Banks Face Web Security Deadline
Many unprepared for guidelines on authenticating online users
July 31, 2006 12:00 PM ETComputerworld - For some bank IT managers, last fall's release of federal guidelines on validating the identities of online users helped catalyze ongoing efforts to adopt so-called strong authentication measures.
But a majority of U.S. banks appear unprepared to meet the Dec. 31 deadline for complying with the guidelines, several analysts said last week. They placed much of the blame for the current lack of preparedness on the fact that the guidelines aren't mandatory and don't specify what form of strong authentication banks should implement.
"Most banks haven't done much with [the guidelines] because there is still some confusion as to what needs to be done," said George Tubin, an analyst at TowerGroup in Needham, Mass.
That isn't the case at Zions Bancorporation in Salt Lake City. Preston Woods, the company's chief information security officer, said the release of the guidelines last October by the Federal Financial Institutions Examination Council gave a push to a strong authentication initiative that Zions had already started. "It validated what we were doing, and it gave us a deadline," he said.
Earlier this month, the company's Zions Bank unit added a multifactor authentication feature called SecurEntry for users of its online banking services. Woods said SecurEntry is based on technology from RSA Security Inc. and allows Zions Bank to better authenticate users to its Web site and ensure that they know they're connected to a legitimate site.
The technology works by profiling the devices that customers typically use to log into the bank's online systems. Whenever there are changes, such as when a customer logs in from a new location or using a different system, SecurEntry challenges the user with specific questions that only he should be able to answer, Woods said. He added that the bank views the process as being minimally disruptive to users.
Desert Schools Federal Credit Union in Phoenix is using a similar authentication approach based on technology from Santa Clara, Calif.-based Bharosa Inc. to meet the FFIEC's guidelines. And like Zions, the credit union was already working toward multifactor authentication when the guidelines were released.
"It kind of moved things up for us," CIO Ron Amstutz said, adding that he thought the FFIEC was quite clear on what it wants banks to do.
The FFIEC's decision to not specify the use of any authentication methods may have caused some confusion early on, said Eric Bangerter, director of Internet services at the University of Wisconsin Credit Union in Madison. But, he added, it has allowed banks to choose the technologies that are best suited to their needs.
banks
Additional Resources



White Papers & Webcasts
US Government Prevents Malware with Application Whitelisting
Download This Case Study Now!
Data in Action: Making the Planet Smarter
Register Now
Protecting Against Targeted Cyber Attacks with Application Whitelisting
Download This Whitepaper Now!
FISMA Prescriptive Guide
A Tactical Guide Enabling you to take Action and Achieve Operational Excellence
The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.
Oracle Accelerate - Not Just Smart but Timely
Download Now!
Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!
Why BI is Ripe - Now! - For Businesses of Any Size
Download Now!
Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.

