<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: davidson]]></title>
    <link>http://securityratty.com/tag/davidson</link>
    <description></description>
    <pubDate>Sat, 29 Dec 2007 08:30:26 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fugitive spammer dead in apparent murder-suicide]]></title>
      <link>http://securityratty.com/article/5eb33436e1926a40842af2cdf1f91a5d</link>
      <guid>http://securityratty.com/article/5eb33436e1926a40842af2cdf1f91a5d</guid>
      <description><![CDATA[Spammer and escaped convict Eddie Davidson shot his wife and three-year-old daughter before turning the gun on himself Thursday night in Bennet,...]]></description>
      <content:encoded><![CDATA[Spammer and escaped convict Eddie Davidson shot his wife and three-year-old daughter before turning the gun on himself Thursday night in Bennet, Colorado.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=OBwgMQ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=OBwgMQ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/345461372" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 07:29:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spammer">spammer</category>
      <category domain="http://securityratty.com/tag/thursday night">thursday night</category>
      <category domain="http://securityratty.com/tag/three-year-old daughter">three-year-old daughter</category>
      <category domain="http://securityratty.com/tag/wife">wife</category>
      <category domain="http://securityratty.com/tag/bennet">bennet</category>
      <category domain="http://securityratty.com/tag/gun">gun</category>
      <category domain="http://securityratty.com/tag/colorado">colorado</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/345461372/article.do">Fugitive spammer dead in apparent murder-suicide</source>
    </item>
    <item>
      <title><![CDATA[Colorado 'Spam King' walks away from prison camp]]></title>
      <link>http://securityratty.com/article/4498c83010a7c8588bb326a52c3ad739</link>
      <guid>http://securityratty.com/article/4498c83010a7c8588bb326a52c3ad739</guid>
      <description><![CDATA[Convicted penny-stock spammer Eddie Davidson walked away from a federal minimum-security prison camp in Colorado on Sunday, the U.S. Department of Justice said...]]></description>
      <content:encoded><![CDATA[Convicted penny-stock spammer Eddie Davidson walked away from a federal minimum-security prison camp in Colorado on Sunday, the U.S. Department of Justice said Tuesday.]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prison camp">prison camp</category>
      <category domain="http://securityratty.com/tag/colorado">colorado</category>
      <category domain="http://securityratty.com/tag/sunday">sunday</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/justice">justice</category>
      <category domain="http://securityratty.com/tag/federal">federal</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <source url="http://www.networkworld.com/news/2008/072208-colorado-spam-king-walks-away.html?fsrc=rss-security">Colorado 'Spam King' walks away from prison camp</source>
    </item>
    <item>
      <title><![CDATA[Colorado penny stock spammer gets jail time]]></title>
      <link>http://securityratty.com/article/42876d784b3126d33ce832f880c9bd9b</link>
      <guid>http://securityratty.com/article/42876d784b3126d33ce832f880c9bd9b</guid>
      <description><![CDATA[A federal judge has ordered convicted spammer Eddie Davidson to just under two years in prison for sending out a large volume of spam promoting watches, perfume and penny...]]></description>
      <content:encoded><![CDATA[A federal judge has ordered convicted spammer Eddie Davidson to just under two years in prison for sending out a large volume of spam promoting watches, perfume and penny stocks.<p><NOLAYER>
<IFRAME id="rss" src="http://ad.doubleclick.net/adi/idg.us.nwf.rss/security;sz=468x60;ord=5368?" width="468" height="60" frameborder="no" border="0" marginwidth="0" marginheight="0" scrolling="no">
<A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=5368?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=5368?" border="0" width="468" height="60"></A>
</IFRAME>
</NOLAYER></p>]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spammer eddie davidson">spammer eddie davidson</category>
      <category domain="http://securityratty.com/tag/federal judge">federal judge</category>
      <category domain="http://securityratty.com/tag/penny stocks">penny stocks</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/volume">volume</category>
      <category domain="http://securityratty.com/tag/perfume">perfume</category>
      <category domain="http://securityratty.com/tag/prison">prison</category>
      <category domain="http://securityratty.com/tag/watches">watches</category>
      <source url="http://www.networkworld.com/news/2008/043008-colorado-penny-stock-spammer-gets.html?fsrc=rss-security">Colorado penny stock spammer gets jail time</source>
    </item>
    <item>
      <title><![CDATA[Is This How Security Will Be Improved?]]></title>
      <link>http://securityratty.com/article/3d5595bce86c4a3a5c72125e493268cb</link>
      <guid>http://securityratty.com/article/3d5595bce86c4a3a5c72125e493268cb</guid>
      <description><![CDATA[Davidson Cos. Sued for Negligence in Data Breach: Lawsuit confirms that companies can be held liable for failing to provide adequate security&quot; ( source

A Billings, Mont., law firm has filed a...]]></description>
      <content:encoded><![CDATA["Davidson Cos. Sued for Negligence in Data Breach: Lawsuit confirms that companies can be held liable for failing to provide adequate security" (<a href="http://www.darkreading.com/document.asp?doc_id=149916">source</a>)<br /><br />"<span><span><span>A Billings, Mont., law firm has filed a class-action lawsuit in federal court against Davidson Companies, claiming the company was negligent when it allowed a hacker to penetrate its systems, resulting in a data security breach and the exposure of some 226,000 customer records, according to a <a href="http://www.greatfallstribune.com/apps/pbcs.dll/article?AID=/20080401/NEWS01/80401014" target="new">report</a>."<br /><br />This will be immensely fun to watch! So, for those companies that didn't start paying enough attention to security after viruses, then worms, then SOX, then PCI DSS, than bots, then data loss, then data theft, how about a threat of a nice cold lawsuit? Will it be enough to pay attention?<br /><br />Well, we will see soon :-)<br /></span></span></span><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=f0cpHYG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=f0cpHYG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mp1tzFG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mp1tzFG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/265965852" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 07 Apr 2008 12:20:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/data security breach">data security breach</category>
      <category domain="http://securityratty.com/tag/davidson companies">davidson companies</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/nice cold lawsuit">nice cold lawsuit</category>
      <category domain="http://securityratty.com/tag/data loss">data loss</category>
      <category domain="http://securityratty.com/tag/immensely fun">immensely fun</category>
      <category domain="http://securityratty.com/tag/davidson cos">davidson cos</category>
      <category domain="http://securityratty.com/tag/data breach">data breach</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/265965852/is-this-how-security-will-be-improved.html">Is This How Security Will Be Improved?</source>
    </item>
    <item>
      <title><![CDATA[Show 024 - An Interview with Mary Ann Davidson]]></title>
      <link>http://securityratty.com/article/f7c222ddabf1457a517c5a30329d0a68</link>
      <guid>http://securityratty.com/article/f7c222ddabf1457a517c5a30329d0a68</guid>
      <description><![CDATA[Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast. Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracles Unbreakable...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Mary Ann Davidson" title="Mary Ann Davidson" src="http://www.cigital.com/silverbullet/madavidson-125.gif" /></p>
<p>Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast.  Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle&#8217;s &#8220;Unbreakable&#8221; campaign, why everyone needs training in secure coding, and how military history informs computer security.  They also talk about how a young CSO-to-be got her first library card.</p>
<ul>
<li><a href="http://blogs.oracle.com/maryanndavidson/">Mary Ann Davidson&#8217;s blog</a></li>
<li><a href="http://wiki.oracle.com/page/Unbreakable+Linux">Unbreakable Linux</a></li>
<li><a href="http://www.amazon.com/Lone-Survivor-Eyewitness-Account-Operation/dp/0316067598"><em>Lone Survivor</em></a></li>
</ul>
]]></content:encoded>
      <pubDate>Fri, 14 Mar 2008 15:26:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mary ann discuss">mary ann discuss</category>
      <category domain="http://securityratty.com/tag/oracles unbreakable campaign">oracles unbreakable campaign</category>
      <category domain="http://securityratty.com/tag/mba helps">mba helps</category>
      <category domain="http://securityratty.com/tag/lone survivor">lone survivor</category>
      <category domain="http://securityratty.com/tag/24th episode">24th episode</category>
      <category domain="http://securityratty.com/tag/library card">library card</category>
      <category domain="http://securityratty.com/tag/cso role">cso role</category>
      <category domain="http://securityratty.com/tag/unbreakable linux">unbreakable linux</category>
      <category domain="http://securityratty.com/tag/cso-to-be">cso-to-be</category>
      <source url="http://www.cigital.com/silverbullet/show-024/">Show 024 - An Interview with Mary Ann Davidson</source>
    </item>
    <item>
      <title><![CDATA[Davidson Companies illegal network intrusion exposes clients]]></title>
      <link>http://securityratty.com/article/e580ded3be81588059a124b7aaa4e5ef</link>
      <guid>http://securityratty.com/article/e580ded3be81588059a124b7aaa4e5ef</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/30/08

Organization
Davidson Companies

Davidson Companies is a financial services holding company based in Montana. It includes D.A. Davidson &amp; Co.,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/Davidson.jpg" align="right" height="119" width="115"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/30/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.davidsoncompanies.com" target="_blank"> Davidson Companies</a>* <br><font size="1"><br>*"Davidson Companies is a financial services holding company based in Montana. It includes D.A. Davidson &amp; Co., an investment firm; Davidson Investment Advisors, a money management firm; Davidson Trust Co., a wealth management and trust company; Davidson Fixed Income Management, an investment and money management services firm; and Davidson Travel, a travel agency." - Source InformationWeek story</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Clients and former clients<br><br><span style="font-weight: bold;">Number Affected:</span><br>226,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, Social Security numbers, and account numbers and balances<br><br><span style="font-weight: bold;">Breach Description:</span><br>Davidson Companies announced that a database containing sensitive personal information belonging to clients and former clients was accessed via an "illegal network intrusion".<br><br><span style="font-weight: bold;">Reference URL:</span><br>Davidson Companies "<a href="http://www.davidsoncompanies.com/protect/" target="_blank"> Important Client Announcement</a>" <br><a href="http://www.greatfallstribune.com/apps/pbcs.dll/article?AID=/20080130/NEWS01/801300301/1002" target="_blank"> Great Falls Tribune online story</a> <br><a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=206100536" target="_blank"> InformationWeek news story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Erin Madison, Great Falls Tribune Business, with a special thanks to "Coop" <br>a Breach Blog reader<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Davidson Companies clients and former clients were notified the week of January 28 of an illegal network intrusion, and steps clients should take to protect themselves from identity theft, including enrolling for a credit monitoring product being offered at Davidson's expense for 12 months.<br><br>A computer hacker broke into a Davidson Companies database and obtained the names and Social Security numbers of virtually all of the Great Falls financial services company's clients.<br><br>The database included information such as account numbers and balances, said Jacquie Burchard, spokeswoman for Davidson Companies. However, the hacker didn't get access to the accounts.<br><br>"People's accounts at Davidson are fine," Burchard said. "Their assets are fine."<br><span style="font-style: italic;">[Evan] Not really, I think of a Social Security number is an asset, an information asset.&nbsp; Just as important as protecting financial or physical assets is protecting information assets.</span><br><br>The computer hacker accessed information on 226,000 current and former clients, Burchard said.<br><br>"With the investigation ongoing, it would be inappropriate to delve into the technical aspects of the security breach," - Burchard<br><span style="font-style: italic;">[Evan] No disrespect, but I don't think Jacquie Burchard would be qualified to "delve into the technical aspects".</span><br><br>"Despite our efforts to safeguard client information, a computer hacker using sophisticated techniques illegally accessed a database and obtained access to confidential client information," said William A. Johnstone, Davidson Companies president and CEO<br><span style="font-style: italic;">[Evan] I respect Mr. Johnstone for communicating his thoughts about this breach.&nbsp; It demonstrates his understanding that he has a fiduciary responsibility to protect confidential information.&nbsp; I think we would be surprised at how many corporate executives do not understand this simple fact.&nbsp; Remember, terms like "sophisticated" are subjective and depend on perspective.</span><br><br>"All of us at Davidson are acutely aware of the uncertainty, stress and inconvenience associated with the potential compromise of personal information. We are fully committed to helping our clients deal with this unfortunate event as quickly as possible and are adopting measures to further enhance our network security." - Johnstone<br><br>The financial services company is temporarily opening call centers and extending branch hours to help answer clients' questions.<br><br>Current clients should call 800-909-6485.<br><br>Former clients should call 800-736-6153.<br><br>The Great Falls office of D.A. Davidson &amp; Co. will be open for extended hours this week as follows:7 a.m. to 7 p.m. through Friday and 9 a.m. to 4 p.m. Saturday<br><br>The computer break-in occurred earlier this month, Burchard said. Authorities investigating the crime asked the company to keep the news extremely confidential during the early stages of the investigation.<br><br>This was a "very, very sophisticated hacker," Burchard said. "We don't know where this person is; we don't know who this person is."<br><span style="font-style: italic;">[Evan] I speculate (I like to speculate when there is little risk!) that this attack was not as technologically advanced as claimed.&nbsp; How "very, very sophisticated" does an attacker need to be in order to convince another person to click on a link or open a browser.&nbsp; Often what seems to be very sophisticated is often very simple.&nbsp; Does that sound like Confucius?</span><br><br>Davidson Companies has many procedures and policies in place to protect client information, Johnstone added.<br><br>The company reportedly hired a penetration testing company last September to assess its IT security and the firm's hackers did not find any holes.<br><span style="font-style: italic;">[Evan] If this company was worth a hill of beans, they should have found flaws.&nbsp; I am going to speculate again and say that they are and did.&nbsp; I don't think that this was a typical external hack (attack).</span><br><br>"Obviously, we're enhancing our IT (Information Technology) security systems," Burchard said.<br><span style="font-style: italic;">[Evan] Yeah, obviously!&nbsp; ALL of us should ALWAYS be enhancing our security systems.&nbsp; Security is a life cycle discipline that requires constant monitoring and improvement.&nbsp; No destination here.</span><br><br>Law enforcement agencies note that because people are constantly finding new ways to hack into systems, it's an ongoing problem, she said.<br><br><span style="font-weight: bold;">Commentary:</span><br>I think I speculated more about this breach than I about any other on The Breach Blog.&nbsp; Maybe it’s a Friday thing, and maybe I have a point to make even if my speculation is 180 degress off.&nbsp; I suppose this could have been some uber l337 hack that got past multiple layers of defense such as firewalls, hardened servers, IDS/IPS, etc. (supposing they exist), but I can tell you that if this was the case, this is rare.&nbsp; Why go through all the work, when there are more effective means to access the same information?<br><br>A majority of security breaches are the result of simple mistakes, lack of knowledge, laziness, and/or poor common sense.<br><br>OK, I am stepping down from my soap box now.&nbsp; Have a nice weekend.<br><br>FYI, the Davidson login page is down<br><img src="http://images.quickblogcast.com/95781-88451/davidsondown.jpg" border="0" width="613">&nbsp;<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/01/davidson.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 01 Feb 2008 11:51:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/davidson">davidson</category>
      <category domain="http://securityratty.com/tag/clients">clients</category>
      <category domain="http://securityratty.com/tag/davidson companies president">davidson companies president</category>
      <category domain="http://securityratty.com/tag/davidson companies clients">davidson companies clients</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/davidson login page">davidson login page</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/davidson companies">davidson companies</category>
      <category domain="http://securityratty.com/tag/davidson trust">davidson trust</category>
      <source url="http://breachblog.com/2008/02/01/davidson.aspx">Davidson Companies illegal network intrusion exposes clients</source>
    </item>
    <item>
      <title><![CDATA[Financial services firm hacked ]]></title>
      <link>http://securityratty.com/article/ff7539fe15c44b91d854ddb8becf2bfe</link>
      <guid>http://securityratty.com/article/ff7539fe15c44b91d854ddb8becf2bfe</guid>
      <description><![CDATA[Great Falls, Mont.-based Davidson Companies yesterday disclosed that hackers broke into its networks and gained access to a database containing the personal information of its...]]></description>
      <content:encoded><![CDATA[Great Falls, Mont.-based Davidson Companies yesterday disclosed that hackers broke into its networks and gained access to a database containing the personal information of its clients.]]></content:encoded>
      <pubDate>Wed, 30 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/davidson companies yesterday">davidson companies yesterday</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/clients">clients</category>
      <category domain="http://securityratty.com/tag/falls">falls</category>
      <category domain="http://securityratty.com/tag/mont">mont</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <source url="http://www.networkworld.com/news/2008/013108-davidson-customer-information-hacked.html?fsrc=rss-security">Financial services firm hacked </source>
    </item>
    <item>
      <title><![CDATA[Stolen laptops affect 337,000 Davidson County voters]]></title>
      <link>http://securityratty.com/article/dd7e2533e3fc9fb78ad0c24a58b10b34</link>
      <guid>http://securityratty.com/article/dd7e2533e3fc9fb78ad0c24a58b10b34</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
12/28/07

Organization
Davidson County Election Commission

Davidson County, Tennessee has an estimated population of 607,413. The county seat is...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dcec.jpg" align="right" height="61" width="196"><font size="2"><span style="font-weight: bold;">Date Reported:</span><br>12/28/07<br><br><span style="font-weight: bold;">Organization:</span><br>Davidson County Election Commission*<br><br><font size="1">*Davidson County, Tennessee has an estimated population of 607,413.&nbsp; The county seat is Nashville.</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Registered Davidson County voters<br><br><span style="font-weight: bold;">Number Affected:</span><br>337,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, Social Security numbers, addresses and telephone numbers.<br><br><span style="font-weight: bold;">Breach Description:</span><br>A pair of laptop computers containing sensitive personal information belonging to 337,000 registered Davidson County, Tennessee voters was stolen from the Davidson County Election Commission office during the Christmas break.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.newschannel5.com/Global/story.asp?S=7550025" target="_blank"> WTVF News Channel 5 Story</a> <br><a href="http://wkrn.com/nashville/news/info-on-337000-davidson-county-voters-stolen/135060.htm" target="_blank"> WKRN Channel 2 News Story</a> <br><a href="http://www.bizjournals.com/nashville/stories/2007/12/24/daily22.html" target="_blank"> Nashville Business Journal</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>News Channel 5<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A break-in at the Davidson County Election Office at 800 Second Ave. has jeopardized a large number of voters' personal data, according to Ray Barrett, election administrator.<br><br>It looks as though they used a rock to break their way in.<br><span style="font-style: italic;">[Evan] A rock is all it took.&nbsp; There is no mention of any alarm system and it appears that nobody noticed until they came back to the office.</span><br style="font-style: italic;"><br>taken were two Dell Latitude laptops containing information of 337,000 registered Davidson County voters<br><br>"As we look deeper into determining the extent of loss that occurred during the holiday break-in, we now know that full social security numbers were included on the voter files contained on one or more of the stolen computers." said Ray Barrett.<br><br>"Initially, we thought that the only information was the same that the public can purchase when putting together mailing lists, we now know that was incorrect." <br><br>The Election Commission says it will formally notify the public by mail that their full Social Security numbers may be available to outside parties and is asking voters monitor their financial and personal accounts for any suspicious activity.<br><br>Barrett says he has asked Metro's information technology department to make immediate changes to safeguard against any future security problems. <br><span style="font-style: italic;">[Evan] I wonder what these people will come up with.&nbsp; Not only "immediate changes", but also effective changes.&nbsp; There are likely numerous changes that could be suggested.&nbsp; It all starts with policy.</span><br style="font-style: italic;"><br>The Election Commission says it does not anticipate that the theft will cause any problems in the upcoming Tennessee presidential primary.<br><br><span style="font-weight: bold;">Commentary:</span><br>This is an example of typical reactionary information security.&nbsp; "Immediate changes" are made after the significant loss of confidential information.&nbsp; I assume that there is not a well written or communicated information security policy at Davidson County.&nbsp; If there is, it is obviously not well enforced or supported by procedural, administrative, or technical controls.<br><br>Why are the offices not physically secure?&nbsp; If a rock is all that is needed to break-in and go undetected for x number of days, then the offices were not physically secure.<br><br>Why is confidential information stored on mobile devices (laptop in this instance)?&nbsp; Confidential information should be stored, whenever possible in a secure (physically and logically), centralized location.<br><br>Why are mobile devices that access, process, store, create, or transmit confidential data not encrypted?&nbsp; This is a point that I have been trying to drill home for years.&nbsp; Some people get it, some people fear it, and some people are oblivious.&nbsp; The sad thing is that consumers don't know which category the organization is in.&nbsp; Until consumers demand more, business as usual.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/29/dcec.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Sat, 29 Dec 2007 08:30:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voters">voters</category>
      <category domain="http://securityratty.com/tag/davidson county voters">davidson county voters</category>
      <category domain="http://securityratty.com/tag/davidson county">davidson county</category>
      <category domain="http://securityratty.com/tag/tennessee voters">tennessee voters</category>
      <category domain="http://securityratty.com/tag/information technology department">information technology department</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/voters monitor">voters monitor</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <source url="http://breachblog.com/2007/12/29/dcec.aspx">Stolen laptops affect 337,000 Davidson County voters</source>
    </item>
  </channel>
</rss>
