10 things you should know about privacy protection and IT

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS

Personal privacy has become a major public concern. Highly visible data breaches, identity theft, and frauds such as phishing scams have created a huge corporate and consumer burden and threaten trust in internet and e-commerce services.

Studies have shown that almost half of US residents have "little or no confidence" that adequate steps have been taken to secure their personal data. Compounding this lack of confidence is the increasing sophistication of online crime schemes. It's hard to tell who is legitimate, and a growing number of users are becoming victims of the internet. Let's look at some privacy concerns and how they affect IT.

#1: Reporting compromised data: It's the law
In the US, several states require that state entities, persons, or businesses disclose to a resident when his or her private information is reasonably believed to have been acquired by someone without authorisation. An organisation must publicly disclose when personal information in its possession appears to have been compromised. In 2003, California passed a law that requires organisations to notify residents if the organisation experienced a data security breach that caused risk to personal information. Currently, 28 states have passed similar laws, and security breach notification bills are pending in more than 15 other states. Notification of a breach is costly, as there is usually a per-person fine.

#2: Customer loyalty is directly dependent on privacy
Consumers rely on the internet for shopping, banking, government, healthcare, and other services, while trusting that their personal and financial information is protected and inaccessible to unauthorised use. When this trust is broken, customer loyalty can evaporate — overnight. The costs of identity theft and other fraud are too great to risk doing business with organisations known for mistrust of private information.

Between 2001and 2004, more than 196 privacy-related legal actions were raised against 255 corporate defendants, including financial services, health care, pharmaceutical, information services, e-commerce, manufacturing, media, and retail. More than 33 class action suits have also been filed. Here are some interesting figures on how web consumers view privacy:

  • 86 percent are concerned about privacy of personal data.
  • 45 percent never provide real names to sites.
  • 5 percent use software to hide computer identities.
  • 86 percent favour "opt-in" that requires permission before using data.
  • 94 percent want privacy violators to be punished.

#3: IT pros bear most of the burden for privacy
Here are a few things to consider when developing systems:

  • Know the types of data you are working with that include PII (personally identifiable information.) This includes the user's name and email address, health care, and credit card or social security numbers. Don't collect more data than necessary.
  • Know how to implement mechanisms for notifying users that their personal data may be collected and offer them ways to opt out or consent to the collection of their data. A record of opt-out acknowledgement may also be required.
  • Determine where the system vulnerabilities lie: in the application, database, wireless network, web access, or other interfaces.
  • Understand the steps to secure PII from misuse or unauthorised access, including access controls, encryption, physical security and auditing. Encryption is probably the best defense. When an encrypted laptop is stolen, at least the data is protected.

#4: A data classification policy is essential
Today, data managers are expected to become steward of their organisation's information. They're asked to view the data under their care as a valuable asset and manage it based on what or who it represents. An organisation should have a policy definition of classified, confidential, and public information and clearly define data that's the most valuable and/or secret.

A key component of this policy is a data security plan that addresses the foreseeable risks to the integrity of the information maintained in an organisation's systems. Control of and access to PII data is the subject of recent privacy regulations in the United States. The European Union also has specific requirements to protect its residents.

#5: Identifying critical systems helps risk analysis
Once you have a clear picture of how the data is classified and have identified potential data risks, target the systems that manage the data for a more detailed analysis of risks to data integrity.

A benefit of this exercise is to have better risk-ranking of major IT processes and systems, allowing you to focus on higher potential privacy risk areas. Auditing controls that are expected by law for critical systems that contain "regulated" data is a best practice.

#6: Organisations carry the burden of proof
Did you get hacked? Was it successful? What data was affected? How many customers? What states? Even unsuccessful attacks may have to be disclosed, unless an organisation can prove that no personal information was made available to or accessed by an unauthorised party. As a result, an organisation's intrusion detection and prevention systems must be effective and create reliable records of their effectiveness.

If a company concludes that a security incident didn't result in unauthorised access to personal data, but a customer suffers identity theft as a result of the attack, the organisation will probably be found liable. Disclosing and reporting a breach is almost sure to damage the organisation with financial consequences. Notification alone costs about $100 (£50) per customer per incident. So if 10,000 customers are affected, the incident will cost at least $1,000,000.

#7: CPOs oversee privacy issues
The primary role of the chief privacy officer (CPO) is to establish privacy policies for both customers and employees and to review and rule on related issues. A CPO usually chairs a privacy committee in larger organisations to provide guidance on managing incidents, privacy policies, security awareness, and many other privacy issues. The buck stops here when there's a decision to be made on technology or business that can affect compliance.

The CPO is becoming very busy these days, fielding questions on legal issues that usually have an impact on IT. IT is often responsible for finding solutions to privacy issues, such as intelligent encryption.

#8: Privacy incident management can prevent future risks
Who gets notified and when? Privacy incident management is not unlike other incident response functions, except when it comes to notification. Notification requirements are usually spelled out in the law, but notification can still be an arduous process. The CPO will likely oversee the incident response team that determines the cause and severity of the incident and issues report findings. An important outcome of investigating an incident and finding the root cause is remedying systems against similar risks in the future.

#9: Boundaries are blurring
Who is responsible when data is shared between organisations in the course of business? What if a breach is caused by one of your organisation's outsourcers? If your employees' pension data is on an insecure laptop owned by the pension provider and the laptop is stolen, who bears the burden?

IT outsourcing is popular, but whose responsibility is it to protect you when an employee or a vendor happens to leave a USB stick on the counter at Starbucks when paying for a latte? If this device contains insecure private information, the mishap could constitute a data breach.

It's most critical to have privacy and security language in all IT contracts with third parties. Incidents can't always be prevented, but you can buy some indemnity if you draft a proper contract. Data security in contracts is becoming more common; use your legal team if necessary.

#10: White collar crime threatens privacy
A huge market exists for selling personal information, especially credit card numbers. The average rate for an ID is about £30. The infrastructure for online crime is more sophisticated than you can imagine.

Marc Gaffan, a marketer at RSA Security, offered this description of the problem in the article "The Net's not-so-secret economy of crime": "There's an organised crime industry out there with defined roles and specialties. There are communications, rules of engagement, and even ethics. It's a whole value chain of facilitating fraud, and only the last steps are actually dedicated to translating activity into money."

A web site called TalkCash.net was a fraud marketplace for its members. To become a member, an applicant was asked to submit a few credit card numbers to show that he or she was really a "crook". This site is no longer open for business.

The 2005 National Survey on White Collar Crime, sponsored by the National White Collar Crime Center (nw3c), shows that nearly half of US households were victimised by a white collar crime within the past 12 months. The FBI has no lack of work.

To obtain a copy of the 2005 Internet Crime Report for your state, visit www.ic3.gov/media/annualreports.aspx.

A few privacy resources

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

apexwm

NanWag : A Windows Server 2008 is being used because the environment that the Macs are in is a heavy Windows environment. I am proposing that...

10 minutes ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
BellamysIT

Really good article. You bring to light a few really good things. However, isn't it true that over 70% of fortune 500 companies use sharepoint?...

12 minutes ago by BellamysIT on Designing a SharePoint farm: Tiers before bedtime
annonymous2

If Piratebay is a crime then so is borrowing a dvd you purchased to a family member or a friend. Why should we not be aloud to share. Most of the...

2 hours ago by annonymous2 on UK ISPs ordered to block Pirate Bay website
NanWag

File Services For Macintosh was causing Excel to prompt for Overwriting changes or Save Another Copy because it was changing the timestamp on the...

3 hours ago by NanWag on Windows Server 2008 drops the ball for Mac compatibility
Regis Machado

creative cloud $48/month in the USA, £48/month in the UK ($79). good for the competitors

4 hours ago by Regis Machado via Facebook on Adobe move promotes piracy
Tom Espiner

Hello KosGirl, Good question. I've asked Belfius for a response. The latest post I can find on Pastebin about it is here:...

5 hours ago by Tom Espiner on Hackers hold bank to ransom over stolen data
KosGirl

Have there been any further updates to this story? I can't find any information on whether the hackers released the data or not.

6 hours ago by KosGirl on Hackers hold bank to ransom over stolen data
SandJ

I have done 7 speed tests this morning on different speed test tools. They tell me my download speed is: 12.3, 12.3, 12.3, 11.1, 12.7, 12.7, 11.7...

6 hours ago by SandJ on Watchdog: TalkTalk's broadband speed test misled users
Jack Schofield

@Mary Microsoft could always send Mozilla a spec sheet and oblige them to meet the same standards as IE. Then Mozilla can spend millions of...

10 hours ago by Jack Schofield on Windows RT browsers and the point of Windows RT
goth1csnake3

Not before time, that people making films,dvd's get whats coming to them. Well done, Virgin Media.

12 hours ago by goth1csnake3 on Virgin Media: Spotify deal will bring down piracy
Simon Bisson and Mary Branscombe

Apex - the question then is what about letting the user choose to have a tablet where they don't have to have that responsibility? why can't the...

22 hours ago by Simon Bisson and Mary Branscombe on Windows RT browsers and the point of Windows RT
Simon Bisson and Mary Branscombe

Moley, Apex, thanks; I think there's an interesting other dimension of choice - the choice to have a platform that is 'locked down' in the sense...

22 hours ago by Simon Bisson and Mary Branscombe on Mozilla accuses Microsoft of shutting Firefox out of WOA
Yellowcave

Not surprised. I once used the methods to let my firewall just notify me of breaches. Not one single logged event was genuine. Once, we all...

1 day ago by Yellowcave on Mobile porn filters catch innocent content, says report
duplex

live realy sucks in facebook becuase people hack your profile

1 day ago by duplex on Irish watchdog: Facebook privacy still falls short
Ed Macnair

If only it was that simple. When you start accessing Cloud applications you are stuck with the security model the vendor provides...........unless...

1 day ago by Ed Macnair via Facebook on IT security? You're doing it wrong!
Phil at Cloud4

Another good updaet, I have enjoyed going on the journey reading this series on SharePoint 2010 and have learned alot. Great writing.

1 day ago by Phil at Cloud4 on Designing a SharePoint farm: Tiers before bedtime
muteen

roumers of an ipad Mini, isnt that just an iTouch!?

1 day ago by muteen on Apple rebrands iPad 4G as 'Wi-Fi + Cellular' for UK
apexwm

Thanks for this article and bringing this issue to light. Unfortunately this type of activity is common not only with Adobe, but many other...

1 day ago by apexwm on Adobe move promotes piracy
Andy Bolstridge

there's a very thin line between tax avoidance and tax efficiency - earning £850 a month and claiming dividends to bring my income up to normal...

1 day ago by Andy Bolstridge via Facebook on The Idle Self-employed
Andy Bolstridge

I see that they are happy to announce these numbers.. but no-one will take any notice until they start announcing sales numbers too.

1 day ago by Andy Bolstridge via Facebook on Microsoft's score card for Smoked by Windows Phone