Traditional Research Paper on Implications (Suggestions) and Risks of WIFI Calling on mobile devices.

profileAKSH7266
MUSTREFER-SAMPLEPAPER.docx

Identity Theft: Hierarchy of Effective Safeguards

Master of Science in xxxxxxx

Date

Table of Contents Abstract 8 Identity Theft: Hierarchy of Effective Safeguards 9 Problem Statement 11 Research Question 11 Rationale 11 Definitions 13 Hypothesis 14 Literature Review 15 Methodology 23 Data Preparation 25 Final Data Analysis 33 Results 38 Compared Effectiveness of Identity Theft Safeguards 38 Creating a Prioritized List of Effective Safeguards (H1) 38 Using a Paired, Two-Sample (two-tailed), t Test 43 Discussion 43 Comparative Effectiveness 43 Discussion of Graphical Analysis 47 Discussion of Using Descriptive Measures to Compare Averages Above the Median 48 Discussion of the Paired, Two-Sample (two-tailed), t Test 49 Discussion Of The Treatment Of Data 51 Additional Value Added by This Research 52 Conclusion 54 References 56

List of Tables and Figures

Table 1 The 13 Key elements of the SCAM model 25

Table 2 Example of identity theft safeguards extracted from the paragraph in Figure 1 27

Table 3 Example of identity theft safeguards assigned to categories 29

Table 4 Example of transformation of identity theft safeguard recommendations 30

Table 5 Example of tradeoff weights calculated for each means of identity theft 36

Table 6 Average of values above median for both lists in the top half of each list 42

Figure 1. Paragraph form recommendation of multiple identity theft safeguards 29

Figure 2. Example of the use of a summated scale to document SCAM ratings 34

Figure 3. Example of a portion of the completed Excel™ spreadsheet 35

Figure 4. Percentage of total reported means of identity theft 36

Figure 5. Example of criminal justice statistical data scored against safeguards 37

Figure 6. Example of spreadsheet with tradeoff weights calculated and summated 39

Figure 7. Distribution of identity theft safeguards from List no. 1 – Bar Graph 42

Figure 8. Distribution of identity theft safeguards from List no. 1 – Line Graph 43

Figure 9. Distribution of identity theft safeguards from List no. 2 – Bar Graph 43

Figure 10. . Distribution of identity theft safeguards from List no. 2 – Line Graph 44

Figure 11. . Highest to lowest ranked safeguards by number of times recommended 46

Figure 12. Highest to lowest ranked safeguards by SCAM compliance score 47

Figure 13. Highest to lowest ranked safeguards by weighted means test 47

Figure 14. Identity theft insurance: Scores could be misleading 48

Figure 15. Distribution of identity theft safeguards from weighted means test 49

Figure 16. Distribution of identity theft safeguards by category 50

Figure 17. Partial list of safeguards deemed not controllable and not analyzed 54

Figure 18. Number of times each SCAM category recommended 55

Figure 19. Number of times each of 12 main identity theft categories recommended 55

List of Appendices

Appendix A Identity Theft Safeguards Proposed from [1 of 5] Government Sources 63

Appendix B Identity Theft Safeguards Proposed from [2 of 5] Government Sources 64

Appendix C Identity Theft Safeguards Proposed from [3 of 5] Government Sources 65

Appendix D Identity Theft Safeguards Proposed from [4 of 5] Government Sources 66

Appendix E Identity Theft Safeguards Proposed from [5 of 5] Government Sources 67

Appendix F Identity Theft Safeguards Proposed from [1 of 3] Law Enforcement 69

Appendix G Identity Theft Safeguards Proposed from [2 of 3] Law Enforcement 71

Appendix H Identity Theft Safeguards Proposed from [3 of 3] Law Enforcement 73

Appendix I Identity Theft Safeguards Proposed from [1 of 13] Private Sector sources 74

Appendix J Identity Theft Safeguards Proposed from [2 of 13] Private Sector sources 76

Appendix K Identity Theft Safeguards Proposed from [3 of 13] the Private Sector sources 78

Appendix L Identity Theft Safeguards Proposed from [4 of 13] Private Sector sources 79

Appendix L (Continued) Identity Theft Safeguards Proposed from [4 of 13] Private Sector sources 80

Appendix M Identity Theft Safeguards Proposed from [5 of 13] Private Sector sources 82

Appendix N Identity Theft Safeguards Proposed from [6 of 13] Private Sector sources 83

Appendix O Identity Theft Safeguards Proposed from [7 of 13] Private Sector sources 84

Appendix P Identity Theft Safeguards Proposed from [8 of 13] Private Sector sources 85

Appendix Q Identity Theft Safeguards Proposed from [9 of 13] Private Sector sources 86

Appendix R Identity Theft Safeguards Proposed from [10 of 13] Private Sector sources 87

Appendix S Identity Theft Safeguards Proposed from [11 of 13] Private Sector sources 88

Appendix T Identity Theft Safeguards Proposed from [12 of 13] Private Sector sources 89

Appendix U Identity Theft Safeguards Proposed from [13 of 13] Private Sector sources 90

Appendix X Safeguards Deemed Not Controllable and Not Considered for Analysis 105

Appendix Y Spreadsheet Used in Descriptive Analysis (Sheet 1 of 7) 107

Appendix Z Method Used to Determine Tradeoff Weights (Page 1 of 2) 114

Appendix AA Master Spreadsheet “Sorted by Weighted Means Test Summated Score” (Sheet 1 of 24) 116

Appendix BB Hierarchy of Effective Identity Theft Safeguards 140

Appendix CC Acronyms 149

Abstract

Identity theft is occurring at an alarming rate affecting everyone. Seven of the 9/11 hijackers made it past airport security with stolen identities. There exists an overwhelming number of identity theft safeguards that individuals are expected to implement and prioritize without knowing how effective they are at preventing identity theft. This research extracted 90 identity theft prevention safeguards from 462 recommendations, covering 12 categories of identity theft prevention. The effectiveness of these safeguards was evaluated, compared, and prioritized resulting in a comprehensive list that should be consulted first when preparing a targeted and effective identity theft prevention program.

Identity Theft: Hierarchy of Effective Safeguards

On May 10, 2006, President George W. Bush said, “Identity theft is a serious problem in America. I have just listened to the horror stories from fellow citizens who have had their identities stolen” (Remarks by the President, 2006, p. 1). The number of annual identity theft complaints reported to the Federal Trade Commission (FTC) is alarming and has reached epidemic proportions. Identity theft reports have increased 296.4% from 86,212 in calendar year (CY) 2001 to 255,565 in CY 2005 (FTC, 2004, 2006b). Although the rate of increase in identity theft is finally slowing, 2006 was expected to be a “record year for identity theft” (Kersnar, 2006). The most current data available from the FTC indicates that identity theft complaints actually declined from the reported 255,565 [255,613 revised] complaints in CY 2005 to 246,035 in CY 2006 (FTC, 2007). The lowering trend is welcomed and a testament to government, law enforcement, and private sector efforts to combat identity theft through awareness, detection, and education.

Private sector research firm, Javelin Strategy & Research, in conjunction with the Better Business Bureau (BBB), published their Identity Theft Survey for 2005 and 2006. Their research indicates that 8.9 million and 8.4 million Americans were victims of identity theft in 2005 and 2006 respectively (Javelin Strategy, 2006, 2007). The number of victims is alarming, but even the Javelin report shows a decrease in reported victims of identity theft year over year. Prevention and deterrence efforts seem to be making a difference. People of all categories are paying more attention to protecting their personal information and education efforts are taking hold as evidenced by the decline in victim complaint reports from 2005 to 2006.

The United States Department of Justice (USDOJ) reports that 3.2 million households suffered one or more episodes of identity theft in the first half of 2004. Of this total, 69.2% of households incurred a monetary loss because of identity theft (U.S. Department of Justice, 2006a). Victims of identity theft suffer the loss of time, work, monetary losses, endure credit denials, and have even being arrested falsely. Recommendations should be taken seriously to properly shield your personally identifying information from identity thieves and these criminals stalking their next target of opportunity (Community Oriented, 2004; Gertler, 2004; Hammond, 2003).

Government, law enforcement, and the private sector have been working at feverish pace to educate and recommend a myriad of safeguards. Effective prevention of identity theft involves the collective efforts of government, business, and consumers working together (Milne, 2003). Domestically, the president’s Executive Order (13402) set in motion a strategy to combat identity theft enlisting the cooperation of government, business, and consumers. This same concept of cooperation is internationally recognized by Canada and requires both “consumers and business take steps to safeguard the security of their data” (Consumer Measures, 2007e, p. 4).

The individual is strapped with the arduous task to choose which safeguards are effective and which safeguards to implement first. It may seem obvious that implementing identity theft safeguards is prudent protection against identity theft. What may not be so obvious is the effectiveness of one identity theft safeguard over another. This research will identify identity theft safeguards suggested by government, law enforcement, and the private sector domestically and internationally. Second, it will analyze these safeguards to determine their potential effectiveness in preventing identity theft when compared against each other using criminal justice statistical data from law enforcement on identity theft. Finally, an effective list of prioritized identity theft safeguards will be presented to offer a targeted strategy to prevent identity theft.

Problem Statement

There are an overwhelming number of recommended safeguards proposed by government, law enforcement, and the private sector that an individual is expected to implement to avoid becoming a victim of identity theft. The purpose of this research is to identify these safeguards and create a hierarchy of effective safeguards that a person can implement to avoid becoming a victim of identity theft.

Research Question

Which identity theft safeguards are more effective than others for an individual to implement to avoid becoming a victim of identity theft?

Subset research question. In what order should these effective safeguards be prioritized?

Rationale

In 2005, 8.9 million identity thefts resulted in $56.6 billion in fraud as reported by the Javelin Strategy & Research Report (2006). Of this total, 63% of the victimizations were categorized as “being within the consumer’s control” (p. 2). It is astounding to realize that most identity theft can be prevented. Government, law enforcement, and private sector sources are hard at work publishing volumes of information on identity theft recommending an overwhelming number of safeguards to consumers. The myriad of identity theft recommendations proposed by all sources seem presented in haphazard ways.

Consumers have the daunting task of selecting and prioritizing these safeguards. Every list of safeguards share similar qualities, but are vastly different in wording leaving the consumer to decipher the meaning and intent of each safeguard. Every identity theft safeguard reviewed during this research never suggested a prioritized hierarchy for implementation of proposed safeguards. Individuals seem left to decide for themselves the safeguards are more effective than others and which ones should be implemented first. It is worthwhile for an individual to know which safeguards

Identity theft is a crime that usually occurs in conjunction with other crimes (Community Oriented, 2004). More ambitious and destructive crimes are even made possible because of identity theft. Seven of the 9/11 hijackers made it past airport security with “illegally obtained identification” (Silver Lake, 2004, p. 113). Identity theft has risen to the level of compromising national security and empowers terrorists and criminals with funding for their crimes.

Information from the countries of Canada and Australia will also be included in this research to arrive at a more comprehensive hierarchy of effective identity theft safeguards. Complete prevention of identity theft may not be possible. The Australian government’s published identity theft kit says the following “While it may never be possible to stop identity theft entirely, there are a number of very simple safeguards you can take to protect yourself from becoming a victim of this type of crime” (NCP, 2007, p. 10). Javelin Strategy & Research said, “While it is impossible to totally prevent identity fraud, it is possible to greatly reduce your risk of becoming a fraud victim” (Javelin Strategy, 2007). The aftermath of identity theft can result in personal tragedy, require a lot of time and effort to remedy, and translate into a national security nightmare as was experienced on September 11, 2001.

Identifying which safeguards are the most effective to implement first go a long way in serving national and public need for this timely, evolving information. From CY 2001 to 2005, the reports of identity and the crime associated with it was outpacing prevention efforts. Only in the past full year of data for CY 2006, is this trend beginning to reverse in favor of law-abiding citizens.

The National Institute of Justice (NIJ) is the research, development, and evaluation agency of the USDOJ. In July 2007, they concluded that “more research is needed to identify the best ways to prevent identity theft crimes” (National Institute, 2007). This research is being conducted against the backdrop of this assertion from the NIJ. This research is highly appropriate and timely. There are daily reports of identities being stolen and people being victimized. Lost/stolen wallets and purses, misuse of personal information by corrupt employees, lost/stolen laptops, and even not protecting identifying information at home around unscrupulous friends, relatives, and family members, all contribute to the growth industry of identity theft.

Definitions

The term controllable describes an identity theft prevention recommendation that can be implemented by an individual without reliance upon another individual.

The term descriptive measure(s) refer to statistical analysis techniques that break down data into “intervals, graph it in special ways, or describe its characteristics in terms of numbers derived from certain formulas” (Gibilisco S., 2004).

The term identity fraud is used to describe “the unauthorized use of some portion of another’s personal information to achieve illicit financial gain” (Javelin Strategy, 2007, p. 11).

The term identity theft is broadly used in this research to describe a variety of illegal acts where theft or misuse of personal information has been involved. Its use will be consistent with the Identity Theft and Assumption Deterrence Act of 1998 formally defining identity theft as having occurred when an offender:

(7) knowingly transfers or uses, without lawful authority, any name or number that may be used, alone or in conjunction with any other information, to identify a specific individual with the intent to commit, or to aid or abet, any unlawful activity that constitutes a violation of Federal law, or that constitutes a felony under any applicable State or local law; (Identity Theft and Assumption Deterrence Act, 1998, § 003 (a) (4))

The term partially controllable describes an identity theft prevention recommendation that can be implemented by an individual with some reliance upon another individual. It is a measure that an individual has some control over.

The term phishing is the use of fraudulent e-mail and Web sites to lure users into revealing personal information, such as passwords, Social Security numbers, account numbers, credit card numbers, and other identifiers (iS3, 2007).

The term uncontrollable describes an identity theft prevention recommendation that cannot be implemented by an individual without total reliance upon another individual. It is a measure that is basically “out of the control” of the individual.

The term urbanicity is used to describe the location where reported identity theft took place (viz., urban, suburban, and rural) (U.S. Department of Justice, 2006a, p. 2).

Hypothesis

Identity theft safeguards can be prioritized based on their effectiveness and presented as a hierarchy of effective safeguards list to provide a targeted strategy to avoid becoming a victim of identity theft.

H1: Identity theft safeguards can be prioritized based on their effectiveness in preventing identity theft.

H0: Identity theft safeguards cannot be prioritized based on their effectiveness in preventing identity theft.

Literature Review

Identity theft data in the United States is derived from five primary sources (a) Identity Theft Victim Complaint Data (FTC, 2006b, 2007), (b) National and State Trends in Fraud & Identity Theft (FTC, 2005, 2004), (c) Identity Theft Survey Report (Synovate, 2003), (d) Identity Theft, 2004 from the National Crime Victimization Survey (NCVS) on identity theft (U.S. Department of Justice, 2006a), and the (e) Identity Fraud Survey Reports by Javelin Strategy & Research [consumer version] (Javelin Strategy, 2006, 2007). This research also compiled data provided by (a) government, (b) law enforcement, and (c) private sector sources to ensure a more comprehensive result.

The Identity Theft Victim Complaint Data (FTC, 2006b, 2007) reports combine complaints registered with the FTC for CY 2003, CY 2004, CY 2005, and CY 2006. The information in these reports are pivotal because they identify how a victim’s identity was misused, the range of victim ages, rankings of identity theft of the major metropolitan areas, identity thefts by state, and the time it took victims to report identity theft. This information is also useful because it will help focus which identity theft safeguards can be more effective than others. The report also breaks down identity theft into categories (a) credit card fraud, (b) phone or utilities fraud, (c) bank fraud, (d) employment-related fraud, (e) government documents or benefits fraud, (f) loan fraud, and (g) other identity theft fraud. Each of these categories is further broken down by subtype to account for the 255,565 [255,613 revised] filed complaints in CY 2005 (FTC, 2006b, 2007).

The National and State Trends in Fraud & Identity Theft (FTC, 2005, 2004) reports victim complaint data for CY 2001, CY 2002, CY 2003, and CY 2004 overlapping the data from the Identity Theft Victim Complaint Data (FTC, 2006b, 2007). Each subsequent report publishes revised data from the previous year’s report. These FTC reports combine to give 6 years of data on identity theft victim complaints and trends in the United States.

The Identity Theft Survey Report of 2003 (Synovate, 2003) tabulates data from a telephone survey of 4,057 U.S. adults between March 17, 2003 and April 23, 2003. The data was extrapolated to the U.S. population age 18 and over to arrive at the results. The Synovate report is extensively cited by others writing about identity theft. The report identifies key categories of identity theft similar to the FTC reports. The Synovate report identifies the number of persons affected by identity theft to be 9.91 M, the cost per victim to be about $500.00, and the time spent in rectifying identity theft per person to be about 30 hours (Synovate, 2003).

The USDOJ bulletin Identity Theft, 2004 (U.S. Department of Justice, 2006a) is a comprehensive report to law enforcement on identity theft statistics. This report breaks down the type of fraud committed, the range of victim ages, victim race, victim income, and urbanicity. The report goes in-depth into the economic losses incurred by identity theft victims and how those losses occurred. This report adds breadth to the research and will provide insight from law enforcement.

Javelin Strategy & Research have produced two consumer version reports on identity theft called the 2006 and 2007 Identity Fraud Survey Report[s] (Javelin Strategy, 2006, 2007). Each report summarizes their survey of approximately 5,000 U.S. adults. In each year about 10% of respondents were identified as victims of identity theft. The reports are funded by private industry and conducted in conjunction with the BBB. These private sector reports tabulate data for CY 2003, CY 2004, CY 2005, and CY 2006. These are high quality reports worthy of significant attention throughout this research. These reports are unique because they analyze survey results in detail and make their own conclusions and recommendations to consumers to avoid identity theft based on that data.

The information Hammond (2003), Khalfani (2004), and Javelin Strategy & Research (2006) provide on minimizing your exposure to identity theft is valuable. Hammond (2003) suggests adoption of the United States Department of Justice “SCAM” acronym and making an “identity thief’s ‘job’ tougher” (p. 73). Khalfiani (2004) recommends “identity theft insurance” (p. 100). Javelin Strategy & Research (2006) promotes “putting into practice a variety of the most effective measures” (p. 2).

The U.S. Department of Justice (USDOJ) promotes the acronym “SCAM” and stands for “stingy, check, ask, maintain” your personally identifying information. The USDOJ believes that implementing identity theft safeguards that comply with SCAM will go a long way to “minimize the risk of becoming a victim of identity theft or fraud” (U.S. Department of Justice, 2006b, p. 4).

The USDOJ commissioned criminal justice professor’s Graeme R. Newman from the University of Albany and Megan M. McNally from Rutgers University, to report on the literature and research available on identity theft. The goal of their research “draws on available scientific studies and a variety of other sources to assess what we know about identity theft and what might be done to further the research base of identity theft” (Newman R. & McNally M., 2005, p. 5). Newman and McNally (2005) point out that a situational approach applied with respect to identity theft prevention is preferable and suggest that identity theft could be reduced if it were possible to 1) increase the effort the offender must make to complete the crime, 2) increase the risks of getting caught, 3) reduce the rewards that result from the crime, 4) reduce provocations that may encourage or otherwise tempt offenders and, 5) remove excuses that offenders may use to justify their crime. An approach in deriving a prioritized hierarchy of effective safeguards list could be to filter unique recommended safeguards using these elements.

The USDOJ is also providing to law enforcement information on identity theft. The USDOJ has a series of problem-oriented guides for police. Their guide Identity Theft (Community Oriented, 2004) explores the factors contributing to identity theft and how offenders steal identities. The guide provides insight into the modi operandi the identity thief uses to commit this crime. Understanding how and why the identity thief accomplishes identity theft is valuable to this research because it will help judge the effectiveness of identity theft prevention safeguards on preventing identity theft.

Kahlfani (2004) offers several avoidance tips to minimize exposure to identity theft and points out that identity theft is a “crime of opportunity” (p. 96). Both Hammond (2003) and Javelin Strategy and Research (2006) agree that an essential element of identity theft protection involves removing the opportunity to become victimized. They each support the need to implement a personal targeted strategy aimed at preventing identity theft.

President Bush recognized that all government agencies must work together in a comprehensive synergistic way and formed the “Identity Theft Task Force” with Executive Order 13402 (Exec. Order, 2006, p. 27945). This executive order mandated “the 13 government agencies involved with identity theft [to] have a well-coordinated strategy to help the victims and to put those who commit the theft behind bars” (Remarks by the President, 2006, p. 1). To effectively combat identity theft takes a collaborative effort of the consumer, business, local police, the U.S. Secret Service (SS), the U.S. Postal Service (USPS), local government, and even the Department of Motor Vehicles (DMV) (Community Oriented, 2006; Milne, 2003). The mission statement of the SS specifically mentions identity theft (U.S. Secret Service, 2006) and the USPS offers safeguards on their website to combat identity theft (U.S. Postal Service, 2006).

The FTC maintains an identity theft information web site and produces an entire education campaign called “Deter, Detect, Defend, AvoID, Theft” (Consumer Response, 2006d). They make available high quality materials and information on identity theft through their web site. Their guide Talking About Identity Theft: A How-To Guide (Consumer Response, 2006a) provides in-depth information in tandem with the companion brochure Deter∙Detect∙Defend AvoID theft (Consumer Response, 2006b). Another pamphlet entitled Take Charge: Fighting Back Against Identity Theft (Consumer Response, 2006c) provides useful insight into what opportunities the identity thief is looking to exploit. These materials discuss identity theft safeguards with the reasons why they should be incorporated into a protective plan as part of an overall strategy to combat identity theft.

Identity Theft 911 produces some extensive identity theft information on their website (Identity Theft, 2006a). Identity Theft 911 in some ways is a private sector version of the FTC’s campaign. Identity Theft 911 is a benchmark site providing essential information on protecting personal identifying information, postal security, minimizing exposure to identity theft, internet scams and phishing, and offers checklists on recommended identity theft safeguards (Identity Theft, 2006b).

The following domestic sources were found to contain profound safeguard recommendations for preventing identity theft: (a) Deter: Minimize Your Risk (FTC, 2006a), (b) Alert: Protect Your Personal Information (Federal Citizen, 2006), (c) Invasion of the ID Snatchers (National Consumers, 2006), (d) Consumer Alert: How to Protect Your Identity from Being Stolen (Direct Marketing, 2006), (e) Identity Theft: How to Protect Your Name, Your Credit and Your Vital Information…and What to do When Someone Hijacks Any of These (Silver Lake, 2004, p. 180), (f) Identity Theft: Protecting Yourself From an Unprotected World (Pope, 2006), (g) Personal Banking: Tips to Avoid Identity Theft (Leppol, 2005), (h) Your Life: 8 Tips to Avoid Identity Theft (AARP Bulletin, 2004), (i) Don’t Let Crooks Steal Your Identity: How to Protect Yourself–and Your Credit Rating (Armstrong, 2001), (j) Take Charge: Fighting Back Against Identity Theft (FTC, 2006c), (k) Somebody’s Snatching You (Gertler E. & Silver M., 2004), (l) Most Identity Theft is low-tech, and so are Steps to Thwart It (Block, 2005) and, (m) How to avoid identity theft (Chiff, 2007).

Identity theft knows no borders and to confine this research only to domestic sources of information could deny valuable information on the topic. Canada has developed consumer and business related identity theft materials under the auspices of the government using their Consumer Measures Committee (CMC) whose role is the following:

The Consumer Measures Committee (CMC) is a forum of federal, provincial and territorial government representatives who cooperate to eliminate barriers to trade between provinces and territories, and to improve the marketplace for Canadian consumers. The CMC is conducting a public consultation on measures to address Identity Theft with the objective of soliciting views from stakeholders and the public on their policy and practical implications. (Consumers Measures, 2007c, p. 2)

The committee is co-chaired by the Director General of the Office of Consumer Affairs, Industry Canada, and by the Director of the Consumers’ Bureau, Manitoba Finance showing a high governmental commitment to identity theft prevention (CMC, 2007a).

Information contained in Canadian publications on ways to reduce identity theft will be incorporated into this research in order to provide more breadth and depth and to support the assertion that identity theft is a global problem. The CMC published two identity theft checklists for consumers and provides many resources through the Canadian Consumer Information Gateway on identity theft (CMC, 2007b, 2007d). These checklists are very thorough and complement the other sources that will be included in this research.

The Australian government publishes extensive educational resources through their National Crime Prevention (NCP) bureau as part of their strategy to combat identity theft. To combat identity theft, the Australian government announced the adoption of The National Identity Security Strategy (NISS). The NISS published a kit containing compiled information that is a cooperative effort of nine different Australian government departments and commissions (NCP, 2007). The Senator of Western Australia and Minister for Justice and Customs says in his forward “By introducing some practical precautions into everyday life, you can take an active role in reducing the risk that your identity may be used without your consent or knowledge” (NCP, 2007, p. 3). Their report offers additional safeguards that will be coupled with all others resulting in a comprehensive list of safeguards from which the hierarchy of effective safeguards list can emerge.

Famous people who have been victims of identity theft include: Steven Spielberg, Oprah Winfrey, Ted Turner, and Tiger Woods (Gertler, 2004; CBS News, 2001). Identity theft will take an emotional toll on anyone that is victimized and everyone is susceptible. Identity theft victims lose a sense of trust for mankind (CBS News, 2001). Victims can develop chronic conditions of pain, nervous breakdowns, and some have even been arrested due to the actions of the identity thief (Community Oriented, 2004; Gertler, 2004; Hammond, 2003).

There is a growing trend in the private sector among insurance companies to offer identity theft insurance products. Companies that are gaining acceptance in the growing demand for identity theft insurance are LifeLock™ (LifeLock™, 2007a) and Zander Insurance Group (Zander, 2007a). Both boast of providing identity theft preventative services that are comprehensive and affordable. Each offers protection, recovery, and reimbursement for lost income and expenses associated with an episode of identity theft.

Lifelock™ openly publishes their CEO’s Social Security number on billboards, print advertising, and their company internet web page to prove how effective their services are (Lifelock™, 2007c). Lifelock™ guarantees their service will prevent your personal information from being used to commit fraud or they will reimburse you up to $1,000,000.00 (Lifelock™, 2007b). The Lifelock™ guarantee is gaining the attention of consumers and is adding awareness/education to the problem of identity theft. This research will benefit by looking at these insurance company’s methods, services, and recommendations to prevent identity theft. It should be noted that these two insurance companies are among the most prominently known due to their advertising efforts. No endorsement of either company should be implied or assumed.

The information found during this research on identity theft is substantial. The safeguards captured from all sources overlap and promote some of the same recommendations worded in different ways. The information is comprehensive, practical, appeals to common sense, and generates thought. A methodically detailed approach will be used to compare the effectiveness of identity theft safeguards compared to one another and create a prioritized list that people should implement when preparing a targeted and effective identity theft prevention program.

Methodology

This proposed research used a hybrid of qualitative and quantitative methods to answer the research questions on the effectiveness of and prioritization of identity theft prevention safeguards. No human subjects were used in this research. An extensive list of safeguards was extracted from 21 different government, law enforcement, and private sector sources of all types. Judgment on the effectiveness of each safeguard was determined. The extracted safeguards were prepared for analysis by:

· Transforming them into unique safeguard recommendations.

· Rating them based on their scored effectiveness against established criteria.

· Sorting them by categories.

· Graphing them.

· Statistically analyzing their differences.

The end product of this analysis was to determine the effectiveness of one safeguard in relation to another and propose a prioritized list from those captured identity theft safeguards. The generated list would be regarded as the hierarchy of effective identity theft safeguards.

Determining the effectiveness of an identity theft prevention safeguard.

Each safeguard was judged against the USDOJ SCAM (stingy, check, ask, and maintain) model to determine a level of effectiveness. Rating each safeguard created a numerical value that was used to rank order that safeguard among the others. The higher the rating the higher and more effective that safeguard was considered. Monitoring how each safeguard changed order within the lists was the test to determine which identity theft safeguard was more effective than another.

Creating a prioritized list of effective identity theft safeguards (H1).

A list of unique safeguards was created before beginning the arduous task of creating a prioritized list of effective identity theft safeguards. The unique list of safeguards was sorted twice, each time against different criteria. List no. 1 was sorted, in descending order, by the number of times each unique safeguard was recommended by the literature. List no. 2 was sorted, in descending order, using the judged effectiveness of each safeguard against the SCAM acronym. Each list was then compared to the actual means of identity theft graphically (bar graph & Line graph) and using descriptive measures. Finally, a paired, two-sample (two-tailed), t test was performed on the two lists using a statistical significance threshold of p < .05.

The safeguards presented in List no. 1 and List no. 2 was derived using safeguard recommendations from 21 different government, law enforcement, and private sector sources. Similar safeguards were combined and transformed to arrive at a unique, comprehensive list. The order of List no. 1 was determined by sorting on how many times a specific safeguard was recommended across all 21 sources. The ones that were presented most often were placed at the top of this list creating List no. 1.

List no. 2 was prioritized through a hybrid of qualitative and quantitative methods. The same 90 safeguards were qualitatively judged against 13 key elements promoted by the USDOJ with their SCAM acronym (Stingy, Check, Ask, and Maintain) (U.S. Department of Justice, 2006b). Each safeguard was subjectively assigned a value of 1 (strongly disagree) to 5 (strongly agree) on a Likert scale with 5 being the most compliant with the SCAM model to 1 being the least compliant. In order for a safeguard to be awarded a high SCAM compliance score, that safeguard had to meet the scope and intent of the 13 elements of the SCAM model (see Table 1).

An overall rating that was termed the SCAM compliance score was tabulated for each unique safeguard. Subjectively, each safeguard was judged whether it met the intent of SCAM. The higher each safeguard scored with respect to the elements of SCAM, the more compliant with SCAM each safeguard was judged to be. The safeguards that had the highest summated SCAM compliance score rose to the top of this list creating the second, preliminary list of effective safeguards. Both lists were then scored against the actual means of identity theft from criminal justice data reported by Javelin Research & Strategy (2006) to determine which list would emerge as the definitive prioritized list of effective safeguards.

Table 1 The 13 Key elements of the SCAM model

SCAM Acronym

13 Key Elements of the SCAM model

S – Stingy

· Establishes a “need to know” approach

· Minimizes printed personal information

· Limits information verbally disseminated

· Establishes security for printed information

· Shrouds personal information when in public

C- Check

· Reconcile all financial information regularly

· Ensures financial information is received as expected

· Guards against unauthorized changes of address

A – Ask

· Periodically ask for a copy of your credit report

· Review your credit report for errors

· Limit access to your credit report

M – Maintain

· Carefully store, secure, and file personal information

· Ensure your records are readily available for 1 year

Data Preparation

List no. 1 and List no. 2 were prepared using protocols on data preparation established by the Web Center for Social Research Methods (WCSRM) and the work of Dr. William M. K. Trochim of Cornell University (Trochim, 2006b). The following five step data preparation process was used creating the necessary framework to analyze the data:

· Logging the data.

· Checking for accuracy.

· Computer entry.

· Data transformation.

· Developing and documenting a database structure that integrates the various

· measures.

Logging the data, checking for accuracy, and computer entry.

Identity theft safeguards were compiled from (a) leading books on identity theft, (b) consumer awareness brochures, (c) government sanctioned reports, and (d) web sites dedicated to identity theft education, awareness, and prevention, to ensure as wide a breadth of information from government, law enforcement, and private sector sources possible. A spreadsheet was created to log these identity theft safeguards in the order in which they were presented by the literature.

Quite often, multiple recommended safeguards were presented in paragraph form and would have to be tediously extracted and logged separately. Logging each safeguard was important so that a unique list of safeguards could be tabulated. This research methodically extracted these safeguards from within the paragraphs. An example of an identity theft safeguard in paragraph form is shown in Figure 1 as obtained from the Federal Citizen Information Center (FCIC) website (FCIC, 2006).

Figure 1. Paragraph form recommendation of multiple identity theft safeguards

The identity theft safeguards that were extracted in this manner were all added to the spreadsheet. Table 2 shows an example of how paragraph type safeguards were extracted.

Table 2 Example of identity theft safeguards extracted from the paragraph in Figure 1

Safeguard

Order Found in Paragraph

Deposit your outgoing mail in a post office

collection box rather than in an unsecured mailbox

1

Promptly remove mail from your mailbox

2

If you won’t be home to pick up your mail for an

extended period of time request a vacation hold

3

When ordering new checks, pick them up from the

bank instead of having them mailed to your home mailbox

4

Tear or shred your charge receipts, copies of credit

applications, insurance forms, physician statements,

checks and bank statements, expired charge cards that

you’re discarding, and credit offers you get in the mail

5

This process was repeated for each identity theft safeguard listing found across all 21 sources. Accuracy was ensured by searching for errors in spelling, diction, and terminology. Some safeguards were easier to extract than others because they were not in paragraph form, but already presented numerically or in bulleted list format. The universe of all compiled safeguards was considered the “raw data” (Trochim, 2006c) list from all government, law enforcement, and private sector sources used in this research. This raw data list became the starting point prior to the data transformation phase that combined and reworded the safeguards.

Data transformation.

Once all safeguards were tabulated, they were in a format ready for transformation. It became apparent that each identity theft safeguard could be assigned to one of 12 main categories of identity theft prevention (a) account and personal information protection, (b) computers and information system protection,(c) credit reports, (d) education, (e) identity theft insurance, (f) internet and e-mail protection, (g) “opt out” of information sharing agreements, (h) password protection, (i) physical security of personal information, (j) purse and wallet protection, (k) Social Security number protection, and (l) protection of trash and mail. Each safeguard was categorized. Those safeguards that could be categorized into more than one category were assigned the category judged to be most closely it was aligned with. There is probably no limit to the number of categories that can be created or the number of subcategories that could be created from these 12 main categories.

The goal of data transformation was to help create a single list of unique safeguards from all the sources researched. Each safeguard had to be categorized and grouped so specific data management functions in Excel™ could be used to analyze the data like (a) auto filtering, (b) advanced filtering, and (c) variations on sorting data, and (d) expanding selections so data would not be lost. Categorizing is one way to help transform data into a usable format (Trochim, 2006c). Each safeguard was documented separately and categorized by keywords. Each safeguard that said the same thing was transformed into a single safeguard condensing the overwhelming number of safeguards to a more manageable selection. Categorizing the universe of recommended safeguards without transforming them first would have made combining like safeguards an order of magnitude more difficult. Keywords were also used to quickly assign safeguards within their respective categories (see Table 3).

Table 3 Example of identity theft safeguards assigned to categories

Safeguard Extracted from Source

Category of Safeguard Assigned

Account and Personal

Information Protection

Computers and Information Systems

Credit Reports

Internet and e-mail

“Opt out” of Information

Sharing Agreement

Password Protection

Physical Security of

Personal Information

Purse and Wallet

Trash and Mail

Social Security Number

1. Speak softly when giving out personal information Account and Personal

in public Information Protection

2. Use a secure browser Computers and information

Systems

3. Check your credit reports once per year Credit Reports

4. Look for clues about security when providing account Internet and e-mail

numbers online

5. “Opt out” of pre-approved credit offers “Opt out” of Information

Sharing Agreements

6, Don’t write PIN numbers down Password Protection

7. Don’t leave bills, statements, and other personal records Physical Security of

around in plain site Personal Information

8. Carry credit cards in a separate holder from your wallet Purse and Wallet

9. Shred information you don’t intend to keep Trash and Mail

10. Ask for an alternate number to identify you on your Social Security Number

driver’s license, insurance card, and other materials

Once each safeguard was categorized, the column containing the recommended safeguards was filtered by this newly assigned category. This resulted in a list of non-prioritized safeguards that categorically proposed the same identity theft prevention measure, but worded each one in a different way. Categorizing was extremely helpful in the transformation process. Each safeguard that proposed the same identity theft recommendation was worded alike being careful to preserve intent and clarity of meaning. Like safeguards were grouped by category, rearranged, reworded, and combined, to prepare them for final transformation (see Table 4).

Table 4 Example of transformation of identity theft safeguard recommendations

Safeguard

Category of Safeguard

Only give your Social Security number when absolutely necessary; ask to use other identifiers

Social Security Number

If your state uses your Social Security number as your driver’s license number, ask to substitute another number

Social Security Number

If your health insurer uses your Social Security number as your policy number, ask to substitute another number

Social Security Number

- - - - - - - - - - - - - - -WAS TRANSFORMED INTO THE FOLLOWING - - - - - - - - - - - - - - -

Ask to use other identifiers other than your Social Security number on: (driver’s licenses, Health insurance/records, registrations, applications, etc.)

Social Security Number

Ask to use other identifiers other than your Social Security number on: (driver’s licenses, Health insurance/records, registrations, applications, etc.)

Social Security Number

Ask to use other identifiers other than your Social Security number on: (driver’s licenses, health insurance/records, registrations, applications, etc.)

Social Security Number

Each safeguard was assigned one of the SCAM categories (stingy, check, ask, maintain) (DOJ, 2006b) after being transformed. A column was added to a master spreadsheet to compile these assignments. If a safeguard said, “Shred all your mail” (Pope, 2006, p. 151) it was assigned the SCAM category of “stingy” because that safeguard most closely related to the identity theft prevention strategy of “increase the effort the offender must make to complete the crime (Newman R. & McNally, 2005, p. 5).

Assigning the SCAM compliance score became a hybrid of qualitative and quantitative analysis. The entire safeguard list was advance filtered to only show unique identity theft safeguards in the leftmost column. The next 13 columns were populated with the elements of SCAM. Each safeguard was qualitatively assigned a score of 1 (strongly disagree) to 5 (strongly agree) on a Likert scale depending upon whether implementing that safeguard would have a desired outcome or an undesirable outcome when compared against the elements of SCAM. A 5 rating was awarded when a safeguard was judged to be in full compliance of the SCAM model and a 1 signified little compliance. The following scaling was used:

· 5 = Strongly Agree

· 4 = Somewhat Agree

· 3 = Undecided

· 2 = Somewhat Disagree

· 1 = Strongly Disagree

At the completion of the scoring, the “summated scale” (Trochim, 2007a) technique was used to arrive at the SCAM compliance score for each identity theft safeguard. The spreadsheet was transformed as follows:

· The 13 SCAM elements were added.

· The spreadsheet was filtered for unique safeguards.

· Likert scaling was accomplished and annotated under each element.

· Individual element scores were summated from right to left across the spreadsheet for each safeguard.

· SCAMRating The spreadsheet was sorted in descending order under “SCAM rating” to identify the most to least SCAM compliant safeguard (see Figure 2).

With all these steps completed, List no. 2 was now tabulated and ready for final analysis.

Figure 2. Example of the use of a summated scale to document SCAM ratings

Developing and documenting a database structure that integrates the various measures.

The final master spreadsheet was completed by:

· Cleaning up all the identity theft prevention phrases in the first column.

· Sorting all the unique safeguards alphabetically.

· Adding a column to count and document the number of occurrences each

· safeguard was recommended from all sources.

· Adding a column to assign one of the four categories DOJ asserts within their SCAM model (Stingy, Check, Ask, and Maintain) (U.S. Department of Justice, 2006b).

· Adding a column to document the SCAM compliancy score.

· Adding a column to assign the word controllable, partially controllable, or uncontrollable to each identity theft safeguard.

· Adding a column to tabulate how many times each category was used.

This codified information structure is suitable for future research endeavors on the prevention of identity theft and can be used to analyze other variations of the data without additional compilation of the data or information (Trochim, 2007c). The structure of the completed spreadsheet used in the final analysis of the data is shown in Figure 3 and integrates the various measures of the research methodology.

Figure 3. Example of a portion of the completed Excel™ spreadsheet

Many of the safeguards have been transformed to say the same thing (see Figure 3, column A). The number of times a safeguard was recommended was tracked in column B, “No. of times recommended,” Care had to be taken not to lose data while filtering and sorting the data. This database structure was pivotal in the treatment of the data.

Final Data Analysis

MeansOfIdentityTheftTable2The final process of analysis to determine if List no. 1 or List no. 2 became the prioritized list of effective identity theft safeguards was to compare both lists against criminal justice statistical data from Javelin Strategy & Research. This data shows, as a percentage and by specific act, all reported “Means of Access” (Javelin Strategy, 2006, p. 7) used to commit identity theft (see Figure 4).

Figure 4. Percentage of total reported means of identity theft

Primarily Consumer Controlled:

A. Lost or stolen wallet, checkbook, or credit card (30.0%)

B. By friends, acquaintances, relatives, or in-home employees (15.0%)

C. From stolen paper mail or by fraudulent change of address (8.0%)

D. Computer viruses, spyware, or hackers (5.0%)

E. Phishing (3.0%)

F. Garbage (1%)

G. Online transactions (0.3%)

Primarily Business Controlled:

H. Taken by a corrupt business employee (15.0%)

I. Misuse of data from an in-store/online/telephone transaction (7.0%)

J. Stolen from a company that handles your financial data (6.0%)

Other:

K. Other – (9.7%)

A system to compare the criminal justice statistical data to both lists had to be created. The list that emerged from this analysis with higher scores in the top half of the list was considered the prioritized list of effective safeguards. Each safeguard was compared to categories A through K (see figure 4) to determine what impact implementing that particular safeguard recommendation would have on preventing identity theft. On a Likert scale of 1 (strongly disagree) to 5 (strongly agree), the question was asked, “would implementing a particular safeguard encourage or discourage each ‘means of identity theft’ from taking place?” The following scaling was used:

· 5 = Strongly Agree

· 4 = Somewhat Agree

· 3 = Undecided

· 2 = Somewhat Disagree

· 1 = Strongly Disagree

Each safeguard was scored against each element of the criminal justice statistical data to derive the “Means Test Raw Score of Compliance” (see Figure 5).

Figure 5. Example of criminal justice statistical data scored against safeguards

A technique of decision analysis called “Tradeoff Weights” (Golub, 2007, p. 159) was then used to weigh each category against another. The determined weight of each means was multiplied by the Likert values determined for that safeguard against that means. Using the “additive utility function” (Golub, 1997, 160) a final number representing the weight of each safeguard was found and termed the “Summated Tradeoff Weight Score” (see Figure 6).

Criminal justice statistical data showed that identity theft from a “Lost or stolen wallet, checkbook, or credit card (30%)” occurs at a rate twice that of “By friends, acquaintances, relatives, or in-home employees (15%)” (see Figure 4). The “direct method” (Golub, 2007, p. 161) was used to determine how much weight should be given to each category of identity theft means. Steps used to apply the direct method in our decision making were to:

· Capture the proportion of one means to another.

· Select a standard to compare the others means of identity theft to.

· Derive the mathematical relationship of each means to the standard.

· Apply these derived weights to our summated Likert scale.

Criminal justice statistics from Javelin Strategy & Research (2006) already prioritized the means of identity theft as a percentage to the total number of identity theft reports. The relative importance of each means, compared to the standard chosen; “Lost or stolen wallet, checkbook, or credit card (30%)” (see Figure 4) was then expressed as a mathematical equation. The percentages calculated also went through a common sense check to make sure the process was sound and correct proportions were being used. An example of the tradeoff weights used in the analysis is shown in Table 5.

Table 5 Example of tradeoff weights calculated for each means of identity theft

A. Lost or stolen wallet, checkbook, or credit card (30.0%)

1

B. By friends, acquaintances, relatives, or in-home employees (15.0%)

0.5

C. From stolen paper mail or by fraudulent change of address (8.0%)

0.26

D. Computer viruses, spyware, or hackers (5.0%)

0.16

E. Phishing (3.0%)

0.1

F. Garbage (1.0%)

0.03

G. Online transactions (0.3%)

0.01

H. Taken by a corrupt business employee (15.0%)

0.5

I. Misuse of data from an in-store/online/telephone transaction (7.0%)

0.23

J. Stolen from a company that handles your financial data (6.0%)

0.32

By multiplying the Likert ratings, by the calculated tradeoff weights, and summating them, the “Summated Tradeoff Weight Score” score was found (see Figure 6).

Treating both lists, using tradeoff weight analysis, was the last step before sorting both lists, in descending order, to determine which list would become the prioritized list.

Figure 6. Example of spreadsheet with tradeoff weights calculated and summated

To determine if List no.1 (generated by the number of times each recommendation was mentioned in the literature), or List no. 2, (prepared by rating each safeguard to the SCAM model), became the prioritized list of effective safeguards; bar graphs and line graphs were generated by Excel™ for each list. Descriptive measures were also used to determine if either list had higher average values above the median value in the top half of each list. Finally, a paired, two-sample (two-tailed) t test was used with a statistical significance threshold set at p < .05 to determine if there was a significant difference between the distribution of List no. 1 compared to List no. 2 to confirm any results obtained graphically and descriptively.

Results

The goal of this research was to show that some identity theft prevention safeguards are more effective than others and can be prioritized based on this effectiveness in preventing identity theft. Identity theft prevention recommendations from 21 different resources across government, law enforcement, and the private sector sources were compiled. An overwhelming number of 462 identity theft prevention safeguard recommendations were extracted (see Appendixes A through U). Of the 462 safeguards, 26 of them were deemed uncontrollable and removed because they were not within the control of an individual to implement. The resulting list contained 436 recommended safeguards that were transformed and combined to make the final 90 unique identity theft safeguard recommendations from which the analysis continued (see Appendixes V or W).

Compared Effectiveness of Identity Theft Safeguards

Each safeguard could be assigned more or less of a rating depending upon its judged effectiveness using the SCAM model. Safeguard positions, within a list, would rise and fall depending upon its given score/rating at preventing identity theft. Each safeguard was determined to be more or less effective because of its characteristic tendency to move higher or lower in ranking. Safeguards considered uncontrollable were not considered in the analysis (see Appendix X). If a safeguard was considered equally effective compared to another, that safeguard would not tend to change positions within the lists created. Identity theft safeguards are considered to be comparatively more or less effective base on their scores not remaining constant.

Creating a Prioritized List of Effective Safeguards (H1)

List no. 1 (see Appendix V) was created by rank ordering the 90 unique safeguards by the number of times each was recommended from the 21 sources of data. The safeguard presented in top place on List no. 1 was the recommendation to “Treat mail and trash carefully: ALWAYS shred/destroy documents with . . . personally identifying information.” This safeguard was recommended 27 times, the most of any safeguard.

List no. 2 (see Appendix W) was created out of a hybrid of qualitatively and quantitatively analysis. Each safeguard was rated against the 13 elements of the SCAM model using a Likert scale from 1 (strongly disagree) to 5 (strongly agree). It was then sorted in descending order. The top recommendation on List no. 2 was to “Never give credit card, bank, Social Security, sensitive, personal, account, or . . . ask that written information be sent.” The highest rated safeguards were usually the ones that promoted the need to know philosophy of being stingy with personally identifying information.

Safeguards that were not included in the analysis were those that were considered uncontrollable (see Appendix X). Lists No. 1 and List No. 2 were then analyzed in the following three ways to determine which could be a candidate for the prioritized list:

· Graphically comparing lists.

· Using descriptive measures to compare average values above the median value in the top half of each list.

· Using the paired, two-sample (two-tailed), t test.

Graphically comparing lists.

List no. 1 and List no. 2 were both graphically plotted as bar graphs and line graphs and analyzed to determine if one list rated the safeguards higher than the other list. Two types of graphs were used to incorporate multiple descriptive measure as a “special way” (Gibilisco, 2004, p. 94), to see if different graphical forms of the data would help identify which list should be chosen as the hierarchy of identity theft safeguards.

The median of the data set was calculated to be 8.37 and was drawn horizontally on each graph crossing the y-axis through this point (see Figure 7, 8, 9, and 10). The median is considered the “middle” (Gibilisco, 2004, p.53) value of the data set arranged in order of magnitude. It is also considered the geographic center of the data.

It could not yet be determined graphically if List no. 1 or List no. 2 presented the better prioritized list of identity theft safeguards. Both the bar graphs and line graphs appear equally distributed. Using the descriptive measure of comparing averages of both lists above the median value, provided an additional way to analyze the distribution. The averages calculated did show that there was a difference between the two lists, but the distinction and significance was not

Figure 7. Distribution of identity theft safeguards from List no. 1 – Bar Graph

Figure 8. Distribution of identity theft safeguards from List no. 1 – Line Graph

Figure 9. Distribution of identity theft safeguards from List no. 2 – Bar Graph

Using descriptive measures to compare average values above the median value in the top half of each list.

Figure 10. . Distribution of identity theft safeguards from List no. 2 – Line Graph

Further analysis used descriptive measures to compare average values above the median in the top half of each list to yield a more definitive solution on the significance between the two lists (see Appendix Y). Comparing the averages for List no. 1 and List no. 2 shows that List no. 2 had a higher average of safeguards compared to List no. 1 in the top half (see Table 6).

Table 6 Average of values above median for both lists in the top half of each list

Total of values above Median of 8.37

No. of safeguards above Median

Average above Median

List no. 1:

317.04

30

10.57

List no. 2:

276.43

26

10.63

The results in Table 6 show that List no. 2 had a higher average value than List no. 1 in the top half of the lists. List no. 2 even had 4 less safeguards that could count toward a better average than List no. 1, 26 vs. 30, respectively. This shows that List no. 2 has higher rated safeguards above the geographic center of the data and is considered prioritized better than List no. 1. To determine the significance of the difference between the two lists, the data had to be statistically tested.

Using a Paired, Two-Sample (two-tailed), t Test

List no. 1 and List no. 2 was statistically tested using a paired, two-sample (two-tailed) t test to determine if there was a significant statistical difference between the two distributions. The paired, two-sample (two-tailed), t test can be used “when a sample group is tested twice–before and after an experiment” (AnalystSoft®, 2007). The test assumed a statistical significance of p < .05. It was determined that the statistical difference between the paired data from List no. 1 and List no. 2 was not significant. The paired, two-sample (two-tailed), t test calculated the significance level to be p = 0.1733, not large enough to exceed the 5% critical threshold value of p = 1.987. It is statistically conclusive, that the null hypothesis (H0) is true and the alternate hypothesis (H1) is false and not accepted. Identity theft safeguards cannot be prioritized based on their effectiveness in preventing identity theft using this methodology.

Discussion

This research set out to prove that the effectiveness of one safeguard over another could be shown and that a prioritized list of effective safeguards could be created. Identity theft safeguards were shown to be more or less effective than others, but did not show that identity theft safeguards could be prioritized using the proposed methodology. Two lists were created, but neither one emerged within a statistical level of significance to create a prioritized list of effective identity theft prevention safeguard.

Comparative Effectiveness

It was shown that some identity theft safeguards are more effective at preventing identity theft than others. In List no. 1 and List no. 2 (see Appendixes V and W); the identity theft safeguard “Use two computers if financially possible” was at the bottom of both lists. This safeguard was recommended (a) only once by all sources, (b) rated lowest against the SCAM model and, (c) rated lowest against criminal justice statistical data (Javelin Research, 2006). This safeguard was found to be typical of some recommendations that would have little to no impact on preventing identity theft. The effectiveness of these types of recommendations was rated very low. Figures 11, 12, and 13 show how two different safeguards are rated higher or lower depending upon the criteria used to score them.

Figure 11. . Highest to lowest ranked safeguards by number of times recommended

Figure 12. Highest to lowest ranked safeguards by SCAM compliance score

Figure 13. Highest to lowest ranked safeguards by weighted means test

The hypothesis linked to the effectiveness of safeguards is proven based on the different scores/ratings they received. More research could be conducted to determine if implementing certain safeguards actually affected victim complaint data. For example, with respect to safeguard number 42, on List no. 1 (see Appendix V), “Ask about identity theft insurance”. Could a group study be performed to monitor victim complaint data after implementing this safeguard? This safeguard was only mentioned twice among all sources in the literature. It scored well against SCAM criteria, but it scored poorly when rated against the actual means of identity theft (see Figure 14, column W).

The score a particular safeguard received was highly dependent upon the criteria used. One of the tenets of identity theft insurance is that these programs place fraud alerts and security freezes on your credit bureau accounts (LifeLock™, 2007a). This is just one line-of-defense aimed at preventing your credit bureau account from being accessed without your permission. Putting a fraud/security alert on your credit bureau account coincides with three of five suggestions Newman and McNally (2005) promote:

Figure 14. Identity theft insurance: Scores could be misleading

· Increase the effort the offender must make to complete the crime.

· Increase the risks of getting caught.

· Reduce the rewards that result from the crime.

If the only criteria used in rating “identity theft insurance” as a safeguard was its

effectiveness at locking down your credit bureau account, than installing this safeguard would score high only in this area, but might score very low against others.

The hypothesis that some identity theft safeguards are more effective than others is dependent upon the criteria that each safeguard is being compared to. Recommended safeguards were shown to be more or less effective compared to one another because they shifted position within List no. 1 or List no. 2 depending upon the type of identity theft being trying to be prevented. Employing a statistical method to determine a safeguard’s effectiveness could be a focus of a further study that compares prevention measures directly to the type of identity theft.

Discussion of Graphical Analysis

Graphs of each list (see Figures 6, 7, 8, and 9) were studied to see if one list had higher rated safeguards graphed first. It was not clear judging from these graphs visually which one could be considered the better list. Graphically, the results of List no. 1 and List no. 2 did not reveal a discernable difference. If a third list had been created and sorted by “weighted means test summated score” (see Appendixes Z and AA), the results would have looked like Figure 15.

Figure 15. Distribution of identity theft safeguards from weighted means test

Median Value = 8.37

Had list no. 1 or list no. 2 achieved the distribution in Figure 15, it would have been strongly considered the definitive hierarchy of effective safeguards. Neither the graphed results of List no. 1 or List no. 2 (see Figures 6 and 7) came close to the Figure 15 distribution, but were distributed evenly. Reordering Figure 15 by category would present a way to target and prevent specific means of identity theft by categories (see Figure 16).

Figure 16. Distribution of identity theft safeguards by category

Median Value = 8.37

Both of the lists presented in Figures 15 and 16 are graphically distributed better than Lists no. 1 and 2 (see Figures 6 and 7) from this research and could be a good starting point for an identity prevention program.

The distribution shown, in Figure 16, prioritizes each safeguard by category and would give the option of tailoring an identity theft prevention program according to an individual’s perception of their level of risk in each category or combination of categories. Sorting the safeguards by weighted means in Figure 15, produced a dramatically different graph that clearly shows the highest rated safeguards first, something that List no. 1 and 2 failed to show and sorting by categories opens up another avenue of research to this topic.

Discussion of Using Descriptive Measures to Compare Averages Above the Median

The descriptive measure of using average values above the median value in the top half of each list was used (see Appendix Y). These averages showed that List no. 2 compared to List no. 1 had a higher average value above the calculated median, 10.63 vs. 10.57, respectively (see Table 6). This result is interpreted to mean that the comparative distribution of List no. 2 to List no. 1 is better, on average. It does not mean that individual safeguards proposed by either list are not effective. Both lists have distributions that require statistical analysis to determine their significance because the distinction is not an obvious one.

Descriptive measures are useful tools designed to break data sets down into intervals. Taking averages of the data above the median in the top half of each list was a good choice that yielded a result consistent with the graphical result. Breaking down the data into intervals and calculating averages was helpful to see if there was a difference between the two lists. Both lists could have been divided into quartiles or deciles too. Dividing the data from List no. 1 and List no. 2 into quartiles or deciles and calculating the average above the median could have been another helpful descriptive measure to use in the treatment of the data.

The averages of the two lists calculated above the median in the top half of the lists were so close, that relying on these averages to determine any significant difference was abandoned. Significance of any difference could only be determined using statistical analysis. The list from Figure 15 has potential to be considered the prioritize list of effective safeguards because of its displayed graph. Using the descriptive measure of averages in the top half of its list compared to either List no. 1 or List no. 2 could show it to score better and remain a candidate for consideration as the prioritized list.

Discussion of the Paired, Two-Sample (two-tailed), t Test

Statistical analysis had to be performed on the data in order to decide if the difference between the two lists was significant since graphically and descriptively the differences were not clear. The paired, two-sample (two-tailed), t test was the best fit for the data set because there was a natural pairing of the data, did not rely on assumed variance, and was accomplished on data sets where the populations were equal (AnalystSoft®, 2007). This t test showed, using a statistical significance factor of p < .05, that there was no statistical significance between the two paired lists proving H0 to be true and H1 to be false

There were other tests considered for the statistical analysis of the data set like the Wilcoxon sign test. Data was even prepared (plus and minus signs) to run this test (see Appendix Y), but the strength of this t test was sufficient to confirm the graphical and descriptive analyses of both lists and further testing was unnecessary. The methodology of this research did not produce a prioritize list of effective safeguards with any statistical certainty.

The list in Figure 15, created by weighted means only, is appealing as a candidate for becoming the prioritize list of effective safeguards. Out of curiosity, running a paired, two-sample (two-tailed) t test, using a statistical significance factor of p < .05, on its distribution compared to either List no. 1 or List no. 2, showed p = 0.1733, the exact same result yielding no significant difference in the distribution of data either. So what happened?

Implementing an identity theft prevention program using this list is preferred to List no. 1 or List no. 2.because we know that the higher rated safeguards are presented first. Statistically, however, the distributions are the same no matter how the lists are arranged. Selecting the safeguards presented by Figure 15 as the prioritized list would mean accepting a Type-I statistical error (prove H0 true and reject it). Statistically, none of the lists presented have any statistical difference or significance.

Discussion Of The Treatment Of Data

Tradeoff weights.

Decision analysis theory encourages a researcher to use “common sense” (Landsberger, 2007) to ensure values make “sense” throughout an analysis. From Figure 4, “Lost or stolen wallet…” occurs at a rate four times that of “From stolen paper mail…” 30% compared to 8% respectively. The tradeoff weight attributed to each means of identity theft was 1.00 and 0.26 respectively. It then makes sense that the tradeoff weight calculated is accurate because one occurs at a rate of nearly four times the other, 30% compared to 8%, 1.00 compared to about 0.26, and/or 100% compared to 26% (see Appendix Z to review the actual calculations of tradeoff weights used). The “other” category (see Figure 4) was not considered because the means of identity theft was not reported within this category and could not be quantified.

Controllable vs. uncontrollable.

The percentages from Figure 4 contained 28% attributed to “business controlled” means of identity theft and the “other” category accounted for 9.7%. One treatment of the data that made good sense was to eliminate the uncontrollable safeguards from the 462 identified safeguards. Each safeguard was subjectively judged against whether or not that safeguard was within the control of an individual. The master spreadsheet was filtered for all uncontrollable safeguards. These uncontrollable safeguards were redacted from the full list (see Appendix X). These safeguards were not used in any further analysis since they were beyond the ability of an individual to control or implement (See Figure 17).

Additional Value Added by This Research

Figure 17. Partial list of safeguards deemed not controllable and not analyzed

Categorizing the 462 identity theft safeguards during this research effort presented other facts from the data. The SCAM acronym is part of the U. S. Department of Justice’s educational campaign to heighten awareness about identity theft prevention. Being “stingy” with your information, “maintaining” accurate records, “asking” to use other identifiers, and “checking” your credit report, are all activities that are expected to reduce identity theft (U. S. Department of Justice, 2006b). During data transformation, each safeguard was filtered against the SCAM category that it was judged a part of. It is interesting to see how many times a safeguard was recorded against a particular SCAM category (see Figure 18). Being “stingy” with your personally identifying information was recommended nearly 8 to 1 over any other identity theft prevention category.

Figure 18. Number of times each SCAM category recommended

Each safeguard was matched against one of the 12 main categories of identity theft prevention identified during this research. The number of times each safeguard recommended addressed each category is shown is Figure 19.

Figure 19. Number of times each of 12 main identity theft categories recommended

When all the identity theft safeguard recommendations are viewed by category, 220 of 436 (over 50%) of them favor the majority of prevention efforts be spent within the categories of a) account and personal information protection, b) trash and mail, and c) computers and information systems. Password protection receives the honorable mention followed by all the others (see Figure 19).

Prioritizing identity theft safeguards in future research should take a categorical approach and identify which safeguards would be the most effective in each category at combating individual types of identity theft. It may not be provable that one prioritized list is better than another, but doing nothing to protect yourself leaves the door wide open to becoming victimized.

Conclusion

This research developed a comprehensive list of 90 unique identity theft prevention safeguards from 462 recommendations of government, law enforcement, and private sector sources. It is alarming that a person still remains vulnerable to identity theft through means outside of their control as in the case where personal information is stolen from company records, stolen laptops, or carelessness by others.

Implementing an identity theft prevention program should use an approach that targets individual types of identity theft. For example, if a person is trying not to have their Social Security number used in an unauthorized way, then any safeguard that prevents unauthorized use should be implemented. This research showed that each safeguard is more or less effective than another safeguard, but only when targeting specific types of identity theft. The research was not able to prove hypothesis (H1), that a comprehensive prioritized list of effective identity theft safeguards could be created.

All 90 Identity theft safeguards tabulated by this research are presented in Appendix BB and make a great starting point for an identity theft prevention program. Many very important identity theft safeguards were recommended only once (see Appendix V) throughout all 21 sources of data such as: “Never write your Social Security number on a check, resume, or other document where it is not needed” (see Appendix BB). There were 350 recommended safeguards out of 436 (80%) that encouraged implementing various means to be “stingy” with personal information and was a common identity theft prevention theme shared by all 21 sources.

Not one source from government, law enforcement, or the private sector recommended any priority to their safeguards. Several reasons for this could be the shear number of safeguards, the complexity in trying to create a one-size-fits-all solution, or that those recommending safeguards do not want to be exposed to potential liability or litigation if, after implementing a recommended safeguard, a person is still victimized

The priority given to an individual safeguard is totally dependant upon the type of identity theft trying to be prevented. A multi-faceted identity theft prevention program utilizing as many safeguards as possible is the best line-of-defense to keep the next identity theft from happening and happening to you because it is not known when or how the next identity theft is going to happen. The most effective safeguard is the one that stops the identity thief. Which of the 90 identity theft recommended safeguards are the most important to implement? The answer is, “all of them.”

References

AARP Bulletin Online (AARP). (2004, February). Your life: 8 Tips to avoid identity theft. Retrieved August 19, 2007, from http://www.aarp.org/bulletin/yourlife/Articles/a2004-01-28-8tips.html

AnalystSoft®. (2007). StatPlus–statistical analysis program. Version 2007. Retrieved November 15, 2007, from http://www.analystsoft.com

Armstrong, L. (2001, November 19). Don't let crooks steal your identity: How to protect yourself--and your credit rating. Business Week, 3758, 134-136.

Block, S. (2005, February 15). Most identity theft is low-tech, and so are steps to thwart it. USA Today, p. 2b.

CBS News. (2001, May 15). Identity theft continues to increase. Retrieved August 19, 2007, from http://www.cbsnews.com/stories/2001/05/15/60II/main291415.shtml Chiff (2007). (How to avoid identity theft 2007)How to avoid identity theft. Retrieved October 11, 2007, from http://www.chiff.com/a/identity_theft_internet.htm

Community Oriented Policing Services (COPS). (2004, June). Identity theft: Problem-oriented guides for police problem-specific guides series No. 25. Retrieved August 13, 2007, from http://www.cops.usdoj.gov//mime/open.pdf?Item=1271

Consumers Measures Committee (CMC). (2007a). About the CMC. Retrieved October 8, 2007, from http://strategis.ic.gc.ca/epic/site/cmc-cmc.nsf/en/h_fe00013e.html

Consumer Measures Committee (CMC). (2007b). Watch your identity: Tips for reducing the risk of identity theft. Retrieved October 8, 2007, from http://cmcweb.ca/epic/site/cmc-cmc.nsf/en/fe00040e.html

Consumer Measures Committee (CMC). (2007c). Working together to prevent identity Theft: A discussion paper. Retrieved October 8, 2007, from http://strategis.ic.gc.ca/ /epic/site/cmc-cmc.nsf/vwapj/DiscussionPaper_IDTheft.rtf/$FILE/DiscussionPaper_IDTheft.rtf

Consumer Measures Committee (CMC). (2007d). Consumer identity theft checklist. Retrieved October 1, 2007, from http://cmcweb.ca/epic/site/cmc-cmc.nsf/en/fe00088e.html

Consumer Measures Committee (CMC). (2007e). Identity theft: Recognize it, report it, stop it. Retrieved on October 11, 2007, from http://cmcweb.ca/epic/site/cmc-cmc.nsf/vwapj/Consumer%20Kit.pdf/$FILE/Consumer%20Kit.pdf

Consumer Response Center (CRC). (2006a). Deter∙Detect∙Defend AvoID theft. [Brochure]. Washington, DC: Federal Trade Commission (FTC).

Consumer Response Center (CRC). (2006b). Talking about identity theft: A how-to guide. Washington, DC: Federal Trade Commission (FTC).

Consumer Response Center (CRC). (2006c). Take Charge: Fighting back against identity theft. Washington, DC: Federal Trade Commission (FTC).

Direct Marketing Association (DMA). (2006). Consumer alert: How to protect your identity from being stolen. Retrieved August 13, 2007, from: http://www.dmaconsumers.org/ consumers/idstolen.html

Exec. Order No. 13402, Federal Register, Volume 71, Number 93, p. 27945-27947 (2006). Retrieved August 15, 2007, from http://a257.g.akamaitech.net/7/257/2422/01jan20061800/edocket.access.gpo.gov/2006/06-4552.htm

Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 (2004).

Federal Citizen Information Center (FCIC) (2006). Alert: Protect your personal information. Retrieved July 11, 2007, from http://www.pueblo.gsa.gov/cfocus/cfpersonalinfo06/focus.htm

Federal Trade Commission (FTC). (2004, January 22). National and state trends in fraud & identity theft; January – December 2003. Retrieved April 12, 2007, from http://www.ftc.gov/bcp/edu/microsites/idtheft/downloads/clearinghouse_2003.pdf

Federal Trade Commission (FTC). (2005, February 1). National and state trends in fraud & identity theft; January – December 2004. Retrieved August 5, 2006, from http://www.ftc.gov/bcp/edu/microsites/idtheft/downloads/clearinghouse_2004.pdf

Federal Trade Commission (FTC). (2006a). Deter: Minimize your risk. Retrieved August 19, 2007, from http://www.ftc.gov/bcp/edu/microsites/idtheft/consumers/deter.html

Federal Trade Commission (FTC). (2006b, January 25). Identity theft victim complaint data: Figures and trends; January 1 – December 31, 2005. Retrieved August 12, 2007, from http://www.ftc.gov/bcp/edu/microsites/idtheft/downloads/clearinghouse_2005.pdf

Federal Trade Commission (FTC). (2006c). Take charge: Fighting back against identity theft. Retrieved August 19, 2007, from http://www.ftc.gov/bcp/edu/pubs/consumer/idtheft/idt04.shtm

Federal Trade Commission (FTC). (2006d). Welcome to the FTC’s identity theft site. Retrieved August 19, 2007, from http://www.ftc.gov/bcp/edu/microsites/idtheft/

Federal Trade Commission (FTC). (2007, February 25). Identity theft victim complaint data: Figures and trends; January 1 – December 31, 2006. Retrieved September 23, 2007, from http://www.ftc.gov/bcp/edu/microsites/idtheft/downloads/clearinghouse_2006.pdf

Gertler, E. (2004). PryingEyes: Protect your privacy from people who sell to you, snoop on you, and steal from you. Random House. New York.

Gertler, E. & Silver, M. (2004, December 6). Somebody's snatching you. U.S. News & World Report, 137 (20), 86.

Gibilisco, S. (2004). Statistics demystified. New York: McGraw-Hill

Golub, A. L. (1997). Decision analysis: An integrated approach. Hoboken, NJ: John Wiley & Sons.

Hammond, R. J., Jr. (2003). Identity theft: How to protect your most valuable asset. Franklin Lakes, NJ: Career Press.

Identity Theft 911. (2006a). Your life. Your identity: America’s source for proactive identity theft education. Retrieved August 19, 2006, from http://www.identitytheft911.org/home.htm

Identity Theft 911. (2006b). Avoiding identity theft: Steps you can take to reduce your risk. Retrieved September 23, 2007, from http://www.identitytheft911.org/protection/protection.htm

Identity Theft and Assumption Deterrence Act, 18 U.S.C. § 1028(a) (1998).International Software Systems Solutions (iS3, 2007). Learning center: What is phishing? Retrieved October 27, 2007, from http://www.is3.com/WhatIsPhishing.do

Khalfani, L. (2004). Zero debt. South Orange, NJ: Advantage World Press.

Javelin Strategy & Research. (2006, January). 2006 Identity fraud survey report (Consumer Version). Pleasanton, CA: Retrieved August 8, 2006, from http://www.javelinstrategy.com/research/2

Javelin Strategy & Research. (2007, February). 2007 Identity fraud survey report–Consumer version: How consumers can protect themselves. Pleasanton, CA: Retrieved September 23, 2006, from http://www.javelinstrategy.com/research/2

Kersnar, S. (2006, June 19). Will 2006 be a record year for identity theft? National Mortgage News, 30(37). Retrieved August 15, 2006, from http:/​/​www.edentify.us/​kalani/​modules/​cindykate/​uploads/​bed195d0e6381ca35dcd7eba896afd31.pdf

Landsberger, J. (1997). Study guides and strategies: Adaptive decision making. Retrieved November 12, 2007, from http://www.studygs.net/problem/problem_adaptive_decisions.htm

Leppol, E. (2005). Personal banking: Tips to avoid identity theft. Retrieved August 19, 2007, from http://www.nationalbusiness.org/nbaweb/Newsletter2005/2050.htm

LifeLock™. (2007a). LifeLock: Guarantee your good name. Retrieved September 23, 2007, from http://www.lifelock.com/

LifeLock™. (2007b). Lifelock: Our $1 million service guarantee. Retrieved October 18, 2007, from http://www.lifelock.com/our-guarantee

LifeLock™. (2007c). Lifelock for people. Retrieved October 25, 2007, from http://www.lifelock.com/lifelock-for-people

Milne, G. (2003). How well do consumers protect themselves from identity theft? The Journal of Consumer Affairs, 37(2), 388-402.

National Consumers League (NCL). (2006). Invasion of the ID snatchers: Get secure! Retrieved August 19, 2007, from http://nclnet.org/privacy/idtheft/getsecure.htm

National Crime Prevention (NCP). (2007). ID Theft: A kit to prevent and respond to identity theft. Retrieved August 15, 2007, from http://www.ag.gov.au/agd/WWW/

rwpattach.nsf/VAP/(C08E61826167B8CED18FCFA5E6BDDCDE)~ID+Theft+Kit+Complete+new.pdf/$file/ID+Theft+Kit+Complete+new.pdf

National Institute of Justice (NIJ). (July 2007). Identity theft—A research review. Retrieved October 21, 2007, from http://www.ojp.usdoj.gov/nij/publications/id-theft/welcome.htm

Newman, R. & McNally M., (2005, January 27-28). Identity theft literature review. Retrieved October 6, 2007, from http://www.ncjrs.gov/pdffiles1/nij/grants/210459.pdf

Pope, E. (2006). Identity theft: Protecting yourself from an unprotected world. Chicago: Moody Publishers.

Privacy & American Business. (2003, June/July). Special double issue on identity theft. Retrieved October 17, 2007, from http://www.bbonline.org/ IDtheft/PABIDTheft.pdf

Remarks by the President After Meeting With Victims of Identity Theft. (2006, May 10). Retrieved September 23, 2007, from http://www.ustreas.gov/offices/domestic-finance/financial-institution/cip/pdf/remarks_by_the_president_after_meeting_with_victims_of_identity_theft.pdf

Silver Lake. (Series Ed.), & Loberg, K., Son, S., Thorpe, M., & Walsh, J. (Vol. Eds.). (2004). Identity theft: How to protect your name, your credit and your vital information…and what to do when someone hijacks any of these (1st ed., No. 12). Los Angeles: Silver Lake.

Synovate. (2003, September). Federal Trade Commission–Identity theft survey report. Retrieved August 5, 2007, from http://www.ftc.gov/os/2003/09/synovatereport.pdf

Trochim, W. (2006a, October 20). Likert Scaling. Retrieved October 29, 2007 from, http://www.socialresearchmethods.net/kb/scallik.php

Trochim, W. (2006b, October 20). Research methods knowledge base: Analysis. Retrieved October 29, 2007 from, http://www.socialresearchmethods.net/kb/analysis.php

Trochim, W. (2006c, October 20). Research methods knowledge base: Data preparation. Retrieved October 29, 2007 from, http://www.socialresearchmethods.net/kb/statprep.php

U.S. Department of Justice (USDOJ). (2005, July). Preventing identity theft: A guide for consumers. Washington, DC: National Crime Prevention Council (NCPC).

U.S. Department of Justice (USDOJ). (2006a). Bureau of justice statistics bulletin: Identity theft, 2004. Retrieved August 12, 2007, from http://www.ojp.usdoj.gov/bjs/pub/pdf/it04.pdf

U.S. Department of Justice (USDOJ). (2006b). Identity theft and identity fraud. Retrieved August 15, 2007, from http://www.usdoj.gov/criminal/fraud/websites/idtheft.html

U.S. Postal Service (USPS). Identity theft is America’s fastest–growing crime. (2006). Retrieved August 19, 2006, from http://www.usps.com/postalinspectors/idthft_ncpw.htm

U.S. Secret Service (SS). Mission Statement. (2006). Retrieved August 19, 2006, from http://www.secretservice.gov/mission.shtml

Zander Insurance Group. (2007a). Identity theft protection. Retrieved September 24, 2007, from http://www.zanderins.com/idtheft/idtheft.aspx

Zander Insurance Group. (2007b). Identity theft insurance: How do we compare? Retrieved October 25, 2007, from http://www.zanderins.com/idtheft/compare.aspx

Appendix A Identity Theft Safeguards Proposed from [1 of 5] Government Sources

(FTC, 2006a)

1. Don't carry your Social Security card in your wallet

2. Don't write your Social Security number on a check

3. Only give your Social Security number when absolutely necessary; ask to use other identifiers

4. If your state uses your Social Security number as your driver's license number, ask to substitute another number

5. If your health insurer uses your Social Security number as your policy number, ask to substitute another number

6. Always shred your charge receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards that you're discarding, and credit offers you get in the mail

7. Opt out of receiving prescreened offers of credit in the mail

8. Deposit your outgoing mail containing personally identifying information in post office collection boxes or at your local post office

9. Promptly remove mail from your mailbox

10. If you're planning to be away from home and can't pick up your mail, contact the U.S. Postal Service at 1-800-275-8777 or online at www.usps.gov, to request a vacation hold

11. Be on guard when using the Internet

12. Select intricate passwords

13. Verify sources before sharing information

14. Safeguard your purse and wallet

15. Store information in secure locations

16. Use a credit freeze

17. Ask about identity theft insurance

Appendix B Identity Theft Safeguards Proposed from [2 of 5] Government Sources

(FCIC, 2006)

1. Check your reports regularly

2. Put a security freeze on your credit report

3. Opt out of information sharing

4. Use unique or unpredictable passwords

5. Avoid using easily available information such as your mother’s maiden name, your birth date, the last four digits of your Social Security Number (SSN) or your phone number, or a series of consecutive numbers

6. Secure your personal information at home

7. Treat your mail and trash carefully

8. Deposit your outgoing mail in a post office collection box rather than in an unsecured mailbox

9. Promptly remove mail from your mailbox

10. If you won’t be home to pick up your mail for an extended period of time request a vacation hold

11. When ordering new checks, pick them up from the bank instead of having them mailed to your home mailbox

12. Tear or shred your charge receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards that you're discarding, and credit offers you get in the mail

13. When you go out take only credit cards you'll need

14. Leave SS# card at home in a safe place

15. Keep your purse or wallet in a safe place at work

16. Give your Social Security number only when absolutely necessary

17. NEVER give personal information unless you initiated the contact with the company

Appendix C Identity Theft Safeguards Proposed from [3 of 5] Government Sources

(FCIC, 2006)

1. Close accounts no longer intended to be used

2. Place passwords on new accounts

3. Place a "fraud alert" on your credit bureau report

4. Get your copy of your credit report and review for errors every year

5. Have incorrect information removed from your credit report

6. Reconcile each bank and credit card statement monthly

7. Stay alert for delayed mail

8. Take action If you receive a credit card that you didn't apply for

9. Take action if you don't get credit that you should have received

10. Take action if you start to get calls from collectors or merchants on accounts that are not yours

11. Place passwords on credit, bank, and phone accounts

12. Secure your personal information at home

13. Pay attention to privacy policies at work and in business dealings

14. Don’t give out personal information unless you made the contact

15. Make sure you are using correct websites

16. Deposit outgoing mail at the post office

17. Promptly remove mail from your mailbox

18. Request "vacation holds" from the post office when you are away

19. Tear or shred your charge receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards that you're discarding, and credit offers you get in the mail

20. Opt out of receiving prescreened offers of credit in the mail

21. Leave SS# card at home in a safe place

22. Use other identifiers as much as possible

23. Carry only the identification and credit cards you actually need

24. Be cautious responding to offers

25. Keep your purse or wallet in a safe place at work

26. Pick up [replacement] checks from the bank

27. Update virus protection software

28. Set operating system to automatically runs scans

29. Do not open files sent to you from strangers

30. Be careful using file-sharing programs

31. Use a firewall program

32. Use secure browsers and look for the "lock" icon

33. Avoid storing financial information on your laptop

34. Use strong passwords

35. Don't use an automatic login feature that saves your user name and password

36. Use a "wipe" utility program when getting rid of a computer

Appendix D Identity Theft Safeguards Proposed from [4 of 5] Government Sources

(CRC, 2006a)

1. Shred financial documents and paperwork with personal information before you discard them

2. Don't carry your Social Security card in your wallet

3. Don't write your Social Security number on a check

4. Give your Social Security number only when absolutely necessary

5. Ask to use an identifier other than your Social Security number

6. Don't give out personal information on the phone

7. Don't give out personal information through the mail

8. Don't give out personal information over the Internet unless you know who you are dealing with

9. Never click on links sent in unsolicited emails

10. Type in URLs that you know are legitimate

11. Use firewalls

12. Use anti-spyware

13. Use anti-virus software

14. Keep all protective software up-to-date

15. Don't use an obvious password like your birth date, mother's maiden name, or the last four digits of your Social Security number

16. Keep your personal information in a secure place at home

17. Be alert for bills that do not arrive as expected

18. Be alert if unexpected credit cards or account statements arrive

19. Be alert if you get unexpected credit denials for no reason

20. Be alert if you get calls or letters about purchases you did not make

21. Get your copy of your credit report and review for errors every year

22. Reconcile each bank and credit card statement monthly

23. Place a "fraud alert" on your credit bureau report

Appendix E Identity Theft Safeguards Proposed from [5 of 5] Government Sources

(NCP, 2007)

1. Order a copy of your credit report regularly

2. Place passwords on all your important accounts

3. Avoid using easily available information such as your mother’s maiden name, your birth date, the last four digits of your Social Security Number (SSN) or your phone number, or a series of consecutive numbers

4. Don't use the same password on different accounts

5. Be careful when writing your passwords down or storing them on your computer

6. Secure your personal information at home

7. Lock personal information in a locked file or safe

8. Collect new checks or credit cards in person at the bank

9. Don't leave documents such as registration papers, driver's licenses, utility bills, or traffic fines, in the car glove box.

10. Don't lend personal documents to others

11. Don't carry personal information unless you have to

12. Never carry your PIN in your wallet with the ATM card

13. When you go out take only credit cards you'll need

14. Don't carry documents like your passport or birth certificate unless you have to

15. Avoid using ATMs that appear to be tampered with

16. Destroy personal information before disposal

17. Use a home shredder

18. Avoid giving out personal information over the phone or internet unless you know who you are speaking to

19. Only provide the minimum amount of information

20. Always ask why your information is needed and how it is going to be used

21. Be suspicious when things don't seem right

22. Unsolicited offers that seem too good to be true or that require you to give out bank account or other personal information are likely to be scams.

23. Secure your mail in a secure lockable letterbox

24. Only post mail at secure, official post boxes

25. Make sure your letterbox is large enough to accept and hold mail in the quantity an size you normally get

26. Quickly remove mail from your mailbox after it is delivered

27. If you won’t be home to pick up your mail for an extended period of time request a vacation hold

28. If your volume of mail changes, inquire at the post office

29. Check you billing and account records carefully checking all transactions on your banking and credit card accounts.

30. Limit the amount of credit you have in accounts

31. Use a separate account for purchases made by telephone or on the internet with as low a credit limit as possible

32. Make sure that you fill out checks carefully so that they cannot be altered easily.

33. Put a line through unused spaces on checks

34. Keep a list of all your accounts and credit cards in a safe place

35. Remove your name from mailing lists

36. Use passwords to secure personal information stored on a computer

37. Avoid obvious passwords on computers

38. Use complex passwords

39. Update your passwords regularly

40. DO NOT use automatic log in features

41. Always remember to log off

42. Avoid saving important data on your computer - save to disk and keep the disk secure

43. Consider buying a program that will ask you to change your password regularly and will shut down your computer after a set time

44. Use the latest protection software

45. Regularly update your protection software

46. Use virus protection programs and encryption browsers programs

47. Use a personal firewall to secure your PC especially using high speed internet

48. Only conduct transactions with secure websites

49. Wipe your hard drive before you dispose of, sell or trade in your old PC or laptop

50. Don't use public computers to access your private information

Appendix F Identity Theft Safeguards Proposed from [1 of 3] Law Enforcement

(U.S. Department of Justice, 2005)

1. Don't put outgoing mail, especially bill payments in personal curbside mailboxes

2. Use a locked mailbox with a slot at home

3. Don't put outgoing mail in an unguarded "out box" at work

4. Don't write your account number on the outside of envelopes containing bill payments

5. When you're out of town have the post office hold your mail for you or have someone you trust pick it up every day

6. Shroud passwords and PINs while using ATMs

7. Pay bills online using a secure site if available

8. Don't give out your credit card number on the Internet unless it is encrypted on a secure site

9. Examine your credit reports yearly

10. When giving out personal information over the phone or cell phone make sure no one is listening or wait until you're in a more secure location

11. Shred all financial statements, billing statements, and pre-approved credit card offers

12. Use a cross cut shredder

13. Minimize the number of identification and credit cards you carry with you

14. Take only what's absolutely necessary with you

15. Take you name off direct mail lists by writing to DMA

16. Call the credit reporting industry at 888-567-8688 to stop credit card and insurance solicitations from coming to your home

17. Use traveler's checks instead of personal bank checks

18. Examine all of your bank and credit card statements each month

19. Monitor your mail to ensure your bills arrive on time and are not delayed

20. Use direct deposit instead of paper paychecks

21. Pick up new checks at the bank instead of being mailed to you

22. Be alert if you get a call from someone purporting to be from your bank who asks for personal data to update your "records."

23. Commit all passwords to memory and never write them down

24. Don't give out your financial or personal information over the phone or internet unless you have initiated the contact or know for certain with whom you are dealing

25. Don't exchange personal information for "prizes."

26. Give out your Social Security number only when absolutely necessary

27. In you're hospitalized, tell your doctor or nurse to safeguard your chart

28. Remove your hard drive before you sell or discard your computer

29. Educate yourself on the various scams that are out there

30. Don't carry your Social Security card

31. Keep your Social Security card in a safe place

32. Don't carry automotive insurance policies in your car

33. Keep insurance policies in a safe place

34. Don't keep you car registration in your car - carry it in your wallet

35. Burglar-proof your home: Use locked filing cabinets or safes

Appendix G Identity Theft Safeguards Proposed from [2 of 3] Law Enforcement

(Newman & McNalley, 2005)

1. Tamperproof credit cards

2. Install Firewalls

3. Tamperproof ID documents

4. Shred utility bills

5. Lock mail boxes

6. Card/password access to databases

7. ID for mail forwarding

8. Disallow remote access to databases

9. Limit number of persons with access to databases

10. Require several forms of ID to obtain new ID or replacements

11. Control sale of ID making equipment (card readers, stripers, & printers)

12. Use tracking ID tags to track location and use and who uses machine

13. Close Scrutiny, background checks of employees with access to ID database

14. ATMs in well lit places

15. Disallow employees to take home work

16. Support whistleblowers

17. Photo, thumb print on ID documents, credit cards

18. Require additional ID for on-line purchases

19. Train clerks, police, officials in document authentication procedures

20. Reward vigilance of supervisors of employee/customer records

21. Retain backup files of computer usage

22. Track keystrokes of computer users

23. Monitor all utilization of ID databases

24. Cameras on ATMs, at check-out counters, shipping and mailing services, and ID granting agencies

25. Background checks of employees

26. No Social Security numbers on health, school cards

27. No credit card numbers on receipts

28. Place ATMs so keystrokes cannot be observed or recorded

29. Shed utility bills

30. Pre-paid cards for pay phones

31. Smart cards that contain limited personal ID information

32. Do not leave wallets in cars

33. Guaranteed ID authentication services (e.g. Microsoft Passport)

34. Vehicle ID licensing and parts marking

35. Monitor pawn shops

36. Monitor retail retunes departments

37. Monitor deliveries to vacant houses

38. Monitor classified ads

39. Swift notification of stolen credit card

40. Maintain positive management-employee relations

41. Avoid public disclosure of security holes and patches in software

42. Do not boast of security features in software

43. Responsible computer use policy

44. Prominent display of signage "Protect Privacy"

45. Prominent display of signage "Protect our customer's Privacy"

46. "Hacking hurts people"

47. Provide shredders for employees

Appendix H Identity Theft Safeguards Proposed from [3 of 3] Law Enforcement

(U.S. Department of Justice, 2006b)

1. Start by adopting a "need to know" approach to your personal data

2. Ask for a written application from someone you don't know who is asking for personal information over the phone

3. Review all applications that you put personal information on - verify using the BBB

4. Put a hold on mail while you are away or ask a trusted person to hold your mail

5. If you have to give out personal information over a phone, use a telephone booth where you can close the door and speak softly at all times

6. Make sure you are receiving all statements from month to month

7. If you stop receiving an expected statement call the financial institution immediately

8. Alert any institution that reports that your statements are going to a different address

9. Ask periodically for a copy of your credit report

10. Maintain careful records of your financial accounts for at least a year

Appendix I Identity Theft Safeguards Proposed from [1 of 13] Private Sector sources

(NCL, 2006)

1. Don’t give your credit or debit card numbers [out] unless you’re making a purchase with that account

2. Don't leave ATM, Credit, or Debit Cards lying around

3. Close accounts you no longer use

4. Memorize PIN numbers

5. Don't write PIN numbers down

6. Carry cards in a separate holder from your wallet

7. Don't lend your ATM, Credit, or Debit Cards to anyone

8. Don’t leave bills, statements, and other personal records around in plain site.

9. Keep important documents in a locked file cabinet.

10. Shred information you don’t need to keep.

11. Block keypads when using ATM, Credit, Debit or Calling Cards

12. Speak softly when giving out personal information in public

13. Check your credit reports once a year

14. Remove incoming mail from your mailbox promptly

15. Send bill payments from the post office or public mailbox, not from home

16. If you are going to be away, ask the post office to hold your mail

17. Look for clues about security when providing account numbers online

18. Don’t provide sensitive information by email, as it is generally not secure

19. See what the Web site says about how your information is safeguarded

20. Seek to use alternate numbers/passwords to secure accounts

21. Don’t give your passwords to anyone

22. Do Memorize passwords

23. Don't write passwords down where others can find them

24. Never verify a password with anyone you didn't contact first

25. When you do business with companies, look for information about their privacy policies. Tell them if you don’t want your personal information shared with other companies

26. Don’t provide information on order forms, warranty forms, and registration forms that isn’t necessary to complete the transaction

27. Be suspicious of anyone who calls or sends you an email requesting personal information to “verify” who you are so they can give you a prize or lottery winnings

28. If you don’t use credit offers that you receive, dispose of them by shredding

29. Opt out of pre-approved credit offers

30. Don’t give out your Social Security number unless it is needed to apply for credit, open a bank account, go to work for someone, or for some other legitimate purpose

31. Never have your Social Security number printed or write it yourself on checks

32. Ask for an alternate number to identify you on your driver’s license, insurance card, and other materials

33. Don’t tempt crooks by leaving your wallet or purse in plain site at work

34. Don’t leave your wallet loose in your back pocket or your purse hanging from a chair at a restaurant or another public place

35. Use purses that close securely

36. Make sure your employer locks and limits access to personnel records

37. Ensure your employer has methods in place to properly secure and prevent strangers from wandering around the workplace

Appendix J Identity Theft Safeguards Proposed from [2 of 13] Private Sector sources

(DMA, 2006)

1. Place unidentifiable passwords on all of your accounts

2. Avoid using easily available information such as your mother’s maiden name, your birth date, the last four digits of your Social Security Number (SSN) or your phone number, or a series of consecutive numbers

3. Lock personal information in a filing cabinet

4. Deposit outgoing mail in post office collection boxes or at your local post office

5. Promptly remove mail from your mailbox

6. If you're planning to be away from home and can't pick up your mail, call the U.S. Postal Service at 1-800-275-8777 to request a hold

7. Tear or shred your charge receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards that you're discarding, and credit offers you get in the mail

8. When ordering new checks, pick them up from the bank instead of having them mailed to your home mailbox

9. Don’t give out personal information unless you’ve initiated contact or are sure you know who you're dealing with

10. Be cautious when responding to promotional offers. Identity thieves may create phony promotional offers to get you to give them your personal information

11. Identity thieves are clever, and have posed as representatives of banks, Internet service providers (ISPs), and even government agencies to get people to reveal their SSN, mother's maiden name, account numbers, and other personal information. Before you share any such information, confirm that you are dealing with a legitimate organization. Check an organization's Web site by typing its URL in the address line. Or call customer service using the number listed on your account statement or in the telephone book

12. Don't carry your SSN card; leave it in a secure place

13. Give your SSN only when absolutely necessary, and ask to use other types of identifiers. If your state uses your SSN as your driver's license number, ask to substitute another number. Do the same if your health insurance company uses your SSN as your policy number

14. Carry only the identification information and the credit and debit cards that you'll actually need when you go out

15. Keep your purse or wallet in a safe place at work; do the same with copies of administrative forms that have your sensitive personal information

16. Update virus protection software and patches for your operating system and other software programs regularly

17. Do not open files sent to you by strangers, or click on hyperlinks or download programs from people you don't know

18. Be careful about using file-sharing programs

19. Use a firewall program to stop uninvited access to your computer

20. Use a secure browser

21. Look for the "Lock" icon when using web pages to send personal information

22. Try not to store financial information on your laptop unless absolutely necessary

23. Use a strong complex password

24. Before you dispose of a computer, delete all the personal information it had stored using a "wipe" program

25. Look for Web site privacy policies

26. Ask about information security procedures in your workplace or at businesses, doctor’s offices or other institutions that collect your personal identifying information

27. Find out who has access to your personal information, and verify that it is handled securely

28. Ask about disposal procedures for your records

29. Find out if your information will be shared with anyone else. If so, ask how your information can be kept confidential

30. One of the most important ways to protect yourself against Identity Theft is to check your credit report status often

Appendix K Identity Theft Safeguards Proposed from [3 of 13] the Private Sector sources

(Silver Lake, 2006)

1. Never Leave your purse or wallet unattended in public or in open view in your car

2. Keep checks in a secure place

3. Destroy checks when you close a checking account

4. Never give credit card, bank or Social Security information over the phone

5. Protect your Social Security number

6. Safeguard your credit, debit and ATM card receipts and shred them before disposing of them

7. Check your utility and subscription bills to make sure the charges are yours

8. Memorize your passwords and PIN numbers

9. Stop credit and insurance offers

Appendix L Identity Theft Safeguards Proposed from [4 of 13] Private Sector sources

(Pope, 2006)

1. Have a good shredder available to use at your home

2. Have a good shredder available to use at your work

3. Shred all your mail

4. Never recycle your financial mail

5. Use caution when around those with financial problem

6. Use a locking file cabinet at your home

7. Use a locking file cabinet at your work

8. Install antivirus software on your computer

9. Install firewall software on your computer

10. Update your antivirus and firewall software daily software daily

11. Regularly download patches for your computer when available

12. Use two computers if financially possible

13. Don't keep your computer "online" twenty-four hours a day

14. Use a wipe-clean software when you dispose of a computer or when you delete files

15. Don't download files from stingers or unsolicited e-mails

16. Don't download free software

17. Create strong passwords used for log-in

18. Don't use the automatic log-in feature when on the Internet

19. Always "log out" of Web sites

20. Use a key chain fob if available Delete temporary Internet files on a regular basis

21. Delete temporary internet files on a regular basis

22. Try to avoid using wireless connection when viewing financial data online

23. Never open e-mail file attachments sent to you by strangers

24. Never click on links in e-mails unless you know the person providing the link and know that it does not relate to financial data

25. Never send personal data such as credit card numbers in a regular e-mail

26. Never send any confidential information that you would not want someone else to read in a regular e-mail

27. Be suspicious of official-looking e-mail from banks or credit card companies

28. Check Web site address to make sure it's the official and not a bogus Web address

29. Know the signs of a secure Web site (icon lock and https)

30. Do not respond to pop-up ads by clicking on "yes"

31. Do not respond to "warning" that pop up and ask if you want your computer scanned for viruses

Appendix L (Continued) Identity Theft Safeguards Proposed from [4 of 13] Private Sector sources

(Pope, 2006)

32. Do not click on unsubscribe links unless you know the company is valid

33. Talk with your kids about cautions when using the computer online

34. Do not print your Social Security number on checks

35. Consider using an initial for your first name on printed checks

36. Consider using a P.O. box for your address on printed checks

37. Don’t write your credit card number on the memo line when paying your bill

38. Consider using a debit card and stop writing checks

39. Change your driver’s license number if it is the same as your Social Security number

40. Never carry your Social Security card in your wallet

41. Store your Social Security card in a safe place

42. Do not print your Social Security number on a resume

43. Ask why your Social Security number is needed on applications

44. Be sure to mail from a secure site-not an open mailbox at work

45. Consider installing a secure mailbox at your home

46. Consider asking your employer to install locked mailboxes at work

47. When traveling, place a temporary "hold" on your mail

48. Inform trusted neighbors when you are traveling to remove any packages delivered to your home

49. Clean your wallet of unnecessary cards before traveling

50. When traveling consider using a preloaded cash card

51. Do not leave personal data or papers on a desk or bed in hotel rooms

52. Keep your hotel key card when you check out

53. Never provide any personal data to anyone calling you on the phone

54. Never provide any personal data to anyone requesting it in a e-mail

55. When in public, cover the keypad with your hand when you type in PIN or other personal data

56. Remember, the government does not endorse any companies

57. Speak softly when providing personal data in a public place

58. Do not leave your purse in an unsecured location at work

59. Reconcile your bank statement every month

60. Review your credit card statement every month

61. Limit the number of credit cards you own and carry to two

62. Don't sign the back of your credit card; instead write "Photo ID Required"

63. on the signature line

64. Maintain low credit limits on your cards

65. Use one credit card for online purchases

66. Keep credit card bills and receipts in a secure location once bill is paid

67. Call credit card companies to opt out of pre approved credit card offers

68. Call your credit card company to stop convenient checks being sent to you

69. Order a free annual credit report once every four months, one from each of the three credit reporting agencies

70. Only us www.annualcreditreport.com to order your free credit report - no other site!

71. If you purchase identity theft insurance, be sure you read the fine print

72. Request from your financial institution a brochure outlining your level of risk for various types of financial fraud

73. Stay on the alert-continually

74. Consider a credit report account freeze

Appendix M Identity Theft Safeguards Proposed from [5 of 13] Private Sector sources

(Leppol, 2006)

1. Know who you are speaking with before divulging any [personally identifying information]

2. Don't make a habit of sharing your Social Security Number

3. Opt for other identifying number rather than your Social Security Number

4. Don't put your Social Security Number on your checks

5. Scrutinize your accounts and bills

6. Monitor your credit report

7. Never carry your Social Security Card

8. Memorize your Social Security Number

9. Carry only the identification information and the credit and debit cards that you'll actually need when you go out

10. Shred personal documents that you no longer need

11. Remove name from marketing lists

Appendix N Identity Theft Safeguards Proposed from [6 of 13] Private Sector sources

(AARP, 2004)

1. Never give your Social Security number out unless you initiated the contact

2. Shred bank and credit card statements, canceled checks, pre-approved credit card offers, bills with account information and the like

3. When you pay bills, don't put them in your mailbox with the flag up

4. Use a locked mailbox or the post office

5. Check your credit reports

6. Cancel open account you don't use

7. Scrutinize your accounts and bills

8. Don't have blank checks mailed to you - pick them up at the bank

9. Shroud passwords and PINs while using ATMs

10. Use a computer firewall

11. Memorize PINs and Passwords

Appendix O Identity Theft Safeguards Proposed from [7 of 13] Private Sector sources

(Armstrong, 2001)

1. Use a shredder

2. Install a lockable mailbox

3. Take outgoing mail to the post office

4. Request a credit report from each of the three credit reporting agencies

5. Sign up for credit monitoring service

6. Remove your name from junk-mail and telemarketing lists

Appendix P Identity Theft Safeguards Proposed from [8 of 13] Private Sector sources

(Gertler & Silver, 2004)

1. Never Leave your purse or wallet unattended in public or in open view in your car

2. Limit the ID information and number of credit, debit, or ATM cards you carry

3. Check your credit report annually

4. Shred or destroy unsolicited mail

5. Shred credit card receipts and other sensitive information

6. Protect passwords and personal identification numbers (PINs)

7. Be cautious about disclosing personal information

8. Review bank and credit card statements regularly by reconciling regularly

Appendix Q Identity Theft Safeguards Proposed from [9 of 13] Private Sector sources

(Block, 2005)

1. Discourage your bank from using the last four digits of your Social Security number

2. Avoid businesses that don't have adequate safeguards for protecting your information

3. Lock up personal financial information, particularly if you have roommates, employ outside help or are having work done in your home

4. Give out your Social Security number only when it is absolutely necessary

5. Monitor your credit report

6. Monitor your mail to ensure your bills arrive on time and are not delayed

7. Scrutinize your credit card bills and bank balances for signs of unauthorized purchases or withdrawals

Appendix R Identity Theft Safeguards Proposed from [10 of 13] Private Sector sources

(Hammond, 2003)

1. Remove your name from pre-approved credit offers

2. Shred mail and trash that contains any personal information

3. Never carry your Social Security card in your wallet

4. Use identifying numbers other than your Social Security number on your drivers license and any other account that uses your Social Security number

5. Use a locked mailbox or the post office

6. Use a locked mailbox at work

7. Never carry your military ID in your wallet

8. Never give out your Social Security number unless it's absolutely necessary

9. Know who you are speaking with before divulging any [personally identifying information]

10. Never have your Social Security number printed or write it yourself on checks

11. Remove your information from "who's who" guides

12. Order a free annual credit report once every four months, one from each of the three credit reporting agencies

13. Secure your trash

Appendix S Identity Theft Safeguards Proposed from [11 of 13] Private Sector sources

(Chiff, 2007)

1. Order a copy of your credit report from each of the three major credit reporting agencies every year. Make sure it is accurate and includes only those activities you've authorized.

2. Place passwords on your credit card, bank, and phone accounts

3. Avoid using easily available information like your mother’s maiden name, your birth date, the last four digits of your Social Security number or your phone number, or a series of consecutive numbers.

4. Use a password instead of your mother's maiden name

5. Secure personal information in your home

6. Ask about information security procedures in your workplace or at businesses, doctor’s offices or other institutions that collect your personal identifying information

7. Never, ever give out personal information on the phone, through the mail or over the Internet unless you’ve initiated the contact or are sure you know who you’re dealing with.

8. Deposit outgoing mail in post office mailboxes or at your local post office, rather than in an unsecured mailbox

9. If you’re planning to be away from home and can’t pick up your mail, call the U.S. Postal Service at 1-800-275-8777 to request a vacation hold

10. Tear or shred your charge receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards that you’re discarding, and credit offers you get in the mail

11. Before revealing any personally identifying information (for example, on an application), find out how it will be used and secured, and whether it will be shared with others

12. Give your Social Security number only when absolutely necessary

13. Ask to use other types of identifiers when possible

14. If your state uses your Social Security number as your driver’s license number, ask to substitute another number

15. Carry only the identification information and the number of credit and debit cards that you’ll actually need

16. Follow up with creditors if your bills don’t arrive on time

17. Be wary of promotional scams - Use www.snopes.com

18. Keep your purse or wallet in a safe place at work

Appendix T Identity Theft Safeguards Proposed from [12 of 13] Private Sector sources

(LifeLock™, 2007)

1. Put a security freeze/fraud alert on your credit report

2. Renew the security freeze/fraud alert on your credit report every 90 days

3. "Opt out" of receiving prescreened offers of credit in the mail

4. Order your free credit report from each of the three bureaus

Appendix U Identity Theft Safeguards Proposed from [13 of 13] Private Sector sources

(Zander, 2007)

1. Take a risk assessment test to determine your identity theft risk

2. Continue your education about identity theft through newsletter

3. Put a security freeze/fraud alert on your credit report

4. Use credit monitoring

Appendix V Identity Theft Safeguard Priority List No. 1 – Sorted By Number of Times Recommended

Safeguard Recommendation

Number of Times Recommended

Safeguard Prevention Category

1. Treat mail and trash carefully: ALWAYS shred/destroy documents with personal information on them before you discard them (i.e., credit/debit/ATM card receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards, any financial mail, and credit offers you get in the mail, etc.) at home and work using a cross-cut shredder; never recycle personally identifying information

27

Trash and Mail

2. Carry only the identification, personally identifying information, and credit cards you actually need; don't carry documents like your Social Security card, passport or birth certificate unless you have to in your purse or wallet

21

Purse and Wallet

3. Use unique, unpredictable, complex, and strong passwords on credit, bank, and phone accounts (Do not use: Mother's maiden name, your birth date, the last four digits of your Social Security Number (SSN), your phone number or a series of consecutive number) or use the same password on different accounts

21

Passwords

4. Order a free annual credit report once every four months, one from each of the three credit reporting agencies and have errors removed. As an minimum order a free annual credit report least once per year and only use www.AnnualCreditReport.com to order free - no other site!

21

Credit Reports

5. Never give credit card, bank, Social Security, sensitive, personal, account, or credit/debit card information over the phone, through e-mail, over the internet, on order forms, warranty forms, and registration forms unless necessary to complete a transaction; verify who you are communicating, ensure you made the contact first, and ask that written information be sent

20

Account and Personal Information Protection

6. Deposit your outgoing mail containing personally identifying information in secure post office collection boxes, at the post office, or in lockable mail boxes at home and work; when you pay bills, don't put them in the mailbox with the flag up

20

Trash and Mail

7. Use and keep updated the latest suite of protection software (Virus, Spyware, firewall, operating system patches, etc.)

18

Computers and Information Systems

8. "Opt out" of information sharing and prescreened offers of credit, junk mail, and telemarketing offers, Call the credit reporting industry to stop credit card and insurance solicitations from coming to your home to include "teaser rate" convenience checks

17

"Opt Out" of Information Sharing Agreements

9. Ask to use other identifiers other than your Social Security number on: driver's licenses, health insurance/records, registrations, applications, etc.)

16

Social Security Number

10. Secure your personal information at home and work - use lockable storage, especially if you have roommates, employ outside help or are having work done in your home and do not leave bills, statements, and other personal records with identifying information in plain site

15

Physical Security of Personal Information

11. Only conduct transactions with secure websites by checking the Web site address to make sure it's the official and not a bogus Web address (Pay bills and give out credit card information with caution) - Be suspicious of official-looking e-mail from banks or credit card companies and know the signs of a secure Web site ("lock" icon and https://). Calling the customer service number is another way to verify legitimacy and look for Web site privacy policies

15

Internet and E-mail

12. Reconcile all bank, billing, utility, and credit card statements as soon as possible to ensure all charges are yours and scrutinize for unauthorized use

11

Account and Personal Information Protection

13. If you're planning to be away from home and can't pick up your mail, contact the U.S. Postal Service at 1-800-275-8777 or online at www.usps.gov, to request a vacation hold; inform trusted neighbors when you are traveling to remove any packages that might be delivered to your home

11

Trash and Mail

14. Safeguard/secure your purse and wallet at home, work, and when out; never leave your wallet or purse in your car

11

Purse and Wallet

15. Never give out your Social Security number unless it is absolutely necessary

10

Social Security Number

16. Keep your Social Security Card, accounts, credit cards, checks, bills, personal information, and insurance policies in a safe place

9

Physical Security of Personal Information

17. Memorize and protect your Social Security number, passwords and Personal Identification Numbers (PINs) and never write them down, give or verify a password with anyone you didn't contact first

9

Passwords

18. Monitor your mail to ensure your bills arrive on time, are not delayed, and the volume of mail doesn't significantly change; alert any institution as necessary

9

Trash and Mail

19. Ask about information security procedures and privacy policies in your workplace or at businesses, doctor’s offices or other institutions that collect your personal identifying information; avoid businesses that don't have adequate safeguards or disposal procedures to protect your personal information and always ask why your information is needed and how it is going to be used; ensure your employer has security in place to guard against strangers wandering around the workplace

8

Account and Personal Information Protection

20. Put a security freeze/fraud alert on your credit report and renew it every 90 days

7

Credit Reports

21. Never write your Social Security number on a check, resume, or other document where it is not needed

7

Social Security Number

22. Be cautious when responding to promotional offers and disclosing personal information; Be suspicious of anyone who calls or sends you an email requesting personal information to “verify” who you are so they can give you a "prize" or "lottery" winnings or when things don't seem right

7

Account and Personal Information Protection

23. When ordering new checks, pick them up from the bank instead of having them mailed to your home mailbox

6

Trash and Mail

24. Promptly remove mail from your mailbox after it is delivered

6

Trash and Mail

25. Before you dispose of a computer, delete all the personal information use a "wipe" program or remove the hard drive

5

Computers and Information Systems

26. Make sure that you fill out checks carefully so that they cannot be altered easily, use an initial instead of your first name, put a line through any unused spaces on checks, and abbreviate account numbers on the memo line if annotated

5

Account and Personal Information Protection

27. Close accounts no longer intended to be used and destroy remaining checks

4

Account and Personal Information Protection

28. Shroud passwords and PINs when using ATMs with credit, debit, or other account access cards

4

Passwords

29. Never click on links, open files or attachments sent in unsolicited emails unless you verify it is from a trusted source

4

Internet and E-mail

30. Avoid saving important data on your computer - save to a secure disk

3

Computers and Information Systems

31. Limit number of persons with access to databases; do not allow remote access and make sure databases are password protected

3

Computers and Information Systems

32. Never use the automatic log-in feature when on the Internet

3

Computers and Information Systems

33. Be alert if you get a call anyone asking you to "verify" / "update your records" or get calls about purchases you did not make

3

Account and Personal Information Protection

34. Never leave ATM, Credit, or Debit Cards lying around or lend them to anyone

3

Account and Personal Information Protection

35. Do not open files sent to you by strangers, click on hyperlinks, download programs from people you don't know, or download files/software from strangers in unsolicited e-mails

3

Computers and Information Systems

36. Speak softly when giving out personal information in public; if you have to give out personal information over a phone, use a telephone booth where you can close the door and speak softly at all times

3

Account and Personal Information Protection

37. Limit the credit limits and number of credit cards you own and carry (Suggest only two total)

3

Account and Personal Information Protection

38. Continue your education about identity theft, current scams, and take a risk assessment test to determine your identity theft risk

3

Education

39. If Passwords are ever written down or stored on a computer, secure them thoroughly

3

Passwords

40. Never send personal data such as credit card numbers in a regular e-mail

2

Internet and E-mail

41. Be careful about using file-sharing programs

2

Computers and Information Systems

42. Ask about identity theft insurance, but be sure to read the fine print

2

Identity Theft Insurance

43. Never leave documents such as registrations, insurance papers, driver's licenses, utility bills, or traffic fines, in the car glove box.

2

Physical Security of Personal Information

44. Use Enhanced tamperproof credit and ID cards when/if available

2

Physical Security of Personal Information

45. Delete temporary internet files on a regular basis

2

Internet and E-mail

46. Avoid using ATMs that appear to be tampered with or are located in unlit places

2

Computers and Information Systems

47. Always "log out" of Web sites

2

Internet and E-mail

48. Take action if you get turned down for credit that you should have received

2

Account and Personal Information Protection

49. Take action if you receive credit cards that you didn't apply for

2

Account and Personal Information Protection

50. Do not respond to "pop-up" Ads or "warnings" that pop up and ask if you want your computer scanned for viruses unless you know the source

2

Internet and E-mail

51. Find out who has access to your personal information, and verify that it is handled securely

1

Account and Personal Information Protection

52. Maintain careful records of your financial accounts

for at least a year

1

Account and Personal Information Protection

53. Use direct deposit instead of paper paychecks

1

Account and Personal Information Protection

54. Start by adopting a "need to know" approach to your

personal data

1

Account and Personal Information Protection

55. Stay on the alert-continually

1

Account and Personal Information Protection

56. Use traveler's checks instead of personal bank checks

1

Account and Personal Information Protection

57. Never keep your computer "on-line" twenty-four hours a day

1

Computers and Information Systems

58. Never use public computers to access your private information

1

Computers and Information Systems

59. Try to avoid using wireless connection when viewing

financial data online

1

Computers and Information Systems

60. Use a secure browser

1

Computers and Information Systems

61. Sign up for credit monitoring services

1

Credit Reports

62. If you're hospitalized, tell your doctor or nurse to safeguard your chart

1

Account and Personal Information Protection

63. Try not to store financial information on your laptop unless absolutely necessary

1

Computers and Information Systems

64. Review all applications that you put personal information on - verify using the Better Business Bureau (BBB)

1

Account and Personal Information Protection

65. Use caution when around those with financial problems

1

Account and Personal Information Protection

66. Make sure your employer locks and limits access to

personnel records

1

Account and Personal Information Protection

67. Never sign the back of your credit card; instead write "Photo ID Required" on the signature line

1

Account and Personal Information Protection

68. Acquire/use a program that will ask you to change your password regularly and will shut down your computer after a set time if not accomplished

1

Passwords

69. Never carry the PIN for your ATM card in your purse or wallet

1

Passwords

70. Use a separate account for purchases made by telephone or on the internet with as low a credit limit as possible

1

Account and Personal Information Protection

71. Only use guaranteed ID authentication services (e.g. Microsoft Passport)

1

Passwords

72. Consider using a P.O. Box and for your address on printed checks

1

Trash and Mail

73. Remove your information from "who's who" guides

1

Account and Personal Information Protection

74. Unsolicited offers that seem too good to be true or that require you to give out bank account or other personal information are likely to be scams

1

Account and Personal Information Protection

75. Talk with your kids about cautions when using the computer online

1

Computers and Information Systems

76. Consider using a debit card and stop writing checks

1

Account and Personal Information Protection

77. Swift notification of stolen credit card

1

Account and Personal Information Protection

78. Use one credit card for online purchases

1

Account and Personal Information Protection

79. Set operating system to automatically run protective scans

1

Computers and Information Systems

80. Never carry your military ID in your wallet

1

Physical Security of Personal Information

81. Do not click on "unsubscribe links" unless you know the company is valid

1

Internet and E-mail

82. Consider using a pre-loaded cash card when traveling

1

Physical Security of Personal Information

83. Use Pre-paid calling cards for pay phones

1

Account and Personal Information Protection

84. Use purses that close securely

1

Purse and Wallet

85. Take action if you get calls from collectors or merchants on accounts not yours

1

Account and Personal Information Protection

86. Keep your hotel key card when you check out, leave a hotel or motel room

1

Physical Security of Personal Information

87. Request from your financial institution a brochure outlining your level of risk for various types of financial fraud

1

Account and Personal Information Protection

88. Remember, the government does not endorse any companies

1

Account and Personal Information Protection

89. Make sure your mailbox is large enough to accept and hold mail in the quantity and size you normally get

1

Trash and Mail

90. Use two computers if financially possible

1

Computers and Information Systems

Appendix W Identity Theft Safeguard Priority List no. 2 – Sorted by SCAM Compliance Score

SCAM SCAM

Recommended Safeguard Compliance Category

Score

1. Never give credit card, bank, Social Security, sensitive, personal, account, or credit/debit card information over the phone, through e-mail, over the internet, on order forms, warranty forms, and registration forms unless necessary to complete a transaction; verify who you are communicating, ensure you made the contact first, and ask that written information be sent

43

Stingy

2. Put a security freeze/fraud alert on your credit report and renew it every 90 days

42

Check

3. Find out who has access to your personal information, and verify that it is handled securely

41

Stingy

4. Maintain careful records of your financial accounts for at least a year

41

Maintain

5. Use direct deposit instead of paper paychecks

41

Stingy

6. Secure your personal information at home and work - use lockable storage, especially if you have roommates, employ outside help or are having work done in your home and do not leave bills, statements, and other personal records with identifying information in plain site

41

Stingy

7. Before you dispose of a computer, delete all the personal information use a "wipe" program or remove the hard drive

40

Stingy

8. Keep your Social Security Card, accounts, credit cards, checks, bills, personal information, and insurance policies in a safe place

40

Stingy

9. Carry only the identification, personally identifying information, and credit cards you actually need; don't carry documents like your Social Security card, passport or birth certificate unless you have to in your purse or wallet

40

Stingy

10. Treat mail and trash carefully: ALWAYS shred/destroy documents with personal information on them before you discard them (i.e., credit/debit/ATM card receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards, any financial mail, and credit offers you get in the mail, etc.) at home and work using a cross-cut shredder; never recycle personally identifying information

40

Stingy

11. When ordering new checks, pick them up from the bank instead of having them mailed to your home mailbox

40

Stingy

12. Close accounts no longer intended to be used and destroy remaining checks

39

Stingy

13. Reconcile all bank, billing, utility, and credit card statements as soon as possible to ensure all charges are yours and scrutinize for unauthorized use

39

Stingy

14. Avoid saving important data on your computer - save to a secure disk

39

Stingy

15. Limit number of persons with access to databases; do not allow remote access and make sure databases are password protected

39

Stingy

16. Use unique, unpredictable, complex, and strong passwords on credit, bank, and phone accounts (Do not use: Mother's maiden name, your birth date, the last four digits of your Social Security Number (SSN), your phone number or a series of consecutive number) or use the same password on different accounts

39

Stingy

17. Start by adopting a "need to know" approach to your personal data

38

Stingy

18. Stay on the alert-continually

38

Maintain

19. Use traveler's checks instead of personal bank checks

38

Stingy

20. Never keep your computer "on-line" twenty-four hours a day

38

Stingy

21. Never use public computers to access your private information

38

Stingy

22. Try to avoid using wireless connection when viewing financial data online

38

Stingy

23. Use a secure browser

38

Stingy

24. Sign up for credit monitoring services

38

Check

25. Never send personal data such as credit card numbers in a regular e-mail

38

Stingy

26. Never write your Social Security number on a check, resume, or other document where it is not needed

38

Stingy

27. If you're hospitalized, tell your doctor or nurse to safeguard your chart

37

Stingy

28. Never use the automatic log-in feature when on the Internet

37

Stingy

29. Try not to store financial information on your laptop unless absolutely necessary

37

Stingy

30. Shroud passwords and PINs when using ATMs with credit, debit, or other account access cards

37

Stingy

31. Ask to use other identifiers other than your Social Security number on: driver's licenses, health insurance/records, registrations, applications, etc.)

37

Ask

32. If you're planning to be away from home and can't pick up your mail, contact the U.S. Postal Service at 1-800-275-8777 or online at www.usps.gov, to request a vacation hold; inform trusted neighbors when you are traveling to remove any packages that might be delivered to your home

37

Stingy

33. Promptly remove mail from your mailbox after it is delivered

37

Stingy

34. Be alert if you get a call anyone asking you to "verify" / "update your records" or get calls about purchases you did not make

36

Stingy

35. Review all applications that you put personal information on - verify using the Better Business Bureau (BBB)

36

Stingy

36. Use caution when around those with financial problems

36

Stingy

37. Never give out your Social Security number unless it is absolutely necessary

36

Stingy

38. Ask about information security procedures and privacy policies in your workplace or at businesses, doctor’s offices or other institutions that collect your personal identifying information; avoid businesses that don't have adequate safeguards or disposal procedures to protect your personal information and always ask why your information is needed and how it is going to be used; ensure your employer has security in place to guard against strangers wandering around the workplace

35

Ask

39. Make sure your employer locks and limits access to personnel records

35

Stingy

40. Never sign the back of your credit card; instead write "Photo ID Required" on the signature line

35

Stingy

41. Acquire/use a program that will ask you to change your password regularly and will shut down your computer after a set time if not accomplished

35

Stingy

42. Memorize and protect your Social Security number, passwords and Personal Identification Numbers (PINs) and never write them down, give or verify a password with anyone you didn't contact first

35

Stingy

43. Never carry the PIN for your ATM card in your purse or wallet

35

Stingy

44. Safeguard/secure your purse and wallet at home, work, and when out; never leave your wallet or purse in your car

35

Stingy

45. Never leave ATM, Credit, or Debit Cards lying around or lend them to anyone

34

Stingy

46. Use a separate account for purchases made by telephone or on the internet with as low a credit limit as possible

34

Stingy

47. Be careful about using file-sharing programs

34

Stingy

48. Do not open files sent to you by strangers, click on hyperlinks, download programs from people you don't know, or download files/software from strangers in unsolicited e-mails

34

Stingy

49. Use and keep updated the latest suite of protection software (Virus, Spyware, firewall, operating system patches, etc.)

34

Stingy

50. Ask about identity theft insurance, but be sure to read the fine print

34

Ask

51. Never click on links, open files or attachments sent in unsolicited emails unless you verify it is from a trusted source

34

Stingy

52. Only conduct transactions with secure websites by checking the Web site address to make sure it's the official and not a bogus Web address (Pay bills and give out credit card information with caution) - Be suspicious of official-looking e-mail from banks or credit card companies and know the signs of a secure Web site ("lock" icon and https://). Calling the customer service number is another way to verify legitimacy and look for Web site privacy policies

34

Stingy

53. Only use guaranteed ID authentication services (e.g. Microsoft Passport)

34

Stingy

54. Consider using a P.O. Box and for your address on printed checks

34

Stingy

55. Deposit your outgoing mail containing personally identifying information in secure post office collection boxes, at the post office, or in lockable mail boxes at home and work; when you pay bills, don't put them in the mailbox with the flag up

34

Stingy

56. Be cautious when responding to promotional offers and disclosing personal information; Be suspicious of anyone who calls or sends you an email requesting personal information to “verify” who you are so they can give you a "prize" or "lottery" winnings or when things don't seem right

33

Stingy

57. Remove your information from "who's who" guides

33

Stingy

58. Speak softly when giving out personal information in public; if you have to give out personal information over a phone, use a telephone booth where you can close the door and speak softly at all times

33

Stingy

59. Unsolicited offers that seem too good to be true or that require you to give out bank account or other personal information are likely to be scams

33

Stingy

60. Order a free annual credit report once every four months, one from each of the three credit reporting agencies and have errors removed. As an minimum order a free annual credit report least once per year and only use www.AnnualCreditReport.com to order free - no other site!

33

Check

61. Never leave documents such as registrations, insurance papers, driver's licenses, utility bills, or traffic fines, in the car glove box.

33

Stingy

62. Use Enhanced tamperproof credit and ID cards when/if available

33

Stingy

63. Limit the credit limits and number of credit cards you own and carry (Suggest only two total)

32

Stingy

64. Talk with your kids about cautions when using the computer online

32

Ask

65. Delete temporary internet files on a regular basis

32

Stingy

66. Avoid using ATMs that appear to be tampered with or are located in unlit places

31

Stingy

67. Always "log out" of Web sites

31

Stingy

68. Consider using a debit card and stop writing checks

30

Stingy

69. Make sure that you fill out checks carefully so that they cannot be altered easily, use an initial instead of your first name, put a line through any unused spaces on checks, and abbreviate account numbers on the memo line if annotated

30

Stingy

70. Swift notification of stolen credit card

30

Check

71. Use one credit card for online purchases

30

Stingy

72. Set operating system to automatically run protective scans

30

Stingy

73. Never carry your military ID in your wallet

30

Stingy

74. Take action if you get turned down for credit that you should have received

29

Ask

75. Take action if you receive credit cards that you didn't apply for

29

Maintain

76. Do not click on "unsubscribe links" unless you know the company is valid

29

Stingy

77. Do not respond to "pop-up" Ads or "warnings" that pop up and ask if you want your computer scanned for viruses unless you know the source

29

Stingy

78. Consider using a pre-loaded cash card when traveling

29

Stingy

79. "Opt out" of information sharing and prescreened offers of credit, junk mail, and telemarketing offers, Call the credit reporting industry to stop credit card and insurance solicitations from coming to your home to include "teaser rate" convenience checks

28

Stingy

80. Use Pre-paid calling cards for pay phones

27

Stingy

81. Continue your education about identity theft, current scams, and take a risk assessment test to determine your identity theft risk

27

Check

82. Use purses that close securely

27

Stingy

83. If Passwords are ever written down or stored on a computer, secure them thoroughly

26

Stingy

84. Take action if you get calls from collectors or merchants on accounts not yours

25

Stingy

85. Keep your hotel key card when you check out, leave a hotel or motel room

25

Stingy

86. Request from your financial institution a brochure outlining your level of risk for various types of financial fraud

23

Ask

87. Remember, the government does not endorse any companies

22

Stingy

88. Monitor your mail to ensure your bills arrive on time, are not delayed, and the volume of mail doesn't significantly change; alert any institution as necessary

22

Check

89. Make sure your mailbox is large enough to accept and hold mail in the quantity and size you normally get

21

Stingy

90. Use two computers if financially possible

19

Stingy

Appendix X Safeguards Deemed Not Controllable and Not Considered for Analysis

1. "Hacking hurts people"

Not Controllable

2. Avoid public disclosure of security holes and patches in software

Not Controllable

3. Background checks of employees

Not Controllable

4. Close Scrutiny, background checks of employees with access to ID database

Not Controllable

5. Disallow employees to take home work

Not Controllable

6. Do not boast of security features in software

Not Controllable

7. ID for mail forwarding

Not Controllable

8. Install cameras on ATMs, at check-out counters, shipping and mailing services, and ID granting agencies

Not Controllable

9. Monitor all utilization of ID databases

Not Controllable

10. Monitor classified ads

Not Controllable

11. Monitor pawn shops

Not Controllable

12. Monitor retail returns at departments

Not Controllable

13. No credit card numbers on receipts

Not Controllable

14. Place ATMs so keystrokes cannot be observed or recorded

Not Controllable

15. Prominent display of signage "Protect our customer's Privacy"

Not Controllable

16. Prominent display of signage "Protect Privacy"

Not Controllable

17. Publish a responsible computer use policy

Not Controllable

18. Require additional ID for on-line purchases

Not Controllable

19. Require several forms of ID to obtain new ID or replacements

Not Controllable

20. Reward vigilance of supervisors of employee/customer records

Not Controllable

21. Support whistleblowers

Not Controllable

22. Train clerks, police, officials in document authentication procedures

Not Controllable

23. Use "Smart cards" that contain limited personal ID information

Not Controllable

24. Use photo/thumb print on ID documents and credit cards

Not Controllable

25. Use tracking ID tags to track location and use and who uses machine

Not Controllable

26. Vehicle ID licensing and parts marking

Not Controllable

Appendix Y Spreadsheet Used in Descriptive Analysis (Sheet 1 of 7)

List #1

 

List #2

Safeguard Number in List #1

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

 

Safeguard Number in List #2

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

317.04

30

44

40

10.57

 

276.43

26

44

40

10.63

 

1

10.53

1

+

Mean

8.4634

 

1

13.55

1

+

Mean

8.4634

2

7.08

-

Median

8.37

 

2

12.27

1

+

Median

8.37

3

9.78

1

+

Mode

3..11

 

3

13.42

1

+

Mode

3..11

4

7.90

-

t test

0.1733

 

4

3.11

-

t test

0.1733

5

13.55

1

+

 

5

10.53

1

+

6

10.92

1

+

 

 

6

12.00

1

+

7

5.49

-

 

 

7

6.52

-

8

12.27

1

+

 

8

7.11

-

9

13.55

1

+

 

9

11.08

1

+

10

13.55

1

NA

NA

 

10

13.55

1

NA

NA

11

13.55

1

+

 

 

11

6.70

-

12

7.11

-

 

 

12

3.11

-

13

13.13

1

+

 

 

13

10.27

1

+

14

8.11

-

 

 

14

14.47

1

+

15

3.11

-

 

 

15

9.90

1

+

16

13.42

1

+

 

 

16

13.55

1

+

Running head: IDENTITY THEFT SAFEGUARDS

IDENTITY THEFT SAFEGUARDS 2

List #1

 

List #2

Safeguard Number in List #1

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

 

Safeguard Number in List #2

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

17

4.92

-

 

 

17

8.77

1

+

18

9.93

1

+

 

 

18

3.11

-

19

7.11

-

 

 

19

9.63

1

+

20

15.55

1

+

 

 

20

7.08

-

21

3.11

-

 

 

21

15.55

1

+

22

9.61

1

+

 

 

22

6.03

1

-

23

12.26

1

+

 

 

23

13.55

1

+

24

5.87

-

 

 

24

11.27

1

+

25

7.55

-

 

 

25

5.49

-

26

9.15

1

+

 

 

26

10.72

1

+

27

11.08

1

+

 

 

27

13.13

1

+

28

7.15

-

 

 

28

8.77

1

+

29

10.27

1

+

 

 

29

4.95

-

List #1

 

List #2

Safeguard Number in List #1

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

 

Safeguard Number in List #2

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

30

8.28

1

-

30

7.11

-

31

11.27

1

+

 

 

31

8.11

-

32

8.77

1

+

 

 

32

8.28

-

33

8.46

1

+

 

 

33

7.83

-

34

7.83

-

 

 

34

4.95

-

35

9.90

1

+

 

 

35

14.47

1

+

36

7.61

-

 

 

36

6.81

-

37

10.99

1

+

 

 

37

11.62

1

+

38

9.83

1

+

 

 

38

3.11

-

39

9.63

1

+

 

 

39

8.75

1

+

40

12.52

1

+

 

 

40

9.93

1

+

41

8.77

1

+

 

 

41

3.11

-

42

8.77

1

+

 

 

42

8.46

1

+

List #1

 

List #2

Safeguard Number in List #1

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

 

Safeguard Number in List #2

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

43

15.11

1

+

 

 

43

10.77

1

+

 

44

14.47

1

+

 

44

6.17

-

45

3.11

 

 

-

 

45

7.47

 

 

-

46

8.46

+

 

46

5.19

-

47

14.47

+

 

 

47

5.61

-

48

12.00

+

 

 

48

3.11

-

49

4.95

-

 

 

49

3.11

-

50

4.95

-

 

 

50

9.78

+

51

14.47

+

 

 

51

7.90

-

52

6.70

-

 

 

52

10.92

+

53

10.39

+

 

 

53

4.92

-

54

7.43

-

 

 

54

7.11

-

55

6.52

-

 

 

55

3.11

-

List #1

 

List #2

Safeguard Number in List #1

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

 

Safeguard Number in List #2

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

56

6.03

-

 

 

56

9.61

+

57

10.77

+

 

 

57

12.26

+

58

3.11

-

 

 

58

5.87

-

59

4.39

-

 

 

59

7.55

-

60

6.81

-

 

 

60

9.15

+

61

6.26

-

 

 

61

7.15

-

62

14.35

+

 

 

62

8.46

+

63

6.17

-

 

 

63

7.61

+

64

11.62

+

 

 

64

10.99

+

65

8.49

+

 

 

65

9.83

+

66

7.47

-

 

 

66

12.52

+

67

5.19

 

 

-

 

 

67

8.77

 

+

 

 

68

13.01

+

 

 

68

15.11

+

List #1

 

List #2

Safeguard Number in List #1

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

Safeguard Number in List #2

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

69

10.72

+

 

 

69

14.47

+

70

10.15

+

70

10.39

+

71

10.27

+

71

7.43

-

72

3.11

-

72

4.39

-

73

4.92

-

73

6.26

-

74

6.13

-

74

14.35

+

75

5.99

-

75

8.49

+

76

5.61

-

76

13.01

+

77

3.11

-

77

10.15

+

78

3.11

-

78

10.27

+

79

7.11

-

79

3.11

-

80

3.11

-

80

4.92

-

81

7.68

-

81

6.13

-

List #1

 

List #2

Safeguard Number in List #1

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

Safeguard Number in List #2

List #1 Weighted Score

No. of Safeguards Above Median

No. of Plus Signs

No. of Minus Signs

Average of Scores Above Median

82

11.15

+

82

5.99

-

83

8.75

+

83

7.68

-

84

12.15

+

84

11.15

+

85

3.11

-

85

12.15

+

86

3.11

-

86

3.11

-

87

3.11

-

87

3.11

-

88

3.11

-

88

3.11

-

89

7.15

-

89

7.15

-

90

3.11

-

90

7.15

-

Appendix Z Method Used to Determine Tradeoff Weights (Page 1 of 2)

The following are the percentages from Figure 4 of each means of identity theft used in calculating the tradeoff weights to arrive at the “Weighted Means Test Score” for each safeguard:

A. Lost or stolen wallet, checkbook, or credit card (30.0%)

B. By friends, acquaintances, relatives, or in-home employees (15.0%)

C. From stolen paper mail or by fraudulent change of address (8.0%)

D. Computer viruses, spyware, or hackers (5.0%)

E. Phishing (3.0%)

F. Garbage (1%)

G. Online transactions (0.3%)

H. Taken by a corrupt business employee (15.0%)

I. Misuse of data from an in-store/online/telephone transaction (7.0%)

J. Stolen from a company that handles your financial data (6.0%)

The means of reported identity percentages are shown in Figure Z1.

address (8 %)

Figure Z1: Means of Identity Theft (Javelin Strategy, 2006)

Note: The category “other” has not been included.

Method Used to Determine Tradeoff Weights (Page 2 of 2)

The standard of 30% was chosen as represented by the means of identity theft A and compared to B through J using a system of proportions consistent with the “Direct Method for Eliciting Tradeoff Weights (Golub, 1997, p 162) in the discipline of decision analysis. After researching the pure derivation of the direct method, it became clear that simple proportions could also be used to arrive at the tradeoff weights as follows:

A B

=

1 Xi

Where,

A = the standard of (30%) used to compare other means to (% of A)

Xi = proportion of any objective to the standard

Solving for X yields: Xi = B / A

where,

Substituting for B and A yields the following tradeoff weights used in calculations:

XB = 15% / 30 % XG = 0.3% / 30 %

XB = 0.50 XG = 0.01

XC = 8% / 30 % XH = 15% / 30 %

XC = 0.26 XH = 0.50

XD = 5% / 30 % XI = 7% / 30 %

XD = 0.16 XI = 0.23

XE = 3% / 30 % XJ = 6% / 30 %

XE = 0.10 XI = 0.20

XF = 1% / 30 %

XF = 0.03

Appendix AA Master Spreadsheet “Sorted by Weighted Means Test Summated Score” (Sheet 1 of 24)

 

Safeguard Recommendation

Weighted Means Test Summated Score (15.55 Possible)

No. of Times Recommended

SCAM Compliance Score (65 Possible)

1

Never write your Social Security number on a check, resume, or other document where it is not needed

15.55

7

38.00

2

Never sign the back of your credit card; instead write "Photo ID Required" on the signature line

15.11

1

35.00

3

Safeguard/secure your purse and wallet at home, work, and when out; never leave your wallet or purse in your car

14.47

11

35.00

4

Never leave ATM, Credit, or Debit Cards lying around or lend them to anyone

14.47

3

34.00

5

Consider using a P.O. Box and for your address on printed checks

14.47

1

34.00

6

Use Enhanced tamperproof credit and ID cards when/if available

14.35

1

33.00

7

Treat mail and trash carefully: ALWAYS shred/destroy documents with personal information on them before you discard them (i.e., credit/debit/ATM card receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards, any financial mail, and credit offers you get in the mail, etc.) at home and work using a cross-cut shredder; never recycle personally identifying information

13.55

27

40.00

8

Secure your personal information at home and work - use lockable storage, especially if you have roommates, employ outside help or are having work done in your home and do not leave bills, statements, and other personal records with identifying information in plain site

13.55

15

41.00

9

Keep your Social Security Card, accounts, credit cards, checks, bills, personal information, and insurance policies in a safe place

13.55

9

40.00

10

When ordering new checks, pick them up from the bank instead of having them mailed to your home mailbox

13.55

6

40.00

 

Safeguard Recommendation

Weighted Means Test Summated Score (15.55 Possible)

No. of Times Recommended

SCAM Compliance Score (65 Possible)

11

Use unique, unpredictable, complex, and strong passwords on credit, bank, and phone accounts (Do not use: Mother's maiden name, your birth date, the last four digits of your Social Security Number (SSN), your phone number or a series of consecutive number) or use the same password on different accounts

13.42

21

39.00

12

Close accounts no longer intended to be used and destroy remaining checks

13.13

4

39.00

13

Consider using a debit card and stop writing checks

13.01

1

30.00

14

Make sure your employer locks and limits access to personnel records

12.52

1

35.00

15

Carry only the identification, personally identifying information, and credit cards you actually need; don't carry documents like your Social Security card, passport or birth certificate unless you have to in your purse or wallet

12.27

21

40.00

16

Stay on the alert-continually

12.26

1

38.00

17

Keep your hotel key card when you check out, leave a hotel or motel room

12.15

1

25.00

18

Deposit your outgoing mail containing personally identifying information in secure post office collection boxes, at the post office, or in lockable mail boxes at home and work; when you pay bills, don't put them in the mailbox with the flag up

12.00

20

34.00

19

Limit the credit limits and number of credit cards you own and carry (Suggest only two total)

11.62

3

32.00

20

Promptly remove mail from your mailbox after it is delivered

11.27

6

37.00

21

Use purses that close securely

11.15

1

27.00

 

Safeguard Recommendation

Weighted Means Test Summated Score (15.55 Possible)

No. of Times Recommended

SCAM Compliance Score (65 Possible)

22

Ask to use other identifiers other than your Social Security number on: driver's licenses, health insurance/records, registrations, applications, etc.)

11.08

16

37.00

23

Use caution when around those with financial problems

10.99

1

36.00

24

Use direct deposit instead of paper paychecks

10.92

1

41.00

25

Never leave documents such as registrations, insurance papers, driver's licenses, utility bills, or traffic fines, in the car glove box.

10.77

2

33.00

26

Make sure that you fill out checks carefully so that they cannot be altered easily, use an initial instead of your first name, put a line through any unused spaces on checks, and abbreviate account numbers on the memo line if annotated

10.72

5

30.00

27

Never give credit card, bank, Social Security, sensitive, personal, account, or credit/debit card information over the phone, through e-mail, over the internet, on order forms, warranty forms, and registration forms unless necessary to complete a transaction; verify who you are communicating, ensure you made the contact first, and ask that written information be sent

10.53

20

43.00

28

Only use guaranteed ID authentication services (e.g. Microsoft Passport)

10.39

1

34.00

29

If you're planning to be away from home and can't pick up your mail, contact the U.S. Postal Service at 1-800-275-8777 or online at www.usps.gov, to request a vacation hold; inform trusted neighbors when you are traveling to remove any packages that might be delivered to your home

10.27

11

37.00

30

Set operating system to automatically run protective scans

10.27

1

30.00

 

Safeguard Recommendation

Weighted Means Test Summated Score (15.55 Possible)

No. of Times Recommended

SCAM Compliance Score (65 Possible)

31

Never carry your military ID in your wallet

10.15

1

30.00

32

Never send personal data such as credit card numbers in a regular e-mail

9.93

2

38.00

33

Never give out your Social Security number unless it is absolutely necessary

9.90

10

36.00

34

Acquire/use a program that will ask you to change your password regularly and will shut down your computer after a set time if not accomplished

9.83

1

35.00

35

Find out who has access to your personal information, and verify that it is handled securely

9.78

1

41.00

36

Ask about information security procedures and privacy policies in your workplace or at businesses, doctor’s offices or other institutions that collect your personal identifying information; avoid businesses that don't have adequate safeguards or disposal procedures to protect your personal information and always ask why your information is needed and how it is going to be used; ensure your employer has security in place to guard against strangers wandering around the workplace

9.63

8

35.00

37

Start by adopting a "need to know" approach to your personal data

9.61

1

38.00

38

Use traveler's checks instead of personal bank checks

9.15

1

38.00

39

Memorize and protect your Social Security number, passwords and Personal Identification Numbers (PINs) and never write them down, give or verify a password with anyone you didn't contact first

8.77

9

35.00

40

Shroud passwords and PINs when using ATMs with credit, debit, or other account access cards

8.77

4

37.00

 

Safeguard Recommendation

Weighted Means Test Summated Score (15.55 Possible)

No. of Times Recommended

SCAM Compliance Score (65 Possible)

41

Never carry the PIN for your ATM card in your purse or wallet

8.77

1

35.00

42

If Passwords are ever written down or stored on a computer, secure them thoroughly

8.75

3

26.00

43

Talk with your kids about cautions when using the computer online

8.49

1

32.00

44

Be careful about using file-sharing programs

8.46

2

34.00

45

Try not to store financial information on your laptop unless absolutely necessary

8.46

1

37.00

46

Never use the automatic log-in feature when on the Internet

8.28

3

37.00

47

Limit number of persons with access to databases; do not allow remote access and make sure databases are password protected

8.11

3

39.00

48

Maintain careful records of your financial accounts for at least a year

7.90

1

41.00

49

Be alert if you get a call anyone asking you to "verify" / "update your records" or get calls about purchases you did not make

7.83

3

36.00

50

Use Pre-paid calling cards for pay phones

7.68

1

27.00

51

Review all applications that you put personal information on - verify using the Better Business Bureau (BBB)

7.61

1

36.00

52

Use a secure browser

7.55

1

38.00

53

Always "log out" of Web sites

7.47

2

31.00

54

Use a separate account for purchases made by telephone or on the internet with as low a credit limit as possible

7.43

1

34.00

55

If you're hospitalized, tell your doctor or nurse to safeguard your chart

7.15

1

37.00

56

Make sure your mailbox is large enough to accept and hold mail in the quantity and size you normally get

7.15

1

21.00

 

Safeguard Recommendation

Weighted Means Test Summated Score (15.55 Possible)

No. of Times Recommended

SCAM Compliance Score (65 Possible)

57

"Opt out" of information sharing and prescreened offers of credit, junk mail, and telemarketing offers, Call the credit reporting industry to stop credit card and insurance solicitations from coming to your home to include "teaser rate" convenience checks

7.11

17

28.00

58

Avoid saving important data on your computer - save to a secure disk

7.11

3

39.00

59

Never use public computers to access your private information

7.11

1

38.00

60

Put a security freeze/fraud alert on your credit report and renew it every 90 days

7.08

7

42.00

61

Speak softly when giving out personal information in public; if you have to give out personal information over a phone, use a telephone booth where you can close the door and speak softly at all times

6.81

3

33.00

62

Only conduct transactions with secure websites by checking the Web site address to make sure it's the official and not a bogus Web address (Pay bills and give out credit card information with caution) - Be suspicious of official-looking e-mail from banks or credit card companies and know the signs of a secure Web site ("lock" icon and https://). Calling the customer service number is another way to verify legitimacy and look for Web site privacy policies

6.70

15

34.00

63

Use and keep updated the latest suite of protection software (Virus, Spyware, firewall, operating system patches, etc.)

6.52

18

34.00

64

Unsolicited offers that seem too good to be true or that require you to give out bank account or other personal information are likely to be scams

6.26

1

33.00

65

Delete temporary internet files on a regular basis

6.17

2

32.00

 

Safeguard Recommendation

Weighted Means Test Summated Score (15.55 Possible)

No. of Times Recommended

SCAM Compliance Score (65 Possible)

66

Consider using a pre-loaded cash card when traveling

6.13

1

29.00

67

Be cautious when responding to promotional offers and disclosing personal information; Be suspicious of anyone who calls or sends you an email requesting personal information to “verify” who you are so they can give you a "prize" or "lottery" winnings or when things don't seem right

6.03

7

33.00

68

Do not click on "unsubscribe links" unless you know the company is valid

5.99

1

29.00

69

Try to avoid using wireless connection when viewing financial data online

5.87

1

38.00

70

Do not respond to "pop-up" Ads or "warnings" that pop up and ask if you want your computer scanned for viruses unless you know the source

5.61

2

29.00

71

Before you dispose of a computer, delete all the personal information use a "wipe" program or remove the hard drive

5.49

5

40.00

72

Avoid using ATMs that appear to be tampered with or are located in unlit places

5.19

2

31.00

73

Never click on links, open files or attachments sent in unsolicited emails unless you verify it is from a trusted source

4.95

4

34.00

74

Do not open files sent to you by strangers, click on hyperlinks, download programs from people you don't know, or download files/software from strangers in unsolicited e-mails

4.95

3

34.00

75

Never keep your computer "on-line" twenty-four hours a day

4.92

1

38.00

76

Use one credit card for online purchases

4.92

1

30.00

77

Remove your information from "who's who" guides

4.39

1

33.00

 

Safeguard Recommendation

Weighted Means Test Summated Score (15.55 Possible)

No. of Times Recommended

SCAM Compliance Score (65 Possible)

78

Order a free annual credit report once every four months, one from each of the three credit reporting agencies and have errors removed. As a minimum order a free annual credit report least once per year and only use www.AnnualCreditReport.com to order free - no other site!

3.11

21

33.00

79

Reconcile all bank, billing, utility, and credit card statements as soon as possible to ensure all charges are yours and scrutinize for unauthorized use

3.11

11

39.00

80

Monitor your mail to ensure your bills arrive on time, are not delayed, and the volume of mail doesn't significantly change; alert any institution as necessary

3.11

9

22.00

81

Continue your education about identity theft, current scams, and take a risk assessment test to determine your identity theft risk

3.11

3

27.00

82

Ask about identity theft insurance, but be sure to read the fine print

3.11

2

34.00

83

Take action if you get turned down for credit that you should have received

3.11

2

29.00

84

Take action if you receive credit cards that you didn't apply for

3.11

2

29.00

85

Sign up for credit monitoring services

3.11

1

38.00

86

Swift notification of stolen credit card

3.11

1

30.00

87

Take action if you get calls from collectors or merchants on accounts not yours

3.11

1

25.00

88

Request from your financial institution a brochure outlining your level of risk for various types of financial fraud

3.11

1

23.00

89

Remember, the government does not endorse any companies

3.11

1

22.00

90

Use two computers if financially possible

3.11

1

19.00

 

Safeguard Recommendation

12 Main Categories of Safeguards

No. of Times Main Category Recommended

SCAM Category

1

Never write your Social Security number on a check, resume, or other document where it is not needed

Social Security Number

33

Stingy

2

Never sign the back of your credit card; instead write "Photo ID Required" on the signature line

Account and Personal Information Protection

91

Stingy

3

Safeguard/secure your purse and wallet at home, work, and when out; never leave your wallet or purse in your car

Purse and Wallet

33

Stingy

4

Never leave ATM, Credit, or Debit Cards lying around or lend them to anyone

Account and Personal Information Protection

91

Stingy

5

Consider using a P.O. Box and for your address on printed checks

Trash and Mail

81

Stingy

6

Use Enhanced tamperproof credit and ID cards when/if available

Physical Security of Personal Information

31

Stingy

7

Treat mail and trash carefully: ALWAYS shred/destroy documents with personal information on them before you discard them (i.e., credit/debit/ATM card receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards, any financial mail, and credit offers you get in the mail, etc.) at home and work using a cross-cut shredder; never recycle personally identifying information

Trash and Mail

81

Stingy

8

Secure your personal information at home and work - use lockable storage, especially if you have roommates, employ outside help or are having work done in your home and do not leave bills, statements, and other personal records with identifying information in plain site

Physical Security of Personal Information

31

Stingy

9

Keep your Social Security Card, accounts, credit cards, checks, bills, personal information, and insurance policies in a safe place

Physical Security of Personal Information

31

Stingy

10

When ordering new checks, pick them up from the bank instead of having them mailed to your home mailbox

Trash and Mail

81

Stingy

 

Safeguard Recommendation

12 Main Categories of Safeguards

No. of Times Main Category Recommended

SCAM Category

11

Use unique, unpredictable, complex, and strong passwords on credit, bank, and phone accounts (Do not use: Mother's maiden name, your birth date, the last four digits of your Social Security Number (SSN), your phone number or a series of consecutive number) or use the same password on different accounts

Passwords

40

Stingy

12

Close accounts no longer intended to be used and destroy remaining checks

Account and Personal Information Protection

91

Stingy

13

Consider using a debit card and stop writing checks

Account and Personal Information Protection

91

Stingy

14

Make sure your employer locks and limits access to personnel records

Account and Personal Information Protection

91

Stingy

15

Carry only the identification, personally identifying information, and credit cards you actually need; don't carry documents like your Social Security card, passport or birth certificate unless you have to in your purse or wallet

Purse and Wallet

33

Stingy

16

Stay on the alert-continually

Account and Personal Information Protection

91

Maintain

17

Keep your hotel key card when you check out, leave a hotel or motel room

Physical Security of Personal Information

31

Stingy

18

Deposit your outgoing mail containing personally identifying information in secure post office collection boxes, at the post office, or in lockable mail boxes at home and work; when you pay bills, don't put them in the mailbox with the flag up

Trash and Mail

81

Stingy

19

Limit the credit limits and number of credit cards you own and carry (Suggest only two total)

Account and Personal Information Protection

91

Stingy

20

Promptly remove mail from your mailbox after it is delivered

Trash and Mail

81

Stingy

21

Use purses that close securely

Purse and Wallet

33

Stingy

 

Safeguard Recommendation

12 Main Categories of Safeguards

No. of Times Main Category Recommended

SCAM Category

22

Ask to use other identifiers other than your Social Security number on: driver's licenses, health insurance/records, registrations, applications, etc.)

Social Security Number

33

Ask

23

Use caution when around those with financial problems

Account and Personal Information Protection

91

Stingy

24

Use direct deposit instead of paper paychecks

Account and Personal Information Protection

91

Stingy

25

Never leave documents such as registrations, insurance papers, driver's licenses, utility bills, or traffic fines, in the car glove box.

Physical Security of Personal Information

31

Stingy

26

Make sure that you fill out checks carefully so that they cannot be altered easily, use an initial instead of your first name, put a line through any unused spaces on checks, and abbreviate account numbers on the memo line if annotated

Account and Personal Information Protection

91

Stingy

27

Never give credit card, bank, Social Security, sensitive, personal, account, or credit/debit card information over the phone, through e-mail, over the internet, on order forms, warranty forms, and registration forms unless necessary to complete a transaction; verify who you are communicating, ensure you made the contact first, and ask that written information be sent

Account and Personal Information Protection

91

Stingy

28

Only use guaranteed ID authentication services (e.g. Microsoft Passport)

Passwords

40

Stingy

29

If you're planning to be away from home and can't pick up your mail, contact the U.S. Postal Service at 1-800-275-8777 or online at www.usps.gov, to request a vacation hold; inform trusted neighbors when you are traveling to remove any packages that might be delivered to your home

Trash and Mail

81

Stingy

30

Set operating system to automatically run protective scans

Computers and Information Systems

48

Stingy

 

Safeguard Recommendation

12 Main Categories of Safeguards

No. of Times Main Category Recommended

SCAM Category

31

Never carry your military ID in your wallet

Physical Security of Personal Information

31

Stingy

32

Never send personal data such as credit card numbers in a regular e-mail

Internet and E-mail

28

Stingy

33

Never give out your Social Security number unless it is absolutely necessary

Social Security Number

33

Stingy

34

Acquire/use a program that will ask you to change your password regularly and will shut down your computer after a set time if not accomplished

Passwords

40

Stingy

35

Find out who has access to your personal information, and verify that it is handled securely

Account and Personal Information Protection

91

Stingy

36

Ask about information security procedures and privacy policies in your workplace or at businesses, doctor’s offices or other institutions that collect your personal identifying information; avoid businesses that don't have adequate safeguards or disposal procedures to protect your personal information and always ask why your information is needed and how it is going to be used; ensure your employer has security in place to guard against strangers wandering around the workplace

Account and Personal Information Protection

91

Ask

37

Start by adopting a "need to know" approach to your personal data

Account and Personal Information Protection

91

Stingy

38

Use traveler's checks instead of personal bank checks

Account and Personal Information Protection

91

Stingy

39

Memorize and protect your Social Security number, passwords and Personal Identification Numbers (PINs) and never write them down, give or verify a password with anyone you didn't contact first

Passwords

40

Stingy

40

Shroud passwords and PINs when using ATMs with credit, debit, or other account access cards

Passwords

40

Stingy

 

Safeguard Recommendation

12 Main Categories of Safeguards

No. of Times Main Category Recommended

SCAM Category

41

Never carry the PIN for your ATM card in your purse or wallet

Passwords

40

Stingy

42

If Passwords are ever written down or stored on a computer, secure them thoroughly

Passwords

40

Stingy

43

Talk with your kids about cautions when using the computer online

Computers and Information Systems

48

Ask

44

Be careful about using file-sharing programs

Computers and Information Systems

48

Stingy

45

Try not to store financial information on your laptop unless absolutely necessary

Computers and Information Systems

48

Stingy

46

Never use the automatic log-in feature when on the Internet

Computers and Information Systems

48

Stingy

47

Limit number of persons with access to databases; do not allow remote access and make sure databases are password protected

Computers and Information Systems

48

Stingy

48

Maintain careful records of your financial accounts for at least a year

Account and Personal Information Protection

91

Maintain

49

Be alert if you get a call anyone asking you to "verify" / "update your records" or get calls about purchases you did not make

Account and Personal Information Protection

91

Stingy

50

Use Pre-paid calling cards for pay phones

Account and Personal Information Protection

91

Stingy

51

Review all applications that you put personal information on - verify using the Better Business Bureau (BBB)

Account and Personal Information Protection

91

Stingy

52

Use a secure browser

Computers and Information Systems

48

Stingy

53

Always "log out" of Web sites

Internet and E-mail

28

Stingy

54

Use a separate account for purchases made by telephone or on the internet with as low a credit limit as possible

Account and Personal Information Protection

91

Stingy

55

If you're hospitalized, tell your doctor or nurse to safeguard your chart

Account and Personal Information Protection

91

Stingy

56

Make sure your mailbox is large enough to accept and hold mail in the quantity and size you normally get

Trash and Mail

81

Stingy

 

Safeguard Recommendation

12 Main Categories of Safeguards

No. of Times Main Category Recommended

SCAM Category

57

"Opt out" of information sharing and prescreened offers of credit, junk mail, and telemarketing offers, Call the credit reporting industry to stop credit card and insurance solicitations from coming to your home to include "teaser rate" convenience checks

"Opt Out" of Information Sharing Agreements

17

Stingy

58

Avoid saving important data on your computer - save to a secure disk

Computers and Information Systems

48

Stingy

59

Never use public computers to access your private information

Computers and Information Systems

48

Stingy

60

Put a security freeze/fraud alert on your credit report and renew it every 90 days

Credit Reports

29

Check

61

Speak softly when giving out personal information in public; if you have to give out personal information over a phone, use a telephone booth where you can close the door and speak softly at all times

Account and Personal Information Protection

91

Stingy

62

Only conduct transactions with secure websites by checking the Web site address to make sure it's the official and not a bogus Web address (Pay bills and give out credit card information with caution) - Be suspicious of official-looking e-mail from banks or credit card companies and know the signs of a secure Web site ("lock" icon and https://). Calling the customer service number is another way to verify legitimacy and look for Web site privacy policies

Internet and E-mail

28

Stingy

63

Use and keep updated the latest suite of protection software (Virus, Spyware, firewall, operating system patches, etc.)

Computers and Information Systems

48

Stingy

64

Unsolicited offers that seem too good to be true or that require you to give out bank account or other personal information are likely to be scams

Account and Personal Information Protection

91

Stingy

65

Delete temporary internet files on a regular basis

Internet and E-mail

28

Stingy

 

Safeguard Recommendation

12 Main Categories of Safeguards

No. of Times Main Category Recommended

SCAM Category

66

Consider using a pre-loaded cash card when traveling

Physical Security of Personal Information

31

Stingy

67

Be cautious when responding to promotional offers and disclosing personal information; Be suspicious of anyone who calls or sends you an email requesting personal information to “verify” who you are so they can give you a "prize" or "lottery" winnings or when things don't seem right

Account and Personal Information Protection

91

Stingy

68

Do not click on "unsubscribe links" unless you know the company is valid

Internet and E-mail

28

Stingy

69

Try to avoid using wireless connection when viewing financial data online

Computers and Information Systems

48

Stingy

70

Do not respond to "pop-up" Ads or "warnings" that pop up and ask if you want your computer scanned for viruses unless you know the source

Internet and E-mail

28

Stingy

71

Before you dispose of a computer, delete all the personal information use a "wipe" program or remove the hard drive

Computers and Information Systems

48

Stingy

72

Avoid using ATMs that appear to be tampered with or are located in unlit places

Computers and Information Systems

48

Stingy

73

Never click on links, open files or attachments sent in unsolicited emails unless you verify it is from a trusted source

Internet and E-mail

28

Stingy

74

Do not open files sent to you by strangers, click on hyperlinks, download programs from people you don't know, or download files/software from strangers in unsolicited e-mails

Computers and Information Systems

48

Stingy

75

Never keep your computer "on-line" twenty-four hours a day

Computers and Information Systems

48

Stingy

76

Use one credit card for online purchases

Account and Personal Information Protection

91

Stingy

77

Remove your information from "who's who" guides

Account and Personal Information Protection

91

Stingy

 

Safeguard Recommendation

12 Main Categories of Safeguards

No. of Times Main Category Recommended

SCAM Category

78

Order a free annual credit report once every four months, one from each of the three credit reporting agencies and have errors removed. As a minimum order a free annual credit report least once per year and only use www.AnnualCreditReport.com to order free - no other site!

Credit Reports

29

Check

79

Reconcile all bank, billing, utility, and credit card statements as soon as possible to ensure all charges are yours and scrutinize for unauthorized use

Account and Personal Information Protection

91

Stingy

80

Monitor your mail to ensure your bills arrive on time, are not delayed, and the volume of mail doesn't significantly change; alert any institution as necessary

Trash and Mail

81

Check

81

Continue your education about identity theft, current scams, and take a risk assessment test to determine your identity theft risk

Education

3

Check

82

Ask about identity theft insurance, but be sure to read the fine print

Identity Theft Insurance

2

Ask

83

Take action if you get turned down for credit that you should have received

Account and Personal Information Protection

91

Ask

84

Take action if you receive credit cards that you didn't apply for

Account and Personal Information Protection

91

Maintain

85

Sign up for credit monitoring services

Credit Reports

29

Check

86

Swift notification of stolen credit card

Account and Personal Information Protection

91

Check

87

Take action if you get calls from collectors or merchants on accounts not yours

Account and Personal Information Protection

91

Stingy

88

Request from your financial institution a brochure outlining your level of risk for various types of financial fraud

Account and Personal Information Protection

91

Ask

89

Remember, the government does not endorse any companies

Account and Personal Information Protection

91

Stingy

90

Use two computers if financially possible

Computers and Information Systems

48

Stingy

 

Safeguard Recommendation

No. of Times Each SCAM Category Recommended

Source of Recommendation

Controllable/Partially Controllable

1

Never write your Social Security number on a check, resume, or other document where it is not needed

350

Private Sector

Controllable

2

Never sign the back of your credit card; instead write "Photo ID Required" on the signature line

350

Private Sector

Controllable

3

Safeguard/secure your purse and wallet at home, work, and when out; never leave your wallet or purse in your car

350

Private Sector

Controllable

4

Never leave ATM, Credit, or Debit Cards lying around or lend them to anyone

350

Private Sector

Controllable

5

Consider using a P.O. Box and for your address on printed checks

350

Government

Controllable

6

Use Enhanced tamperproof credit and ID cards when/if available

350

Law Enforcement

Controllable

7

Treat mail and trash carefully: ALWAYS shred/destroy documents with personal information on them before you discard them (i.e., credit/debit/ATM card receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards, any financial mail, and credit offers you get in the mail, etc.) at home and work using a cross-cut shredder; never recycle personally identifying information

350

Private Sector

Controllable

8

Secure your personal information at home and work - use lockable storage, especially if you have roommates, employ outside help or are having work done in your home and do not leave bills, statements, and other personal records with identifying information in plain site

350

Private Sector

Controllable

9

Keep your Social Security Card, accounts, credit cards, checks, bills, personal information, and insurance policies in a safe place

350

Law Enforcement

Controllable

10

When ordering new checks, pick them up from the bank instead of having them mailed to your home mailbox

350

Private Sector

Controllable

 

Safeguard Recommendation

No. of Times Each SCAM Category Recommended

Source of Recommendation

Controllable/Partially Controllable

11

Use unique, unpredictable, complex, and strong passwords on credit, bank, and phone accounts (Do not use: Mother's maiden name, your birth date, the last four digits of your Social Security Number (SSN), your phone number or a series of consecutive number) or use the same password on different accounts

350

Government

Controllable

12

Close accounts no longer intended to be used and destroy remaining checks

350

Private Sector

Controllable

13

Consider using a debit card and stop writing checks

350

Private Sector

Controllable

14

Make sure your employer locks and limits access to personnel records

 

Government

Controllable

15

Carry only the identification, personally identifying information, and credit cards you actually need; don't carry documents like your Social Security card, passport or birth certificate unless you have to in your purse or wallet

350

Private Sector

Controllable

16

Stay on the alert-continually

9

Private Sector

Controllable

17

Keep your hotel key card when you check out, leave a hotel or motel room

350

Private Sector

Controllable

18

Deposit your outgoing mail containing personally identifying information in secure post office collection boxes, at the post office, or in lockable mail boxes at home and work; when you pay bills, don't put them in the mailbox with the flag up

350

Private Sector

Controllable

19

Limit the credit limits and number of credit cards you own and carry (Suggest only two total)

350

Private Sector

Controllable

20

Promptly remove mail from your mailbox after it is delivered

350

Government

Partially Controllable

21

Use purses that close securely

350

Private Sector

Partially Controllable

 

Safeguard Recommendation

No. of Times Each SCAM Category Recommended

Source of Recommendation

Controllable/Partially Controllable

22

Ask to use other identifiers other than your Social Security number on: driver's licenses, health insurance/records, registrations, applications, etc.)

35

Private Sector

Partially Controllable

23

Use caution when around those with financial problems

350

Law Enforcement

Controllable

24

Use direct deposit instead of paper paychecks

350

Private Sector

Controllable

25

Never leave documents such as registrations, insurance papers, driver's licenses, utility bills, or traffic fines, in the car glove box.

350

Government

Controllable

26

Make sure that you fill out checks carefully so that they cannot be altered easily, use an initial instead of your first name, put a line through any unused spaces on checks, and abbreviate account numbers on the memo line if annotated

350

Government

Controllable

27

Never give credit card, bank, Social Security, sensitive, personal, account, or credit/debit card information over the phone, through e-mail, over the internet, on order forms, warranty forms, and registration forms unless necessary to complete a transaction; verify who you are communicating, ensure you made the contact first, and ask that written information be sent

350

Private Sector

Controllable

28

Only use guaranteed ID authentication services (e.g. Microsoft Passport)

350

Private Sector

Partially Controllable

29

If you're planning to be away from home and can't pick up your mail, contact the U.S. Postal Service at 1-800-275-8777 or online at www.usps.gov, to request a vacation hold; inform trusted neighbors when you are traveling to remove any packages that might be delivered to your home

350

Private Sector

Controllable

30

Set operating system to automatically run protective scans

350

Government

Controllable

 

Safeguard Recommendation

No. of Times Each SCAM Category Recommended

Source of Recommendation

Controllable/Partially Controllable

31

Never carry your military ID in your wallet

350

Private Sector

Partially Controllable

32

Never send personal data such as credit card numbers in a regular e-mail

350

Private Sector

Partially Controllable

33

Never give out your Social Security number unless it is absolutely necessary

350

Private Sector

Controllable

34

Acquire/use a program that will ask you to change your password regularly and will shut down your computer after a set time if not accomplished

350

Private Sector

Controllable

35

Find out who has access to your personal information, and verify that it is handled securely

350

Private Sector

Partially Controllable

36

Ask about information security procedures and privacy policies in your workplace or at businesses, doctor’s offices or other institutions that collect your personal identifying information; avoid businesses that don't have adequate safeguards or disposal procedures to protect your personal information and always ask why your information is needed and how it is going to be used; ensure your employer has security in place to guard against strangers wandering around the workplace

35

Private Sector

Partially Controllable

37

Start by adopting a "need to know" approach to your personal data

350

Government

Controllable

38

Use traveler's checks instead of personal bank checks

9

Private Sector

Controllable

39

Memorize and protect your Social Security number, passwords and Personal Identification Numbers (PINs) and never write them down, give or verify a password with anyone you didn't contact first

350

Private Sector

Controllable

40

Shroud passwords and PINs when using ATMs with credit, debit, or other account access cards

350

Law Enforcement

Controllable

 

Safeguard Recommendation

No. of Times Each SCAM Category Recommended

Source of Recommendation

Controllable/Partially Controllable

41

Never carry the PIN for your ATM card in your purse or wallet

350

Government

Controllable

42

If Passwords are ever written down or stored on a computer, secure them thoroughly

350

Private Sector

Controllable

43

Talk with your kids about cautions when using the computer online

35

Law Enforcement

Controllable

44

Be careful about using file-sharing programs

350

Private Sector

Partially Controllable

45

Try not to store financial information on your laptop unless absolutely necessary

350

Private Sector

Partially Controllable

46

Never use the automatic log-in feature when on the Internet

350

Law Enforcement

Controllable

47

Limit number of persons with access to databases; do not allow remote access and make sure databases are password protected

350

Law Enforcement

Partially Controllable

48

Maintain careful records of your financial accounts for at least a year

9

Private Sector

Controllable

49

Be alert if you get a call anyone asking you to "verify" / "update your records" or get calls about purchases you did not make

350

Law Enforcement

Controllable

50

Use Pre-paid calling cards for pay phones

350

Government

Controllable

51

Review all applications that you put personal information on - verify using the Better Business Bureau (BBB)

350

Law Enforcement

Controllable

52

Use a secure browser

9

Government

Controllable

53

Always "log out" of Web sites

350

Private Sector

Controllable

54

Use a separate account for purchases made by telephone or on the internet with as low a credit limit as possible

350

Private Sector

Controllable

55

If you're hospitalized, tell your doctor or nurse to safeguard your chart

350

Government

Controllable

56

Make sure your mailbox is large enough to accept and hold mail in the quantity and size you normally get

350

Private Sector

Controllable

 

Safeguard Recommendation

No. of Times Each SCAM Category Recommended

Source of Recommendation

Controllable/Partially Controllable

57

"Opt out" of information sharing and prescreened offers of credit, junk mail, and telemarketing offers, Call the credit reporting industry to stop credit card and insurance solicitations from coming to your home to include "teaser rate" convenience checks

350

Private Sector

Controllable

58

Avoid saving important data on your computer - save to a secure disk

350

Government

Controllable

59

Never use public computers to access your private information

350

Private Sector

Controllable

60

Put a security freeze/fraud alert on your credit report and renew it every 90 days

42

Private Sector

Partially Controllable

61

Speak softly when giving out personal information in public; if you have to give out personal information over a phone, use a telephone booth where you can close the door and speak softly at all times

350

Private Sector

Controllable

62

Only conduct transactions with secure websites by checking the Web site address to make sure it's the official and not a bogus Web address (Pay bills and give out credit card information with caution) - Be suspicious of official-looking e-mail from banks or credit card companies and know the signs of a secure Web site ("lock" icon and https://). Calling the customer service number is another way to verify legitimacy and look for Web site privacy policies

350

Government

Partially Controllable

63

Use and keep updated the latest suite of protection software (Virus, Spyware, firewall, operating system patches, etc.)

350

Private Sector

Controllable

64

Unsolicited offers that seem too good to be true or that require you to give out bank account or other personal information are likely to be scams

350

Government

Controllable

65

Delete temporary internet files on a regular basis

350

Government

Controllable

 

Safeguard Recommendation

No. of Times Each SCAM Category Recommended

Source of Recommendation

Controllable/Partially Controllable

66

Consider using a pre-loaded cash card when traveling

350

Private Sector

Controllable

67

Be cautious when responding to promotional offers and disclosing personal information; Be suspicious of anyone who calls or sends you an email requesting personal information to “verify” who you are so they can give you a "prize" or "lottery" winnings or when things don't seem right

350

Government

Partially Controllable

68

Do not click on "unsubscribe links" unless you know the company is valid

350

Private Sector

Controllable

69

Try to avoid using wireless connection when viewing financial data online

350

Private Sector

Controllable

70

Do not respond to "pop-up" Ads or "warnings" that pop up and ask if you want your computer scanned for viruses unless you know the source

350

Private Sector

Controllable

71

Before you dispose of a computer, delete all the personal information use a "wipe" program or remove the hard drive

350

Government

Controllable

72

Avoid using ATMs that appear to be tampered with or are located in unlit places

350

Private Sector

Controllable

73

Never click on links, open files or attachments sent in unsolicited emails unless you verify it is from a trusted source

350

Private Sector

Partially Controllable

74

Do not open files sent to you by strangers, click on hyperlinks, download programs from people you don't know, or download files/software from strangers in unsolicited e-mails

350

Private Sector

Partially Controllable

75

Never keep your computer "on-line" twenty-four hours a day

350

Private Sector

Controllable

76

Use one credit card for online purchases

350

Private Sector

Controllable

77

Remove your information from "who's who" guides

350

Private Sector

Controllable

 

Safeguard Recommendation

No. of Times Each SCAM Category Recommended

Source of Recommendation

Controllable/Partially Controllable

78

Order a free annual credit report once every four months, one from each of the three credit reporting agencies and have errors removed. As a minimum order a free annual credit report least once per year and only use www.AnnualCreditReport.com to order free - no other site!

42

Private Sector

Controllable

79

Reconcile all bank, billing, utility, and credit card statements as soon as possible to ensure all charges are yours and scrutinize for unauthorized use

350

Government

Controllable

80

Monitor your mail to ensure your bills arrive on time, are not delayed, and the volume of mail doesn't significantly change; alert any institution as necessary

42

Law Enforcement

Partially Controllable

81

Continue your education about identity theft, current scams, and take a risk assessment test to determine your identity theft risk

42

Law Enforcement

Partially Controllable

82

Ask about identity theft insurance, but be sure to read the fine print

35

Law Enforcement

Controllable

83

Take action if you get turned down for credit that you should have received

35

Government

Controllable

84

Take action if you receive credit cards that you didn't apply for

9

Law Enforcement

Controllable

85

Sign up for credit monitoring services

42

Private Sector

Controllable

86

Swift notification of stolen credit card

42

Private Sector

Controllable

87

Take action if you get calls from collectors or merchants on accounts not yours

350

Private Sector

Controllable

88

Request from your financial institution a brochure outlining your level of risk for various types of financial fraud

35

Private Sector

Partially Controllable

89

Remember, the government does not endorse any companies

350

Law Enforcement

Controllable

90

Use two computers if financially possible

350

Private Sector

Partially Controllable

Appendix BB Hierarchy of Effective Identity Theft Safeguards

Safeguard Recommendation

Safeguard Prevention Category

1. Never write your Social Security number on a check, resume, or other document where it is not needed

Social Security Number

2. Never sign the back of your credit card instead write “photo ID Required”

Account and Personal Information Protection

3. Safeguard/secure your purse and wallet at home, work, and when out; never leave your wallet or purse in your car

Purse and Wallet

4. Never leave ATM, Credit, or Debit Cards lying around or lend them to anyone

Account and Personal Information Protection

5. Consider using a P.O. Box and for your address on printed checks

Trash and Mail

6. Use Enhanced tamperproof credit and ID cards when/if available

Physical Security of Personal Information

7. Treat mail and trash carefully: ALWAYS shred/destroy documents with personal information on them before you discard them (i.e., credit/debit/ATM card receipts, copies of credit applications, insurance forms, physician statements, checks and bank statements, expired charge cards, any financial mail, and credit offers you get in the mail, etc.) at home and work using a cross-cut shredder; never recycle personally identifying information

Trash and Mail

8. Secure your personal information at home and work - use lockable storage, especially if you have roommates, employ outside help or are having work done in your home and do not leave bills, statements, and other personal records with identifying information in plain site

Physical Security of Personal Information

9. Keep your Social Security Card, accounts, credit cards, checks, bills, personal information, and insurance policies in a safe place

Physical Security of Personal Information

Safeguard Recommendation

Safeguard Prevention Category

10. When ordering new checks, pick them up from the bank instead of having them mailed to your home mailbox

Trash and Mail

11. Use unique, unpredictable, complex, and strong passwords on credit, bank, and phone accounts (Do not use: Mother's maiden name, your birth date, the last four digits of your Social Security Number (SSN), your phone number or a series of consecutive number) or use the same password on different accounts

Passwords

12. Close accounts no longer intended to be used and destroy remaining checks

Account and Personal Information Protection

13. Consider using a debit card and stop writing checks

Account and Personal Information Protection

14. Make sure your employer locks and limits access to personnel records

Account and Personal Information Protection

15. Carry only the identification, personally identifying information, and credit cards you actually need; don't carry documents like your Social Security card, passport or birth certificate unless you have to in your purse or wallet

Purse and Wallet

16. Stay on the alert-continually

Account and Personal Information Protection

17. Keep your hotel key card when you check out, leave a hotel or motel room

Physical Security of Personal Information

18. Deposit your outgoing mail containing personally identifying information in secure post office collection boxes, at the post office, or in lockable mail boxes at home and work; when you pay bills, don't put them in the mailbox with the flag up

Trash and Mail

19. Limit the credit limits and number of credit cards you own and carry (Suggest only two total)

Account and Personal Information Protection

20. Promptly remove mail from your mailbox after it is delivered

Trash and Mail

Safeguard Recommendation

Safeguard Prevention Category

21. Use purses that close securely

Purse and Wallet

22. Ask to use other identifiers other than your Social Security number on: driver's licenses, health insurance/records, registrations, applications, etc.)

Social Security Number

23. Use caution when around those with financial problems

Account and Personal Information Protection

24. Use direct deposit instead of paper paychecks

Account and Personal Information Protection

25. Never leave documents such as registrations, insurance papers, driver's licenses, utility bills, or traffic fines, in the car glove box.

Physical Security of Personal Information

26. Make sure that you fill out checks carefully so that they cannot be altered easily, use an initial instead of your first name, put a line through any unused spaces on checks, and abbreviate account numbers on the memo line if annotated

Account and Personal Information Protection

27. Never give credit card, bank, Social Security, sensitive, personal, account, or credit/debit card information over the phone, through e-mail, over the internet, on order forms, warranty forms, and registration forms unless necessary to complete a transaction; verify who you are communicating, ensure you made the contact first, and ask that written information be sent

Account and Personal Information Protection

28. Only use guaranteed ID authentication services (e.g. Microsoft Passport)

Passwords

29. If you're planning to be away from home and can't pick up your mail, contact the U.S. Postal Service at 1-800-275-8777 or online at www.usps.gov, to request a vacation hold; inform trusted neighbors when you are traveling to remove any packages that might be delivered to your home

Trash and Mail

Safeguard Recommendation

Safeguard Prevention Category

30. Set operating system to automatically run protective scans

Computers and Information Systems

31. Never carry your military ID in your wallet

Physical Security of Personal Information

32. Never send personal data such as credit card numbers in a regular e-mail

Internet and E-mail

33. Never give out your Social Security number unless it is absolutely necessary

Social Security Number

34. Acquire/use a program that will ask you to change your password regularly and will shut down your computer after a set time if not accomplished

Passwords

35. Find out who has access to your personal information, and verify that it is handled securely

Account and Personal Information Protection

36. Ask about information security procedures and privacy policies in your workplace or at businesses, doctor’s offices or other institutions that collect your personal identifying information; avoid businesses that don't have adequate safeguards or disposal procedures to protect your personal information and always ask why your information is needed and how it is going to be used; ensure your employer has security in place to guard against strangers wandering around the workplace

Account and Personal Information Protection

37. Start by adopting a "need to know" approach to your personal data

Account and Personal Information Protection

38. Use traveler's checks instead of personal bank checks

Account and Personal Information Protection

39. Memorize and protect your Social Security number, passwords and Personal Identification Numbers (PINs) and never write them down, give or verify a password with anyone you didn't contact first

Passwords

Safeguard Recommendation

Safeguard Prevention Category

40. Shroud passwords and PINs when using ATMs with credit, debit, or other account access cards

Passwords

41. Never carry the PIN for your ATM card in your purse or wallet

Passwords

42. If Passwords are ever written down or stored on a computer, secure them thoroughly

Passwords

43. Talk with your kids about cautions when using the computer online

Computers and Information Systems

44. Be careful about using file-sharing programs

Computers and Information Systems

45. Try not to store financial information on your laptop unless absolutely necessary

Computers and Information Systems

46. Never use the automatic log-in feature when on the Internet

Computers and Information Systems

47. Limit number of persons with access to databases; do not allow remote access and make sure databases are password protected

Computers and Information Systems

48. Maintain careful records of your financial accounts for at least a year

Account and Personal Information Protection

49. Be alert if you get a call anyone asking you to "verify" / "update your records" or get calls about purchases you did not make

Account and Personal Information Protection

50. Use Pre-paid calling cards for pay phones

Account and Personal Information Protection

51. Review all applications that you put personal information on - verify using the Better Business Bureau (BBB)

Account and Personal Information Protection

52. Use a secure browser

Computers and Information Systems

53. Always "log out" of Web sites

Internet and E-mail

54. Use a separate account for purchases made by telephone or on the internet with as low a credit limit as possible

Account and Personal Information Protection

Safeguard Recommendation

Safeguard Prevention Category

55. If you're hospitalized, tell your doctor or nurse to safeguard your chart

Account and Personal Information Protection

56. Make sure your mailbox is large enough to accept and hold mail in the quantity and size you normally get

Trash and Mail

57. "Opt out" of information sharing and prescreened offers of credit, junk mail, and telemarketing offers, Call the credit reporting industry to stop credit card and insurance solicitations from coming to your home to include "teaser rate" convenience checks

"Opt Out" of Information Sharing Agreements

58. Avoid saving important data on your computer - save to a secure disk

Computers and Information Systems

59. Never use public computers to access your private information

Computers and Information Systems

60. Put a security freeze/fraud alert on your credit report and renew it every 90 days

Credit Reports

61. Speak softly when giving out personal information in public; if you have to give out personal information over a phone, use a telephone booth where you can close the door and speak softly at all times

Account and Personal Information Protection

62. Only conduct transactions with secure websites by checking the Web site address to make sure it's the official and not a bogus Web address (Pay bills and give out credit card information with caution) - Be suspicious of official-looking e-mail from banks or credit card companies and know the signs of a secure Web site ("lock" icon and https://). Calling the customer service number is another way to verify legitimacy and look for Web site privacy policies

Internet and E-mail

63. Use and keep updated the latest suite of protection software (Virus, Spyware, firewall, operating system patches, etc.)

Computers and Information Systems

Safeguard Recommendation

Safeguard Prevention Category

64. Unsolicited offers that seem too good to be true or that require you to give out bank account or other personal information are likely to be scams

Account and Personal Information Protection

65. Delete temporary internet files on a regular basis

Internet and E-mail

66. Consider using a pre-loaded cash card when traveling

Physical Security of Personal Information

67. Be cautious when responding to promotional offers and disclosing personal information; Be suspicious of anyone who calls or sends you an email requesting personal information to “verify” who you are so they can give you a "prize" or "lottery" winnings or when things don't seem right

Account and Personal Information Protection

68. Do not click on "unsubscribe links" unless you know the company is valid

Internet and E-mail

69. Try to avoid using wireless connection when viewing financial data online

Computers and Information Systems

70. Do not respond to "pop-up" Ads or "warnings" that pop up and ask if you want your computer scanned for viruses unless you know the source

Internet and E-mail

71. Before you dispose of a computer, delete all the personal information use a "wipe" program or remove the hard drive

Computers and Information Systems

72. Avoid using ATMs that appear to be tampered with or are located in unlit places

Computers and Information Systems

73. Never click on links, open files or attachments sent in unsolicited emails unless you verify it is from a trusted source

Internet and E-mail

74. Do not open files sent to you by strangers, click on hyperlinks, download programs from people you don't know, or download files/software from strangers in unsolicited e-mails

Computers and Information Systems

Safeguard Recommendation

Safeguard Prevention Category

75. Never keep your computer "on-line" twenty-four hours a day

Computers and Information Systems

76. Use one credit card for online purchases

Account and Personal Information Protection

77. Remove your information from "who's who" guides

Account and Personal Information Protection

78. Order a free annual credit report once every four months, one from each of the three credit reporting agencies and have errors removed. As a minimum order a free annual credit report least once per year and only use www.AnnualCreditReport.com to order free - no other site!

Credit Reports

79. Reconcile all bank, billing, utility, and credit card statements as soon as possible to ensure all charges are yours and scrutinize for unauthorized use

Account and Personal Information Protection

80. Monitor your mail to ensure your bills arrive on time, are not delayed, and the volume of mail doesn't significantly change; alert any institution as necessary

Trash and Mail

81. Continue your education about identity theft, current scams, and take a risk assessment test to determine your identity theft risk

Education

82. Ask about identity theft insurance, but be sure to read the fine print

Identity Theft Insurance

83. Take action if you get turned down for credit that you should have received

Account and Personal Information Protection

84. Take action if you receive credit cards that you didn't apply for

Account and Personal Information Protection

85. Sign up for credit monitoring services

Credit Reports

Safeguard Recommendation

Safeguard Prevention Category

86. Swift notification of stolen credit card

Account and Personal Information Protection

87. Take action if you get calls from collectors or merchants on accounts not yours

Account and Personal Information Protection

88. Request from your financial institution a brochure outlining your level of risk for various types of financial fraud

Account and Personal Information Protection

89. Remember, the government does not endorse any companies

Account and Personal Information Protection

90. Use two computers if financially possible

Computers and Information Systems

Appendix CC Acronyms

AARP American Association of Retired Persons

BBB Better Business Bureau

CMC Consumers Measures Committee

COPS Community Oriented Policing Services

CRC Consumer Response Center

CY Calendar Year

DMA Direct Marketing Association

DMV Department of Motor Vehicles

FCIC Federal Citizen Information Center

FCRA Fair Credit Reporting Act

FTC Federal Trade Commission

iS3 International Software Systems Solutions

NCL National Consumers League

NCP National Crime Prevention

NCVS National Crime Victimization Survey

NIJ National Institute of Justice

SCAM Stingy, Check, Ask, Maintain

SS Secret Service

USDOJ United States Department of Justice

USPS United States Postal Service

WCSRM Web Center for Social Research Methods

Distribution of Identity Theft Safeguards From List #1

(Appendix V)

0.00

2.50

5.00

7.50

10.00

12.50

15.00

17.50

1591317212529333741454953576165697377818589

Recommended Safeguard

Weighted Value

Distribution of Identity Theft Safeguards From List #1

(Appendix V)

0.00

2.50

5.00

7.50

10.00

12.50

15.00

17.50

1591317212529333741454953576165697377818589

Recommended Safeguard

Weighted Value

Distribution of Identity Theft Safeguards From List #1

(Appendix V)

0.00

2.50

5.00

7.50

10.00

12.50

15.00

17.50

1591317212529333741454953576165697377818589

Recommended Safeguard

Weighted Value

Distribution of Identity Theft Safeguards From List #1

(Appendix V)

0.00

2.50

5.00

7.50

10.00

12.50

15.00

17.50

1591317212529333741454953576165697377818589

Recommended Safeguard

Weighted Value

Distribution of Identity Theft Safeguards From List #2

(Appendix W)

0.00

2.50

5.00

7.50

10.00

12.50

15.00

17.50

1591317212529333741454953576165697377818589

Recommended Safeguard

Weighted Value

Distribution of Identity Theft Safeguards From List #2

(Appendix W)

0.00

2.50

5.00

7.50

10.00

12.50

15.00

17.50

1591317212529333741454953576165697377818589

Recommended Safeguard

Weighted Value

Distribution of Identity Theft Safeguards from Weighted Means Test

(See Master Spreadsheet - Appendix AA; Column W)

0.00

5.00

10.00

15.00

20.00

1591317212529333741454953576165697377818589

Recommended Safeguard

Weighted Value

Distribution of Identity Theft Safeguards by Category

0.00

2.00

4.00

6.00

8.00

10.00

12.00

14.00

16.00

18.00

1

5

9

13

17

21

25

29

33

37

41

45

49

53

57

61

65

69

73

77

81

85

89

Recommended Safeguard

Weighted Average

Distribution of Identity Theft Safeguards by Category

0.00

2.00

4.00

6.00

8.00

10.00

12.00

14.00

16.00

18.00

1

5

9

13

17

21

25

29

33

37

41

45

49

53

57

61

65

69

73

77

81

85

89

Recommended Safeguard

Weighted Average

Number of Times Each SCAM Category

Recommended

9

350

42

35

0

100

200

300

400

StingyCheckAskMaintain

SCAM Category

Number of Single

Recommendations

Number of Times Each SCAM Category

Recommended

9

350

42

35

0

100

200

300

400

StingyCheckAskMaintain

SCAM Category

Number of Single

Recommendations

Number of Times Each of 12 Main IdentityTheft Categories Recommended

81

48

40

3333

31

29

28

17

3

2

91

0

20

40

60

80

100

120

Account and

Personal

Information

Protection

Trash and

Mail

Computers

and

Information

Systems

Passwords

Purse and

Wallet

Social

Security

Number

Physical

Security of

Personal

Information

Credit

Reports

Internet and

E-mail

"Opt Out" of

Information

Sharing

Agreements

Education

Identity Theft

Insurance

Category of Identity Prevention

Number of Single

Recommendations

Number of Times Each of 12 Main IdentityTheft Categories Recommended

81

48

40

3333

31

29

28

17

3

2

91

0

20

40

60

80

100

120

Account and

Personal

Information

Protection

Trash and

Mail

Computers

and

Information

Systems

Passwords

Purse and

Wallet

Social

Security

Number

Physical

Security of

Personal

Information

Credit

Reports

Internet and

E-mail

"Opt Out" of

Information

Sharing

Agreements

Education

Identity Theft

Insurance

Category of Identity Prevention

Number of Single

Recommendations

Means of Identity Theft

(Javelin Strategy, 2006)

A.      Lost or stolen

wallet, checkbook, or

credit card (30.0%)

B.      By friends,

acquaintances,

relatives, or in-home

employees (15.0%)

C.      From stolen

paper mail or by

fraudulent change of

address (8.0%)

D.      Computer

viruses, spyware, or

hackers (5.0%)

E.       Phishing (3.0%)

F.       Garbage (1%)

G.      Online

transactions (0.3%)

H.      Taken by a

corrupt business

employee (15.0%)

J.        Stolen from a

company that handles

your financial data

(6.0%)

I.        Misuse of data

from an in-

store/online/telephone

transaction (7.0%)

Means of Identity Theft

(Javelin Strategy, 2006)

A.      Lost or stolen

wallet, checkbook, or

credit card (30.0%)

B.      By friends,

acquaintances,

relatives, or in-home

employees (15.0%)

C.      From stolen

paper mail or by

fraudulent change of

address (8.0%)

D.      Computer

viruses, spyware, or

hackers (5.0%)

E.       Phishing (3.0%)

F.       Garbage (1%)

G.      Online

transactions (0.3%)

H.      Taken by a

corrupt business

employee (15.0%)

J.        Stolen from a

company that handles

your financial data

(6.0%)

I.        Misuse of data

from an in-

store/online/telephone

transaction (7.0%)