Is Security Team 2 Glba

861 views

Published on

Published in: Technology, Business
0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total views
861
On SlideShare
0
From Embeds
0
Number of Embeds
4
Actions
Shares
0
Downloads
30
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide
  • Is Security Team 2 Glba

    1. 1. The Gramm-Leach Bliley Act Presented By: Team II Catherine King Alex Kelley Saahil Goel Steven Irvine
    2. 2. <ul><li>The Financial Services Modernization Act or the Gramm-Leach-Bliley Act (GLBA) was introduced in November 1999 </li></ul><ul><li>Main goal: remove regulations (especially Glass Steagall Act of 1933) that did not allow banks, insurance firms and stock brokerage firms to merge </li></ul><ul><li>Contains 7 titles </li></ul>
    3. 3. <ul><li>Title V refers to Privacy </li></ul><ul><li>Introduced because: </li></ul><ul><ul><li>Merged financial institutions would have access to a large quantity of citizens’ personal information </li></ul></ul><ul><ul><li>Could sell information to third parties </li></ul></ul><ul><li>Three requirements in GLBA: </li></ul><ul><ul><li>Comprehensive information security for storing personal data </li></ul></ul><ul><ul><li>Disclosure of privacy policy to clients </li></ul></ul><ul><ul><li>Customers given the right to opt out of information sharing schemes </li></ul></ul><ul><li>Compliance deadline: May 23, 2003 </li></ul>
    4. 4. <ul><li>Information security program coordinator </li></ul><ul><li>Identity risks </li></ul><ul><li>Safeguard to control the risks </li></ul><ul><li>Oversee service providers </li></ul><ul><li>Evaluate and adjust the program </li></ul><ul><li>GLBA requires administrative, technical and physical safeguards </li></ul>
    5. 5. <ul><li>Financial Institutions: </li></ul><ul><ul><li>Companies that offer financial products or services to individuals including: </li></ul></ul><ul><ul><ul><li>Loans </li></ul></ul></ul><ul><ul><ul><li>Financial or Investment Advice </li></ul></ul></ul><ul><ul><ul><li>Insurance </li></ul></ul></ul><ul><li>Other Companies: </li></ul><ul><ul><li>Non Financial Institutions who receive customers’ personal financial information </li></ul></ul>
    6. 6. <ul><li>Non Financial Institution Examples </li></ul><ul><ul><li>Retailers </li></ul></ul><ul><ul><ul><li>American Eagle Outfitters </li></ul></ul></ul><ul><ul><ul><li>Macy’s </li></ul></ul></ul><ul><ul><ul><li>Dell </li></ul></ul></ul><ul><ul><li>All companies that information is shared with </li></ul></ul>
    7. 7. <ul><li>Businesses’ Protection </li></ul><ul><ul><li>A business is not an individual with personal nonpublic information </li></ul></ul><ul><ul><li>Not Protected under GLBA </li></ul></ul><ul><li>Individuals’ Protection </li></ul><ul><ul><li>Customer – those with a continuing relationship </li></ul></ul><ul><ul><li>Consumer – those with a non continuing relationship </li></ul></ul>
    8. 8. <ul><li>Companies that fall under the GLBA must create and distribute a Privacy Policy </li></ul><ul><li>Governs the collection and disclosure of customers’ personal financial information </li></ul>
    9. 9. <ul><li>A Privacy Policy must achieve the following: </li></ul><ul><ul><li>Clear, Conspicuous, and Accurate </li></ul></ul><ul><ul><li>Explanation of personal nonpublic information collected </li></ul></ul><ul><ul><li>Explanation of how the information is shared </li></ul></ul><ul><ul><li>Explanation of how the information is used </li></ul></ul><ul><ul><li>Explanation of how the information is protected </li></ul></ul>
    10. 10. <ul><li>Privacy Policy must be provided to a customer : </li></ul><ul><ul><li>In person delivery or by mail </li></ul></ul><ul><ul><li>Relationship is established </li></ul></ul><ul><ul><li>Annually thereafter </li></ul></ul><ul><ul><li>Upon policy changes </li></ul></ul>
    11. 11. <ul><li>Opt-Out Rights </li></ul><ul><ul><li>Customers and Consumers have the right to say No to having their information shared. </li></ul></ul><ul><ul><li>Does not include information sharing with company affiliates </li></ul></ul><ul><li>No Opt-Out Rights </li></ul><ul><ul><li>Information sharing is essential </li></ul></ul><ul><ul><li>Disclosure is legally required </li></ul></ul><ul><ul><li>Outside service providers that market the company’s products/services. </li></ul></ul>
    12. 12. <ul><li>Safeguard Rule requires financial institution to develop, implement, and maintain a “comprehensive information security program” that is written “in one or more readily accessible parts”, which contains “administrative, technical and physical safeguards” designed to “to protect the security confidentiality, and integrity of customer information”. </li></ul>
    13. 13. <ul><li>Ensure security and confidentiality of customer info </li></ul><ul><li>Protect against anticipated threats or hazards </li></ul><ul><li>Protect against unauthorized access or use of customer info (that can harm/inconvenience customer) </li></ul>
    14. 14. <ul><li>Designate one of more employees to coordinate its information security program </li></ul><ul><li>Identify and assess risks to customer info in each relevant part of the company OPS </li></ul><ul><li>Evaluate current safeguards </li></ul><ul><li>Regularly monitor and test it </li></ul><ul><li>Designed to be flexible </li></ul><ul><li>Different company divisions and unique risks raised by their business OPS </li></ul>
    15. 15. <ul><li>Employee Management and Training </li></ul><ul><ul><li>Background checks on new employees </li></ul></ul><ul><ul><li>Confidentiality agreement </li></ul></ul><ul><ul><li>Training </li></ul></ul><ul><ul><li>Disciplinary Action </li></ul></ul><ul><ul><li>Knowing were sensitive info is and keeping it secure </li></ul></ul><ul><li>Information Systems </li></ul><ul><li>- Encrypting sensitive info </li></ul><ul><li>- Proper disposal of customer info </li></ul>
    16. 16. <ul><li>- Maintaining up-to-date firewalls </li></ul><ul><li>- Monitor websites of your software vendors </li></ul><ul><li>Detecting and Managing System Failures </li></ul><ul><ul><li>Oversight and audit procedures </li></ul></ul><ul><ul><li>Notifying those affected and law if a breach occurs </li></ul></ul>
    17. 17. GLBA Agency Financial Institutions Board of Governors of the Federal Reserve System Bank holding companies; member banks of the Federal Reserve System Commodity Futures Trading Commission Commodities brokers Department of the Treasury, Office of the Comptroller of the Currency (OCC) National banks; federal branches of foreign banks Department of the Treasury, Office of Thrift Supervision (OTS) Savings associations insured by the FDIC Federal Deposit Insurance Corporations (FDIC) Banks they insure, not including Federal Reserve System members Securities and Exchange Commission (SEC) Securities brokers and dealers; investment companies National Credit Union Administration Federally insured credit unions Federal Trade Commission (FTC) Institutions not covered by the other agencies
    18. 18. <ul><li>Varieties of fines – 5 years of imprisonment </li></ul><ul><li>GLBA </li></ul><ul><ul><li>Company liable for $100,000 for each violation </li></ul></ul><ul><ul><li>Company directors liable for $10,000 for each violation </li></ul></ul><ul><li>Section 8 of the Federal Deposit Insurance Act. </li></ul><ul><ul><ul><li>Termination of FDIC insurance </li></ul></ul></ul><ul><ul><ul><li>Cease and Desist Orders </li></ul></ul></ul><ul><ul><ul><li>Removal of management </li></ul></ul></ul><ul><ul><ul><li>Fines of $1000,000 or > of 1% of total assets </li></ul></ul></ul><ul><li>Reputation: customer trust, lost future business </li></ul>
    19. 19. <ul><li>Impacted Systems </li></ul><ul><ul><li>Vulnerability assessment tests </li></ul></ul><ul><ul><li>Intrusion detection monitors </li></ul></ul><ul><ul><li>Password management programs </li></ul></ul><ul><ul><li>System and physical access control systems </li></ul></ul><ul><ul><li>Encryption of customer data </li></ul></ul><ul><li>Business Continuity Plans </li></ul><ul><ul><li>Floods, fire, earthquakes, etc. </li></ul></ul><ul><li>Security Policies </li></ul><ul><ul><li>Constantly re-evaluate, measure and update </li></ul></ul><ul><ul><li>Set benchmarks and enforce those </li></ul></ul>
    20. 20. <ul><li>People </li></ul><ul><ul><li>75% of breaches are due to insiders </li></ul></ul><ul><ul><li>Top management awareness and absolute buy-in </li></ul></ul><ul><ul><li>Strict security policies </li></ul></ul><ul><ul><li>Internal process to enforce policies </li></ul></ul><ul><ul><ul><li>Segregation of duties – better access control </li></ul></ul></ul><ul><ul><li>Training </li></ul></ul><ul><ul><ul><li>Awareness </li></ul></ul></ul><ul><ul><ul><li>Process, impact, scope, actions </li></ul></ul></ul><ul><ul><li>Surveys, assessments and internal certifications </li></ul></ul>
    21. 21. <ul><li>1997: Charter Pacific Bank: sold credit cards to adult website </li></ul><ul><li>1998: NationsBank shared customer information with its subsidiary affiliate, NationsSecurities </li></ul><ul><li>June 1999: US Bank shared customer data with a telemarketer, in violation of its own policy </li></ul>
    22. 22. <ul><li>Sunbelt (2004): did not provide privacy information to its online customers </li></ul><ul><ul><li>FTC imposed biannual audits of Sunbelt’s information security program by independent professionals for 10 years </li></ul></ul><ul><li>Goal Financial (2008): as a result of security failures, employees transferred files containing consumer information to third parties </li></ul>
    23. 23. <ul><li>Questions? </li></ul>

    ×