More Content - Including Podcasts

Friday, February 17, 2012

Policing in the Digital Revolution

Session 13 - Keynote Speaker

Dale McFee, President, Canadian Association of Chiefs of Police


The police of Canada are active players in the digital revolution.
There are four goals here for the CACP:
Quality of service
The public right and responsibility and right tomparticipate
Innovative solutions to crime and public order
Community partnerships

The CACP is not a privacy advocate, but a very interested party in access to information in alignment with those four goals.

Four areas of the CACP relate to privacy and security:
Counter terrorism and national security
Electronic crime
Emergency management and informatics
Law amendments committee

"... The police are the public and the public are the police."
Sir Robert Peele was quoted to make the point that policing the electronic domain is not exclusively the domain of the police, but the public must contribute and participate. Case in point is the wide spread use of portable digital recording devices such as phones and cameras.

Digitally recorded information from the public shifted the perspective of the police as to who were the instigators of the Stanley Cup riots.
Hackers recently outed NeoNazi groups in Canada to the RCMP and prevented hate crimes.

Court acceptance of digital evidence varies by region and by individual judge, as the law is vague and open to interpretation. Police will continue to test the bounds of digital privacy in the interest of keeping peace and preventing crime, while respecting the Canadian charter of rights and freedoms. This document is silent on the right to privacy, or at the best, vague.

PI is not defined in the criminal code of Canada.

Information is claimed as the lifeblood of policing, so the plea is for access to the information desired. The police are asking for checks and balances but not roadblocks. The need for privacy is acknowledged, but the need for information is vital. Lawful access debates have been going on for 10 years, and the police are asking for a balance between privacy and safety.




- Posted using BlogPress from my iPad

Location:13th Privacy and Security Conference

Privacy, accountability and the digital revolution

Luncheon Keynote Address
(Salon AB)

Elizabeth Denham, Privacy and Information Commissioner of British Columbia

Privacy, accountability and the digital revolution
Just as the computer revolutionized how we work and the internet revolutionized how we connect with people, we must revolutionize the way we think about privacy in today’s digitized world.
Join B.C.’s Information and Privacy Commissioner Elizabeth Denham for an engaging discussion about how we fuse privacy with technology as the digital revolution unfolds, including case examples and practical tools to help organizations demonstrate their compliance with B.C.’s privacy laws.

This year marks the 20th anniversary of our privacy legislation. It was not predicted how the technologies have transformed our lives. June 1993 had 130 websites, Mosaic was brand new as a graphic browser, the Apple Newton was released, and the US White House had 2 email addresses.

Today 1/3 of the world population is online, and the number of people seeking to mine the data of our online transactions is growing rapidly.

Privacy is not an add on or upgrade, nor is it a lens applied to data moving across borders. Privacy must be part of an organisations DNA.

The encouragement is for us all to become proactive to privacy, not reactively. Last year, her team was split into an investigatory group, and a development team that looks forward to guide organisations and individuals as well help the Office be proactive.

The topic of SmartMeters was discussed; the investigation led to the discovery that Hydro did not provide their customers with adequate notice of their intent. The question was not only is Hydro complying with privacy laws, but can they manage the data they collect. BC Hydro is complying with all 13 recommendations.

The Playoff Riot is the next topic, and ICBCs offer to leverage facial recognition to identify rioters. This led to a realisation that most BC citizens did not know ICBC had and used this technology. The data matching offer was denied because it did not align with the original intended use of the technology. ICBCs data and privacy management program was subsequently reviewed, and recommendations have been reported.

Both of these show the value of strong data governance.

BC's movement into IDM is exciting in our national leadership, but the people, policies, and practices to ensure privacy is baked in has been and continues to be essential to this effort.

Tools are coming available to all organisations for the development of privacy policies and incident response. This relates to the workshop I attended Wednesday morning. In all situations the bottom line to privacy protection is accountability.

An accountability tool is announced. "getting accountability right for privacy management frameworks" is a document that will be publicly available in two to three weeks.

Bill C-30, which combines previous bills that failed to pass the house. Police and other authorities are granted access to private information with much lower thresholds of access controls than ever before, and Canadians fundamental rights to privacy and confidentiality is at risk, and concerns about lawful access need to be brought to bear against your MPs. Elizabeth clarified that she has concerns about the bill as it stands, and that should be a consideration for us all.


- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

Cyber Security Panel Debate

Panel B: Cyber Security
(Theatre)

Privacy and security are truly symbiotic, yet because each has its own focus and proponents, there is often contention. This esteemed panel of experts will work towards ending some of that conflict. We will begin with a simple question: What are the top 3 things that security experts can offer the privacy sector that have not yet been adopted or integrated? Why are they so important and how can they benefit the goals of privacy professionals? In a PowerPoint free setting, this issues-oriented panel is designed to be highly interactive, encouraging audience questions and spirited debate so attendees come away with new insights and approaches.

Moderator: Winn Schwartau, President, Interpact Inc. Author of Information Warfare, Cyber Shock, Time Based Security & Internet & Computer Ethics for Kids
Speakers:
1. John Engels, Group Product Manager, Enterprise Mobility Group, Symantec
2. Robert Dick, Director General, National Cyber Security Directorate
3. Steve Hutchens, Director, Global Government Industry, HP
4. Paul Laurent, Public Sector Director of Cybersecurity Strategy, Oracle Canada
5. Eddie Schwartz, Chief Security Officer, RSA

Our moderator starts with a position on the critical infrastructure interdependencies between nation states, and the related privacy issues.

Robert rebuts the moderator's proposal that the US invade Canada to protect power reserves with a reference to the 100th anniversary of the war of 1812.
Robert moves on to note the seriousness of command and control infrastructure and the protection thereof, in addition to the protection of Canadian citizens privacy. The solution proposed is to not go alone as a nation state, but to partner wisely to protect national security. Suspects are national state actors as well as private criminal organisations, and failures to infrastructure that may be out of the direct control of Ottawa require clarity of communications between business and government, not draconian gov't actions. Debate on these topics to find collaborative opportunities is encouraged. Need to understand where the responsibility lines are drawn between public and private sectors for the protection against risk to all the infrastructures that support the functioning of our nation.

It is proposed that 70-80% of successful attacks can be defended against by proper infrastructure maintenance (patch management, security controls, audit, etc), but there is a small but vital percentage of very determined and well backed attackers where there is no easy defence, so we need a capable and prepared response.

John spoke to the risk of mobility to not just the PI of average citizens, but to those in positions of pow and leadership in industry and government - consider the risk of the bad guys knowing where the PMs kids are or will be.
There is also a need to be able to manage and secure not only what information is taken, but what information leaks due to unaware consumers of mobile platforms using the technology improperly. Tools and applications are great, but awareness and education are core. John claims that as an industry we must be more advanced in how we manage mobile devices and the data that moves back and forth to them; an auto delete button at central control is great, but not an ideal solution for the consumer.

Steve brings a different perspective, and states that the soft part of IT security is around policy and must be kept in context of the need to use or populate that information in a crisis to maximise the well being of citizens. Understand who are your customers and consumers, and who might might to obtain that information, and why. Steve considers that this is at the root of the risk analysis and management. Balance all of this with appropriate access to the information for the right people at the right time, be prepared to do this with minimal interference in a critical situation. Steve cites the examples of physicians bypassing network security for ease of access when working remotely from the site where the EMR systems are, and that our policies must bridge the need for access with the need for privacy. Steve proposed the concept of "secret shoppers" as employees who will share their feedback on the security of the operational infrastructure and the availability of the information they need.

Paul feels that data classification is the starting point of calculating risk, as you must know what you have before you determine how best to protect it. The extension nationally is how much effort we should place on critical infrastructure versus how much we protect the civil liberties of Canadians. Paul states that in the privacy discussion, the people involved should be outward facing, as public trust is at core.

Eddie has three points to share, to consider security from a perspective of control and visibility.
The first point is that security is broken. The more you invest in technology, you don't really move the security level higher. The prevention game is a game of catch up, but detection and response is a far more useful place to invest. Step back and say what do I have today that was relevant 10 years ago, and what is relevant today? Rethink information security.
Second, if we think there are changes needed in the doctrine of security management, make them. How do we measure usefully our risk level? Almost all metrics available are arbitrary, and don't consider all assets at relative values to the organisation. Eddie cites the recent RSA breach, and asks what was the actual objective? What are your high value assets to you, to your customers, and to the attackers? What is your ability to collaborate outside your organisation in response and in preparation? What is your ability to take what you learn about an adversary or the value of your assets and apply that knowledge dynamically to improve your security stance?
This segues to the third, how do you evaluate your performance metrics? Rate yourself in your effectiveness and continue to move that bar. We cant have compliance be the driver for security and privacy programs; we have to get security right first.

The topic of graceful degradation was brought up by Winn; how much can we consider shooting back as a mechanism of protection. The answer proposed is layers and segregation as a defence concept. Adaptive networking defense is also brought up, but that is at a risk of creating your own DoS on yourself. The rush to shut down, re-image, and other reactive actions is a risk to your business continuity; you need to understand the attack vector and respond accordingly to balance protection and service delivery. Paul brings up a really valid point, which is "what does normal look like?" as a necessary understanding of our own enterprises so that we can not only detect, but understand the scope, impact, and assess the correct response to any information incident.





- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

The Elements of a Data Governance Program: People, Practices, Policies and Technology

Joe Alhadeff, Vice President for Global Public Policy, Chief Privacy Officer, Oracle Corporation
(Theatre)
The Elements of a Data Governance Program: People, Practices, Policies and Technology
This keynote will focus on the evolving needs of organizational governance and accountability. Governance and accountability are multifaceted concepts that must be applied in ways that are accessible to the individual, credible at the level of the organization and extensible across the ecosystem. The elements of such a program are based in organizational policies and processes, the technology that supports them and people that oversee and implement them. Today’s accountability and governance program must be developed collaboratively across disciplines to assure that each element supports and underpins the other. Where technology may have limitations to secure data beyond the transaction; policies, processes and contracts may supplement. Technology may support policies and processes through identity management, rights allocation, audit and other tools. When all of these elements function together the whole is greater than the sum of its parts. As part of this keynote we will also consider trends in Canadian law and practice as well as specific applications of technology in identity and privilege management

Global data flows and big data can be "something really cool and marvellous that happens when you get enough data together" or they can be Big Brother.

Privacy questions span generations, but change as they do; again, theme of the continuously moving target of privacy definitions and requirements that legal bodies are continually playing catch-up with.

"Canada has the PhD on accountability" when it comes to privacy leadership worldwide. We are moving from a compliance of objects to an accountability and governance approach.

At the core of privacy and data management, we are tasked with getting the right data to the right people at the right time. This is reflective of the Wednesday morning workshop I attended at the conference.

Reference made to the TAS3 project in the EU. Trusted Architecture for Securely Shared Services. This is a PPP project where technology, governance, law, and policy were co-developed in support of privacy and security. Technolgy assures the first hop, but law, and policy fill the ecosystem and value chain gaps.

Visual shared, a sign from Quebec that states fair-play SVP. Being prepared means being a good neighbour, playing fair, and successful preparation for information management involves:
Stewardship of information
Transparency
Controls
Proof/audit/testing
Information lifecycle
Training
Learning organisation

We are encouraged to look at compliance as an opportunity; privacy impact assessments must be user friendly to be valuable. Make it an opportunity to learn, and teach. Security and privacy are visualised as a Venn diagram, and we want to operate in the sweet spot, which is compliance, which optimises operational costs in the long term. Have the backend understand compliance, and governance bodies understand security.






- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

Know Your Enemy: Understanding the Threat Landscape, Challenges, and Best Practices

Cheri F. McGuire, Vice President, Global Government Affairs & Cybersecurity Policy, Symantec Corporation
Know Your Enemy: Understanding the Threat Landscape, Challenges, and Best Practices
Sensitive information under attack from a wide variety of sources, including well-meaning insiders, organized crime rings, nation states and advanced persistent threats (APT’s). Private and Public Sector are facing a changing information technology landscape that sees more information stored on smart phones, tablets and cloud services. Tiffany Jones will discuss the current global threat landscape, identify key security challenges apply critical best practices and solutions to protect your environment.

Key trends and security drivers
1. Sophisticated attacks
97% 2009 breaches used customised malware
75% of enterprises reported a cyber attack
2. Complex and changing infrastructure
More than 1B mobile devices connected tonthe Internet
Cloud computing expected to double by 2014, enterprise architectures at greater risk
3. Information explosion
Corporate info grows by 66% each year
4. Consumerisation of IT
BYOD, telecommuting, and the opening of corporate and public service networks to greater risks

Trends changing the threat landscape
1. Moving from a signature model to a reputational model
2. Desktop to mobile
3. Physical to virtual

Security must move from being system centric approaches to information centric to adapt and protect.

Threat landscape trends, as noted in report to be published in two months:
1. Targeted attacks continue to evolve
2. Social networking leveraged via social engineering
3. Hide and seek or 0 day vulns and rootkits
4. Attack kits are becoming more easily leveraged and accessed and complexity of attack is simplified in delivery
5. Mobile threats are increasing dramatically, as the PI on mobile devices is a high value target

Symantec is proposing that hacking remIns the highest impact breach type, and the average resolving cost is $7.2M. I think these numbers are inflated by a small number of high profile attacks, and think that insider attacks deserve far more attention. This smells of marketing scare tactics to sell security tools.

Mobile devices are noted as being primarily subject to trojans as the preferred attack vector, and often these are tied into social media avenues to gain access to PII and PCI; this I agree with.

Critical infrastructure attacks (SCADA) is cited by Symantec as an increasing risk area. In reality these have always been high risk, it's simply increased awareness of this now, I would suggest.

Device management, device security, content security, and identity & access are the defences against mobile threats proposed by Symantec. I wonder if they sell any products that do this? Yes, that was sarcasm.

The bottom line was to present a layered and clear security technology approach, to which I can agree, but I would have an increased focus on in parallel with the technologies, building both awareness and governance.

And at the tail end of the discussion, Cheri comes to plans and policies, so now we are in agreement. She suggests we start with governance with policies and plans socialised and established in the enterprise, including security requirements being built into acquisition contracts, buying from trusted sources, effective backup and recovery plans, and support for setting and enforcing security policies from the top of the organisation.

Cloudsecurityalliance.org, onlinetrustalliance.org, SAFECode.org are cited as useful sources for preparedness and practice planning.

The suggestion came for collaboration between the public and private sectors to increase visibility, adaptability, and optimisation of plans, policies, and preparedness.


- Posted using BlogPress from my iPad

PII & the Law

Session 9 – Keynote Speaker

Daniel J. Solove, Professor of Law, George Washington University Law School
and Paul Schwartz, Professor of Law at the University of California, Berkeley School of Law.

Personally identifiable information (PII) is one of the most central concepts in information privacy regulation. The scope of privacy laws typically turns on whether PII is involved. The basic assumption behind the applicable laws is that if PII is not involved, then there can be no privacy harm. At the same time, there is no uniform definition of PII in information privacy law. Moreover, computer science has shown that the very concept of PII can be highly malleable. Because PII defines the scope of so much privacy regulation, the concept of PII must be rethought. Professors Paul Schwartz (Berkeley Law School) and Daniel Solove (George Washington University Law School) will argue that PII cannot be abandoned; the concept is essential as a way to define regulatory boundaries. Instead, they will propose a new conception of PII, one that will be far more effective than current approaches.

Daniel is the founder of the organisation TeachPrivacy

Introduced themselves as Bert & Ernie of the Privacy world.

Technology changes the meaning of PII, it is a moving target. It plays a central concept in privacy law, and is often the trigger for when privacy law applies. Unfortunately, there is not a consistent definition or approach to PII in the law.

The three approaches to PII in the US

Tautological approach
PII is information that identifies a person. Not particularly useful as it is circular logic. Then the aspect of the answer being indentified versus indentifiable, means the burden of proff is upon the claimant to prove that the information clearly identified, not is at risk of indentifying.

Non public approach
the problem here is that there is actually not a clear definition of what non public actually means. There is a huge grey area, and this becomes an ineffective trigger.

Specific types approach
This is a rule, as opposed to the prior twomstandards. It attempts to enumerate the specific PII types and list them. The childrens PII act does this in the US. The problem here is that this is a static and inflexible approach being applied to a moving target. Many of these statues become under inclusive when it comes to information that actually could identify a person.

PIPEDA uses the term identifiable data, and is fairly broad in its application for PII. The problem becomes less the definition now rather the approach becomes all or nothing under Cdn legislation. This is reflective of EU legislation.

Problems of de-identification.
Case in point is the NetFlix survey contents, where supposedly anonymous data in the survey was readily identified by a third party research group, by cross correlating against data publicly available in IMDB.

We are seeing more and more data about people out there, and the ability to link it up to create correlations is becoming easier. The more information you have on the Internet, the harder it is to remain anonymous. The calim is that the combination of a zip code, birthdate and gender can identify 80% of the US population, my seatmate, a seasoned privacy expert calls BS on that claim quietly at our table.

The scholars provide us with a spectrum of risk of identification based on their theory.

U of Colorado prof is quoted as comparing PII to a game of whack a mole, and states that we should instead regulate the flow of information. However, without some concept of PII, privacy law has to regulate all data, not just the sensitive data.

Google flue trends cited as an example of the use of deidentified PII in the medical field as a public service.

PII 2.0 is the proposed solution to these dilemmas based on three tenents:
Identifiability is a continuum of risk.
Approach should be as a standard, not a rule.
Privacy should not be a hard on/off switch, but a tailored solution.

There are three categories of PII in this theory, moving from the current two categories.
Identified - the PII has been ascertained and the information must be protected. Plus identifiable data when significant probability of linkage to a specific person can occur.
Identifiable - specific identification is possible, has not yet occurred, And this data must also be protected and audited.
Non identifiable - only a remote risk of identification, need for protection of data is minor.

The speakers cite the dangers of the "release and forget" approach, and agree that there is a need for a track and audit approach coupled with risk assessments for identified and identifiable data.

This approach is compatible with the methodology of privacy by design, embedding privacy constraints and models into technological design and business practices.

Summing up, the presenters state that there is still great legal uncertainty about the concept of PII on a world-wide basis, and it is hard to predict the impact of privacy law on business, and therefore it is a source of business risk.

In the end, the PII 2.0 concept is about the taxonomy of PII, intended to help organisations to understand if they are subject to privacy laws or not per geo-political boundaries and constraints.

One delegate challenged that creating these categories in a vacuum from practical application is of limited value. The response was that the first two categories put the onus on the regulatory regimes and business to be responsible about how they classify data.

Questions were raised on the practicality of data moving from one category to the other over time, and how this could be managed from a track and audit purpose. The response was de-identification should be the rule, not the option for organisations holding data that is to be published. I'm uncertain this really answered the question.

The discussion was fairly esoteric, and likely provides something of use within legal circles, but moderate to low value in practical application in the technology world until legislation applies clearer boundaries to the PII containers, which, is what these gents are trying to encourage.




- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

Thursday, February 16, 2012

20 in 2012: The Top Privacy Issues to Watch

Trevor Hughes, President and CEO, International Association of Privacy Professionals
(Salon AB)

20 in 2012: The Top Privacy Issues to Watch
Privacy has long been an important part of any information protection program; however, new potential laws and shifts in the landscape are creating new challenges and business imperatives for privacy, security, IT and legal professionals. Organizations and companies are under more pressure than ever to develop and explain strong privacy practices. From calls for a ”Do Not Track” tool to requiring concepts of Privacy by Design and new potential new data breach notification rules, there are many new priorities to consider. J. Trevor Hughes, president and CEO of the world’s largest association of privacy professionals, will cover the top privacy policy and technical developments to watch in the coming year.

EU proposed regulations
First major review of the existing regulations.
First aspect of this is the right to be forgotten, including data portability to take it from a vendor and move it with you. This is a challenge to implement. There is also the right to delete, or expunge their data from any place it might be stored.
Europe is looking for streamlined jurisdiction; the european main site of your business will be authoritative for the regulations you must comply with.

E-Privacy Directive
This EU directive (the cookie directive) says if you set or read information on a client device you need to get consent for that. This will be untenable for the end user with today's web browsing technologies. The regulators are debating still what this will actually mean. Browser controls permitting cookies may be the loophole for this.

FTC Staff Report
The US has been struggling with their privacy regulator, and an analysis of privacy issues (including online privacy but not exclusively) has resulted in a draft framework report. It should be released in the next 6 weeks, and is expected to include the idea of operational privacy; it becomes a business concern, it is baked into business controls in each enterprise/organisation. This accepts that there are implied consent items, within the boundaries of reasonable privacy expectations between the consumer and the enterprise.

Do not track is hugely accepted, switching off online tracking being an option for all browsers. Browser manufacturers are already on this, and we can see more of this available later this year.

The FTC accepts that there is a new type of data called consumer data; data that relates to a particular consumer, but is not identifiable. The definition of this will be in the paper.

The US Dept of Commerce has a white paper report coming (called a green paper until it is released in 6 weeks) and are playing chicken with the FTC on who will release first. The Obama administration is willing to consider a privacy bill of rights, and a recognition that law cannot answer every question, therefore industry needs a code of conduct.

Notice of security breach is catching on like wildfire since it started in California. The current state of this provides a patchwork quilt of responses because each state legislation is unique. Industry is pushing for a standardised approach to simplify. The strong aspects of this policy is that it is consequential, rather than prescriptive, and therefore has increased the use of encryption, for example.

Art called FaceOff by italian artist illustrates the layers of persona that social media encourages of the populace.

facebooks IPO listed privacy more times than any other risk, showing that social media giants recognise the risks, but aren't yet really doing anything because we are not voting with our fingers.

Online behavioural advertising where via cookies you are cross site tracked for your interests and behaviours. Self regulatory efforts are starting to see some traction. The digital advertising alliance is starting to see some maturity.
Consumers value privacy, but we have trouble setting that value to more than 50 cents off a cheeseburger.

Mobile devices, and the privacy considerations for mobile apps. Industry must accept and respect privacy because people are begining to vote with their fingers, and it easy to delete an app that violates our trust.

Geo-data sensitivity is an awareness that is growing with the consumer marketplace. Most devices that deliver your geo-data to other parties do so with no knowledge of the device user.

Cloud computing continues to be a controversial topic, because the information economy knows no jurisdictional boundaries. The issues are not de facto compatible with data transfer and privacy expectations and needs to make functional use of the cloud concept.

Emerging markets introducing privacy laws, mexico, brazil, argentina, india are all creating privacy laws that face outwards more so than inwards, to protect the outsource business processing industry.

Regulatory risk is where the rubber hits the road for privacy and security. Regulators around the world are seeking and obtaining more powers than they have ever had to enforce data protection. The FTC is becoming more aggressive in going after privacy violating organisations.

Class action risk also grows, NetFlix settled for $9M in the US this week, for their data collection practices. The barrier has been the issue of harm, but a number of judges are starting to show a willingness to close their eyes to allow the cases to progress to the point where a settlement occurs. Watch the US market and the reactions to these law suits.

Brand risk is more amorphous but it is growing in awareness, as most major publications are establishing beat reporters for privacy topics specifically. As many as 500 stories per day globally are published with respect to privacy issues, so the brand risk is growing as media is slavering for the next big story.

Privacy by design and default is necessary because of these risks. Privacy cannot be an option, or an after thought placed on the infrastructure to hold responsibility for.

Accountability is necessary through metrics, audits, controls, and generally taking information and managing the data in your enterprise seriously.

Everyone is talking about big data because it is solidly in place, and every role dealing with big data is on some respect a privacy role. privacy needs to have complete oversight over big data collection, storage, use, and management. big data is driving big jobs that require privacy knowledge and awareness.

we are all privacy professionals: if you touch data, information security, or systems that touch data, you need to understand privacy to an adequate level to react correctly when any issue arises.

Stay aware, track the EU framework, FTC report, and the risk environment. Build privacy before launch, operationalise privacy into your organisation. Build response plans, and train your organisation.


- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference