Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Monday, June 16, 2008

Identity Thefts, The US FACT Act and Red Flag rules …

How may of you were aware of the fact that US Financial institutions face a mandatory deadline of November 1, 2008 to comply with 3 new US Fair and Accurate Credit Transactions Act (FACT Act) regulations referred to as the Red Flag rules?

As explained (in a nutshell) in this wikipedia page, these are 3 new regulations:
  • “One that requires financial institutions or creditors to develop and implement an Identity Theft Prevention Program in connection with both new and existing accounts. The Program must include reasonable policies and procedures for detecting, preventing, and mitigating identity theft;
  • Another that requires users of consumer reports to respond to Notices of Address Discrepancies that they receive;
  • A third that places special requirements on issuers of debit or credit cards to assess the validity of a change of address if they receive notification of a change of address for a consumer’s debit or credit card account and, within a short period of time afterward they receive a request for an additional or replacement card for the same account.”

I wonder how much these new measures will be effective in mitigating the risks of identity thefts …

--- NOTE: my original HP blog can be found here ---

No comments: