- Take stock
- Scale down.
- Lock it.
- Pitch it.
- Plan ahead.
Thursday, December 06, 2007
Guide For Businesses On Protecting Personal Information
Entitled “Protecting Personal Information: A Guide for Business,” this new tutorial from the FTC outlines a framework businesses can use to implement a data security plan. The framework offered in the tutorial is built on 5 principles:
New CRS Report On Botnets, Cybercrime
CRS recently published a new report entitled "Botnets, Cybercrime, and Cyberterrorism: Vulnerabilities and Policy Issues." Among the findings in the report are that "cybercrime is becoming more organized and established as a transnational business....[and that] designs for cybercrime botnets arebecoming more sophisticated, and future botnet architectures may be more resistant to computer security countermeasures."
Monday, December 03, 2007
Study Shows Low Awareness of Security Freeze Laws
A study conducted by the AARP indicates that although consumers have a high concern about identity theft, their awareness of security freeze legislation remains extremely low. The study indicates that more than half (57%) of the respondents did not know where to turn for security freeze information. For the full text of the study, click here. For a summary, click here.
Monday, November 12, 2007
First Prosecution In File Sharing ID Theft
This AP news story reports on the case of Gregory Kopiloff. According to the Justice Department this is the first prosecution against someone accused of using file-sharing to commit identity theft. Kopiloff used file sharing programs to gain access to the personal information of more than 50 people. He then used that information to fraudulently buy and resell more than $73,000 in merchandise.
Thursday, November 08, 2007
The Prevalence of Identity Theft
The Bureau of Justice Statistics recently published a report on identity theft. According to the report, in 2005, 6.4 million households (5.5% of all households in the US) discovered that at least one member experienced one or more types of identity theft. Of this group, unauthorized use of an existing credit card was the the most prevalent type of identity theft (about 3 million households). Given that the data in the report is from 2005, the statistics today would likely be significantly larger.
Monday, November 05, 2007
Fair Use For User Generated Content
With the growth of user generated content (UGC) services like Youtube.com, the question of what is considered fair use is only now beginning to be defined. This article from the Electronic Frontier Foundation provides a framework for applying fair use in the UCG context. Hats off to beSpacific for this catch.
Thursday, October 25, 2007
E-Discovery Local Rules
Following on yesterday's post, Maryland is not the only state where federal courts have proposed or enacted e-discovery local rules. As this article shows, at least 32 US District Courts have enacted or proposed special rules addressing electronic discovery.
Wednesday, October 24, 2007
Suggested Protocol For E-Discovery
Judge Paul W. Grimm of the US District Court of Maryland recently posted this "Suggested Protocol For Discovery of Electronically Stored Information." Although not currently adopted, the document is a "working model" which may at some point be recommended for adoption.
Website Liability For User Posted Content
This Findlaw article by Eric Sinrod discusses when websites will be held liable for the content posted by others on their site. In particular, the article discusses the case of Fair Housing Council of San Fernando Valley v. Roommates.com, LLC where the website http://www.roommates.com/ was sued by the Fair Housing Councils of San Fernando Valley and San Diego. The plaintiffs alleged that the site's practice of allowing users to filter out potential roommates according to user-selected criteria violated the Fair Housing Act (FHA).
Tuesday, October 09, 2007
'07 Global Security Survey
Deloitte recently published it's annual review of the state of information security in the financial services industry. The survey includes data from 169 global financial institutions in 32 countries. Key findings include: companies are moving away from a sole focus on shoring up infrastructure against external breaches and are focusing instead on a a layered approach of preventative, detective and corrective controls; respondents identified access and identity management (50%) as their top operational initiative; generic countermeasures (encryption, access control, and network security) are proving inadequate at protecting on-line applications; and in an organization’s attempt to prevent security breaches, people remain the weakest link.
Tuesday, September 25, 2007
A Global Privacy Standard?
A senior executive at Google stated today that he agreed on the need for a basic set of global privacy protections. See this CNET article for more.
Domain Name Theft
This Wall Street Journal article examines how domain name hijacking is becoming an increasingly prevalent phenomenon.
Monday, September 24, 2007
EU Data Transfer Regulations
U.S. companies transferring personal data from Europe to the U.S. must follow prescribed methods to protect data in accord with EU data privacy protection laws. Complying with this "adequacy requirement" means satisfying each European nation's data protection authorities. Binding Corporate Rules allow a company to design a single set of internal rules that work on their own data protection policies for intranet sites, databases and other electronic business tools that also comply with EU requirements. For more on this, see this article from the New York Law Journal.
Monday, September 17, 2007
Robot Exclusion Protocol
If you are concerned, as I am, about the privacy threats posed by Google's search bots, take a look at the following post from Paul Ford of Ftrain.com.
Tuesday, September 11, 2007
VOIP Security Whitepaper From IBM
This 16-page whitepaper from IBM discusses "vishing." From the intro, "Vishing is the practice of leveraging IP-based voice messaging technologies (primarily Voice over Internet Protocol, or VoIP) to socially engineer the intended victim into providing personal, financial or other confidential infor-mation for the purpose of financial reward." The term "vishing" is a contraction of the terms 'voice' and 'phishing.'
Friday, September 07, 2007
DOT Issues Memo On Loss of Personal Information
The US Department of Transporation issued this memorandum on the theft of two laptops belonging to the Office of The Inspector General. Both laptops contained large amounts of Sensitive Personally Identifiable Information.
Thursday, September 06, 2007
National Security Archive Sues White House Over Emails
See this press release. The suit, filed in the US District Court of the District of Columbia, demands the recovery and preservation of 5 million emails which were allegedly deleted by the White House during the period of March 2003 and October 2005.
Wednesday, September 05, 2007
Source Code For Breathalyzer Softwere Held Not To Be Trade Secret
See this post from the DUI Blog. A number of manufacturers of breathalyzer software had refused to disclose their source close, claiming they were trade secrets. The Supreme Court of New Jersey, however, recently ruled that the source code for this software is not a trade secret and therefore the company should be forced to reveal the code.
Online Listing Qualifies For Copyright Protection
In a decision published on June 21 (BUC Int'l Corp. v. Int'l Yacht Council), the 11th Circuit Court of Appeals affirmed that BUC International Corp.'s method of organizing its online listings of yachts for sale was unique enough to qualify for copyright protection. The defendant had "scraped" adds off of BUC's website.
Executive Office of The President Not Subject To FOIA
This page on the White House website states "The Office of Administration, whose sole function is to advise and assist the President, and which has no substantial independent authority, is not subject to FOIA and related authorities."
Subscribe to:
Posts (Atom)