Home > Beyond HIPAA and GLBA
Information Security magazine:
EMAIL THIS

Beyond HIPAA and GLBA

01 Aug 2006 | Kelley Damore, Editorial Director

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Most organizations are familiar with HIPAA, Gramm-Leach-Bliley (GLBA) and Sarbanes-Oxley (SOX), but newer regulations are pushing certain industry sectors to adopt strong authentication.

The Federal Financial Institutions Examination Council (FFIEC), which consists of five federal banking regulators, issued guidance last October that financial institutions must deploy security measures to reliably authenticate online banking customers. While the FFIEC guidance does not specify the type of authentication technology needed, it does say that single-factor authentication is insufficient in light of increasingly sophisticated malware and rising identity theft. Banks must conduct comprehensive assessments of the risks associated with online banking and adopt authentication methods to reduce the risks by January. This regulation came as a surprise to some, but could set a standard for the security industry, says Cydelity CEO Bob Ciccone. In other domains, like e-commerce, sites can be hacked the same way as with online banking, he says, and the FFIEC could spur projects and products.

At the same time, federal agencies are grappling with Homeland Security Presidential Directive 12 (HSPD 12), which was issued in August 2004 and requires them to have a single ID card for physical and IT access. The card must be strongly resistant to fraud and tampering and be rapidly verifiable electronically.

More on authentication and compliance

Visit Identity and Access Management Security School to learn how to create an effective identity and access mangement plan to meet the demands of government regulations.

Learn more about two-factor authentication and FFIEC compliance.

According to security experts, agencies are scrambling to meet HSPD 12's Oct. 27 deadline for implementation. The National Institute of Standards and Technology (NIST) issued a standard, called FIPS 201 PIV, for the directive in February, but products are still being mapped out, evaluated and certified to the standard. Complying with HSPD 12 will take time, and some question whether it will have a positive impact. According to a survey done by RSA Security, 76% of government integrators polled said none or only a few, of the agencies they do business with view HSPD 12 as an opportunity to lay the foundation for longer term identity and access management initiatives. But if the directive is successful, David Troy, identity solutions delivery manager at EDS, says HSPD 12 will drive interest for smart cards, which has had lackluster acceptance in the commercial sector in the U.S.



BROWSE BY TAG
Security Audit, Compliance and Standards,   FFIEC Regulations and Guidelines,   Gramm-Leach-Bliley Act (GLBA),   HIPAA,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
FFIEC Regulations and Guidelines
FTC Red Flags Rules: How to create an identity theft prevention plan
Protecting data in a merger and acquisition
This May Day, banks wave the Red Flags
IT security pros face challenge during economic crisis
Understanding multifactor authentication features in IAM suites
Compliance drives credit union to catch online bill payment fraudsters
The road to compliance
At RSA, feds seek help to close widening cybersecurity gaps
TJX should have had stronger Wi-Fi encryption, say Canadian officials
Interview: FDIC director explains FFIEC standard

Gramm-Leach-Bliley Act (GLBA)
Implement security and compliance in a risk management context
The road to compliance
IBM to boost security spending, push PCI DSS program
ISO 27001 could bridge the regulatory divide, expert says
Policies and regulatory compliance
Where hard drives go to die, or do they?
Compliance guide for managers: Lessons learned and best decisions
Become compliant -- without breaking the bank
Compliance Guide for Managers
Making sense of the maze
Gramm-Leach-Bliley Act (GLBA) Research

HIPAA
Cost of security, IT management add up at healthcare facilities, study finds
Healthcare security spending remains sluggish, report shows
Creating a HIPAA employee training program
FTC extends breach notification to Web-based health repositories
Are there guidelines to create a HIPAA-compliant data center?
HHS HIPAA guidance on encryption requirements and data destruction
Writing a patient identifier policy to prevent common HIPAA violations
HIPAA compliance: New regulations change the game
HIPAA compliance manual: Training, audit and requirement checklist
Key elements of a HIPAA compliance checklist
HIPAA Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
FFIEC compliance  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Find Expert White Papers on Financial Data Security
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts