Presentation is loading. Please wait.

Presentation is loading. Please wait.

NYSE Blue Security Concerns for Offset Registries

Similar presentations


Presentation on theme: "NYSE Blue Security Concerns for Offset Registries"— Presentation transcript:

1 NYSE Blue Security Concerns for Offset Registries
July 26, 2011 © NYSE Blue. All Rights Reserved.

2 Security Framework for an Offset Program
Registry Technology Know Your Client Procedures Program Legal & Operational Rules Training on User Best Practices Thank you Joel and good morning everyone; I just want to take a moment to congratulate Joel, Gary, and the whole CAR team for the recognition they’ve gotten over the course of the last few months. Having worked with this wonderful group of people for now over 3 years ….. I can tell you they deserve the appreciation! When Joel called and asked me to speak about registry security….I had 2 reactions.. 1. oh boy, how am I going to make this one interesting! 2. with my luck there will be a hacker in the audience who makes it his life mission to prove me wrong But seriously,there is a good story to tell about the security framework CAR has in place. That’s because long before the European issues broke….well over 2 years ago, Car was committed to working with then APX / NYSE Blue in creating a rigorous security framework for the registry. Since carbon is essentially unregulated, this security framework is not just about technology. -- although that is certainly important There are no regulators involved so CAR needs to include It also includes: know your client procedures, … proper operating rules;.. And informing users about best practices in using the registries. All of these things play an integrated role

3 Registry Technology Encrypted connection (HTTPS)
Disable user ID upon 3 incorrect logins Ongoing vulnerability testing for registry Later this year, introduction of two-factor authentication

4 Know Your Client Procedures
Identify clients and ascertain relevant information about their businesses Request copies of documents confirming identity of legal entity organization documents, memorandum of incorporation, bank accounts, utility bills Become familiar with the principals and ask for identification documents such as drivers license, passports, and birth certificates Review marketing materials and business plan Perform OFAC / AML checks to ensure entities not found on Terrorist Watch lists. Monitor activity to ensure it matches the company profile

5 Program Legal & Operational Rules
Omnibus accounts Only a regulated entity can maintain an omnibus account (and these regulated entities must show proof of proper KYC procedures) Certain unregulated entities can be given the ability to maintain omnibus accounts Retail Marketers Retirement of greater than 99 credits on behalf of a client must be done in an specific client sub-account Retirement of greater than 99k credits on behalf of a client must be made public

6 Registry User Best Practices
Use latest anti-virus protection programs Update contact information for users/logins to their account Perform weekly/monthly account reviews to ensure data is correct Users should not access The Reserve from public locations where others could capture their confidential information. Users should pay close attention to the registry notifications for transfer confirmations.

7


Download ppt "NYSE Blue Security Concerns for Offset Registries"

Similar presentations


Ads by Google