クレジットカード大手5社、データ・セキュリティ基準の管理組織設立

FIVE LEADING PAYMENT BRANDS UNITE TO STRENGTHEN GLOBAL DATA SECURITY
New Independent Organization to Develop and Maintain Security Standards

 アメリカン・エクスプレス、ディスカバー・フィナンシャル・サービシズ(DFS)、JCB、マスターカード・ワールドワイド、ビザ・インターナショナルの 5社は9月7日、クレジットカード業界のデータ・セキュリティ基準「PCI DSS(PCI Data Security Standard)」の策定・維持管理・普及を推進するための、独立した監督組織「PCI Security Standards Council」を設立したと発表。これに伴い、PSI DSSの改訂版(バージョン1.1)を公開した。

 PCI DSSは、ネットワーク情報セキュリティの安全性について、定期的に第三者の監査を受けるよう定めた技術要件集で、クレジットカード会社ごとに適用されていた複数のセキュリティ・ガイドラインを一本化することを目的に策定された。2005年6月に初めて適用されたが、その基準が曖昧で順守が難しいとの苦情が多く、ビザの推計によると、PCI基準に準拠しているのは22%に留まっていたという。

Hackers put heat on security

Hackers and corporate suits joined in Las Vegas this week to discuss security at the annual Black Hat conference. Microsoft hosted a whole day of discussion on security in its Vista update--a sign of the conference changing. The FBI also made an appearance to make a call for hacker help with cybercrime. Meanwhile, one hacker at the conference demonstrated flaws in Wi-Fi software that could let an attacker break into a PC. Other researchers released tools to test the security of increasingly popular voice over Internet Protocol telephony systems.
Read full story

AT&T hack exposes 19,000 identities

AT&T on Tuesday said hackers broke into one of its computer systems and accessed personal data on thousands of customers who used its online store.

The information that was illegally accessed includes credit card numbers, AT&T said in a statement. The cyberattack affects about 19,000 customers who purchased equipment for high-speed DSL Internet connections through AT&T's Web site, the company said.
Link

How Carnivore worked

FBI-seal
Carnivore, a controversial program developed by the U.S. Federal Bureau of Investigation (FBI) to give the agency access to the online/e-mail activities of suspected criminals. For many, it is eerily reminiscent of George Orwell's book "1984." Although Carnivore was abandoned by the FBI in favor of commercially available eavesdropping software by January 2005, the program that once promised to renew the FBI's specific influence in the world of computer-communications monitoring is nonetheless intriguing in its structure and application.

誤廃棄か、りそな銀が顧客データ17万人分紛失

読売新聞 - 14分前
りそな銀行は18日、全店舗の1割強にあたる43店舗で計17万1612人分の顧客情報が記録された小型フィルムを紛失したと発表した ...
りそなHD傘下の2行、顧客情報を紛失 日本経済新聞
りそな銀、17万人分顧客情報紛失 統廃合の際、廃棄か朝日新聞
徳島新聞 - 産経新聞 - 関連記事 21 件 »

*Fidelityラップトップ盗難

Lost Fidelity laptop stirs fear of ID theft Friday March 24, 03:15 AM By Svea Herbst-Bayliss

ボストンに本社があるミューチュアルファンド大企業Fidelity Investmentsは、同社のラップトップ一台が盗まれ、それに入っていたHP社の現在と元社員19万6000人の個人情報がなくなったことを明らかにした。

2006年1月には、Ameriprise Financial Inc. 従業員の車の中に置いてあったラップトップから 158,000人の個人情報が盗まれた。また、2005年12月には ABN Amro Bank NVが 200万人の顧客情報を紛失したが、幸い回収することができたと報告している。

Continue reading "*Fidelityラップトップ盗難" »

*EU Selects COBIT as an Auditing Standard

200年5月、欧州連合はCOBITをITセキュリティとガバナンスのガイドラインに採用した。ISO17799とBSI(ドイツ)に続く第三の標準となる。

連邦法案の最新状況(CRS)

11:12 pm - S.1789 Personal Data Privacy and Security Act of 2005
(Introduced in Senate)


Title: A bill to prevent and mitigate identity theft, to ensure
privacy, to provide notice of security breaches, and to enhance criminal
penalties, law enforcement assistance, and other protections against security
breaches, fraudulent access, and misuse of personally identifiable information.


Related Bills: S.1332

Latest Major Action: 11/17/2005
Placed on Senate Legislative Calendar under General Orders. Calendar No. 297.



Continue reading "連邦法案の最新状況(CRS)" »

*欧米における情報セキュリティとプライバシ保護の基本原則

 Fair Information Practice Principles
These widely accepted Fair Information Practice Principles are the basis for many privacy laws in the United States, Canada, Europe and other parts of the world.

情報セキュリティとプライバシ保護の8原則は、アメリカ・カナダ・ヨーロッパ各国でのプライバシ保護法の基本となっている。歴史的には1973年に当時のDepartment of Health, Education and Welfareが提案したのが最初で、その後各国の代表からなるOECD理事会で合意されたのが下記に示す8原則である。詳細な説明はOECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (http://www1.oecd.org/publications/e-book/9302011e.pdf)にある。

Continue reading "*欧米における情報セキュリティとプライバシ保護の基本原則" »

*CA Privacy Laws - Security Breach Notice

Security Breach Notice - Civil Code sections 1798.29, 1798.82, and 1798.84. This law requires a business or a State agency that maintains unencrypted computerized data that includes personal information, as defined, to notify any California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The type of information that triggers the notice requirement is an individual's name plus one or more of the following: Social Security number, driver's license or state ID card number, or financial account numbers. The law's intention is to give affected individuals the opportunity to take steps to protect themselves from identity theft. See the Office of Privacy Protection’s Recommended Practices in relation to this law.

French Regulations

Interministerial Instruction no. 920: 25 January 2005 version
The systems dealing with classified information of defence on a confidential level.

Directive no. 1223, 23 December 2004
The physical protection of information on protected supports.

Interministerial General Instruction no. 1300, 25 August 2003
The protection of the national defence secret.

Directive 4201/SG, 13 April 1995
Information Systems Security.

Recommendation no. 901, 2 March 1994
Recommendation for the protection of information systems dealing with sensitive information that is not classified defence.

Recommendation no. 600, March 1993
Protection of sensitive information not governed by defence secrecy.
Recommendations for computer workstations.

European Regulations

European legal context

  • Personal data protection

    Directive 95/46/CE issued by the European Parliament and Council on 24 October 1995 on the protection of individuals with regard to the processing of personal data and the free movement of such data - Official Journal No. L281, 23/11/1995, p. 0031-0050

    Directive 2002/58/CE issued by the European Parliament and Council, 12 July 2002, concerning the processing of personal data and the protection of privacy in the Electronic Communications Sector (Directive on privacy and electronic communications) - European Community Official Journal No. 1201/37, 31/07/2002 (abrogates directive 97/66/CE)
    (http://europa.eu.int/eur-lex/en/index.html)

  • Consumer protection

    Directive 85/374/CEE issued by the Council on 25 July 1985 on the approximation of laws, regulations and administrative provisions of the Member States concerning liability for defective products - Official Journal No. L210, 07/08/1985, p. 0029 - 0033 Amended by 399L0034 (OJ L 141 04.06.1999 p. 20)

    Directive 91/250/CEE issued by the Council on 14 May 1991 on the legal protection of computer programs - Official Journal No. L 122, 17/05/1991 p. 0042-0046

    Directive 1999/5/EC by the European Parliament and Council held on 9 March 1999 on radio equipment and telecommunication terminal equipment and the mutual recognition of their conformity - Official Journal No. L 091, 07/04/1999, p. 0010 - 0028
  • Electronic signature
    Directive 1999/93/CE by the European Parliament and Council, 13 December 1999 on a community framework for electronic signatures - Official Journal No. L 013 19/01/2000, p. 0012-0020

 

European initiatives

  • Internet security

    Communication from the Commission to the Council, the European Parliament, the Economic and Social Committee and the Regions committee (adopted on 26 January 2001 - COM 2000/890 end):
    "Create a more secure information society while improving the security of information infrastructures and fighting against cybercrime"

    Communication from the Commission to the Council, the European Parliament, the Economic and Social Committee and the Regions committee on network and information security, 6 June 2001
    (http://europa.eu.int/information_society/eeurope/news_library/pdf_files/netsec_fr.pdf)

European Council Convention on cybercrime
(Treaty open for signature on 23.XI.2001 in Budapest)
For further information about this treaty (status of signatures and ratifications, list of declarations and reserves, explanatory report, etc.), see the Council of Europe site:
(http://conventions.coe.int/Treaty/EN/WhatYouWant.asp?NT=185)

Resolution of the European Union Council No. 15152/01, 11 December 2001 on networks and information security.
(http://europa.eu.int/information_society/eeurope/news_library/pdf_files/netsecres_en.pdf)

Communication from the commission to the Council, the European Parliament, the Economic and social committee and Regions committee (COM 2002 152):
"Proposal for a decision of the European Parliament and of the Council amending decision 276/1999/CE adopting a multiannual community action plan on promoting safer use of the Internet by combating illegal and harmful contents on global networks.
(http://europa.eu.int/information_society/programmes/iap/programmes/followup/index_en.htm)

Proposed Council Framework decision related to attacks on information systems (COM 2002 173 final) published in the European Communities Official Journal C 203 E, 27 August 2002.
(http://europa.eu.int/eur-lex/en/archive/2002/ce20320020827en.html)

European Council Convention for protection of individuals with regard to automatic processing of personal data, 28 January 1981
(http://conventions.coe.int/Treaty/EN/Treaties/Html/108.htm)

個人情報保護法制

個人情報の保護に関する法律(平成15年5月30日法律第57号)

個人情報保護基本法制に関するこれまでの経緯
概要
法律
解説

◆ 諸外国における個人情報保護法制

OECD加盟国(29カ国)における個人情報保護法等
EU指令
主要各国における個人情報保護制度の概要とメディア関係規定
各国におけるメディアの扱い

Legislation on IT Security

European Community

eInvoicing
Directive 2001/115/EC

Electronic signatures
Decision 2003/511/EC (English)
Directive 1999/93/EC (English)

E-Commerce
Directive 2000/31/EC (English)

Technical rules and regulations
Coordinated Text of Directives 1998/34/CE and 1998/48/CE (unofficial text)
Direttiva 1998/48/CE
Direttiva 1998/34/CE

Distance contracts
Direttiva 1997/7/CE

Privacy protection
Direttiva 2002/58/CE
Direttiva 1997/66/CE
Direttiva 1995/46/CE

Telecommunications
Direttiva 2002/19/CE (access directive)
Direttiva 2002/20/CE (authorisation directive)
Direttiva 2002/21/CE (framework directive)
Direttiva 2002/22/CE (universal service directive)
Decisione n. 676/2002/CE (radiospectrum decision)

United Nations

UNCITRAL Model Law on Electronic Commerce (English)

Italy

eInvoicing
DM 23 gennaio 2004 - UNOFFICIAL ENGLISH TRANSLATION

Certified email
DPR 11 February 2005 n. 68 - Unofficial English translation
Technical Rules Draft 2005-05-12- Unofficial English Translation

Electronic signatures

D.Lgs. 23 gennaio 2002 n.10 ( English unofficial translation)
DPCM 8 febbraio 1999 (English)
DPR 10 novembre 1997 nー 513 (English)
Art. 15 Legge 15 marzo 1997 nー 59 (English)

Optical storage
Deliberazione CNIPA 19 febbraio 2004 n. 11: regole tecniche per la riproduzione e conservazione di documenti su supporto ottico idoneo a garantire la conformit・dei documenti agli originali -(UNOFFICIAL ENGLISH)

Privacy protection
Legge 31 dicembre 1996 nー 675 (old) (English)

France

Projet de loi relatif au commerce ectronique
Loi n. 2000_230 Droit de la preuve e signature ectronique (Franis)
Article 28 loi sur la reglementation des tommunications 90 (Franis)

Germany

German Digital Signature Law 21st May 2001(English - Unofficial version)
German Digital Signature Ordinance (English - Unofficial version)
German Digital Signature Law 1997 (English)
German Digital Signature Ordinance 1997 (English)

Japan

不正アクセス行為の禁止等に関する法律(平成11年法律第128号) 【PDF形式:8KB

USA

アメリカ合衆国の「グローバル商取引及び国内商取引における電子署名法案」 仮訳

OECD Official Documents

OECD科学技術産業局の情報セキュリティ関係資料(pdf)。太字は一読すべき報告書。

DIRECTORATE FOR SCIENCE, TECHNOLOGY AND INDUSTRY
COMMITTEE FOR INFORMATION, COMPUTER AND COMMUNICATIONS POLICY

  • SCOPING STUDY FOR THE MEASUREMENT OF TRUST IN THE ONLINE ENVIRONMENT  02 december 2005
  • APEC-OECD WORKSHOP ON SECURITY OF INFORMATION SYSTEMS AND NETWORKS  07 december 2005
  • THE PROMOTION OF A CULTURE OF SECURITY FOR INFORMATION SYSTEMS AND NETWORKS IN OECD COUNTRIES 16 december 2005
  • TELECOMMUNICATION REGULATORY INSTITUTIONAL STRUCTURES AND RESPONSIBILITIES 11 january 2006
  • THE IMPLICATIONS OF WIMAX FOR COMPETITION AND REGULATION02 march 2006
  • THE POLICY IMPLICATIONS OF VOICE OVER INTERNET PROTOCOL13 february 2006
  • OECD QUESTIONNAIRE ON THE CROSS-BORDER ENFORCEMENT OF PRIVACY LAWS 07 february 2006

COMMITTEE ON CONSUMER POLICY

  • CONSUMER POLICY: A REPORT ON CONSUMER INFORMATION CAMPAIGNS CONCERNING SCAMS 20 december 2005
  • EDUCATION AND AWARENESS RAISING 04 august 2005
  • ANTI-SPAM REGULATION  15 november 2005

ITGI Research Publications

  • COBIT 4.0 This new version of ITGI痴 flagship product offers a streamlined, pragmatic and business-focused approach to implementing IT governance enterprisewide.
  • COBIT Security Baseline Based on COBIT, this guide is a comprehensive set of resources to guide the information organization as it adopts an IT governance and control framework. This guide focuses on the specific risks of IT security in an easy-to-follow-and-implement way for all users: small to medium enterprises, executives and board members of larger organizations, and home users.
  • COBIT Quickstart This is an abbreviated version of COBIT designed for small to medium enterprises, or those organizations in which IT is not strategically critical to enterprise success. Available from the ISACA Bookstore.
  • IT Control Objectives for Sarbanes-Oxley (PDF, 363K) A new research document from the ITGI, focusing on Sarbanes-Oxley, using COSO as the overall framework upon which the supplementary IT guidance was based, and COBIT as the initial IT controls baseline to develop a control objective template. Download also available in Japanese.

*IT Governance Institute

ITGI:1998年に設立されたITガバナンス普及・促進団体。

ITGI Releases New Survey Data Image
Groundbreaking research into IT governance knowledge and attitudes worldwide in 2003 are updated in the 2005 survey.
- IT Governance Global Status Report 2006 (PDF, 420K)
- IT Governance Global Status Report 2003 (PDF, 1.2M)


Continue reading "*IT Governance Institute" »

*ISACA

1967年設立。世界140カ国の会員50,000からなる情報システムコントロール協会。60カ国170の支部がある。

   Logo 

CISM(Certified Information Security Manager)『公認情報セキュリティマネージャー』
情報セキュリティの国際的資格。 ISACAにより、2002年に資格制度が創設され、2003年度より試験が開始された。

Security management tool comes to hospital's aid

Tool guards 250 wireless access points at Carilion Health System
News Story by Matt Hamblen

JANUARY 24, 2006 (COMPUTERWORLD) - Carilion Health System has been working to make its wireless LAN secure and compliant with federal regulations for three years, but the company recently found a new tool to simplify its wireless security management.
Brian Brindle, senior network engineer for the health care provider in Roanoke, Va., said Carilion has been using a new version of a wireless security tool for managing 250 wireless access points that offers better reports and simplifies administration.

Continue reading "Security management tool comes to hospital's aid " »

Compliance Archiving System with Vignette

JANUARY 19, 2006 (COMPUTERWORLD) - Organizations today face two major information problems: managing increasing volumes of information and complying with stricter regulations. This paper discusses an integrated document management solution based on Vignette Records & Documents and the Sun StorEdge^(TM) 5310 Compliance Archiving System, a solution that streamlines information management and automates compliance with information management regulations.
Download this white paper now

Security: Fast and Furious

What's Next: Security - Computerworld
Expect threats to get nastier as networks become more complex.
News Story by Bob Violino
JANUARY 02, 2006 (COMPUTERWORLD) - Most information technology managers have already devoted long hours to shoring up their companies' security -- and they can expect more of the same in 2006. Attacks will likely come faster and with less warning, and experts predict that there will be attempts against a new range of applications and devices.

Bank of Americaなどがデータセキュリティで共通のガイドラインを制定へ

THE WALL STREET JOURNAL 2006年2月1日

Bank of America Corp. 、Bank of New York Co.、Citigroup Inc. 、J.P. Morgan Chase and Co. 、U.S. Bancorp 、Wells Fargo & Co.が集まって、機密データの保護方法の開示に対して、より系統だった方法を取らせるようコンピュータサービスプロバイダに圧力をかける方針を2月1日に発表する。
Member Only

EU法規制の概要

Compliance Regulatory Overview: European Union legislation
http://techrepublic.com.com/5208-11179-0.html?foru... - Dec 5, 2005

Lesson 6 of 7

In the United States, the Health Insurance Portability and Accountability Act (HIPAA) addresses the need to protect private and sensitive data. For members of the European Union (EU), those issues are the focus of the European Data Protection Directive of 1995.

The European Data Protection Directive, along with the requirements of Basel II and the UK Data Protection Act, offers the major compliance frameworks for members of the EU.

European Data Protection Directive

The directive sets up a regulatory framework that seeks to strike a balance between a high level of protection for the privacy of individuals and the free movement of personal data within the EU. To do so, the directive sets strict limits on the collection and use of personal data and demands that each Member State set up an independent national body responsible for the protection of these data. Another section of the directive calls on Member States to determine more precisely the conditions under which the processing of data is lawful.

The directive states that personal data must be:

  • Processed fairly and lawfully.
  • Collected for specific, explicit, and legitimate purposes.
  • Adequate, relevant, and not excessive in relation to the purposes for which they are collected.
  • Kept in a form which permits identification of data subjects for no longer than is necessary.

For details on the directive, which covers the processing of personal data including automatically processed data and manual data in a filing system, see EU Data Protection Directive (EU DPD).

Basel II

Gramm-Leach-Bliley and Sarbanes-Oxley require that U.S. financial service organizations put safeguards in place to increase data security. For members of the EU, similar safeguards are addressed in Basel II, which requires that financial organizations meet both reporting and risk assessment requirements.

UK Data Protection Act

The UK Data Protection Act makes it a legal obligation for anyone processing personal data to establish good practice in managing and using the data. Anyone processing personal information must comply with eight enforceable principles of good information handling practice. The act covers any organization that collects personal data.

For a comprehensive list of European Union compliance resources, used with permission of RSA Security, see page two.

Next Page

European Union compliance resources

  • EU Data Protection Directive (EU DPD)
    The directive covers the processing of personal data, including automatically processed data and manual data in a filing system.
  • Basel II
    The Basel II regulation intends to better align bank capital requirements with underlying risk. Basel II applies to global financial services organizations, specifically internationally-active banks with assets greater than $250 billion or foreign exposures greater than $10 billion.
  • UK Data Protection Act
    The act makes it a legal obligation for anyone processing personal data to establish good practice in managing and using the data.
  • Money Laundering Regulations 2003
    Businesses must appoint a money laundering reporting officer (MLRO) to train employees on the relevant principals and requirements of the legislation, verify the identity of new clients, and maintain records of client identification and transactions for five years.
  • The Companies Act 1985 (Investment Companies and Accounting and Audit Amendments) Regulations 2005
    These sets of regulations amend the Companies Act of 1985 and introduce the need for an Operating and Financial Review. This must contain a fair review of the business of the company and a description of the principal risks and uncertainties facing the company. This review must also include business analysis via key performance indicators.
  • Privacy and Electronic Communication Regulations 2003 (EC Directive)
    The legislation protects the public from electronic marketing practices that cause nuisance, offence, and invasion of privacy.
  • The Freedom of Information Act 2000--UK
    The act states that public authority information cannot be altered, defaced, or destroyed. Public authorities need to implement effective records and document management systems.
  • The Turnbull Guidance 1999
    Known as "Internal Control: Guidance for Directors on the Combined Code," this regulation's principal aim is to encourage companies to identify and manage internal and external risk within their organizations.
  • EU Annex 11, Computerized Systems
    The central consideration of this regulation is that "records are accurately made and protected against loss or damage or unauthorized alteration so that there is a clear and accurate audit trail throughout the manufacturing process".
  • Payment Card Industry (PCI) Data Security Standard
    This information security standard enables merchants and service providers to assess their security status by using a single set of security requirements for all payment organizations.

White papers

  • Data Protection: A Global Challenge
    This paper from PeopleSoft provides insight into portions of the European Data Protection Directive, and focuses on some controversial issues, international initiatives, and the Internet. It also describes some of the features PeopleSoft products provide to facilitate enterprises' compliance with data protection laws.
  • Basel II Compliance: The Data Management Challenge
    The New Capital Accord from the Basel Committee on Banking Supervision ("Basel II") effects sweeping changes in the way many financial companies collect and analyze data. This IBM paper discusses the data management challenges that companies will face during Basel II implementations, and how IBM's solutions can help financial companies meet those challenges.
  • Complying with confidence
    Whether it is Sarbanes-Oxley, Basel II, International Accounting Standards (IAS), HIPAA, or the USA Patriot Act, integrating information in support of compliance is not a one-off proposition. Compliance requires ongoing and constant enforcement. It's never a matter of simply checking a box and then moving to another project. Companies typically dedicate one or two people solely to compliance projects. Read this paper from the Sarbanes-Oxley Compliance Journal to learn how to effectively handle data integration and provide visibility.

Course list

Sign up for the Compliance Regulatory Overview series

If you haven't subscribed to this series, automatically sign up today to receive the entire Compliance Regulatory Overview series in your inbox.


Computerworld Legislation
http://www.computerworld.com/governmenttopics/gove... - Dec 6, 2005

Security Conforms To Regulatory Compliance
By Helen D'Antoni InformationWeek 8 29, 2005 12:00 HM
Business-technology professionals spend nearly one day a week dealing with industry- and government-related issues, according to InformationWeek Research. AMR Research expects compliance-related spending to hit nearly $15.5 billion this year. The cost for a typical company is estimated at approximately $500,000. Regulatory compliance is influencing security practices. Of the 2,540 U.S. business-technology and security professionals who recently participated in our 2005 Global Information Security Survey, an editorial research product of InformationWeek and management-consulting and technology-services company Accenture, more than half report that government regulations have pressured their company to adopt a more-structured approach to information security.

More stories on InformationWeek Research's
U.S. Information Security Survey 2005


  • The Threats Get Nastier
  • Sidebar: A New Type Of Worm
  • Sidebar: Source Of The Problem
  • Report: U.S. Information Security 2005
  • Tool: Compare Your Security Practices

    Accenture

  • Security and Privacy Compliance Download the full article [PDF, 178K]
    Client Successes
  • eCommerce Startup: Secure Infrastructure Implementation
  • European Bank: Electronic Banking Service Reengineering
  • European Mint: Electronic Tax Filing System Infrastructure
  • Health Care Organization: Electronic Information Exchange Solution
  • QinetiQ: Leveraging End User Computing Transformation for Improved Business Productivity
  • Spanish Ministry of Labor and Social Security: Human Services
  • Telecommunications Startup: Technology Environment Security Plan

  • Global Information Security Research Highlights

    The Research Results are In—Accenture and InformationWeek Global Information Security Survey

    Alastair MacWilsonI am pleased to share the results of the Accenture and InformationWeek Global Information Security Survey. In its eighth year, the research examines the security drivers, challenges and opportunities as expressed by 2,540 US business-technology and security professionals.

    The research reveal that regulatory compliance, internal attacks, and the vulnerability of electronic communications—especially instant messaging and e-mail—are among the key factors reshaping data security systems.

    Key Findings:

    • Compliance is reshaping corporate security practices, yet is having little impact on technology decisions.
    • Security attacks are becoming increasingly more sophisticated, yet basic passwords continue to be the most common line of defense.
    • Security breaches are increasingly coming from within, forcing companies to keep tabs on their employees.
    • Vulnerabilities in operating systems and applications—including the use of instant messaging—continue to be common points of entry.
    • Concern continues to grow over privacy and identity theft, yet organizations are failing to provide rigorous protection of customer data.

    Security and Vulnerability Management

    CA NAMED TOP SECURITY AND VULNERABILITY MANAGEMENT SOFTWARE
    VENDOR BY LEADING MARKET RESEARCH FIRM
    Follows IDC's Selection of CA as Top Identity and Access Management Software Vendor
    ISLANDIA, N.Y., December 1, 2004 ? Computer Associates International, Inc. (NYSE: CA) today announced that it has been named the worldwide market leader in Security and Vulnerability Management (SVM) software for 2003 by IDC with a 7.8 percent worldwide market share and revenues exceeding $94 million.

    Continue reading "Security and Vulnerability Management " »

    *eTrust Customer Success

    University of Verona Achieves Centralized, Secure Infrastructure Management Using CA Solutions
    Summary:

    “We immediately recognized in Unicenter all the features we considered indispensable…”-Dr. Giovanni Michele Bianco, Director of Information Services University of Verona Read Full Story | 88 KB PDF

    Continue reading "*eTrust Customer Success" »

    Sarbanes-Oxley Act

    The Sarbanes-Oxley Act (SOX) was signed into law on July 30th, 2002, and introduced significant legislative changes to financial practice and corporate governance regulation. It introduced strict new rules with the stated objective, “to protect investors by improving the accuracy and reliability of corporate disclosures made pursuant to the securities laws.” These rules are required to be met by certain deadlines. Most public companies must meet the financial reporting and certification mandates for financial statements filed after November 15th, 2004. Smaller and foreign companies must be in compliance for any statements filed after July 15th, 2005.

    Continue reading "Sarbanes-Oxley Act" »

    Health Care (HIPAA)

    The Health Insurance Portability and Accountability Act (HIPAA) is primarily focused on the health care and insurance industries but has far-reaching impact. Its primary intent is to allow employees to move between employers and continue to have health care coverage.

    Continue reading "Health Care (HIPAA)" »

    Compliance

    Compliance with regulatory mandates, such as the Sarbanes-Oxley Act, HIPAA, and the Gramm-Leach-Bliley Act, are increasing the drive for both desktop security and standardization. However compliance with organizational mandates, including corporate standard operating procedures (SOP) and process standards such as ITIL can be equally important to IT departments. Compliance management adds a new dimension to security and standardization solutions. By definition, compliance requires that an objective standard be met. In order to satisfy this objectivity requirement, organizations must implement solutions that can be monitored and measured against the compliance standard.

    Continue reading "Compliance" »

    2005 Global Security Survey

    Deloitte's third annual Global Security Survey was produced with input from Chief Security Officers and security management teams from financial services industry organizations around the world. It attempts to provide broad insight around the question: How does the information security of my organization compare to that of my counterparts?

    As this is the third year that we have conducted the security survey, we are now able to confidently observe differences from previous years as well as future trends. Results of this year’s survey show cause for both congratulations and concern.

    Continue reading "2005 Global Security Survey" »

    欧州ネットワーク情報セキュリティ委員会

    ENISA:European Network and Information Security Agency
     EU機関と各加盟国における公益事業、金融、テレコム等のITインフラのセキュリティとリスクマネジメントをサポートすることを目的に2004年3月に創設された。ENISAの具体的なビジネスモデルは、未だ発表されていないものの、加盟国の行政機関や民間企業と連携しながら、EUと加盟国にアドバイスをすること、そしてIT分野におけるセキュリティ確保とリスクマネジメントのベストプラクティスを普及させることが主要業務とされている。国際的なサイバー犯罪への対応を専門とするEU機関が今まで存在しなかったこともあり、官民ともにENISAの今後の活躍を期待している。

    ドイツの情報セキュリティ政策

     軍事・外交を除くと、行政・立法・司法に関する多くの権限が連邦州政府に移管されている。また、連邦政府の権限の一部は欧州連合レベルでの調整を必要としている。情報セキュリティ分野においては、軍事・外交・経済面でのグローバルな対応が必要なことから連邦政府が権限をもっている。しかし、その場合にも分権志向の連邦制度の与える影響を考慮する必要がある。

     情報セキュリティ分野では欧州連合がより大きな影響力を持つようになっている。2004年3月に欧州ネットワーク情報セキュリティ委員会(ENISA)が創設され、欧州連合レベルでの動きが活発になっている。

     ドイツ連邦政府では、内務省(BMI)が電子政府を含む情報政策全般を担当しており、その中のCIO室がITの戦略・政策・セキュリティを統括している。政府のITインフラの構築・運用については、CIO指揮下でKBStが担当している。情報セキュリティ施策は、BMIの一組織であるBSI(連邦情報セキュリティ局)が中心となって担当している。

    欧州におけるIT政策

     欧州のIT政策の基本目標は、欧州連合の企業・政府・市民が、世界的な知識情報立脚型経済の形成に中心的役割で参画できる環境を作り上げることにある。これは、2000年3月にリスボンで開催された欧州連合サミットにおいて、欧州連合の社会経済政策の第一目標として掲げられ、同時に、2010年までに世界最大の知識立脚型経済の実現を目指した総合戦略(通称「リスボン戦略」)の一環として、より明確な位置付けが行われた。2004年11月に発表された中間評価報告書では、現状はその目標達成には程遠いという厳しい評価が下されている。

     欧州連合のIT政策の最大の特徴は、それが情報社会政策と呼ばれるように、情報技術を通じた幅広い経済社会の変革を目指すことにある。これは技術としてのITの影響力が広範かつ深甚であることにもよるが、欧州連合の場合は、域内統合を基礎としたEUの理念そのものとも関係している。また、域内統合政策との関係は、現在の欧州委員会における情報社会政策の実施体制にも反映されている。

    Continue reading "欧州におけるIT政策" »

    Compliance WHITE PAPER

    Notable New Issues

    ComplianceINSIGHT: Health Insurance Portability and Accountability Act (HIPAA)
    This in-depth white paper provides a solid definition of the Health Insurance Portability and Accountability Act (HIPAA), some of the surrounding interpretations of HIPAA's key sections, and how to deal with what an IT staff needs to understand, do, and document in order to bring internal controls in line with HIPAA security requirements. It also provides insight into specific tools and technologies available to simplify compliance initiatives.
    Offered By: ITCi

    ComplianceINSIGHT: Sarbanes-Oxley
    From regulatory requirements to IT impacts and technology solutions

    ComplianceINSIGHT: Sarbanes-Oxley takes an in-depth look at the SOX sections which hold the most impact for IT departments, including 403, 404, 802, and 1102. This paper evaluates SOX's original intent, its IT implications, and 10 steps necessary to sustain SOX-compliance benefits. Insight into specific compliance tools, and a sample top-down compliance plan are also given.
    Offered By: ITCi

    Top 10 Reasons Why ITIL Implementations Fail
    Learn how to make your ITIL implementation successful with a complimentary white paper from BMC Software. Gain valuable advice about solving common ITIL challenges and learn how to deliver reliable IT services that support business goals. Leading ITIL expert Malcolm Fry tells you how.
    Offered By: ITCi

    Continue reading "Compliance WHITE PAPER" »

    POLICY AND LEGISLATION

    Policy and Standards
    A factsheet that explains the policies and standards related to information security, including associated terminology and advice on implementation.
    Download PDF(109 Kb)

    Legislation
    Introduces some of the legislation relating to information security.
    Download PDF
    (124 Kb)

    Continue reading "POLICY AND LEGISLATION " »

    Information Security, DTI

    The Information Security market was worth £865 million in the UK in 2002. The UK industry is widely recognised to be highly innovative and has led the way in the development of standards and good practices, notably with the BS7799 standard. However, it has generally failed to build successful mass-market suppliers in a market that is dominated by overseas companies, particularly from the US. In practice the market is fragmented on both the supplier and the user side. Many companies have no single point of responsibility for their information security, and purchasing is often split across several departments. One of the reasons for this is that security is often viewed as a bag of technologies by both buyer and seller, rather than a coherent framework built around robust policies and procedures.

    The prime responsibility of the DTI's Information Security Policy Team is to help UK businesses address this issue, and manage their information security more effectively. We work with business to:

    ・identify the barriers to the adoption of new technologies
    ・raise awareness of the importance of effective information security management
    ・develop guidance on good practice in information security. This includes the development of 'ISO/IEC 17799/BS 7799: A Code of Practice for Information Security Management'
    ・develop solutions to emerging problems. This has included the new arrangements for Trusted Third Parties that provide cryptographic services
    ・promote the development of appropriate international standards and a regulatory framework that encourages the uptake of electronic commerce

    Continue reading "Information Security, DTI" »

    Compliance, Information Assurance Governance Framework

    Introduction

    In the context of the framework, ‘compliance’ is taken to be a measurement of the degree to which security practice in an organisation accords with the documented security requirements and standards.

    This definition encompasses the idea that an organisation could be partially compliant, and also the concept that compliance must be against something - an agreed set of procedures or a defined target state of affairs.

    Principles of Governance

    Cabinet Office requires UK Government departments to have developed an ISMS demonstrating compliance with ISO/IEC 17799 for all their nominated key information systems.

    ISO/IEC 17799 identifies two kinds of compliance:

    • compliance with legal and regulatory requirements; and
    • physical, personnel, procedural and technical compliance, primarily against the stated security policy.

    In practice the applicable legal and regulatory requirements will normally be documented within the security policy; consequently the target for compliance is the agreed security policy. However, this section of the framework is nevertheless based on the ISO/IEC 17799 division.

    Continue reading "Compliance, Information Assurance Governance Framework" »

    ThruVision Ltd

    – Launching a New Era in Security Screening (2004 Competition Winner)

    Hidden guns, explosives and contraband will be easier to detect thanks to revolutionary radiation-free imaging technology developed by ThruVision Ltd. Winners of the £25,000 top prize in the 2004 Research Councils Business Plan Competition, the company is due to start rolling out a range of security screening products at the end of 2005.

    A spin-out company from the CCLRC Rutherford Appleton Laboratory in Oxfordshire, ThruVision aims to become the leading commercial provider of compact security screening equipment using terahertz imaging technology. This technology works by detecting the terahertz waves that all people and objects emit. Because no X-rays or other types of ionising radiation are used, health and safety is not a concern.

    Link

    イギリスの情報セキュリティ政策

    中央政府の各省庁が個別に研究開発資金を提供している。民間の重要なインフラのセキュリティ対策は「国立インフラストラクチャ・セキュリティ調整センタ(NISCC)」が担っている。一方、大学などの学術研究機関への研究助成は「工学・物理・科学研究評議会(EPSRC)」が行っている。

    NISCC
    1999年に設立され、広く国家安全保障に関係する省庁からの出向者85名(2004年60名)で構成されている。内務省、セキュリティサービス(MI5)、貿易産業省、警察、国防省が関係している。NISCCの2003/2004年度予算は515万ポンド(約10億円)で、2005/2006年度は1000万ポンド(約20億円)となっている。予算額はセキュリティレベルに応じて決定されている。セキュリテュレベルの評価は内務省が行っている。⇒What is the Critical National Infrastructure?

    EPSRC

    Continue reading "イギリスの情報セキュリティ政策" »

    CSOs seek regulatory sanity in 2006

    By Bill Brenner, Senior News Writer
    26 Dec 2005 | SearchSecurity.com   LINK

    CSOがもっとも苦労しているのが法令遵守への対応である。
    Sarbanes-Oxley (SOX)
    Gramm-Leach-Bliley
    Health Insurance Portability and Accountability Act

    これらの法律に対応すると同時に業界の自主規制、たとえば Payment Card Industry (PCI) Data Security Standard にも対応していかねばならない。 2005 年は ChoicePoint Inc., Lexis-Nexis Group and CardSystems Inc. にとって受難の年であった。この傾向は2006年も続き、California's Security Breach Information Act (SB-1386)をはじめとした州法にも対応していかなければいけない。現在39の州が類似の法整備に着手している。

    White Papers
    The Sarbanes-Oxley Act: A Business Blessing in Disguise
    Case Study: Managing Powerful Users Helps C&D Technologies Meet Sarbanes Oxley Requirements (The PowerTech Group)
    Successful Compliance Strategies -- a SearchCIO.com Research Guide (SearchCIO.com, Sponsored by Symantec)
    Achieving Regulatory Compliance for IT Change and Configuration Control (BMC Software, Inc)
    Achieving Regulatory Compliance for Identity Management Control (BMC Software, Inc)

    Top trends for 2006!

    Are you wondering what to watch out for in 2006? Worried about when the next big scare is going to hit? SearchSecurity.com is the perfect place to stay up to date in 2006. From the editors of Information Security magazine and SearchSecurity.com, compiled below are recent news stories designed to give you a 'sneak peak' of what's to come.

    Spyware, application attacks to be biggest 2006 threats
    Security experts say virus writers will turn their attention to spyware in the year ahead, victimizing many still-unsuspecting users. Application-specific attacks, phishing and data exposures will also plague security pros.

    CSOs seek regulatory sanity in 2006
    IT security officers long for a common system to comply with laws that are similar, but often have conflicting demands. Some say a single set of federal guidelines could help, but others fear the implications.

    End of spam, phishing threats not far off
    Viruses, spam and phishing aren't going away overnight. But for 2006, one research firm says a new set of messaging security threats will take center stage.

    米国国土安全保障省

    同時多発テロを受け、米国を防御し、国民の自由を守るため国土安全保障省(Department of Homeland Security、以下DHS)が2003年に設立されている。日本ではテロ対策よりも地震災害を想定して、ITに依存するライフライン(重要インフラ)のセキュリティ対策への関心が高まってきている。ここでは重要インフラへの脅威とそこからの防護について紹介する。

    Continue reading "米国国土安全保障省" »

    ITU Cybersecurity news

    ITU SPU Newslog
    ★ News from the ITU SPU Newslog related to