Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts

Wednesday, September 3, 2014

Jason Atchley : Information Governance : Digital Assets Can Be Information Assets

Jason Atchley

Digital Assets Can Be Information Assets

Digital assets are not only valuable, they can also be used to glean important information.
, Law Technology News
    | 0 Comments

Digital assets have become true assets in this day and age. They serve as monetary and information assets. In a recent post on Charles Griffin Intelligence, Philip Segal explains that such things as domain names, Twitter handles and the like should be included in asset searches. Not only are these digital assets valuable, but they’re also useful for tracking people down and investigating them, said Segal. He explained the two most useful ways to digitally track someone down is through domain names and email header information. Here are some more of his tips on just how to use information assets.
  • Domain name registration: Segal said there is a wealth of information stored on a domain name registration, as long as the person or company hasn’t used a proxy. Things such as home addresses, cellphone numbers and other Internet addresses can all be accessed through the registry database.
  • Email headers: According to the free online tool MXToolBox.com, an email message contains two parts: the header and the message body of the email. “A full and valid e-mail header provides a detailed log of the network path taken by the message between the mail sender and the mail receivers.” Using applications such as MXToolBox, such information as where someone sent an email from can be gleaned.


Read more: http://www.lawtechnologynews.com/id=1202668717256/Digital-Assets-Can-Be-Information-Assets#ixzz3CHnyvUpe



Tuesday, September 2, 2014

Jason Atchley : Data Security : How to Guard Against Data Breaches in a BYOD World

How to Guard Against Data Breaches in a BYOD World

While BYOD programs have many benefits for employees, they can be detrimental to an employer.
, Law Technology News
    | 0 Comments

Shot of mobile device consists of laptop computer, mobile phone, and tablet
Bring you own device doesn’t mean bring in your own security breach, said Foley & Lardner of counsel Mark Neuberger (http://www.foley.com/mark-j-neuberger/) in this recent blog post. “As technology continues to evolve, so must your policies,” he emphasized, and noted that while BYOD programs have many benefits for employees, such as increased productivity, improved communications and facilitated remote working, they can also be detrimental to a corporation.
To avoid pitfalls, Neuberger suggests that before any device is brought in, policies and guidelines have been drafted and distributed amongst the company. These should address all the uses of technology, such as how devices track and capture data and work as cameras, recorders and mobile storage units. He suggests prohibiting taking photographs inside plants to protect technology. These policies should then be signed by each employee, somewhat like an employment agreement, he said.
The next step, is preparing for the inevitable—data loss. Devise strategies and make it known companywide that employees must disclose a breach when they know of one. “Getting employees to promptly tell you they have lost their device is the first practical hurdle to overcome,” he said. The next? Getting senior executives on board. Since they’re the ones dealing with the most sensitive information, and as Neuberger says, “operate with less supervision than others,” it’s imperative they understand the BYOD policies and procedures.


Read more: http://www.lawtechnologynews.com/id=1202668502675/How-to-Guard-Against-Data-Breaches-in-a-BYOD-World#ixzz3CACW7QEz



Wednesday, June 4, 2014

Jason Atchley : Data Security : Stand Up to Sue Companies for Data Breaches

jason atchley

Stand Up to Sue Companies for Data Breaches

Before a data breach class action can make it to class certification named plaintiffs must show that they have standing.
, Law Technology News
    |0 Comments

Deborah Renner
Deborah Renner
Data breach cases are often brought as class actions because large numbers of people can potentially be affected. But the potential for injury is not enough to create constitutional standing. Before a putative data breach class action can make it to the class certification stage, the named plaintiffs in the case must show that they have standing to pursue the case for themselves, which boils down to a showing that they were injured as a result of the breach.
While the question of standing remains hotly debated in the data breach context, the defense bar has been winning many recent cases, most recently in In re: Science Applications International Corp. (SAIC) Backup Tape Data Theft Litigation, slip op., Misc. Action No. 12-347 (JEB) MDL 2360 (U.S. D.C. May 9, 2014), in which the U.S. District Court for the District of Colombia held that the “mere loss of data” in a data breach case does not constitute an injury sufficient to confer standing.
The ruling follows on the heels of two other district court rulings holding that standing was not satisfied in the data breach context, Polanco v. Omnicell, Inc., 2013 WL 6823265  (D.N.J. 2013); Barnes & Noble Pin Pad Litigation, 2013 WL 4759588, (N.D. Ill. 2013).
SAIC is an information technology company that was handling data for Tricare, a government agency that provides insurance coverage and health care to active-duty service members and their families.
Plaintiffs alleged that tapes containing personal and medical information for 4.7 million members of the U.S. military and their families were stolen from the parked car of an SAIC employee. The breach victims sued Tricare and SAIC, among others, asserting numerous causes of action (some of which were creative), including increased risk of identity theft, costs related to mitigating future harm, the loss of privacy, failure to adequately protect data and a violation of the right to truthful personal information.
The court granted the defendants’ motions to dismiss the claims all of the plaintiffs who lacked an actual injury traceable to the data breach on the ground that they lacked standing. Only two plaintiffs pled sufficient injury to confer standing.
The court held that plaintiffs lacked standing because the “degree by with the risk of harm has increased is irrelevant — instead, the question is whether the harm is certainly impending.” The court also found that costs incurred to prevent future injury did not create standing. The court also rejected the invasion of privacy claim of most plaintiffs because they did not allege that their personal information had been viewed or exposed in a way that would facilitate access to the data.
The plaintiffs’ claims that were based on alleged legal violations were also found to be deficient: “Standing . . . does not merely require a showing that the law has been violated, or that a statute will reward litigants in general upon a showing of a violation," the court ruled. "Rather, standing demands some form of injury — some showing that the legal violation harmed you in particular, and that you are therefore an appropriate advocate in the federal courts.”
The court also dismissed the plaintiffs’ claim based on deprivation of their “right to truthful information about the security of their PII/PHI,” holding that no independent harm has flowed from that alleged deprivation.
Significantly, as the courts did in Omnicell and Barnes & Noble, the SAIC court relied in large part on the U.S. Supreme Court’s decision in Clapper v. Amnesty International, 133 S. Ct. 1138 (2013), a case outside of the data breach context, decided under the Foreign Intelligence Surveillance Act (“FISA”). In Clapper, the court relied on well-settled precedent to hold that “allegations of possible future injury are not sufficient” to confer constitutional standing. 


Read more: http://www.lawtechnologynews.com/id=1202657423964/Stand-Up-to-Sue-Companies-for-Data-Breaches#ixzz33gR5Y0Xr





Saturday, May 24, 2014

Jason Atchley : Data Security : 12 Tips to Cope With a Data Breach

jason atchley

12 Tips to Cope With a Data Breach

Georgetown Law cybersecurity panelists suggest strategies to minimize impact of data breaches.
, Law Technology News
    |0 Comments

stock art
When customers should be notified of a data breach, how to react if a breach occurs and best practices for preserving data were the topics of a panel at Georgetown Law Center's Cybersecurity Law Institute on Thursday.
“Potential Legal Exposure/Aftermath of a Breach: A Simulation” discussed potential data breach scenarios and how they can best be handled. The moderator of the panel was Kimberly Peretti, a partner at Alston & Bird. Panelists included: Thomas Hibarger, managing director of Stroz Friedberg in Washington, D.C.; Pablo Martinez, managing director of global investigations and cybercrime at Citibank; Joseph Moan, associate general counsel handling employment law and data privacy at Coca-Cola Co.; and Greg Schaffer, CEO of the cybersecurity firm First72 Cyber.
Before a data breach is announced to the public, it is best to make sure that the number of affected users is accurate, said Schaffer, otherwise that number might have to be revised, which can be embarrassing. “It’s not the event that gets you killed,” said Schaffer. “It’s the cover-up that gets you killed.”
Law enforcement might ask that notification be delayed to help aid the investigation of catching the cyber “bad guy” behind the attack, said Martinez, as the incident could potentially be linked to another crime. In the event of a breach, contaminated servers should be taken offline and information necessary to the case should be preserved, said Martinez.
In some instances, law enforcement agencies that have good working relationships with outside counsel will use the firm as a point of contact—for example, if the firm asks to receive the subpoena instead of its client. In that scenario, law enforcement must receive the information they are requesting in a timely manner, and a forensic report must be conducted by a third party, Martinez said.
When a data breach hits, companies are well-advised to overact, rather than underreact, observed Hibarger.
The panelists each shared three data security tips:   
Hibarger: 1) Take a proactive step by creating an incident response plan; 2) have a good information governance policy in place; and 3) make sure that your antianxiety medication is up-to-date, joked Hibarger.
Moan: 1) Have the right data security personnel in place; 2) if a breach occurs, tap the highest-level executives at your organization for a more strategic view of the issues at hand; and 3) get to know government regulators ahead of time.
Martinez: 1) Properly train employees; 2) have a playbook; and 3) make sure that there is an internal communication plan in place before a crisis happens.
Schaffer: 1) Know your data security plan and procedures (so it does not have to be pulled off the shelf in the event of a breach); 2) know your assets (e.g., where your data is and where it flows through an enterprise); and 3) know your vendors (how your data is moving around in the vendor’s system) and acquisitions.
Mark Gerlach is a staff reporter for Law Technology News.
 


Read more: http://www.lawtechnologynews.com/id=1400767741333/12-Tips-to-Cope-With-a-Data-Breach-#ixzz32dn4GXt7




Friday, May 23, 2014

Jason Atchley : Data Security : Protect Your Data Like Fort Knox Guards Gold

jason atchley

Protect Your Data Like Fort Knox Guards Gold

Nuala O’Connor, CEO of the Center for Democracy and Technology, lists cybersecurity threats.
, Law Technology News
    |0 Comments

security concept - Lock on digital screen with world map
security concept - Lock on digital screen with world map
Can digital data truly be secure? This question was the main focus Wednesday during the second annual Cybersecurity Law Institute held at Georgetown University Law Center in Washington, D.C. The two-day conference (May 21 and 22) kicked off with a keynote address from Nuala O’Connor, CEO of the nonprofit Center for Democracy and Technology.
“What is the curtilage of the self online?” asked O’Connor, speaking broadly of the data footprint left by everyday Internet users. “Where is the space that is mine, that is private, that I control?” Data is no longer a property right, she said, noting that the concept of owning your own territory online that no one can access is a “thing of the past.” If the line drawn in the sand pertaining to protecting personal data from the eyes of companies and the government is blurred, individuals will never express themselves freely online, she said.
Honing in on businesses, O’Connor polled both in-house and outside counsel in the audience to see how many attendees at the nearly packed Hart Auditorium knew their organization's chief information officer, chief risk officer and chief privacy officer. “Who is responsible for the system?” O’Connor inquired.
Citing the Target Corp. data breach of last year, she observed that customer trust was seriously wounded by the incident. But there are lessons to be learned from the mishap.
For companies such as Amazon.com Inc., where O’Connor previously worked as vice president of compliance and consumer trust, and as associate general counsel for data and privacy protection, consumer data is like “gold at Fort Knox,” she said. Data is one of Amazon’s primary assets; compromising that data would deal a serious blow to the company’s reputation and the trust of its customers. “When trust erodes, it is very hard to get back,” said O’Connor.
Factors such as angry ex-employees, rogue inside employees, accidental disclosures, poor security measures and various other factors can potentially jeopardize the precise commodity of data for companies, she noted.
The conference was sponsored by the American Bar Association Cybersecurity Task Force, AFCEA International, the Council on Cybersecurity and Inside Cybersecurity.
Mark Gerlach is a staff reporter for Law Technology News,


Read more: http://www.lawtechnologynews.com/id=1400756544884/Protect-Your-Data-Like-Fort-Knox-Guards-Gold-#ixzz32XtDd9T4