OCC Guidance re: Phishing
Ethan Preston comments on the recent guidance (.doc) issued by the Office of the Comptroller of the Currency regarding countermeasures against phishing attacks.
I wonder how many banks comply with these measures, even this late in the game. In particular, analyzing web logs seems like an very good way to identify phishing websites early on, but I suspect relatively few banks (or any other commercial entities) do so.And if litigation were to follow a successful phishing attack, it seems to me that a bank's failure to comply with the OCC's guidance here would be a strong indicator of negligence.





Add your comment... (note that all comments are reviewed before they're published)