Showing posts with label big data. Show all posts
Showing posts with label big data. Show all posts

Thursday, May 15, 2014

Jason Atchley : Data Security : Coping With Evolving U.S., State Cyber-security Rules

jason atchley

Coping With Evolving U.S., State Cybersecurity Rules

, Corporate Counsel
    |0 Comments

Cybersecurity and data protection, more than ever, are priority items for the government and private sector. The government’s interest is to protect the country from a cyberattack that will cripple the economy or critical infrastructure. The private sector’s interest is to protect its products as well as the safety of its customers’ financial and private data. Recent high-profile data breaches exposed vulnerabilities in the safety of our country’s consumer data, which is the bedrock of the rebounding economy, resulting in millions of dollars in damages.
The government has reacted by proposing legislative “fixes” that would require organizations to satisfy basic levels of cybersecurity protection and disclose breaches or face fines. Whether a mandatory compliance model for cybersecurity will be effective given the rapid pace by which technology advances is unclear. It may be unrealistic to expect the government’s legislative pace to keep up with hackers.
Another complication that affects the efficiency of solutions is the question of who should regulate and enforce cyber law. To date, federal and state governments have been able to share jurisdiction over cybersecurity and data protection without much controversy, albeit with some inefficiency. However, this shared jurisdiction may be getting more complicated as federal agencies, such as the Federal Trade Commission (FTC), try to take a bigger role.
Regardless of whether cybersecurity laws are enforced on a federal or state level, or both, corporate counsel, who are on the front lines of data security compliance, should be aware of their legal obligations in order to mitigate risk for the organization and its customers. The primary jurisdicational questions that should be on corporate counsel’s radar during this time of change in cybersecurity law are: 1) What is the federal government’s role in cybersecurity compliance, and will it change in the near future? 2) Will a federal disclosure law increase a corporation’s obligations or streamline them?
The Federal Government’s Role
At present, there are more than 50 federal laws that govern some aspect of cybersecurity law. In addition, many federal agencies have jurisdiction to enforce these laws in sectors such as finance, energy and health care. Recent attempts at passing comprehensive legislation have failed, resulting in a piecemeal approach. This began with the 2013 Cybersecurity Executive Order, which created a voluntary best practices model for organizations of all sizes, with a focus on organizations considered “critical infrastructure.” The National Institute of Standards and Technology and the Department of Homeland Security, which have led this initiative, plan to continue implementation efforts in coming years to incentivize organizations to improve their cybersecurity on a voluntary basis led by the private sector.
At the same time, mandatory statutory measures are being formulated. The FTC has been actively advocating for Congress to pass legislation that would increase its enforcement authority and ability to fine organizations that do not adequately protect their data. Congress has drafted bills that would create such a compliance model, but, to date, no consensus has been reached and no new laws passed. Notwithstanding the absence of new legislation, the FTC’s authority to enforce data privacy standards for consumers was affirmed by the judicial branch in a decision in April. A federal district court in New Jersey denied Wyndham Worldwide Corporation’s motion to dismiss an FTC complaint alleging that Wyndham engaged in unfair and deceptive data security practices by failing to maintain “reasonable and appropriate data security” for its customers. In doing so, the court affirmed that the FTC’s authority to redress “unfair” or “deceptive” trade practices extends to data security
The practical reach of the Wyndham decision is unsettled because the court expressly recognized limits to the FTC’s authority in future cases. The court stated that the FTC does not have “a blank check to sustain a lawsuit against every business that has been hacked.” That said, Wyndham involves claims of deceptive practices relating to online privacy policies. In the short term, corporations should take from the court’s holding that accurate descriptions of their online privacy policies (and their effectiveness) must be a priority in order to minimize legal vulnerabilities, such as a possible lawsuit from the FTC. Corporations should also understand that the FTC’s jurisdictional reach and enforcement in the area of cybersecurity will likely continue to expand given the growing support for such jurisdiction in the courts and in Congress.
With increasing FTC authority, it is unclear what will happen to state cybersecurity laws. For example, California and Massachusetts have implemented robust cybersecurity enforcement initiatives. Whether these state initiatives will be curtailed in light of increased federal authority will likely be answered in coming years. For now, corporations should be prepared to comply with both federal and state initiatives until compliance models are finalized.
The Effect of a Disclosure Law
Most states require organizations to disclose breaches of their citizens’ data. Kentucky is the most recent state to enact a disclosure law. The problem for disclosing entities is that state laws have different requirements and thus lack uniformity. In response, one of the proposed federal bills establishes a federal data breach disclosure law. The purpose is to clarify and simplify the onerous requirements of inconsistent state laws. A federal law would also aim to resolve potential jurisdictional obstacles in state court actions where a state is trying to enforce its disclosure statute on an out-of-state organization.
In reality, it is unlikely that states will take a “back seat” to the federal government on data breach issues, particularly because of the state’s interest in protecting the personal and financial data of its citizens. While it is possible that a federal-state cybersecurity disclosure model may evolve similar to that which is in place under existing laws (like the Health Insurance Portability and Accountability Act), a federal disclosure law would likely not supplant state efforts, especially given the limited enforcement capabilities and budget of both.


Read more: http://www.corpcounsel.com/id=1202654946074/Coping-With-Evolving-U.S.%2C-State-Cybersecurity-Rules#ixzz31mz8NZZE




Wednesday, May 14, 2014

Jason Atchley : Big Data : Turn Up the Heat on Big Data Views

jason atchley

Turn Up the Heat on Big Data Views

Use heat maps to persuasively share Big Data.
, Law Technology News
    |0 Comments

When captured smartly, Big Data represents big opportunities for attorneys.  Consider the way thatStanford Law School, in collaboration with Cornerstone Research, illustrates the frequency of new securities class action filings occurring over time.  Assessing eleven industry sectors in the S&P 500 index, Stanford uses a heat map to show the percentage of companies in the index subject to new filings. Viewers of this graph can quickly locate the most frequent filers industry wide by focusing on the colors—the most saturated color, the greater frequency of new filings over time.
Attorneys should think about using heat maps when they want to communicate relationships between data values that would be more difficult to understand if presented simply as two-dimensional data in a spreadsheet.  Caveats do apply:  Heat maps are generally less effective resources for color-blind readers.  Also, heat map colors don’t always look the same printed as they do online.
To take advantage of the potential of heat maps, attorneys don’t have to spend an arm and leg on proprietary software.  While there are a number of third party providers, they can get their feet wet by trying out Excel’s Surface Chart option.  Take a look at both alternatives by watching the following YouTube tutorials.

1. Use heat maps in Excel.

Producer: Annielytics, published July 13, 2013.
Viewing time: 4 minutes.
Style: Presenter Annie Cushing is dedicated to ‘making data sexy.’ That’s a goal few viewers will protest!
Takeaway: Cushing guides you through this Excel feature in less than five minutes.  She shows that it’s a low-cost option that is easy to learn and use.  Some detractors say that Excel’s default color scheme is inferior to those offered by customized software packages. However Excel’s colors can be edited easily to improve their visibility.

2. Use data visualization software.

Producer: Data Champions, published January 19, 2012.
Viewing time: 3 minutes.
Style: This channel provider concentrates exclusively on Tableau tutorials.
Takeaway:  Tableau is one of a number of data visualization providers, (such as MicroStrategy, LabEscape) that offer heat map features.  Smart companies know that many clients associate ‘complex’ with Big Data. Thus Tableau Software boils down their mission statement: “To help people see and understand data.”  The company also offers specialized data visualization packages targeted for over a dozen industries.
Law firms that invest heavily in marketing strategies to drive traffic to their websites are already familiar with heat maps.  These tools are used extensively for analyzing the behavior of visitors—tracking the behavior of mouse clicks (mousetracking heatmaps) and eye movement (eye-tracking heatmaps). With  rapid mobile adoption, heat map providers are also providing  software that tracks  taps, swipes and  other gestures on a variety of mobile devices.
Patricia Kutza is a business and technology journalist based in the San Francisco Bay Area. Email:pkutza@pacbell.net.


Read more: http://www.lawtechnologynews.com/id=1202655185985/Turn-Up-the-Heat-on-Big-Data-Views#ixzz31iQj22oK




Thursday, May 8, 2014

Jason Atchley : Big Data : White House Out With Big Report on Big Data

jason atchley

White House Out With Big Report on Big Data

Obama administration recommendations on big data include a national data notification breach law.
, Law Technology News
    |0 Comments




The White House has released a big report on big data. The 79-page report outlines policy recommendations for the use of personal data in the commercial, education and health-care sectors, said Jo-Ellyn Sakowitz Klein and Francine Friedman of Akin Gump. The report was requested by the president himself, who asked for a study to “examine how big data will transform the way we live and work and alter the relationships between government, citizens, businesses and consumers.”
Klein and Friedman say the report starts by discussing how both public and private entities can make use of big data and minimize its risks. It then goes on to discuss key questions for the development of a policy framework, such as how it alters the consumer landscape and how to protect people from discrimination enabled by this new technology. 
“Although the report does not create binding law, it provides insight into the administration’s priorities on a wide range of privacy and security issues, from government surveillance to data breaches,” said Jeff Kosseff of Covington & Burling.  He outlines some of the key themes emerging from the report: data use vs. data collection, notice and consent, predictive analytics, and law enforcement and digital discrimination.
Other takeaways include the educational component of big data. Kosseff said the report recognizes the “tremendous opportunities for innovative approaches to education,” but warns schools have to ensure the information gathered is not misused. The working group preparing the report also “sharply criticizes data brokers,” said Kosseff, drawing on the fact they’re unregulated, yet their information is often used in the same way as data in regulated industries. And last, but most definitely not least, the report calls for a uniform national data breach notification law, he says.
The study was led by John Podesta, White House counselor; along with John Holdren, the director of the White House Office of Science and Technology Policy; Jeffrey Zients, director of the National Economic Council; U.S. Commerce Department Secretary Penny Pritzker; and U.S. Department of Energy Secretary Ernest Moniz.
Attorney Marlisse Silver Sweeney is a freelance writer based in Vancouver. MarlisseSilverSweeney@gmail.com. Twitter: @MarlisseSS. LTN: @lawtechnews.



Read more: http://www.lawtechnologynews.com/id=1399300179804/White-House-Out-With-Big-Report-on-Big-Data#ixzz318pEuhCv




Wednesday, April 16, 2014

Jason Atchley : Big Data : What is the Best Use for Big Data?

jason atchley

What Is the Best Use for Big Data?

The best data analytics can lead to the same organizational culture.
, Law Technology News
    |0 Comments

Are the big bucks being shelled out on big data not having the big impact anticipated? Michael Schrage wrote in the Harvard Business Review that the best data analytics lead to the same organizational culture.
Schrage’s research suggests it’s how the companies use their analytics that really matters.  The ones that have moderate outcomes are employing big data for decision support, he said, whereas the most successful return on analytics is when “firms use them to effect and support behavior change.”  It seems analytics are the most effective when “they’re used to invent and encourage different kinds of conversations and interactions,” he said.
However, this isn’t as easy as it may seem.  “People may need to share and collaborate more; functions may need to set up different or complementary business processes; managers and executives may need to make sure existing incentives don’t undermine analytic-enabled opportunities for growth and efficiencies,” suggested Schrage.  He used the example of a medical supply company that employed their results not to support existing sales programs, but to implement entirely new ones.  “[T]he most productive conversations centered on how analytics changed behaviors rather than solved problems,” he said.  Ask not what analytics can do for you, but what you can do for analytics.
Attorney Marlisse Silver Sweeney is a freelance writer based in Vancouver.MarlisseSilverSweeney@gmail.com. Twitter: @MarlisseSS. LTN: @lawtechnews.


Read more: http://www.lawtechnologynews.com/id=1397574150063/What-Is-the-Best-Use-for-Big-Data%3F#ixzz2z3ctZlYH