<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: touche]]></title>
    <link>http://securityratty.com/tag/touche</link>
    <description></description>
    <pubDate>Thu, 20 Dec 2007 11:23:09 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Deloitte & Touche and IKON lose confidential information]]></title>
      <link>http://securityratty.com/article/fb71334da45d13f8777c9bb4a4f5052f</link>
      <guid>http://securityratty.com/article/fb71334da45d13f8777c9bb4a4f5052f</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
12/14/07

Organization
Deloitte &amp; Touche USA LLP

Contractor/Consultant/Branch
IKON Office Solutions

Victims
Current and former partners, principals,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/deloitte.jpg" align="right" height="49" width="162"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>12/14/07<br><br><span style="font-weight: bold;">Organization: </span><br>Deloitte &amp; Touche USA LLP<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>IKON Office Solutions<br><br><span style="font-weight: bold;">Victims:</span><br>Current and former partners, principals, and employees of Deloitte &amp; Touche and its subsidiaries<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, Social Security numbers, dates of birth, "and other information relating to those personnel, such as employee hire and termination dates"<br><br><span style="font-weight: bold;">Breach Description:</span><br>An un-encrypted laptop was stolen from an IKON Office Solutions employee on November 19th, 2007 that contained sensitive personally identifiable information belonging to current and former Deloitte &amp; Touche partners, principals and employees.&nbsp; IKON was serving as Deloitte &amp; Touche's document management vendor.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/deloitte_touche.pdf" target="_blank"> The New Hampshire State Attorney General breach notification</a><br><a href="http://www.scmagazineus.com/Deloitte-partner-principal-confidential-information-on-stolen-laptop/article/99945/" target="_blank"> SC Magazine Story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>On November 21st, 2007, D&amp;T USA's document management vendor, IKON Office Solutions, Inc. ("IKON"), informed D&amp;T USA that a laptop containing a file with information about current and former partners, principals and employees of D&amp;T USA and its subsidiaries had been stolen from an IKON employee's vehicle two days earlier.<br><br>The file included names, Social Security numbers, dates of birth and other information relating to those personnel, such as employee hire and termination dates.<br><br>IKON's employee reported the theft to the Walnut Creek, California police department.&nbsp; The police report number is 07-27609.<br><br>So far, the computer has not been recovered.<br><br>The laptop was not encrypted, but the laptop was password protected.<br><br>We have no information indicating the information has been misused.<br><br>we are in the process of notifying all affected individuals through first class mail, postage prepaid.<br><br>We have contracted with ConsumerInfo.com, Inc., an Experian company, to provide you with one year of credit monitoring, at no cost to you.<br><br>We are committed to protecting all confidential information that is entrusted to us.&nbsp; Accordingly, we have suspended all work with the vendor on the pension record scanning project until the vendor can demonstrate that it has implemented appropriate data security protections.<br><span style="font-style: italic;">[Evan] Its not uncommon for an organization to overlook the information that vendors and other third-parties access and/or store.&nbsp; Information security controls surrounding vendor access must be addressed in policy, and then followed up standards and controls.&nbsp; I wonder what Deloitte &amp; Touche's policy is around vendor access to confidential information.</span><br><br>if you have any additional questions about this incident, please call the Personal Service Network (PSN) at +1 800 DELOITT (+1 800 335 6488) and enter 12 to go directly to people who can answer questions about this incident.<br><br><span style="font-weight: bold;">Comments on the SC Magazine Story:</span><br><br>What makes Deloitte think that one year of monitoring will be all that is needed for the potential victims. I read where the average victim does not know til well beyond 12 months. - Mike<br><br>If "noted security experts" (so called in the article) can't get it right, then we're all in trouble. Laptop drive encryption is extremely easy to implement and manage corporate wide...and has been for years. So, why is this still happening? - Jim<br><br><span style="font-weight: bold;">Commentary:</span><br>According to the letter to affected individuals, IKON Office Solutions was responsible for scanning pension fund documents.<br><br>Although IKON definitely has blame in the cause of this breach, Deloitte &amp; Touche certainly does to.&nbsp; It seems that Deloitte &amp; Touche makes some attempts to deflect their responsibility.&nbsp; Deloitte &amp; Touche was given the information in the first place and they are responsible for what happens to it until it is ultimately destroyed (if it ever gets destroyed).&nbsp; We advise any clients that contract with third parties to create and adopt a "<a href="http://trustedtoolkit.com/Documents/VendorThirdPartyPolicySample.pdf">Vendor/Third-Party Access Security Policy</a>".&nbsp; Vendors are required to comply with the policy and many times it is even mentioned in the contract itself.&nbsp; The purpose of the policy is to ensure that vendors and other third-parties secure information at no less of a level than the original company.<br><br>The comments made by readers of the SC Magazine story really sum up my immediate thoughts. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/20/deloitte.aspx'%20type=" text="" javascript="" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Thu, 20 Dec 2007 11:23:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/touche">touche</category>
      <category domain="http://securityratty.com/tag/ikon">ikon</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/information security controls">information security controls</category>
      <category domain="http://securityratty.com/tag/deloitte">deloitte</category>
      <category domain="http://securityratty.com/tag/third-parties secure information">third-parties secure information</category>
      <category domain="http://securityratty.com/tag/touche partners">touche partners</category>
      <category domain="http://securityratty.com/tag/ikon office solutions">ikon office solutions</category>
      <source url="http://breachblog.com/2007/12/20/deloitte.aspx">Deloitte &amp; Touche and IKON lose confidential information</source>
    </item>
  </channel>
</rss>
