Anda di halaman 1dari 2

10686 Federal Register / Vol. 71, No.

41 / Thursday, March 2, 2006 / Notices

and regulations to become a bank methods of competition. The attached FOR FURTHER INFORMATION CONTACT:
holding company and/or to acquire the Analysis to Aid Public Comment Jessica Rich or Alain Sheer, Bureau of
assets or the ownership of, control of, or describes both the allegations in the Consumer Protection, 600 Pennsylvania
the power to vote shares of a bank or draft complaint and the terms of the Avenue, NW., Washington, DC 20580,
bank holding company and all of the consent order—embodied in the consent (202) 326–3224.
banks and nonbanking companies agreement—that would settle these SUPPLEMENTARY INFORMATION: Pursuant
owned by the bank holding company, allegations. to section 6(f) of the Federal Trade
including the companies listed below. DATES: Comments must be received on Commission Act, 38 Stat. 721, 15 U.S.C.
The applications listed below, as well 46(f), and § 2.34 of the Commission
or before March 27, 2006.
as other related filings required by the Rules of Practice, 16 CFR 2.34, notice is
Board, are available for immediate ADDRESSES: Interested parties are hereby given that the above-captioned
inspection at the Federal Reserve Bank invited to submit written comments. consent agreement containing a consent
indicated. The application also will be Comments should refer to ‘‘CardSystems order to cease and desist, having been
available for inspection at the offices of Solutions, File No. 052 3148,’’ to filed with and accepted, subject to final
the Board of Governors. Interested facilitate the organization of comments. approval, by the Commission, has been
persons may express their views in A comment filed in paper form should placed on the public record for a period
writing on the standards enumerated in include this reference both in the text of thirty (30) days. The following
the BHC Act (12 U.S.C. 1842(c)). If the and on the envelope, and should be Analysis to Aid Public Comment
proposal also involves the acquisition of mailed or delivered to the following describes the terms of the consent
a nonbanking company, the review also address: Federal Trade Commission/ agreement, and the allegations in the
includes whether the acquisition of the Office of the Secretary, Room 135–H, complaint. An electronic copy of the
nonbanking company complies with the 600 Pennsylvania Avenue, NW., full text of the consent agreement
standards in section 4 of the BHC Act Washington, DC 20580. Comments package can be obtained from the FTC
(12 U.S.C. 1843). Unless otherwise containing confidential material must be Home Page (for February 23, 2006), on
noted, nonbanking activities will be filed in paper form, must be clearly the World Wide Web, at http://
conducted throughout the United States. labeled ‘‘Confidential,’’ and must www.ftc.gov/os/2006/02/index.htm. A
Additional information on all bank comply with Commission Rule 4.9(c). paper copy can be obtained from the
holding companies may be obtained 16 CFR 4.9(c) (2005).1 The FTC is FTC Public Reference Room, Room 130–
from the National Information Center requesting that any comment filed in H, 600 Pennsylvania Avenue, NW.,
Web site at http://www.ffiec.gov/nic/. paper form be sent by courier or Washington, DC 20580, either in person
Unless otherwise noted, comments overnight service, if possible, because or by calling (202) 326–2222.
regarding each of these applications U.S. postal mail in the Washington area Public comments are invited, and may
must be received at the Reserve Bank and at the Commission is subject to be filed with the Commission in either
indicated or the offices of the Board of delay due to heightened security paper or electronic form. All comments
Governors not later than March 27, precautions. Comments that do not should be filed as prescribed in the
2006. contain any nonpublic information may ADDRESSES section above, and must be
A. Federal Reserve Bank of San instead be filed in electronic form as received on or before the date specified
Francisco (Tracy Basinger, Director, part of or as an attachment to e-mail in the DATES section.
Regional and Community Bank Group) messages directed to the following e-
Analysis of Agreement Containing
101 Market Street, San Francisco, mail box: consentagreement@ftc.gov.
Consent Order To Aid Public Comment
California 94105-1579: The FTC Act and other laws the
1. Canyon Bancorp, Palm Springs, Commission administers permit the The Federal Trade Commission has
California; to become a bank holding collection of public comments to accepted, subject to final approval, a
company by acquiring 100 percent of consider and use in this proceeding as consent agreement from CardSystems
the voting shares of Canyon National appropriate. All timely and responsive Solutions Inc. (‘‘CardSystems’’) and its
Bank, Palm Springs, California. public comments, whether filed in successor, Solidus Networks, Inc., doing
paper or electronic form, will be business as Pay By Touch Solutions
Board of Governors of the Federal Reserve (‘‘Pay By Touch’’).
System, February 27, 2006. considered by the Commission, and will
be available to the public on the FTC The consent agreement has been
Robert deV. Frierson, placed on the public record for thirty
Web site, to the extent practicable, at
Deputy Secretary of the Board. (30) days for receipt of comments by
http://www.ftc.gov. As a matter of
[FR Doc. E6–2941 Filed 3–1–06; 8:45 am] discretion, the FTC makes every effort to interested persons. Comments received
BILLING CODE 6210–01–S remove home contact information for during this period will become part of
individuals from the public comments it the public record. After thirty (30) days,
receives before placing those comments the Commission will again review the
FEDERAL TRADE COMMISSION on the FTC Web site. More information, agreement and the comments received,
including routine uses permitted by the and will decide whether it should
[File No. 052 3148] withdraw from the agreement and take
Privacy Act, may be found in the FTC’s
privacy policy, at http://www.ftc.gov/ appropriate action or make final the
CardSystems Solutions, Inc.; Analysis
ftc/privacy.htm. agreement’s proposed order.
of Proposed Consent Order To Aid According to the Commission’s
Public Comment proposed complaint, CardSystems
1 The comment must be accompanied by an
AGENCY: Federal Trade Commission. explicit request for confidential treatment,
provides merchants with products and
ACTION: Proposed consent agreement. including the factual and legal basis for the request, services used in ‘‘authorization
wwhite on PROD1PC61 with NOTICES

and must identify the specific portions of the processing’’—obtaining approval for
SUMMARY: The consent agreement in this comment to be withheld from the public record. credit and debit card purchases from
The request will be granted or denied by the
matter settles alleged violations of Commission’s General Counsel, consistent with
banks that issued the cards. Last year, it
Federal law prohibiting unfair or applicable law and the public interest. See processed about 210 million card
deceptive acts or practices or unfair Commission Rule 4.9(c), 16 CFR 4.9(c). purchases, totaling more than $15

VerDate Aug<31>2005 17:54 Mar 01, 2006 Jkt 208001 PO 00000 Frm 00053 Fmt 4703 Sfmt 4703 E:\FR\FM\02MRN1.SGM 02MRN1
Federal Register / Vol. 71, No. 41 / Thursday, March 2, 2006 / Notices 10687

billion, for more than 119,000 small and these cards were unable to use them to sufficient effectiveness to provide
mid-size merchants. In the course of access credit and their own bank reasonable assurance that the security,
processing these credit and debit card accounts. confidentiality, and integrity of
purchases, CardSystems collected and The proposed order applies to consumers’ personal information has
stored personal information about personal information from or about been protected.
consumers, including card number and consumers that CardSystems and Pay By Parts III through VII of the proposed
expiration date and other information, Touch (as CardSystems’ successor) order are reporting and compliance
from magnetic stripes on the cards. Pay collect in connection with authorization provisions. Part III requires
By Touch acquired CardSystems’ assets processing. The proposed order contains CardSystems and Pay By Touch to
on December 9, 2005, at which time provisions designed to prevent them retain documents relating to their
CardSystems ceased doing business. Pay from engaging in the future in practices compliance with the order. Part IV
By Touch uses CardSystems’ former similar to those alleged in the requires dissemination of the order now
employees, equipment, and technology complaint. and in the future to persons with
to process transactions for the same Part I of the proposed order requires responsibilities relating to the subject
merchants CardSystems served. CardSystems and Pay By Touch to matter of the order. Part V requires them
The Commission’s proposed establish and maintain a comprehensive to notify the Commission of changes in
complaint alleges that CardSystems information security program in writing their corporate status. Part VI mandates
stored personal information on that is reasonably designed to protect that CardSystems and Pay By Touch
computers on its computer network and the security, confidentiality, and submit compliance reports to the FTC.
failed to employ reasonable and integrity of personal information they Part VII is a provision ‘‘sunsetting’’ the
appropriate security measures to protect collect from or about consumers. The order after twenty (20) years, with
the information. The complaint alleges security program must contain certain exceptions.
that this failure was an unfair practice administrative, technical, and physical This case is similar to the recent FTC
because it caused or was likely to cause safeguards appropriate to their size and cases against BJ’s Wholesale Club and
substantial consumer injury that was complexity, the nature and scope of DSW Inc., which also involved alleged
not reasonably avoidable and was not their activities, and the sensitivity of the failures to secure credit and debit card
outweighed by countervailing benefits personal information collected. information. As in those cases,
to consumers or competition. In Specifically, the order requires CardSystems faces potential liability in
particular, CardSystems engaged in a CardSystems and Pay By Touch to: the millions of dollars under bank
number of practices that, taken together, • Designate an employee or procedures and in private litigation for
failed to provide reasonable and employees to coordinate and be losses related to the breach.
appropriate security for personal accountable for the information security The purpose of this analysis is to
information stored on its computer program. facilitate public comment on the
network. Among other things, it: (1) • Identify material internal and proposed order. It is not intended to
Created unnecessary risks to the external risks to the security, constitute an official interpretation of
information by storing it; (2) did not confidentiality, and integrity of the proposed order or to modify its
adequately assess the vulnerability of its consumer information that could result terms in any way.
computer network to commonly known in unauthorized disclosure, misuse,
or reasonably foreseeable attacks, loss, alteration, destruction, or other By direction of the Commission, with
compromise of such information, and Commissioner Harbour recused.
including but not limited to ‘‘Structured
Query Language’’ injection attacks; (3) assess the sufficiency of any safeguards Donald S. Clark,
did not implement simple, low-cost, in place to control these risks. Secretary.
and readily available defenses to such • Design and implement reasonable [FR Doc. E6–2934 Filed 3–1–06; 8:45 am]
attacks; (4) failed to use strong safeguards to control the risks identified BILLING CODE 6750–01–P
passwords to prevent a hacker from through risk assessment, and regularly
gaining control over computers on its test or monitor the effectiveness of the
computer network and access to safeguards’ key controls, systems, and GENERAL SERVICES
personal information stored on the procedures. ADMINISTRATION
network; (5) did not use readily • Evaluate and adjust their
information security program in light of [OMB Control No. 3090–0228]
available security measures to limit
access between computers on its the results of testing and monitoring,
Office of Civil Rights; Information
network and between such computers any material changes to their operations
Collection; Nondiscrimination in
and the Internet; and (6) failed to or business arrangements, or any other
Federal Financial Assistance Programs
employ sufficient measures to detect circumstances that they know or have to
unauthorized access to personal reason to know may have a material AGENCY: Office of Civil Rights, GSA.
information or to conduct security impact on the effectiveness of their ACTION: Notice of request for comments
investigations. information security program. regarding a renewal to an existing OMB
The complaint further alleges that Part II of the proposed order requires clearance.
several million dollars in fraudulent that CardSystems and Pay By Touch
purchases were made using counterfeit obtain within 180 days, and on a SUMMARY: Under the provisions of the
copies of credit and debit cards that biennial basis thereafter, an assessment Paperwork Reduction Act of 1995 (44
contained the same personal and report from a qualified, objective, U.S.C. Chapter 35), the General Services
information CardSystems had collected independent third-party professional, Administration will be submitting to the
from the magnetic stripes of credit and certifying, among other things, that: (1) Office of Management and Budget
wwhite on PROD1PC61 with NOTICES

debit cards and then stored on its They have in place a security program (OMB) a request to review and approve
computer network. After discovering the that provides protections that meet or a renewal of a currently approved
fraudulent purchases, banks cancelled exceed the protections required by Part information collection requirement
and re-issued thousands of these credit I of the proposed order, and (2) their regarding nondiscrimination in Federal
and debit cards, and consumers holding security program is operating with financial assistance programs. The

VerDate Aug<31>2005 17:54 Mar 01, 2006 Jkt 208001 PO 00000 Frm 00054 Fmt 4703 Sfmt 4703 E:\FR\FM\02MRN1.SGM 02MRN1

Anda mungkin juga menyukai