In a letter sent to customers on Friday, and obtained by SecurityWeek, NASDAQ outlined measures put in place to secure its Directors Desk platform, including changes made since an attack that occurred October of 2010.
“After the attack, our customers rightly questioned our security. Since then we have made substantial investments to implement additional cutting-edge security enhancements, thereby outpacing our competitors and bringing our security to an industry leading, military-grade level,” the letter explained.
“Our achievements in security are not lost on our new and existing customers. In fact, in the last 12 months, we have increased sales of Directors Desk by 52% and the number of new users increased by more than 170. This is no doubt a measure of the fact that you recognize that we are hyper-focused on providing the most secure environment for our customers.”
Included in the security overview for Directors Desk is the mention of hardened operating system, database, and network perimeter deployments. NASDAQ’s security posture has been subject of several reports suggesting that lax security controls contributed to the 2010 attack against the exchange.
Other security mentions include, AES-256 encryption for data storage, encrypted backups, customer data segregation, IDS systems, extensive integrated logging, alerting, and reporting (SEIM), a policy of least privilege, as well as vulnerability and patch reviewing processes.
The interesting part however was focused on the WebAppSec processed, which include WebApplication Firewalls, annual third-party audits, and the kicker – independent validation against the OWASP Top 10.
“The NASDAQ OMX Information Security Department conducts ongoing security assessments of Directors Desk using multiple leading security testing firms. The independent reviews have been expanded to include the new iPad app that was recently launched,” the security overview explains.
When it comes to disclosure, the final report summaries for the independent testing are included in the Directors Desk Information Security Packet, available to all Directors Desk clients.
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Insider Q&A: Artificial Intelligence and Cybersecurity In Military Tech
- In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack
- OpenAI Unveils Million-Dollar Cybersecurity Grant Program
- Galvanick Banks $10 Million for Industrial XDR Technology
- Information of 2.5M People Stolen in Ransomware Attack at Massachusetts Health Insurer
- US, South Korea Detail North Korea’s Social Engineering Techniques
- High-Severity Vulnerabilities Patched in Splunk Enterprise
- Idaho Hospitals Working to Resume Full Operations After Cyberattack
