READER QUESTION
I'm looking for some workable strategies to ensure we don't accidentally post confidential member data online; an issue we just had a very close call with. What are your panel's suggestions?
John San Filippo, Marketing Manager, Symitar, San Diego
I wouldn't go so far as to say preventing the theft of member data is easy, but it's certainly manageable-if you adhere to some basic best practices. For starters, your entire network needs a solid perimeter defense, meaning some combination of a firewall and an intrusion detection/prevention server, or IDS. It's also critical that both systems are fully patched and monitored continuously.
Best practices demand that computers that store sensitive data never be allowed direct access to/from the Internet. Internet data should be routed to a front-end server located in a demilitarized zone, or DMZ. The front-end server accepts connections from a client and then proxies the information to the back-end server. The front-end server can handle all the SSL traffic, reducing overhead on the back-end server. Common uses for front-end servers are home banking applications and web-based e-mail access for you employees.
It's important to keep in mind, though, that a lot of ID theft occurs internally. That's why it's extremely important to have good internal security measures, too. This includes restricting access to USB drives, recordable CD/DVD drives and any other portable media accessed with a PC. All sensitive information taken offsite should be encrypted, including backup tapes and laptop hard drives.
Chris Barber, Senior Vice President/Chief Information Officer, WesCorp, San Dimas, Calif.
A suggestion would be to combine user awareness training with strong outbound controls over the use of the Internet-both web and e-mail.
There are commercial "data leak prevention" products from almost all of the security vendors that can also greatly help however they must be specifically tuned to look for member data and pointed at places on the network that could detect it. For example, an endpoint data leak product can monitor a workstation/laptop for any instance where the user attempts to copy or upload information that contains the data format of a Social Security Number or credit card number. It's not an exact science yet, however it may be worth investigating.
READER QUESTION
Just how much of a hassle will the new Red Flag rules really be, and is there any aspect of those rules your panel thinks are not getting the attention they deserve?
Ted Dreyer, Senior Attorney, Wolters Kluwer Financial Services, Minneapolis
There are no specific requirements regarding documentation of your Red Flags compliance program, but you should do so to show the regulators you are complying with the rules.
First, document your program development, including your process for a risk assessment to determine which accounts are covered accounts as well as your decision-making process for determining which Red Flags are relevant for your covered accounts and how they should be detected.
After your program is in place, document your ongoing processes. There are several reasons for doing this:
* for audit and examination purposes to show that you are following your program;
* to provide a documented basis to assist in the reporting that is required to be done as part of your program's administration, and
* to standardize your process for training to make training easier and more consistent across the various operational areas at your credit union.
Ongoing documentation should cover:
* Red flags detected;
* Responses taken to detected red flags;
* Records of your required training; and
* The annual reporting on your program that is required.
Following the steps above will help you adequately document your Red Flags compliance program, illustrating to regulators you're doing everything possible to comply with the new requirements.
Kay Nichols, Executive Vice President, Fidelity National Information Services, Inc., Jacksonville, Florida
It's going to be quite a hassle! While auditors may have been lenient on first examinations in the past, regulators have now indicated that they expect institutions to be fully compliant by the Nov. 1 deadline. Most credit unions will need to take rapid action to meet the stringent regulatory demands.
Examiners will look for evidence that an ID theft prevention program is in place and that red flags are being logically detected, managed and, most importantly, acted upon.
We think address analysis in particular is an area where many financial institutions will fall short, but every company is different. Our approach is to help evaluate the tools credit unions already have in place, and supplement those with additional components that will give them the complete solution they need at the least cost and hassle. We have information available at www.FISOneVoice.com/redflag that will help clients better understand the new rules and requirements and also show how we can help.
Chris Barber, Wescorp, San Dimas, Calif.
In meetings with our examiners, they stated that the Red Flag rules should be an extension of existing enterprise risk management and anti-fraud procedures. To that end, it should be a matter of formalizing aspects of a program that may already be in place or incorporating some best practices if there are gaps.
Have a question for our panel of experts? Send it to Managing Editor Lisa Freeman at lfreeman










