The National Institute of Standards and Technology is working on guidance in the privacy risk management sector, according to a post on the Inside Privacy blog by Elizabeth Canter, associate at Covington & Burling. The institute is known for its work in the security risk management arena. NIST publishes standards security and application standards for public and private entities, said Canter. Earlier this week she reported they’re now considering drafting privacy definitions for programmers.
NIST’s focus for this new project is “on providing guidance to developers and designers of information systems that handle personal information,” said Canter. She said it can also reduce privacy risk and help make decisions on on computer resource allocation and security controls.
The three-tiered focus of the standards comprises predictability, manageability and confidentiality. Regarding predictability, it will outline the rational for collecting personal information. The standards also seek to explain how and when to modify personal information and how to preserve confidentiality within the data.
The comment period for the draft privacy engineering objections is open until October 10.
Last month's International Legal Technology Association annual meeting in Nashville was jam-packed with amazing sessions, brilliant speakers, endless networking opportunities and of course a little honky-tonk!
Cybersecurity and client privacy demands are two major reasons why law firms are now taking information governance seriously. This reality was illustrated quite well by the robust information governance track at ILTA, with several sessions designed to help firms get their info/gov programs off the ground.
Rod Beckstrom’s Aug. 23 keynote address, “It’s a Mad, Mad, Mad Cyber World: Imagine What You Can Do,” made it clear that there is absolutely no privacy in today’s information workplace. Beckstrom's resume includes the former president and CEO of the Internet Corp. for Assigned Names and Numbers, and the founding director of the U.S. National Cybersecurity Center.
Despite the ballroom full of attendees, Beckstrom's presentation was effectively interactive. He engaged the audience by getting everyone into three-person groups that tackled a series of hypotheticals and questions.
Here are highlights from four other panels:
"Build Enterprise Information Governance from the Ground Up," Aug. 18.
Where to start? That’s the biggest question facing law firms when embarking on an info/gov initiative. A theme among panelists: take a three step approach:
1. Collaborate with key stakeholders from IT, practice groups, business units, etc. Make sure everyone understands why info/gov is important and how it affects their day-to-day activity.
2. Break down silos. Too often departments work independently of each other. This is a major roadblock that needs to be eliminated.
3. Concentrate on “low hanging fruit.” Look for short-term projects with fast return-on-investment projects (data remediation, box storage reduction, etc.) that are measurable. That can help you create a culture of "success" and defuse anxiety when more difficult projects are considered.
• “It doesn’t matter if you’re a 20-attorney firm or 2,000 attorney firm, the challenges and the risks are the same. You don’t have to be perfect, the key is to keep it simple and start somewhere,” said Rudy Moliere, director of records and information at Morgan Lewis & Bockius.
• “Choose an existing committee rather than creating a new one. It gives you an opportunity to help with governance-related projects that may exist already,” advised Dana Moore, manager of records and information compliance at Vedder Price. “Following this advice has helped me identify the key players and quickly learn the firm’s hierarchy and best approval routes,” she said.
"Managing IG Expectations Across Generations," Aug. 18
Every generation has different work styles and expectations, which create collaborative opportunities, but also challenge existing models of training, information management and information security. Panelists shared experiences and provided insights on how to manage all these generations while mitigating risk.
Erik Schmidt, manager at HBR Consulting, shared three reasons why he feels understanding the role generational characteristics play in IG is critical:
• Gaining support and approval for info/gov programs requires understanding the mindset of traditionalists/Baby boomers (post World War II) and how to get them to consider changing their established habits.
• Getting adoption from rank-and-file staff requires understanding Generation X (born in 1960s to '80s) so you can train them in ways they will respond to and accept (i.e., self-service, e-learning and short videos).
• To win over Millennials (aka Generation Y, birth dates ranging from early 1980s to early 2000s) requires understanding that they have very different concepts of what is private, personal or confidential in the workplace. Proactive education will not only help generate compliance but potentially prevent significant damage to firm reputation.
"Ungoverned Information Equals Litigation Disaster: What Your Firm Should Do," Aug. 19
Client data often enters a law firm through the litigation support process. It is the firm’s responsibility to engage the right people, implement practical processes and use its technology, to ensure proper governance of client information. This panel competed through a game of “Information Governance Jeopardy,” showcasing their knowledge, experience and lessons learned at their respective law firms.
"Law firms may manage vast amounts of client electronically stored information collected in response to requests for production. Having a system in place to systematically track, retain and, at the end of the matter, dispose this information is a vital component of a well-executed litigation plan," said Brian Jenson, director, litigation and e-discovery services at Orrick, Herrington & Sutcliffe said. "By establishing a repeatable process that can be communicated to the appropriate stakeholders (those that come in contact with client ESI) and audited for compliance, firms minimize the risks surrounding handling client ESI.”
"Aligning Records, Privacy, Cyber Security & eDiscovery Programs to Mitigate IG Risk," Aug. 20
Successful development of an info/gov strategy incorporates the four dimensions of information risk management: records management, privacy, cyber security and e-discovery. Panelists shared their expertise on each dimension and provided real life experiences of how they integrated setting privacy controls, reduced costs and improved compliance at their firms.
"Identifying the key information related processes at the firm (or company) is a crucial first step in creating an information governance strategy to understand and then mitigate the risk associated with these processes," said Bryn Bowen, principal at Greenheart Consulting Partners. Cybersecurity, privacy, e-discovery considerations and proper records management are all significant elements to be considered in this assessment step, as well as in crafting [options] consistent with a sound information governance strategy."
ILTA's Path
ILTA has paved the way for law firms to be successful in executing info/gov programs. Clients expect that its data will be protected against external threats, and lawyers' ethics rules reinforce this requirement. By applying info/gov concepts law firms will position themselves well to help clients mitigate risk and maximize the value of its information.
Have you implemented an info/governance program? Where did you start? How has your firm benefited? Please share in the comments section below, and/or visit Law Technology News' Linkedin group (http://at.law.com/LTNgroup) and continue the conversation.
Back in May of this year there was a “Global Privacy Enforcement Sweep” conducted in 19 countries that assessed the transparency of 1,211 popular mobile applications. These results were published yesterday and according to a recent post on firm site Hunton & Williams, “a large majority of the apps are accessing personal data without providing adequate information to users.”
Specifically, the new information demonstrated a whopping 85 percent of mobile apps that were surveyed didn’t provide users with clear information on how they collected, processed and disclosed their data. In 59 percent of them it was difficult to find information on privacy before the apps were installed and once it was accessed, 43 percent of privacy notices weren’t tailored to the size of screens, according to the lawyers at Hunton & Williams.
“In light of these results, the data protection authorities that participated in the sweep are likely to launch enforcement actions in their jurisdictions,” say the Huntington & Williams lawyers. Most recently the Belgian data protection authority said they were speaking with stakeholders and getting ready to send cease and desist letters in certain severe cases.
Big Data is all around us. That was the conclusion of the International Working Group on Data Protection in Telecommunications, according to special counsel Monika Kuschewsky of Covington & Burling. Well, not quite, but they said it’s “everywhere” and growing on a global level by 50 percent annually. To harness this data while respecting privacy principles, the working group had recommendations, as set out by Kuschewsky in her article on the Inside Privacy blog:
Meaningful consent: When using personal data for analysis and profiling, meaningful consent is your best move. Though it may be possible to process this data without consent, said Kuschewsky, it’s not without risk.
Anonymity is paramount: “The risk of re-identification has been a theme throughout the Working Paper,” said Kuschewsky. To alleviate this risk, stressing anonymity can sometimes eliminate privacy concerns, she said.
Transparency: When collecting and using data, be transparent about it. Kuschewsky suggested, “Each individual should have access to his or her profile, including information on which algorithms have been used, and information should be provided in a clear and understandable format.”
The report, called “2014 ILTA/InsideLegal Technology Purchasing Survey,” is the ninth annual report from ILTA and InsideLegal. Forshee and Elster sent a 31-question, Web-based survey to 1,407 ILTA-member firms to gather information for the report, of which 281 firms responded.
More than three-quarters (86 percent) of respondents were from U.S. firms, with the remainder from Canada (eight percent) and the U.K., Europe, Australia and South America (for a combined total of six percent). The survey was released on Aug. 18.
Responses were collected from smaller scale firms with less than 50 attorneys, as well as larger firms with more than 50 attorneys. Nearly three-quarters of respondents (70 percent) consisted of C-Level, or “director level executives,” the report noted.
KEY TAKEAWAYS
Fifty-four percent (up six percent from 2013) of all surveyed law firms spend between 2-4 percent of their total revenue on technology.
Sixty-two percent of all respondents spend more than $8,000 per attorney on technology.
Forty-nine percent of all respondents said that their technology budgets increased this year from 2013. The number of firms reporting an increase is up six percent from last year.
The top three tech purchases included: laptops and notebooks at 64 percent; desktop hardware and PCs at 63 percent; and network upgrade and servers at 50 percent.
There is a “cooling off” period of Microsoft Corp.'s applications, the report said, as 18 percent of all respondents upgraded their Microsoft Office suites within the past year, as opposed to 39 percent in 2012. SharePoint purchases are also down 14 percent from two years ago, the report noted.
Mobile devices: A majority of firms are purchasing Apple Inc.’s iPhones (63 percent), followed by Android (39 percent) and BlackBerry devices (28 percent).
Tablets: Nearly half (44 percent) of respondents picked iPads, followed by Microsoft Surface (17 percent) and Android devices (10 percent).
Internet research, peer recommendations and consultants are the main influences for legal IT purchasing decisions, the report said.
Unless Congress acts on a major cybersecurity bill this session, the U.S. will face “a major catastrophic event” that takes down an American company or institution in the next 18 months, according to Rep. Michael Rogers, R-Mich., chairman of the U.S. House of Representatives Select Committee on Intelligence.
“Now is the time to act,” Rogers told a high-level conference of government and industry leaders Wednesday in Washington, D.C. “We are getting crushed. We are in a cyberwar, and we are losing.”
He warned that Russia, China, Iran and North Korea “are about a half stroke away” from destroying something like an electric grid. “Cyber will prep our next battlefield,” Rogers warned. “They are developing the capability to wipe us out.”
Rogers said Iran cyberattacked U.S. financial institutions 350 times last year. “We don’t have a sense of urgency on this that we need to have,” he warned. Besides nation states, cyberattacks are increasingly coming from organized criminals, especially in Eastern Europe, the experts said.
The conference brought together members of the Merchant-Financial Services Cybersecurity Partnership, a coalition of 19 associations, including the Financial Roundtable and the Retail Industry Leaders Association.
Most speakers agreed that what is needed is information sharing by the private and public sectors on data breaches and technology strategies. “That’s the guts of this,” admitted Sen. Saxby Chambliss, R-Ga., ranking member of the Senate Select Committee on Intelligence.
So why don’t they just share what they know? Speakers cited various reasons, most dealing with their fears: Fear of competitors taking advantage, fear of liability and lawsuits, fear of loss of privacy for customers and, to a lesser extent, fear of antitrust accusations.
The conference made clear that companies want protection from liability if they are going to disclose breaches more openly and share cyberinformation with the government, other corporations and their customers. And that requirement is one of the snags facing proposed legislation.
Michael Daniel, special assistant to President Barack Obama and cybersecurity coordinator for the White House, pointed out that already there are 47 different state laws mandating some form of disclosure. So a national law that would standardize disclosure should be welcomed.
“The other point is we’re very clear when we talk to companies about sharing information with the government, that we don’t want that to be public, at least not yet,” Daniel said. “We don’t want to give the bad guys a road map.”
One panelist, Joe Demarest, assistant director of the Federal Bureau of Investigation’s Cyber Division, mentioned general counsel a couple of times when speaking about roadblocks to information sharing. And he noted there is often a lack of trust between the private sector and government.
“We collect information, but some people have to work through their general counsel and there is a bit of delay, sometimes hours or days,” Demarest said. “Companies want [information] validated more. We need to get trust.”
He suggested that corporations set up cyber task forces and develop ongoing relationships with the FBI “before we come knocking on your door at 6 p.m. on a Friday evening to tell you about a breach.”
Several speakers made reference to major data breaches, including a massive one at Home Depot Stores Inc. confirmed by the company this week. Assuming the government had shared information about the Target Corp. breach over the holidays with Home Depot, one person wondered how helpful information sharing really is.
The FBI’s Demarest replied, “It’s part of the solution, but only part.” Also vital, he said, are internal policies that hold employees accountable and training on opening emails that may contain malware. “Bad actors are brilliant today,” he added, “so internal controls and training are important.”
Another panelist, Nancy O’Malley, chief payment system integrity officer for MasterCard Inc., spoke of legislation as too slow a process. “The criminal community is moving so quickly,” she noted. “What we’re trying to do is [develop] a payment security task force looking to the future and what we can do to build a safer environment.”
One panelist mentioned Apple Inc.’s introduction Tuesday of “Apple Pay,” a way to pay using iPhones with near-field communication technology. O’Malley said, “Mobile is one of the single most important opportunities to get it right. Now we have a chip that has computing capability for security. Now a mobile secure element is at an unprecedented level in terms of the technology each consumer is carrying in [her] hand.”
Reed Luhtanen, senior director for payments strategy at Wal-Mart Stores Inc., agreed. “You can use a mobile device to create a more secure transaction than a card,” he said. “A merchant never has to see customer private data or numbers. And we need to leverage it for all we can get.”