<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: COVID-19- WFH- Security Issues in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/COVID-19-WFH-Security-Issues/m-p/34465#M2534</link>
    <description>&lt;P&gt;I think you first need to ask yourselves why the agent working from home is raising new PII concerns.&amp;nbsp; Identifying the underlying reason for concern will help you identify the appropriate mitigation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not trust your agent to have PII access in the first place, you need to consider measures like you are suggesting even when they are in the office.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not trust the house, you need to figure out how to enhance that trust (e.g. send corporate laptops home; use VDI solutions; enable MFA on your corporate mobile-VPN solution; provide corporate network assets; purchase home shredders, etc.).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you can not trust agents to work with less supervision, it is time for staffing changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PII protection is also a concern of risk management, public relations and legal departments.&amp;nbsp; You might consult with them regarding the appropriate protective levels for your organization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 04 Apr 2020 15:50:33 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2020-04-04T15:50:33Z</dc:date>
    <item>
      <title>COVID-19- WFH- Security Issues</title>
      <link>https://community.isc2.org/t5/Tech-Talk/COVID-19-WFH-Security-Issues/m-p/34374#M2514</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope most of you WFH and are safe and secure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a question to get some opinions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for COVID-19 emergency&amp;nbsp; there could be a situation where some changes requested for Agent Desktops to allow Member Service Agents to work from home.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The changes allows the identity to be confirmed without the caller speaking their SSN, DOB, etc... and without the agent being able to view the callers SSN, DOB, etc..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think one of them is OTP.&amp;nbsp;&lt;SPAN&gt;The way the change works involves new APIs that create a 10 digit 1 time password that the caller tells the agent over the phone to confirm the identity&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;any better way of doing it with 2F&amp;nbsp;&lt;/SPAN&gt;authentication&lt;/P&gt;&lt;P&gt;any suggestions /opinions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 15:15:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/COVID-19-WFH-Security-Issues/m-p/34374#M2514</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2020-04-01T15:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: COVID-19- WFH- Security Issues</title>
      <link>https://community.isc2.org/t5/Tech-Talk/COVID-19-WFH-Security-Issues/m-p/34465#M2534</link>
      <description>&lt;P&gt;I think you first need to ask yourselves why the agent working from home is raising new PII concerns.&amp;nbsp; Identifying the underlying reason for concern will help you identify the appropriate mitigation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not trust your agent to have PII access in the first place, you need to consider measures like you are suggesting even when they are in the office.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not trust the house, you need to figure out how to enhance that trust (e.g. send corporate laptops home; use VDI solutions; enable MFA on your corporate mobile-VPN solution; provide corporate network assets; purchase home shredders, etc.).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you can not trust agents to work with less supervision, it is time for staffing changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PII protection is also a concern of risk management, public relations and legal departments.&amp;nbsp; You might consult with them regarding the appropriate protective levels for your organization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 15:50:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/COVID-19-WFH-Security-Issues/m-p/34465#M2534</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2020-04-04T15:50:33Z</dc:date>
    </item>
  </channel>
</rss>

