Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts

Sunday, November 30, 2008

Giving up Email

How long could you live without email? What would it cost in terms of lost productivity and increased difficulty and expense of communication?

I know that I could live without email. I suspect that doing so would significantly decrease my productivity (a suspicion supported by this study of the impact of email on productivity in a white collar environment). There would unquestionably be a period of adjustment when I would be most unhappy to lose what is probably my primary means of communication with friends and clients.

Now, Barack Obama is facing the prospect of losing his ability to use email (see article here). The short version of why is that there are concerns that email isn't secure enough for presidential communications, and the White House doesn't want the president to create an email paper trail which could potentially be subpoenaed. To me, this is crazy. Other secrecy sensitive professions, such as lawyers (who have to protect client confidences) have managed to make peace with the limitations of email and embraced it as a useful tool (see, e.g., this opinion regarding usage of cell phones and email by lawyers). Now, it's true that the president has information (e.g., plans for the conduct of war) which is substantially more important than the confidential information lawyers have access to. However, there's no reason for the president to be completely cut off from email.

So, given that most people are not, and will never be, president, what significance does this have for the day to day lives of ordinary individuals? Only this: I don't think Obama will do it. Even back in 2000, George W. Bush lamented having to give up his email. Since 2000, people's usage of email has increased dramatically (compare this article from 2000 which predicted email usage of about 9 megs/day/person in 2001, with this white paper which puts email usage at 19.3 megs/day/person in 2008) and Obama is a famously wired individual. I predict (though I realize that there is a note of wishful thinking in this prediction) that Obama will rebel against the prohibition on email, and will use his position as the most powerful person in the world to do something about it. Maybe he'll request that technology be put in place that will make his emails more secure, and that technology will eventually become available to the public at large. Maybe he'll propose tougher laws or regulations on network service providers so that email becomes a more secure medium of communication. Whatever the case, if Obama takes action to make being a wired professional more consistent with the heightened security requirements of being president, it can't help but have positive security implications for the country as a whole.

Sunday, October 19, 2008

Weaknesses in Government Systems

According to this report (via), the IRS deployed two major software systems, its Customer Account Data Engine (CADE), and its Account Management Services (AMS) system, despite the existence of "known security vulnerabilities relating to the protection of sensitive data, system access, monitoring of system access, and disaster recovery." Obviously, this is a problem. Indeed, given some of the vulnerabilities noted in the Computer World article summarizing the report (e.g., failure to encrypt data either in storage or transit), the IRS systems wouldn't even pass the private sector PCI Data Security Standard, let alone government imposed standards such as those in HIPAA.

The interesting part of the report though, is not that the IRS deployed systems with flaws. Frankly, while that part may be depressing, similar mistakes take place in both the public and private spheres frequently enough that the existence of one more flawed system doesn't really raise my attention. What interests me about the report is that it shows the limits on what you can do with regulation. The IRS has specific guidelines and requirement for handling data that, in theory, should have prevented the deployment of systems with known vulnerabilities. Moreover, as the report noted the IRS had implemented development policies which "require security and privacy safeguards to be planned for and designed in the early phases of a system’s development life" - something that many private sector businesses would benefit from doing. The problem was that the IRS' cybersecurity organization knew about the vulnerabilities and accepted them anyway - in other words, it decided to save money by skimping on security for taxpayer information. With that kind of culture (which I find a bit surprising in government) it's not likely that an organization will have good security, regardless of how heavily regulated it is.

So how do you create a security conscious culture? The easy answer is feedback. Make sure that there are rewards for doing things right, penalties for doing things wrong, and that the rewards and penalties (as well as what counts as right and wrong) are well known. Unfortunately, that easy answer is only easy in theory. In practice it's really hard to implement, and involves things like keeping open lines of communication, making sure decision makers pay attention to security even though it doesn't contribute directly to the bottom line, and educating people about what resources are available in an organization to provide decision support on security issues. While it seems that there is a slow change underway from a culture where consumer data is treated only as something to be valued, to a culture where it's viewed as something to be protected, that change is very slow indeed. Before the change is complete, I think there will be many more reports revealing that large entities (both public and private) have undervalued securing consumer data.

Thursday, March 27, 2008

DATA PRIVACY PROTECTION LAWS POSE CHALLENGES

Compliance by U.S. multinational companies with the data protection and e-discovery laws, rules and regulations in both the U.S. as well as other international jurisdictions can pose significant challenges. While the laws do not impose conflicting requirements, the differences in the approach to data privacy protection between U.S. laws and those of the EU and its member states and the complexities of their requirements demand a comprehensive team approach to compliance.
The U.S. federal and state laws take a patchwork approach to personal data protection, with a myriad of data privacy requirements based upon industry. There is, however, no a comprehensive data privacy protection law. Nor are there special requirements for the transfer of personal data, cross-border or otherwise, as long as the “sharing” has been disclosed to the consumer, or is within the exceptions provided for by applicable law.
More than 35 states have enacted data breach notification and security freeze laws, with many variations on the method and timing of notification among them. To date, the U.S. Congress has not been able to agree upon a uniform approach for data breach notification and security freeze rights. Amendments to the Federal Rules of Civil Procedure that became effective in December, 2006 have underscored the importance of electronic discovery, so that corporate counsel must be concerned with the risks and potential sanctions that could result from non-compliance with a discovery order.
Companies that collect and process their own employee or customer data in the U.S. when that data resides in a European Union member country are presented with even greater challenges. The EU Data Protection Directive, as well as the data protection laws of the country of the data subjects’ residence, impose broader data privacy requirements on companies. In addition to the U.S. laws, such companies must be cognizant of the laws of the jurisdiction where the data to be processed resides. The aim of the Directive is to ensure that each member state imposes a similar level of protection of data, so that data can be transferred freely within the EU subject to the same security standards in the country of receipt as it is in the country of transfer.
The EU member states that were formerly under the control of fascist regimes during World War II are particularly keen on avoiding the abuses of individual privacy rights that occurred during that period. Thus, the Data Protection Authorities of France, Spain, Germany and Italy are very active in their enforcement efforts, conducting costly investigations, and levying monetary sanctions and fines against violators of their laws. On April 12, 2007, the French DPA, CNIL, announced the imposition of a fine of €30,000 against Tyco Healthcare France Corporation for non-cooperation and for providing CNIL with erroneous information. To date, the CNIL has imposed 16 monetary sanctions, ranging from €300 to €60,000, issued 170 summons, 11 orders or cease or amend processing practices, and 15 warnings. This equals a 200% increase in activity since 2006. In July, 2007, Spain’s Supreme Court confirmed its DPA’s largest ever fine in the amount of €1,081,822 against Zeppelin Television, S.A. Additionally, for the first time Spain’s DPA has conducted a data privacy audit outside of Spain, in Colombia, where Spanish citizens’ personal data is being processed. In addition, the EU’s Data Privacy Commission has been active in enforcing the requirements of the Privacy Directive on its member countries.
Earlier this year, an independent EU panel launched an investigation into whether U.S.-based Google Inc.'s Internet search engine abides by European Union privacy rules. The panel convinced Google to clear its user data of information that could be used to identify the user once the data has existed for 18 months. Google accurately noted, however, that governments and businesses are obliged to retain information, and it is difficult to operate a global Internet service according to different privacy standards in different countries.
The same observation can be made as to many other types of businesses as well. The complexities and risks associated with privacy laws have never been greater, and require vigilant monitoring by counsel and data security officers. One of the EU Directive principles requires that personal data be transferred cross-border only if the country of receipt provides “adequate protection.” Various options are available to companies to address the requirements of the EU Privacy Directive. Model contractual clauses have been approved by the EU, for inclusion in contracts between companies and their service providers. For companies with employees or customers in multiple European jurisdictions, adoption of Binding Corporate Rules that address all of the EU Directive requirements has also been deemed acceptable by the EU, provided that the BCR have been approved by the EU Data Privacy Commission and the applicable country’s DPA. The EU DPAs are also working on uniform BCRs, so that it would be unnecessary to obtain approval from each EU member state. Finally, certification within the U.S.-EU. Safe Harbor Framework provides protection against challenges of non-compliance with the EU Directive. More information on Safe Harbor certification, including a list of the more than 1300 U.S. companies who have joined the Safe Harbor Framework, can be found at http://www.export.gov/safeharbor/. Adopting one of the suggested methods to meet the “adequate protection” principle will permit multinational companies with European operations to truly operate without borders with respect to the personal data of their employees and customers.

Thursday, December 27, 2007

2008 Budgets Beefed Up for Data Security Expenses

One item that is not getting short shrift in the community bankers' 2008 budgets is expenses for protecting consumer data. While controlling costs has consistently been a top priority for these financial institutions, many report being fearful of an unauthorized infiltration of their bank databases, and are investing security related technology. In an article in the December 21, 2007 American Banker, bankers report that criminals are constantly searching for a weakness in banks' firewalls, and that they must continually monitor such attempts to be certain they have addressed any vulnerabilities. These banks now appear to be keenly aware of the damage to their reputation that could result from a data security breach, particularly where it could be shown that they did not take sufficient preventive steps to stave off an attack. This reputation risk, combined with increased attention being paid to banks' risk management policies and procedures by banking regulators, has caused banks to increase their budgets on fraud detection technology for the coming year. Reports of banks who were unprepared when a hacker "intrusion" occurred, and the resulting financial resources required to address the aftermath, have been a "wakeup call" for many banks. It has been this writer's frustration over the past several years that risk of data security breach has not been taken seriously enough. In the end, however, it appears that it was the plight of these victims of security breaches that finally convinced financial institutions that being penny wise and pound foolish should not be their motto when it comes to securing customer data.

Wednesday, October 31, 2007

Merchants Challenged to Comply with PCI Standards

As a follow up to the prior blog post, recent reports from VISA USA illustrate the Faustian choice many merchants are faced with when considering what to do about the requirements for PCI -DSS compliance. Former Level 4 merchants had until September 30, 2007 to demonstrate compliance, with non-compliance carrying stiff penalties. However, the complexity of the standards and the expense of overhauling IT practices have caused many merchants to decide to accept the fines rather than to incur the expense. This is an unfortunate development for the cause of privacy professionals and others who have been advocating tighter security standards as the best preventive steps against data security breaches. The President and CEO of VISA, Philip Coghlin, recently indicated that only 20% of VISA merchants are PCI-DSS compliant. But he also indicated that the industry was advocating even tighter security standards. Such an approach ignores the potential merchant noncompliance with the security standards may have on consumer trust of e-commerce. If the standards are difficult to comply with so that compliance is lagging, consumer confidence in the electronic delivery system could erode. article