Showing posts with label reactive. Show all posts
Showing posts with label reactive. Show all posts

Monday, April 7, 2014

Canadian Anti-Spam legislation (Including software instalation) (Part II)



This blog is a continuation of a previous post concerning the new Canadian Anti-Spam Legislation (CASL). Part I can be found here.

This part will deal with how to prepare for this new legislation.

First of all, the question comes to mind on what should we do to prepare for this law. One must first understand that this law deals with ALL commercial electronic communication from companies, organizations, non-profits, individuals etc, that send out email and install software programs.

Lets take an example or three.

Your company has a booth at a trade show. You have a fish bowl at your booth for a prize draw. After the show, you take all the names of those people who entered the draw and add them to a mailing list. Then as you prospect these potential clients you send out an email soliciting for their business. Unless they have specifically 'signed' permission to allow you to do this (OPT-IN), your company can be found in contradiction of the law and be fined up to $5 million dollars.

Another example:

You have a web site where potential customers can download marketing material on the goods or services you provide. However, you require these web surfers to register before that material would be made available for download. At the bottom of the webpage you have a check box (which is already pre-checked for the user) allowing the company in question to email further updates. This case could be interpreted as being an OPT-OUT option because the check box is already prefilled. This would satisfy the CAN-SPAM Act (US) but would not be deemed complaint with the new Canadian law that requires an explicit OPT-IN option. And once again the company could be liable for millions of dollars in fines.

And one final example:

You bought a software application to be installed on your Smart Phone (or PC or IPAD or Mac or Tablet). When you start installing the package, there is no explicit consent to allow for the installation, therefore the software company would be liable. Also note that an End User License (EUL) acceptance may not be enough to satisfy the requirements.

Find below a few suggestions that, I believe, would help to start planning for compliance.

1) Take an inventory of all commercial messages that your organization is currently, or planning on sending out. This includes text messaging, Facebook campaigns, emails etc.

2) Discuss and create policies and guidelines that define what a Commercial Electronic Message (CEM) (as per CASL) is within your organization. If there are any exceptions that are applicable these should also be noted within the new policy.

3) Create an all-encompassing list of computer programs that your company directly, or indirectly installs on any electronic device.

4) If applicable, create a list of all computer products (and services) that your organization is involved with. This includes not only the initial software installation but any updates/upgrades that are part of your business process.

5) Discuss and create policies and guidelines that determine when your organization needs to obtain consent for installation of some software. Also note, while there are some exceptions (which should also be documented), all the information will need to be retained for review at a later date.

6) Review current consent that has been collected and see if it complies with the new legislation. If not, a process may need to be created to obtain consent using the new polices. This is further complicated because of the three year transition period mentioned within the law.

7) Document, create, clarify, create a process where the end user can agree to enter into a commercial arrangement, yet withhold consent to CEM.

8) Retain documentation/proof that a written consent was obtained. This includes date, time and manner of consent. Further consideration may also be needed if your organization allows for verbal consent rather than written. Given the strong penalties that can be doled out, every type of consent must be tracked.

9) Update the avenues of interaction between the organization and the end user to reflect the new polices (see above). This includes templates that are used to send out CEM, websites, social media etc. Also be aware that mandatory identity and contact information must be included in any future CEM.

10) Create a process so that the end user can rescind any previous consent. Remember that the withdrawal of consent must then also be forwarded to any third parties and associated companies, if applicable.

Consider the above as only a guideline on how to proceed. Again, I emphasize that this is not legal advice nor is it intended to be all encompassing. Every situation is different.

If you have any questions, concerns  feel free in contacting me.


Monday, October 14, 2013

Robert's Law of security and technology progress


Robert's law of privacy & security.

"The number of advances in capabilities within the online world is proportional to the number of issues with privacy and security."

 A strong statement, some would gather, and something that would seem counterintuative. Would not technology improve security, or as some would say build a better mouse trap?

Let’s delve into this a little further.

We now have a number of cloud computing capabilities that improve the ability to share resources, DropBox, Google Drive, Dump Truck to name but three. These types of software/hardware allows us to share files among our peers within the 'Cloud', thus allowing a more seamless experience when trying to share presentations, school projects etc. Yet this year alone Drop Box (and I only use this as an example as some other cloud suppliers have had security concerns expressed about them as well) had a security issue. In a four(4) hour period, accounts were unlocked and accessible to the general public.

Let’s take another example.

Social media. It is in the forefront of most peoples minds right now. And, as we see, a lot of companies are embracing this new market place with vigor. It is seen, by some, to better connect or re-connect, with friends and family. I for one, keep in touch with relatives from Australia, Hungary and Michigan using a combination of Twitter, Facebook and LinkedIn. Companies are jumping on board as well,  seeing the opportunity to have another marketing vehicle in their arsenal,  providing enhanced customer service and differentiating themselves from the competition. Yet there have been a multitude of security and privacy issues with the social media suppliers. For example, there was the time a that a certain number of users  potentially exposed their personal identifiable information within Facebook. Twitter, another social media darling  had a number of issues concerning security as well.

And another

RFID = Radio Frequency IDentification.. We all use it. But what is it? It actually encompasses a lot of different devices and uses. They include the NEXIS card, issued by the US and Canadian governments to allow pre-screened passengers, speedier border crossings. It allows Jane Smith to tap her credit card on the gas pump reader to pay. it can be used to track merchandise in warehouses etc. Yet within a very short period of time after general deployment in the public arena security issues started to be asked/exploited in both the public as well as informed experts hands.

And finally within the last month (as of this is being written) the fingerprint recognition capability within the new iOS 7 had it’s security questioned. The new capability allows anyone with a new Iphone 5Sc  to buy songs etc., using their fingerprint, in the ITUNE store (more to follow I am sure). Yet within a very short period of time, concerns about the security of this capability surfaced.

So what does this all mean? Should we ban all new technology? While I am sure there maybe some people who would say yes (as there are still some people who believe the world is flat and Elvis is alive) that is not going to happen. If we would have banned technology then, no computers? Or if we waited and implemented the ban when transistors came about. or when the Arpnet/Internet was created, or when the WWW (world wide web) etc. where would we be now?

In reality as the human race continues to explore and innovate, technology will move forward.

So Am I advocating we just plow ahead full steam? Well.....

I think we need to recognize that with each innovation, invention etc the security privacy landscape changes. That when we embrace the new mouse trap, we should also realize that it brings with it potential security privacy issues that need to be addressed.

Let’s take the last example I used.  Apple introduced the new capability stating that Iphone 5S is an innovative way to simply and securely unlock your iPhone with just the touch of a finger. However, noticeably absent was any further discussion about the security component.  While I don't expect a detailed discussion, I do expect a phrase or two addressing the obvious concerns.

Why is it that security (and indirectly privacy) is such  an afterthought.  We introduce new ways to build a better mouse trap1 yet we do not look at what the implications for this new technology are and what changes need to be so it is implemented safely and securely. Companies jump on bandwagons all the time without fully engaging in a analysis of the various issues of concern. Apple introduces a finger scanner, yet a hack was published within the month. Banks introduced 'chip and pin' credit cards and then tried to deny any reimbursement for fraudulently used cards.

So what does this all mean? In all our dealings, whether it is building a new web site (Privacy by Design) or a new technology, we should be advocating Security by Design in what ever we do. It should not be an afterthought. We should expect that there will be issues and not wait for some smart hacker to point out the problems. We should take the bull by the tail and face the situation. Be proactive rather then reactive as we seem to be most of the time. If we do this, then we will hear less and less press releases on how some new technology was hacked and broken. And as a result, a fix had to be  developed and deployed. Never mind the PR issues that raise their head during this event.

FOOTNOTE

1 The actual saying goes like this 'If a man has good corn or wood, or boards, or pigs, to sell, or can make better chairs or knives, crucibles or church organs, than anybody else, you will find a broad hard-beaten road to his house, though it be in the woods' Ralph Waldo Emerson. I prefer the modern version for brevity, if for no other reason.