Home > Ask the Security Experts > Security Management Questions & Answers > How can birth certificate fraud and passport fraud be prevented?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How can birth certificate fraud and passport fraud be prevented?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 16 January 2008
What should be done to prevent hackers from using birth certificates and passports for fraudulent activity? What advice do you have for individuals and companies? It seems like this is happening more often.

>
EXPERT RESPONSE
It really depends on the type of business. Birth certificates and passports aren't really that useful when running an online business -- they're essentially paper documents in an increasingly digital world. In any case, corporations should verify identity based upon a credit card lookup to make sure that the card number, address and CVV2 number are consistent. For an financial transaction, that usually suffices and meets the risk criteria of the merchant bank that is underwriting the purchase.

In terms of a brick-and-mortar retail or other business services environment, it's a different ballgame and corporations need to walk the fine line between causing the transaction to be painful for the customer and ensuring that it is secure. Again, it gets back to an organization's tolerance for risk and to what degree a company wants to inconvenience its customers by making them bring all sorts of supporting documentation to prove who they are.

The final point I'll make is that employees need to be trained to spot fake credentials and to ask the appropriate questions if they get suspicious. If employees don't enforce with the same level of scrutiny, then the tightest policy in the world won't matter too much. An enterprise also needs to have a defined process to deal with such situations quickly and effectively. Front-line employees shouldn't solely bear the brunt of a hacker that is trying to commit fraud.

More information:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Management
What's your advice for getting other business units to contribute to crafting an effective information security policy?
How can organizations secure implanted microchips and RFID tags?
Any recommendations for recruiting information security pros?
I am concerned that a former employee will utilize corporate information in a malicious way.
Is it necessary to grant a full administrative privileges to a security administrator?
Recently I found my computer's serial number had been reported stolen. Will I face legal repercussions?
What are the possible benefits of microchip implants and RFID tags for employees?
Is it against HIPAA regulations to permanently store sensitive information?
Two-tier distributed systems vs. three-tier distributed systems
How to prevent software piracy

Identity Theft and Data Security Breaches
TJX hacking ring charged in federal indictment
Security data lapses hamper researchers
Data breaches caused by employee errors, process failures
Data breach laws have no effect on prevention, researchers say
Walter Reed admits breach of patient information
Address Authentication and Transaction Validation Protocols to Stem Identity Theft
Stolen data ending up in Google cache, say researchers
Security breach management: Planning and preparation
Societe Generale bolsters internal controls, discovers second insider
Companies still monitoring email manually, survey finds

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
CISP-PCI  (SearchFinancialSecurity.com)
cookie poisoning  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
extrusion prevention  (SearchSecurity.com)
identity theft  (SearchSecurity.com)
parameter tampering  (SearchSecurity.com)
pretexting  (SearchCIO.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts