Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Addressing Web-Based Access and Authentication Challenges | Main | Maine Seed Company Website Hacked: Demonstrates SMB Vulnerability & Questions Hacker Safe Seals »

Vermont State Privacy Breach Follow-up: Penetration Testing Reveals No Additional Vulnerabilities

After the January Vermont State privacy breach through a remote attack that compromised Social Security numbers and bank account numbers for nearly 70,000 people, Governor Jim Douglas ordered a security review of the computer systems.

Today it was reported that no other vulnerabilities were found in the online applications and systems.

""The penetration testing of the State's web applications have not exposed any vulnerability in the web-based systems," according to the report, issued Thursday. "Agency reviews of their security measures and applications have not uncovered any serious issues."

Department Commissioner Thomas Murray said the review uncovered a number of minor administrative concerns about which the state needs to be more diligent."

"Among the recommendations, the report advises the state:

_implement a more thorough process for system support, documentation and managing the impacts of changes in the system;

_implement a system of data access procedures that ensures the appropriate level of access to confidential data;

_strengthen its security policies and standards;

_set up new "demilitarized zones" the state's main computer network, Govnet, to allow key partners like the federal government access to some state systems while barring them from wide-open access to the network.

Murray said the many of these steps were under way.

Other changes include a new encryption policy, stepped-up employee training on security issues and annual audits with funding for new equipment hinging on problems being fixed.

Over the next few months all state departments and agencies will be asked to complete an inventory and risk assessment of their computer systems, he said. "All systems with confidential data will be required to submit a security plan and each system will be audited based on need and risk," the report said.

Douglas also has asked the department to create long-term protocols to strengthen the state's computer security.

Completing those steps could take up to a year, Murray said."


Good plans. Hopefully they will be fulfilled.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/332

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.