Sunday, April 29, 2012

IT Policy for the Win











IT Policy for the Win
Samuel Warren
IS464 - Policy
Professor Ryan Gunhold
January 26, 2012




I.T. Policy for the Win
            There are many drivers in the world of Information Technology (IT). If IT were a car, policy would be the chassis. Just like a physical car could not drive without the chassis, IT cannot function properly without policy. To carry this thought further: there are good and bad frames. All of the very best frames help to enhance and further guide the drive-ability of the car. Bad frames are accidents waiting to happen. Policies, just like the aforementioned frames, must enhance, control, and cause an increased effectiveness of a business. If they do not directly, and positively, affect the business, what good do they do? A study of two recent policy decisions, one good, and one bad, will help to frame a discussion of how to better manage policy development, deployment, and enforcement.
            Since its creation, there is no doubt that Google has vied for greatness. When they started in 1996, they have had one simple goal, “…to organize the world‘s information and make it universally accessible and useful” (Google.com, 2012). With so much information in the world, this goal becomes very daunting unless there are good policies to keep track of how Google operates. On January 24, 2012, Google unveiled a unified approach to privacy. According to their blog,
The main change is for users with Google Accounts. Our new Privacy Policy makes clear that, if you’re signed in, we may combine information you've provided from one service with information from other services. (2012)
            With so many products out there, most of which are free to anyone willing to sign up, the approach seems to make sense. But does it? By combining your information across multiple tools, the lines between Google’s tools blur and may cause problems. Imagine having all your data available for Google and to whomever they decide to sell it. The worst part of the whole new privacy policy is that they are attempting to play this move as a helpful tool for better, more accurate searching and sharing across all of one’s Google tools. However, Google’s main revenue is from advertising (Dawson, 2012); that said this policy seems more self-serving than noble. If Google holds all one’s personal data, they could, in effect, tailor large amounts of ads based off of user profiles to spam all the applications one has under their name. Because they know exactly what a user does on their applications that would be like selling alcohol to an alcoholic. It is not illegal, but it does raise a question of appropriateness. Should someone who knows exactly what users search for, read, post, and watch be allowed to make money on the knowledge that one will have a higher likelihood of clicking the links? Google maintains that they already had the information (Dawson, 2012). When developing this policy they seemed to overlook one crucial behavior of users: compartmentalization.
            Simply put, this is the behavior of using different tools for different things. By combining all of the tools into one user-focused place, means Google will not allow one to use Google Adwords for their small business without it being affected by their Google Search, Google Plus, and Youtube behavior. All that data rolled into one location would make for an extremely tempting target for would-be data thieves.
But for others, Google’s moves reinforce just how much the giant company knows about them, from their browsing history to their email conversations. For those who want to “compartmentalize” their lives, with some services reserved for personal use and others for business or public use, the pooling of information is a very real threat. (Ingram, 2012)
When developing privacy policy, businesses must not simply look to their own needs. They must take into account things like compartmentalization and how real customers use their systems. Having a way to “opt-out” of this change would go a long way to encouraging friendly adoption of this policy by Google’s supporters and would have lessened the sting from their opponents.
            While the development of this new privacy policy was not the best, Google did do a pretty good job of deploying the new policy. On Google’s blog they fully explained the major changes, and even gave a brief video to explain the changes. The explanation was easy to understand and simple to follow. It did a good job of reassuring its fans of the need to keep the information streamlined and unified. However, the glaring hole in the development and lack of consideration clearly outweighs whatever good work Google did in promoting the policy.
            The last key area of policy management that Google seems to struggle with on this policy is the area of enforcement. If one is ok with their policy, then there are no problems. But as the aforementioned quote points out, some are now more aware of the fact that Google is swiftly becoming more knowledgeable about its users than the Federal Government. If users are concerned, there is really only one option: leave Google and all of its tools behind. That is it; no other options. They did not give anyone the option to try it out or to put up a flag to say, “Please do not share my information across tools, I like it the way it is.”
            With the vast amount of free tools and services that Google puts at one’s fingertips, one may very easily sacrifice their desire for privacy to be able to have access to their favorite Google tool. However, the fact that it conveniently serves up your information into one place for would-be hackers and spammers means that there is a price associated with this new privacy policy. On the flip side of this bad IT policy, is a new idea that is starting to gain traction.
            Swedish Medical in Seattle is embracing a new policy called “Bring your own Device.” It means using one’s personal device to assist in his/her job. However, it typically sends shudders down the spines of the Chief Information Officer (CIO) and the Information Security (InfoSec) teams. To understand why, one must understand the sacred trust that CIO’s and InfoSec teams share. The trust they share involves the protection of all the information their organization gathers and resources. Whether that be directly acquired information, such as the company’s customers, or indirectly acquired, such as a purchased marketing list; the information must be protected.  Also, they must take into account protected Intellectual Property and trade secrets; it is no wonder the previously mentioned teams are nervous. Each personal device represents a possible hole in the security infrastructure. Because the electronic devices are typically used to access secure information, patient data in the case of Swedish Medical, it is very important to the InfoSec team and the CIO that the information is then completely removed from the device. If said device were to be stolen or misplaced by its owner, the information would probably be accessible by anyone. Additionally, the use of some password storage tools on the device may add to the convenience of repeated access, all the more reason to carefully consider how this type of policy will be enforced. 
            Some recent research suggests there are several good reasons to develop a “Bring your own Device” policy. Charles Bess, a blogger for Hewlett-Packard, suggests the following favorable areas: Cost-control for the company, higher overall morale, increased productivity for the employee, freedom from the limited devices supported by the company, and flexibility. According to Bess, “If employees are allowed to use a device that they want to use and are familiar and comfortable with, it stands to reason that they will be more productive” (2011). While these areas are not a guaranteed win in IT, especially since there are so many possible problems, doing some sort of Risk Analysis should be a priority prior to implementing anything along these lines.
            With Swedish Medical’s decision to allow “Bring your own Device,” doctors are finding a new level of communication and service with their comrades and patients. Inasmuch as he is using his personal Apple iPad, a doctor was able to make a potentially life-threatening decision from the comfort of his home. A woman went into one of the Swedish Medical hospitals and was going to get a procedure done that would require her to be removed from her regimen of anticoagulants. His colleague called him,
[Dr.] Westcott was at home when he got the call, but he had his iPad and logged into his hospital's Epic electronic medical records system's iPad client and was able to see that the woman had an artificial aortic valve and must remain on the drug for that reason. (Carr, 2011)
This kind of collaboration, especially in light of the potential loss of life was the kind of scenario that must have played out in the development of this policy. Getting more access, while remaining secure, should be a goal of every IT department. In this case, the patient’s record was also secured inside a separate information system, which has password authentication associated with it. Swedish Medical is still in the process of testing, as are many medical groups, the potentially positive impact of a “Bring your own Device” policy. One area for concern is the physical bacteria level of a device brought in from the outside. Or even the fact that the personal device could be left unlocked and open with patient data outside the hospital, or doctor’s home.
Despite all the benefits, many hospital and healthcare technologists are still trying to sort out where the iPad and other mobile devices fit into their medical bags. Ensuring information security and protecting patient privacy both loom large in the context of devices that can easily walk out the door. If it's a doctor's personal device, rather than hospital property, it's going to exit at the end of every shift. While that lets the doctor quickly look up medical records when called at home or at a restaurant, it also opens up the possibility that the device will be left behind on a restaurant table. (Carr, 2011)
During deployment of any policy related to “Bring your own Device,” Swedish Medical would need to be abundantly clear about who is able to take advantage of this policy, as well as when they can participate. Allowing anyone access to patient records at any time would cause a serious breach in the age-old code of doctor-patient confidentiality and would cause numerous potential problems for InfoSec teams, possibly outweighing any benefits. On the other hand, with what is clearly a potential for productivity increase, a “Bring your own Device” policy may require some additional costs-benefits analysis.
While enforcing this policy, one needs to consider the potential impact associated with their field. After all, showing someone’s name, address, and email address is far less damaging than showing a patient’s medical records. Swedish Medical and other hospitals must take into account the potential for their networks to be breached through the personal devices. To mitigate that, one hospital, Seattle Children’s, uses middle-ware presentation software to allow viewing access, but no direct access to the patient records (Carr 2011).
With different cars, come different chassis’ or frames. The same can be said for IT groups and policies. When developing policy, one needs to be keenly aware of what their customers and most loyal users think, while keeping technological changes in their mind’s eye. Understanding that no policy is perfect, nor will it ever last forever, is a wise approach to creating policies in the IT world. Also, one needs to be cognizant of the number of policies created:
In smaller organizations, a single policy document may be enough to address most Information Management issues. However, most medium and large organizations will require a number of different policy and practice documents to adequately address the Information Management needs of different departments and different operations. (Kahn & Blair 2009)
While making it easy for the organization, as was the example of Google’s privacy policy, is dangerous. It borders on what Kahn and Blair call a “catch all” (2009) policy, which they say should be avoided as much as possible. While making it easier for Google to manage the multiple applications, it takes away the freedom of users to choose what applications with which they want to interact. For example, if I want to only use Gmail, when I register a new user email on Gmail, they take my information and share it. Now Google+, Google Music, Google Calendars, Google Search, and Youtube all have access to that information. This makes it convenient for Google, but tough on users. By comparison, Swedish’s policy is making it easier for users and puts limits on the support given to the users, thereby keeping costs down. Development, deployment, and enforcement should not be passed over lightly. They are the key pillars of successful management of policy. Adding to the pillars, it is important to make clear, concise, and granular policies. Each company should manage their policies with the intent to protect their employees, their information, and their customers. By avoiding the pitfalls of catch-all policies, as well as the temptation to rush the development and deployment phases, corporate policy can be a win-win for everyone. When enforcing policy, corporations must be consistent and follow their policies. If the policies are outdated, they ought to be reviewed by the Human Resources department and management. If they are too big, they should be broken down with clear verbiage and description of consequences associated with non-compliance. No group is exempt from policy within the corporate entity, including the CEO; therefore, enforcement must happen at every level.

References
Bess, C. (2011, October 26). Are there 5 top reasons CIOs should allow a Bring Your Own Device (BYOD) policy? [Web log post]. Retrieved from Enterprise CIO Fourm:
http://www.enterprisecioforum.com/en/blogs/cebess/are-there-5-top-reasons-cios-should-allow-bring-your-own-device-byod-policy
Carr, D. (2011, May 21). Healthcare. In Healthcare Puts Tablets To The Test [Editorial]. Retrieved January 26, 2012, from InformationWeek website: http://www.informationweek.com/news/healthcare/mobile-wireless/229503387
Dawson, C. (2012, January 25). News & blogs, Googling Google. In Confessions of a Google junkie (or, Privacy? What privacy?) [Online Editorial]. Retrieved January 23, 2012x, from ZDNET website: http://www.zdnet.com/blog/google/confessions-of-a-google-junkie-or-privacy-what-privacy/3553?tag=content;siu-container
Ingram, M. (2012, January 25). Google’s new privacy policy: Should you be concerned? [Online Editorial]. Retrieved January 26, 2012, from GigaOm website: http://gigaom.com/2012/01/25/googles-new-privacy-policy-should-you-be-concerned/
Kahn, Randolph & Blair, Barclay. (2009). Information nation: seven keys to information management compliance. [Books24x7 version] Available from http://common.books24x7.com.proxy.cityu.edu/toc.aspx?bookid=29596.
Whitten, A. (2012, January 24). Updating our Privacy Policies and Terms of Service [Web log post]. Retrieved from The Official Google Blog: http://googleblog.blogspot.com/2012/01/updating-our-privacy-policies-and-terms.html


Saturday, April 28, 2012

I2010 Standards: Influence beyond Europe














I2010 Standards: Influence beyond Europe
Samuel Warren
IS464-Policy
Ryan Gunhold
City University
March 3, 2012



Contents
Executive Summary........................................................................................................................... 3
I2010 Standards Overview................................................................................................................ 3
Impacts on eGovernment................................................................................................................... 4
Impact on Other Businesses............................................................................................................... 6
References........................................................................................................................................ 6


Executive Summary

Standards are a great resource for organizations that are emerging into their chosen market. The European Union (EU) took some common standards and decided to act upon them. The newly christened “i2010” was a grand project to increase revenue, innovation, jobs, and the collective economies of the EU. While they are often beneficial from an end-user perspective, they can be very costly and complex to maintain, as discussed herein. The following outlines some of the key understandings of how the standards influence, not only eGovernment, but also businesses directly affected by the standards.

I2010 Standards Overview

Standards are multifaceted and extremely hard to get right. Most often, standards are created to rally partners around a common framework, or guiding principle. When larger groups set standards for other groups to follow, the constant search for balance comes into play. Forcing one’s set of standards on other groups can be a dangerous and costly venture. When the European Union (EU) was formed, they began to assemble collective standards including standards for Internet technologies. Thus, the newly christened i2010 was created with several goals to improve the collective Internet technologies. The goal was to make broad and sweeping technological changes in the European Union by 2010. The governing body wanted to make ICT (Internet and Communications Technologies) readily available to every person living in the EU, as well as those outside.
Information and communication technologies are a powerful driver of growth and employment. A quarter of EU GDP growth and 40% of productivity growth are due to ICT. Differences in economic performances between industrialised countries are largely explained by the level of ICT investment, research, and use, and by the competitiveness of information society and media industries[1]. ICT services, skills, media and content are a growing part of the economy and society. (European Commission Digital Agenda, 2005)
There are positives and negatives to these standards being implemented. While the standards are implemented, some of the positives include improved user experience, access to the Internet for all citizens. Another major positive is the ability within the EU to connect to other services and applications much more quickly.
The interconnection can be very good, but it may also be a negative. Unless there is a clear delineation of applications with security for each, protecting the systems would be a nightmare. Creating access and interconnection between applications presents a huge vulnerability. Because information is shared freely between Internet applications and other technology, such as cellular phones, an attacker would only need to gain access to one vulnerable system to gain access to all other connected applications. When determining international standards such as i2010, one should be aware of the risks and determine the best course of action to combat the possible loopholes.

Impacts on eGovernment

Along with the standards provided by the European Commission for Information and Communication Technologies, there has been significant improvement in how government interacts with its constituents. Since the beginning of the Internet, there have been proponents that have pushed its potential. They have pushed as many services as they can online. One of the first services available was a bulletin board for people to dial into using their modem. With the invention of DSL, Broadband, and Fiber-Optic based Internet connections, and tools that can communicate that rapidly, the Internet exploded. What was once a bulletin board and e-mail landscape has quickly shifted to eServices, ecommerce, live-video streaming, music transfer, and the like. It seems only natural that the government, which requires a high level of communication internally and externally would follow suit. Creating a system that allows Department of Licensing tasks to be done online or paying taxes online makes it easier for the consumer and the government to communicate and handle business. That said, having broadly accepted standards for a group of nations, as is the case with the European Union (EU), makes it easier for the citizens of the EU to interact. However, there is a side to setting up this sort of international standard that is not as good. Managing eGovernment requires an immense amount of bandwidth and infrastructure. Many of the i2010 standards are aimed at making infrastructure changes to provide higher broadband connection speeds, but at what cost? The commission has said that it is investing 11 billion Euros into this project (European Commission Digital Agenda, 2005), which is equivalent to roughly $14.51 Billion USD, more than Starbucks’ 2011 total revenue (Starbucks, 2011). Cost is not the only factor to keep in mind. According to Fenwick and Stimac,
Governance becomes increasingly complex in a society with a substantial number of daily transactions. This occurs because the relationship between the number of transactions and the resulting burden on governance is not proportional. Each transaction imposes its own burden, which is amplified by many layers of government. (2009)
Essentially, when you take a high rate of online transactions, which is one of the chief goals of the EU’s i2010 standards (European Commission Digital Agenda, 2005), and pair it with multiple layers of government, you get multifariously complex systems with extremely slow reaction time. The goal of self-service is a noble one; however, eGovernment needs to be carefully monitored and built so that when the layers of government stack up, the Internet portion of the government is not an afterthought.

Impact on Other Businesses

            While the impacts of adding standards to eGovernment may help, especially at an international level, the impact on businesses is most often negative. When standards are enforced by any agency in an attempt to make everyone “play nicely,” the businesses involved frequently have to pay more to keep up. One key example: PCI compliance for credit and debit cards. Visa started with the Consumer Information Security Program and the rest of the industry followed suit. PCI Compliance is now a required task for any organization wishing to transact on the Internet. While some may say being in compliance with PCI is not a requirement, think of trying to build an eCommerce platform using only Paypal, or hand-written checks sent in the mail. The ongoing costs of PCI, too, are not simply money, but manpower. Internet developers, working in parallel with Information Security and Network technicians must scan the systems, constantly keep up with new PCI requirements, and repair any noncompliant issues. Obviously, with such a potential loss looming, organizations must do everything within their power to keep in compliance. For some smaller organizations, the costs may be too much to allow a continued foray on the web.


References

European Commission Digital Agenda. (2005). Communication from the Commission to the Council, the European Parliament, the European Economic and Social Committee and the Committee of the Regions - “i2010 – A European Information Society for growth and employment. Multiple: European Union.
Europe's Information Society. (2010). i2010 - Digital Single Market. Retrieved from European Commission Digital Agenda: http://ec.europa.eu/information_society/newsroom/cf/pillar.cfm?pillar_id=43&pillar=Digital%20Single%20Market
Fenwick, W. J. (2009). The necessity of egovernment. Santa Clara Computer and High. Technology Law Journal, 25(3), 427-465.
Starbucks. (2011, January 26). Starbucks Reports Record First Quarter 2011 Results. Retrieved from Starbucks Corporate Site: http://news.starbucks.com/article_display.cfm?article_id=495


Friday, April 27, 2012

Failing Adequacy: Policy problems abound








Failing Adequacy: Policy problems abound
Samuel Warren
IS464-Policy
Professor Ryan Gunhold
City University
February 20, 2012



Contents
Executive Summary........................................................................................................................... 3
Introduction...................................................................................................................................... 3
Incomplete Phases............................................................................................................................ 3
No Ownership................................................................................................................................... 4
Social Awareness of Intentions.......................................................................................................... 5
References........................................................................................................................................ 6





Adequacy is a term that denotes meeting standards. While adequacy in and of itself is just above mediocrity, it is something that has to be attained along the way to greatness. During the development, deployment, and enforcement of policies, there are often problems when lack of completeness, lack of ownership, and lack of awareness of the reasons behind the policy are present. To be sure, these issues are not the only issues that could arise; however, they are three of the most commonly occurring issues in policy creation today.
When policies are created, they go through three separate, yet interconnected phases. Development, deployment, and enforcement need to be taken seriously if one is to create effective policies. During the creation process, there are many critical points where a policy can fail at any attempt at adequacy. Three such points are when the phases are not fully completed, when no one takes ownership over the policy, and when there is little to no awareness of the intentions behind the policy. Any one of these points could spell disaster for a new policy if left uncorrected; so it is imperative that the policy control group is watchful for their signs.
During the aforementioned phases, there are points at which it may seem appropriate to skip ahead, but that is dangerous. The most common reason development, deployment, and enforcement go to an incomplete state is the workload factor. When policy is created, it most often comes in the form of “blue sky” or ideal scenarios. When a large amount of workload is pushed onto this policy it is akin to putting stress on a load-bearing wall. If the wall is not built correctly, the pressure will cause it to fracture, crack, and fall apart. If enough of these load-bearing walls are compromised, the entire structural integrity is at risk.
For these situations, where available resources are already constrained and a decision is riding on the risk assessment, it is recommended to stop all other work and assign all the resources to risk management activities. (Peabody, 2010)
When developing, deploying, and enforcing policy, it is crucial that time is set aside to monitor the effectiveness of the phase prior. If time is not given, the weight of the workload, as Peabody indicated, runs additional risks. Furthermore, Peabody recommends a complete work stoppage prior to doing any risk assessment. While he is speaking strictly of risk assessment, the idea holds weight with policy creation.
            Another major issue that could arise during development, deployment, and enforcement of new policies is no one claiming the policy and taking ownership. Taking ownership of a policy is a scary thought to some because it requires a modicum of responsibility. Owning up to the idea of allowing all employees to wear jeans in private, or to one’s team, is one thing. However, as soon as it is brought up to the level of an entire organization, that idea could come under scrutiny. While some accept this, there are those who will never be comfortable with the idea of owning a policy. Therefore, the management of each group should be the authorizing party for any new policies. They should help to craft the policies and bring guidance in order to be the owner of any new policy.
            The final issue that needs to be mentioned is the lack of social awareness as to the intention of the policy. If there is a dress code policy that states “all employees must wear business casual clothing,” but no employees understand the reason for it, then it becomes almost impossible to manage perception when there is an enforcement issue relating to the policy. The intention of the policy is not to inhibit comfort, but rather to provide a more professional appearance to the many visitors that show up at the organization. However, if every employee understands the policy and their interaction with it, the understanding aids in what Michael McKinney describes as “ownership thinking” (2011). He adds:
When people understand the business, their role in it, and are informed of what is going on and take responsibility for the outcomes, then they become better stewards of the company’s resources and help to create wealth. (McKinney, 2011)
            Not only does this aid in the understanding of policy, but also as indicated, employees actually assist in capital increases, efficiencies, and resource management. That kind of buy-in cannot be bought, it must be caught. The only way to do that is to create a culture that is transparent with intentions and shares readily the intentions behind everything being done, including policy.

References

McKinney, M. (2011, September 13). Ownership thinking. Retrieved from Leading Blog:Building a community of leaders: http://www.leadershipnow.com/leadingblog/2011/09/ownership_thinking.html
Peabody, J. &. (2010, August 8). Final Report: Rushing Risk Management. Retrieved from MIT.EDU: http://jo18926.scripts.mit.edu/JohnPeabodyJr/wp-content/uploads/Peabody+Pietrzyk_RushingRiskManagement.pdf


Thursday, April 26, 2012

Incident Waiting to Happen













Incident Waiting to Happen
Samuel Warren
CS481
Dan Morrill
City University
December 12, 2011

Incident Waiting to Happen
            When the internet was invented, the goal was to allow computers to share information (Howe, 2010). That goal has since exploded into people sharing music, videos, software, and even their own lives with others through social media. The problem: music, movies, and software, unless shared freely by the authors, have very powerful protection associated with them. So much so that if one uses any of the aforementioned media that was not purchased, and is caught, one may face fines or even imprisonment. Instead of outright hosting files for download on their own personal sites, those who pirate bootlegged media use what are called “Torrents.”
            Torrents work by having a person host the file “seed” to a site. Then someone can go to that particular site, find the file, and begin downloading. The more individuals hosting the file, the quicker the download speed is. “Unlike other download methods, BitTorrent maximizes transfer speed by gathering pieces of the file you want and downloading these pieces simultaneously from people who already have them” (Carmack, 2005).
The biggest problem for the Department of Justice concerning pirating is attempting to stop literally millions of people from downloading media from Torrent sites, such as “piratebay.org.” In this case, anonymity is a powerful ally for the pirates. However, there is a new potential game changer for the Department of Justice, the F.B.I., and other policing agencies that tracks what was downloaded by IP address. It is simple, just go to the website, “http://www.youhavedownloaded.com/#” and it scans your IP address and determines if you have ever downloaded any torrent.
            From a security analyst perspective, the goal is to protect the data and the customers from undue risks. If a security analyst uses tools like the previously mentioned site and checks one of the many IP addresses his/her organization has, he/she could very easily see if someone has ever downloaded files from Torrents. However, not every file is necessarily pirated. For example, open source software that downloads faster on a torrent, someone may have purposefully attached a worm or Trojan to the file. The worst part is that if the file is downloaded outside the corporation’s purview, say while working from home, the user downloading the file would infect the computer. Then when they returned to their network, if there was not a strong scanning system in place, the rest of the network could possibly be infected. A security analyst should file an incident with the senior management to create awareness of a potential breach, exposing the customer base. The next responsible choice is notifying the clients of a potential risk that their data may be exposed.
            This is a very serious situation, because no matter the reasoning behind the download, there is no way to validate, prior to download, if the source is trustworthy. As a security analyst, one has to be constantly vigilant. If an analyst ever discovers that one of their users has downloaded pirated materials, a security incident ought to be filed with management to make them aware that someone has downloaded a file that is either pirated, or may be potentially dangerous. Responsible managers may choose to take action, if possible, against their employee, but notifying the customer base of a possible breach is something that should be done immediately upon detection of torrent download.



References
Howe, W. (2010, March 24). A brief history of the internet. Retrieved from http://www.walthowe.com/navnet/history.html
Carmack, Carmen. (2005, March 26) How BitTorrent Works.  HowStuffWorks.com.
Retrieved from http://computer.howstuffworks.com/bittorrent.htm  
Morrill, D. R. (2011, December 11). Spy on bittorrent i know what you have downloaded. Retrieved from http://it.toolbox.com/blogs/managing-infosec/spy-on-bittorrent-i-know-what-you-have-downloaded-49711