<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-19586308</id><updated>2011-04-21T18:49:46.423-07:00</updated><category term='security'/><title type='text'>eCrime Watch</title><subtitle type='html'>Electronic crime threatens every corporation.  "eCrime" (a.k.a security breach) can undermine shareholder value and destroy the tenure of senior executives.  A company's biggest liability is to be found negligent or out of compliance following a security breach involving data loss.  This blog addresses risk management in regard to electronic crime, with a focus on governance, integration (or convergence) of physical security and data security and that which pertains.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ecrimewatch.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>30</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-19586308.post-539446756186028406</id><published>2008-04-19T13:55:00.000-07:00</published><updated>2008-04-19T13:56:48.315-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Security is a Process...Not a State (Revisited)</title><content type='html'>It is second nature to security professionals that security is a process and not a state.  However, many of us overlook the implications of this fact in regard to data security. Let's consider the implications now.The breach of sensitive information is different than a breach of security in regard to physical items. For example, when a laptop is stolen it is no longer available for use. In contrast, when data is stolen it is often the case that an instance (a copy) of that data is in the possession of an unauthorized person. However, the original data is probably still available to the owner. There are many implications resulting from this difference. Security professionals discuss this in terms of operational risk versus organizational risk. The actual loss of data derives not from the theft itself, but from the litigation and bad press the results. The risk applies to brand and shareholder value. It is for this reason that the process of security trumps the actual state of security at any one time. A formal program of security, even if it is a low-budget, understated program, is imperative for most companies today. If the loss results from bad press and litigation then the defense is the ability to demonstrate a reasonable standard of care was being provided. This is best demonstrated by producing a written plan, evidence of effective management with third party oversight and evidence of the progress being made on the plan. Formalizing the security process does not need to be burdensome or costly, and as a risk mitigation measure, it is almost instantaneous in its effect and unassailable in its cost effectiveness.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-539446756186028406?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/539446756186028406'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/539446756186028406'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2008/04/security-is-processnot-state-revisited.html' title='Security is a Process...Not a State (Revisited)'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-5833486732153689005</id><published>2007-10-23T22:30:00.001-07:00</published><updated>2007-10-23T22:30:32.951-07:00</updated><title type='text'>The Virtual Perimeter in the Age of Convergence</title><content type='html'>Security is essentially the ancient art of protecting the perimeter. Sometimes ancient, and even recent-day, technologies cannot adequately protect the actual exterior perimeter. For such instances, we recommend establishing a virtual perimeter inside the exterior one. This virtual perimeter is created by delineating a line of pixels in the image of one or more digital cameras. This line of pixels can form the interior, virtual perimeter. The cameras feed the video signal to a server performing analysis of the video images. The server is looking for specific objects in the images that have certain attributes associated with humans, such as a neck and shoulders. When such objects appear near the virtual perimeter and approach that perimeter, the server issues an alert to the security force. A guard carries a handheld device which displays the object and tracks its movement as the guard approaches the intruder.&lt;br /&gt;&lt;br /&gt;This solution requires technical sophistication to design and deploy, but it is a perfect example of a security solution that is available as a result of the convergence of certain technologies.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-5833486732153689005?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/5833486732153689005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/5833486732153689005'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2007/10/virtual-perimeter-in-age-of-convergence.html' title='The Virtual Perimeter in the Age of Convergence'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-5655919807064100746</id><published>2007-06-17T20:43:00.000-07:00</published><updated>2007-06-17T20:55:43.682-07:00</updated><title type='text'>Beyond Convergence</title><content type='html'>I get dozens of emails each week on "convergence."  I gave the keynote address at Security Summit 2007 in Los Angeles and the title of the Summit was:  Convergence:  The Next Horizon.  It is safe to say that convergence is the number one topic in the security field.  The industry is experiencing a major transformation.  However, the focus on convergence is misplaced.  I believe it derives from the perspective that as security devices become network peripherals, security professionals are focused on the point of convergence.  The problem with this focus, is that it results in under achieving.  Such a focus leads to security devices operating on Ethernet networks and doing providing the same functions as those same devices provided previously, when they were standalone electronic systems.  I encourage all security systems manufacturers and integrators to look beyond convergence.  This longer-range focus changes the objective from gain equivalent functionality to engineering the network, which means optimizing it, to protect people, facilities, data and prevent fraud.  Looking beyond convergence helps expand the context to achieve a higher level of protection by using the benefits that become available through convergence.&lt;br /&gt;&lt;br /&gt;Please let me know your thoughts on this topic.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-5655919807064100746?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/5655919807064100746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/5655919807064100746'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2007/06/beyond-convergence.html' title='Beyond Convergence'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-2932144874228273253</id><published>2007-03-03T16:20:00.000-08:00</published><updated>2007-03-03T16:40:28.413-08:00</updated><title type='text'>Industry Report Points to Ollivier Corporation</title><content type='html'>&lt;p&gt;Ray Bernard is an industry analyst who I have known for about four years.  When I was new to the security industry, he was one of the first security consultants whose eyes lit up when he and I talked about the integration of physical and data security.  He has gone on to create an incisive new report on the industry. &lt;br /&gt;&lt;/p&gt;&lt;p&gt;He talks about such projects as &lt;strong style="font-weight: normal;"&gt;&lt;/strong&gt;the national retailer (over 300,000 employees) &lt;strong style="font-weight: normal;"&gt;deploying 150,000 IP cameras&lt;/strong&gt; globally, as &lt;strong style="font-weight: normal;"&gt;an incremental addition&lt;/strong&gt; to their global deployment of &lt;strong style="font-weight: normal;"&gt;IP Telephony. &lt;/strong&gt;IP Telephony (VoIP) replaces analog phones and connect directly to a network, getting both power and communication connectivity over Ethernet-based networks.&lt;br /&gt;&lt;/p&gt;Very few discussions of convergence in the security industry use "installation" as an example.  Ray does in his report.  He talks about the installer &lt;strong style="font-weight: normal;"&gt;preparing the IP-based cameras in the same manner as IP-based phones.  &lt;/strong&gt;Both are put in similar boxes, prior to distributing to regional offices, with the same &lt;strong style="font-weight: normal;"&gt;information barcodes on the boxes&lt;/strong&gt; and with network cable location numbers. A swipe of the computerized barcode scanner &lt;strong style="font-weight: normal;"&gt;displays exactly where a phone or camera is to go&lt;/strong&gt; along with other installation information.  This enables an integrator to&lt;strong style="font-weight: normal;"&gt; reduce the typical per-camera installation time from 3 hours to 30 minutes&lt;/strong&gt;. This is a classic IT application.  &lt;p&gt;Ray then points out that Ollivier Corporation is using common IT installation strategies for its security deployments.  He reports that customers want the benefit of IT expertise from their security integrator and that Ollivier Corporation is way out in front of other physical security integrators.  &lt;strong&gt;&lt;/strong&gt;&lt;strong&gt;&lt;/strong&gt; I encourage you to learn more about &lt;a href="http://http://go-rbcs.com/report_security_industry.htm"&gt;Mr. Bernard's&lt;/a&gt; industry report. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-2932144874228273253?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/2932144874228273253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/2932144874228273253'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2007/03/industry-report-points-to-ollivier.html' title='Industry Report Points to Ollivier Corporation'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-117039575152265681</id><published>2007-02-01T21:46:00.000-08:00</published><updated>2007-06-17T20:42:07.061-07:00</updated><title type='text'>Guards, Dogs and Technology</title><content type='html'>I am still surprised how the discussion of balancing a guard force and technology-based security systems is seldom discussed.  It seems as though the discussions of how to deploy each of these is done in isolation of the other.  Here are some of my thoughts.   Now that security devices, such as cameras and access control readers are peripherals on the network, they are much more intelligent than just a couple of years ago.  They are especially intelligent if the network is engineered to take advantage of communication between the devices and with the data available on the network.  It is this communication that enables Eye on Cash, GPS Logon, Virtual Perimeters, Virtual Mantrap, CRM Secure and other solutions developed by Ollivier Corporation to be available at low cost in today's market.&lt;br /&gt;&lt;br /&gt;As intelligent as these solutions are, they still require the judgment provided by a competent guard force.  These solutions sort through hundreds of events to create alerts and alarms that are rendered important or meaningless by the guard force.  The guard force is the comprised of first responders.  What this means is that the guard force's value and contribution is significantly increased by relegating monitoring and surveillance to devices.  I have been told by guard service organizations that they make more money deploying intelligent guards to monitor and assess the output of computer-based security systems than they do selling low-paid guards.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-117039575152265681?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/117039575152265681'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/117039575152265681'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2007/02/guards-dogs-and-technology.html' title='Guards, Dogs and Technology'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-116742581787839078</id><published>2006-12-29T12:48:00.000-08:00</published><updated>2007-02-01T21:46:22.586-08:00</updated><title type='text'>Meshing Surveillance</title><content type='html'>I am working with residential building owners in a very high crime area of Los Angeles.  We intend to cover the entire 5 square mile area with IP-based surveillance cameras.  The trick is that each of the buildings in this area is owned by individuals, acting in a loose confederation as property owners.  They require high quality cameras because the ambient lighting will vary dramatically and a high level of visual acuity will assist in making proper identifications.&lt;br /&gt;&lt;br /&gt;While the cameras must be high quality the infrastructure must be low cost, yet tie each camera into the network.&lt;br /&gt;&lt;br /&gt;New mesh network technology dramatically reduces the cost and planning required to improve infrastructure and therefore creates a platform for higher functioning cameras.  This configuration is working well in a few cities and we hope to apply it to our situation in Los Angeles.  If you have any comments, please contact me at joelrakow@olliviercorp.com.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-116742581787839078?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/116742581787839078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/116742581787839078'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/12/meshing-surveillance.html' title='Meshing Surveillance'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-116369422684000389</id><published>2006-11-16T08:01:00.000-08:00</published><updated>2006-12-29T12:48:09.460-08:00</updated><title type='text'>Security is a Process...Not a State</title><content type='html'>It is second nature to most of us that security is a process and not a state.  However, many of us overlook the implications of this fact in regard to data security.  Let's consider the implications now.&lt;br /&gt;&lt;br /&gt;The breach of sensitive information is different than a breach of security in regard to physical items and is discussed more than once in previous postings on this blog.  The actual loss derives not from the breach, but from the litigation and bad press the results.  The risk applies to brand and shareholder value.  It is for this reason that the process of security must be formalized.  If the loss results from bad press and litigation then the defense is the ability to demonstrate the a reasonable standard of care was being provided.  This is best demonstrated by producing a written plan, evidence of effective management with third party oversight and evidence of the progress being made on the plan.&lt;br /&gt;&lt;br /&gt;Formalizing the security process does not need to be burdensome or costly, and as a risk mitigation measure, it is almost instantaneous in its effect and unassailable in its cost effectiveness.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-116369422684000389?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/116369422684000389'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/116369422684000389'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/11/security-is-processnot-state.html' title='Security is a Process...Not a State'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-116369277321935151</id><published>2006-11-16T07:58:00.000-08:00</published><updated>2006-11-16T07:59:48.703-08:00</updated><title type='text'>Access Control Moving to IT?</title><content type='html'>&lt;p class="MsoNormal"&gt;Two years ago, physical security appeared to be the sole domain of the traditional security organization.  Maybe it is me, but it seems that in small and large organizations alike, I am seeing the IT organization as the prime mover in access control... and often surveillance.  In the just the last week, I have visited a hosting company for 40,000 realtors, the company responsible for 80% of all transmissions of digital cinema films and one of the oldest large residential communities in &lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;Los Angeles&lt;/st1:City&gt;&lt;/st1:place&gt;.  &lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;In each case, the Technology Director, the Network Administrator or Facilities Technician (in the IT department) has been the primary point of contact.  Two of these companies are part of very large organizations that have traditional security, yet it is as though they do not exist.  What does this mean?  &lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;It seems to be the beginning of a trend.  It seems to me that while the physical security professionals get comfortable with the concept of convergence, the IT professionals are filling the void of indecision.  In my opinion, all that has to happen for physical security to re-establish its rightful place is to understand that IT wants to be the custodian of the access control system and they want security to be the owner of the data.  This can be an easy arrangement to negotiate and one that serves both professional communities.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-116369277321935151?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/116369277321935151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/116369277321935151'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/11/access-control-moving-to-it.html' title='Access Control Moving to IT?'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-115928388119743015</id><published>2006-09-26T08:15:00.000-07:00</published><updated>2006-09-26T08:52:24.400-07:00</updated><title type='text'>When Cost of Smartcards is Too High</title><content type='html'>Very few companies will want to bear the high cost of re-badging their entire workforce.   And, why should they?  Integrating physical and data security is the desired goal.  Smartcards represent a technology approach to achieving that goal.  Integration can also be achieved through directory services (e.g. Active directory, LDAP) without having to re-badge.  Here is how I advise my clients when they are confronted with budget constraints:  i) Identify the assets that represent the greatest risk (e.g. top security government work); ii)  Provide smartcards to the people who need to access those assets; iii) Protect all other assets using directory services.  This is a practical approach to achieve convergence between physical and data security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-115928388119743015?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/115928388119743015'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/115928388119743015'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/09/when-cost-of-smartcards-is-too-high.html' title='When Cost of Smartcards is Too High'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-115925094894657391</id><published>2006-09-25T23:03:00.000-07:00</published><updated>2006-09-25T23:11:16.890-07:00</updated><title type='text'>Three Hundred Data Breaches</title><content type='html'>We hear a lot about data breaches.  It seems as though one is announced nearly every week.  Well, it turns out that between February 2005 and July 2006 more than 300 data breaches were reported.  That is almost 20 a week.   Click on the link to see a listing of these data breaches:&lt;br /&gt;&lt;a href="http://http://www.privacyrights.org/ar/ChronDataBreaches.htm"&gt;http://www.privacyrights.org/ar/ChronDataBreaches.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It is useful to remember that we hear very little about the outcomes of these breaches.  The lawsuits and penalties rarely appear in the press, yet the general counsel or representing attorneys know that the cost of the breach will occur in the cost of litigation, the penalties and shareholder value.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-115925094894657391?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/115925094894657391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/115925094894657391'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/09/three-hundred-data-breaches.html' title='Three Hundred Data Breaches'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-115181971016752833</id><published>2006-07-01T22:41:00.000-07:00</published><updated>2006-11-27T07:49:49.563-08:00</updated><title type='text'>Value Proposition for Covergance - Free ROI Tool</title><content type='html'>&lt;p class="MsoNormal"&gt;Using smartcards is one way to integrate physical and data security. Using directory services (e.g. Active Directory, LDAP) is another. In either case, many security directors have discussed with me how this convergence might be financially justified during this budgeting season. This is becoming such a widespread concern that I have initiated the development of a sophisticated eCrime ROI Tool that links several worksheets into a consolidated value proposition. This is one of the advantages of belonging to a company with over 500 CFOs.&lt;br /&gt;&lt;br /&gt;So far, it seems quite easy to justify a smartcard initiative if the company also sells security products. When this is the case, it is clear that aligning the customer-facing product strategy with security operations will both enhance revenue and reduce risks. This helps the numbers favor integrating security, even with the more expensive smartcards. When this situation is not the case, then it helps to explore applications, in addition to access control, that can be added to the smartcards. Such applications might be for travel expenses, credit union, cafeteria access, uniforms and equipment accounts and so on.&lt;br /&gt;&lt;br /&gt;We have found that expenses related to lawsuits can be a good source of cost justification, especially when we look at how they prevent lawsuits, decrease the potential for awards going to the other party and increase the potential for winning awards. In a related manner, consider the costs related to investigations. A major value in convergence is its audit ability: You should be able to create very nice support when you look at the time and cost of tracking down events that occur on physical space and on the network. These systems are usually disparate, record events with clocks on slightly different time and have user IDs that are often different. They are a quagmire of line items that take a lot of time to sort through.&lt;br /&gt;&lt;br /&gt;The ROI Tool is easy to use and available upon request. All I ask is that after you use it, you provide comments on how it worked and how you would like to see it improved. I am glad to share this ROI Tool. Simply send me an email (joelrakow@olliviercorp.com) and I will send it you.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-115181971016752833?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/115181971016752833'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/115181971016752833'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/07/value-proposition-for-covergance-free.html' title='Value Proposition for Covergance - Free ROI Tool'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-114816412966566768</id><published>2006-05-20T15:17:00.000-07:00</published><updated>2006-05-20T15:28:52.266-07:00</updated><title type='text'>Convergence:  The Whole Story</title><content type='html'>I recently attended a security conference where convergence was a major topic.  To my surprise and disappointment, convergence sometimes means using the IT infrastructure to run security applications such as access control and surveillance.  What a small view of an important topic!&lt;br /&gt;&lt;br /&gt;This view of convergence grounded in the lowest level of operational security:  It is satisfied with incremental change that may or may not lead to a direct path of increasing the security of critical assets.  This view operates as though automating processes is an end in itself.  It runs headlong into the age old IT conundrum of automating a broken process...thereby making things worse.&lt;br /&gt;&lt;br /&gt;We all agree, I am sure, that the processes between physical security and data security are so broken that, for the most part, they do not even exist.  I encourage all participants in the discussion of convergence between physical and data security to make sure that the processes around security are fixed before or at the same time as the security systems are implemented on the IT infrastructure.  That way, you can avoid making the same mistake our IT predecessors made in the early 60's and 70's.  Let's learn from our mistakes so that our effort increases the level of protection.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-114816412966566768?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114816412966566768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114816412966566768'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/05/convergence-whole-story.html' title='Convergence:  The Whole Story'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-114507973345687902</id><published>2006-04-14T22:28:00.000-07:00</published><updated>2006-04-14T22:45:59.306-07:00</updated><title type='text'>Security Activities and Operational Risk</title><content type='html'>I see a lot of IT security organizations engaging in wide range of security "activities".   I use this term to distinguish these companies from the very rare "program" of IT security.  IT security professionals are often guilty of identifying a risk and then finding a tool that addresses that risk.  They fail to start with the assets that need protection and the identification of each asset's vulnerabilities.&lt;br /&gt;&lt;br /&gt;IT professionals can be excused in doing this because security is really a new discipline for IT.  Ten years ago, it was difficult to find an IT security professional.  Although they are much more plentiful now, they often lack a solid foundation in security processes.  Without the initial groundwork of an asset/risk assessment, IT security activities are highly random and seldom contextualized or programmatic.  This lack of foundational security processes leads IT security efforts into the corporate black hole of "operational security".&lt;br /&gt;&lt;br /&gt;Please see my post on February 22 about the distinction between operational risk and organizational risk.  Security data is different from security computer hardware or other physical security.  The operational risk associated with data is very minor while the organizational risk is quite high.  This is exactly the inverse of most physical security issues.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-114507973345687902?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114507973345687902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114507973345687902'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/04/security-activities-and-operational.html' title='Security Activities and Operational Risk'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-114365902323173187</id><published>2006-03-29T10:52:00.000-08:00</published><updated>2006-03-29T11:03:46.696-08:00</updated><title type='text'>Weeding Out the Unprepared.</title><content type='html'>Ongoing process improvement is an often overlooked and important element of every security program.  It is not enough to identify a vulnerability and implement remediation, if you do not also ensure that the asset and risk assessment is all reviewed again on a regular schedule.   This is often considered the mark of a true security program...rather a collection of security activities.  If you work in a regulated industry or submit to other types of audits, ongoing process improvement is almost always one of the "weeder" items on the checklist.  Remember college, where there was always that one course that weeded out the less talented students.  The same applies to ongoing process improvement, the audit checklist and security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-114365902323173187?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114365902323173187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114365902323173187'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/03/weeding-out-unprepared.html' title='Weeding Out the Unprepared.'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-114162139125152216</id><published>2006-03-05T20:52:00.000-08:00</published><updated>2006-04-23T20:35:03.410-07:00</updated><title type='text'>Why Convergence?</title><content type='html'>&lt;p class="MsoNormal"&gt;Physical security and data security organizations typically work independently of each other.  You know this to be true since you see at every company you have ever worked at, unless it is &lt;st1:stockticker&gt;IBM&lt;/st1:stockticker&gt;, Microsoft and just a handful of others.  Well, let's take a look at some obvious security events that never get detected in the typical (unconverged) environment:&lt;br /&gt;1.  Bob does not badge in to work today, but someone accesses data and applications normally used by Bob.  This is probably not a security event in your company.&lt;br /&gt;2.  Bob gets up from his computer workstation, leaves the building to go home for the night. He even badges out.  Bob’s computer continues to run just as though he went down the hall to use the restroom.  Would this be true at your company?&lt;br /&gt;3.  Bob works in customer support, yet he uses the computers his department to access files that are normally accesses only by people in accounting.  These two departments are on separate floors of the building.  Would this be a security event in your organization?&lt;br /&gt;&lt;br /&gt;These three examples illustrate how the separation of physical security and data security creates a set of vulnerabilities that ought to embarrass any security organization that claims to have performed a risk assessment&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-114162139125152216?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114162139125152216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114162139125152216'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/03/why-convergence.html' title='Why Convergence?'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-114161709781294742</id><published>2006-03-05T18:59:00.000-08:00</published><updated>2006-04-23T20:35:53.223-07:00</updated><title type='text'>Sopranos Go After the Data</title><content type='html'>Have you every watched the Sapranos on television? Or , any mafia movie for that matter? They seem to always be hijacking trucks: What are they after? Well, they steal cigarettes, razor blades, electronics: Things that are easily converted into cash. These are called fungible items.&lt;br /&gt;&lt;br /&gt;In today's world, financial identities are fungible items. A good financial identity will get $2 on the open Internet. Moreover, there are a number of scams that allow less than $10,000 to be converted into $1.5 million with virtually no risk of being caught.&lt;br /&gt;&lt;br /&gt;I am not writing this to encourage any of you to get into the Internet scam business. Rather, I write this to underscore why so many businesses and individuals are under very intense attack over those financial identities. These attacks are increasing and will be looking for new targets and new victims.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-114161709781294742?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114161709781294742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114161709781294742'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/03/sopranos-go-after-data.html' title='Sopranos Go After the Data'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-114098419303518673</id><published>2006-02-26T11:51:00.000-08:00</published><updated>2006-02-26T12:03:21.770-08:00</updated><title type='text'>A Meeting of Two Cultures with Identical Goals</title><content type='html'>&lt;p class="MsoNormal"&gt;I recently conducted a joint security discussion at a $5 billion beverage company.   I moderated the discussion, which was between the physical security organization and the data security organization.  The physical security personnel fit the stereotype of burly, blue collar and rough hewn language skills.  The  data security folks also fit their stereotype:   brainy and articulate.  Yet, during the meeting, it became clear that the physical security folks had a lot to offer the IT people.  It is true, the physical security folks might be able to persuade, but it was clear to me and to the IT people that physical and data security can and should work together.&lt;br /&gt;&lt;br /&gt;We found that physical security had skills in conducting risk-based assessments that were sorely lacking in the IT people.  We also discovered that the physical security people would immediately view change procedures as an area of high vulnerability.  Yet, such procedures at this company were incomplete and inadequate.  Finally, the parties reached consensus that third-party oversight might benefit IT's security efforts.&lt;br /&gt;&lt;br /&gt;Convergence is a term used to imply the integration of physical and data security.  Most people think this means the integration of entry control systems for facilities and the computer network.   In the case of this global company, convergence means integrating the two organizations in a way that allows both to contribute to improving the protection of assets.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-114098419303518673?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114098419303518673'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114098419303518673'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/02/meeting-of-two-cultures-with-identical.html' title='A Meeting of Two Cultures with Identical Goals'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-114092295338855343</id><published>2006-02-25T19:02:00.000-08:00</published><updated>2006-02-25T19:02:33.473-08:00</updated><title type='text'>Operational Risk and Organizational Risk</title><content type='html'>&lt;p class="MsoNormal"&gt;Electronic crime has increased the organizational risk that corporations face. With physical crime operations tend to bear the greatest risk. Six or seven years ago organizations could focus on securing its operations in order to deal with it greatest risk. If a truckload of product were stolen, the loss would often be the company's greatest exposure. The Internet has initiated such changes as: i) Financial identities can be obtained (i.e. stolen) and sold by people thousands of miles away; ii) Laws have been implemented to protect consumers and employees from having their identities stolen as a result of corporate negligence; and iii) Penalties and sanctions can, when made public, result in a loss of approximately 17% of a corporation's market capitalization for at least a year following the breach, in addition to damages. This loss of shareholder value along with a loss by the brand makes the organizational risk greater than that borne by the operations. The corporation suffers very little, it at all, when its customers' financial identities are purloined...at least the direct loss is very little. The litigation that follows is now the major risk factor. A competent security plan protects the corporation from this organizational risk.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-114092295338855343?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114092295338855343'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/114092295338855343'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2006/02/operational-risk-and-organizational.html' title='Operational Risk and Organizational Risk'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113475727661577481</id><published>2005-12-16T10:19:00.000-08:00</published><updated>2006-02-25T18:46:10.906-08:00</updated><title type='text'>Aligning Risk with Security Solutions</title><content type='html'>&lt;p class="MsoNormal"&gt;IT organizations almost never conduct a risk assessment before they implement security. How smart is that? Well, not very. The standard practice in, say, configuring a firewall is to see what traffic comes through and then configure it to block that traffic. Wait for and block the next set of traffic to come and then repeat this process until satisfied.&lt;br /&gt;&lt;br /&gt;Think about securing your house in the same manner: Well, people walk in front of the building so you put locks on the front door. People walk by and look in the windows so you lock the front windows. The garage door is left open at times and people walk by, so you lock the door from the garage to the house. Let's say that is the extent of traffic for about a week. Is your house secure? Hardly...and neither are IT systems, and for the very same reason.&lt;br /&gt;&lt;br /&gt;I actively advocate having physical security people work with IT people in conducting risk assessments. Physical security people have risk-based assessments etched into their &lt;st1:stockticker&gt;DNA&lt;/st1:stockticker&gt;.  They can provide a lot of guidance to IT people when it comes to securing IT systems.&lt;br /&gt;&lt;br /&gt;I like to think of this as one step in integrating physical and data security: This is also call convergence in security circles. I exhort my clients to integrate the two organizations, physical and data security, before they try to integrate systems such as access controls. IT learned many years ago that automating a bad procedure only makes the matter worse: Integrating the IT systems of physical and data systems before the organizations are working together will also make the system worse.&lt;br /&gt;&lt;br /&gt;In addition to conducting risk-based assessments, I encourage my clients to have physical security provide guidance in development enforceable policies for IT change controls and to provide third-party oversight when those change procedures are being performed. Collaboration in these three areas represents a satisfactory prerequisite to integrating various access control systems.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113475727661577481?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113475727661577481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113475727661577481'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/aligning-risk-with-security-solutions.html' title='Aligning Risk with Security Solutions'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113475413809036879</id><published>2005-12-16T09:28:00.000-08:00</published><updated>2006-01-21T09:54:19.236-08:00</updated><title type='text'>Securing the Corporation</title><content type='html'>&lt;p class="MsoNormal"&gt;Ask most data security professionals how to secure the assets of a company: They will talk about operational security.  They will discuss firewalls; intrusion prevention and the like. They wrongly focus on the loss of data and other operational security matters.  Yet, they will also tell you that they can never be 100% security.  At the same time, they nearly always fail to also discuss the biggest risk for a corporation...and that is often the legal aftermath of a data loss. The legal entanglements will often result in far more financial loss than the actual damages, especially a loss of data. I think this is a holdover from physical security when the actual loss was often the majority of the material damages.  This is simply not the case in today's world of data loss.  So, how do you protect against this?&lt;br /&gt;&lt;br /&gt;I like to distinguish operational security from organizational security.  Securing a corporation requires both operational security and organizational security.  At the minimum, organizational security is comprised of:  i) Some kind of oversight or governance; ii)  A formal security plan; and, iii) Progress against than plan.  While the devil is indeed in the details, these three elements typically protect a corporation from its greatest risk.  Moreover, it can be implemented often within 30 to 60 days.  I often call it the fast track to compliance.  With an active oversight program, companies can actually extend their remediation efforts and be more systematic and therefore economical in deploying their operational security. &lt;br /&gt;&lt;br /&gt;I strongly advocate organizational and operational security programs as joint initiatives.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113475413809036879?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113475413809036879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113475413809036879'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/securing-corporation.html' title='Securing the Corporation'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113475313268567118</id><published>2005-12-16T08:57:00.000-08:00</published><updated>2005-12-17T13:29:46.423-08:00</updated><title type='text'>Integrating Physical and Data Security for Money</title><content type='html'>&lt;p class="MsoNormal"&gt;I continue to bang the drum for integrating physical and data security. It makes too much sense not to. Not only does it dramatically improve security, make electronic crime much more difficult to perpetrate, it is even inexpensive. Think of the situation in this way:&lt;br /&gt;&lt;br /&gt;A company with 3,000 employees in three buildings has to issue changes orders for every new employee, every departing employee and every employee who relocates in the buildings. This means HR must document the changes, physical security must update its various (one for each building) access control lists, and IT must modify the server configuration. This 300 change requests times three, 900 per month, assuming 10% of the employees have change monthly. By the way, I hear that Cisco has 10,000 change requests a day! They manage those requests with 5 people. You know how: They have integrated their systems.&lt;br /&gt;&lt;br /&gt;Integrating physical access control and computer accounts for our hypothetical corporation will provide a full return on its investment (estimated at $160,000) in 16 months, based on compensation levels in Los Angeles circa 2004.&lt;br /&gt;&lt;br /&gt;Why isn't this being done across all corporations? I maintain that the obstacle is simply the cultural gap between physical security organizations and the information technology organizations. I spend a good deal of my professional time explaining and showing physical security personnel how to bridge the gap with IT. I identify and describe how to integrate with IT even before the access control systems are integrated.&lt;br /&gt;&lt;br /&gt;Integrating access control systems and the computer network will produce tremendous gains in both security and productivity. If Cisco can process 10,000 change requests a day with five people then certainly access control can become the low-level administrative task it should be.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113475313268567118?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113475313268567118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113475313268567118'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/integrating-physical-and-data-security_16.html' title='Integrating Physical and Data Security for Money'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113466621486545566</id><published>2005-12-15T08:41:00.000-08:00</published><updated>2005-12-17T13:33:35.210-08:00</updated><title type='text'>Identity or Transaction</title><content type='html'>&lt;p class="MsoNormal"&gt;Identity management is one of the most obvious places to focus security attention, but it may not be the most economical. This is especially true for a large corporation that needs to protect shareholder value and may be the object of attack from dozens of unknown sources. Having said that, identity management has experienced a number of improvements in recent years.&lt;br /&gt;&lt;br /&gt;I was in the middle of these developments two years ago when I was advising the president of a company that secures communication between the White House and the DOD. This was during the transition between "&lt;st1:stockticker&gt;PKI&lt;/st1:stockticker&gt; is too hard to use" and the new approach which is "wrapped &lt;st1:stockticker&gt;PKI&lt;/st1:stockticker&gt; in a registration authority software interface". Now, there are a number of identify management solutions that make the process of administering &lt;st1:stockticker&gt;PKI&lt;/st1:stockticker&gt;-level identify management as easy as email account administration.&lt;br /&gt;&lt;br /&gt;Returning to my first point, there two things to remember: You can never have perfect knowledge of your users' identities, so this will always remain a vulnerability even if it is reduced; and You could have near perfect identity management and still not reduce your company's largest risk. These two facts of life in today's world, suggest identity management is not, as I stated at the outset, the most economical security focus.&lt;br /&gt;&lt;br /&gt;So, what is? I continue to believe the it is best to keep the focus on two places and keep it there until it cannot be implemented any better: One, secure the point of the transaction; and two, optimize the three-point implementation of i) maintaining a formal security plan, ii) providing formal governance over that plan, and iii) show progress against that plan. These two points of focus easily provide the greatest security (especially when cost is considered) a corporation can obtain.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113466621486545566?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113466621486545566'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113466621486545566'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/identity-or-transaction.html' title='Identity or Transaction'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113454169235889284</id><published>2005-12-13T22:16:00.000-08:00</published><updated>2005-12-17T13:36:11.320-08:00</updated><title type='text'>Disaster Recovery Begs a Context</title><content type='html'>&lt;p class="MsoNormal"&gt;It is a fact of corporate life in &lt;st1:country-region&gt;&lt;st1:place&gt;America&lt;/st1:place&gt;&lt;/st1:country-region&gt; that a company's biggest risk derives not from the direct impact of a disaster but from the litigation that follows. Emergency management provides the proper framework for planning disaster recovery and business continuity (DR/BC). This framework defines the continuity from the first instance of an emergency and continuing until the emergency has fully passed and normalcy is restored. Too often disaster recovery is combined with business continuity as though they represent a complete entity.&lt;br /&gt;&lt;br /&gt;A company should build its DR/BC plan in a framework for distinguishing incidents (breaches in service to the customer) disasters (breaches in service that require replacement of facilities and/or equipment) and crisis (breaches that become the focus of the news media). As these different emergencies are distinguished different emergency response teams are activated.&lt;br /&gt;&lt;br /&gt;Similarly, the emergency response plan should exist within a governance program. It requires both of these layers:&lt;span style=""&gt;  &lt;/span&gt;governance and an emergency response plan (including DR/BC) to truly mitigate a company's liability.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113454169235889284?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113454169235889284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113454169235889284'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/disaster-recovery-begs-context.html' title='Disaster Recovery Begs a Context'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113436856095582088</id><published>2005-12-11T22:16:00.000-08:00</published><updated>2005-12-17T13:37:18.220-08:00</updated><title type='text'>When is your IT department an obstacle to security?</title><content type='html'>&lt;p class="MsoNormal"&gt;It may seem like a funny question, but the IT department is an obstacle to security when they operate under the myth that a high thick wall keeps the bad guys out. This is a myth because 60 to 80% of all corporate crimes have an insider element: This element can be unwitting or witting.&lt;br /&gt;&lt;br /&gt;So how do you know if your IT department believes in this myth? Simply listen when an executive asks them: Are we secure? If they answer by saying something along the lines of "Yes, we have a firewall, intrusion detection and virus protection" then indeed they do believe the myth.&lt;br /&gt;&lt;br /&gt;An electronic crime does not occur as a simple event. It evolves. It begins with the bad guy collecting information form unsuspecting sources. He (or she) then uses that information to create traffic that looks to your firewall, intrusion systems or perhaps your virus scanners, every bit like valid traffic. Electronic crime sneaks past the barrier of the "high, thick wall."&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113436856095582088?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113436856095582088'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113436856095582088'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/when-is-your-it-department-obstacle-to.html' title='When is your IT department an obstacle to security?'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113419476333678478</id><published>2005-12-09T21:58:00.000-08:00</published><updated>2005-12-17T14:00:02.500-08:00</updated><title type='text'>Integrating Physical and Data Security</title><content type='html'>&lt;p class="MsoNormal"&gt;Over 15,000 physical access control systems have been sold and installed in US corporations. These systems fully support integration of access control in both physical and logical space: Yet, less than a dozen companies have completed this integration. Despite the existence of these systems, the place to start the integration is with the people. Physical security personnel hold many of the key skills. &lt;span style=""&gt; &lt;/span&gt;Here is what I recommend:&lt;br /&gt;1. Have physical security lead the risk based assessment of the company's computer systems. This skill is in their DNA. IT folks almost never conduct risk based assessments.&lt;br /&gt;2. Have physical security write enforceable policies for change management within IT. IT seldom writes such policies for themselves...and when they do they seldom do them so they are readily enforceable.&lt;br /&gt;3. Have physical security provide third party oversight when key change procedures are performed. This of data as cash: digital cash. Doing so highlights the need for third party oversight.&lt;br /&gt;Integrating these three functions is the forerunner of integrating the access control systems. It follows the old IT adage: Do not automate broken processes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113419476333678478?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113419476333678478'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113419476333678478'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/integrating-physical-and-data-security.html' title='Integrating Physical and Data Security'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113397171776085126</id><published>2005-12-07T08:04:00.000-08:00</published><updated>2005-12-17T14:01:56.866-08:00</updated><title type='text'>eCrime or Security</title><content type='html'>&lt;p class="MsoNormal"&gt;I use eCrime because it is a conversation starter. It leads to more questions, more dialog. When the term security is used people often rely on their image of ex-cops, fences, dogs, kiosks, etc. It stops conversation and questioning. eCrime is a conversation starter. It invites such questions as: How is electronic crime different than physical crime; Why is electronic crime on the rise and physical crime at a plateau; How physical crime (security) people interact with electronic crime people? These questions are addressed throughout this blog and in Tatum's eCrime practice.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113397171776085126?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113397171776085126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113397171776085126'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/ecrime-or-security.html' title='eCrime or Security'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113390467885503841</id><published>2005-12-06T13:25:00.000-08:00</published><updated>2005-12-17T14:03:04.273-08:00</updated><title type='text'>Cyberbust!</title><content type='html'>&lt;p class="MsoNormal" style="line-height: 150%;"&gt;&lt;span style="font-family: Arial;"&gt;This was the allure that got me into this business:&lt;br /&gt; &lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt; &lt;!--[endif]--&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;     &lt;p class="MsoNormal" style="line-height: 150%;"&gt;&lt;st1:time hour="17" minute="30"&gt;&lt;st1:time minute="30" hour="17"&gt;&lt;span style="font-family: Arial;"&gt;Five thirty&lt;/span&gt;&lt;/st1:time&gt;&lt;/st1:time&gt;&lt;span style="font-family: Arial;"&gt; on a dark Saturday morning, I led an experienced team in a court-ordered break in to investigate a number of companies allegedly linked to illegal operations taking place in a single building south of &lt;/span&gt;&lt;st1:city&gt;&lt;st1:place&gt;&lt;st1:city&gt;&lt;st1:place&gt;&lt;span style="font-family: Arial;"&gt;Los Angeles&lt;/span&gt;&lt;/st1:place&gt;&lt;/st1:City&gt;&lt;/st1:place&gt;&lt;/st1:city&gt;&lt;span style="font-family: Arial;"&gt;. In this concrete-slab tilt-up building so typical of &lt;/span&gt;&lt;st1:state&gt;&lt;st1:place&gt;&lt;st1:state&gt;&lt;st1:place&gt;&lt;span style="font-family: Arial;"&gt;California&lt;/span&gt;&lt;/st1:place&gt;&lt;/st1:State&gt;&lt;/st1:place&gt;&lt;/st1:state&gt;&lt;span style="font-family: Arial;"&gt; industrial parks were slightly less than a dozen companies providing credit card and bounced check processing services. These companies were spawned from a single company that the State Court had just recently judged to be stolen, in its entirety, two years before. Two employees with minority shareholdings, it seems, hijacked the hard drive from the server leaving bogus drives as replacements, thereby taking the clients, the vendors and all future transactions. The majority owner of the original company was left with the existing cash, which was not much, the lease to the building, furniture and little else. He pursued the thieves in the courts for two years, finally receiving a judgment for $24 million and a court order to seize the business to collect evidence of the commingling of assets between the companies. The seizure was foiled because the defendants placed the stolen company into bankruptcy, thereby forcing a change in venue from state to federal court. This bankruptcy was filed, of course, after the most valuable assets were transferred from the bankrupted company to the other legal entities, leaving the owner with a bankrupt company worth far less than his $24 million judgment. This crime is one example of how difficult it is to catch up with cunning thieves who understand the subtleties of electronic forms of data and the law.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="line-height: 150%;"&gt;&lt;span style="line-height: 150%;font-family:Arial;font-size:11;"  &gt;&lt;span class="bodytext1"&gt;&lt;span style="line-height: 150%;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113390467885503841?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113390467885503841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113390467885503841'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/cyberbust.html' title='Cyberbust!'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113389692065585740</id><published>2005-12-06T11:14:00.000-08:00</published><updated>2005-12-17T14:07:04.370-08:00</updated><title type='text'>Where is the leadership?</title><content type='html'>&lt;p class="MsoNormal"&gt;What happens if Bob does not badge in and then someone else accesses Bob's computer and data? Answer: Nothing. It is not even a security event or alert. This scenario illustrates the fact that there is no connection between physical security and data security in corporations. Here is the punch line: Over 15,000 systems have already been sold and installed in corporations in &lt;st1:country-region&gt;&lt;st1:place&gt;America&lt;/st1:place&gt;&lt;/st1:country-region&gt; that enable the integration of physical and data security. Why the disconnect?&lt;br /&gt;&lt;br /&gt;I believe it is a failure of leadership. There is nothing to prevent physical security people and data security people working together except for: i) a cultural gap; and ii) the lack of leadership to bridge that gap.&lt;br /&gt;&lt;br /&gt;When Tatum's eCrime practice is operating at its highest level, we provide that leadership. Our goal is increase the amount of time we spend operating at that level. In the meantime, we devote ourselves to the blocking and tackling of compliance and operational security.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113389692065585740?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113389692065585740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113389692065585740'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/where-is-leadership.html' title='Where is the leadership?'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113376374499916844</id><published>2005-12-04T22:22:00.000-08:00</published><updated>2006-03-05T20:52:09.770-08:00</updated><title type='text'>Making Money with Financial Identities</title><content type='html'>&lt;p class="MsoNormal"&gt;Here is an example of how fianancial identities are used in scams to make money for the bad guys:&lt;br /&gt;1. Bad Guy Bob buys 2,000 financial identities for $2 apiece. So, here one person makes $4,000 for a product (the financial identities) that he gets to sell over and over again.&lt;br /&gt;2. Bob then uses one of the identities to get a credit account at &lt;st1:place&gt;&lt;st1:placename&gt;Circuit&lt;/st1:placename&gt;  &lt;st1:placetype&gt;City&lt;/st1:placetype&gt;&lt;/st1:place&gt; where he buys 10 digital cameras for $500 each. This charge of course is against someone else, not Bob.&lt;br /&gt;3. Bob has the cameras shipped to one of his re-mailers. He got the re-mailer by posting an advertisement on a telephone pole saying, "Work at home, make $20 per hour."&lt;br /&gt;4. Bob opens a store on eBay advertising brand new, still under warranty cameras, still in the packaging, for sale for only $350. Bob will get a lot of orders for these cameras.&lt;br /&gt;5. Bob sends ten of the orders to his re-mailer and says, " Open the box from &lt;st1:place&gt;&lt;st1:placename&gt;Circuit&lt;/st1:placename&gt; &lt;st1:placetype&gt;City&lt;/st1:placetype&gt;&lt;/st1:place&gt; and send one camera for each of these orders. Bob pays the re-mailer, say, $40 for this work.&lt;br /&gt;&lt;br /&gt;Let's do the math. Bob make $3,500 for his $2 investment when he used one of the 2,000 financial identities he had purchased earlier. If he does this same routine 1,999 more times he will gross $700,000. By the way, Bob could execute this entire scam from outside of the &lt;st1:country-region&gt;&lt;st1:place&gt;U.S.&lt;/st1:place&gt;&lt;/st1:country-region&gt; He could also move the operation (the re-mailers and the &lt;st1:place&gt;&lt;st1:placename&gt;Circuit&lt;/st1:placename&gt;  &lt;st1:placetype&gt;City&lt;/st1:placetype&gt;&lt;/st1:place&gt; store) from city to city each month.&lt;br /&gt;&lt;br /&gt;This scam is a very difficult one to catch up with. It is very lucrative and very low risk. The point of all of this is that with such easy gain and low risk, there is a high level of motivation for bad guys to steal identities. You can bet that the pressure on financial identities will increase for many years to come.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;a href="http://picasa.google.com/blogger/" target="ext"&gt;&lt;img src="http://photos1.blogger.com/pbp.gif" alt="Posted by Picasa" style="border: 0px none ; padding: 0px; background: transparent none repeat scroll 0% 50%; -moz-background-clip: initial; -moz-background-origin: initial; -moz-background-inline-policy: initial;" align="middle" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113376374499916844?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113376374499916844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113376374499916844'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/making-money-with-financial-identities.html' title='Making Money with Financial Identities'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-19586308.post-113376288330355765</id><published>2005-12-04T22:07:00.000-08:00</published><updated>2005-12-04T22:08:03.310-08:00</updated><title type='text'>Information Tatum - Joel Rakow, Ed.D. - December 2005</title><content type='html'>Here's a first.  A prominent computer security expert claims that the proceeds derived from electronic crime exceeded, for the first time this year, the proceeds derived from illegal drug trafficking:  $105B.  This statement could simply be a case of an expert with a self interest is making a dramatic statement to draw attention to himself.  Nonetheless, it shows how rampant eCrime has become in the ten years since the Internet became a mainstream tool. &lt;br /&gt;&lt;br /&gt;The holiday season inspired me to select my three favorite news bites as Hot Topics.  One illustrates how companies are attacking their competitors web properties, using regulatory acts.  The second presents new progress in blocking SPAM, and the third discusses the new strategy and sensitivities regarding protecting the corporate network the point of user workstations through the new "lockdown" technologies.  I hope you enjoy this month's selection.  Best wishes for the&lt;br /&gt;****************************************&lt;br /&gt;Joel's Activities:&lt;br /&gt;1.  At the Conference Board in New York, Joel Presented to approximately 120 security executives of America's top corporations including WalMart, FedEx, Bell South, Genetech, Cisco, etc.&lt;br /&gt;2.  Tatum's Denver office and Joel will prepare a global security plan for that area's largest beverage company. 3.  As part of the World Shoe Association's relocation of corporate headquarters, Joel lead the relocation and re-staffing of the IT operations, including the implementation of a new tradeshow production system and back office system. 4.  Joel chaired the first three IT Steering Committee meetings after developing and obtaining approvals on the charter and operating plan for Bidz.com's governance program.&lt;br /&gt;***************************************&lt;br /&gt;HOT TOPICS&lt;br /&gt;WEB ATTACKS USING REGULATIONS&lt;br /&gt;--Study of Take-Down Notices Under DMCA Section 512 Finds Potential for Abuse (28 November 2005) Researchers at the University of California at Berkeley and the University of Southern California looked at 876 takedown requests made to web sites and search engines under the section 512 Digital Millennium Copyright Act (DMCA). Section 512 requires that hosting and search providers take down content and links to content to be exempt from copyright lawsuits. The notice needs no judicial review of whether or not a copyright has been infringed upon. The researchers found that more than half of the requests were made by companies against competitors, and that 30 percent of the requests were the ones in which it was questionable as to whether or not copyright had been infringed upon. There were only seven cases among those studied in which the questioned content was reinstated on web sites. http://www.vnunet.com/vnunet/news/2146807/dmca-hindrance-help&lt;br /&gt;http://www.securityfocus.com/brief/62&lt;br /&gt;http://lawweb.usc.edu/news/dmca.html&lt;br /&gt;http://mylaw.usc.edu/documents/512Rep-ExecSum_out.pdf&lt;br /&gt;[Editor's Note (Pescatore):The DMCA is a pretty good example of how legislation aimed at technology usually has more wacky side effects than any actual positive effect. That said, it is pretty straightforward to file a counter-notification if someone has used DMCA improperly to cause legitimate content to be removed - the Electronic Frontier Foundation and a number of universities sponsor a site that provides information and templates on how to do so: http://www.chillingeffects.org/&lt;br /&gt;(Schultz): The DMCA has been a proverbial can of worms ever since the day it went into law. Studies such as the ones at UC Berkeley and USC provide empirical evidence of some of the DMCA-related abuses that occur. The big question, however, is whether legislators will respond appropriately or whether they will continue to blindly support the industries that so strongly lobbied for this legislation.&lt;br /&gt;(Hoepman): A similar study in the Netherlands found that the vast majority of ISP's, when presented with a take-down notice, prefer to err on the safe side and comply without checking the validity of the claim at all.]&lt;br /&gt;&lt;br /&gt;SPAM BLOCKS&lt;br /&gt;--FTC: Spam Blocking Technology is Getting Better&lt;br /&gt;(28 November 2005)&lt;br /&gt;A study conducted by the US Federal Trade Commission (FTC) indicates that Internet service providers (ISPs) are improving their spam blocking techniques. In a test, the FTC found that two unnamed web-based email service providers effectively blocked 96 percent of spam messages. However, the onus of filtering the bad messages from the good still falls to the ISPs. Spammers collect email addresses by "scraping," or using automated programs that look for the "@" sign present in all email addresses. The FTC recommends that if people need to post their email addresses on the Internet, they do so in an alternate syntax in order to avoid having their addresses added to spammers' lists. http://today.reuters.com/news/NewsArticle.aspx?type=internetNews Note (Schmidt): From a personal perspective, using ISP tools with a "near free" toolbar, I have not had a single SPAM or Phising email in any of my 7 different email inboxes in going on 10 months. Progress is being made and the tools are there if people would just use them.&lt;br /&gt;(Honan): Filtering Spam at the ISP level makes good business sense for the ISPs. It reduces the network overhead on their links while at the same time making for happier customers. A win win solution, except for the spammers.]&lt;br /&gt;&lt;br /&gt;LOCKING IT DOWN&lt;br /&gt;System Lockdown an Effective Tool Against Malware&lt;br /&gt;(28 November 2005)&lt;br /&gt;IT managers should look not only at products to protect their systems from malware, but also at the possibility of locking down end-user computers. With system lockdown, users have limited abilities to compromise their systems. Most malware comes in the form of applications, most of which require some user interaction to gain a foothold within systems. http://www.thechannelinsider.com/print_article2/0,1217,a=166172,00.asp&lt;br /&gt;[Editor's Note (Schmidt): There once was a time where this would create huge push back but given the wide use of broadband at home and use of mobile devices to stay connected there are many other options then using work machines. This may be more palatable as many that are successful at enterprise security have used configuration management around security to get there.]&lt;br /&gt;&lt;br /&gt;Hot Topics is adapted from SANS Newsbites for Tatum Partners.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19586308-113376288330355765?l=ecrimewatch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113376288330355765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19586308/posts/default/113376288330355765'/><link rel='alternate' type='text/html' href='http://ecrimewatch.blogspot.com/2005/12/information-tatum-joel-rakow-edd.html' title='Information Tatum - Joel Rakow, Ed.D. - December 2005'/><author><name>Joel Rakow, Ed.D.</name><uri>http://www.blogger.com/profile/15064611348048424086</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/hello/201/8900/640/Tatum%20Rakow.jpg'/></author></entry></feed>
