subject: Is It Hard To Beat The Bank Insider? [print this page] Information - a vital resource in the banking industry. It is stored and processed in the computer systems of banks, and streams are moving to internal and external communications: where controlled, and where a completely uncontrolled. And the safety of its use in banking institutions often leaves much to be desired, experts conclude.
In terms of security the bank can conclude: no authentication, no data protection against unauthorized access and data security software unable to keep a tight rein on uncontrolled insiders and employees with just a low awareness of personal responsibility, competence, training. And the output in such a situation seems the same: raising restrictions while working in EIS, the reduction of access, to disable all the "extra" devices, interfaces and gateways. Such conclusions are likely to have the right to life: currently investigating crimes related to theft of information is difficult, not to mention the lack of case law on the facts of insider information. Refer to the opinion of authoritative experts (including insiders) in this matter also somehow does not work - the Russian banking community has reserved comment on the incidents in their own information systems, preferring to hide or conceal.
It is obvious that in addition to the introduction of hardware and software need to implement a comprehensive early warning nature, allowing employees to inform on the inadmissibility of certain actions with respect to information of limited use. And this all means: legislative initiatives, which include those administrative (criminal) proceedings, corporate - in the form of material incentives (penalties) and to prevent the commission of an employee with specific operations of computers. Last performed sometimes not maliciously, but in terms of access to information and opportunities for its treatment in the home or other conditions. In these cases, it can help a variety of hardware and software solutions, including tools to protect information from unauthorized access.
This is, in general. But speaking of banks, which are often used several information systems for various purposes, it is worth noting another distinctive feature: the staff of these institutions are physically difficult if not impossible - to keep in mind authenticators their accounts, especially after the IT department staff include periodic regime change passwords with a check for the uniqueness and reliability. And that means that employees will use the above-mentioned "available means" to make their lives easier. Such a way out of this situation, as a result - would entail the possibility of using accounts of other employees, breach of trust on the part of colleagues, and in the worst scenario - theft and leakage of information under the guise of foreign workers' profiles, in fact, unauthorized access to data.
A significant part of the issues from the sphere of information security (IS) in the banking institutions can resolve the latest software and hardware technologies and systems. It can be used solutions such as system access control systems (ACS), biometric access control to information resources staff of the bank, strengthening of authentication systems with additional elements - the multifactor authentication, account management system, centralization of user access to all information systems used in the bank.