<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cher&#039;s canvas &#187; incidents</title>
	<atom:link href="https://jollyvip.com/research/category/incidents/feed/" rel="self" type="application/rss+xml" />
	<link>https://jollyvip.com/research</link>
	<description>Exploring the messy confluence of technology and people (law)</description>
	<lastBuildDate>Mon, 20 Feb 2023 16:44:15 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
		<item>
		<title>#GDPR Press Briefing in City, University of #London</title>
		<link>https://jollyvip.com/research/2018/04/21/gdpr-press-briefing-in-city-university-of-london/</link>
		<comments>https://jollyvip.com/research/2018/04/21/gdpr-press-briefing-in-city-university-of-london/#comments</comments>
		<pubDate>Sat, 21 Apr 2018 10:04:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2018]]></category>
		<category><![CDATA[dashboard]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[incidents]]></category>
		<category><![CDATA[research presentation]]></category>

		<guid isPermaLink="false">http://jollyvip.com/research/?p=1204</guid>
		<description><![CDATA[On 17th April 2018, I was one of the speakers in the GDPR Press Briefing held at City, University of London (City). Checkout the hot off the press &#8216;City academics discuss GDPR at press briefing&#8217; My written prepared talk is shared below. Privacy and the Individual &#8211; What difference will GDPR Make? Thanks John for <a href='https://jollyvip.com/research/2018/04/21/gdpr-press-briefing-in-city-university-of-london/' class='excerpt-more'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>On 17th April 2018, I was one of the speakers in the GDPR Press Briefing held at City, University of London (City). Checkout the hot off the press <a href="https://www.city.ac.uk/news/2018/april/city-academics-discuss-gdpr-at-press-briefing" title="City academics discuss GDPR at press briefing" target="_blank">&#8216;City academics discuss GDPR at press briefing&#8217;</a></p>
<p><strong>My written prepared talk is shared below.</strong></p>
<p>Privacy and the Individual &#8211; What difference will GDPR Make?</p>
<p>Thanks John for the introduction. A warm welcome to all.</p>
<p>Any talk on privacy and the GDPR invariably uses terms or phrases that may be blurry or obscure. So just to set the scene, when I say the ICO I&#8217;m referring to the UK&#8217;s data protection watchdog &#8211; The Information Commissioner&#8217;s Office. When I say &#8216;data&#8217; I&#8217;m referring to personal data as described in the GDPR. </p>
<p>Although the GDPR did not reference privacy &#8211; itself a complex term, privacy is embedded as information or data privacy and expressed in phrases such as:<br />
<em>&#8216;respect for human rights and fundamental freedoms (Art. 12 &#8211; exercise of the rights of the data subject); &#8216;High risk to the rights and freedoms of natural persons&#8217; (Art. 35 -Data protection impact assessment), and &#8216;Risks to the rights and freedoms of natural persons (individuals)&#8217; (Recital 75).</em>  </p>
<p>It is no longer just about protecting personal data or processing of personal data but <strong>data privacy.</strong></p>
<p><strong>With this comes obscure or unclear terms.</strong></p>
<p>What is &#8216;high risk&#8217;? How do you express &#8216;rights and freedoms&#8217; of natural persons (individuals) especially in the context of privacy impact assessment (PIA) or data protection impact assessment (DPIA)? </p>
<p>We know that the GDPR describes DPIA (Art. 35) and also breach notification (Art. 33 &#8211; notify the ICO, and Art. 34 &#8211; communicate to the data subjects).</p>
<p>I know fresh in our minds is the recent Facebook-Cambridge Analytica scandal. Flashback to October 2015, anyone here still remembers the TalkTalk data breach incident? </p>
<p>Would you all agree that both Facebook &#038; TalkTalk responded or handled the data breach announcement or notification to affected individuals rather badly or failed to do so in the eyes of the public and the affected individuals? </p>
<p>Certainly, under the GDPR both would be required to notify the ICO within 72 hours and to affected UK individuals without undue delay or &#8216;as soon as possible&#8217; (<a href="http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612052" title="wp250rev.01" target="_blank">Guidelines on Personal data breach notification under Regulation 2016/679)</a></p>
<p>As we know the GDPR requires organisations to notify the ICO where there is a risk to the rights and freedoms of individuals, and only notify the individuals where there is high risk.</p>
<p>My research examines data incidents response, in particular, the privacy harm to individuals as a consequence of the data incident. I have designed a <strong>prototype dashboard</strong> and have conducted user evaluation study with industry practitioners. The dashboard is for assessing privacy data harm by addressing the initial breach notification question to notify or not affected individuals and to the ICO during initial data incident response. </p>
<p>There is still fear in organisations when it comes to disclosure of data incidents. However, the GDPR will held organisations accountable e.g. with the fines and penalties, and to be transparent to report data incidents. Affected individuals have the right to know.</p>
<p>The outcome of my study also revealed that it is possible to do an initial data breach assessment even with the unclear terms: &#8216;high risk&#8217; and the &#8216;rights and freedoms&#8217; of individuals. The prototype dashboard also shows notification alerts with the countdown to 72 hrs from the point of being aware of the incident. One participant remarked: &#8216;<em>It (the dashboard) provides a calm objectivity in time of panic &#038; stress. Because you&#8217;re going to be stressed, you immediately think your personal reputation and your organisation&#8217;s reputation. Would we be fined? And all these things come in rather than actual thinking of the consequences to individuals&#8217;.</em> </p>
<p>When the data incident happened, the genie was out of the bottle, out in the wild &#8211; the harm was already done. </p>
<p>The GDPR would not bring the genie back into the bottle or stop the harm. So as a matter of good business practice and in the spirit of the law, organisations should notify their customers. </p>
<p>Thank you.<br />
Cher<br />
p.s.<br />
May post a photo taken by John Stevenson (City&#8217;s Senior Communications Officer)</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/research/2018/04/21/gdpr-press-briefing-in-city-university-of-london/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My final piece of study &#8211; user evaluation</title>
		<link>https://jollyvip.com/research/2018/02/25/my-final-piece-of-study/</link>
		<comments>https://jollyvip.com/research/2018/02/25/my-final-piece-of-study/#comments</comments>
		<pubDate>Sun, 25 Feb 2018 15:29:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2018]]></category>
		<category><![CDATA[dashboard]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[incidents]]></category>
		<category><![CDATA[Month-by-month]]></category>

		<guid isPermaLink="false">http://jollyvip.com/research/?p=1156</guid>
		<description><![CDATA[I am now extending my user evaluation (January-February schedule) to March as January was a quiet month. It has been difficult to get practitioners in industry to commit their time to participate in my user evaluations study. Personal data incidents are still regarded &#8216;scary&#8217; stuff to disclose or to talk about openly or even privately <a href='https://jollyvip.com/research/2018/02/25/my-final-piece-of-study/' class='excerpt-more'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>I am now extending my user evaluation (January-February schedule) to March as January was a quiet month. It has been difficult to get practitioners in industry to commit their time to participate in my user evaluations study. Personal data incidents are still regarded &#8216;scary&#8217; stuff to disclose or to talk about openly or even privately with a researcher.</p>
<p>Even after I reassure folks that my research does not require disclosing any personal or commercially sensitive information, folks (esp. senior managers) still won&#8217;t allow their employees (those that have the relevant knowledge/experience) to share and participate in my research.This is a pity as they will certainly learn something in sharing and participating in my user evaluation. According to this <a href="https://www.linkedin.com/groups/4395105/4395105-6365985607465918464" title="FCA news"target="_blank">news,</a> the #FCA is to require UK banks to make details of cyber security #incidents public from August 2018. Under the GDPR, organisations processing personal data of EU residents/citizens will need to report certain breaches to the ICO and also to affected individuals. My prototype dashboard will help organisations to conduct an initial personal data harm assessment.</p>
<p>So far, practitioners who took my user evaluation study involving a questionnaire and the prototype dashboard have expressed positive remarks and provided suggestions for further improvement or commercialisation of the prototype concepts.</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/research/2018/02/25/my-final-piece-of-study/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data breaches (UK)</title>
		<link>https://jollyvip.com/research/2016/05/29/data-breaches-uk/</link>
		<comments>https://jollyvip.com/research/2016/05/29/data-breaches-uk/#comments</comments>
		<pubDate>Sun, 29 May 2016 12:08:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[data breaches]]></category>
		<category><![CDATA[incidents]]></category>
		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://jollyvip.com/research/?p=1025</guid>
		<description><![CDATA[I&#8217;ve collected some sites/links on data breaches. Some are listed under &#8216;DataHub&#8217; on the menus on the right columns of this site. On my ToDo lists is an item to &#8216;somehow create/use visualisation tools&#8217; to extract and represent the data breaches in the UK that have been reported in the press or elsewhere. Here&#8217;re more <a href='https://jollyvip.com/research/2016/05/29/data-breaches-uk/' class='excerpt-more'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve collected some sites/links on data breaches. Some are listed under &#8216;DataHub&#8217; on the menus on the right columns of this site.</p>
<p>On my ToDo lists is an item to &#8216;somehow create/use visualisation tools&#8217; to extract and represent the data breaches in the UK that have been reported in the press or elsewhere.</p>
<p>Here&#8217;re more links on data breaches (in no particular ordering) in the UK, including other notable data incidents (some requiring registration/account login):</p>
<p><a href="http://www.computing.co.uk/ctg/news/2411812/all-of-uk-s-major-banks-and-lenders-have-reported-data-breaches-in-the-last-two-years" title="All of UK’s major banks and lenders have reported data breaches in the past two years" target="_blank">All of UK’s major banks and lenders have reported data breaches in the past two years &#8211; FOI request finds that 791 incidents reported to the ICO by financial services firms since 2013</a></p>
<p><a href="http://www.computing.co.uk/ctg/news/2451266/linkedin-being-used-as-a-front-door-to-phishing-attacks" title="LinkedIn being used as a 'front door' to phishing attacks" target="_blank"></a></p>
<p><a href="http://www.computing.co.uk/ctg/news/2459497/ecuadorian-bank-cyber-thieves-used-hsbc-accounts-in-hong-kong" title="Ecuadorian bank cyber thieves used HSBC accounts in Hong Kong" target="_blank">Ecuadorian bank cyber thieves used HSBC accounts in Hong Kong</a></p>
<p><a href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2016/05/london-nhs-trust-fined-for-hiv-newsletter-data-breach/" title="London NHS trust fined for HIV newsletter data breach" target="_blank">London NHS trust fined for HIV newsletter data breach</a></p>
<p><a href="http://www.scmagazineuk.com/uk-charity-calm-hacked-in-senseless-attack/article/430417/" title="UK charity CALM hacked in 'senseless' attack" target="_blank">UK charity CALM hacked in &#8216;senseless&#8217; attack</a></p>
<p><a href="http://www.scmagazineuk.com/uk-charity-gets-hacked-twice-in-motiveless-attack/article/324460/" title="UK charity gets hacked twice in 'motiveless' attack" target="_blank">UK charity gets hacked twice in &#8216;motiveless&#8217; attack</a></p>
<p><a href="http://www.scmagazineuk.com/scottish-charity-reports-data-loss-due-to-unencrypted-usb-sticks/article/231561/" title="Scottish charity reports data loss due to unencrypted USB sticks" target="_blank">Scottish charity reports data loss due to unencrypted USB sticks</a></p>
<p><a href="http://www.scmagazineuk.com/data-losses-on-usb-sticks--its-raining-again/article/227808/" title="Data losses on USB sticks - it's raining again">Data losses on USB sticks &#8211; it&#8217;s raining again</a></p>
<p><a href="http://www.scmagazineuk.com/third-ico-fine-in-a-week-after-sensitive-information-widely-distributed-by-webmail/article/227805/" title="Third ICO fine in a week after sensitive information widely distributed by webmail" target="_blank">Third ICO fine in a week after sensitive information widely distributed by webmail</a></p>
<p><a href=" http://www.scmagazineuk.com/ico-fines-scottish-council/article/225228/" title="ICO fines Scottish council" target="_blank">ICO fines Scottish council</a></p>
<p><a href="http://www.theguardian.com/money/2007/feb/15/business.accounts" title="Nationwide fined £1m over laptop theft security breach" target="_blank">Nationwide fined £1m over laptop theft security breach</a></p>
<p><a href="http://www.computing.co.uk/ctg/news/2404351/more-than-170-law-firms-investigated-by-ico-over-data-breaches-in-2014" title="More than 170 law firms investigated by ICO over data breaches in 2014" target="_blank">More than 170 law firms investigated by ICO over data breaches in 2014</a></p>
<p><a href="http://www.techworld.com/security/uks-11-most-infamous-data-breaches-2015-3604586/" title="The UK’s 11 most infamous data breaches 2015" target="_blank">The UK’s 11 most infamous data breaches 2015:</a></p>
<p>Nationwide Building Society (2006) -<br />
<a href="http://news.bbc.co.uk/1/hi/business/6360715.stm" title="Nationwide fine for stolen laptop" target="_blank">Nationwide fine for stolen laptop</a></p>
<p>HM Revenue &#038; Customs (2007) &#8211;<br />
<a href="http://www.techworld.com/blog/war-on-error/another-bad-day-for-the-database-guys-3537711/" title="Another bad day for the database guys" target="_blank">Another bad day for the database guys</a></p>
<p>HM Revenue &#038; Customs Child Benefit Office (2008) -</p>
<p><a href="http://www.telegraph.co.uk/news/majornews/2191680/Child-benefit-data-loss-timeline-of-scandal.html" title="Child benefit data loss: timeline of scandal" target="_blank">Child benefit data loss: timeline of scandal</a></p>
<p><a href=" https://www.ipcc.gov.uk/news/ipcc-publishes-report-missing-hmrc-data-cds-full-version" title="IPCC publishes report into missing HMRC data CDs (full version)" target="_blank">IPCC publishes report into missing HMRC data CDs (full version)</a></p>
<p>Sony PlayStation Network (2011) -<br />
<a href="http://www.techworld.com/news/security/sony-admits-huge-playstation-network-data-breach-3276404/" title="Sony admits huge PlayStation Network data breach" target="_blank">Sony admits huge PlayStation Network data breach</a></p>
<p>NHS Trust in Brighton (2012) &#8211;<br />
<a href="http://www.information-age.com/it-management/risk-and-compliance/2106478/nhs-trust-receives-largest-ever-data-breach-fine" title="NHS Trust receives largest ever data breach fine" target="_blank">NHS Trust receives largest ever data breach fine</a></p>
<p>Morrison’s supermarket (2014) -<br />
<a href="http://www.techworld.com/news/security/morrisons-supermarket-suffers-major-pay-roll-data-breach-after-insider-attack-3506753/" title="Morrisons supermarket suffers major pay-roll data breach after insider attack" target="_blank">Morrisons supermarket suffers major pay-roll data breach after insider attack</a></p>
<p>Staffordshire University (2014) -<br />
<a href="http://www.bbc.co.uk/news/uk-england-stoke-staffordshire-30046151" title="Staffordshire University stolen laptop had student contacts details" target="_blank">Staffordshire University stolen laptop had student contacts details</a></p>
<p>Mumsnet (2014) -<br />
<a href="http://www.techworld.com/news/security/mumsnet-falls-heartbleed-hackers-as-15-million-users-reset-passwords-3511830/" title="Mumsnet falls to Heartbleed hackers as 1.5 million users reset passwords" target="_blank">Mumsnet falls to Heartbleed hackers as 1.5 million users reset passwords</a></p>
<p>Think W3 Limited (2014) -<br />
<a href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2014/07/online-travel-services-company-exposes-more-than-a-million-customer-records-to-malicious-hacker/" title="Online travel services company exposes more than a million customer records to malicious hacker" target="_blank">Online travel services company exposes more than a million customer records to malicious hacker</a></p>
<p>Moonpig (2015) -<br />
<a href="http://www.techworld.com/news/security/moonpig-android-app-flaw-puts-three-million-accounts-at-risk-3592812/" title="Moonpig Android app flaw puts THREE MILLION accounts at risk" target="_blank">Moonpig Android app flaw puts THREE MILLION accounts at risk</a></p>
<p>TalkTalk (2014/2015) &#8211; various news:<br />
<a href="http://www.itpro.co.uk/security/24136/talktalk-hack-what-to-do-if-hackers-have-your-data-20" title="TalkTalk hack: What to do if hackers have your data" target="_blank">TalkTalk hack: What to do if hackers have your data</a></p>
<p><a href="http://www.thisismoney.co.uk/money/news/article-3292565/The-small-print-says-quit-TalkTalk-Hacked-telecoms-giant-refusing-let-customers-leave-without-paying-fees-ve-loophole.html" title="TalkTalk Hacked-telecoms-giant-refusing-let-customers-leave-without-paying-fees-ve-loophole" target="_blank">TalkTalk: Hacked telecoms giant refusing to let customers leave without paying fees</a></p>
<p><a href="http://www.bbc.co.uk/news/business-36273449" title="TalkTalk profits halve after cyber attack" target="_blank">TalkTalk profits halve after cyber attack</a></p>
<p><a href="http://uk.reuters.com/article/uk-talktalk-tlcm-gp-results-idUKKCN0VB0I7" title="TalkTalk lost more than 100,000 customers after cyber attack" target="_blank">TalkTalk lost more than 100,000 customers after cyber attack</a></p>
<p><a href="http://www.ft.com/cms/s/0/1e03001c-e22b-11e5-96b7-9f778349aba2.html#axzz4A2rrilSA" title="TalkTalk chief signals change after cyber attack" target="_blank">TalkTalk chief signals change after cyber attack</a></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/research/2016/05/29/data-breaches-uk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OASIS Cyber Threat Intelligence Technical Committee（CTI TC）</title>
		<link>https://jollyvip.com/research/2015/09/07/oasis-cyber-threat-intelligence-technical-committee%ef%bc%88cti-tc%ef%bc%89/</link>
		<comments>https://jollyvip.com/research/2015/09/07/oasis-cyber-threat-intelligence-technical-committee%ef%bc%88cti-tc%ef%bc%89/#comments</comments>
		<pubDate>Mon, 07 Sep 2015 19:18:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Extracts]]></category>
		<category><![CDATA[incidents]]></category>
		<category><![CDATA[US]]></category>

		<guid isPermaLink="false">http://jollyvip.com/research/?p=937</guid>
		<description><![CDATA[OASIS Cyber Threat Intelligence Technical Committee（CTI TC） Extracted information from the site; Overview The OASIS Cyber Threat Intelligence (CTI) TC was chartered to define a set of information representations and protocols to address the need to model, analyze, and share cyber threat intelligence. In the initial phase of TC work, three specifications will be transitioned <a href='https://jollyvip.com/research/2015/09/07/oasis-cyber-threat-intelligence-technical-committee%ef%bc%88cti-tc%ef%bc%89/' class='excerpt-more'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p><a href="https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=cti" title="OASIS Cyber Threat Intelligence community" target="_blank">OASIS Cyber Threat Intelligence Technical Committee（CTI TC） </a></p>
<p>Extracted information from the site;<br />
Overview</p>
<p>The OASIS Cyber Threat Intelligence (CTI) TC was chartered to define a set of information representations and protocols to address the need to model, analyze, and share cyber threat intelligence. In the initial phase of TC work, three specifications will be transitioned from the US Department of Homeland Security (DHS) for development and standardization under the OASIS open standards process: STIX (Structured Threat Information Expression), TAXII (Trusted Automated Exchange of Indicator Information), and CybOX (Cyber Observable Expression).</p>
<p>The OASIS CTI Technical Committee will:</p>
<p>    define composable information sharing services for peer-to-peer, hub-and-spoke, and source subscriber threat intelligence sharing models<br />
    develop standardized representations for campaigns, threat actors, incidents, tactics techniques and procedures (TTPs), indicators, exploit targets, observables, and courses of action<br />
    develop formal models that allow organizations to develop their own standards-based sharing architectures to meet specific needs</p>
<p>I will certainly be interested in the &#8216;incidents, indicators, observables and courses of action&#8217;. Anything shareable is worth researching.</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/research/2015/09/07/oasis-cyber-threat-intelligence-technical-committee%ef%bc%88cti-tc%ef%bc%89/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybersecurity Assessment Tool from The Federal Financial Institutions Examination Council (FFIEC)</title>
		<link>https://jollyvip.com/research/2015/09/03/cybersecurity-assessment-tool-from-the-federal-financial-institutions-examination-council-ffiec/</link>
		<comments>https://jollyvip.com/research/2015/09/03/cybersecurity-assessment-tool-from-the-federal-financial-institutions-examination-council-ffiec/#comments</comments>
		<pubDate>Thu, 03 Sep 2015 13:48:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[incidents]]></category>
		<category><![CDATA[US]]></category>

		<guid isPermaLink="false">http://jollyvip.com/research/?p=932</guid>
		<description><![CDATA[The Federal Financial Institutions Examination Council (FFIEC) Cybersecurity Assessment Tool The news release at FFIEC Releases Cybersecurity Assessment Tool Here&#8217;s the extracted news; FFIEC Releases Cybersecurity Assessment Tool The Federal Financial Institutions Examination Council (FFIEC), on behalf of its members, today released a Cybersecurity Assessment Tool (Assessment) to help institutions identify their risks and assess <a href='https://jollyvip.com/research/2015/09/03/cybersecurity-assessment-tool-from-the-federal-financial-institutions-examination-council-ffiec/' class='excerpt-more'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p><a href="https://www.ffiec.gov/cyberassessmenttool.htm" title=" the Federal Financial Institutions Examination Council (FFIEC) Cybersecurity Assessment Tool" target="_blank">The Federal Financial Institutions Examination Council (FFIEC) Cybersecurity Assessment Tool</a></p>
<p>The news release at <a href="https://www.ffiec.gov/press/pr063015.htm" title="news release" target="_blank">FFIEC Releases Cybersecurity Assessment Tool</a></p>
<p>Here&#8217;s the extracted news;</p>
<p>FFIEC Releases Cybersecurity Assessment Tool</p>
<p>The Federal Financial Institutions Examination Council (FFIEC), on behalf of its members, today released a Cybersecurity Assessment Tool (Assessment) to help institutions identify their risks and assess their cybersecurity preparedness.<br />
Financial institutions of all sizes may use the Assessment and other methodologies to perform a self-assessment and inform their risk management strategies. The release of the Cybsercurity Assessment Tool follows last year’s pilot assessment of cybersecurity preparedness at more than 500 institutions. The FFIEC members plan to update the Assessment as threats, vulnerabilities, and operational environments evolve.<br />
In addition to the Assessment, the FFIEC has also made available resources institutions may find useful, including an executive overview, a user’s guide, an online presentation explaining the Assessment, and appendices mapping the Assessment’s baseline maturity statements to the FFIEC Information Technology Examination Handbook, mapping all maturity statements to the National Institute of Standards and Technology&#8217;s Cybersecurity Framework, and providing a glossary of terms.<br />
The FFIEC members are also encouraging institutions to comment on the Assessment through an upcoming Paperwork Reduction Act notice in the Federal Register.<br />
The FFIEC provides several resources to further awareness of cyber threats and help financial institutions improve their cybersecurity. These resources are available on the FFIEC website at http://www.ffiec.gov/cybersecurity.htm.</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/research/2015/09/03/cybersecurity-assessment-tool-from-the-federal-financial-institutions-examination-council-ffiec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
