User Awareness Program

Protected: Managed Security Services Provider Limitations

Managed Security Services Provider Limitations As an Intrusion Prevention System / Intrusion Detection System (IDS / IPS) client, you should be aware of certain limitations of the intrusion prevention and detection process that are beyond our control. Note that every other v...

Twenty Eleven

Top Ten 2011 Bank Information Security Issues Our third year coming up with a “year-end article” for Dan’s New Leaf exudes a few new “controls” that we’ve implemented to mitigate “year-end article risk!”  Yes, new controls! I actually had enough...

Masquerading Web site: Helpwithmybank.com

Malware Website Alter! The Office of the Comptroller of the Currency (OCC) has been informed that the following Web site, “helpwithmybank.com,” is attempting to masquerade as the legitimate Web site, “helpwithmybank.gov,” and contains potentially damaging malware.    The ill...

The Customer Awareness Control

Infotex has released a White Paper in response to the customer awareness training requirements of the June 28th Supplement to the 2005 Authentication Guidance released by the FFIEC.   The goal was to pull everything we know about customer awareness training into one place.  ...

Online Vehicle Scam Using Kelley Blue Book’s Name

Scamming Online Vehicle Purchasers The IC3 has received complaints reporting fraudsters for misrepresenting themselves as Kelley Blue Book (KBB) agents to swindle victims out of thousands of dollars in online vehicle purchases. Upon finding a vehicle and making an inquiry to...

User Accountability

Keeping Passwords Safe and Log-ins Secure As users of your information resources, your employees should be reminded on a periodic basis that they are responsible for all activity that takes place while using their user name. If the security of their user login is compromise...

Interim Framework for Auditing Progress on Supplement

An Interim Audit Framework for the Supplement to the 2005 Authentication Guidance Since I find myself sending this in e-mails to several of our Clients, I thought it would make a good Dan’s New Leaf post: The problem:  Between now and your next examination, depending on when...

E-mail Claiming to Be From the FDIC

The Federal Deposit Insurance Corporation (FDIC) has received numerous reports of a fraudulent e-mail that has the appearance of being sent from the FDIC. The e-mails appear to be sent from various “@fdic.gov” e-mail addresses, such as “insurance @fdic.gov...

FFIEC Scores on Supplement to Authentication Guidance

Jump to Dan’s Bottom Line Okay, let me be the first to admit that until today I had not “analyzed” the new authentication guidance.  Like many of my clients, I felt the guidance “couldn’t have come at a worse time.”  I was busy with a hundred projects and couldn’t mus...

‘McDonald’s Free Dinner’ E-mail Scam Could Lead to Virus

An email scam spreading around the Internet on Wednesday advertising free food at McDonald’s is a scam that could lead to harmful Malware. The e-mail, which has been confirmed as fake by McDonald’s, started spreading late Tuesday into Wednesday. The e-mail claim...