<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dwp]]></title>
    <link>http://securityratty.com/tag/dwp</link>
    <description></description>
    <pubDate>Tue, 19 Feb 2008 14:11:13 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[UPDATE: A computer stolen from Systematic Automation is found]]></title>
      <link>http://securityratty.com/article/9b792cac1e080d88a38cc9805a13d12f</link>
      <guid>http://securityratty.com/article/9b792cac1e080d88a38cc9805a13d12f</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/11/08

Organization
19 organizations, including Modesto City Schools , Torrance Unified School District , Clovis Unified School District , Los Angeles...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/sysauto.jpg" align="right" height="51" width="201">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/11/08<br><br></font><font size="2"><span style="font-weight: bold;">Organization: <br></span></font><span id="RDS_article">19 organizations, including </span><font size="2"><span style="font-weight: bold;"></span><a href="http://www.monet.k12.ca.us/mcsnew/" target="_blank"> Modesto City Schools</a>, </font><font size="2"><a target="_blank" href="http://www.tusd.org/">Torrance Unified School District</a>, </font><font size="2"><a target="_blank" href="http://www.cusd.com/">Clovis Unified School District</a></font>, <font size="2"><a target="_blank" href="http://www.ladwp.com/ladwp/homepage.jsp">Los Angeles Department of Water and Power ("DWP")</a>,&nbsp; and </font><font size="2"><a href="http://www.nestle-watersna.com/">Nestle Waters North America Inc. ("NWNA")</a> </font><font size="2"> </font><br><font size="2"><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456" target="_blank"> Systematic Automation Inc.</a>*<br><br></font><font size="1">*This breach is related to:<br>"<a href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, <br>"<a href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08, <br>"<a href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a>" dated 2/21/08<br></font><font size="1">"<a href="http://breachblog.com/2008/02/25/torrance.aspx">Systematic Automation breach continued...</a>" dated 2/22/08</font><font size="1">, and<br></font><font size="1">"<a href="http://breachblog.com/2008/03/04/nestlewaters.aspx">Nestle Waters North America employee affected by Systematic Automation breach</a>" dated 3/4/08<br><br><font size="2"><span style="font-weight: bold;">Update:</span><br></font></font>The Modesto Bee and the Whittier Daily News are reporting that a computer has been recovered from the home of <span id="RDS_article">Todd Irvine, 43 from </span><span id="RDS_article">La Habra.&nbsp; The computer "</span><span id="RDS_article">contained more than 40,000 names, addresses and Social Security numbers of California residents" according to a </span><span id="RDS_article">Fullerton police sergeant.<br><br><span style="font-weight: bold;">Reference URL:<br></span><a href="http://www.whittierdailynews.com/news/ci_8540659">Whittier Daily News</a><br><a href="http://www.modbee.com/local/story/235943.html">Modesto Bee</a><br><br></span><font size="2"><span style="font-weight: bold;">Report Credit:</span><br>Whittier Daily News<br><br></font><font size="2"><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br></font><span id="RDS_article">Fullerton police detectives analyzed data
Tuesday from a stolen computer seized from a La Habra man that
contained more than 40,000 names, addresses and Social Security numbers
of California residents, a sergeant said.<br><br>Todd Irvine, 43, was arrested on Friday after Fullerton detectives served a search warrant at his home in the 700 block of La Serna Avenue, said Fullerton police Sgt. Linda King.<br><br>The computer was stolen in a Feb. 11 commercial burglary of Systematic Automation Inc., a Fullerton data processing firm. The company prints individualized annual statements customized for employees with a summary of their health and other employee benefits, King said.<br><br>Fullerton police received information that the stolen computer was being used to access the Internet, which led to detectives obtaining the search warrant, King said.<br><br>Several other computers also were seized, she said.<br><br>Police are analyzing the computer to determine if the employee information files had been compromised, but no related cases of identity theft have been reported, she said.<br><br>Irvine, a parolee, faces possession of stolen property charges, King said.<br><br><span style="font-weight: bold;">Commentary:<br></span>Mr. Irvine is not a very bright individual, is he?&nbsp; I suspect that the confidential information was not accessed by Mr. Irvine, and I also suspect he didn't even know what he had.<br><br>Police did a superb job by following up on leads and treating this crime very seriously.&nbsp; They should be commended on their work.<br><br>This has been one of the most popular breaches in terms of the number of times the articles have been read, since The Breach Blog was launched in September, 2007<br><br>What should become of Systematic Automations? <span style="font-weight: bold;"><span style="font-weight: bold;"></span><br></span></span><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/12/sysautoupdate.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 12 Mar 2008 09:22:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fullerton police sergeant">fullerton police sergeant</category>
      <category domain="http://securityratty.com/tag/fullerton police">fullerton police</category>
      <category domain="http://securityratty.com/tag/fullerton police sgt">fullerton police sgt</category>
      <category domain="http://securityratty.com/tag/systematic automation">systematic automation</category>
      <category domain="http://securityratty.com/tag/fullerton police detectives">fullerton police detectives</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/systematic automation breach">systematic automation breach</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <source url="http://breachblog.com/2008/03/12/sysautoupdate.aspx">UPDATE: A computer stolen from Systematic Automation is found</source>
    </item>
    <item>
      <title><![CDATA[Clovis Unified School District employees receive notice]]></title>
      <link>http://securityratty.com/article/662c821c98ea5a31b7ba3df83725eae5</link>
      <guid>http://securityratty.com/article/662c821c98ea5a31b7ba3df83725eae5</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/16/08

Organization
Clovis Unified School District

Contractor/Consultant/Branch
Systematic Automation

This breach is related to
Theft from vendor...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/clovis.jpg" align="right" height="76" width="200">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/16/08<br><br><span style="font-weight: bold;">Organization: </span><br><a target="_blank" href="http://www.cusd.com/">Clovis Unified School District</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a target="_blank" href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456">Systematic Automation</a>* <br><font size="1"><br>*This breach is related to:<br>"<a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspxdated%202/12/08">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, and<br>"<a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08</font><br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>~4,000**<br><br><font size="1">**Over 15,000 total (and counting)</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computer equipment was stolen from a Clovis Unified School District vendor, Systematic Automation that contained sensitive personal information belonging to employees of the district.&nbsp; Systematic Automation manages employee benefit information, and the district is the third reported organization affected by the loss.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a target="_blank" href="http://www.cbs47.tv/news/local/story.aspx?content_id=1ba0136a-9863-4073-b33c-807a493ba9fc">CBS Channel 47 News online story</a> <br><a target="_blank" href="http://www.fresnobee.com/263/story/396688.html">The Fresno Bee online story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>CBS Channel 47 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Clovis Unified School District employees were notified that a computer stolen this week from a Fullerton company contained personal information -- including Social Security numbers -- for about 4,000 district employees.<br><br>police do not believe the intent of the burglary was to steal identity information<br><span style="font-style: italic;">[Evan] I don't know how you would determine intent based on the limited information available.&nbsp; At some point in time thieves are going to figure out that there is a heckuva lot more to gain by using the stolen information than there is in the pawning off the hardware.</span><br style="font-style: italic;"><br>Fullerton police say the computers are password protected but that doesn't mean the code can't be cracked<br><span style="font-style: italic;">[Evan] This is very true.&nbsp; Most Windows passwords can be bypassed in less than five minutes.</span><br><br>the district has recommended that employees establish fraud alerts on their credit files<br><br>The district also held two fraud-prevention seminars for employees Wednesday, with seven more planned during the next week.<br><br>Employee information for Clovis Unified and 15 other organizations was jeopardized when Systematic Automation of Fullerton was burglarized about 4:30 a.m. Monday.<br><span style="font-style: italic;">[Evan] Wow.&nbsp; 15 organizations and their employees are at risk due to one breach.&nbsp; We know of at least three; Clovis Unified School District, Los Angeles Department of Water and Power ("DWP"), and Modesto City Schools.</span><br style="font-style: italic;"><br>District employees were alerted in an e-mail about 3:30 p.m. Tuesday<br><span style="font-style: italic;">[Evan] Quick notification.&nbsp; This was a good decision on the part of district management</span><br><br>The stolen computer contained Clovis Unified employee names, addresses and salaries, as well as Social Security numbers. It did not contain birth dates or other personal information.<br><br>Systematic Automation handles the online benefits enrollment for Clovis Unified employees and publishes information on what benefits each employee receives<br><span style="font-style: italic;">[Evan] Might need to change "handles" to "handled".&nbsp; I wonder how this single breach affects Systematic Automation's business viability.</span><br style="font-style: italic;"><br>The police believe the computers contained tens of thousands of pieces of information.<br><br><span style="font-weight: bold;">Commentary:</span><br>What is there to say that hasn't already been said in the two previous postings?&nbsp; Did any of the 15 organizations audit Systematic Automation's information security practices? <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">Clovis Unified School District:</span><br>Unknown<br><span style="font-weight: bold;">Systematic Automation:</span><br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a> <br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/21/clovis.aspx" type="text/javascript" charset="utf-8"></script>
]]></content:encoded>
      <pubDate>Wed, 20 Feb 2008 22:57:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/district">district</category>
      <category domain="http://securityratty.com/tag/district employees">district employees</category>
      <category domain="http://securityratty.com/tag/school district">school district</category>
      <category domain="http://securityratty.com/tag/district management">district management</category>
      <category domain="http://securityratty.com/tag/school district vendor">school district vendor</category>
      <category domain="http://securityratty.com/tag/school district employees">school district employees</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</source>
    </item>
    <item>
      <title><![CDATA[L.A. Dept. of Water of Power employees exposed]]></title>
      <link>http://securityratty.com/article/f70613215508b1a91be5d9f49aab2c95</link>
      <guid>http://securityratty.com/article/f70613215508b1a91be5d9f49aab2c95</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/15/08

Organization
Los Angeles Department of Water and Power (&quot;DWP

Contractor/Consultant/Branch
Systematic Automation Inc

This breach appears to be...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dwp.jpg" align="right" height="70" width="168"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/15/08<br><br><span style="font-weight: bold;">Organization: </span><br><a target="_blank" href="http://www.ladwp.com/ladwp/homepage.jsp">Los Angeles Department of Water and Power ("DWP")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a target="_blank" href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456*">Systematic Automation Inc.</a> <br><br><font size="1">*This breach appears to be related to "<a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08</font><br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>8,275<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, Social Security numbers, dates of birth, employee identification numbers, salaries, work locations, deferred compensation balances (but not account numbers), insurance plan coverage and health care benefits selection"<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computer equipment was stolen from a Los Angeles Department of Water and Power vendor, Systematic Automation that contained sensitive personal information belonging to every employee of the utility.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a target="_blank" href="http://www.dailynews.com/news/ci_8277304">Los Angeles Daily News online story</a> <br><a target="_blank" href="http://www.latimes.com/news/printedition/california/la-me-dwp16feb16,1,22139.story?ctrack=1&amp;cset=true">Los Angeles Times online story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Beth Barrett, Los Angeles Daily News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Computer equipment containing the private financial data of every employee of the Los Angeles Department of Water and Power was stolen earlier this week, prompting the utility to pay for a credit monitoring service for each of its 8,275 workers.<br><br>DWP General Manager H. David Nahai sent a letter to employees Wednesday informing them of the "possible security breach" and of steps being taken to safeguard them from the risk of identity theft.<br><br>DWP officials said the theft occurred at Systematic Automation Inc. in Fullerton and is being investigated by Fullerton law enforcement.<br><span style="font-style: italic;">[Evan] From last week's Modesto City Schools breach, in which "A computer hard drive containing sensitive personal information belonging to Modesto City School district employees was stolen from Systematic Automation Inc. in Fullerton, California."&nbsp; Do you suppose this means that Systematic Automation was storing multiple client data sets on the same drive?</span><br><br>The data that was taken on active DWP employees included names, Social Security numbers, dates of birth, employee identification numbers, salaries, work locations, deferred compensation balances (but not account numbers), insurance plan coverage and health care benefits selection.<br><br>Nahai said the DWP had contracted with the company to print retirement booklets showing employees' benefits and other information<br><br>"This kind of work is done by very specialized companies, and I think many companies contract out this kind of work," he said. (Nahai)<br><span style="font-style: italic;">[Evan] This may justify why DWP sent the information out to a vendor, but it does not justify the breach or the lack of oversight (vendor management).&nbsp; Vendors trusted with confidential information <span style="font-weight: bold;">MUST </span>be held to the same strict standards as the company itself.</span><br><br>Nahai said the DWP was taking "extraordinary steps to protect our employees.<br><br>He said the data is encrypted and that the thieves may not be able to extract it.<br><span style="font-style: italic;">[Evan] Encrypting the information is a very good call by DWP, but according to the Modesto City Schools breach, "Snelling said the district sent the employee information in an encrypted format to Systematic Automation, where it apparently was stored on the computer in an unencrypted format."&nbsp; I would be surprised if the DWP information were not in a similar state.</span><br><br>The utility's Retirement Office (213-367-1692) also has made arrangements for a one-year subscription to a credit monitoring service for employees.<br><br>"It's in the very early stages of the investigation, and very early to point fingers," he said. (Nahai)<br><br>DWP spokesman Joe Ramallo said the utility had no evidence that the missing information had been misused<br><br>"We're required by law to notify our employees that this theft occurred," he said. "But we don't have any knowledge at this point that the data was the target, and law enforcement said they don't believe that it is."<br><br>a spokesman for the International Brotherhood of Electrical Workers Local 18, the union that represents DWP employees, said Friday that his workers were "shocked and upset" by the loss of the data.<br><br>"They believe this is a direct result of the mania for outsourcing that the DWP has had," said Bob Cherry, a communications consultant for the union. "The DWP should have been paying more attention to the potential impact of sensitive data like this getting sent to outside vendors."<br><span style="font-style: italic;">[Evan] Bob Cherry knows a thing or two.&nbsp; The security of information is the responsibility of the organization to whom it was originally given to by the owner.&nbsp; This is a simple owner/custodian relationship.&nbsp; Just because the custodian did not lose the hard drive directly does not mean that the custodian is not responsible for the breach.</span><br><br>Vince Foley, who serves on the board of the DWP Retired Employees Assn., said he has received anxious calls from retirees. The stolen computer equipment also contained financial data on employees who retired between July 1, 2006, and June 30, 2007.<br><br>Foley said. "DWP's computers are, of course, encrypted and protected. But this is a situation where they had . . . a consultant who's given all this data so they can prepare the [benefits] statements."<br><br><span style="font-weight: bold;">Commentary:</span><br>I wonder how many more organizations are affected by the Systematic Automation burglary.&nbsp; So far, we know of two organizations and over 11,000 affected persons.<br><br>There are lessons to be learned from almost any breach, and it's easier to play the "Monday morning quarterback".&nbsp; Good information security programs recognize the importance of managing security throughout the life-cycle of the information, no matter where it resides.&nbsp; At a minimum:<br><br></font><ol><li><font size="2">Thoroughly evaluate the information security practices of vendors before engaging in formal business agreements.</font></li><li>Information security language should be included in contractual agreements.</li><li>Conduct regular audits of vendors to ensure that they continue to abide by your information security policies, standards, guidelines and procedures.</li><li>If your company engages vendors on a regular basis, formalize the vendor security evaluation, approval and audit process.<br></li></ol><font size="2"><br>These are just some tips that could easily be expanded upon and refined to your individual situation. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Related:<br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/19/dwp.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 19 Feb 2008 14:11:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/employee information">employee information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security practices">information security practices</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/information security policies">information security policies</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/dwp">dwp</category>
      <category domain="http://securityratty.com/tag/dwp officials">dwp officials</category>
      <category domain="http://securityratty.com/tag/represents dwp employees">represents dwp employees</category>
      <source url="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</source>
    </item>
  </channel>
</rss>
