<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data Security Policies &#187; Network Security Policy</title>
	<atom:link href="http://www.datasecuritypolicies.com/category/security-policies/network-security-policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.datasecuritypolicies.com</link>
	<description></description>
	<lastBuildDate>Sat, 14 Jan 2012 22:22:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>World Bank Data Breach</title>
		<link>http://www.datasecuritypolicies.com/world-bank-data-breach/</link>
		<comments>http://www.datasecuritypolicies.com/world-bank-data-breach/#comments</comments>
		<pubDate>Sun, 12 Oct 2008 16:39:19 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
				<category><![CDATA[Corporate Security Policy]]></category>
		<category><![CDATA[Data Security Policy]]></category>
		<category><![CDATA[Incident Response Policy]]></category>
		<category><![CDATA[Network Security Policy]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Vulnerability Management Policy]]></category>
		<category><![CDATA[Information Security Policy]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[World Bank Data Breach]]></category>

		<guid isPermaLink="false">http://www.datasecuritypolicies.com/?p=81</guid>
		<description><![CDATA[In breaking news directly related to data security policies, FoxNews is reporting that the World Bank has suffered possibly &#8220;the worst security breach ever at a global financial institution&#8221;:  The World Bank Group&#8217;s computer network — one of the largest repositories of sensitive data about the economies of every nation — has been raided repeatedly [...]]]></description>
			<content:encoded><![CDATA[<p></p><div id="attachment_82" class="wp-caption alignleft" style="width: 300px">
	<img class="size-medium wp-image-82" title="world-bank-data-breach" src="http://www.datasecuritypolicies.com/wp-content/uploads/2008/10/world-bank-data-breach-300x247.jpg" alt="Photo credit: KAREN BLEIER/AFP/Getty Images" width="300" height="247" />
	<p class="wp-caption-text">Photo credit: KAREN BLEIER/AFP/Getty Images</p>
</div>
<p>In breaking news directly related to data security policies, <a href="http://www.foxnews.com/story/0,2933,435681,00.html" target="_blank">FoxNews is reporting</a> that the World Bank has suffered possibly &#8220;the worst security breach ever at a global financial institution&#8221;:</p>
<blockquote><p> The World Bank Group&#8217;s computer network — one of the largest repositories of sensitive data about the economies of every nation — has been raided repeatedly by outsiders for more than a year, FOX News has learned.</p>
<p>It is still not known how much information was stolen. But sources inside the bank confirm that servers in the institution&#8217;s highly-restricted treasury unit were deeply penetrated with spy software last April. Invaders also had full access to the rest of the bank&#8217;s network for nearly a month in June and July.</p>
<p>In total, at least six major intrusions — two of them using the same group of IP addresses originating from China — have been detected at the World Bank since the summer of 2007, with the most recent breach occurring just last month.</p>
<p>While it remains unclear how much data has been pilfered from the bank, it&#8217;s a lot. According to internal memos, &#8220;a minimum of 18 servers have been compromised,&#8221; including some of the bank&#8217;s most sensitive systems — ranging from the bank&#8217;s security and password server to a Human Resources server &#8220;that contains scanned images of staff documents.&#8221;</p>
<p>One World Bank director tells FOX News that as many as 40 servers have been penetrated, including one that held contract-procurement data.</p>
<p>Despite the gravity of the break-ins, the bank is trying hard to pretend to outsiders it didn&#8217;t happen. &#8220;There were attempts to hack the bank&#8217;s computer systems last summer,&#8221; says a World Bank spokesman. &#8220;However, there was no compromise of confidential information.&#8221;</p></blockquote>
<p>So if this actually happened, which data security policies could have helped prevent the &#8220;the worst security breach ever at a global financial institution&#8221;?</p>
<ul>
<li>Corporate Security Policy</li>
<li>Incident Response Policy</li>
<li>Network Security Policy</li>
<li>Vulnerability Management Policy</li>
</ul>
<p>Others?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.datasecuritypolicies.com/world-bank-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network Security Policy</title>
		<link>http://www.datasecuritypolicies.com/network-security-policy/</link>
		<comments>http://www.datasecuritypolicies.com/network-security-policy/#comments</comments>
		<pubDate>Sun, 28 Oct 2007 23:55:54 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
				<category><![CDATA[Network Security Policy]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Data Security Policy]]></category>
		<category><![CDATA[Information Security Policy]]></category>
		<category><![CDATA[Security Policy]]></category>

		<guid isPermaLink="false">http://www.datasecuritypolicies.com/network-security-policy</guid>
		<description><![CDATA[The University of Toronto has a great example of a Network Security Policy here. Here’s an excerpt: Computing &#38; Networking Services will: monitor in real-time, backbone network traffic, as necessary and appropriate, for the detection of unauthorized activity, intrusion attempts and compromised equipment. carry out and review the results of automated network-based vulnerability, compromise assessment [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>The University of Toronto has a great example of a Network Security Policy <a target="_blank" href="http://www.utoronto.ca/security/documentation/policies/policy_5.htm">here</a>.</p>
<p>Here’s an excerpt:</p>
<blockquote>
<p class="style3"><strong>Computing &amp; Networking Services will: </strong></p>
<ul class="style3">
<li>monitor in real-time, backbone network traffic, as necessary and appropriate, for the detection of unauthorized activity, intrusion attempts and compromised equipment.</li>
<li>carry out and review the results of automated network-based vulnerability, compromise assessment and guideline compliance scans of the systems and devices on University networks in order to detect known vulnerabilities, compromised hosts, and guideline compliance failures,</li>
<li>test campus wireless network access to ensure compliance to published guidelines.</li>
<li>prepare summary reports of its network security activities for the Technical Operations Committee on a quarterly basis</li>
</ul>
</blockquote>
<p>Also includes the appendix <strong>Guidelines for the Implementation of Wireless and Wired Docking Infrastructure</strong>.</p>
<p>Check it out!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.datasecuritypolicies.com/network-security-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

