版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、data security:a roadmapdodi iverson, executive vice presidentdriasirichard bellanca, senior vice presidentbank of america corporationbank of americaover 38 million consumer & small business relationshipsover 5,800 retail banking officesover 16,700 atmsover 14.7 million active online usersno. 1 o
2、verall small business administration lender in the usbank of america corporation stock (ticker: bac) is listed on the new york stock exchangehigher standardsinsurance services groupline of business within global consumer & small business bankingproducts include:qcredit protection productsqloan p
3、rotection productsqterm life insuranceqaccidental death & disabilityqhealth savings accountsqlong term care insuranceqhomeowners and auto insurancedriasioutsourcing solution for insurance and non-insurance productscarrier and product independentservice 250+ financial institutions and 50+ insuran
4、ce companiescore focus administrationend to end or modular solutionsretention and process optimizationsas 70 type iioperational excellence driven by security, innovation and reliabilitydata can only be shared internally on a need to know basis. examples include consumer information such as date of b
5、irth, marital status, social security number, health claims.information intended for internal distribution only. examples include organizational charts, inter-office mail, unreleased pilot offerings.information obtained from or intended for public disclosure. examples include marketing brochures, pr
6、ess releases, annual reports.terms & overviewdata vs. informationconfidential data proprietary datapublic dataencryption068567839068-56-7839transmitted data is coded, making it unintelligible if intercepted by a 3rd party. only the sender and the recipient have the “key” to unlock the code. secu
7、rity breachescommunications company robbed of employee datain efforts to recycle used paper, company exposes confidential customer datalaptop stolen, grad students info exposedid verification service provider sends personal, financial info to con artistsun-encrypted data with 20 years of employee da
8、ta vanishes while in transportbehavior& valuemanagementawareness &responsibilityriskassessmentsecurity design& managementexecutionkeycomponentsdata security roadmapmethods of the tradesystem hackingcodes/scamsphysical negligencestolen equipmentdisgruntled employeesidentity theft categori
9、espersonal identifiable theft:qexamples: social security number, online banking log-in/passwordqtheft is beyond a single accountqthief has ability to create additional accountsqloss potential is greaterqcriminal may wait in excess of 15 months before strikingaccount theft:qexample: credit card is st
10、olenqtheft is typically limited to a single accountqshort-term window for thiefroot causes for identity theftprevalence of ssn as a unique identifierinformation security not equal among organizationsmore information about individuals stored on central databasespersonal securityexpansion of electroni
11、c fraudkey customer data customer data that can be used against you:qchecking or credit card account numbersqsocial security numberqdrivers license numberqatm cardqdate of birthqhome addressqphone numberqcredit reportsqpasswordscommon security concernscyber threats rank higher than physical breaches
12、73% felt domestic suppliers posed less riskbuyers dont believe security claims of suppliers and are conducting their own audits 30% factoriso 17799 iso 27001sas 70 type iisource: booz allen hamilton study, june 2006data security a supplier differentiatorthennowassessing data security riskfailure mod
13、es & effects analysisexpense vs. security achieveddollarssecurity achieved100%securitydollar amount losses by typesource: csi/fbi 2005 computer crime and security survey; computer security institutesecurity technologies usedsource: csi/fbi 2005 computer crime and security survey; computer securi
14、ty institutedata stewarddata stewards ensure that a critical asset, customer and account data, is received, verified and delivered to all appropriate information users in an accessible, consistent and timely manner.data exchange process mapparticipants: 3rd party vendor (bus) 3rd party vendor (tech)
15、 bac product manager bac information mgrpurpose: introductory meeting high level overview of the data exchange processparticipants: 3rd party vendor (bus) 3rd party vendor (tech) bac information mgrpurpose: # of files file layouts frequency contacts exchange protocols quality assurance requirements
16、slaparticipants: bac information mgrpurpose: register data exchange in the central repositoryparticipants: bac dts 3rd party vendor (tech)purpose: bac dts provides email with instructions for data exchange processparticipants: bac dts 3rd party vendor (tech)purpose: exchange ip addresses exchange pa
17、sswords notification procedures automate scripts, if necessaryparticipants: bac information manager 3rd party vendor (bus) 3rd party vendor (tech)purpose: review field definitions determine valid values that vendor will provide answer additional questionsparticipants: bac information manager bac - d
18、ts 3rd party vendor (tech)purpose: test end to end file submission, connectivity testparticipants: bac information manager bac - dts 3rd party vendor (tech) 3rd party vendor (bus)purpose: file receipt and load continual feedback on new valid values or data anomaliesdata management environmentmitigat
19、ing thefttechnical infrastructureqmulti-tier architectureqmulti-factor authenticationqcontinuous server monitoringqaccess controlsbusiness processesqemployee trainingqpolicy enforcementqno confidential data on hard driveqcross shreddingqaccess controlstechnical toolsqencryptionqanti-virus/spywareqel
20、ectronic transmissions (secure sockets layer (ssl), ftp/pgp, ndm)infrastructure categoriesproduction contact routines/calendarroles & responsibilitieschange controladding new sourcesqualityquality assurance practicesmetadata managementdefect resolution processgovernance the data councildownstrea
21、m slasource data provider slauser access/standardscommunicationscommunication plandata steward programcorporate partnershipssampledo notuse your name in any formuse a word contained in dictionaries, or standard word listsuse other information easily obtained about you write a password down or store
22、it online reveal a password to anyoneuse shared accountspassword best practicesdouse a password with mixed-case lettersuse a password that contains alphanumeric characters and punctuationuse a password that can be typed quicklychange passwords regularly blak4bord2l8againseeeshorrabf&r2ocinformat
23、ion exchangeall data exchanges must be submitted via encrypted electronic transmission. never submit customer or account data via tape, cd, disks, etc.any email communication that contains confidential information must be encrypted.data exchanges between vendors that contain bac customer data must adhere to same standards as exchanging with bac.never store customer or other sensitive banking data on computer/laptop hard drives.governance elementsmajor deliverables: service level agreements source providers service level agreements information users user access request forms
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 有机化学探究
- XX 学研-K12 个性化学习力提升机构创业计划书范文
- 奥林匹克运动会专题解析
- 大华监控管理平台
- 产科医院实习心得总结
- 餐饮每周工作总结
- 宇宙秘境解析
- 英语学习之路
- 班组及人员管理
- 安管员入职培训 – 埃森哲管理咨询公司
- 2022年煤炭企业管理现代化创新成果获奖项目
- GB/T 3033.1-2005船舶与海上技术管路系统内含物的识别颜色第1部分:主颜色和介质
- GA/T 1173-2014即时通讯记录检验技术方法
- GA 1800.2-2021电力系统治安反恐防范要求第2部分:火力发电企业
- 《公路设计》第九章-挡土墙设计(39P)课件
- 工程案例-金域华府住宅小区
- 肾病综合征护理查房课件-
- 《建设项目全过程造价咨询规程》2017年1月18日
- 人音版小学音乐二上《蜗牛与黄鹂鸟》课件
- 土壤样品采集现场记录表
- (完整版)永遇乐京口北固亭怀古学案及答案
评论
0/150
提交评论