated. In the context of [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">Security Risk Analysis is something that we recommend all organizations conduct periodically or before a  significant process or technology change. After all, threats, vulnerabilities and impact (three components of risk, </span><a href="http://rnc2.com/regulatory-compliance/pcidss/verizon-2010-data-breach-investigations-report-key-takeaways-for-security-assessors-or-auditors/" target="_blank"><span style="color: #000080;"><strong>see my other post here</strong></span></a><span style="color: #000080;">) often change or evolve over time which means that risk analysis results can soon become outdated.</span></p>
<p><span style="color: #000080;">In the context of Healthcare, Security Risk Analysis is also mandatory for two reasons.</span></p>
<p><span style="color: #000080;">The first reason is that it is required for compliance with </span><a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/security101.pdf" target="_blank"><span style="color: #000080;"><strong>HIPAA Security Rule</strong></span></a><span style="color: #000080;"> which, </span><a href="http://rnc2.com/regulatory-compliance/hipaahhitech/proposed-updates-to-hipaa-security-and-privacy-rules-what-is-new/" target="_blank"><span style="color: #000080;"><strong>by way of the HITECH Act</strong></span></a><span style="color: #000080;">, now applies to Business Associates in addition to Covered Entities.  It is a “Required” Implementation Specification in the “Security Management Process” standard under Administrative Safeguards of the HIPAA Security Rule, as highlighted in the table below.</span></p>
<p><a href="http://rnc2.com/wp-content/uploads/2010/09/image6.png"><img style="display: inline; border-width: 0px;" title="image" src="http://rnc2.com/wp-content/uploads/2010/09/image_thumb6.png" border="0" alt="image" width="618" height="139" /></a></p>
<p><span style="color: #000080;">The second (and more urgent) reason to conduct a Security Risk Analysis is that it is a core requirement for providers to achieve </span><a href="http://healthit.hhs.gov/portal/server.pt?open=512&amp;objID=2996&amp;mode=2" target="_blank"><span style="color: #000080;"><strong>Meaningful Use certification of Electronic Health Records (EHRs)</strong></span></a><span style="color: #000080;"> and thereby become eligible for Medicare/Medicaid incentives beginning April 2011 or risk Medicare reimbursement penalties beginning 2015 (see below).</span></p>
<p><a href="http://rnc2.com/wp-content/uploads/2010/09/image7.png"><img style="display: inline; border-width: 0px;" title="image" src="http://rnc2.com/wp-content/uploads/2010/09/image_thumb7.png" border="0" alt="image" width="619" height="71" /></a> <a href="http://rnc2.com/wp-content/uploads/2010/09/image8.png"><img style="display: inline; border-width: 0px;" title="image" src="http://rnc2.com/wp-content/uploads/2010/09/image_thumb8.png" border="0" alt="image" width="620" height="125" /></a></p>
<p><a href="http://rnc2.com/wp-content/uploads/2010/09/clip_image00131.png"><img style="display: inline; border-width: 0px;" title="clip_image001[3]" src="http://rnc2.com/wp-content/uploads/2010/09/clip_image0013_thumb1.png" border="0" alt="clip_image001[3]" width="609" height="324" /></a></p>
<p><strong>Source: Center for Medicare &amp; Medicaid Services (CMS)</strong></p>
<p><strong><br />
</strong></p>
<p><span style="color: #000080;">So, it is important that providers plan on conducting a security risk analysis within the next few months unless you have conducted one recently. If you have already implemented an EHR system, you will need to ensure that the risk analysis included the EHR system and the related processes or practice workflows. If you plan to implement an EHR system in the next few months, we would recommend conducting risk analysis before the implementation so that any discovered risks can be identified and mitigated by proper design of the system and associated workflows or processes.  Any change to the system or processes after implementation is going to be hard, not to talk of the disruption to the practice and other costs.</span></p>
<p><span style="color: #000080;">The <a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/rafinalguidance.html" target="_blank"><strong>Final Guidance from OCR on Risk Analysis</strong></a></span><span style="color: #000080;"> </span><span style="color: #000080;"> can be a useful reference in planning and conduct of risk analysis efforts.</span></p>
<p><span style="color: #000080;">Finally, I would like to go back to what I said right at the beginning. We recommend that organizations focus on managing all information risks, not just the risk of non-compliance with regulations such as HIPAA.  Therefore, it is critical that personnel performing the risks analysis are up-to-date on the current threat environment. Upon determination of the threats, one must be able to clearly identify the organization’s vulnerabilities to those threats and then the impact resulting from any exploits and various legal or compliance obligations including HIPAA.  Last but not the least, risk analysis must be conducted at appropriate intervals and certainly whenever there is a significant change in processes or technologies.</span></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p><em>Important Disclaimer </em></p>
<p><em>The guidance and content we provide in our blogs including this one is based on our experience and understanding of best practices. Readers must always exercise due diligence and obtain professional advice before applying the guidance within their environments.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/regulatory-compliance/hipaahhitech/providers-is-hipaa-security-risk-analysis-in-your-plan-over-the-next-few-months/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Let&#8217;s talk some &#8220;real&#8221; insider threat numbers &#8211; How can Access Governance and SIEM be useful as effective safeguards?</title>
		<link>http://rnc2.com/information-risk/accessgovernance-siem-effective-safeguards-against-insider-threats/</link>
		<comments>http://rnc2.com/information-risk/accessgovernance-siem-effective-safeguards-against-insider-threats/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 21:25:35 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[Access Governance]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Information Risk]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIEM]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=307</guid>
		<description><![CDATA[If you have been following some of our posts, you probably realize that we don’t advocate security for the sake of security. Nor do we like to do compliance for the sake of compliance though you may not have much choice there if the compliance requirements are mandated by external regulations such as industry regulations [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080">If you have been following some of our posts, you probably realize that we don’t advocate security for the sake of security. Nor do we like to do compliance for the sake of compliance though you may not have much choice there if the compliance requirements are mandated by external regulations such as industry regulations (e.g. PCI DSS, NERC CIP etc.) or government regulations (e.g. HIPAA, GLBA, SOX etc.). On the other hand, we think that every investment in security projects or operations (beyond what is required for routine business support) must be justifiable in terms of the risk(s) that we are trying to mitigate or eliminate. And the allocation of IT resources and budgets must be prioritized by risk level which in turn requires every IT organization to conduct periodic risk assessments&#160; and rank the risks by severity.&#160; This probably sounds all too obvious but we still see a lot of security purchasing decisions being made that are not based on formal risk assessments or discernable risk-aligned&#160; priorities. BTW, I talk about the quality of risk assessments </span><a href="http://rnc2.com/regulatory-compliance/pcidss/verizon-2010-data-breach-investigations-report-key-takeaways-for-security-assessors-or-auditors/" target="_blank"><span style="color: #000080"><strong>in another post</strong></span></a><span style="color: #000080">.</span></p>
<p><span style="color: #000080">In this post, I would like to go over some “real” numbers on insider threats, as we know from a few recent survey reports. More importantly, I’ll cover how Access Governance and Security Information and Event Management (SIEM) can be effective safeguards in mitigating risks from insider threats.&#160; If you are not up to speed on what Access Governance (sometimes also referred to as Access Assurance) includes, I would point </span><span style="color: #000080">you <a href="http://www.kuppingercole.com/events/n40069" target="_blank"><strong>here</strong></a></span><span style="color: #000080"> (may need registration).&#160; For SIEM, I would point you </span><a href="http://en.wikipedia.org/wiki/SIEM" target="_blank"><span style="color: #000080"><strong>here</strong></span></a><span style="color: #000080">.</span></p>
<p><span style="color: #000080">It probably needs an explanation as to why I chose Access Governance and SIEM for this discussion. Insider threats, by definition, are caused by people&#160; (employers, contractors, partners etc.) whose identity is known to the organization and have been provided some level of access to one or more of the organization&#8217;s information systems.&#160; Access Governance can be both an effective detective control (through access reviews) and preventative control (through role based access provisioning and access remediation) for user access. SIEM can be an effective control for detecting anomalous, suspicious&#160; or&#160; unauthorized user activities. When properly integrated, Access Governance and SIEM&#160; solutions can help achieve substantial reduction of risks from insider threats.</span></p>
<p><span style="color: #000080">Below is a discussion of findings related to insider threats from recent reports. Also provided are notes on how effective implementations of Access Governance and SIEM processes or technologies can be useful safeguards against these threats. I use findings from three recent reports for the analysis &#8211; </span><a href="http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf" target="_blank"><span style="color: #000080"><strong>2010 Verizon Data Breach Investigations Report</strong></span></a><span style="color: #000080"><strong> (DBIR), </strong></span><a href="http://www.sei.cmu.edu/newsitems/cyber_sec_watch_2010_release.cfm" target="_blank"><span style="color: #000080"><strong>2010 CyberSecurity Watch Survey</strong></span></a><span style="color: #000080"> <strong>(CSWS)</strong>and </span><a href="http://securosis.com/blog/the-securosis-2010-data-security-survey-report-rates-the-top-5-data-securit" target="_blank"><span style="color: #000080"><strong>Securosis 2010 Data Security Survey</strong></span></a><span style="color: #000080"> <strong>(SDSS).</strong></span></p>
<p><strong><span style="font-size: medium"><span style="color: #000080"></span></span></strong></p>
<p><strong><span style="font-size: medium"><span style="color: #000080"></span></span></strong></p>
<p><strong><span style="font-size: medium"><span style="color: #000080"></span></span></strong></p>
<p><strong><span style="font-size: medium"><span style="color: #000080">Size and significance of Insider Threats</span></span></strong></p>
<table style="border-bottom: medium none; border-left: medium none; border-collapse: collapse; border-top: medium none; border-right: medium none; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt" class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr style="height: 18.4pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #1f497d; height: 18.4pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2" valign="top" width="59">
<p style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: white; font-size: 10.5pt; mso-themecolor: background1">Report </span></strong></p>
<p><strong></strong><strong></strong></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #1f497d; height: 18.4pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" valign="top" width="408">
<p style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: white; font-size: 10.5pt; mso-themecolor: background1">Finding </span></strong></p>
<p><strong></strong><strong></strong></p>
</td>
</tr>
<tr style="height: 18.4pt; mso-yfti-irow: 1">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51" valign="top" width="59">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">DBIR </font></span></span></span></span></span></strong></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="408">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">48% of all breaches were attributed to internal agents </font></span></span></span></span></span></p>
</td>
</tr>
<tr style="height: 18.4pt; mso-yfti-irow: 2">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51" valign="top" width="59">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">CSWS </font></span></span></span></span></span></strong></p>
<p><span style="font-size: x-small"><span style="color: #1f497d"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><font size="2"><font color="#000080"><strong></strong><strong></strong></font></font></span></span></span></span></span></span></span></span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="408">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">“The most costly or damaging attacks are more often caused by insiders (employees or contractors with authorized access)” </font></span></span></span></span></span></p>
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">“It is alarming that although most of the top 15 security policies and procedures from the survey are aimed at preventing insider attacks, 51% of respondents who experienced a cyber security event were still victims of an insider attack. This number is holding constant with the previous two surveys (2007 and 2006) </font></span></span></span></span></span></p>
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">Insider incidents are more costly than external breaches, according to 67% of respondents </font></span></span></span></span></span></p>
</td>
</tr>
<tr style="height: 18.4pt; mso-yfti-irow: 3; mso-yfti-lastrow: yes">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51" valign="top" width="59">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">SDSS </font></span></span></span></span></span></strong></p>
<p><span style="font-size: x-small"><span style="color: #1f497d"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><font size="2"><font color="#000080"><strong></strong><strong></strong></font></font></span></span></span></span></span></span></span></span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="408">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">Among respondents who knew of data breaches in their own organizations, 62 percent said malicious intentions were behind them. Insider breaches comprised 33 percent of incidents, hackers comprised 29 percent, and the remaining breaches were accidental.</font></span></span> </span></span></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal">
<p><span style="color: #000080">As one can infer from these findings, insider threats are the cause of at least as many security breaches as external threats. It also appears that the cost of breaches caused by internal threats could be higher than those caused by external threats.</span></p>
<p class="MsoNormal"><strong><span style="color: #000080"></span></strong></p>
<p class="MsoNormal"><strong><span style="color: #000080"><span style="font-size: small"></span></span></strong></p>
<p class="MsoNormal"><strong><span style="color: #000080"><span style="font-size: small"><span style="font-size: small"><span style="font-size: small"><span style="font-size: small"><font size="3">Intentional Vs Accidental</font></span></span></span></span></span></strong></p>
<table style="border-bottom: medium none; border-left: medium none; border-collapse: collapse; border-top: medium none; border-right: medium none; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt" class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr style="height: 18.4pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #1f497d; height: 18.4pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2" valign="top" width="59">
<p style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: white; font-size: 10.5pt; mso-themecolor: background1">Report </span></strong></p>
<p><strong></strong><strong></strong></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #1f497d; height: 18.4pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" valign="top" width="408">
<p style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: white; font-size: 10.5pt; mso-themecolor: background1">Finding </span></strong></p>
<p><strong></strong><strong></strong></p>
</td>
</tr>
<tr style="height: 18.4pt; mso-yfti-irow: 1">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51" valign="top" width="59">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">DBIR </font></span></span></span></span></span></strong></p>
<p><span style="font-size: x-small"><span style="color: #1f497d"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><font size="2"><font color="#000080"><strong></strong><strong></strong></font></font></span></span></span></span></span></span></span></span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="408">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">90% of these internal agents’ caused breaches were the result of deliberate and malicious activity.</font></span></span></span></span></span></p>
</td>
</tr>
<tr style="height: 18.4pt; mso-yfti-irow: 2">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51" valign="top" width="59">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">CSWS </font></span></span></span></span></span></strong></p>
<p><span style="font-size: x-small"><span style="color: #1f497d"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><font size="2"><font color="#000080"><strong></strong><strong></strong></font></font></span></span></span></span></span></span></span></span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="408">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">Insiders most commonly expose private or sensitive information unintentionally, gain unauthorized access to/use of information systems or networks and steal intellectual property </font></span></span></span></span></span></p>
</td>
</tr>
<tr style="height: 18.4pt; mso-yfti-irow: 3; mso-yfti-lastrow: yes">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51" valign="top" width="59">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">SDSS </font></span></span></span></span></span></strong></p>
<p><span style="font-size: x-small"><span style="color: #1f497d"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><font size="2"><font color="#000080"><strong></strong><strong></strong></font></font></span></span></span></span></span></span></span></span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="408">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">Among respondents who knew of data breaches in their own organizations, 62 percent said malicious intentions were behind them. Insider breaches comprised 33 percent of incidents, hackers comprised 29 percent, and the remaining breaches were accidental.</font></span></span></span></span></span></p>
</td>
</tr>
</tbody>
</table>
<p><span style="color: #000080">It appears from the findings that insiders could be causing breaches intentionally more often than accidentally. Access Governance can help reduce malicious insider risk&#160; by enforcing “least privilege” user access and &quot;segregation of duties&quot; through role based access provisioning, access reviews and remediation of improper access. On the other hand, a properly implemented SIEM solution can be an effective deterrent (as a detective control) to malicious insider threats by logging user activities, correlation of user activities and alerting on suspicious activities by the user. By suitable integration of SIEM and Access Governance solutions, it is possible to analyze user activities (obtained from SIEM) against a user’s role in the organization and hence what the user is authorized to do (obtained from Access Governance).</span></p>
<p><strong></strong></p>
<p class="MsoNormal"><strong></strong></p>
<p class="MsoNormal"><strong></strong></p>
<p class="MsoNormal"><strong><span style="font-size: medium"><span style="color: #000080">Cause and prevention</span></span></strong></p>
<table style="border-bottom: medium none; border-left: medium none; border-collapse: collapse; border-top: medium none; border-right: medium none; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt" class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr style="height: 18.4pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #1f497d; height: 18.4pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2" valign="top" width="59">
<p style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: white; font-size: 10.5pt; mso-themecolor: background1">Report </span></strong></p>
<p><strong></strong><strong></strong></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #1f497d; height: 18.4pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" valign="top" width="408">
<p style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: white; font-size: 10.5pt; mso-themecolor: background1">Finding </span></strong></p>
<p><strong></strong><strong></strong></p>
</td>
</tr>
<tr style="height: 18.4pt; mso-yfti-irow: 1">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51" valign="top" width="59">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">DBIR </font></span></span></span></span></span></strong></p>
<p><span style="font-size: x-small"><span style="color: #1f497d"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><font size="2"><font color="#000080"><strong></strong><strong></strong></font></font></span></span></span></span></span></span></span></span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="408">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">51% of these internal agents&#8217; caused breaches involves regular users or employees, 12% involved accounting or finance staff and 12% involved network or systems administrators </font></span></span></span></span></span></p>
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">“In general, employees are granted more privileges than they need to perform their job duties and the activities of those that do require higher privileges are usually not monitored in any real way.” </font></span></span></span></span></span></p>
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">“Across all types of internal agents and crimes, we found that 24% was perpetrated by employees who recently underwent some kind of job change. Half of those had been fired, some had resigned, some were newly hired, and a few changed roles within the organization.” </font></span></span></span></span></span></p>
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">“With respect to breaches caused by recently terminated employees, we observed the same scenarios we have in the past: 1) the employee’s accounts were not disabled in a timely manner, and&#160;&#160; 2) the employee was allowed to “finish the day” as usual after being notified of termination. This obviously speaks to the need for termination plans that are timely and encompass all areas of access (decommissioning accounts, disabling privileges, escorting terminated employees, forensic analysis of systems, etc.)” </font></span></span></span></span></span></p>
</td>
</tr>
<tr style="height: 18.4pt; mso-yfti-irow: 2; mso-yfti-lastrow: yes">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 44pt; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51" valign="top" width="59">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><strong><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">CSWS </font></span></span></span></span></span></strong></p>
<p><span style="font-size: x-small"><span style="color: #1f497d"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><span style="font-size: x-small"><span style="color: #000080"><font size="2"><font color="#000080"><strong></strong><strong></strong></font></font></span></span></span></span></span></span></span></span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 4.25in; padding-right: 5.4pt; background: #c6d9f1; height: 18.4pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="408">
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">“The most costly or damaging attacks are more often caused by insiders (employees or contractors with authorized access)” </font></span></span></span></span></span></p>
<p style="margin-bottom: 0.2in; vertical-align: baseline; mso-margin-top-alt: auto; mso-para-margin-bottom: 1.2gd; mso-hyphenate: auto" class="MsoNormal"><span style="font-family: &amp;amp; color: #1f497d; font-size: 10.5pt; mso-themecolor: text2"><span style="font-size: x-small"><span style="color: #000080; font-size: x-small"><span style="font-size: x-small"><span style="font-size: x-small"><font size="2">“It is alarming that although most of the top 15 security policies and procedures from the survey are aimed at preventing insider attacks, 51% of respondents who experienced a cyber security event were still victims of an insider attack. This number is holding constant with the previous two surveys (2007 and 2006)</font></span></span></span></span></span></p>
</td>
</tr>
</tbody>
</table>
<p><span style="color: #000080">The DBIR findings clearly illustrate the need for organizations to enforce least privilege access through business need-to-know (managing user access based on a user’s </span><em><span style="color: #000080">role</span></em><span style="color: #000080">), periodic review of user access (access reviews and certification) and prompt remediation of improper user access.&#160; Access Governance solutions can help achieve these objectives effectively as well as efficiently.</span></p>
<p><span style="color: #000080">The CSWS finding seems to suggest a problem with the enforcement of organization’s policies related to user access.&#160; As mentioned above, a properly implemented Access Governance program and solution can help with effective enforcement of user access policies.</span></p>
<p><span style="color: #000080">To conclude, it is obvious that risk management of insider threats needs to be a key focus area of any Information Security&#160; or Risk Management program. An effective Access Governance and SIEM program can help with significant mitigation of the insider risk.</span></p>
<p><span style="color: #000080">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</span></p>
<p><strong><em>RisknCompliance Consulting Services Note</em></strong></p>
<p><em>We at RisknCompliance have extensive advisory and implementation experience in the Access Governance and SIEM areas. </em></p>
<p><em>Please <a href="http://rnc2.com/contact/"><strong>contact us here</strong></a> if you would like to discuss your needs. We will be glad to talk to you about how we could be of assistance.</em></p>
<p><span style="color: #000080">     <br /></span></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/information-risk/accessgovernance-siem-effective-safeguards-against-insider-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You don&#8217;t know what you don&#8217;t know &#8211; Do we have a &quot;detection&quot; problem with the healthcare data breach numbers?</title>
		<link>http://rnc2.com/regulatory-compliance/hipaahhitech/you-dont-know-what-you-dont-know-do-we-have-a-detection-problem-with-the-healthcare-data-breach-numbers/</link>
		<comments>http://rnc2.com/regulatory-compliance/hipaahhitech/you-dont-know-what-you-dont-know-do-we-have-a-detection-problem-with-the-healthcare-data-breach-numbers/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 22:57:16 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[HIPAA/HITECH Compliance]]></category>
		<category><![CDATA[Information Risk]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=263</guid>
		<description><![CDATA[Like some of you perhaps, I have been reading a few recent articles on Healthcare data breaches, especially the one from Dark Reading and a detailed analysis of the 2010-to-date breaches from HITRUST Alliance. What stood out for me from these articles is something that is not necessarily highlighted in the articles and that is [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">Like some of you perhaps, I have been reading a few recent articles on Healthcare data breaches, especially the one from </span><a href="http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=226600307" target="_blank"><span style="color: #000080;"><strong>Dark Reading</strong></span></a><span style="color: #000080;"> and a<strong> </strong></span><a href="https://www.hitrustcentral.net/blogs/attachment/1c3d9fa8-be55-4183-8708-267935cf1dcf.ashx" target="_blank"><span style="color: #000080;"><strong>detailed analysis of the 2010-to-date breaches from HITRUST Alliance</strong></span></a><span style="color: #000080;">.</span></p>
<p><span style="color: #000080;">What stood out for me from these articles is something that is not necessarily highlighted in the articles and that is the very low number of breaches involving technology/people/process controls as opposed to physical losses. </span></p>
<p><span style="color: #000080;">These articles focused on the 119 or so breaches that have been reported to Department of Health and Human Services (HHS) or made public to date in 2010. From the HITRUST Alliance analysis, it is clear that an overwhelming majority of the breaches resulted from physical loss/theft of paper or electronic media, laptops etc.  Only two breaches resulted from hacking incidents.</span></p>
<p><span style="color: #000080;">I then went back to do a little bit of my own analysis of the 2010 data breach incidents covered in the Identity Theft Resource Center report available </span><a href="http://www.idtheftcenter.org/artman2/publish/lib_survey/ITRC_2008_Breach_List.shtml#" target="_blank"><span style="color: #000080;"><strong>here</strong></span></a><span style="color: #000080;">. I came up with the following numbers for breaches other than those that involved physical loss, theft, burglary, improper disposal etc. :</span></p>
<ul>
<li><span style="color: #000080;">Malware  infection -1 </span></li>
<li><span style="color: #000080;">Unauthorized access to file share – 1 </span></li>
<li><span style="color: #000080;">Database misconfiguration or vulnerability – 2 </span></li>
<li><span style="color: #000080;">Website vulnerability – 1 </span></li>
<li><span style="color: #000080;">Improper access or misuse by internal personnel – 6 </span></li>
</ul>
<p><span style="color: #000080;">As you can see, these account for less than 10% of the healthcare breaches known or reported so far this year.  Contrast this with the findings in </span><a href="http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf" target="_blank"><span style="color: #000080;"><strong>2010 Verizon Data Breach Investigation Report</strong></span></a><span style="color: #000080;"><strong> </strong>which attributes 38% of breaches to malware, 40% to hacking and 48% to misuse. It is pertinent to note that the Verizon report focused on 141 confirmed breaches from 2009 covering  a variety of industries,  but I think it is still good for a high level comparison to determine if we may be missing something in the healthcare breach data.</span></p>
<p><span style="color: #000080;">The comparison seems to suggest that the healthcare industry probably has much stronger safeguards  against malware, hacking, improper logical access etc.  I know from my own experience working with healthcare entities that this is not necessarily the case. For further corroboration, I reviewed two Ponemon Institute survey reports &#8211; </span><a href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/Electronic%20Health%20Information%20at%20Risk%20FINAL%201.pdf" target="_blank"><span style="color: #000080;"><strong>Electronic Health Information at Risk: A Study of IT Practitioners</strong></span></a><span style="color: #000080;"><strong> </strong>and </span><a href="http://www.crowehorwath.com/crowe/lp/knowledge-center-lp.cfm?webDocId=TR9014F" target="_blank"><span style="color: #000080;"><strong>Are You Ready for HITECH? &#8211; A benchmark study of healthcare covered entities &amp; business associates</strong></span></a><span style="color: #000080;">, both from Q4 2009. Following sample numbers from these reports further validate that the state of Information Security and Privacy among HIPAA Covered Entities (CEs) and Business Associates (BAs) is far from perfect:</span></p>
<p><span style="color: #000080;"> </span><a href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/Electronic%20Health%20Information%20at%20Risk%20FINAL%201.pdf"><span style="color: #000080;"><strong>Electronic Health Information at Risk: A Study of IT Practitioners</strong></span></a></p>
<table class="MsoTableGrid" style="border-collapse: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; border: medium none;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr style="height: 34.15pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes;">
<td style="padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #1f497d; height: 34.15pt; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; border: black 1pt solid;" width="38" valign="top">
<p class="MsoNormal" style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><strong><span style="font-family: &amp;amp;amp; color: white; font-size: 8pt; mso-fareast-language: en-us;"># </span></strong></p>
<p><strong> </strong><strong> </strong></td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #1f497d; height: 34.15pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><strong><span style="font-family: &amp;amp;amp; color: white; font-size: 8pt; mso-fareast-language: en-us;">Question </span></strong></p>
<p><strong> </strong><strong> </strong></td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #1f497d; height: 34.15pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; margin-bottom: 0.2in; vertical-align: baseline; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><strong><span style="font-family: &amp;amp;amp; color: white; font-size: 8pt; mso-fareast-language: en-us;">% of respondents saying “Yes” </span></strong></p>
<p><strong> </strong><strong> </strong></td>
</tr>
<tr style="height: 21.1pt; mso-yfti-irow: 1;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #dbe5f1; height: 21.1pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="38" valign="top">
<p class="MsoNormal" style="margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">1 </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #dbe5f1; height: 21.1pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">My organization’s senior management does not view privacy and data security as a top priority </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #dbe5f1; height: 21.1pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">70% </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 2;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="38" valign="top">
<p class="MsoNormal" style="margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">2 </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">My organization does not have ample resources to ensure privacy and data security requirements are met – 61% of respondents. </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">61% </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 3;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="38" valign="top">
<p class="MsoNormal" style="margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">3 </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">My organization does not have adequate policies and procedures to protect health information </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">54% </span></p>
</td>
</tr>
<tr style="height: 30.1pt; mso-yfti-irow: 4; mso-yfti-lastrow: yes;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #dbe5f1; height: 30.1pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="38" valign="top">
<p class="MsoNormal" style="margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">4 </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #dbe5f1; height: 30.1pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">My organization does not take appropriate steps to comply with the requirements of HIPAA and other related healthcare regulations </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #dbe5f1; height: 30.1pt; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; margin-bottom: 0.2in; mso-hyphenate: auto; mso-para-margin-bottom: 1.2gd;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">53% </span></p>
</td>
</tr>
</tbody>
</table>
<p><a href="http://www.crowehorwath.com/crowe/lp/knowledge-center-lp.cfm?webDocId=TR9014F"><strong>Are You Ready for HITECH? &#8211; A benchmark study of healthcare covered entities &amp; business associates</strong></a></p>
<table class="MsoTableGrid" style="border-collapse: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; border: medium none;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;">
<td style="padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #1f497d; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; border: black 1pt solid;" width="38" valign="top">
<p class="MsoNormal" style="text-align: center; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><strong><span style="font-family: &amp;amp;amp; color: white; font-size: 8pt; mso-fareast-language: en-us; mso-themecolor: background1;"># </span></strong></p>
<p><strong> </strong><strong> </strong></td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #1f497d; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="text-align: center; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><strong><span style="font-family: &amp;amp;amp; color: white; font-size: 8pt; mso-fareast-language: en-us; mso-themecolor: background1;">HIPAA compliance requirements that are not formally implemented </span></strong></p>
<p><strong> </strong><strong> </strong></td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #1f497d; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><strong><span style="font-family: &amp;amp;amp; color: white; font-size: 8pt; mso-fareast-language: en-us; mso-themecolor: background1;">% of respondents saying “Yes” </span></strong></p>
<p><strong> </strong><strong> </strong></td>
</tr>
<tr style="mso-yfti-irow: 1;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="38" valign="top">
<p class="MsoNormal" style="mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">1 </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">Risk-based assessment of PHI handling practices </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">49% </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 2;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="38" valign="top">
<p class="MsoNormal" style="mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">2 </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">Access governance a and an access management policy </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">47% </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 3;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="38" valign="top">
<p class="MsoNormal" style="mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">3 </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">Staff training </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">47% </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 4; mso-yfti-lastrow: yes;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 28.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="38" valign="top">
<p class="MsoNormal" style="mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">4 </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 193.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="258" valign="top">
<p class="MsoNormal" style="mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">Detailed risk analysis </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 112.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="150" valign="top">
<p class="MsoNormal" style="text-align: center; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: &amp;amp;amp; font-size: 8pt; mso-fareast-language: en-us;">45% </span></p>
</td>
</tr>
</tbody>
</table>
<p><span style="color: #000080;">All this leads me to think of the possibility that some HIPAA CEs and BAs may not be detecting potential breaches. If you study the healthcare breaches that have been reported so far, almost all of them have been through physical losses of computers or media (which is easy to know and detect) or through reporting by third parties (victims, law enforcement, someone finding improperly disposed PHI paper records in trash bins  etc.).  I don’t know of any healthcare data breach this year that was detected through proactive monitoring of information systems.</span></p>
<p><span style="color: #000080;">As I covered in a </span><a href="http://rnc2.com/regulatory-compliance/pcidss/may-we-suggest-some-priority-adjustments-to-your-pci-dss-compliance-program/" target="_blank"><strong><span style="color: #000080;">related post</span></strong></a><span style="color: #000080;"><strong> </strong>on breach reports and what they tell us, I would recommend that CEs and BAs focus on certain key controls and related activities (see table below) in order to improve their breach prevention and detection capabilities:</span></p>
<table class="MsoNormalTable" style="border-collapse: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 0in 0in 0in; mso-border-alt: solid windowtext .5pt; mso-border-insideh: .5pt solid windowtext; mso-border-insidev: .5pt solid windowtext; border: medium none;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;">
<td style="padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #1f497d; padding-top: 0in; mso-border-alt: solid windowtext .5pt; border: windowtext 1pt solid;" width="26" valign="top">
<p class="MsoNormal" style="text-align: center; margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><strong><span style="color: white; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 12.0pt;">#</span></strong><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;"> </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #1f497d; border-top: windowtext 1pt solid; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt;" width="132">
<p class="MsoNormal" style="text-align: center; margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><strong><span style="color: white; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 12.0pt;">Key Controls</span></strong><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;"> </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #1f497d; border-top: windowtext 1pt solid; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt;" width="294">
<p class="MsoNormal" style="text-align: center; margin-bottom: 6pt; margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto;"><strong><span style="color: white; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 12.0pt;">Recommended Activities</span></strong><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;"> </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 1;">
<td style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="26" valign="top">
<p class="MsoNormal" style="margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">1 </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Secure Configuration and Lockdown </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="294" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Review configuration of information systems (network devices, servers, applications, databases etc.) periodically and ensure that they are locked down from a security configuration standpoint </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 2;">
<td style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="26" valign="top">
<p class="MsoNormal" style="margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">2 </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Web Application Security </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="294" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Scan web applications periodically for OWASP Top 10 vulnerabilities and fix any discovered vulnerabilities </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">For new applications under development, perform code reviews and/or vulnerability scans to fix any security vulnerabilities before the applications are put to production use (Studies show that it is far more cost effective to fix the vulnerabilities before applications are put to production use than after) </span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Use Web Application Firewalls as appropriate </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 3;">
<td style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="26" valign="top">
<p class="MsoNormal" style="margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">3 </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Strong Access Credentials </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="294" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Configure PHI systems and applications to have a strong password policy (complexity of the password, periodic change of password etc.) </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Implement multi-factor authentication on PHI systems and applications wherever possible </span></p>
<p class="MsoListParagraphCxSpLast" style="margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-add-space: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;"><br />
(Note: According to 2010 Verizon Data Breach investigation report, stolen access credentials lead to largest number of breaches from hacking incidents) </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 4;">
<td style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="26" valign="top">
<p class="MsoNormal" style="margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">4 </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Access Assurance or Governance </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="294" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Conduct Access Certifications periodically, preferably at least every quarter for PHI systems and applications. </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 6pt 5.75pt 0pt 0.5in; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Review access privileges within PHI systems and applications to ensure all access conforms to the “Least Privilege” principle. In other words, no user, application or service must have any more privileges than what is required for the job function or role </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 6pt 5.75pt 0pt 0.5in; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">If any excess privileges are found, they must be remediated promptly </span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Revoke access to PHI systems and applications promptly in the event that a person leaves the organization or no longer requires access due to a change in the person’s job role within the organization </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 5;">
<td style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="26" valign="top">
<p class="MsoNormal" style="margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">5 </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Logging, Monitoring and Reporting </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="294" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Identify “risky” events within PHI systems </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Configure the systems to generate logs for the identified events </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Tamper-proof the logs </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Implement appropriate technologies and/or processes for monitoring of the events (Refer to our related posts <a href="http://rnc2.com/regulatory-compliance/pcidss/logging-unix-network-databases-pci-dss/"><span style="color: black; text-decoration: none; text-underline: none;"><strong>here</strong></span></a> and <a href="http://rnc2.com/regulatory-compliance/pcidss/logging-for-pci-dss-compliance/"><span style="color: black; text-decoration: none; text-underline: none;"><strong>here</strong></span></a> for examples) </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">High risk events must be identified and monitored through near-real-time alerts </span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Responsibilities for daily review of log reports and alerts must be assigned to specific personnel </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 6;">
<td style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="26" valign="top">
<p class="MsoNormal" style="margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">6 </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Encryption (Data at rest, media), Physical security of media </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="294" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Maintain an inventory of locations and systems wherever PHI exists </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Implement suitable encryption of PHI on laptops and removable media </span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Implement appropriate physical security safeguards to prevent theft of devices or systems containing PHI </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 7;">
<td style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="26" valign="top">
<p class="MsoNormal" style="margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">7 </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Security Incident Response </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="294" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;"><span style="mso-spacerun: yes;"> </span>Implement and operationalize an effective Security Incident Response program including clear assignment of responsibilities, response steps/workflows  etc. </span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Test Incident Response process periodically as required </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 8; mso-yfti-lastrow: yes;">
<td style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 19.65pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="26" valign="top">
<p class="MsoNormal" style="margin-left: 6pt; margin-right: 6pt; mso-hyphenate: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">8 </span><span style="mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 99pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="margin: 6pt 5.75pt 0pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Security Awareness and Training </span></p>
</td>
<td style="border-bottom: windowtext 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 220.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="294" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Implement a formal security awareness and training program so the workforce is aware of their responsibilities,  security/privacy best practices and actions to take in the event of suspected incidents </span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9.35pt; margin: 6pt 5.75pt 0pt 9.35pt; mso-hyphenate: auto; mso-list: l0 level1 lfo1; mso-add-space: auto;"><span style="font-family: symbol; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="font-family: &amp;amp;amp; color: black; font-size: 8pt; mso-fareast-language: en-us; mso-bidi-font-size: 10.0pt;">Require personnel to go through the security awareness and/or training periodically as appropriate </span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><span style="color: #000080;"> </span></p>
<p class="MsoNormal"><span style="color: #000080;">If you are familiar with the HIPAA Security Rule, you will notice that not all of the above controls are “Required” (as opposed to “Addressable”) under HIPAA Security Rule or in the proposed amendments to the rule under the HITECH Act. One may argue however, that the above controls must be identified as required based on &#8220;risk analysis&#8221; , which of course is a required implementation specification in the HIPAA Security Rule. In any event, CEs and BAs need to look beyond the HIPAA compliance risk and focus on the risk to their business or brand reputation if a breach were to occur.</span></p>
<p><span style="color: #000080;">Hope this is useful! As always, we welcome your thoughts and comments.</span></p>
<p><strong><em>RisknCompliance Services Note</em></strong></p>
<p><em>We at RisknCompliance maintain a up-to-date database of the current security threats and vulnerabilities at a detailed level. We are able to leverage this knowledge in  providing our clients with  high quality risk analysis. </em></p>
<p><em>Please <a href="http://rnc2.com/contact/"><strong>contact us here</strong></a> if you would like to discuss your HIPAA security or privacy needs. We will be glad to talk to you about how we could be of assistance.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/regulatory-compliance/hipaahhitech/you-dont-know-what-you-dont-know-do-we-have-a-detection-problem-with-the-healthcare-data-breach-numbers/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>May we suggest some priority adjustments to your PCI DSS Compliance program?</title>
		<link>http://rnc2.com/regulatory-compliance/pcidss/may-we-suggest-some-priority-adjustments-to-your-pci-dss-compliance-program/</link>
		<comments>http://rnc2.com/regulatory-compliance/pcidss/may-we-suggest-some-priority-adjustments-to-your-pci-dss-compliance-program/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 16:34:03 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[Information Risk]]></category>
		<category><![CDATA[PCI DSS Compliance]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=235</guid>
		<description><![CDATA[It isn’t any news that achieving PCI DSS Compliance continues to be onerous for many merchants out there. PCI DSS is after all an all-or-nothing regulation meaning that not passing even one of over 200 requirements could prevent you from getting there. And then, if you do become compliant, there is really no assurance that [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">It isn’t any news that achieving </span><a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank"><strong><span style="color: #000080;">PCI DSS</span></strong></a><span style="color: #000080;"> Compliance continues to be onerous for many merchants out there. PCI DSS is after all an all-or-nothing regulation meaning that not passing even one of over 200 requirements could prevent you from getting there. And then, if you do become compliant, there is really no assurance that you will have 100% security. This is something we have known all along to be true for any regulation and now we have one more statistic from the </span><a href="http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf" target="_blank"><strong><span style="color: #000080;">2010 Verizon Data Breach Investigation Report</span></strong></a><span style="color: #000080;"> to prove it …  21% of organizations facing payment card data breaches were compliant with PCI DSS at the time of the breach.</span></p>
<p><span style="color: #000080;">So, may be it is time to rethink our approach to PCI DSS compliance, in terms of how do we get there by way of addressing controls that carry higher breach risks before the others. That will at least help improve your  organization’s security posture against potential breaches even if you are nowhere close to meeting all PCI DSS requirements.   I think recent breach surveys or reports are a great source to identify such controls  with an objective of prioritizing the remediation initiatives in the right order. Such prioritization should help in achieving a better security posture sooner, as we’ll see below.</span></p>
<p><span style="color: #000080;">I am not the first one to suggest a prioritized approach to achieving PCI DSS compliance. In fact, PCI SSC already has </span><a href="https://www.pcisecuritystandards.org/education/prioritized.shtml" target="_blank"><strong><span style="color: #000080;">guidance on this</span></strong></a><span style="color: #000080;">, though the guidance itself is somewhat dated having been issued back in February 2009. Since then,  the threat environment has probably evolved somewhat and exploitation of certain  vulnerabilities isn’t quite of the same order relative to others. Therefore, I suggest leveraging the data breach findings to make necessary prioritization adjustments.</span></p>
<p><span style="color: #000080;">Here are some findings from three recent reports on which I am basing my recommendations:</span></p>
<table class="MsoTableGrid" style="border-collapse: collapse; margin-left: 0.9pt; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-table-layout-alt: fixed; border: medium none;" border="1" cellspacing="0" cellpadding="0" width="588">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;">
<td style="padding-bottom: 0in; padding-left: 5.4pt; width: 27.9pt; padding-right: 5.4pt; background: #17365d; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-background-themeshade: 191; border: black 1pt solid;" width="37" valign="top">
<p class="MsoNormal" style="text-align: center;"><strong><span style="color: white; mso-themecolor: background1;"># </span></strong></p>
<p><strong> </strong><strong> </strong></td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 80.1pt; padding-right: 5.4pt; background: #17365d; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-background-themeshade: 191; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1;" width="107" valign="top">
<p class="MsoNormal" style="text-align: center;"><strong><span style="color: white; mso-themecolor: background1;">Report </span></strong></p>
<p><strong> </strong><strong> </strong></td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 157.5pt; padding-right: 5.4pt; background: #17365d; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-background-themeshade: 191; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1;" width="210" valign="top">
<p class="MsoNormal" style="text-align: center;"><strong><span style="color: white; mso-themecolor: background1;">Findings </span></strong></p>
<p><strong> </strong><strong> </strong></td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 175.5pt; padding-right: 5.4pt; background: #17365d; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-background-themeshade: 191; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1;" width="234" valign="top">
<p class="MsoNormal" style="text-align: center;"><strong><span style="color: white; mso-themecolor: background1;">Relevant Controls (Our Analysis)</span></strong></p>
<p><strong> </strong><strong> </strong></td>
</tr>
<tr style="mso-yfti-irow: 1;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 27.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="37" valign="top">
<p class="MsoNormal">1</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 80.1pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="107" valign="top">
<p class="MsoNormal">Verizon Data Breach Investigations Report 2010</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 157.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="210" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>61% of the breaches were discovered by a third party</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>86%<span style="mso-spacerun: yes;"> </span>of victims had evidence of the breach in their log files</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 175.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="234" valign="top">
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Technology – Monitoring, correlation, reporting and alerting off the log events</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Process – Regular reviews of logs, log reports or alerts</p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>People – Clear definition and assignment of responsibilities around log reviews and incident response</p>
</td>
</tr>
<tr style="mso-yfti-irow: 2;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 27.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="37" valign="top">
<p class="MsoNormal">2</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 80.1pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="107" valign="top">
<p class="MsoNormal">Verizon Data Breach Investigations Report 2010</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 157.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="210" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>94% of breached records had malware as one of the causes and 96% of breached records involved hacking</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="mso-spacerun: yes;"> </span>51% of malware was installed or injected remotely by the attacker (by obtaining privileged access to the system or other means such as SQL Injection)</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>85% of records breached by malware involved the attacker gaining backdoor access to the system</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>81% of records breached by malware involved data being sent to an external entity or site</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>86% of records breached by hacking involved use of stolen login credentials</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>86% of records breached by hacking involved use of stolen login credentials</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>89% of records breached by hacking involved SQL Injection</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>92% of records breached by hacking used web applications as the attack pathway</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 175.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="234" valign="top">
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Technology – Proper configuration and lockdown of systems, strong access credentials, access controls or assurance, assessment of web applications and remediation for OWASP Top 10 vulnerabilities, deployment of Web Application Firewalls, Logging/Monitoring/Reporting/Alerting of important events on critical systems</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Process – Configuration reviews, OWASP Top 10 vulnerability management, access assurance in the form of ongoing role/privilege management processes and periodic access certifications, regular reviews of logs, log reports or alerts, effective security incident response</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>People – Clear definition and assignment of responsibilities around configuration reviews, access certifications, log reviews and incident response</p>
<p class="MsoListParagraphCxSpLast" style="margin-left: 12.25pt; mso-add-space: auto;">
<p class="MsoNormal">
<p class="MsoNormal">
</td>
</tr>
<tr style="mso-yfti-irow: 3;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 27.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="37" valign="top">
<p class="MsoNormal">3</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 80.1pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="107" valign="top">
<p class="MsoNormal">Verizon Data Breach Investigations Report 2010</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 157.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="210" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>More than 50% of breaches remain undiscovered for months or more</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>61% of the breaches were discovered by 3rd parties, and not the victim organization itself</p>
<p class="MsoListParagraphCxSpMiddle" style="margin-left: 12.25pt; mso-add-space: auto;">
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 175.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="234" valign="top">
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Technology – Monitoring, correlation, reporting and alerting off the log events</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Process – regular reviews of logs, log reports or alerts</p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>People – Clear definition and assignment of responsibilities around log reviews and incident response, User awareness and training</p>
</td>
</tr>
<tr style="mso-yfti-irow: 4;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 27.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="37" valign="top">
<p class="MsoNormal">4</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 80.1pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="107" valign="top">
<p class="MsoNormal">Verizon Data Breach Investigations Report 2010</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 157.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="210" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Few breaches were caused due to exploitation of vulnerabilities for which a patch was available.</p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span> Likelihood of exploitation of an unpatched vulnerability is far less as compared to a vulnerability caused by a configuration issue.</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 175.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="234" valign="top">
<p class="MsoNormal">Lockdown (secure configuration) of systems may receive higher priority over application of vendor patches unless there is a specific reason not to do so</p>
</td>
</tr>
<tr style="mso-yfti-irow: 5;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 27.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="37" valign="top">
<p class="MsoNormal">5</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 80.1pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="107" valign="top">
<p class="MsoNormal">Leaking Vault &#8211; Five years of data breaches – July 2010</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 157.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="210" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Drives/Media and hacking were the top two breach vectors</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Documents and Fraud (Social Engineering) have been increasing in prominence as threat breach vectors recently <span style="mso-spacerun: yes;"> </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Of the breaches that involved hacking, SQL Injection, stolen credentials and malware accounted for most breaches</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 175.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="234" valign="top">
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Technology – Disk/Tape encryption, appropriate system lockdown to prevent use of media such as USB drives , Encryption of unstructured data (documents), Refer to controls in #2 against hacking</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Process – Physical Security, Encryption and Key Management</p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>People – Awareness and Training</p>
</td>
</tr>
<tr style="mso-yfti-irow: 6; mso-yfti-lastrow: yes;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 27.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="37" valign="top">
<p class="MsoNormal">6</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 80.1pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="107" valign="top">
<p class="MsoNormal">Ponemon Institute &#8211; Annual Cost of Cybercrime study – July 2010</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 157.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="210" valign="top">
<p class="MsoListParagraphCxSpFirst" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>The most costly cyber crimes are those caused by web attacks, malicious code and malicious insiders, which account for more than 90 percent of all cyber crime costs per organization on an annual basis.</p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -9pt; margin-left: 12.25pt; mso-add-space: auto; mso-list: l0 level1 lfo1;"><span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt &amp;amp;amp;"> </span></span></span>The average number of days to resolve a cyber attack was 14 days with an average cost to the organization of $17,696 per day. The survey revealed that malicious insider attacks can take up to 42 days or more to resolve.</p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 175.5pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="234" valign="top">
<p class="MsoNormal">Refer to #2 above</p>
</td>
</tr>
</tbody>
</table>
<p><span style="color: #000080;"> </span></p>
<p><span style="color: #000080;">Here then is a summary of the key controls in the above table, relevant PCI DSS requirements and priorities from the </span><a href="https://www.pcisecuritystandards.org/education/prioritized.shtml" target="_blank"><strong><span style="color: #000080;">PCI SSC Guidance</span></strong></a><span style="color: #000080;">.</span></p>
<table class="MsoNormalTable" style="border-collapse: collapse; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt; border: medium none;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;">
<td style="padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #17365d; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-background-themeshade: 191; border: black 1pt solid;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><strong><span style="font-family: &amp;amp;amp; color: white; font-size: 10.5pt; mso-themecolor: background1; mso-fareast-language: en-us;">Key Control (Our Analysis)</span></strong><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;"> </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #17365d; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: text2; mso-background-themeshade: 191; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><strong><span style="font-family: &amp;amp;amp; color: white; font-size: 10.5pt; mso-themecolor: background1; mso-fareast-language: en-us;">Relevant PCI DSS Requirement Numbers (See Notes below)</span></strong><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;"> </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 1;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">Secure Configuration and Lockdown </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">1.1.5 (2), 1.2 (2), 2.1 (2), <span style="color: red;">2.2.3 (3), 2.2.4 (3), </span>2.3 (2) </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 2;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">Web Application Security </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: red; font-size: 10.5pt; mso-fareast-language: en-us;">6.5 (3)</span><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;"> </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 3;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">Strong Access Credentials including periodic changes in credentials (e.g. password) </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: red; font-size: 10.5pt; mso-fareast-language: en-us;">8 (4)</span><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;"> </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 4;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">Access Assurance (Least Privilege access based on users’ business or job roles, timely revocation of access privileges) </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: red; font-size: 10.5pt; mso-fareast-language: en-us;">7 (4), 12.2(6), 12.5.4(6), 12.5.5(6)</span><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;"> </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 5;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">Logging, Monitoring and Reporting </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: red; font-size: 10.5pt; mso-fareast-language: en-us;">10.1(4), 10.2(4), 10.3(4), 10.4(4), 10.5(4), 10.5(6),</span><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;"> 10.7(4), <span style="color: red;">12.2(6), 12.5.2(6), </span></span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 6;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">Encryption (Data at rest, media), Physical security of media </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: red; font-size: 10.5pt; mso-fareast-language: en-us;">3.3(5), 3.4(5), 3.5(5), 9.5(5), 9.6(5), 9.7(5), 9.8(5), 9.9(5)</span><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;"> </span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 7;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">Security Incident Response </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: red; font-size: 10.5pt; mso-fareast-language: en-us;">12.5.3(6), 12.9(6)</span></p>
</td>
</tr>
<tr style="mso-yfti-irow: 8; mso-yfti-lastrow: yes;">
<td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; padding-left: 5.4pt; width: 216.9pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51;" width="289" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;">Security Awareness and Training </span></p>
</td>
<td style="border-bottom: black 1pt solid; border-left: medium none; padding-bottom: 0in; padding-left: 5.4pt; width: 207pt; padding-right: 5.4pt; background: #dbe5f1; border-top: medium none; border-right: black 1pt solid; padding-top: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-background-themecolor: accent1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-background-themetint: 51; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1;" width="276" valign="top">
<p class="MsoNormal" style="margin: 7.5pt 0in; mso-hyphenate: auto;"><span style="font-family: &amp;amp;amp; color: red; font-size: 10.5pt; mso-fareast-language: en-us;">12.3(6), 12.3.10(6), 12.4(6), 12.6(6)</span><span style="font-family: &amp;amp;amp; font-size: 10.5pt; mso-fareast-language: en-us;"> </span></p>
</td>
</tr>
</tbody>
</table>
<p><span style="text-decoration: underline;"><span style="color: #000080;">Note</span></span><span style="color: #000080;">: Numbers in brackets are the priority numbers from the PCI SSC guidance. Numbers in the guidance range from 1 through 6. A lower number indicates a higher priority.</span></p>
<p><span style="color: #000080;">As we can see from the table, there are several requirements which if addressed sooner, will actually improve an organization’s security posture against potential breaches, based on what we know from the recent breach studies.  I would recommend increasing the priority of the requirements in red to at least 3 if not 2. I do realize that organizations may not be able to afford to address too many requirements at a higher priority. If that is the case, you may want to review the current priority 2 and 3 requirements against the key controls in the table above and then decide to push some of them lower down the priority order as applicable.</span></p>
<p><span style="color: #000080;">Hope this is useful! As always, we welcome your thoughts and comments.</span></p>
<p><strong><em>RisknCompliance Services Note</em></strong></p>
<p><em>We at RisknCompliance track about a dozen of such reports every year and maintain a up-to-date database of the current security threats and vulnerabilities at a detailed level. We are able to leverage this knowledge in  providing our clients with  a much-wanted third-party assessment of their risk management or audit methodologies and  programs. After all, security risk assessments and audits form the very foundation of risk management or audit programs, so we believe it is critical that every organization fine-tunes its methodologies and  knowledgebase.</em></p>
<p><em>Please <a href="http://rnc2.com/contact/"><strong>contact us here</strong></a> if you would like to discuss your needs. We will be glad to talk to you with the details and how we could be of assistance to you.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/regulatory-compliance/pcidss/may-we-suggest-some-priority-adjustments-to-your-pci-dss-compliance-program/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Verizon 2010 Data Breach Investigations Report &#8211; Key takeaways for Security Assessors and Auditors</title>
		<link>http://rnc2.com/regulatory-compliance/pcidss/verizon-2010-data-breach-investigations-report-key-takeaways-for-security-assessors-or-auditors/</link>
		<comments>http://rnc2.com/regulatory-compliance/pcidss/verizon-2010-data-breach-investigations-report-key-takeaways-for-security-assessors-or-auditors/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 05:19:14 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[Information Risk]]></category>
		<category><![CDATA[PCI DSS Compliance]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Assessment]]></category>
		<category><![CDATA[Audit]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=192</guid>
		<description><![CDATA[The Verizon 2010 Data Breach Investigations Report (DBIR) released last week has some interesting findings, just as it did last year. What makes it special this year is that Verizon partnered with the United States Secret Service in developing this report. I don’t intend to discuss all the statistics in this blog (will do so [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">The </span><a href="http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf" target="_blank"><strong><span style="color: #000080;">Verizon 2010 Data Breach Investigations Report</span></strong></a><span style="color: #000080;"> (DBIR) released last week has some interesting findings, just as it did last year. What makes it special this year is that Verizon partnered with the United States Secret Service in developing this report. I don’t intend to discuss all the statistics in this blog (will do so in another upcoming blog) but as you will see explained in the report, the Secret Service’s involvement has thrown new light into some of the findings.</span></p>
<p><span style="color: #000080;">My intention here is to highlight the significance of such a report to security and audit practitioners with the objective of improving the quality of their risk assessments or audits and more importantly, help make the right recommendations to management.  From my experience as a security practitioner and an occasional auditor, I can tell that we may not always be using all the available information to help improve the quality of our risk assessments or audits. And, I think reports such as the Verizon DBIR can provide some valuable help from that standpoint.</span></p>
<p><span style="color: #000080;">Let me explain what I mean… Deliverables for any risk assessment or audit typically include a list of findings and for each finding, we provide an explanation of the risk, the risk severity  (High, Medium, Low) and suitable recommendations for risk mitigation or remediation.  The management would then proceed to remediate various gaps in priority based on our risk rankings. Considering that risk is a product of likelihood and impact (I like the </span><a href="http://www.owasp.org/index.php/OWASP_Risk_Rating_Methodology" target="_blank"><strong><span style="color: #000080;">OWASP risk rating methodology</span></strong></a><span style="color: #000080;">, so will use it here), it is important that we get the impact and likelihood right.  Impact is largely a function of the organization’s characteristics including various </span><a href="http://www.owasp.org/index.php/OWASP_Risk_Rating_Methodology#Technical_Impact_Factors" target="_blank"><strong><span style="color: #000080;">technical and business factors seen in the methodology</span></strong></a><span style="color: #000080;">. On the other hand, likelihood is a </span><a href="http://www.owasp.org/index.php/OWASP_Risk_Rating_Methodology#Step_2:_Factors_for_Estimating_Likelihood" target="_blank"><strong><span style="color: #000080;">function of threats and vulnerabilities</span></strong></a><span style="color: #000080;">.  I think the DBIR can be a useful reference in estimating the likelihood.</span></p>
<p><span style="color: #000080;">For example, the DBIR says that external agents were responsible for about 78% of the breaches whereas about 48% were caused by insiders. These numbers can be used to arrive at a better objective estimate  of the likelihood that these threat agents may cause any harm. Similarly, the DBIR also says that  48% of the breaches involved privilege misuse, 40% resulted from hacking  and 38% utilized malware. These numbers can be used for objective estimation of the likelihood that associated vulnerabilities could be exploited. The OWASP methodology has </span><a href="http://www.owasp.org/index.php/OWASP_Risk_Rating_Methodology#Repeatable_Method" target="_blank"><strong><span style="color: #000080;">an illustration for such objective risk estimation</span></strong></a><span style="color: #000080;">.</span></p>
<p><span style="color: #000080;">These are but a couple of examples. The DBIR has a wealth of information that can be useful to auditors and security practitioners alike, both in improving the quality of their work as well as in being able to defend their risk rankings. We all realize that risk rankings almost always have a level of subjectivity in them but I think reports like the DBIR can be leveraged to make them as objective as possible. A very good example is the risk level one might normally assign to a case of unpatched vulnerability versus a configuration issue.  It may not be readily obvious that one might need to be assigned a higher risk level over another until you read the DBIR. The DBIR tells us that the likelihood of exploitation of an unpatched  vulnerability is far less as compared to a vulnerability caused by a configuration issue. If we didn’t leverage the DBIR (and assuming both issues had equal impacts), we might assign equal risk levels to both the findings or worse, we might assign the unpatched vulnerability a higher risk level.</span></p>
<p><span style="color: #000080;">Over the next couple of weeks, I plan to be blogging with a detailed commentary on some of the findings in the report including a special post on how the report can be leveraged to enhance the effectiveness of PCI DSS programs.</span></p>
<p><span style="color: #000080;">Hope this is useful! As always, we welcome your thoughts and comments. </span></p>
<p><span style="color: #993300;"><strong><span style="text-decoration: underline;"><span style="color: #003300;"><em><span style="color: #003300;">RisknCompliance Services Note</span></em></span></span></strong></span></p>
<p><span style="color: #000080;"><em><span style="color: #003300;">We at RisknCompliance track about a dozen of such reports every year and maintain a up-to-date database of the current security threats and vulnerabilities at a detailed level. We are able to leverage this knowledge in  providing our clients with  a much-wanted third-party assessment of their risk management or audit methodologies and  programs. After all, security risk assessments and audits form the very foundation of risk management or audit programs, so we believe it is critical that every organization fine-tunes its methodologies and  knowledgebase. </span></em></span></p>
<p><span style="color: #000080;"><em><span style="color: #003300;">Please </span><a href="http://rnc2.com/contact/" target="_blank"><span style="color: #003300;"><strong>contact us here</strong></span></a><span style="color: #003300;"> if you would like to discuss your needs. We will be glad to talk to you with the details and how we might be of assistance to you.</span></em></span></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/regulatory-compliance/pcidss/verizon-2010-data-breach-investigations-report-key-takeaways-for-security-assessors-or-auditors/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Proposed updates to HIPAA Security and Privacy Rules &#8211; What is new?</title>
		<link>http://rnc2.com/regulatory-compliance/hipaahhitech/proposed-updates-to-hipaa-security-and-privacy-rules-what-is-new/</link>
		<comments>http://rnc2.com/regulatory-compliance/hipaahhitech/proposed-updates-to-hipaa-security-and-privacy-rules-what-is-new/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 12:34:07 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[HIPAA/HITECH Compliance]]></category>
		<category><![CDATA[Information Risk]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=188</guid>
		<description><![CDATA[It was good to see the Office of Civil Rights (OCR) publish the long awaited proposed updates to HIPAA Security and Privacy Rules Thursday last week. Note that OCR is the division of the Department of Health and Human Services (HHS) responsible for enforcing both the HIPAA Security and Privacy Rules. I want to emphasize [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">It was good to see the Office of Civil Rights (OCR) publish </span><span style="color: #000080;">the long awaited proposed updates to  HIPAA Security and Privacy Rules</span><span style="color: #000080;"> Thursday last week.  Note that OCR is the division of the Department of Health and Human Services (HHS) responsible for enforcing both the HIPAA Security and Privacy Rules.</span></p>
<p><span style="color: #000080;">I want to emphasize that these are proposed updates, also called Notice of Proposed Rulemaking (NPRM) in Federal Government parlance. There is a 60 days period for the public to submit comments on the NPRM after<strong> </strong></span><a href="http://www.regulations.gov/search/Regs/home.html#documentDetail?R=0900006480b195a0" target="_blank"><span style="color: #000080;"><strong>it was published yesterday in the Federal Register</strong></span></a><span style="color: #000080;">. The comments are due by 09/13/2010.</span></p>
<p><span style="color: #000080;">The NPRM includes updates to the following  HIPAA rules or areas:</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">1.	Privacy Rule</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">2.	Security Rule</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">3.	Rules pertaining to Compliance and Investigations</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">4.	Imposition of Civil Money Penalties, and</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">5.	Procedures for Hearings (Enforcement Rule)</span></p>
<p><span style="color: #000080;">As noted in the NPRM, these updates are being made to “<em>implement recent statutory amendments under the Health Information Technology for Economic and Clinical Health Act (HITECH) and to strengthen the privacy and security protection of health information, and to improve the workability and effectiveness of these HIPAA Rules</em>”.</span></p>
<p><span style="color: #000080;">For those who don’t have much history on HIPAA, the current Privacy Rule was issued on December 28, 2000, and amended on August 14, 2002 while the Security Rule was issued on February 20, 2003. So, the proposed updates are long overdue in any case given that Information Security and Privacy risk landscapes have changed substantially since these rules were issued.</span></p>
<p><span style="color: #000080;">I’ll focus on updates to just the Security and Privacy Rules in this post. I’ll have two more posts over the next week or so, one with an in-depth coverage on what to expect from proposed updates to the Security Rule and the other one with a similar coverage of the Privacy Rule.</span></p>
<p><span style="color: #000080;">So, here are notable proposed updates:</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">1.	Replace “individually identifiable health information” with “protected health information” to better reflect the scope of the Privacy and Security Rules.</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">2.	Definition of “Business Associate”(BA) being expanded to include the following new constituents:</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">a. Patient Safety Organizations (PSO)</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">b. Health Information Organizations (HIO)</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">c. E-Prescribing Gateways</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">d. Other Persons that facilitate PHI data transmissions for Covered Entities or other BAs and require routine access to such PHI</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">e. Vendors of Personal Health Records (like Google Health and Microsoft Healthvault)</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">f. Subcontractors of a Covered Entity (CE) – i.e., those persons that perform functions for or provide services to a BA, other than in the capacity as a member of the business associate’s workforce.</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">3.	As provided in section 13401 of the HITECH Act, the Security Rule’s administrative, physical, and technical safeguards requirements in §§ 164.308, 164.310, and 164.312, as well as its policies and procedures and documentation requirements in § 164.316, shall apply to BAs  in the same manner as these requirements apply to CEs.</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">4.	BAs shall be civilly and criminally liable for penalties for violations of the provisions in #3 above.</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">5.	Requirements of BA contracts (or other arrangements) between CEs and BAs will now apply to contracts (or other arrangements) between BAs and their subcontractors. It is important to note here that the burden of obtaining assurances (through contracts) from subcontractors regarding safety of PHI falls on the BA rather than the CE.</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">6.	A subcontractor will be required to notify any breaches of unsecured PHI to the BA who in turn would be required to notify the CE. The CE then notifies the affected individuals, HHS, and, if applicable, the media, of the breach, unless it has delegated such responsibilities to a BA.</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">7.	BAs, like CEs, may not use or disclose PHI except as permitted or required by the Privacy Rule or their  contracts with CEs or  as required by law.  If a CE and its BA have failed to enter into a BA contract or other arrangement, then the BA may use or disclose PHI only as necessary to perform its obligations for the CE.</span></p>
<p style="padding-left: 30px;"><span style="color: #000080;">8.	Other proposed changes to the Privacy Rule include:</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">a. Certain material changes to the Notice of Privacy Practices (NPP) issued by a CE or by a BA, if delegated so by a CE through contract</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">b. A number of changes to the definition of “marketing” in the Privacy Rule at § 164.501</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">c. Provisions for individuals to request restriction of disclosure of certain PHI to a health plan under certain circumstances</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">d. New restrictions on sale of PHI by CEs and BAs</span></p>
<p style="padding-left: 60px;"><span style="color: #000080;">e. Strengthen the right of “access” more uniformly to cover all protected health information maintained in one or more designated record sets electronically, regardless of whether the designated record set is an electronic health record</span></p>
<p><span style="color: #000080;">OCR has also proposed that the compliance deadline for all <span style="text-decoration: underline;">new and updated</span> requirements in the Security and Privacy rules will be 180 days after the final update which I believe can be expected in Q4 this year.  OCR is also proposing an additional one-year transition period to modify certain BA agreements. The NPRM further qualifies the one-year transition period as  “<em>The additional transition period would be available to a covered entity or business associate if, prior to the publication date of the modified Rules, the covered entity or business associate had an existing contract or other written arrangement with a business associate or subcontractor, respectively, that complied with the prior provisions of the HIPAA Rules and such contract or arrangement was not renewed or modified between the effective date and the compliance date of the modifications to the Rules.</em>”</span></p>
<p><span style="color: #000080;">Assuming that these timelines don’t change in the final rule,  all CEs and BAs need to plan for full compliance with the final rules by Q2 of 2011 and for revision of existing BA agreements no later than Q2 of 2012. I want to emphasize here that the current BAs<span style="color: #333399;"> <span style="color: #000080;">(</span></span></span><span style="color: #000080;">as defined in </span><a href="http://ecfr.gpoaccess.gov/cgi/t/text/text-idx?c=ecfr&amp;sid=399ab8cb7578e6343750a45564345abd&amp;rgn=div8&amp;view=text&amp;node=45:1.0.1.3.68.1.27.3&amp;idno=45" target="_blank"><span style="color: #333399;"><strong><span style="color: #000080;">section § 160.103  of 45 CFR 160</span></strong></span></a><span style="color: #000080;">)</span><span style="color: #000080;"> </span><span style="color: #000080;">must already be in compliance with the current  Privacy Rule and certain provisions of the current Security Rule beginning February 18, 2010 as required by the HITECH Act. The new deadlines will apply only to the new BAs (see 2. a-f above)  and for all CEs and current BAs to comply with any new or updated requirements in the final rules.</span></p>
<p><span style="color: #000080;">So, what are the highlights in this NPRM? We have known all along (from the HITECH Act) that the BAs need to comply with the Privacy Rule and certain provisions of the Security Rule. The real highlight to me in this NPRM is the expansion of the definition of a BA.  Pretty much everyone (including all subcontractors  and others) that has the custody of PHI will now have to comply with both the Security and Privacy Rules. Another highlight to me is the expected compliance deadlines as discussed in the previous paragraph.</span></p>
<p><span style="color: #000080;">As I mentioned earlier in this post, I’ll provide an in-depth coverage of the updates to Security and Privacy Rules in two of my upcoming posts. </span></p>
<p><span style="color: #000080;">As always, we welcome your thoughts and comments. We would also obviously like to hear if you need any consulting support in order to prepare for the anticipated HIPAA changes.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/regulatory-compliance/hipaahhitech/proposed-updates-to-hipaa-security-and-privacy-rules-what-is-new/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Logging for Effective SIEM and PCI DSS Compliance &#8230;. UNIX, Network Devices and Databases</title>
		<link>http://rnc2.com/regulatory-compliance/pcidss/logging-unix-network-databases-pci-dss/</link>
		<comments>http://rnc2.com/regulatory-compliance/pcidss/logging-unix-network-databases-pci-dss/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 22:38:23 +0000</pubDate>
		<dc:creator>Kamal Govindaswamy</dc:creator>
				<category><![CDATA[HIPAA/HITECH Compliance]]></category>
		<category><![CDATA[PCI DSS Compliance]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://rnc2.com/?p=167</guid>
		<description><![CDATA[In one of my previous blogs, I covered the importance of logging the “right” events for an effective Log Management or Security Information and Event Management (SIEM) deployment … see here or here for a discussion on the two technologies. The blog also provided a suggested listing of the Windows or Active Directory events that [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000080;">In </span><a href="http://rnc2.com/regulatory-compliance/pcidss/logging-for-pci-dss-compliance/" target="_blank"><span style="color: #000080;"><strong>one of my previous blogs</strong></span></a><span style="color: #000080;">, I covered the importance of logging the “right” events for an effective Log Management or Security Information and Event Management (SIEM) deployment … see </span><a href="http://securosis.com/blog/understanding-and-selecting-siem-log-management-introduction/" target="_blank"><span style="color: #000080;"><strong>here</strong></span></a><span style="color: #000080;"> or </span><a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html" target="_blank"><span style="color: #000080;"><strong>here</strong></span></a><span style="color: #000080;"> for a discussion on the two technologies. The blog also provided a suggested listing of the Windows or Active Directory events that you might want to log from a PCI DSS Compliance standpoint.</span></p>
<p><span style="color: #000080;">Clearly, no amount of investment in your Log Management or SIEM solution is going to do much good, unless you have been able to generate all the right logs to begin with … see a related discussion with the recognized PCI Expert and Author, Dr. Anton Chuvakin </span><a href="http://blog.elementps.com/element_payment_solutions/2010/03/pci-compliance-anton-chuvakin.html" target="_blank"><span style="color: #000080;"><strong>here</strong></span></a><span style="color: #000080;">.</span></p>
<p><span style="color: #000080;">I would like to extend my suggested list in the previous post to cover a few other systems here,  specifically UNIX/LINUX, Network Devices and Databases. Note that this list is only a starting point so you can work with the respective System Specialists or Administrators in your organization to generate these events.</span></p>
<p><span style="color: #000080;"><br />
</span></p>
<p><span style="color: #000080;"> </span></p>
<p><span style="color: #000080;"> </span></p>
<p><a href="http://www.docstoc.com/docs/41657408/UNIX/LINUX Logging for Effective Security Monitoring and Compliance with PCI DSS"><span style="font-size: medium;"><strong><span style="color: #0000a0; font-size: medium;">UNIX/LINUX Logging for Effective SIEM and PCI DSS Compliance</span></strong></span></a><span style="font-size: medium;"><strong><span style="color: #669966; font-size: medium;"> </span></strong></span></p>
<p><object id="_ds_41657408" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="570" height="550" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="name" value="_ds_41657408" /><param name="data" value="http://viewer.docstoc.com/" /><param name="FlashVars" value="doc_id=41657408&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " /><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="src" value="http://viewer.docstoc.com/" /><param name="flashvars" value="doc_id=41657408&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " /><param name="allowfullscreen" value="true" /><embed id="_ds_41657408" type="application/x-shockwave-flash" width="570" height="550" src="http://viewer.docstoc.com/" allowfullscreen="true" allowscriptaccess="always" flashvars="doc_id=41657408&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " data="http://viewer.docstoc.com/" name="_ds_41657408"></embed></object><br />
<span> </span></p>
<p><span><br />
</span></p>
<p><span style="font-size: xx-small;"> </span></p>
<p><span style="font-size: xx-small;"> </span></p>
<p><span style="font-size: xx-small;"><a href="http://www.docstoc.com/docs/41664637/Logging of Network Devices for SIEM and PCI DSS"><span style="font-size: medium;"><strong><span style="color: #004080; font-size: medium;">Logging of Network Devices for Effective SIEM and PCI DSS Compliance</span></strong></span></a> </span></p>
<p><object id="_ds_41664637" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="570" height="550" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="name" value="_ds_41664637" /><param name="data" value="http://viewer.docstoc.com/" /><param name="FlashVars" value="doc_id=41664637&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " /><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="src" value="http://viewer.docstoc.com/" /><param name="flashvars" value="doc_id=41664637&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " /><param name="allowfullscreen" value="true" /><embed id="_ds_41664637" type="application/x-shockwave-flash" width="570" height="550" src="http://viewer.docstoc.com/" allowfullscreen="true" allowscriptaccess="always" flashvars="doc_id=41664637&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " data="http://viewer.docstoc.com/" name="_ds_41664637"></embed></object></p>
<p><span style="font-size: xx-small;">- </span></p>
<p><span style="font-size: xx-small;"><a href="http://www.docstoc.com/docs/41666383/Database Logging for Effective SIEM and PCI DSS Compliance"><span style="font-size: medium;"><strong><span style="color: #004080; font-size: medium;">Database Logging for Effective SIEM and PCI DSS Compliance</span></strong></span></a></span></p>
<p><object id="_ds_41666383" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="570" height="550" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="name" value="_ds_41666383" /><param name="data" value="http://viewer.docstoc.com/" /><param name="FlashVars" value="doc_id=41666383&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " /><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="src" value="http://viewer.docstoc.com/" /><param name="flashvars" value="doc_id=41666383&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " /><param name="allowfullscreen" value="true" /><embed id="_ds_41666383" type="application/x-shockwave-flash" width="570" height="550" src="http://viewer.docstoc.com/" allowfullscreen="true" allowscriptaccess="always" flashvars="doc_id=41666383&amp;mem_id=3178170&amp;doc_type=pdf&amp;fullscreen=0&amp;showrelated=0&amp;showotherdocs=0&amp;showstats=0 " data="http://viewer.docstoc.com/" name="_ds_41666383"></embed></object><br />
<span><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://rnc2.com/regulatory-compliance/pcidss/logging-unix-network-databases-pci-dss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

