Home > Financial Services Information Security Tips > Security Architecture Insider > How to build Web application security into your mobile banking policy
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

How to build Web application security into your mobile banking policy


Judith Myerson, Contributor
11.11.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Today's threats are growing in size and complexity as more mobile devices are used to check bank balances or execute simple transfers, exchange email that contains sensitive information or store confidential documents. Most banks develop a password policy to protect Web applications on these mobile devices. The reality is that this is not enough.

Web applications associated with mobile banking are under threat from a variety of sources, such as: loss or theft of the mobile device resulting in exposure of data, interception of sensitive data that passes over Wi-Fi or a 3G network, capture of data via Bluetooth connections and mobile viruses.

The goal of a Web application security policy is to find or intercept these threats before they fully exploit the vulnerabilities and to maintain balance between consumer convenience and heavy-duty security. To achieve this, financial services should work through the following steps before a Web application is released to end users.

Review security policies to ensure they are specific to already-installed Web applications and adequately govern the use of mobile devices on the network. These policies must be enforced technologically and are dependent on user compliance. Do not apply generic security policies.

Review software life cycle documents in all phases to ensure planned Web applications have met security requirements and that their


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Architecture Insider
Winning the war: Personal information protection
Why financials must implement Web application security best practices
Identity management for financial firms in turbulent times
Identity management for financial firms in turbulent times
How to use data loss prevention tools to stop data exfiltration
Security questions to ask SaaS vendors when outsourcing services
Book chapter: Remote deposit capture risks
How to communicate the value of security controls for online transactions
How to perform a network device audit
Emerging themes in identity access management

Mobile device security in financial institutions
Study reveals lack of financial wireless computer security
Secure communications
Security on the street with SearchFinancialSecurity.com: Mobile banking
Out-of-band authentication: Methods for preventing fraud
Policies for reducing mobile risk
Virus onslaught sickens smartphones
BlackBerry flaw highlights growing mobile device risks
Mobile device security in six simple steps

Emerging attacks to financial institutions
Download presentations from Financial Information Security Decisions 2009
Man pleads guilty in online banking hacking scam
Banks using Twitter need to proceed with caution, experts say
ATM malware used in Russia lets attackers control machines
Infected bank computers part of massive botnet, Finjan says
Financial services hit hard by data breaches, Verizon finds
Study: banking Trojans dynamic, insidious
Credit unions confirm new processor credit card breach
Three men arrested in connection with Heartland breach
FBI investigates coordinated ATM scam

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


threat vulnerability analysis has been updated. Ensure application design evaluation has been adequately conducted.

Conduct a pilot study by testing Web application security in a sample portion of a mobile banking system. This will help security managers to solve any potential technological and user compliance problems before conducting the test on a large scale, as well as determine what education and training the testers will need to solve unusual anomalies. Without proper training and education, finding or stopping the threats before they exploit the application vulnerabilities can be difficult.

As part of the study, perform the following steps to ensure the application security policy is adequate. This process can be repeated within any step to fix inherent problems.

Protecting Web applications within banking mobility can be a challenge for a financial services firm. Developing the policy to protect them can make the job easier and keep data safer.

About the author:
Judith M. Myerson is a Systems Architect and Engineer and Enterprise System Integration consultant. Her areas of interest include middleware technologies, enterprise-wide systems, database technologies, application development, network management, computer security, information assurance, financial RFID technologies and project management. She can be reached at jmyerson@verizon.com.


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts