IT News & Technology update

Provide comprehensive update related to Computer, technology, software, anti virus and another electric device

Top 3 Medical Organizations to lose data in 2008

Written by IT News on 1:45 PM

IT security world continues to be plagued by incidents of data loss; laptops with confidential data are stolen or lost at airports, have disks, USB memory devices are hidden, and so forth. According technology blue chips, among all the things that cause data to be lost, human error accounts for 26% of everything. Let's see now the first three companies that manage to lose private, confidential data this year and the number of people affected by these incidents.

No sooner does not begin by 2008 Horizon Cross Blue Shield Blue found in one of its laptops were stolen. On 5 January, a laptop containing information about 300000 people covered by Horizon was stolen while in custody of employees who have not yet been identified. Thankfully, the data on the laptop was password protected and scheduled to automatically delete itself in 17 days' time (23 January).

In February, from one blood bank Memphis, called the lifeblood lost two laptops containing information on 321000 donors. The amount of information collected for each donor is truly amazing: name, address, birth date, social security numbers, phone number and email address, driving license, and of course blood type. One question arises: how much private information, should you give, to donate blood?

Number one spot goes to Scotland of the Office for Emergency Assistance Services, which in June lost data staggering 894629 calls to emergency services for a period exceeding one year. It seems that the data are stored data on portable disk, which was entrusted to the courier company TNT, so that they can be transported by TANTRA to Glasgow. At least the data is encrypted and password protected.

Note that the ranking is presented above in respect of organizations which specialize in medical services. Currently all the winner when it comes to loss of data is U.S. Department of Veterans Affairs, which managed to lose data for 28.6 million people in May 2006.

Phishing and pharming

Written by IT News on 11:07 PM

Using a variety of nefarious methods, phishing and pharming are a consistent problem that threatens everyone with identity theft. If you recognize what these methods are and how malicious users employ them, you can keep yourself and your users from becoming a victim.

A quick review

Phishing involves sending an e-mail that claims to be a legitimate business in an attempt to scam the user into surrendering private information. Pharming involves the same goals with a different method; malicious users employ spyware, keyloggers, domain spoofing, domain hijacking, or domain cache poisoning to obtain personal or private (usually financial) information.

To put it bluntly, criminals try to steal your identity by getting you to divulge financial data such as credit card numbers, account usernames, passwords, and social security numbers. They sell this information, and it then becomes an identity theft crime.

Recognize the methods

The primary method for this crime is to send e-mails that look like valid correspondence coming from a bank asking users to click the link provided and log into their account for some type of important information. But your bank and other institutions where you do business don’t work this way. They may send you an e-mail and ask you to review or verify information. However, they don’t send links to a Web site. You already do business with them, and they know you don’t need the link to the Web site.

If you click that link, one of two things is going to occur. It could download spyware onto your computer, which will then capture your personal information and send it to the criminals. Or, the link will direct you to a Web site that looks and feels like the site you expected — but it’s actually just a front to collect your login information to help the criminals harvest your personal information.

Fight back

To protect yourself and your users against phishing and pharming schemes, here are four rules to live by:

  • Rule 1: Stop clicking links in e-mails that direct you to your bank or a financial institution. Stop filling out forms sent to you by your bank or financial institution. If you want to visit the site to see if you need to confirm/update/verify your account, open up a browser and type the link or retrieve it from your favorites.
  • Rule 2: If you suspect an e-mail is part of a phishing scheme, report it. Report it to the financial institution, the FTC, and the Internet Crime Complaint Center.
  • Rule 3: Update your browser, your antivirus software, and any other security software. The latest versions of such software have phishing filters that detect attempts and warn you if it suspects you’ve surfed to a site that isn’t legitimate.
  • Rule 4: Stop using public computers to access private information. Internet kiosks at hotels and other business are convenient but often have Trojans and keyloggers installed that collect and transmit your information to the criminals. Access personal and financial information only from a computer you trust to be free from these evils.

Final thoughts

Criminals have learned that they don’t need to pull a gun on you to get your wallet or purse. They’re using the Internet to steal everything in your accounts — and your good credit too. Take a few simple steps to stop them, and don’t become an identity theft statistic.

Take steps to safeguard sensitive data

Written by IT News on 9:56 PM

Is your organization responsible for complying with one or more of the many privacy-related pieces of legislation that the U.S. government has enacted over the past decade? It’s a good bet that it is.

Whether it’s the Health Insurance Portability and Accountability Act (HIPAA), which addresses healthcare information, the Gramm-Leach-Bliley Act (GLBA), which addresses financial information, or even the Family Educational Rights and Privacy Act (FERPA), which addresses education information, chances are good that one of these affects your organization in some way.

Compliance is nothing to fool around with, and it’s imperative that your organization understand its responsibilities for safeguarding protected data. Protected data is any information that someone could use to identify an individual. Information protected by legislation can include:

  • Salary and fringe benefits (except for federal employees)
  • Terms of employment (including performance and disciplinary records)
  • Academic and educational history
  • Criminal investigation and arrest history
  • Employment history (including general or security clearance information)
  • Biographical history
  • Social Security information
  • Identification codes
  • Personnel profile (including home address and phone number)
  • Medical history

Your organization’s network obviously contains and/or processes protected sensitive information. Unauthorized disclosure of such sensitive information could adversely impact your organization with both civil and criminal liabilities. To protect yourself and your company, it’s vital that you implement some extra precautions.

Administrator responsibilities

If you’re responsible for the security of your company’s network, then you’re also responsible for overseeing the day-to-day collection, storage, and use of personal data subject to such legislation. You must apply adequate data security safeguards to protect data from the following:

  • Inappropriate disclosure
  • Improper use
  • Access by unauthorized or unapproved users
  • Data tampering

Individuals who fail to follow specific requirements can face fines up to $5,000 per violation, as well as misdemeanor charges. That’s one more reason your organization needs to take appropriate security measures to protect sensitive information. But don’t forget that security measures, no matter how solid, are only as good as the educated employee who wants to do the right thing.

Employee responsibilities

An organization’s users are potentially the weakest link in your security efforts. You’ve heard it before, but it’s worth repeating: Educate your users.

To better protect sensitive data, train all users to do the following:

  • Label all media (e.g., disks and documents) containing sensitive information.
  • Securely store sensitive information.
  • Immediately notify supervisors of any security breach.
  • Don’t send unencrypted sensitive information via e-mail.
  • Log off or use a screen saver with a password when leaving workstations unattended.
  • Erase all data from hard disks before sending PCs off-site for maintenance.
  • Store data on network drives instead of workstations.
  • Be on the lookout for hardware keystroke loggers.

Final thoughts

Privacy-related legislation grew out of a concern over the potential misuse of the vast amounts and types of personal information collected and maintained on corporate networks, which store, manipulate, and transmit the data for a variety of reasons. Don’t become a statistic in the news by mishandling protected information — protect that information with adequate safeguards, and train your users to do the same.

Mike Mullins has served as an assistant network administrator and a network security administrator for the U.S. Secret Service and the Defense Information Systems Agency. He is currently the director of operations for the Southern Theater Network Operations and Security Center.

Search This Blog

Ads and Sponsored by:



Want to subscribe?

Subscribe in a reader.