Adobe Systems Software Ireland Ltd

Size: px
Start display at page:

Download "Adobe Systems Software Ireland Ltd"

Transcription

1 Adobe Systems Software Ireland Ltd Own motion investigation report 13/00007 Timothy Pilgrim, Australian Privacy Commissioner

2 Contents Overview... 2 Background... 3 Relevant provisions of the Privacy Act... 3 Findings... 4 Use and disclosure (NPP 2)... 4 Data security (NPP 4.1)... 4 Security of passwords and password hints... 5 NPP 4 conclusion whether Adobe took reasonable steps to protect the personal information it held... 7 Rectification... 7 Recommendations... 8 Conclusion... 9 Acronyms and abbreviations... 9 Office of the Australian Information Commissioner 1

3 Overview On 13 December 2013, the Australian Privacy Commissioner (the Commissioner) opened an own motion investigation into Adobe Systems Software Ireland Ltd (Adobe) following Adobe s statement on its website that it had been the target of a cyber-attack involving the illegal access of customer information as well as source code for numerous Adobe products (the data breach). 1 The investigation focused on whether Adobe took reasonable steps to protect the personal information that it held from misuse and loss and from unauthorised access, modification or disclosure. As part of his decision-making process, the Commissioner considered the facts of the case, submissions from Adobe and relevant provisions of the Privacy Act 1988 (Cth) (the Privacy Act). This data breach affected the personal information of millions of individuals globally. In order to maximise the efficiency of his investigation and avoid regulatory duplication, the Commissioner liaised with the Data Protection Commissioner of Ireland (DPCI) 2 and the Office of the Privacy Commissioner of Canada (OPCC) 3 throughout the course of his investigation, and referred to the analysis of the data breach conducted by the DPCI and OPCC in making his findings. The Commissioner came to the view that Adobe had breached the Privacy Act by failing to take reasonable steps to protect all of the personal information it held from misuse and loss and from unauthorised access, modification or disclosure. In particular, the Commissioner had concerns about how Adobe protected user credential information ( addresses and associated passwords). While Adobe generally took a sophisticated and layered approach to information security and the protection of its IT systems, it failed to implement consistently strong security measures across its various internal systems. In particular, a backup server stored a database of unencrypted credential information ( addresses and password hints) of over 1.7 million Australian users, directly linked to the encrypted password for each user. The type of encryption used, together with plaintext password hints, allowed security experts with access to the database, which became widely available on the internet after the breach, to identify the 100 most common passwords and customer accounts associated with those passwords. This data breach demonstrates the importance of designing an information security system with multiple levels of protections, checks and balances, and for organisations to The DPCI and OAIC entered into a Memorandum of Understanding on Mutual Assistance in the Enforcement of Laws Protecting Personal Information in the Private Sector on 25 April See OAIC website < 3 Under the APEC Cross-Border Privacy Enforcement Arrangement. Office of the Australian Information Commissioner 2

4 ensure that sufficiently robust security measures are applied consistently across all systems. Background On 3 October 2013, Adobe reported on its website that it had been the target of a cyber-attack. Between 30 August 2013 and 17 September 2013, an unauthorised third party illegally accessed certain customer order information. Adobe became aware of the unauthorised access on 17 September 2013 when an attempt by the attacker to decrypt card numbers that were a part of the customer order information was discovered by Adobe. Adobe s subsequent investigation into the attack discovered that the attacker had compromised a public-facing web server and used this compromised web server to access other servers on Adobe s network. The attacker transferred data out of Adobe s network. The attacker took a copy of a backup database containing the personal information of customers, consisting of: customer usernames (Adobe IDs) addresses encrypted passwords (a small number of unencrypted passwords, held in a separate database, may also have been compromised) plain text password hints names addresses and telephone numbers of some users encrypted payment card numbers and payment card expiration dates. Adobe advised the Commissioner that there were: 135,288 Australian users whose encrypted payment card numbers and other payment information were involved in the data breach 1,787,100 Australian active and inactive users whose current password data was involved 218,750 Australian active and inactive users whose obsolete password data was involved 36 Australian users who may have had plain text passwords exposed. Relevant provisions of the Privacy Act Until 11 March 2014, organisations covered by the Privacy Act were required to comply with ten National Privacy Principles (NPPs), contained in Schedule 3 of the Privacy Act. Office of the Australian Information Commissioner 3

5 The NPPs were replaced by the Australian Privacy Principles (APPs) on 12 March Adobe was subject to the NPPs at the time of the data breach. The NPPs applied to the handling of personal information which the Privacy Act defined as: information or an opinion (including information or an opinion forming part of a database), whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion. NPP 2 (use and disclosure) and NPP 4 (data security) were the Privacy Act provisions relevant to this data breach. In particular: NPP 2 stated that an organisation must not use or disclose personal information about an individual for a purpose other than the primary purpose of collection, unless a listed exception applies. NPP 4.1 provided that an organisation must take reasonable steps to protect the personal information it holds from misuse and loss and from unauthorised access, modification or disclosure. Findings Use and disclosure (NPP 2) An organisation discloses personal information when it makes it accessible or visible to others outside the organisation and releases the subsequent handling of the personal information from its effective control. The release may be an accidental release or an unauthorised release by an employee. An organisation is not taken to have disclosed personal information where a third party intentionally exploits the entity s security measures and gains unauthorised access to the information. In respect of the data breach, the personal information of Adobe s customers was accessed as the result of a malicious third party or parties exploiting Adobe s security systems to gain access to its customer s personal information. The Commissioner did not consider this to be a disclosure by Adobe within the meaning of NPP 2. Therefore, the Commissioner did not consider Adobe to have breached NPP 2 in this matter. Data security (NPP 4.1) In assessing whether Adobe took reasonable steps to comply with NPP 4.1, the Commissioner considered the information provided by Adobe, the OPCC and the DPCI about the security safeguards that were in place prior to the data breach. He also considered what steps would have been reasonable in the circumstances to protect the personal information that Adobe held. This included considering Adobe s particular circumstances, such as: the amount and sensitivity of the personal information it held Office of the Australian Information Commissioner 4

6 the risk to the individuals concerned the ease with which it could implement particular security measures. The Commissioner also had regard to the guidance set out in the OAIC s Guide to information security: Reasonable steps to protect personal information. 4 Generally, an organisation will need to have a range of security safeguards in place to protect all of the personal information that it holds that address the particular security risks that are present within that organisation. Adobe s submissions to the OAIC indicated that, at the time of the data breach, Adobe had extensive and detailed security measures in place to protect its systems and the personal information that it held, including the following: Information technology security measures, including firewalls, two-factor authentication for remote access, web traffic filtering, and antivirus/antimalware systems. Security training materials available to employees on Adobe s intranet and annual security training for IT personnel. Monitoring tools for malware detection, data loss prevention traffic monitoring and intrusion detection/intrusion prevention. Annual audit of the database servers that maintain the customer data that was accessed by the attacker. Penetration testing and regular vulnerability scanning on Adobe s IT-managed network infrastructure. Several incident response plans that establish Adobe s response procedures for security incidents, depending on the resources involved. A security program that involved a variety of risk assessments, including an annual risk assessment to identify risks at an enterprise-wide level, and assessments to evaluate risks relating to the handling of sensitive information or information which otherwise ought to be subject to higher standards of protection, such as payment card numbers. Security of passwords and password hints The system that the attackers gained access to during the attack was a backup system that was designated to be decommissioned (the backup system ). At the time of the data breach, two data fields within the customer database held on this system were encrypted: password and payment card number. Adobe introduced a new system in April 2010 as a more secure means of authenticating users than the encrypted passwords stored in the backup system (the new system ). According to an Adobe statement made to Ars Technica: 5 4 Replaced in January 2015 with the OAIC s Guide to securing personal information: Reasonable steps to protect personal information, January 2015, OAIC website < Office of the Australian Information Commissioner 5

7 For more than a year, Adobe s authentication system has cryptographically hashed customer passwords using the SHA-256 algorithm, including salting the passwords and iterating the hash more than 1,000 times. This system was not the subject of the attack we publicly disclosed on October 3, The authentication system involved in the attack was a backup system and was designated to be decommissioned. The system involved in the attack used Triple DES encryption to protect all password information stored. This supports Adobe s claim that it regularly reassesses and updates its systems and processes in response to changes in technology and emerging risks. However, despite apparently recognising the deficiencies of the backup system, Adobe continued to store user credential information in that system using a single encryption key and a block cipher encryption algorithm. As well as encrypted passwords, the backup system stored user addresses and plain text password hints. The choice of a block cipher encryption algorithm meant that common passwords shared by different users had the same ciphertext representation. For example, each of the 1,911,938 users listed in the database who shared the most common password had their password converted into the following ciphertext which was stored in the database: EQ7fIpT7i/Q=. Although this cipher text is meaningless without access to the encryption key, the fact that different users with the same passwords have the same cipher text (because of the encryption method used) allows common passwords to be grouped together. Adobe also stored customer password hints in the backup system in plain text rather than in an encrypted format. The OPCC s investigation found that some of the plain text hints contained the password itself, or an obvious hint. For example, some of the users associated with the password ciphertext set out above provided a password hint which included the actual password. This allows an attacker to infer the password of every one of those nearly 2 million users: The use of a block cipher encryption algorithm meant that if one user s password becomes compromised, the password of every other user in the database with the same password is also compromised. The user credential database taken from the backup system was published on the internet following the attack. Security experts reported that they had been able to circumvent the encryption on the most common passwords by analysing password hints and using other techniques to guess at them. 6 Lists of commonly used passwords, and related ciphertexts, have been posted online. 7 Therefore, the security of passwords of individuals with at least those commonly used passwords has been compromised as a result of the data breach and the method of encryption used by Adobe. 5 See Ars Technica, How an epic blunder by Adobe could strengthen hand of password crackers, 1 November 2013 (viewed 2 September 2014), Ars Technica website <arstechnica.com/security/2013/11/how-an-epicblunder-by-adobe-could-strengthen-hand-of-password-crackers>. 6 See Reuters UK, Adobe says breach notification taking longer than anticipated, viewed 2 September 2014, Reuters UK website <uk.reuters.com/article/2013/11/25/us-adobe-cyberattackidukbre9ao10r >. 7 See, e.g. Office of the Australian Information Commissioner 6

8 The publication of the encrypted passwords and plain text password hints on the internet has consequences beyond the immediate relationship between Adobe and its customers. Where passwords are compromised, individuals are placed at risk on other systems where they use a common password. While Adobe is not responsible for its customers failing to take its advice to change their passwords, Adobe s password security measures in the backup system have nonetheless placed some of its customers at an unnecessary risk of harm. NPP 4 conclusion whether Adobe took reasonable steps to protect the personal information it held The Commissioner noted the challenges in guarding against sophisticated cyber-attacks such as this. Taking reasonable steps to protect personal information does not mean that an organisation must design impenetrable systems. However, in order for an organisation to comply with the requirement to take reasonable steps, its security measures must adequately address known risks. Further, NPP 4 requires an organisation to take reasonable steps to protect all of the personal information that it holds. The requirements of NPP 4 will not be satisfied if an organisation has adequate security measures in place to protect personal information stored in one area of its systems, but does not implement these measures in relation to all of the personal information that it holds. The information Adobe provided about its security measures indicates that Adobe has a sophisticated and layered approach to information security and the protection of its IT systems. However, encryption techniques vary in their effectiveness, and in their suitability for protecting particular types of information. The passwords stored on the system compromised in the breach were each encrypted, apparently using the same key, rather than being individually salted then hashed. Hashing and salting is a basic security step that Adobe could reasonably have implemented to better protect the passwords in its backup system. 8 Adobe also stored customer password hints in plain text rather than in an encrypted format, further exposing its customers passwords to risk. Given the resources available to Adobe to implement robust security measures consistently across all its systems and the consequences for individuals if the data on the old servers was compromised, the Commissioner found that Adobe breached NPP 4 by failing to take reasonable steps to protect all of the personal information it held from misuse and loss and from unauthorised access, modification or disclosure. Rectification Once Adobe became aware of the data breach, it took steps to contain the breach, including: 8 Generally speaking, 'salting' is where an additional string of data, such as random numbers or text, is added to the password to make it less predictable and harder to attack, and 'hashing' is where passwords are processed through cryptographic algorithms that convert them into seemingly random characters. While passwords may be guessed through computational 'brute-force' attacks, this becomes very difficult when strong hash algorithms and passwords are used. Hashed passwords are therefore more secure to store than their clear-text passwords. Office of the Australian Information Commissioner 7

9 Disconnecting the compromised database server from the network. Initiating an investigation into the data breach. Blacklisting IP addresses. Changing passwords for all administrator accounts. Resetting passwords (on 3-4 October 2013) for users whose Adobe ID and current password data (i.e. a password that was valid against Adobe s production authentication system) were in the database taken. Notifying affected individuals whose Adobe ID, password data and/or payment card numbers were accessed, including expressing regret for any inconvenience or concern this incident may cause. Notifying the banks processing customer payments for Adobe, so that they could work with the payment card companies and card-issuing banks to help protect customers accounts. Notifying law enforcement authorities. Sending takedown requests to third party site operators that had published the compromised personal information. The Commissioner expressed concern about the risk of customer passwords being compromised and misused during the period between Adobe discovering that the attacker had accessed encrypted passwords on 23 September 2014 and resetting the passwords nine days later. However the Commissioner noted that Adobe was taking reasonable steps during this time to prepare for the password reset to address this risk. Adobe also took steps to mitigate against the risk of future data breaches of this nature, including in relation to network monitoring, the storage of payment card information and passwords, two-factor authentication, decommissioning the affected server and abolishing the use of password hints. Recommendations The Commissioner was satisfied that the measures that Adobe took in response to the data breach will assist Adobe to significantly strengthen its privacy framework and meet its obligations under the Privacy Act. The Commissioner endorsed the recommendations of the DPCI in its final report on its investigation into this data breach. In summary, the recommendations specify steps that Adobe can take to enhance its password protection, network security and access security. Adobe has already implemented many of these measures. The Commissioner requested that Adobe ensure it implements all of these recommendations in order to further strengthen its information security systems. The Commissioner also recommended that Adobe regularly review its data security processes to continue to aim for best privacy practice that protects the personal information of its extensive user base. Office of the Australian Information Commissioner 8

10 The Commissioner recommended that Adobe takes steps to ensure that it is able to implement a faster and more wide-spread notification procedure if it experiences another data breach of this nature and scale. Adobe advised that it intends to engage a suitably qualified independent auditor to certify that it has implemented a number of security measures to strengthen its information security systems. Conclusion The Commissioner found that Adobe breached NPP 4 by failing to take reasonable steps to protect the personal information it held from misuse and loss and from unauthorised access, modification or disclosure. The Commissioner was satisfied that Adobe responded quickly and effectively when it discovered the attack on its systems, working to secure its servers, contain and respond to the data breach, and to implement steps to mitigate against future data breaches of this nature. Based on Adobe s remediation activities and its intention to engage an auditor to confirm its remediation steps, the Commissioner decided to close the investigation. Acronyms and abbreviations Commissioner Australian Privacy Commissioner Adobe Adobe Systems Software Ireland Ltd NPPs National Privacy Principles (contained in Schedule 3 of the Privacy Act 1988 (Cth), prior to 12 March 2014) OAIC Office of the Australian Information Commissioner Privacy Act Privacy Act 1988 (Cth) Office of the Australian Information Commissioner 9

Revised Guide to information security

Revised Guide to information security Revised Guide to information security Reasonable steps to protect personal information Consultation draft August 2014 Contents Background... 1 The purpose of this guide... 1 The Privacy Act and the security

More information

005ASubmission to the Serious Data Breach Notification Consultation

005ASubmission to the Serious Data Breach Notification Consultation 005ASubmission to the Serious Data Breach Notification Consultation (Consultation closes 4 March 2016 please send electronic submissions to privacy.consultation@ag.gov.au) Your details Name/organisation

More information

Newcastle University Information Security Procedures Version 3

Newcastle University Information Security Procedures Version 3 Newcastle University Information Security Procedures Version 3 A Information Security Procedures 2 B Business Continuity 3 C Compliance 4 D Outsourcing and Third Party Access 5 E Personnel 6 F Operations

More information

PCI DSS Policies Outline. PCI DSS Policies. All Rights Reserved. ecfirst. 2010. Page 1 of 7 www.ecfirst.com

PCI DSS Policies Outline. PCI DSS Policies. All Rights Reserved. ecfirst. 2010. Page 1 of 7 www.ecfirst.com Policy/Procedure Description PCI DSS Policies Install and Maintain a Firewall Configuration to Protect Cardholder Data Establish Firewall and Router Configuration Standards Build a Firewall Configuration

More information

Guidance End User Devices Security Guidance: Apple OS X 10.9

Guidance End User Devices Security Guidance: Apple OS X 10.9 GOV.UK Guidance End User Devices Security Guidance: Apple OS X 10.9 Published 23 January 2014 Contents 1. Changes since previous guidance 2. Usage Scenario 3. Summary of Platform Security 4. How the Platform

More information

Privacy and Cloud Computing for Australian Government Agencies

Privacy and Cloud Computing for Australian Government Agencies Privacy and Cloud Computing for Australian Government Agencies Better Practice Guide February 2013 Version 1.1 Introduction Despite common perceptions, cloud computing has the potential to enhance privacy

More information

Supplier Information Security Addendum for GE Restricted Data

Supplier Information Security Addendum for GE Restricted Data Supplier Information Security Addendum for GE Restricted Data This Supplier Information Security Addendum lists the security controls that GE Suppliers are required to adopt when accessing, processing,

More information

BMC s Security Strategy for ITSM in the SaaS Environment

BMC s Security Strategy for ITSM in the SaaS Environment BMC s Security Strategy for ITSM in the SaaS Environment TABLE OF CONTENTS Introduction... 3 Data Security... 4 Secure Backup... 6 Administrative Access... 6 Patching Processes... 6 Security Certifications...

More information

Cyber Essentials Scheme

Cyber Essentials Scheme Cyber Essentials Scheme Requirements for basic technical protection from cyber attacks June 2014 December 2013 Contents Contents... 2 Introduction... 3 Who should use this document?... 3 What can these

More information

ensure prompt restart of critical applications and business activities in a timely manner following an emergency or disaster

ensure prompt restart of critical applications and business activities in a timely manner following an emergency or disaster Security Standards Symantec shall maintain administrative, technical, and physical safeguards for the Symantec Network designed to (i) protect the security and integrity of the Symantec Network, and (ii)

More information

REGULATIONS FOR THE SECURITY OF INTERNET BANKING

REGULATIONS FOR THE SECURITY OF INTERNET BANKING REGULATIONS FOR THE SECURITY OF INTERNET BANKING PAYMENT SYSTEMS DEPARTMENT STATE BANK OF PAKISTAN Table of Contents PREFACE... 3 DEFINITIONS... 4 1. SCOPE OF THE REGULATIONS... 6 2. INTERNET BANKING SECURITY

More information

A HELPING HAND TO PROTECT YOUR REPUTATION

A HELPING HAND TO PROTECT YOUR REPUTATION OVERVIEW SECURITY SOLUTIONS A HELPING HAND TO PROTECT YOUR REPUTATION CONTENTS INFORMATION SECURITY MATTERS 01 TAKE NOTE! 02 LAYERS OF PROTECTION 04 ON GUARD WITH OPTUS 05 THREE STEPS TO SECURITY PROTECTION

More information

MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE

MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE WHITE PAPER MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE 1. OVERVIEW Do you want to design a file transfer process that is secure? Or one that is compliant? Of course, the answer is both. But it s

More information

Security Controls for the Autodesk 360 Managed Services

Security Controls for the Autodesk 360 Managed Services Autodesk Trust Center Security Controls for the Autodesk 360 Managed Services Autodesk strives to apply the operational best practices of leading cloud-computing providers around the world. Sound practices

More information

Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 EES17 --------------

Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 EES17 -------------- w Microsoft Volume Licensing Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 Enrollment for Education Solutions number Microsoft to complete --------------

More information

Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10

Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10 Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID This Microsoft Online Services Security Amendment ( Amendment ) is between

More information

HIPAA Privacy & Security White Paper

HIPAA Privacy & Security White Paper HIPAA Privacy & Security White Paper Sabrina Patel, JD +1.718.683.6577 sabrina@captureproof.com Compliance TABLE OF CONTENTS Overview 2 Security Frameworks & Standards 3 Key Security & Privacy Elements

More information

2013-2014-2015 THE PARLIAMENT OF THE COMMONWEALTH OF AUSTRALIA HOUSE OF REPRESENTATIVES/THE SENATE

2013-2014-2015 THE PARLIAMENT OF THE COMMONWEALTH OF AUSTRALIA HOUSE OF REPRESENTATIVES/THE SENATE 2013-2014-2015 THE PARLIAMENT OF THE COMMONWEALTH OF AUSTRALIA HOUSE OF REPRESENTATIVES/THE SENATE PRIVACY AMENDMENT (NOTIFICATION OF SERIOUS DATA BREACHES) BILL 2015 EXPLANATORY MEMORANDUM (Circulated

More information

Mandatory data breach notification in the ehealth record system

Mandatory data breach notification in the ehealth record system Mandatory data breach notification in the ehealth record system Draft September 2012 A guide to mandatory data breach notification under the personally controlled electronic health record system Contents

More information

BYOD Guidance: BlackBerry Secure Work Space

BYOD Guidance: BlackBerry Secure Work Space GOV.UK Guidance BYOD Guidance: BlackBerry Secure Work Space Published 17 February 2015 Contents 1. About this guidance 2. Summary of key risks 3. Secure Work Space components 4. Technical assessment 5.

More information

End User Devices Security Guidance: Apple OS X 10.10

End User Devices Security Guidance: Apple OS X 10.10 GOV.UK Guidance End User Devices Security Guidance: Apple OS X 10.10 Published Contents 1. Changes since previous guidance 2. Usage scenario 3. Summary of platform security 4. How the platform can best

More information

Third Party Security Requirements Policy

Third Party Security Requirements Policy Overview This policy sets out the requirements expected of third parties to effectively protect BBC information. Audience Owner Contacts This policy applies to all third parties and staff, including contractors,

More information

IT Best Practices Audit TCS offers a wide range of IT Best Practices Audit content covering 15 subjects and over 2200 topics, including:

IT Best Practices Audit TCS offers a wide range of IT Best Practices Audit content covering 15 subjects and over 2200 topics, including: IT Best Practices Audit TCS offers a wide range of IT Best Practices Audit content covering 15 subjects and over 2200 topics, including: 1. IT Cost Containment 84 topics 2. Cloud Computing Readiness 225

More information

Infor CloudSuite. Defense-in-depth. Table of Contents. Technical Paper Plain talk about Infor CloudSuite security

Infor CloudSuite. Defense-in-depth. Table of Contents. Technical Paper Plain talk about Infor CloudSuite security Technical Paper Plain talk about security When it comes to Cloud deployment, security is top of mind for all concerned. The Infor CloudSuite team uses best-practice protocols and a thorough, continuous

More information

Guidance on the Use of Portable Storage Devices 1

Guidance on the Use of Portable Storage Devices 1 Guidance on the Use of Portable Storage Devices Introduction Portable storage devices ( PSDs ) such as USB flash memories or drives, notebook computers or backup tapes provide a convenient means to store

More information

2. From a control perspective, the PRIMARY objective of classifying information assets is to:

2. From a control perspective, the PRIMARY objective of classifying information assets is to: MIS5206 Week 13 Your Name Date 1. When conducting a penetration test of an organization's internal network, which of the following approaches would BEST enable the conductor of the test to remain undetected

More information

How to Practice Safely in an era of Cybercrime and Privacy Fears

How to Practice Safely in an era of Cybercrime and Privacy Fears How to Practice Safely in an era of Cybercrime and Privacy Fears Christina Harbridge INFORMATION PROTECTION SPECIALIST Information Security The practice of defending information from unauthorised access,

More information

Host Hardening. Presented by. Douglas Couch & Nathan Heck Security Analysts for ITaP 1

Host Hardening. Presented by. Douglas Couch & Nathan Heck Security Analysts for ITaP 1 Host Hardening Presented by Douglas Couch & Nathan Heck Security Analysts for ITaP 1 Background National Institute of Standards and Technology Draft Guide to General Server Security SP800-123 Server A

More information

PCI DSS Requirements - Security Controls and Processes

PCI DSS Requirements - Security Controls and Processes 1. Build and maintain a secure network 1.1 Establish firewall and router configuration standards that formalize testing whenever configurations change; that identify all connections to cardholder data

More information

FileCloud Security FAQ

FileCloud Security FAQ is currently used by many large organizations including banks, health care organizations, educational institutions and government agencies. Thousands of organizations rely on File- Cloud for their file

More information

Guide to information security

Guide to information security Guide to information security April 2013 Reasonable steps to protect personal information The (OAIC) was established on 1 November 2010 by the Australian Information Commissioner Act 2010. All OAIC publications

More information

Using AWS in the context of Australian Privacy Considerations October 2015

Using AWS in the context of Australian Privacy Considerations October 2015 Using AWS in the context of Australian Privacy Considerations October 2015 (Please consult https://aws.amazon.com/compliance/aws-whitepapers/for the latest version of this paper) Page 1 of 13 Overview

More information

Kenna Platform Security. A technical overview of the comprehensive security measures Kenna uses to protect your data

Kenna Platform Security. A technical overview of the comprehensive security measures Kenna uses to protect your data Kenna Platform Security A technical overview of the comprehensive security measures Kenna uses to protect your data V2.0, JULY 2015 Multiple Layers of Protection Overview Password Salted-Hash Thank you

More information

787 Wye Road, Akron, Ohio 44333 P 330-666-6200 F 330-666-7801 www.keystonecorp.com

787 Wye Road, Akron, Ohio 44333 P 330-666-6200 F 330-666-7801 www.keystonecorp.com Introduction Keystone White Paper: Regulations affecting IT This document describes specific sections of current U.S. regulations applicable to IT governance and data protection and maps those requirements

More information

TASK -040. TDSP Web Portal Project Cyber Security Standards Best Practices

TASK -040. TDSP Web Portal Project Cyber Security Standards Best Practices Page 1 of 10 TSK- 040 Determine what PCI, NERC CIP cyber security standards are, which are applicable, and what requirements are around them. Find out what TRE thinks about the NERC CIP cyber security

More information

APPENDIX G ASP/SaaS SECURITY ASSESSMENT CHECKLIST

APPENDIX G ASP/SaaS SECURITY ASSESSMENT CHECKLIST APPENDIX G ASP/SaaS SECURITY ASSESSMENT CHECKLIST Application Name: Vendor Name: Briefly describe the purpose of the application. Include an overview of the application architecture, and identify the data

More information

www.corrs.com.au OFFSHORING Data the new privacy laws

www.corrs.com.au OFFSHORING Data the new privacy laws www.corrs.com.au OFFSHORING Data the new privacy laws OFFSHORING DATA THE NEW PRIVACY LAWS Transfer of data by Australian organisations to other jurisdictions is increasingly common. This is a result of

More information

Complying with PCI Data Security

Complying with PCI Data Security Complying with PCI Data Security Solution BRIEF Retailers, financial institutions, data processors, and any other vendors that manage credit card holder data today must adhere to strict policies for ensuring

More information

Executive Summary Program Highlights for FY2009/2010 Mission Statement Authority State Law: University Policy:

Executive Summary Program Highlights for FY2009/2010 Mission Statement Authority State Law: University Policy: Executive Summary Texas state law requires that each state agency, including Institutions of Higher Education, have in place an Program (ISP) that is approved by the head of the institution. 1 Governance

More information

Guideline on Auditing and Log Management

Guideline on Auditing and Log Management CMSGu2012-05 Mauritian Computer Emergency Response Team CERT-MU SECURITY GUIDELINE 2011-02 Enhancing Cyber Security in Mauritius Guideline on Auditing and Log Management National Computer Board Mauritius

More information

Information Security Basic Concepts

Information Security Basic Concepts Information Security Basic Concepts 1 What is security in general Security is about protecting assets from damage or harm Focuses on all types of assets Example: your body, possessions, the environment,

More information

Auditor s Checklist. A XYPRO Solution Paper. MAY, 2009 XYPRO Technology Corporation

Auditor s Checklist. A XYPRO Solution Paper. MAY, 2009 XYPRO Technology Corporation Auditor s Checklist A XYPRO Solution Paper MAY, 2009 XYPRO Technology Corporation 3325 Cochran Street, Suite 200 Simi Valley, California 93063-2528 U.S.A. Email: info@xypro.com Telephone: + 1 805-583-2874

More information

FormFire Application and IT Security. White Paper

FormFire Application and IT Security. White Paper FormFire Application and IT Security White Paper Contents Overview... 3 FormFire Corporate Security Policy... 3 Organizational Security... 3 Infrastructure and Security Team... 4 Application Development

More information

PCI PA - DSS. Point XSA Implementation Guide. Atos Worldline Banksys XENTA SA. Version 1.00

PCI PA - DSS. Point XSA Implementation Guide. Atos Worldline Banksys XENTA SA. Version 1.00 PCI PA - DSS Point XSA Implementation Guide Atos Worldline Banksys XENTA SA Version 1.00 POINT TRANSACTION SYSTEMS AB Box 92031, 120 06 Stockholm, Tel. +46 8 566 287 00 www.point.se Page number 2 (16)

More information

Data Protection Act 1998. Monetary Penalty Notice. Dated: 20 February 2015

Data Protection Act 1998. Monetary Penalty Notice. Dated: 20 February 2015 Data Protection Act 1998 Monetary Penalty Notice Dated: 20 February 2015 Name: Staysure.co.uk Limited Address: McGowan House, Waterside Way, The Lakes, Northampton, NN4 7XD Statutory framework 1. Staysure.co.uk

More information

IBX Business Network Platform Information Security Controls. 2015-02- 20 Document Classification [Public]

IBX Business Network Platform Information Security Controls. 2015-02- 20 Document Classification [Public] IBX Business Network Platform Information Security Controls 2015-02- 20 Document Classification [Public] Table of Contents 1. General 2 2. Physical Security 2 3. Network Access Control 2 4. Operating System

More information

Data Security Incident Response Plan. [Insert Organization Name]

Data Security Incident Response Plan. [Insert Organization Name] Data Security Incident Response Plan Dated: [Month] & [Year] [Insert Organization Name] 1 Introduction Purpose This data security incident response plan provides the framework to respond to a security

More information

NEES@Buffalo Cybersecurity Plan. Introduction. Roles and Responsibilities. Laboratory Executive Commitee (ExCom)

NEES@Buffalo Cybersecurity Plan. Introduction. Roles and Responsibilities. Laboratory Executive Commitee (ExCom) NEES@Buffalo Cybersecurity Plan Introduction The NEES Cyberinfrastructure (CI) system is composed of fourteen equipment sites and one central IT facility, henceforth referred to as NEEScomm IT. With IT

More information

IBM Global Technology Services Statement of Work. for. IBM Infrastructure Security Services - Penetration Testing - Express Penetration Testing

IBM Global Technology Services Statement of Work. for. IBM Infrastructure Security Services - Penetration Testing - Express Penetration Testing IBM Global Technology Services Statement of Work for IBM Infrastructure Security Services - Penetration Testing - Express Penetration Testing The information in this Statement of Work may not be disclosed

More information

Projectplace: A Secure Project Collaboration Solution

Projectplace: A Secure Project Collaboration Solution Solution brief Projectplace: A Secure Project Collaboration Solution The security of your information is as critical as your business is dynamic. That s why we built Projectplace on a foundation of the

More information

LAMAR STATE COLLEGE - ORANGE INFORMATION RESOURCES SECURITY MANUAL. for INFORMATION RESOURCES

LAMAR STATE COLLEGE - ORANGE INFORMATION RESOURCES SECURITY MANUAL. for INFORMATION RESOURCES LAMAR STATE COLLEGE - ORANGE INFORMATION RESOURCES SECURITY MANUAL for INFORMATION RESOURCES Updated: June 2007 Information Resources Security Manual 1. Purpose of Security Manual 2. Audience 3. Acceptable

More information

CYBERSECURITY TESTING & CERTIFICATION SERVICE TERMS

CYBERSECURITY TESTING & CERTIFICATION SERVICE TERMS CYBERSECURITY TESTING & CERTIFICATION SERVICE TERMS These Cybersecurity Testing and Certification Service Terms ( Service Terms ) shall govern the provision of cybersecurity testing and certification services

More information

Estate Agents Authority

Estate Agents Authority INFORMATION SECURITY AND PRIVACY PROTECTION POLICY AND GUIDELINES FOR ESTATE AGENTS Estate Agents Authority The contents of this document remain the property of, and may not be reproduced in whole or in

More information

The Respect Network Technical and Operational Specifications Version 1.0

The Respect Network Technical and Operational Specifications Version 1.0 The Respect Network Technical and Operational Specifications Version 1.0 V1 2014-06- 23 Abstract This subdocument of the Respect Trust Framework defines the technical and operational rules of the Respect

More information

Security Management. Keeping the IT Security Administrator Busy

Security Management. Keeping the IT Security Administrator Busy Security Management Keeping the IT Security Administrator Busy Dr. Jane LeClair Chief Operating Officer National Cybersecurity Institute, Excelsior College James L. Antonakos SUNY Distinguished Teaching

More information

INFORMATION AND PRIVACY COMMISSIONER OF ALBERTA

INFORMATION AND PRIVACY COMMISSIONER OF ALBERTA INFORMATION AND PRIVACY COMMISSIONER OF ALBERTA Report of an investigation of a malicious software outbreak affecting health information August 19, 2011 Dr. Cathy MacLean Investigation Report H2011-IR-003

More information

EVALUATION REPORT. Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review. March 13, 2015 REPORT NUMBER 15-07

EVALUATION REPORT. Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review. March 13, 2015 REPORT NUMBER 15-07 EVALUATION REPORT Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review March 13, 2015 REPORT NUMBER 15-07 EXECUTIVE SUMMARY Weaknesses Identified During the FY 2014

More information

Information Security Policies. Version 6.1

Information Security Policies. Version 6.1 Information Security Policies Version 6.1 Information Security Policies Contents: 1. Information Security page 3 2. Business Continuity page 5 3. Compliance page 6 4. Outsourcing and Third Party Access

More information

Top Three POS System Vulnerabilities Identified to Promote Data Security Awareness

Top Three POS System Vulnerabilities Identified to Promote Data Security Awareness CISP BULLETIN Top Three POS System Vulnerabilities Identified to Promote Data Security Awareness November 21, 2006 To support compliance with the Cardholder Information Security Program (CISP), Visa USA

More information

BANKING SECURITY and COMPLIANCE

BANKING SECURITY and COMPLIANCE BANKING SECURITY and COMPLIANCE Cashing In On Banking Security and Compliance With awareness of data breaches at an all-time high, banking institutions are working hard to implement policies and solutions

More information

Data Protection Breach Management Policy

Data Protection Breach Management Policy Data Protection Breach Management Policy Please check the HSE intranet for the most up to date version of this policy http://hsenet.hse.ie/hse_central/commercial_and_support_services/ict/policies_and_procedures/policies/

More information

Our Key Security Features Are:

Our Key Security Features Are: September 2014 Version v1.8" Thank you for your interest in PasswordBox. On the following pages, you ll find a technical overview of the comprehensive security measures PasswordBox uses to protect your

More information

NOS for IT User and Application Specialist. IT Security (ESKITU04) November 2014 V1.0

NOS for IT User and Application Specialist. IT Security (ESKITU04) November 2014 V1.0 NOS for IT User and Application Specialist IT Security (ESKITU04) November 2014 V1.0 NOS Reference ESKITU040 ESKITU041 ESKITU042 Level 3 not defined Use digital systems NOS Title Set up and use security

More information

Hang Seng HSBCnet Security. May 2016

Hang Seng HSBCnet Security. May 2016 Hang Seng HSBCnet Security May 2016 1 Security The Bank aims to provide you with a robust, reliable and secure online environment in which to do business. We seek to achieve this through the adoption of

More information

BalaBit IT Security Insight Singaporean Internet Banking and Technology Risk Management Guidelines Compliance

BalaBit IT Security Insight Singaporean Internet Banking and Technology Risk Management Guidelines Compliance GUARDING YOUR BUSINESS BalaBit IT Security Insight Singaporean Internet Banking and Technology Risk Management Guidelines Compliance www.balabit.com In 2008, the Monetary Authority of Singapore (MAS),

More information

Contents. Identity Assurance (Scott Rea Dartmouth College) IdM Workshop, Brisbane Australia, August 19, 2008

Contents. Identity Assurance (Scott Rea Dartmouth College) IdM Workshop, Brisbane Australia, August 19, 2008 Identity Assurance (Scott Rea Dartmouth College) IdM Workshop, Brisbane Australia, August 19, 2008 Contents Authentication and Identity Assurance The Identity Assurance continuum Plain Password Authentication

More information

SITA Security Requirements for Third-Party Service Providers that Access, Process, Store or Transmit Data on Behalf of SITA

SITA Security Requirements for Third-Party Service Providers that Access, Process, Store or Transmit Data on Behalf of SITA SITA Information Security SITA Security Requirements for Third-Party Service Providers that Access, Process, Store or Transmit Data on Behalf of SITA September, 2012 Contents 1. Introduction... 3 1.1 Overview...

More information

Becoming PCI Compliant

Becoming PCI Compliant Becoming PCI Compliant Jason Brown - brownj52@michigan.gov Enterprise Security Architect Enterprise Architecture Department of Technology, Management and Budget State of Michigan @jasonbrown17 History

More information

University of California, Riverside Computing and Communications. IS3 Local Campus Overview Departmental Planning Template

University of California, Riverside Computing and Communications. IS3 Local Campus Overview Departmental Planning Template University of California, Riverside Computing and Communications IS3 Local Campus Overview Departmental Planning Template Last Updated April 21 st, 2011 Table of Contents: Introduction Security Plan Administrative

More information

CS 356 Lecture 25 and 26 Operating System Security. Spring 2013

CS 356 Lecture 25 and 26 Operating System Security. Spring 2013 CS 356 Lecture 25 and 26 Operating System Security Spring 2013 Review Chapter 1: Basic Concepts and Terminology Chapter 2: Basic Cryptographic Tools Chapter 3 User Authentication Chapter 4 Access Control

More information

PCI Requirements Coverage Summary Table

PCI Requirements Coverage Summary Table StillSecure PCI Complete Managed PCI Compliance Solution PCI Requirements Coverage Summary Table January 2013 Table of Contents Introduction... 2 Coverage assumptions for PCI Complete deployments... 2

More information

Additional Security Considerations and Controls for Virtual Private Networks

Additional Security Considerations and Controls for Virtual Private Networks CYBER SECURITY OPERATIONS CENTRE APRIL 2013 (U) LEGAL NOTICE: THIS PUBLICATION HAS BEEN PRODUCED BY THE DEFENCE SIGNALS DIRECTORATE (DSD), ALSO KNOWN AS THE AUSTRALIAN SIGNALS DIRECTORATE (ASD). ALL REFERENCES

More information

Data Protection Act 1998. Guidance on the use of cloud computing

Data Protection Act 1998. Guidance on the use of cloud computing Data Protection Act 1998 Guidance on the use of cloud computing Contents Overview... 2 Introduction... 2 What is cloud computing?... 3 Definitions... 3 Deployment models... 4 Service models... 5 Layered

More information

How To Protect Decd Information From Harm

How To Protect Decd Information From Harm Policy ICT Security Please note this policy is mandatory and staff are required to adhere to the content Summary DECD is committed to ensuring its information is appropriately managed according to the

More information

nwstor Storage Security Solution 1. Executive Summary 2. Need for Data Security 3. Solution: nwstor isav Storage Security Appliances 4.

nwstor Storage Security Solution 1. Executive Summary 2. Need for Data Security 3. Solution: nwstor isav Storage Security Appliances 4. CONTENTS 1. Executive Summary 2. Need for Data Security 3. Solution: nwstor isav Storage Security Appliances 4. Conclusion 1. EXECUTIVE SUMMARY The advantages of networked data storage technologies such

More information

Presentation for : The New England Board of Higher Education. Hot Topics in IT Security and Data Privacy

Presentation for : The New England Board of Higher Education. Hot Topics in IT Security and Data Privacy Presentation for : The New England Board of Higher Education Hot Topics in IT Security and Data Privacy October 22, 2010 Rocco Grillo, CISSP Managing Director Protiviti Inc. Quote of the Day "It takes

More information

Overcoming PCI Compliance Challenges

Overcoming PCI Compliance Challenges Overcoming PCI Compliance Challenges Randy Rosenbaum - Security Services Exec. Alert Logic, CPISM Brian Anderson - Product Manager, Security Services, SunGard AS www.sungardas.com Goal: Understand the

More information

Summary of the Dutch Data Protection Authority s guidelines for the Data Breach Notification Act

Summary of the Dutch Data Protection Authority s guidelines for the Data Breach Notification Act Summary of the Dutch Data Protection Authority s guidelines for the Data Breach Notification Act On 1 January 2016, the Dutch Data Breach Notification Act will enter into force. The Dutch DPA issued Guidelines

More information

Privacy and data breaches how information governance minimises the risk

Privacy and data breaches how information governance minimises the risk Privacy and data breaches how information governance minimises the risk Preventing data privacy breaches is becoming increasingly important, with the increasing costs of dealing with cyber attacks, IT

More information

3rd Party Assurance & Information Governance 2014-2016 outlook IIA Ireland Annual Conference 2014. Straightforward Security and Compliance

3rd Party Assurance & Information Governance 2014-2016 outlook IIA Ireland Annual Conference 2014. Straightforward Security and Compliance 3rd Party Assurance & Information Governance 2014-2016 outlook IIA Ireland Annual Conference 2014 Continuous Education Services (elearning/workshops) Compliance Management Portals Information Security

More information

Pension Benefit Guaranty Corporation. Office of Inspector General. Evaluation Report. Penetration Testing 2001 - An Update

Pension Benefit Guaranty Corporation. Office of Inspector General. Evaluation Report. Penetration Testing 2001 - An Update Pension Benefit Guaranty Corporation Office of Inspector General Evaluation Report Penetration Testing 2001 - An Update August 28, 2001 2001-18/23148-2 Penetration Testing 2001 An Update Evaluation Report

More information

HIPAA: MANAGING ACCESS TO SYSTEMS STORING ephi WITH SECRET SERVER

HIPAA: MANAGING ACCESS TO SYSTEMS STORING ephi WITH SECRET SERVER HIPAA: MANAGING ACCESS TO SYSTEMS STORING ephi WITH SECRET SERVER With technology everywhere we look, the technical safeguards required by HIPAA are extremely important in ensuring that our information

More information

NETWORK AND CERTIFICATE SYSTEM SECURITY REQUIREMENTS

NETWORK AND CERTIFICATE SYSTEM SECURITY REQUIREMENTS NETWORK AND CERTIFICATE SYSTEM SECURITY REQUIREMENTS Scope and Applicability: These Network and Certificate System Security Requirements (Requirements) apply to all publicly trusted Certification Authorities

More information

Personally controlled electronic health record (ehealth record) system

Personally controlled electronic health record (ehealth record) system Personally controlled electronic health record (ehealth record) system ehealth record System Operator Audit report Information Privacy Principles audit Section 27(1)(h) Privacy Act 1988 Audit undertaken:

More information

DBC 999 Incident Reporting Procedure

DBC 999 Incident Reporting Procedure DBC 999 Incident Reporting Procedure Signed: Chief Executive Introduction This procedure is intended to identify the actions to be taken in the event of a security incident or breach, and the persons responsible

More information

Central Agency for Information Technology

Central Agency for Information Technology Central Agency for Information Technology Kuwait National IT Governance Framework Information Security Agenda 1 Manage security policy 2 Information security management system procedure Agenda 3 Manage

More information

Top tips for improved network security

Top tips for improved network security Top tips for improved network security Network security is beleaguered by malware, spam and security breaches. Some criminal, some malicious, some just annoying but all impeding the smooth running of a

More information

PCI Compliance. Top 10 Questions & Answers

PCI Compliance. Top 10 Questions & Answers PCI Compliance Top 10 Questions & Answers 1. What is PCI Compliance and PCI DSS? 2. Who needs to follow the PCI Data Security Standard? 3. What happens if I don t comply? 4. What are the basic requirements

More information

¼ããÀ ããè¾ã ¹ãÆãä ã¼ãîãä ã ããõà ãäìããä ã½ã¾ã ºããñ à Securities and Exchange Board of India

¼ããÀ ããè¾ã ¹ãÆãä ã¼ãîãä ã ããõà ãäìããä ã½ã¾ã ºããñ à Securities and Exchange Board of India CIRCULAR CIR/MRD/DP/13/2015 July 06, 2015 To, All Stock Exchanges, Clearing Corporation and Depositories. Dear Sir / Madam, Subject: Cyber Security and Cyber Resilience framework of Stock Exchanges, Clearing

More information

BAE Systems PCI Essentail. PCI Requirements Coverage Summary Table

BAE Systems PCI Essentail. PCI Requirements Coverage Summary Table BAE Systems PCI Essentail PCI Requirements Coverage Summary Table Introduction BAE Systems PCI Essential solution can help your company significantly reduce the costs and complexity of meeting PCI compliance

More information

Cloud Software Services for Schools

Cloud Software Services for Schools Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Please insert supplier details below Supplier name Address Contact name Contact email Contact

More information

HIPAA Security Alert

HIPAA Security Alert Shipman & Goodwin LLP HIPAA Security Alert July 2008 EXECUTIVE GUIDANCE HIPAA SECURITY COMPLIANCE How would your organization s senior management respond to CMS or OIG inquiries about health information

More information

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections. Evaluation Report

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections. Evaluation Report U.S. Department of Energy Office of Inspector General Office of Audits and Inspections Evaluation Report The Department's Unclassified Cyber Security Program 2011 DOE/IG-0856 October 2011 Department of

More information

Information Technology Security Review April 16, 2012

Information Technology Security Review April 16, 2012 Information Technology Security Review April 16, 2012 The Office of the City Auditor conducted this project in accordance with the International Standards for the Professional Practice of Internal Auditing

More information

8/17/2010. Over 90% of all compromised merchants are PCI level 4 (small) merchants or merchants with less than 1 million transactions per year

8/17/2010. Over 90% of all compromised merchants are PCI level 4 (small) merchants or merchants with less than 1 million transactions per year Over 90% of all compromised merchants are PCI level 4 (small) merchants or merchants with less than 1 million transactions per year Over 80% of compromised systems were card present or in-person transactions

More information

Network Password Management Policy & Procedures

Network Password Management Policy & Procedures Network Password Management Policy & Procedures Document Ref ISO 27001 Section 11 Issue No Version 1.3 Document Control Information Issue Date April 2009, June 2010, September 2011 Status Approved By FINAL

More information

A Rackspace White Paper Spring 2010

A Rackspace White Paper Spring 2010 Achieving PCI DSS Compliance with A White Paper Spring 2010 Summary The Payment Card Industry Data Security Standard (PCI DSS) is a global information security standard defined by the Payment Card Industry

More information

How To Protect Information At De Montfort University

How To Protect Information At De Montfort University Network Security Policy De Montfort University January 2006 Page 1 of 18 Contents 1 INTRODUCTION 1.1 Background... 1.2 Purpose and Scope... 1.3 Validity... 1.4 Assumptions... 1.5 Definitions... 1.6 References..

More information

Exam Papers Encryption Project PGP Universal Server Trial Progress Report

Exam Papers Encryption Project PGP Universal Server Trial Progress Report Exam Papers Encryption Project PGP Universal Server Trial Progress Report Introduction Using encryption for secure file storage and transfer presents a number of challenges. While the use of strong, well

More information