Security Is Still a Study of the Basics
Lauren Bielski · ABA banking journal · 2007
Susan Orr spent 14 years as an FDIC bank examiner, holding positions that include regional IT examination specialist, special assistant to the regional director, special assistant to the director of DSC, and special assistant to the vice-chairman. Susan was also a Lead instructor for the FDIC's technology school and worked on projects such as FDIC E-Risk Strategic Initiatives Risk Monitoring Committee and the Federal Financial Institutions Examination Council IT Handbook rewrites. Currently she heads Susan Orr Consulting, based in Naperville, Ill., with duties that include regulatory reviews for banks. Recently, she spoke with ABA BJ Senior Editor Lauren Bielski about what she's been seeing at client sites and what her sense is of current concerns and issues. How would you describe the security stance of the industry? On the whole, banks are doing a pretty good job safeguarding digital information and protecting systems. Given the regulatory scrutiny, this makes sense. They are fairing better than, say, mortgage providers or other financial services firms, which are still learning the basics, as a rule. But really, conditions vary pretty significantly from bank to bank. Companies that are the most proactive are doing things like monitoring employee internet usage and blocking specific sites to prevent abuse. Or, they are using log correlation tools to monitor network usage in real-time to get a dearer sense of who is using what applications and systems, and if there is any inappropriate access and usage. Basically, they are creating visibility into a complex operating environment and attempting to ensure some policy enforcement. Because regulators have been insisting on better perimeter controls as well as controls on key infrastructure and application areas, like internet banking or the core processor, most banks have those systems protected fairly well. Most are also savvy, and are trying to catch up on other malware trends, such as blended threats [e.g. virus worms or Trojans with embedded html files]. And yet, there's room for improvement out there. I'll still find a bank that doesn't have an Information Security Program developed, which seems hard to believe given how much has been written about the importance of policy. What are some foundation elements or key basics of improving your security effort? Well, developing a usage policy is critical. GLBA requires a comprehensive information security plan, and when I review bank plans, I use the International IS0 17799 standard, which addresses systems access control, operations management, system development and maintenance, and even physical and environmental security. But the risk assessment is an equally important part of preparation. You have to learn your operational profile and the gaps unique to your company. I see a lot of confusion around risk assessment. People tend to look very narrowly at the practice. There was confusion in recent times when regulators used language such as IT risk assessment versus assessment of information risk. In truth, you can't took at information or systems out of context. Also, being secure requires more than controlling digital information. How are documents being handled? What's going on at that shredder? Are you using it consistently? The whole area of social engineering is a tough one. Yes, people don't understand how easily information can be taken or be exposed to unauthorized access. A lot of work still needs to be done in what I'd call facilities protection. When I walk through offices, I still see desks with a lot of important paperwork exposed--loan documents, documents that only senior officers and board members should have access to that are left on cabinets--that sort of thing. Again, it's not every place, but I see it enough to mention it. The thinking is that everyone knows the employees and there is no reason for vigilance. Yet you don't always know who's gotten in the building under false pretenses, or who has gained access after hours. …