* Threat of identity theft requires better risk management
endif; ?>In a recent newsletter I mentioned that with all the focus on technology in information security management it’s easy for us to forget that security is primarily a people issue. We are, after all, seeking to protect the enterprise – and ourselves – from the risks posed maliciously or unintentionally by individuals. Never, however, is the risk more personal than when it comes to identity theft.
A victim of identity theft is as completely exposed to the vulnerabilities of our credit-based society as they can possibly be, with lingering after-effects that may follow them for years to come. Businesses whose personal information resources have been exploited have sometimes been extremely ginger in their responses – understandably, considering the potential liability involved.
That won’t continue. Mandating a more forthright response to exploits is behind regulatory measures such as California Senate Bill 1386, which essentially requires any business to disclose a security breach in which personal information of California residents may have been compromised. This affects virtually any business, anywhere. Such measures are forcing a more proactive enterprise approach to identity theft risk management.
The trend is still in its early stages. Some consumer-facing efforts, for example, seem almost surreal when they ask consumers to provide the very information they are trying to protect, via a Web site that the consumer may not know how to authenticate. Others, however, are more proactive, such as banks that recognize and intercept questionable credit card transactions before they are approved. This is good, considering that attacks targeting tangible assets – and even blackmail – are on the rise. Mercenary attacks against businesses, which the attacker promises to stop if paid off, are appearing. When coupled with the rising tide of regulation, businesses can no longer simply turn their backs on these trends as they may have in the past, when the cost of simply absorbing fraud was less than the cost of mitigation.
While identity risk management continues to mature, there are things that consumers can do to be more proactive in safeguarding their own information. Beginning this month, for example, individuals in several western U.S. states can obtain a free credit report once every 12 months from each of three major credit-reporting firms – Equifax, Experian and TransUnion – thanks to the provisions of the Fair and Accurate Credit Transactions Act (FACTA). A regular credit report check helps verify that personal information has not been misused – not a bad idea during the holiday shopping season. Availability of the free annual report will gradually be extended throughout the U.S. over the course of the coming year.
I visited the service Dec. 1, the first day of availability here in Colorado, at http://www.annualcreditreport.com
While I was successful in obtaining a report from Equifax, links were either broken or unavailable when trying to connect to Experian and TransUnion. In fairness, it was the first day of availability, after all, and the site allowed me to retry – but to report a problem, one can only send a “snail mail” to the Annual Credit Report Request Service, so this service has a ways to go before it becomes as responsive as the spirit of the legislative mandate suggests.
But it’s certainly a start in the right direction. People have a right to the security of their own information. It’s not just a commodity for identity-focused businesses. Look for increasing maturity in the management of that security, as the enterprise continues to awaken to the many critical aspects of identity.




