Banks face Web security deadline
Many aren't prepared for guidelines on authenticating online users
July 28, 2006 12:00 PM ETComputerworld - For some bank IT managers, last fall's release of federal guidelines for validating the identities of online users helped catalyze ongoing efforts to adopt so-called strong authentication measures.
But a majority of U.S. banks appear unprepared to meet the Dec. 31 deadline by which they're supposed to comply with the guidelines, several analysts said this week. They placed much of the blame for the current lack of preparedness on the fact that the guidelines aren't mandatory and leave it up to banks to decide what form of strong authentication they should implement.
"Most banks haven't done much with [the guidelines] because there is still some confusion as to what needs to be done," said George Tubin, an analyst at TowerGroup in Needham, Mass.
That isn't the case at Zions Bancorporation in Salt Lake City. Preston Woods, the company's chief information security officer, said the release of the guidelines last October by the Federal Financial Institutions Examination Council gave a push to a strong authentication initiative that Zions had already started. "It validated what we were doing, and it gave us a deadline," he said.
Earlier this month, the company's Zions Bank unit added a multifactor authentication feature called SecurEntry for users of its online banking services. Woods said SecurEntry is based on technology from RSA Security Inc. and allows Zions to better authenticate users to its Web site and ensure that they know they're connected to a legitimate site.
The technology works by profiling the devices that customers typically use to log into the bank's online systems. Whenever there are changes, such as when a customer logs in from a new location or using a different system, SecurEntry challenges users with specific questions that only they should be able to answer, Woods said. He added that the bank views the process as being minimally disruptive to users.
Desert Schools Federal Credit Union in Phoenix is using a similar authentication approach based on technology from Santa Clara, Calif.-based Bharosa Inc. to meet the FFIEC's guidelines. And like Zions, the credit union was already working toward multifactor authentication when the guidelines were released.
"It kind of moved things up for us," CIO Ron Amstutz said, adding that he thought the FFIEC was quite clear on what it wanted banks to do.
The FFIEC's decision not to specify the use of any authentication methods may have caused some confusion early on, said Eric Bangerter, director of Internet services at the University of Wisconsin Credit Union in Madison. But, he added, it has allowed banks to choose the technologies that best meet their needs.
FFIEC
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

