Saturday, July 10, 2010
A Bad Week for Higher Ed Security Breaches
A few days ago I read about the University of Hawaii - Manoa data breach affecting about 53,000 people. Their parking office system was hacked, and they lost a lot of data from Social Security Numbers to payment cards (take a look at your school's parking permit application, and you get an idea of what was lost).
Then I learned about the breach at the University of Maine that was also announced this week. This didn't involved payment cards, but once again their security was found lacking.
Then to cap things off the whole topic of security in Higher Ed got more visibility with an article in Dark Reading entitled University Databases in the Bull's Eye. The author details these two breaches plus more.
All of this points up the importance of securing your data - all of it. Yes, I know this blog is about PCI DSS and protecting cardholder data, but you also have a lot of other personally identifiable information (PII) lurking in your computers, and you need to comply with HIPAA, too.
The bad guys are out there and they are targeting a number of industries including Higher Ed. That means you are in the "bull's eye." Make sure you are compliant all 365 days a year. You may have vulnerability scans quarterly to meet your PCI requirements, but remember you are being scanned by the bad guys a few hundred times an hour. The difference is they don't give you a report of your vulnerabilities, so maybe give a thought to more frequent (e.g., monthly) scans. Also make sure you reduce your scope. If you are storing cardholder data (like the unfortunate people at UH-Manoa) ask yourself: WHY!!! Is it worth the risk? When did you start putting your institution at risk under the false banner of "customer service?"
Lastly, watch out for data seepage. Most of you who retain cardholder data know where those data are...you hope! Often it is the faculty or staff workstation that has old data and was never purged that is vulnerable. Another risk is when the data are stored (against policy, but gosh, it sure was convenient...) and you don't know about it. Are you using a data discovery tool to find these data seepages?
Lots to think about during these summer months.
Tuesday, June 15, 2010
PCI DSS Lifecycle Webinar
According to the Council's press release:
The one hour webinar, hosted by PCI SSC General Manager Bob Russo, will provide a brief update on the lifecycle used to manage PCI Security Standards development, followed by a live Q&A session.You need to submit questions in advance to a website listed in the press release.
The presentation will outline:
- PCI SSC standards development
- Overview of current lifecycle
- Changes to current lifecycle
As I've previously noted, the Council is evaluating whether to go from the present 2-year lifecycle for DSS to a 3-year lifecycle. The longer time reflects the stable nature of the DSS and matches better with the other standards managed by the Council.
This webinar is the latest in what appear to be a series of communications from the Council leading up to the revised DSS due in October. Bob Russo has promised there would be "no surprises" by the time of the September Community Meeting, and it looks like he and his colleagues are keeping their word.
Friday, May 21, 2010
Memory Sticks Complete with Pre-Loaded Malware
Dear AusCERT Delegate,
At the AusCERT conference this week, you may have collected a complimentary USB key from the IBM booth. Unfortunately we have discovered that some of these USB keys contained malware and we suspect that all USB keys may be affected.
The malware is detected by the majority of current Anti Virus products [as at 20/05/2010] and been known since 2008.The malware is known by a number of names and is contained in the setup.exe and autorun.ini files. It is spread when the infected USB device is inserted into a Microsoft Windows workstation or server whereby the setup.exe and autorun.ini files run automatically.
Please do not use the USB key, and we ask that you return it to IBM at Reply Paid 120, PO Box 400, West Pennant Hills 2120.
If you have inserted the USB device into your Microsoft Windows machine, we suggest that you contact your IT administrator for assessment, remediation and removal, or you may want to take the precaution of performing the steps below.
Thursday, May 20, 2010
Advice for Keeping Your PC (or Mac) Safe
- Protect your browser. If you run Firefox, get NoScript (personal recommendation).
- Download the Adobe updates as they come in, and the sooner the better. PDFs are an increasingly common vector for malware, so keep things patched.
- Don't click on malicious ads. Duh...How about: Don't click on ANY ads!?! And especially, ESPECIALLY don't click on any pop-up telling you that your computer is infected and you need to upgrade your anti-virus. Check with your IT or security department -- that's what they do for a living, and most neither need nor want our help.
- Watch out for poisoned search results. After every disaster, celebrity dust-up, or major news story hundreds of sits spring up with similar-looking URLs to lure you to a site loaded with malware. The bad guys know how to tweak the search engine results, so steer clear of one-off sites.
- Keep away from social exhibitionism -- er, networking -- sites using any computer that you might remotely want to use for business.
Wednesday, May 19, 2010
PCI is Required - Even if Your Bank Doesn't Call You
Thursday, May 13, 2010
PCI Council Releases New PCI PTS Today
As merchants, the big thing for you to know about this is that if you are replacing or upgrading your PIN devices, you need to go to the PCI Council website and look at the list of approved devices. Many of the requirements in v3.0 won't be effective for about a year, but that doesn't mean you should buy PIN pads or kiosks that accept PIN-based debit or anything that takes a PIN that isn't on this list.
Friday, May 7, 2010
PCI Workshop #7 Is Over
Two other highlights were our keynote speakers, Anton Chuvakin and Bob Russo. You can read Anton's take on the workshop (hint: he found it an education, too!) here and even download his best PCI presentation ever. BTW, if you download it, you might not want to share the 'kitten bit' slide (see his post script) with your children... Bob's always dynamic and informative presentation covered developments at the PCI Council including some general ideas, but nothing on the revisions to PCI in October. (Note: Bob made me promise not to blog about anything he said, so I am not going to get in trouble with him...again...)
Our expert panel -- which included both Anton and Bob plus Don Roeber of Fifth Third Processing Solutions and Marco Mabante of Elavon -- was outstanding. They answered questions on PCI scoping, hotel compliance, tokenization and end-to-end encryption, SAQs, and a whole host of specific attendee questions.
Congratulations to Dennis Reedy and the Treasury Institute for a great workshop. If you missed it, mark your calendars for early May next year when we'll do it all again but with a completely different program, as usual.
I don't know about the rest of the attendees, but I'm pooped. So I found the perfect way to relax and recharge: I'm running the 500 Festival half-marathon tomorrow (Saturday). Wish me luck!