<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Emerging Business Advocate</title>
	<atom:link href="http://emergingbusinessadvocate.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://emergingbusinessadvocate.wordpress.com</link>
	<description>Where Technology and the Law Meet</description>
	<lastBuildDate>Mon, 29 Apr 2013 21:22:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='emergingbusinessadvocate.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/39ba547d6933f6b52ca58cf3e15345d3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>The Emerging Business Advocate</title>
		<link>http://emergingbusinessadvocate.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://emergingbusinessadvocate.wordpress.com/osd.xml" title="The Emerging Business Advocate" />
	<atom:link rel='hub' href='http://emergingbusinessadvocate.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Intellectual Property Theft Soars as Cyber-Attacks Against Businesses Increase</title>
		<link>http://emergingbusinessadvocate.wordpress.com/2013/04/29/intellectual-property-theft-soars-as-cyber-attacks-against-businesses-increase/</link>
		<comments>http://emergingbusinessadvocate.wordpress.com/2013/04/29/intellectual-property-theft-soars-as-cyber-attacks-against-businesses-increase/#comments</comments>
		<pubDate>Mon, 29 Apr 2013 21:22:42 +0000</pubDate>
		<dc:creator>Seaton Daly</dc:creator>
				<category><![CDATA[Business Law]]></category>
		<category><![CDATA[Data Security & Privacy]]></category>
		<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[data governance]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Intellectual Property]]></category>

		<guid isPermaLink="false">http://emergingbusinessadvocate.wordpress.com/?p=913</guid>
		<description><![CDATA[Verizon recently released its 2013 Data Breach Investigations Report, and the outlook for organizations trying to protect their intellectual property is dire.  Cyber-based corporate and industrial espionage has risen so dramatically in the last year that intelligence officials are asking boardrooms across the U.S. to be more vigilant against cyber-criminals who are motivated by financial gain [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=913&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Verizon recently released its 2013 Data Breach Investigations Report, and the outlook for organizations trying to protect their intellectual property is dire.  Cyber-based corporate and industrial espionage has risen so dramatically in the last year that intelligence officials are asking boardrooms across the U.S. to be more vigilant against cyber-criminals who are motivated by financial gain to steal intellectual property and trade secrets.  Former U.S. intelligence chief, John &#8220;Mike&#8221; McConnell stated that &#8220;unless urgent action is taken, the U.S. faces a &#8216;cyber&#8217; equivalent of the World Trade Center attack.&#8221;</p>
<p>The Chinese and U.S. economies are so inextricably linked that China naturally is the main culprit for targeted theft of confidential business information and proprietary technologies.  However, there are many other state-sponsored and political &#8220;hacktivist&#8221; groups that are actively stealing corporate digital assets.  The proliferation of employee-owned mobile devices in the workplace, along with antiquated network systems, has allowed cyber-criminals to access corporate databases at unprecedented levels.  Saudi Arabian oil producer, Aramco, was recently a victim of a massive cyber-attack where 30,000 desktop PCs were wiped in what some can only presume was designed to disrupt oil production.  Additionally, JP Morgan Chase, Wells Fargo, and Bank of America were victims of a sustained distributed denial of service (DDoS) attack that appears to have been commenced overseas.</p>
<p>What frustrates investigators most when a breach of corporate data occurs is the lack of internal and external controls within the organization.  While readily available technology allows organizations to address security issues, it is often a failure to properly train and educate employees that makes theft of intellectual property so easy for cyber-criminals to obtain.  Technology alone will not prevent the theft of intellectual property.  Organizations must have a tone at the top mentality when it comes to awareness training and policy creation around cyber-security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/emergingbusinessadvocate.wordpress.com/913/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/emergingbusinessadvocate.wordpress.com/913/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=913&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://emergingbusinessadvocate.wordpress.com/2013/04/29/intellectual-property-theft-soars-as-cyber-attacks-against-businesses-increase/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62fa97c0d2bee7051421a3897fabc9fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dalylaw07</media:title>
		</media:content>
	</item>
		<item>
		<title>SEC Ruling on Social-Media Disclosures Offers Little Guidance for Businesses</title>
		<link>http://emergingbusinessadvocate.wordpress.com/2013/04/11/sec-ruling-on-social-media-disclosures-offers-little-guidance-for-businesses/</link>
		<comments>http://emergingbusinessadvocate.wordpress.com/2013/04/11/sec-ruling-on-social-media-disclosures-offers-little-guidance-for-businesses/#comments</comments>
		<pubDate>Thu, 11 Apr 2013 23:06:58 +0000</pubDate>
		<dc:creator>Seaton Daly</dc:creator>
				<category><![CDATA[Business Law]]></category>
		<category><![CDATA[Netflix]]></category>
		<category><![CDATA[SEC]]></category>

		<guid isPermaLink="false">http://emergingbusinessadvocate.wordpress.com/?p=909</guid>
		<description><![CDATA[As reported in The Wall Street Journal today, Netflix, Inc., has filed documents with the Securities and Exchange Commission (&#8220;SEC&#8221;) stating its intent to disclose &#8220;material information&#8221; on its corporate Twitter feed, Facebook page, and blog, as well as the Facebook page of its CEO.  The Los Gatos-based company will continue to file traditional disclosures, regarding important [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=909&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>As reported in <em>The Wall Street Journal</em> today, Netflix, Inc., has filed documents with the Securities and Exchange Commission (&#8220;SEC&#8221;) stating its intent to disclose &#8220;material information&#8221; on its corporate Twitter feed, Facebook page, and blog, as well as the Facebook page of its CEO.  The Los Gatos-based company will continue to file traditional disclosures, regarding important company information, but the filing is a first for any publicly-traded company and will likely not be the last.</p>
<p>How quickly other organizations adopt Netflix&#8217;s example will be dependent upon an internal assessment of risk for potentially running afoul against decades-old rules that are designed to protect consumers and investors from fraudulent activities.  The SEC has signaled an unwillingness to update years of regulatory legislation, in response to new technology, out of fear that doing so would create a slippery slope of deceptive or &#8220;puffed&#8221; disclosures/activities.  Frustrated by this unwillingness, many financial industry and Wall Street firms are trying to seek guidance on how to apply social-media disclosures to antiquated regulatory requirements.</p>
<p>An example of this frustration is whether a third-party&#8217;s use of the &#8220;like&#8221; button on a financial services company Facebook page, or endorsing an advisor&#8217;s skills on LinkedIn, could be viewed as an improper testimonial defined under applicable regulations.  Such an act, could potentially subject the company, and/or individual, to penalties and jail time.  Financial services firms seek relief from these regulatory bans that prohibit testimonials in advertisements, but the SEC considers them to be &#8220;inherently misleading,&#8221; and suggests they get pre-clearance before posting on social media sites.</p>
<p>Therefore, while the SEC seems to have acknowledged the presence of social media in our daily routines, it still remains skeptical on how it is going to be applied in our everyday world and will leave it up to the organizations to police themselves.  In this regard, a proper assessment of social-media use within an organization is an emerging talking point across most boardrooms in America.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/emergingbusinessadvocate.wordpress.com/909/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/emergingbusinessadvocate.wordpress.com/909/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=909&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://emergingbusinessadvocate.wordpress.com/2013/04/11/sec-ruling-on-social-media-disclosures-offers-little-guidance-for-businesses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62fa97c0d2bee7051421a3897fabc9fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dalylaw07</media:title>
		</media:content>
	</item>
		<item>
		<title>The Lessons &#8216;Joe Camel&#8217; Will Teach Developers of &#8216;Kids Apps&#8217;</title>
		<link>http://emergingbusinessadvocate.wordpress.com/2013/04/05/the-lessons-joe-camel-will-teach-developers-of-kids-apps/</link>
		<comments>http://emergingbusinessadvocate.wordpress.com/2013/04/05/the-lessons-joe-camel-will-teach-developers-of-kids-apps/#comments</comments>
		<pubDate>Fri, 05 Apr 2013 23:32:45 +0000</pubDate>
		<dc:creator>Seaton Daly</dc:creator>
				<category><![CDATA[Business Law]]></category>
		<category><![CDATA[Data Security & Privacy]]></category>
		<category><![CDATA[Big Data]]></category>
		<category><![CDATA[Big Tobacco]]></category>
		<category><![CDATA[COPPA]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[Joe Camel]]></category>

		<guid isPermaLink="false">http://emergingbusinessadvocate.wordpress.com/?p=900</guid>
		<description><![CDATA[On July 1, 2013, the Federal Trade Commission (&#8220;FTC&#8221;) will begin enforcement of new regulations pertaining to the Children&#8217;s Online Privacy Protection Act of 1998 (&#8220;COPPA&#8221;).  For two years, regulator&#8217;s had sought to update COPPA &#8221;with the times&#8221; by expanding the law beyond its original intent - to prevent web-based companies from obtaining personal information of children [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=900&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>On July 1, 2013, the Federal Trade Commission (&#8220;FTC&#8221;) will begin enforcement of new regulations pertaining to the Children&#8217;s Online Privacy Protection Act of 1998 (&#8220;COPPA&#8221;).  For two years, regulator&#8217;s had sought to update COPPA &#8221;with the times&#8221; by expanding the law beyond its original intent - to prevent web-based companies from obtaining personal information of children without their parents&#8217; consent.  Tablet and smartphone devices have propelled the app industry into a multi-billion dollar market, but it is the mechanics of how the app industry makes its money that has regulators concerned.  The business model for most app development firms is to build a product that consumers can download for free on their mobile device, and in exchange, the consumer allows software embedded into the app to be sent to a third-party data aggregator who then returns the aggregated data back to the developers for their discretional use. </p>
<p>Software Application firms are weary of the new rules because they fear regulatory fallout from developing a game, like Angry Birds, and being classified as a &#8220;kid app&#8221; under the new COPPA rules.  Such a designation would subject the game designer to strict regulatory requirements or face civil penalties.  The FTC has signaled that it will look to define what constitutes a &#8220;kids&#8217; app&#8221; broadly, and suggests that all software firms know the law if they plan on building an app with a cartoon character in it.  Enter the lessons learned in Big Tobacco&#8230;</p>
<p>In the mid-1990&#8242;s, Big Tobacco faced an onslaught of class action and regulatory (i.e. FTC) lawsuits that would end up changing the way the industry fundamentally advertises its products to the general public.  On or about September 12, 1997, the Tobacco Industry was informed that &#8220;Joe Camel in California is dead.&#8221;  The makers of the Joe Camel marketing campaign, R.J. Reynolds, repeatedly denied that it was targeting smoking to minors, and stated that the Joe Camel campaign was directed at &#8220;adults in their 20&#8242;s who choose to smoke.&#8221;  However, R.J. Reynolds agreed to settle the numerous lawsuits by agreeing to a cash settlement payout and dropping the ads that depict Joe Camel.</p>
<p>Now one would logically ask how in the world do kid apps and the targeting of smoking to minors belong in the same discussion?  The answer to that question lies in a minors&#8217; ability to make an intelligible informed decision.  For years Big Tobacco lawsuits addressed the health, safety and public welfare issues related to minors smoking, but it was not until Joe Camel was literally put on trial, that the issue of a minors&#8217; informed consent was raised.  How possible is it for a minor to distinguish between a simple cartoon character and the message that cartoon character is sending?</p>
<p>Similarly, App Industry advocates suggest that in order to offer free software apps, data collection about the user, like time spent on the device, is needed to ensure its long-term ability to offer targeted advertising (which is where their money is made).  Additionally, app providers fear losing important third-party data aggregators, because the data aggregators don&#8217;t want to deal with the regulatory headache of COPPA.  Online privacy advocates, like their predecessor anti-smoking advocates, state that the lucrative children&#8217;s technology market needs basic fundamental safeguards in place to prevent minors from being preyed upon by Big Data advertisers.  Is it incredulous for app development firms to know when your child goes to sleep, eat, bathroom, etc., based on their login/logout time?  Is there an expectation that a minor has the capacity to fully understand that their location may be accessed remotely via the mobile device they are walking around with?  In that sense, a seven year-old boy/girl will login to Angry Birds expecting to smash pigs and hippos, and not fully comprehend the impact of his/her actions.</p>
<p>Stagnation is the worst thing that could happen to any organization, and never being satisfied with the status quo is what sets successful organizations apart.  Application firms need to change the development process to make regulatory compliance a core part of their design programs &#8211; but is that necessarily a bad thing?  Big Tobacco companies have survived now for almost 15 years without Joe Camel by adapting the strict regulatory requirements into their advertising campaigns.  In this vein, software application firms are no different &#8211; at least the innovative ones.  The future of the software application industry depends upon its ability to develop a product that is adaptable to emerging trends.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/emergingbusinessadvocate.wordpress.com/900/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/emergingbusinessadvocate.wordpress.com/900/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=900&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://emergingbusinessadvocate.wordpress.com/2013/04/05/the-lessons-joe-camel-will-teach-developers-of-kids-apps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62fa97c0d2bee7051421a3897fabc9fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dalylaw07</media:title>
		</media:content>
	</item>
		<item>
		<title>Ninth Circuit: Warrantless Forensic Examination of Electronic Data Must Meet 4th Amendment Requirements</title>
		<link>http://emergingbusinessadvocate.wordpress.com/2013/03/27/ninth-circuit-warrantless-forensic-examination-of-electronic-data-must-meet-4th-amendment-requirements/</link>
		<comments>http://emergingbusinessadvocate.wordpress.com/2013/03/27/ninth-circuit-warrantless-forensic-examination-of-electronic-data-must-meet-4th-amendment-requirements/#comments</comments>
		<pubDate>Wed, 27 Mar 2013 21:58:03 +0000</pubDate>
		<dc:creator>Seaton Daly</dc:creator>
				<category><![CDATA[Data Security & Privacy]]></category>
		<category><![CDATA[U.S Constitution]]></category>
		<category><![CDATA[U.S. v. Cotterman]]></category>
		<category><![CDATA[SCOTUS]]></category>
		<category><![CDATA[4th Amendment]]></category>
		<category><![CDATA[Reasonable Suspicion]]></category>
		<category><![CDATA[U.S. v. Comprehensive Drug Testing]]></category>

		<guid isPermaLink="false">http://emergingbusinessadvocate.wordpress.com/?p=896</guid>
		<description><![CDATA[Earlier this month, March 8, 2013, the Ninth Circuit U.S. Court of Appeals issued a ruling related to the warrantless forensic examination of electronic data on a laptop that was seized at the U.S.-Mexico border in Arizona (U.S. v. Cotterman, No. 09-10139).  The fallout from the U.S. v. Cotterman ruling is significant in that, going forward, law [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=896&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Earlier this month, March 8, 2013, the Ninth Circuit U.S. Court of Appeals issued a ruling related to the warrantless forensic examination of electronic data on a laptop that was seized at the U.S.-Mexico border in Arizona (U.S. v. Cotterman, No. 09-10139).  The fallout from the <em>U.S. v. Cotterman </em>ruling is significant in that, going forward, law enforcement agencies, absent some &#8220;particularized&#8221; suspicion, will be barred from conducting an unfettered dragnet of electronic data stored on hardware devices brought into the U.S. by international travelers.  The 9th Circuit&#8217;s determination of a &#8220;reasonable suspicion&#8221; requirement is consistent with its other rulings involving the search and seizure of electronic data.</p>
<p>The Court opined that the &#8220;uniquely sensitive nature of data [stored] on electronic devices&#8221; gives rise to a significant expectation of privacy that renders an exhaustive exploratory, or in Cotterman&#8217;s case, forensic, search more intrusive than a mere cursory scan, or quick look, through the electronic device.  The Court continues to state that &#8220;digital media nowadays contains volumes of intimate details of our lives.  It is simultaneously an office and personal diary.  This type of material implicates the 4th Amendments specific guarantees of the people&#8217;s right to be secure in their papers.&#8221;</p>
<p>In the &#8220;cloud,&#8221; an electronic device (i.e. laptop) is merely a conduit for accessing user data that, in earlier times, would be akin to sensitive &#8220;papers&#8221; found in the home &#8211; thus triggering 4th Amendment protections for the cloud data.  While the information stored in the &#8220;cloud&#8221; may not itself cross the U.S. border, it may appear as a &#8220;seamless part of the digital device when presented at the border.&#8221;  In making reference to cloud computing technology, the Court seems to not distinguish between the type of hardware being used to store electronic data.  Regardless of whether the device is mobile, like a laptop, or stationary, like a server, a warrant is needed, absent reasonable suspicion, to search the content of any electronic device.</p>
<p>The <em>Cotterman </em>conclusion is consistent with, and builds upon, other &#8220;electronic data&#8221; 4th Amendment cases brought before the 9th Circuit.   In <em>U.S. v. Comprehensive Drug Testing</em> (the &#8220;Balco&#8221; case), the Court was asked to determine the proper administration of a search warrant.  In the Balco case, the Court determined that special, independent third-parties must segregate and redact seizable data from non-seizable data when the Government wants to execute a search warrant of electronic databases.  Again, the Court is trying to prevent the Government from conducting an unfettered dragnet on persons who might not even be aware that information is being seized about them.</p>
<p>As for Mr. Cotterman&#8217;s narrative, the Court did conclude that the forensic examination of his laptop required a showing of reasonable suspicion, however the facts, viewed in totality of the circumstances, supported the Government&#8217;s assertion that the border agents had acted upon reasonable suspicion in conducting the initial search of Mr. Cotterman&#8217;s laptop and subsequent forensic examination.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/emergingbusinessadvocate.wordpress.com/896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/emergingbusinessadvocate.wordpress.com/896/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=896&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://emergingbusinessadvocate.wordpress.com/2013/03/27/ninth-circuit-warrantless-forensic-examination-of-electronic-data-must-meet-4th-amendment-requirements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62fa97c0d2bee7051421a3897fabc9fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dalylaw07</media:title>
		</media:content>
	</item>
		<item>
		<title>Failure to Reach Regulatory Oversight on Cybersecurity, Highlights Tension Between FCC and ISP&#8217;s</title>
		<link>http://emergingbusinessadvocate.wordpress.com/2013/03/25/failure-to-reach-regulatory-oversight-on-cybersecurity-highlights-tension-between-fcc-and-isps/</link>
		<comments>http://emergingbusinessadvocate.wordpress.com/2013/03/25/failure-to-reach-regulatory-oversight-on-cybersecurity-highlights-tension-between-fcc-and-isps/#comments</comments>
		<pubDate>Mon, 25 Mar 2013 22:19:33 +0000</pubDate>
		<dc:creator>Seaton Daly</dc:creator>
				<category><![CDATA[Data Security & Privacy]]></category>

		<guid isPermaLink="false">http://emergingbusinessadvocate.wordpress.com/?p=893</guid>
		<description><![CDATA[The United States Telecom Association, whose member representatives include Internet service provider&#8217;s like CenturyLink, AT&#38;T, and Verizon, appears to have blocked a Federal Communications Commission advisory panel&#8217;s recommendation on measures needed to deal with the nation&#8217;s cyber-security problem.  The lack of an agreement on Internet regulatory oversight highlights growing tension between the Obama administration&#8217;s directive, which orders [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=893&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>The United States Telecom Association, whose member representatives include Internet service provider&#8217;s like CenturyLink, AT&amp;T, and Verizon, appears to have blocked a Federal Communications Commission advisory panel&#8217;s recommendation on measures needed to deal with the nation&#8217;s cyber-security problem.  The lack of an agreement on Internet regulatory oversight highlights growing tension between the Obama administration&#8217;s directive, which orders federal agencies to develop a cyber-security framework for specific industries, and private sector industries, which view government oversight as stifling innovation and &#8220;not flexible.&#8221;</p>
<p>Advocates for regulatory oversight suggest that the federal government should develop a set of strict security standards that are developed in &#8220;concert&#8221; with the National Security Agency and other agencies.  However, Telco advocates say that a &#8220;checklist&#8221; of government standards would be &#8220;clunky,&#8221; create an additional layer of unnecessary bureaucracy, and potentially expose ISPs to liability for failing to prevent cyber-attacks (since a vast majority of malicious code travels over the fiber optic pipes owned by Telco&#8217;s). </p>
<p>The irony behind the Telco industry lobbying against a checklist of standards for fear that their industry would become &#8221;clunky&#8221; and &#8220;bureaucratic,&#8221;  has never made a customer service call to Verizon, AT&amp;T, et al, or taken a tour of a telecommunication co-location facility.  A response to the &#8220;bureaucratic&#8221; position requires little mention, simply because its absurdity.  A co-location facility, which is the physical aberration of the Internet &#8220;clouds,&#8221; can best be described as a large, climate- and air- controlled office space with a seemingly endless series of interconnected wires, metallic racks stuffed with servers, switches, routers, processing units, &#8220;fan noise&#8221; and blinking yellow, blue, red, orange, and white lights that resembles Dr. Seuss&#8217; Thinga-ma-jigger - it&#8217;s the definition of already being &#8220;clunky.&#8221; </p>
<p>In fairness to the regulatory oversight advocates, the government has been telling the private sector for years that self-regulation is a preferred option, but even self-regulation has its limitations.  Organizations cannot self-regulate, because they themselves have become, or are, too bureaucratic &#8211; and this is not limited only to the Telco industry.  If the Telco industry wants to have a straight-faced discussion on why a checklist of standards would not work, then they should look no further than the financial sector.</p>
<p>The financial industry has tried its own version of self-regulation in the form of the Payment Card Industry Data Security Standard, or as it is more commonly known, &#8220;PCI Compliance.&#8221;  Banks and credit card companies love to show regulators that they have their act together when it comes to the issue of cyber-security, because participating members must be in compliance with the set of standards articulated by the PCI governing body (which is exclusively made up of banks and credit card companies).  The problem with the PCI checklist is that, regardless of when a breach of data will occur (and it will),  the customer, not the credit card companies,  will still be liable for the loss in data.  There is no &#8220;risk transference&#8221; in the PCI standard, and therefore what&#8217;s the incentive for customers to be PCI compliant?</p>
<p>Consider the Heartland Payment Systems (HPS) data breach case - at the time, the HPS data breach was the world&#8217;s largest release of unauthorized data; HPS was PCI Compliant; ended up numerous pending class action lawsuits as a result of the data breach; PCI governing body &#8220;revoked&#8221; their compliance AFTER the breach; and HPS is still in business today.  Result:  can a checklist of standards have any teeth if a company is &#8220;certified&#8221; compliant one day, and a cyber-incident occurs on another? </p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/emergingbusinessadvocate.wordpress.com/893/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/emergingbusinessadvocate.wordpress.com/893/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=emergingbusinessadvocate.wordpress.com&#038;blog=16173638&#038;post=893&#038;subd=emergingbusinessadvocate&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://emergingbusinessadvocate.wordpress.com/2013/03/25/failure-to-reach-regulatory-oversight-on-cybersecurity-highlights-tension-between-fcc-and-isps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62fa97c0d2bee7051421a3897fabc9fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dalylaw07</media:title>
		</media:content>
	</item>
	</channel>
</rss>
