Title: VERISIGN REPORT
1VERISIGN REPORT THE NEXT STEPSBuilding the
Culture of Internet SecurityEmerging Security
Standards for E- Banking
Marta A. TomovskaCEO, UNETE-society.MkNovembe
r 16, 2006
2Culture of Security Initiative HISTORY
- March 2004 90 of US e-commerce providers block
access from MK IP range. Action started! - December 2004 half of US e-commerce providers
blocked access from MK IP range. USAID engages
VeriSigns Global Security consulting team to
investigate the problem! - March 2005 VeriSign presents the report on the
scale of problem and gives recommendations to
overcome it - Step 1 ISPs - MK ISPs and MarNet
- Step 2 E-presence Companies / Financial
Institutions - MK companies with e-presence (banks, stores,
ISPs) - To encourage adoption of strong authentication
schemes
3Culture of Security InitiativeSECURE INTERNET
TRANSACTIONS
- Q1 How to improve the cyber-image of
Macedonia? - V/A1 To educate existing and potential Internet
users on the security standards through simple
examples from their everyday life. - Q2 What is the most obvious example of
secure Internet transaction? - V/A2 E-banking transaction. In the same time,
it is considered as one of the most
vulnerable processes in terms of security. - E-banking for retail customers on-line payment
of power/ water/central heating/phone/cell
phone/cable TV bills/liabilities
(mortgage/consumer loan instalments)/debts upon
credit cards/etc. - E-banking for corporate customers orders/all
types of payments/ including salary
payments/taxes/day-to-day dealings with the bank.
4Culture of Security InitiativeTHE PILOT PROJECT
- SCOPE OF WORK Setting the security standards for
e-banking applications, by aggressive marketing
of security focus and deployment of strong
authentication - PILOT PROJECT Implementation of OTP tokens
authentication system for retail banking users.
Tokens can be used for access both to the bank
e-banking application and to the international
providers that participate in the VIP - TEAM VeriSign, UNET, Komercijalna Banka AD
Skopje, USAID/MCA
5Culture of Security InitiativeVIP
- OTP token
- A single security device!!!
- Two Factor Authentication
- VIP Strong authentication VIP Fraud Detection
- KB e-banking application
- any VIP-enabled Web site of network members such
as PayPal, eBay or Yahoo! -
VIP Nework
6Culture of Security InitiativeVIP/PayPal example
- First Global VIP Implementation
- Within 6 months
- Initially 4 countries
- Germany, US, Japan, Australia
- 1 Million tokens
- By the end of 2007
7Culture of Security InitiativeVIP Today
8Culture of Security InitiativeWHO BENEFITS?
- The Bank
- First European Bank to join the prestige VIP
network - Set standards for information security in MK
- Achieve greater integration into the
international digital economy - Win market share
- MK Citizens
- Get a new perception of the use of Internet
- Save time and money
- Conduct their banking online securely
- Get secure access to a network of VIP-compatible
sites - For the first time in the history, be able to use
PayPal to handle payments on the Web, eBay to
shop at the biggest web marketplace, and Skype
to communicate online!
9Culture of Security InitiativeWHO BENEFITS?
- The country itself
- Positive perception in the international Internet
community Macedonian Bank gets connected /
Macedonian comunity doing clean e-business
internationally - Proactive approach to fight fraud to beat the
undeservedly poor reputation / shows readiness
not only in the cyber context - To obtain a proven record of non-fraudulent
on-line transactions within MK and worldwide /
positive reports - Gets removed from the Internet blacklists/Gets
in the whitelists - Increase the overall Internet usage and
contribute to the other sectors of Macedonian
Economy - MK businesses to sell worldwide generate profit
10Culture of Security InitiativeNEXT STEPS?
- To monitor and to report satisfaction level of
the KB OTP/VIP implementation - To continue the larger framework of projects that
USAID started and will help ensure that
Macedonias nascent IT and e-business
infrastructure develops healthily, limiting
fraud, crime, and other illegal activity. - To implement the VIP platform to multiple sectors
in MK (Internet payment, Health Care, On-line
Banking and Trading, E-commerce, Communication
and Government services) - To increase public awareness and acceptance of
secure Internet