




版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡介
1、Data Security:A RoadmapDodi Iverson, Executive Vice PresidentDRIASIRichard Bellanca, Senior Vice PresidentBank of America CorporationDodi Iverson, Executive Vice PBank of AmericaOver 38 million consumer & small business relationshipsOver 5,800 retail banking officesOver 16,700 ATMsOver 14.7 million
2、active online usersNo. 1 overall Small Business Administration lender in the USBank of America Corporation stock (ticker: BAC) is listed on the New York Stock ExchangeHigher StandardsBank of AmericaOver 38 millioInsurance Services GroupLine of business within Global Consumer & Small Business Banking
3、Products Include:Credit Protection ProductsLoan Protection ProductsTerm Life InsuranceAccidental Death & DisabilityHealth Savings AccountsLong Term Care InsuranceHomeowners and Auto InsuranceInsurance Services GroupLine oDRIASIOutsourcing solution for insurance and non-insurance productsCarrier and
4、product independentService 250+ financial institutions and 50+ insurance companiesCore focus administrationEnd to end or modular solutionsRetention and process optimizationSAS 70 Type IIOperational excellence driven by security, innovation and reliabilityDRIASIOutsourcing solution forData can only b
5、e shared internally on a need to know basis. Examples include consumer information such as date of birth, marital status, social security number, health claims.Information intended for internal distribution only. Examples include organizational charts, inter-office mail, unreleased pilot offerings.I
6、nformation obtained from or intended for public disclosure. Examples include marketing brochures, press releases, annual reports.Terms & OverviewData vs. InformationConfidential Data Proprietary DataPublic DataEncryption068567839068-56-7839Transmitted data is coded, making it unintelligible if inter
7、cepted by a 3rd party. Only the sender and the recipient have the “key” to unlock the code. Data can only be shared internSecurity BreachesCommunications company robbed of employee dataIn efforts to recycle used paper, company exposes confidential customer dataLaptop stolen, Grad Students info expos
8、edID verification service provider sends personal, financial info to con artistsUn-encrypted data with 20 years of employee data vanishes while in transportSecurity BreachesCommunicationBehavior& ValueManagementAwareness &ResponsibilityRiskAssessmentSecurity Design& ManagementExecutionKeyComponentsD
9、ata Security RoadmapBehaviorAwareness &RiskSecuritMethods of the TradeSystem hackingCodes/scamsPhysical negligenceStolen equipmentDisgruntled employeesMethods of the TradeSystem hacIdentity Theft CategoriesPersonal Identifiable Theft:Examples: social security number, online banking log-in/passwordTh
10、eft is beyond a single accountThief has ability to create additional accountsLoss potential is greaterCriminal may wait in excess of 15 months before strikingAccount Theft:Example: credit card is stolenTheft is typically limited to a single accountShort-term window for thiefIdentity Theft Categories
11、PersoRoot Causes for Identity TheftPrevalence of SSN as a unique identifierInformation security not equal among organizationsMore information about individuals stored on central databasesPersonal securityExpansion of electronic fraudRoot Causes for Identity TheftKey Customer Data Customer data that
12、can be used against you:Checking or credit card account numbersSocial security numberDrivers license numberATM cardDate of birthHome addressPhone numberCredit reportsPasswordsKey Customer Data Customer datCommon Security ConcernsCyber threats rank higher than physical breaches73% felt domestic suppl
13、iers posed less riskBuyers dont believe security claims of suppliers and are conducting their own audits 30% factorISO 17799 ISO 27001SAS 70 Type IISource: Booz Allen Hamilton study, June 2019Common Security ConcernsCyber Data Security A Supplier DifferentiatorThenBetterServiceCostHigherQualityImpro
14、vedSatisfactionFreedResourcesInnovationNowCustomerCentricityCostDataSecurityRetentionData Security A Supplier DifAssessing Data Security RiskFailure Modes & Effects AnalysisAssessing Data Security RiskFaExpense vs. Security AchievedDollarsSecurity Achieved100%SecurityExpense vs. Security AchievedDDo
15、llar Amount Losses by TypeSource: CSI/FBI 2019 Computer Crime and Security Survey; Computer Security InstituteDollar Amount Losses by TypeSoSecurity Technologies UsedSource: CSI/FBI 2019 Computer Crime and Security Survey; Computer Security InstituteSecurity Technologies UsedSourData StewardData Ste
16、wards ensure that a critical asset, customer and account data, is received, verified and delivered to all appropriate information users in an accessible, consistent and timely manner.Data StewardData Stewards ensuData Exchange Process MapParticipants:3RD Party Vendor (Bus)3rd Party Vendor (Tech)BAC
17、Product ManagerBAC Information MgrPurpose:Introductory Meeting High level overview of the data exchange processParticipants:3RD Party Vendor (Bus)3rd Party Vendor (Tech)BAC Information MgrPurpose:# of FilesFile LayoutsFrequency ContactsExchange ProtocolsQuality Assurance requirementsSLAParticipants:
18、BAC Information MgrPurpose:Register data exchange in the central repositoryParticipants:BAC DTS3rd Party Vendor (Tech)Purpose:BAC DTS provides email with instructions for data exchange processParticipants:BAC DTS3rd Party Vendor (Tech)Purpose:Exchange IP AddressesExchange PasswordsNotification proce
19、duresAutomate scripts, if necessaryParticipants:BAC Information Manager3rd Party Vendor (Bus)3rd Party Vendor (Tech)Purpose:Review field definitionsDetermine valid values that vendor will provideAnswer additional questionsParticipants:BAC Information ManagerBAC - DTS3rd Party Vendor (Tech)Purpose:Te
20、st end to end file submission, connectivity testParticipants:BAC Information ManagerBAC - DTS3rd Party Vendor (Tech)3RD Party Vendor (Bus)Purpose:File receipt and loadContinual feedback on new valid values or data anomaliesData Exchange Process MapPartiData Management EnvironmentData Management Envi
21、ronmentMitigating TheftTechnical InfrastructureMulti-tier architectureMulti-factor authenticationContinuous server monitoringAccess controlsBusiness ProcessesEmployee trainingPolicy enforcementNo confidential data on hard driveCross shreddingAccess controlsTechnical ToolsEncryptionAnti-virus/spyware
22、Electronic Transmissions (Secure Sockets Layer (SSL), FTP/PGP, NDM)Mitigating TheftTechnical InfrInfrastructure CategoriesProduction Contact routines/calendarRoles & responsibilitiesChange controlAdding new sourcesQualityQuality assurance practicesMetadata managementDefect resolution processGovernan
23、ce The Data CouncilDownstream SLASource data provider SLAUser access/standardsCommunicationsCommunication planData Steward ProgramCorporate partnershipsInfrastructure CategoriesProdSAMPLEDO NOTUse your name in any formUse a word contained in dictionaries, or standard word listsUse other information
24、easily obtained about you Write a password down or store it online Reveal a password to anyoneUse shared accountsPassword Best PracticesDOUse a password with mixed-case lettersUse a password that contains alphanumeric characters and punctuationUse a password that can be typed quicklyChange passwords
25、 regularly blaK4borD2L8againSeeeSHorrAbf&r2ocSAMPLEDO NOTPassword Best PracInformation ExchangeAll data exchanges must be submitted via encrypted electronic transmission. Never submit customer or account data via tape, CD, disks, etc.Any email communication that contains confidential information must be encrypted.Data exchanges between vendors that contain BAC customer data must adhere to same standards
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 河北省邢臺(tái)市巨鹿縣二中2024年高三下學(xué)期高中等級(jí)考質(zhì)量抽測(cè)數(shù)學(xué)試題試卷
- 2024-2025學(xué)年江蘇省鹽城市解放路實(shí)驗(yàn)學(xué)校小學(xué)六年級(jí)數(shù)學(xué)畢業(yè)檢測(cè)指導(dǎo)卷含解析
- 路氹城2025年數(shù)學(xué)四年級(jí)第二學(xué)期期末統(tǒng)考模擬試題含解析
- 貴金屬在醫(yī)療設(shè)備制造中的創(chuàng)新技術(shù)
- 沈陽師范大學(xué)《西方文明史導(dǎo)論》2023-2024學(xué)年第二學(xué)期期末試卷
- 河北石油職業(yè)技術(shù)學(xué)院《建筑結(jié)構(gòu)設(shè)計(jì)A》2023-2024學(xué)年第二學(xué)期期末試卷
- 砌墻合同范本
- 哈爾濱幼兒師范高等??茖W(xué)?!禞ava語言程序設(shè)計(jì)》2023-2024學(xué)年第二學(xué)期期末試卷
- 遠(yuǎn)程診斷醫(yī)療的興起及市場(chǎng)調(diào)研概覽
- 北京語言大學(xué)《材質(zhì)燈光制作》2023-2024學(xué)年第二學(xué)期期末試卷
- 2024解析:第二章聲現(xiàn)象-基礎(chǔ)練(解析版)
- 整體法蘭強(qiáng)度校核計(jì)算表(設(shè)計(jì):zxg)
- 《供配電技術(shù)》課件第1章
- 建筑垃圾清理及運(yùn)輸方案
- 2024年甘肅省公務(wù)員錄用考試《行測(cè)》真題卷及答案解析
- 2024版Visio入門到精通完整教程
- 2024年團(tuán)??荚嚾雸F(tuán)考試題庫及答案
- 西鐵城手表H149機(jī)芯中文使用說明書
- 2024年執(zhí)業(yè)藥師繼續(xù)教育專業(yè)答案
- 非ST段抬高型急性冠脈綜合征診斷和治療指南(2024)解讀
- 報(bào)廢汽車拆解項(xiàng)目可行性研究報(bào)告
評(píng)論
0/150
提交評(píng)論