Subscribe to Updates in Technology, Media & Telecom

RSS By Email

RSS By RSS

Add to Google Reader or Homepage

Subscribe in Bloglines


The Expertise Imperative and Compliance Technology
Access to a diverse array of specialized expert inputs drives superior decisions in every organizational context: within corporations, by investors and consultancies, and within nonprofits. When decision makers are confident of their decision inputs, they can respond more quickly and creatively to challenges and opportunities.Learn more about GLG's Compliance Framework


This page may include content provided by Council Members, your access to which is subject to the Terms of Use.
Find Out More

December 10, 2007

Laws on Online protection are behind the times

Analysis of: Looming Online Security Threats in 2008 | www.businessweek.com
This analysis is solely the work of the author. It has not been edited or endorsed by GLG.
Analysis By:
Cliff Bell, Chief Information OfficerCliff Bell
Chief Information Officer, Infogain Corporation
Implications: 1. It is difficult for law to keep up with quick changing business and technology. 2. People take advantage of the lag is consumer protection.

Analysis: Security problems in 2008 are looking a lot like security problems in 1988.  In 1988, you could post an ad in a newspaper selling fake copies of a copyright document that you had photocopied.  Or you could receive a fake chain letter and be tricked into giving away money.  In 2008, the same methods of fake emails, using copyrighted material to trick you into some action.

I sure do miss throwing away scams I received in the mail.  They were annoying just like the article mentions about those early misspelled emails. 

The problem today is the speed at which the law can be broken.  It is also harder to trace the fraud back to the originator.  And lastly, the fraud today is a global business.

The internet has made getting to things a whole lot more efficient.  And that goes for crime.  Crime can be very efficient.  I now get emails from friends one or twice a month warning me about some new cyber crime.  It is like the neighborhood watch, except the neighborhood is the internet.

The technology to trace information back to the source is much more difficult.  It was hard, but usually you could trace all paper mail back to the source mailbox or at least a post office.  With Cyber crime, this is difficult at best and sometimes impossible.  Even when you find the source, it could be someone's compromised computer that had nothing to do with the crime.  It would be unlikely that I would send money in an envelop to China, but a mouse click going to China (or anywhere) looks the same as anywhere else.  And tracking cyber-crime is not automated leaving investigators overwhelmed.

So what can you do as a CIO?  I know some companies have started to block access to sites such as facebook and my space.  Whether you decide to do so or not, I think it is important for CIO's to educate the user community.  Find ways to protect your data and block traffic being sent to unknown sites.  We often send out emails to warn out users of threats we hear about.  We view this as our duty in IT.  There are also some new companies that are starting up that use fake emails to test your user community to become aware of this type of fraud.

I remember learning the laws of how to stop post office fraud when I was in college.  The challenge today is that the laws are much more complex because of the new nature of the fraud.  So making laws is more complex.  This is not the first time this has happened.  During the beginning of the banking system, there was much crime that took people's money before the laws were written.  And labor laws were not written until well after the industrial revolution was underway.

So, as much as I would like to think the laws and protection should be solved in short order, I do not think this will happen.  The information revolution has created another period of time where the laws will be forced to catch up with the crimes that have occurred.  In 1988, they used to say, "let the buyer beware".  In 2008, the word is "let the surfer beware".  A CIO's job in 2008 is to remind the business user of this fact.

Other Analyses of the Same Source Article:
Generalizations Are False
January 22, 2008, Author: GLG Expert Contributor
PT Barnum's famous "sucker born every minute" quote didn't factor in Internet Time
January 2, 2008, Author: GLG Expert Contributor
Response to security threats same as they have always been
December 17, 2007, Author: GLG Expert Contributor
Your PC is safe now, but your MySpace page is not!!
November 26, 2007, Author: Hans van Rietschote, Senior Director, Symantec Corporation
Security Threats in 2008
November 20, 2007, Author: GLG Expert Contributor
Growing Security Threats – It Is About ACCESS and TRUST
November 20, 2007, Author: P.J. Louis, President, PJ Louis LLC
The Annual "Online Security Threats" Repeats The The Same "Old" Stuff
November 19, 2007, Author: GLG Expert Contributor
The Internet is not necessarily safe or accurate - CYA
November 19, 2007, Author: Scott Holcomb, Chief Executive Officer, HOLCOMB ENTERPRISES
Social Engineering - Information Security; The Weakest Link
November 19, 2007, Author: Shawn Burgess, CIO/Director, Kingman Hospital Inc
The Dangers to Information Infrastructures and Sources Due to Internet and Cybercrime
November 15, 2007, Author: GLG Expert Contributor
Cybercrime and Cyber warfare
November 15, 2007, Author: GLG Expert Contributor
New Technology and Capability Bring New Security Challenges
November 14, 2007, Author: John Pironti, Chief Information Risk Strategist, CompuCom

Report a Concern

GLG News: What Experts Think Is Important





Analytics


Generated at 2008-09-04T21:45:16.757