corrections

profilesony22
sample_for_recommendations.docx

Recommendations & Implementations

“Security Management for Efficient Online Service Delivery from Citibank Group

A research literature review submitted in partial fulfillment of Master’s degree in Computers and Information Systems.

Submitted to

Dr. Asila Sayedi

By

Sravan Kumar Reddy

ID: 515221

California University of Management and Sciences, Virginia.

July 17th 2016

VII. Recommendations and implementations

Protecting the user information and preventing the phishing attempts from various threats across the globe is something which Citibank Group & Co. should constantly keep a track of. Market analysts around the world estimate a loss of $400 Billion each year due to cyber-attacks and moreover the financial firms are attacked more frequently than any other firm in the world. Constant monitoring along with the implementation of new threat-effective technology will help Citibank Group & Co. stay alert and shield itself from cyber-attacks.

With this primary conviction the security risk management approach outlines few necessary requirements for Citibank Group & Co. to consider itself cyber-safe in the web of threats. The constant need to prevent intrusion, protect the sensitive data and secure the transaction system has helped come up with few plans that shield the financial firm from cyber-attacks. (Crossman, 2016).

Plans recommended for Citibank Group & Co. for better security

Security threats can be both internal and external threats. However, the security risk management approach helps come up with few recommendations for Citibank Group & Co. whose implementations need to be strategized.

I. Detecting the intrusion

The online trade of shares and stocks has become the order of the day for the investment bankers. These trades are mostly carried out by the servers which are secured through various protocols. These protocols are easily invaded by hackers around the world when they have access to the primary keys through which these servers are secured. The decrypted server is something which endangers the entire organization and can put an end to the further transactions of the trading world. (Irrera, 2014)

II. Protecting sensitive data

Every trader registered with the bank can trade over NASDAQ scales or NYSE scales. These are generally done through the entry access given by Citibank which have the user ID’s and access control parameters which can help the trade to run smoothly. These ID’s help traders to identify themselves and have access in order to invest or sell the stock. These access names and ID’s can be easily fall into the hands of intruder who phish to get control of all the transaction through impersonating a particular user. Hence there is always a need to protect this sensitive data. (Elliot, 2016)

III. Securing the transaction system

The transaction system is basically the IT hardware and software implemented in order to process all the trading through proper encryption. These transaction systems are the core for all the transactions. This system can be corrupted through malware which affects the transaction system and there by the access to various stock values can be achieved and the entire stock market can be mutilated. This can be a big threat to Citibank and proper implementations need to plan in order to stay secure at times of a malware attack. (Citibank Group & Co., 2016).

Implementation strategy for the recommended plans

The implementation strategy for the recommended plans can be categorized based on the plans themselves. These recommendations can never be settled for as accomplished as time to time work has to be done in developing the existent technology so that future Trojans can have no effect on the present implementations.

I. Preventing the intrusion into the servers

a. Biometric authentication

The users and account holders are provided with various credentials which are required to be kept safe. Most of them are on papers credentials which are safe most of the time but the online credentials are never safe. Hence a need for biometric authentication arises. (Goldstein, Perlroth & Sanger, 2014)

b. Sophisticated trader-dealer digital agreements

The trading over various shared assets occurs from multiple servers across the world. People from all over the world are interested in constant investment in these assets and most of it is online these days. Hence these trades are mostly exposed to these threats. And digital agreements prevent such intrusion. (Titcomb, 2014)

c. Access control and digital alarming devices

The account holders of Citibank have certain authentication data which they have to use at the time of processing a transaction online. These transactions can include anything from a simple transfer of funds between accounts to buying or selling shares over the stock market. When such process is interrupted by foreign attacks and disrupted by the involvement of cyber-threats Citibank must implement the latest technology which aretechnologies which are the digital alarming devices. (Pultarova, 2014)

These devices alert the administrator and the network engineer mainly to realize the existence of a threat and help them act according to the damage expected based on the threat detected.

Along with the implementation of alarming devices the latest technology used by Citibank currently is the access control and authentication restriction through a two factor keying system. This system prevents the entry of any phish into transaction system and its attempt to corrupt the system. (Snider & Johnson, 2014)

II. Protecting sensitive data

a. Investing in data security tools and firms

The investment banking is now a days mostly online and the data is mostly processed through a server -client technology. This technology helps exchange of information over a particular protocol and thus facilitating the need to develop the transmission of online trade over the server protocols. This facility is there by provided by the secure transaction of the bank terminal and can thereby be processed through a secure link of web servers. These servers can be instigated with a defense mechanism through the investment of tools and firms can thereby be selected as a firm secure implementation over the entire organization structure. (American Bankers Association, 2016)

b. Fraud management tools

Fraud can include anything from simple online duplication to creation of false identity which only increases the number of accounts for the firm. But these useless accounts only serve as the loss trackers. This can strictly be avoided when such fraud can be detected. The fraud is mainly due to the phishing attacks attempted by hacker all over the world. Citibank been the biggest investment banking company in world has the highest chance of been affected by these cyber- threats. (Bernard, 2014).

The data duplication is a severe threat and hence fraud management approach helps prevent the existence of fraud accounts.

c. Multiple layers of webbed secure networks

The process of money transfers whether it is investing in a particular or trading for a particular entity over the banks protocol based transaction system is generally a process which has to go through several levels of security. These secure layers are generally bytes of code generated by developers hired by the firm. The IT department takes care of the entire processing and the protocols generated by these developers help enhance the risk measures taken by the organization. (Banking Tech, 2016)

Webbed security layers are implemented in such a way that the highest priority risk which can cause the maximum damage is defended first and the threats are managed based on the priority levels. Multiple web layers ensure secure transaction and thereby facilitating the transaction mechanism with the highest possible security level. (Witty, 2015)

d. Employing trust worthy

The employers within the organization maintain the database of over millions of customers all over the world. The most secure information which identifies the users and their sensitive information which may include the social security numbers, account numbers and other sensitive information which is actually exposed at their disposal. managing such information requires the utmost ethical discipline of the employee as a small change of thought of the employee can result in the collapse of the entire organization. The unethical behavior should strictly be avoided within the organization’s functioning. The complete database is generally secured with utmost encryption which helps secure the information of the users. The trade and commerce of Citibank also depends on the employer’s ethics and the trustworthiness of the employers plays a very critical role in gaining the customer confidence. (Bernstein, 2016)

III. Securing the transaction system

a. Digital certifications

The transaction system is generally accredited by several government agencies which check for its proper functioning. Over and over again these agencies constantly check for the performance and validity of the transaction system and its functioning. With the approval of these agencies the transaction system is generally certified. These certifications are mostly digital these days and the entire transaction system is monitored remotely from various other localities of the firm technical support. (Conference of State Bank Supervisors, n. d.)

Digital certifications like SSL, act as blockers. They help to block sites which have broken links and also prevent any access attempts made through such broken links. (Sheen, 2016)

b. Cyber Insurance

Insurance generally ensures any firms or individuals assurance or future in case of any occurrence of disaster over the period wherein the person or the firm pays the insurance premiums. a similar facility is provided for the all the disasters which occur over the internet. This kind of insurance is called Cyber- insurance and helps ensure restoring of the organization’s assets to the maximum possible extent in an event of cyber-attack. (Morgan Stanley, 2015)

According to Horne (2014), Cyber -insurance nowadays is offered by the federal clients after the 2007 disaster which collapsed the entire US and world economy. United States at least has taken up the task of creating the insurance plans for all the possible disasters possible and helps grant the funds to restore the property. Cyber-insurance however only helps the firm and not the account holders or the users. Hence, it is the responsibility of Citibank to ensure that the maximum funds are restored first to the users or account holders and later on the firm should look into investing in its development and restoring activities.

Cyber Insurance helps the financial firm during times of hacker attacks and in times when the firm faces huge financial losses. (Horne, 2014)

c. Coordination with law enforcement agencies

Coordination with law enforcement agencies helps provide a legal backing to the firm and thereby allowing the federal agencies to take care of the security. The law enforcement agencies take on the monitoring of the transaction system. Citibank when collaborating with these agencies tends to develop a security which will help the firm to attain stability in times of any huge debacles. (McGee, 2014).

The entire turn over loss can be recovered through staying signed in and collaborating with these agencies thus providing the platform to grow and expand with proper back up so that any future trade can be easily processed with federal security. (Luyendijk, 2015).

d. Secure ETF

Roman (2014) stated that ETF stands for Exchange traded funds. These funds are provided by the federal agencies as well as the private organization. Citibank itself has come up with its own elite working on the implementation ETF with its management and services. This helps secure the transaction and all the user and account holder profile. This ensures security and the suffices the need to expand the customer base all over the world. The Pure Funds ISE Cyber Security ETF and First Trust NASDAQ Cybersecurity ETF are the cybersecurity ETF’s available in the market which help to make profit during the cyber-attacks. (Roman, 2014)

References

Adam, J. (2010). Citibank Group SWOT analysis. Free SWOT Analysis. Retrieved from http://www.freeswotanalysis.com/swot-analysis-of-banking-sector/41-j-p-morgan- -co-swot-analysis.

American Bankers Association. (2016). Cybersecurity/Fraud. Retrieved from http://www.aba.com/Tools/Function/Cyber/Pages/default.aspx.

Banking Tech (2016). Cyber security. Retrieved from http://www.bankingtech.com/tag/cybersecurity/

Bernard, S. T. (2014). Ways to protect yourself after the Citibank Grouphacking. The New York Times. Retrieved from http://www.nytimes.com/2014/10/04/your-money/ Citibank - -hack-ways-to-protect-yourself.html

Bernstein, S. (2016). Three steps to improve cyber security. Fraud prevention strategies: Citibank Group Retrieved from https://www.Citibank.com/country/US/EN/cb/preventing-cybercrime

Conference of State Bank Supervisors. (n.d.). Cybersecurity 101.Retrieved from https://www.csbs.org/CyberSecurity/Documents/CSBS%20Cybersecurity%20101%20Resource%20Guide%20FINAL.pdf

Crossman, P. (2016). Are you ready for cyber security challenges of 2016? American Banker. Retrieved from http://www.americanbanker.com/news/bank-technology/are-you-ready-for-the-cybersecurity-challenges-of-2016-1078663-1.html

Di Pietro, B. (2015). Citibank: Managing cyber security and protecting patient data. HFM Magazine. Retrieved from https://www.hfma.org/Content.aspx?id=40650

Elliot, T. (2016). Top 10 challenges for investment banking in 2016. Cyber security: Confronting the threat. Retrieved from https://www.accenture.com/us-en/insight-investment-bank-challenges-confronting-cybersecurity.aspx

Goldstein, M., Perlroth, N. & Sanger, E. D. (2014). Hacker’s attack cracked 10 financial firms in major assault. Deal Book: New York times. Retrieved from http://dealbook.nytimes.com/2014/10/03/hackers-attack-cracked-10-banks-in-major-assault/

Horne, R. (2014). The cyber threat to banking. British Banker’s Association. Retrieved from https://www.bba.org.uk/wp-content/uploads/2014/06/BBAJ2110_Cyber_report_May_2014_WEB.pdf

Irrera, A. (2014). Cyber spooks are in demand at investment banking. The Wall Street Journal. Retrieved from http://blogs.wsj.com/digits/2014/08/05/cyber-spooks-in-demand-at-investment-banks/

Citibank Group (2016). security center. Retrieved from https://www. .com/digital/resources/privacy-security

Citibank Group (2014). Privacy Policy. Retrieved from https://www.Citibank.com/country/US/EN/privacy

Luyendijk, J. (2015). Cyber-attacks could be bigger threat to our banking system than bad debts. The guardian. Retrieved from http://www.theguardian.com/sustainable-business/2015/oct/24/cyber-attacks-could-be-bigger-threat-to-our-banking-system-than-bad-debts

Maverick, B. J. (2016). Analyzing porters five forces on Citibank Group . Investopedia. http://www.investopedia.com/articles/markets/020916/analyzing-porters-five-forces-Citibank- -jpm.asp

Morgan Stanley. (2015). Beyond Firewalls: A new world of cyber security. Retrieved from http://www.morganstanley.com/ideas/Cyber-security-risks-and-opportunities

McGee,S. (2014).JP Morgan data breach: how long can banks live in denial over cyber threats? The Guardian. Retrieved from http://www.theguardian.com/money/us-money-blog/2014/oct/03/jp-morgan-data-breach-banks-state-denial

Pultarova, T. (2014). Citibank Groupsuffers massive data breach despite cyber-security investment. Engineering and Technology magazine. Retrieved from http://eandt.theiet.org/news/2014/oct/jp-morgan-cyber-attack.cfm

Roman, J. (2014), NIST releases cyber security framework. Bank Info Security. Retrieved from http://www.bankinfosecurity.com/nist-releases-cybersecurity-framework-a-6497/op-1

Scanell, K. & Chon, G. (2015). Cyber insecurity: When 95% isn’t good enough. Big Read: Financial Times. Retrieved from http://www.ft.com/intl/cms/s/2/251a40ea-2fcf-11e5-91ac-a5e17d9b4cff.html#axzz45Xt04uao.

Sheen, C. (2016). Identity theft kit, security center. Retrieved from https://www. .com/content/dam/ -ux/documents/digital/resources/identity-theft-kit.pdf

Snider, M. & Johnson, K. (2014). New cyber-attacks on banks very sophisticated. USA Today. Retrieved from http://www.usatoday.com/story/money/business/2014/08/28/Citibank- -bank-hack/14730183/

Source Media (2016). Top 5 security threats banks will face in 2015. American Banker. Retrieved from http://www.americanbanker.com/gallery/top-5-security-threats-banks-will-face-in-2015-1071763-1.html

Titcomb, J. (2014). Could your banks be the next victim of cyber-attack? Banks and Finance: The Telegraph. Retrieved from http://www.telegraph.co.uk/finance/newsbysector/banksandfinance/11170888/Could-your-bank-be-the-next-victim-of-a-cyber-attack.html

Witty, J. (2015). Cyber security state of union. The Private Client Reserve. Retrieved from https://reserve.usbank.com/pcrcp/pdfs/MUC%20transcripts%20and%20handouts/cybersecurity-1-29-15.pdf