Wall Street & Technology: Blog
subscribe December 13, 2006

A Word for the Authentication Stragglers

Cory Levine, Wall Street & Technology

In just a few short weeks, stronger user authentication should be in place for the online financial services industry, or so the Federal Financial Institutions Examination Council (FFIEC) is hoping. According to research from Aite Group, the retail brokerage community should be ready for the FFIEC's end-of-year deadline, but there's nothing like a little last-minute advice. Authentication solution provider Cogneto offers some things to think about before leaving for your holiday vacation.

Cogneto made three recommendations for firms still considering how to meet FFIEC guidelines:

Information security programs must identify and assess the risks associated with Internet-based products and services:
The FFIEC states that financial institutions complete an overall assessment of their current security requirements. Cogneto recommends that organizations look for a solution that will constantly assess the risk climate in which transactions are taking place. A system that continuously analyzes risk in real time will go a long way in helping organizations adapt to future threats.

Information security programs must identify risk mitigation actions, including appropriate authentication strength:
The appropriate risk mitigation technique depends entirely on the environment in which a transaction is being conducted. Financial organizations should stay away from solutions that rely on a single method of authentication, and instead find solutions that take a consensus approach to security. Solutions that evaluate risk at multiple levels, each weighted differently depending on the situation, give financial institutions the power to adapt to ever-changing customer profiles and situations

Information security programs need to measure and evaluate customer awareness efforts:
User education is key to successfully preventing social engineering attacks such as phishing. Technology alone cannot solve the problems of fraud and ID theft, and users must also learn how they can play their part in the security process. Financial institutions should implement solutions that not only protect users, but also provide them with tools that will allow them to better protect themselves. Interactive help and educational components help should be a part of any FFIEC-compliant security solution.

Posted by Cory Levine at 03:11 PM



This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.


CHECK THIS OUT

Novell Real Time Linux Webcast Series
In order to succeed, companies must be able to respond quickly, deliver superior value and quality of service, and carefully manage their costs. In this series of brief webcasts, you will learn how SUSE Linux Enterprise Real Time from Novell enables organizations to respond quicker by delivering low latencies, deliver increased value with fast response times, and better manage costs.

Events

Live Events:
Accelerating Wall Street 2
October 02, 2008

Buy-Side Trading Summit 2008
November 16-18, 2008


White Papers

Level 3 Connectivity Kit
Stay ahead of the bandwidth curve. The Level 3 Connectivity Kit provides full resources to help you make informed decisions regarding your network infrastructure. Download the Data Center Networking Strategies for Financial Services Firms White Paper; Business Class Ethernet: Trends in Perspective eBook and BC/DR Best Practices for the Data-Intensive Enterprise Gartner Webcast

Surviving and Thriving in a Challenging Market
Learn how financial services firms can use customer-centric strategies and tools to maximize client value and loyalty, gain insight into new opportunities, and do more with less, counteracting market volatility.

Marketplace

Career Center


Ready to take that job and shove it?

Function:
Information Technology
Engineering
State:


Keyword(s):

Browse By:
State | City
techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics