• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
BARC BI Survey 13 banner
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register For Membership | Member Login

 
 
DOMAINS
  • Business Issues
  • Channels
  • Enterprise
  • Services
  • SME
  • Technology
FEATURED EVENTS
  • Performance and Risk Control
    21st June
    Webinar (online)
  • Brainstorm San Francisco 2013
    24th June - 27th June
    Burlingame CA, USA
POPULAR PAPERS
  • Exploiting the Internet of Things with investigative analytics by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Observations - "If you pick up a starving dog and make him prosperous he will not bite you. This is the principal difference between a man and a dog." - Mark Twain

PAGE TOOLS
RECENT POSTS
  • CA - Same old same old, or new opportunities?
  • Dreaming of the perfect trip
  • Policing the virtual perimeter
  • Kaspersky Lab - Russia's IT security jewel
  • Is the use of cloud sharing systems worrying you?
  • The age of bring-your-own-identity (BYOID)
ADVERTISEMENT
BLOG ARCHIVE
  • May, 2013
  • April, 2013
  • March, 2013
  • February, 2013
  • January, 2013
  • November, 2012
  • October, 2012
  • September, 2012
  • August, 2012
  • July, 2012
  • June, 2012
  • May, 2012
Blogs > Quocirca

A critical software problem for banks

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 2nd December 2011
Copyright Quocirca © 2011
Logo for Quocirca
Tweet

New Quocirca research (sponsored by on-demand software code security specialist, Veracode) underlines a problem faced by financial services organisations when it comes to security and compliance; they track getting on for twice as many critical software applications as other organisations.

This is not just an issue when it comes to ensuring that all the code of all their commercially acquired and in-house developed software code is secure (as a new Quocirca report to be published in early 2012 will discuss); it is also an issue when it comes to monitoring and restricting access to all those applications.

There is more for banks to worry about than their own employees. A previous Quocirca research report (The distributed business index, sponsored by network acceleration vendor Riverbed) showed that banks are more likely than other organisations to make their applications accessible to outsiders; namely contractors, partners, suppliers and customers.

Providing access to so many applications for such a broad range of users is of course a big security headache. However, it is also a compliance issue. The financial services industry is heavily regulated, with national, EU and global watch dogs keeping an eye on them. Compliance often means proving who has been doing what; some are specific about this. For example, PCI DSS V2.0 Requirement 8 states that organisations that handle payment card data should "assign a unique ID to each person with computer access" and "ensure that each individual is uniquely accountable for his or her actions".

Achieving this requires a way to centrally manage identities and associate a single identity with all a user’s actions, whatever the systems and applications they are accessing. How these issues affect financial services organisation i is a subject of a webinar Quocirca is speaking at on Dec 7th in conjunction with Centrify (an identify management specialist).

To find out more and register for the webinar, click here.

Reader Comments

We have not received any comments against this entry. Why not be the first?

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

  • Contact
  • | Site Map
  • | Terms of Use
  • | Privacy Policy
  • | Cookie Policy

Published by: Electronicdawn Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761