Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Egregious Privacy Infringment: Fire Chief Emails Photo Of Topless Crash Victim | Main | 13 Minnesota Students Disciplined For Facebook Photos »

New FTC Spam & Phishing Report

On December 28 the U.S. Federal Trade Commission (FTC) made a new report available to the public, "Spam Summit: The Next Generation of Threats and Solutions."

The report describes the findings from a July 2007 workshop the FTC hosted, and proposes follow-up action steps to mitigate the damages caused by malicious spam and phishing.

The report also provides:

* Recommended action steps to fight spam and phishing

* An overview of the FTC’s role in fighting spam and phishing

* Results from the FTC's 2007 Harvesting and Filtering Study

The report provides an interesting short history of spam and the subsequent next generations of annoying as well as malicious and privacy-invading messages.

The report also provides an interesting discussion of how, in October 2007, the FTC brought the first case using tools under the U.S. Safe Web Act (SAFE WEB), to stop spammers operating domestically and from outside the U.S., in Canada and Australia.

The report provides some good information and examples that could be used within spam and phishing awareness communications and training sessions.

Here's an excerpt that provides the FTC's recommendations for fighting spam and phishing:

"V. Next Steps

Based on the information provided by Spam Summit panelists, public comments submitted in response to the Spam Summit press release, and the Commission’s own research and law enforcement experience, FTC staff proposes the following next steps to combat malicious spam and phishing.

A. Stakeholders Should Heighten Collaboration Among Criminal Law Enforcement, Industry, and Other Stakeholders

The Summit record confirms that criminal authorities are best suited to tackle the problems of malicious spam and phishing. By collaborating with industry and working globally, the efforts of criminal law enforcement can only be heightened. Toward this end, stakeholders should maximize the effectiveness of partnerships among criminal law enforcement, industry, and other stakeholders in the fight against malicious spam, both domestically and abroad. In addition, the FTC will continue to bring civil law enforcement actions as appropriate.

B. Stakeholders Should Intensify Efforts to Deploy Technological Tools

Authentication technologies are critical building blocks for other spam-fighting tools. Stakeholders have made significant strides in the deployment of these technologies. Staff will encourage continued industry-driven efforts to deploy authentication, and, in turn, work with stakeholders to: (1) encourage entities and associations to authenticate outbound email;97 (2) educate senders about how to properly configure and authenticate their email; (3) urge ISPs to further implement negative scoring for non-authenticated email; and (4) urge ISPs that have the ability to detect bot activity to stop bots immediately to prevent unauthorized access to consumers’ computers by spammers and phishers.

C.Stakeholders Should Continue to Develop and Disseminate Effective Educational Materials for Consumers and Businesses

Consumer and business education can have a significant impact in the fight against spam and phishing.98 Because spam is an ever-evolving problem, stakeholders should revitalize efforts to educate consumers about how to protect their computers from online threats and improve methods for disseminating educational materials to consumers and businesses.99 In addition, the Summit identified consumer-interfacing tools such as spam reporting buttons as valuable tools for ISPs and reputation service providers.100 Accordingly, staff will encourage industry to continue to develop and fine-tune such tools."

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/622

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.