Security and IT Audit & Control Resources
 
Title
Download or site
Start your morning with a cup of java and....Computer Security Resource Center (NIST CRSC) The Computer Security Division (CSD) - (893) is one of eight divisions within NIST's Information Technology Laboratory. Among many significant areas of focus and contribution, they provide guidance to increase secure IT planning, implementation, management and operation.
SANS Institute - Computer Security Education and Information Security Training http://www.sans.org/
Gentoo Linux Gentoo Linux Security Audit Project http://www.gentoo.org

Network Security Audit (Linux)

http://www.linuxsecurity.com
The Institute of Internal Auditors http://www.theiia.org/itaudit/
National Institute of Standards and Technology http://www.nist.gov/
Electronic and Digital Signatures A Global Status Report digitalsignatures.pdf
Audit Risk; Proposed International Standards on Auditing; AND Proposed Amendment to ISA 200 "Objective and Principles Governing an Audit of Financial Statements" IFAC ED-Audit_Risk_Oct021.pdf
NSA's Central Security Service Division of the System and Network Attack Center (SNAC) Security Configuration Guides
FFIEC Federal Financial Institutions Examination Council (FFIEC)'s IT Examination Handbook http://www.ffiec.gov/ffiecinfobase/
The primary mission of the U.S. Securities and Exchange Commission (SEC) is to protect investors and maintain the integrity of the securities markets. http://www.sec.gov/index.htm
Understanding the Layers of Wireless LAN Security & Management Understanding the Layers of Wireless...
BITPIPE 38 White Papers on standard 802.11 802.11
Protecting Against Wireless Threats Protecting against Wireless Threats
Do you know how to successfully implement a wireless network? Sign up for Certified Wireless Network Professional Certified Wireless Network Professional
NIST 800-30 Risk Management Guide for Information Technology Systems NIST 800-30
Sound Practices for Mgmt & Supervision of Operational Risk http://www.bis.org/publ/bcbs96.pdf
Common Sense Guide for Home and Individual Users (Internet Security Alliance) http://www.isalliance.org
StaySafeOnline (FTC/NCSA) -- Top 10 Security Tips, Security Test, educational materials, more. http://www.staysafeonline.info/
FTC Consumer and Business Education

FTC Consumer and Business Education

Cybersecurity and Consumer Data: What's at Risk for the Consumer? -- Prepared statement of the Federal Trade Commission (FTC) before the Commerce, Trade & Consumer Protection Subcommittee, Committee on Energy & Commerce, U.S. House of Representatives, November 19, 2003 Cybersecurity and Consumer...
Cyber-Safety for Everyone: From Kids to Elders

Cyber-Safety for Everyone: From Kids to Elders

 

Internet & Computer Ethics for Kids; (and Parents & Teachers Who Haven't Got a Clue.) - Winn Schwartau & D.L. Busch http://www.amazon.com
Top Ten Security Steps for Kids

Top Ten Security Steps for Kids

Security Procedures for Educators

Security Procedures for Educators

REPORTING FRAUD:  THIS AREA NEGLECTED TO PROVIDE PROPER ATTRIBUTION and is corrected today November 4th.  Please accept our apology Les Henderson

The intent in listing this area is to point to important resources that any auditor would benefit by insuring their clients are made aware of there existence.

Courtesy of Crimes of Persuasion: Schemes, Scams, Frauds. www.crimes-of-persuasion.com

U.S. Reporting Agencies

Federal Trade Commission - Know Fraud Complaint Form

The FTC also receives over 10,000 individual pieces of spam every day from irate consumers who forward the deceptive e-mail to them at uce@ftc.gov 

Internet Fraud Complaint Center - FBI backed site for online fraud reporting. Being renamed the Internet Crime Complaint Center

Individuals who suspect possible corporate fraud may report suspicious activity to the FBI in Washington, DC, via a toll-free Corporate Fraud Hotline. The number is (888) 622- 0117. The Hotline is manned Monday through Friday 9 a.m. to 5 p.m. by FBI analysts.

The FBI also has a terrorist tip line which has been extended to include other serious crimes.

They have received over 600,000 tips from around the globe.  Initially, almost 100% of the tips received were related to the terrorist attacks; however, now approximately 45% of all tips received are related to almost every other FBI criminal program, e.g., drug trafficking, organized crime, money laundering, pyramid schemes, child pornography, fugitives, bank robbery.

The operation is completely automated and paperless.  Submitted tips are received immediately, reviewed within minutes and prioritized by trained Professional Support personnel.

Cross-Border E-Commerce Purchase Complaint Form - FTC initiated international effort ( econsumer.gov )

USPS Mail Fraud Complaint Form - use if the mail system has been part of the fraud. (solicitations, mailed payments, etc.) You can also Email for a postal fraud complaint form.

Securities Exchange Commission - U.S. investment scams

Securities Exchange Commission - e-mail Prime Bank complaints.

National Association of Securities Dealers  - U.S. investment scams by members.

State Securities Regulators - U.S. investment scams / state links. 

North American Securities Commissions ( Canada, U.S., Mexico )

If you have been victimized by one of the Nigerian Advance Fee schemes, please forward appropriate written documentation to the 

United States Secret Service,  Financial Crimes Division,  950 H Street, NW,   Washington, DC 20001, or telephone (202) 406-5850  fax: (202) 406-8203

You can report this crime online to the U.S. Treasury Department  Secret Service ( Nigerian Frauds )  e-mail  

A list of local Field Offices for the Secret Service.

If you receive such a letter in the mail send it along to: Inspection Service Operations Support Group Two Gateway Center, 9th Floor Newark, NJ 07175-0001   If you have somehow reached the stage of meeting with Nigerian scammers in the United States for collection of the marked currency and need to Locate an FBI field office.

National Consumers League - Fraud.org - Info placed in database accessible by law enforcement.  1-800-876-7060

Better Business Bureau - Directs you to specific branches for primarily consumer complaints.

eBay Auction Fraud Department: this is the mailing address

IRONY - IS THIS FRAUD?  I've disable the link and included the address in brackets.  Government reporting site  says "American Internet Investigators - Originating from Australia, this volunteer organization consists of only "sworn police officers" who take in complaints, no matter how trivial, and try to supply you with the appropriate reporting agency." The source code states we will be directed to <https://www.datastar.net/secure/unitedstates-investigators/testform.htm> But we land at an advertisement for https://www.datastar.net/solutions.htm services... BOOO HISSSS, I hate this kind of thing.

For complaints of a "civil" nature they generally advise you to consult with your attorney, but if it has a criminal element and occurs within a member's jurisdiction they can and do prosecute, otherwise you are pointed elsewhere.

Florida's Attorney General Charlie Crist has a 1-866-No-Scam hotline.

National Fraud Information Center - Incident Report Form (Due to the obscurity of the IP address I used "view source before sending in a report.  I also checked the linked pages and ran a whois on the IP address. The whois brought back nothing, but I feel the form is legitimate.  If anyone finds this is not the case, please call our office right away so we can delete this link and report them as fraud.)

Get the Taxman After the Conman

Did the scammer report your losses as income or did they hide it somewhere? If you suspect any tax fraud activity, you can report it to the Internal Revenue Service toll free at 800-829-0433.  You may even get a reward by filing a Form 211 with the IRS.

International Reporting Agencies

eConsumer.gov  - Provides information on consumer protection laws in thirteen countries and offer consumers a way to file cross-border e-commerce complaints online.

 

 

sans

news

certpmi

The image above is an example of Available to Public, but not "public domain" .  We asked for legal permission to use the logo and were granted permission in writing by Eric Hayes Intellectual Property Coordinator CERT, Software Engineering Institute Carnegie Mellon University.

Their site links include:

The Software Engineering Institute (SEI) is a federally funded research and development center sponsored by the U.S. Department of Defense and operated by Carnegie Mellon University. AND Copyright 2005 by Carnegie Mellon University Terms of Use

Copyrighted material are exclusive to a third party organization. We are not Carnegie Mellon Software Engineering Institute, and unless Julia Allen or any other brilliant Cert Team writer joins our ranks, it is unlikely we ever will be.

We respectfully suggest they fund and create defining material. We only provide a link to their fully owned and managed domain.

If SEI, NIST, PMI or any other authoring organization removes or modifies their materials, the links to their publications will fail. That is a good thing.

We will do our best to remove dead links.