ISACA applauds plan to boost Information Commissioner's Office powers

Rolling Meadows, IL, USA, June 2009 (Eskenzi PR) – ISACA (formerly the Information Systems Audit and Control Association), a not for-profit organisation that seeks to encourage best practice in the ITsecurity industry, has given the `thumbs up' to plans to significantly increase the powers of the Information Commissioner's Office (ICO) later this year.

"Last July, in his outgoing report, Information Commissioner Richard homas criticised the EU data protection directive - which underpins the UKs Data Protection Act - for effectively showing its age," said Vernon Poole, CISM, Member of ISACA’s Information Security Management Committee and Head of Business Consultancy for Sapphire.

"Reports now suggest that the UK Government will enhance the powers of the ICO, allowing it to raise penalties against data controllers, under Section 55A of the Data Protection Act," he added.

According to Vernon Poole, under Section 55A of the Act - which the Ministry of Justice has reportedly set an internal target for implementation on for later this year - the Information Commissioner will be able to impose penalties on companies that fail to protect their data, when that data is subsequently lost.

Current Government practice, he says, is to provide statutory guidance at least 12 weeks before the legislation comes into force.

The original game plan, he explained, was for the penalties to be published in March of this year, ready for Section 55A of the Act to become law this month.

These dates have now passed, he says, but if the internal target is to pass the legislation amendment before the Parliamentary summer recess, then Section 55A could become law by the late Autumn of this year.

"This is good news as, at that stage, we will coming up on the second anniversary of the infamous loss of 15,000 pension customer details on a CD-ROM mailed between HMRC's offices in Newcastle and Edinburgh," he said.

"That incident became the milestone which started off a chain of reports of data losses in the public and private sector in the UK and effectively triggered the amendments to the DPA we now know as Section 55A," he added.

For more on the DPA Section 55A plans: http://preview.tinyurl.com/ljaujn

For more on ISACA: http://www.isaca.org.uk

With more than 86,000 constituents in more than 160 countries, ISACA® (www.isaca.org) is a leading global provider of knowledge, certifications, community, advocacy and education on information systems assurance and security, enterprise governance of IT, and IT-related risk and compliance. Founded in 1969, ISACA sponsors international conferences, publishes the ISACA® Journal, and develops international information systems auditing and control standards. It also administers the globally respected Certified Information Systems Auditor™ (CISA®), Certified Information Security Manager® (CISM®) and Certified in the Governance of Enterprise IT® (CGEIT®) designations.

ISACA developed and continually updates the COBIT®, Val IT™ and Risk IT frameworks, which help IT professionals and enterprise leaders fulfill their IT governance responsibilities and deliver value to the business.

<>

Responding to Cyber Criminals Finjan release SecureTwitter FREE to all users

No Way to Treat Twitter". Responding to Cyber Criminals Targeting Twitter, Finjan Made Available SecureTwitter FREE to All Users

Farnborough, United Kingdom, June 2009 (Eskenzi PR) – Finjan Inc., a provider of real-time web security for the enterprise market, today responds to reports on thousands of Twitter messages (tweets) embedded with malicious URLs targeting users and businesses.

Utilizing its patented real-time web security technologies, Finjan provides users and businesses with FREE access to SecureTwitter which is built into the latest version of SecureBrowsing. SecureTwitter is powered by Finjan's SecureBrowsing plug-in that provides users with look-ahead alerts on the safety of URLs showing in their Web 2.0 sites, Search results and Web Email applications such as: Twitter, Bebo, digg, Slashdot, Myspace, Blogger, MSN, Gmail, Google and Yahoo search.

"Reading the recent reports about the proliferation of tweets containing criminal malware, we have taken immediate action to release the SecureTwitter plug-in which is powered by Finjan's Secure Browsing as a free download to all users. SecureTwitter is effective, simple to use and based upon proven effective technology" said Yuval Ben-Itzhak, CTO of Finjan.

TO GET YOUR FREE COPY GO TO http://securebrowsing.finjan.com

CNN report on malicious URLs embedded in Twitter messages is available at: http://edition.cnn.com/2009/TECH/06/21/cyber.crime.internet/

Finjan Secure Gateway provides organizations with a unified web security solution combining productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies. Crimeware, malware and data leakage are proactively prevented via patented active real-time content inspection technologies and optional anti-virus modules. Powerful central management enables intuitive task-based policy management, excellent drill-down reporting capabilities and easy directory integration for all network implementation options. By integrating several security engines in a single dedicated appliance, Finjan’s comprehensive and integrated web security solution enables quick deployment, simplified management and reduction of costs. Business benefits include real-time web security (no patches or updates needed), lower total cost of ownership (TCO), cost savings in administration efforts, lower maintenance costs, and reduction in loss of productivity. Finjan's security solutions have received industry awards and recognition from leading analyst houses and publications, including Gartner, IDC, Butler Group, SC Magazine, eWEEK, CRN, ITPro, PCPro, ITWeek, Network Computing, and Information Security. With Finjan’s award-winning and widely used solutions, businesses can focus on implementing web strategies to realize their full organizational and commercial potential. For more information about Finjan, please visit: www.finjan.com.

<>

Digital Britain plan leaves Infosecurity Adviser bemused

London, UK, June 2009 (Eskenzi PR) - According to Infosecurity Adviser The Digital Britain paper - penned by Lord Carter and his team, and which sets out the game plan for broadband Britain in the future - has left the editor of Infosecurity Adviser, somewhat bemused.

The problem, says Mike Barwise, is that security is only dealt with in the broadest of brush strokes, whilst the recurring emphasis is digital.

The problem he adds, is that most security breaches are not digital, but analogue in nature, as they are caused by people.

"Whether it be failing to harden a web server to prevent malware injection, clicking on a dodgy link in an unsecured Web browser or leaving documents on trains, information security is fundamentally a human problem," he explained.

According to Barwise, who has some three decades-worth of experience in the IT industry, the report also makes no mention of the fundamental Internet security problem faced by today's general public, namely endpoint security.

As a result of the IT security issues, Barwise argues that evolving an effective digital Britain plan is a lot more complex than the authors of the `Digital Britain' blueprint suggest.

"I have practically never seen, in any office I have visited, anything other than a default installation of Windows on the desktop - and that default is not terribly robust," he said.

Barwise pointed out that browsing poorly secured legitimate web sites in this configuration can easily result in your computer becoming one of the several million zombies on the net, but improving your security may prevent you running some programs and viewing many web sites that have been created without considering the security implications. "So in addition to encouraging the sexy innovations that keep the IT market churning, we have to educate not only users but also the application programmers, Web designers and managers of corporate Web sites," he added.

And developing such a game plan requires the willpower to implement national programmes that take longer than the life of a Parliament to show effect.

For more on Mike Barwise's blog on Digital Britain skims over security: http://www.infosecurityadviser.com/view_message?id=122

Infosecurity Adviser is a unique community portal representing the information security industry and it's users, organized in association with Infosecurity Europe. It offers advice from industry experts and bloggers as well as end user product reviews. It also contains information on qualifications, career paths and jobs from all the major accreditation bodies and is supported by the Information Security Awareness Forum. For more information see http://www.infosecurityadviser.com

<>

Open Source Software in Business & Government

by Michael Smith (Veshengro)

Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still in the USA.

Open Source is a very wide field and for the purpose of this article we shall be talking just about operating systems such as Linux and applications and not Web technology.

When it comes to Open Source Operating Systems the most “common” one is Linux in its various distros, whether Fedora (Red Hat), SUSE, Ubuntu, etc., and while both governments and businesses in a great number of European Union member states on the European mainland have taken up such operating systems, including the most popular Linux in carnation, Ubuntu, against what is being offered by a certain company based in Redwood in the USA or even Apple, Britain lags very much behind here. The USA, so I am led to believe is worth even in that field.

The same is also true in government and, to a great degree also in business, as to other Open Source programs, whether those be office suites, photo editing programs, PDF creators and even PDF readers, etc.

It appears that most choose proprietary software over Open Source rather; this despite the fact that Open Source software such as, for instance, Open Office, a basically complete replacement for Microsoft Office, is free; no license required to buy and it can be installed without incurring costs on as many PCs as one would wish. The same with PDF creators and many other such pieces of software.

In a downturn-cum-depression as far as the economy is concerned both business and government should take a much closer and much more serious look at those options.

Open Office, in my opinion, is many ways far superior to MS Office as it can read most formats and can be defaulted to save everything in MS Windows format, for instance, thus making for great interoperability.

The learning curve is very flat as there are but very few differences between Open Office and MS Office; mostly only some keyboard shortcuts are different and some terms.

Users of Open Office's PowerPoint equivalent have told me – though I cannot judge as I do not normally use presentation programs; no need – that Open Office's version is more powerful that that of MS Office, that is too say PowerPoint.

The only thing that Open Office so far has not offered is an Outlook equivalent but it is possible, so I understand, to integrate Evolution Mail as an Outlook equivalent.

Personally I have been using Open Office 2.0 now ever since I fired up Ubuntu”Dapper Drake” and I have never looked back. The only shame is that the likes of Avery with their templates for labels and such are still locked into MS Word.
Templates are also, in general, in rather sort supply, unfortunately, for Open Office and it does not have a ClipArt collection either.
But, having said that, I must admit that I prefer Open Office to MS Office.

Is Open Office suitable for business and government? Yes, definitely, and it interoperability is much better.

All I am wondering is what everyone is waiting for...

© 2009
<>

Experts say Irish Gas Board data loss highlights need for digital vaulting of customer records

Cyber-Ark says Irish Gas Board data loss highlights need for digital vaulting of customer records

June 2009 (Eskenzi PR) - The theft of a laptop containing the bank account details of around 75,000 customers of the Irish Gas Board highlights a serious security procedure failing, rather than an unfortunate incident, says Cyber- Ark, the digital vaulting specialist.

The fact that the data on the laptop - one of four stolen from the Bord Gais offices and adjacent buildings earlier this month - was not encrypted is a very serious issue says Mark Fulbrook, Cyber-Ark's UK and Ireland Director.

"That's bad enough, but best practices in IT security mean that the sensitive customer data shouldn't have been stored on a laptop in the first place – it should have been digitally vaulted or at the very least encrypted locally and accessible only on a need-to-use basis," he said.
"And that need-to-use basis should only be available across the company's network, using authenticated and logged access procedures," he said.

Whilst there is a case for allowing access to customer records remotely, the information should never include customer payment details, and certainly not their bank account information unless through a secure channel with full authentication, encryption and security measures in place such as digital vaulting, he explained.

"But to store customer bank account data unencrypted on a laptop goes against all known IT security procedures. It's a very serious procedural error," he added.

For more on the Bord Gais laptop customer record fiasco: http://preview.tinyurl.com/lcxzup

For more on Cyber-Ark: http://www.cyber-ark.com

<>

Women's British Bobsleigh team zooms along with Origin Storage

Origin Storage carries on supporting Women’s British Bobsleigh team

Basingstoke, London, June 2009 (Eskenzi PR) - Origin Storage, the portable secure storage specialists, announced today that they have renewed their sponsorship of the women’s British Bobsleigh team. The sponsorship deal will run until the end of the season which will see them through the winter Olympics in Canada.

Andy Cordial, MD of Origin Storage, comments “Origin Storage is delighted to be involved with the team and is very proud of their success last season when they won Gold in the World Championships in the USA. Considering the quality of the competition, the achievements of the team last season was fantastic and puts them in a very strong position going into the winter Olympics. It is great to be a British company helping our home grown talent.”

More support needed
The Women’s bobsleigh team is still looking for companies to sponsor them. The sponsorship is a fantastic opportunity for an organisation to have their logo on the award winning bobsleigh and be associated with the success of a team that has potential to win an Olympic gold medal.

Nicola Minichiello, Member of the Women’s British Bobsleigh team, comments “Origin Storage has been a long standing supporter of the team and we are delighted to have them on board for this very exciting year. Sponsorship deals like this are very important as it allows the team to concentrate on training and fitness programmes. I would like to take this opportunity to personally thank Origin and wish them every success.”

To see the Women’s Bobsleigh team in action and for further details about sponsorship, please visit - http://www.teamminichiello.co.uk/

Founded in 2001 and based in Hampshire, UK, Origin Storage Ltd. is fast becoming one of Europe's leading IT storage manufacturers. Its wide-ranging product portfolio includes branded hard disk drive solutions, RAID solutions and OEM parts.

Origin Storage is a main supplier for all Tier one manufacturers, providing matched storage upgrades and has held a Pan European Agreement with Dell™ for the past five years. The business has grown year on year and now supplies to main distribution and reseller partners across EMEA.

In January 2006 Origin Storage acquired the brand and assets of Amacom and began to manufacture the Amacom range of portable storage solutions including the Flip2disk, IOdisk and Portable Optical solutions. It is also a distributor for some of the most respected storage enclosure manufacturers and offers a full range of rack, desktop and RAID products and accessories.

The company’s emphasis on superior customer service, UK-based assembly and stock-holding that delivers competitive pricing and unbeatable turn-around times makes Origin Storage the ideal partner for all storage management needs. - www.originstorage.com

<>

Experts say Parcelforce data leaks caused by code audit shortcomings

Fortify says Parcelforce data leaks caused by code audit shortcomings

June 2009 (Eskenzi PR) - Fortify Software, the application vulnerability specialist, says that the Parcelforce data leak - in which Web customers were given access to the entire customer records of seemingly random data relating to other customer's postal consignments - is almost certainly the result of shortcomings at the program code auditing stage.

"From what has been reported by the BBC and others, this sounds like a scripting issue with the site concerned," said Richard Kirk, Fortify's European director.

"What's interesting about the Parcelforce site is the scripts used on the main landing pages appear to have been developed in-house, rather than the firm relying on third-party interfaces. This suggests to me that the site was developed by an in-house programming team using Omniture's SiteCatalyst software," he added.

The problem with in-house development of Web sites, says Kirk, is that whilst the staff concerned can be well acquainted with the requirements of the company, they may well lack the facility of looking at the code from an audit perspective.

Things have moved on from the old days of `soak tests' with programs and Web sites, he explained, adding that his means that external professionals are usually asked to conduct a range of tests on the Web site software, even including penetration testing where appropriate.
Whether this happened or not remains to be seen, but the fact that customer data was leaked means that the company has probably breached the Data Protection Act, meaning that an investigation is likely.

The Information Commissioner's Office is reported to be contacting Parcelforce to work out what actually happened with the Web site errors and what can be done to prevent it happening again, said Kirk.

"Almost certainly this will involve some sort of audit. It is to be hoped that, as well as Parcelforce learning from this situation, that other companies realise it could be their own IT team involved in the corporate red face stakes and review their own Web sites as well," he said.

"Only by efficient code auditing can major errors like this be avoided. We all learn from mistakes. Some more than others," he added.

For more on the Parcelforce Web site errors: http://preview.tinyurl.com/m59pcy

For more on Fortify Software: http://www.fortify.com

<>