Showing posts with label CICA. Show all posts
Showing posts with label CICA. Show all posts

Sunday, March 17, 2013

Google Glass and Privacy: You've just been Glassed!

Last week at the SXSW Conference, Google showed off its latest product Google Glass, The gadget last made headlines when Sergei Brin claimed that - while sporting Google glass - mobile phones are "emasculating", In other words, men (and women?) will fork over money to Google to be "real men". Prior to that ,the search engine giant invited the Verge's Josh Topolsky and revealed in this interview that the product will be available to the wider public by the end of 2013. The company plans to work with eye-glass manufacturers to make the technology available through such channels as well.


As can be seen in this interview, Google believes that the glasses will assist human beings to better connect in the world we live in: we can stay in the moment without having to take out our smartphones to capture the moment. For example, if you attend your kids sporting or extra curricular events you are probably used to seeing parents viewing the event through to their iPads or smartphones - instead of actually watching the kids play.

Is this the next big thing?
With Apple's steady stream of innovative products, such as the iPhone and iPad, having seem to become mainstream, some are questioning whether innovation in technology is becoming stagnant. For example, on this show on the Agenda, a group of panelists explored this topic based on a survey conducted by TVO that indicated the biggest inventions occurred decades ago.

Enter wearable technology: is Google Glass the next "big thing"?

Some commentators, such as Leo Laporte, have questioned the value of Google Glass or other wearable technology (e.g. it is rumoured that Apple is working on a watch). Does it really solve a problem that we have? Or is it a means to manufacture a want in order to satisfy Wall Street insatiable appetite for endless growth and profits?

Laporte, humourously,  has judged the soon-to-be-released device as a "Segway for your face" - referring to the 'people mover' that had low commercial success due to the fact it did not look fashionable to ride one of these things. Consequently, it is not clear whether Google glass will be the next big thing or be a commercial failure.

Privacy implications of Wearable Tech
That being said, the privacy implications of this device are hard to ignore. In fact, one business in Seattle, the 5 point cafe has gone to ban the device. The owner of the establishment has admitted that the is was partially a PR stunt. However, one could argue that the ploy was successful because it speaks to underlying concern in society with the increasing encroachment of technology on one's privacy.

In a previous blog post, I have discussed how the shift to social media is from a certain perspective an adjustment in privacy for people that live in non-rural environments - where individuals are used to the anonymity of the condominium or the suburban sub-division. However, it is not for those that live in a more village oriented setting where everybody knows everybody and individuals could anonymity.

The issue, however, with Google Glass is that it is integrated into one's person's physical body and, unlike a smartphone, video camera or that ancient camera with smoke and all,  it inherently lacks the social mechanism to communicate that the interaction is being recorded. Even with social media, it is well understood that the communication is occurring in a medium that can be easily shared, so those that engage in such a communication understand there is a possibility that their conversation is not private and may not be kept confidential. In other words, precisely because Google Glass is integrated into the moment, it inherently lacks the ability to gather:
  • "Notice. The entity provides notice about its privacy policies and procedures and identifies the purposes for which personal information is collected, used, retained, and disclosed."
  • "Choice and consent. The entity describes the choices available to the individual and obtains implicit or explicit consent with respect to the collection, use, and disclosure of personal information."
(This was taken from AICPA-CICA Generally Accepted Privacy Principles, see page 7)

Of course these principles are designed for companies and organizations to manage the privacy of their customers and other stakeholders. However, they are useful because they help breakdown the problem of "wearable technology" in terms of what the privacy issues exactly are - beyond the "creepy factor". (Jeff Jarvis, professor of Journalism at CUNY and open-Google-fan-boy often talks about how creepy is too vague a term to be an obstacle to technological innovations that, in his opinion, increase the ability of a person to live life in public.) That is, the problem with Google glass is that when you lean in to talk to someone you are expecting them to keep what you are saying confidential. However, if they are wearing technology that can record what you are saying (i.e.without your knowledge) - then it effectively violates that expectation of privacy because the person wearing Google Glass has failed to give "notice" and therefore cannot gain "consent".

Consequently there will be need to be some adjustment in terms of wearing Google Glass. For example, one suggestion I have heard from someone on the Twit network, is that Google Glass should have some kind of light on that indicates it is taking pictures/videos/etc. However, given the nature of things, people can always find a way around such "controls".

Avoiding being Glassed
Inevitably, the privacy issues will go the way of social media. As horror stories of being "Glassed" (i.e. what I define as "an embarrassing-Glass-recorded-personal-moments makes it way YouTube or other video sharing site") get around,  people will become aware of the privacy risk of being involved with Google Glass and may simply request: "Can you take those off before we talk? I'd rather not be Glassed. Thanks."


Sunday, February 3, 2013

CNET, CES and Crowd-sourced audits: Independence does matter

In a previous post, I looked at how the editorial interference from CBS forced CNET to award the Best in Show category to another contestant because CBS was involved in litigation against the company who actually did win best in show. The perspective that I took was more of a "decision usefulness" perspective: could a reader actually figure out who the real winner is due to the use of disclaimers. 

Others were much more outraged over this lack of objectivity. 

Since my post, Greg Sandoval, a reporter at CNET, has resigned over the controversy (click here to see his tweet).  More importantly, the Consumer Electronics Association (CEA) itselft has taken a firm stand against this move by CBS. As noted in this press release, they have effectively overturned CNET's decision and have awarded the Best in Show to both the Hopper and Razor's Edge (effectively CNET's second choice). They have also are requesting a request for proposal for "a new partner to run the Best of CES awards program". 

Looking at the heart of the issue, the question is how does one maintain independence when reporting on a matter? 

We can take a look at what the Canadian Institute of Chartered Accountants (CICA) and the Canadian Public Accountability Board (CPAB) have written about independence in this publication. On page 7, they cite the International Ethics Standards Board for Accountants (IESBA) and breakdown independence in two categories: 
  • "Independence of mind: The state of mind that permits the expression of a conclusion without being affected by influences that compromise professional judgment, thereby allowing an individual to act with integrity and exercise objectivity and professional skepticism.
  • "Independence in appearance: The avoidance of facts and circumstances that are so significant that a reasonable and informed  third party would be likely to conclude, weighing all the specific facts and circumstances, that a firm’s, or a member of the audit team’s, integrity, objectivity or professional skepticism has been compromised."
The publication also a number of threats to independence. The two probably most relevant are the "self-interest threat" and the "intimidation threat", which I think are probably most relevant to the CNET-CES controversy. Effectively, CBS's objectivity of the reporters was put aside in favour of the self-interest emanating from their litigation against DISH (who makes the Hopper). 

But the more interesting one to explore is the "intimidation threat". And this is most felt by reporters and editors who are pressured to abandon their view in favour of what the parent company wanted. And it speaks to a fundamental flaw in journalism: the press depends on money from the companies and others that they need to write about. The biggest illustration of this is what went down between Fox News and Jane Akre and Steve Wilson when they were forced to stop reporting about the health effects of drinking milk from cows that had been given Monanto's Bovine Growth Hormone. The reporters were fired when they refused to give into the "intimidation threat". They initially won their case under Florida's whistle blower law, but when Fox appealed they lost. The reason? The media has no obligation to tell the truth.  

So the challenge remains as to how does one remain independent when they need to eat and pay their bills in a free market system? Greg took the principled stance as, Jane Akre and Steve Wilson did, but not everyone can afford to pay the prices. People have to pay rent and take care of their families. The reality is that if society really cares about have access to information that has integrity they need to pay for it.

Is it time to have audited standards for the media, similar to the one used for financial information generated by financial companies? 

Although not perfect by any stretch of the imagination - the accounting scandals, a la Enron, serve as an important reminder of the lack of perfection in the system - the way financial information is subjected to testing serves at least as a starting to point as way to understand what needs to be there to ensure the information has integrity. 

Another probably more plausible approach is to leverage crowd sourcing and organize it to enable people comment or blow the whistle on information that is produced in a manner that is inaccurate, incomplete or invalid. The Guardian actually did this for the MPs expenses: they built an app that allowed ordinary users to analyze MPs expenses (if interested check out the Google Docs Spreadsheet with this info). As noted in the article, there was another attempt to build such an app (see here for the alternative). This is both good and bad. It's good in the sense that no one organization has the ability to monopolize such initiatives. However, it is bad in the sense that the efforts of the crowd are effectively divided. Regardless, it does illustrate that the potential for "crowd sourced audits". 

Sunday, January 20, 2013

Unauthorized Access to China? Value of IT Audits and Control Frameworks

Various media sites and blogs, including the BBC, picked up on the story reported by this blog about one enterprising individual who decided to apply what all the major manufacturing companies and service companies are doing: outsource work to cheap labour pools in China (and also India). According to the Verizon post, the individual would basically show his face to work and surf the Internet, while the developers in China were doing all the hard work. Although many have attacked him as being lazy and "scamming" the system, the reality is that many enterprises, such as Apple, depend on such strategies for their profitability. Regardless of this debate, it ultimately the individual violated his agreement with the company. (I am assuming that he had a standard terms of employment that required him to do the work assigned to him and not to provide his credentials to unauthorized users).

From Information Security Risk and Control perspective, this story is a good one for IT Audit and Security practitioners to highlight the importance of IT control framework, risk analysis and audits. The company that discovered the issue was reviewing the security logs. As Andrew Valentine notes in the original Verizon security blog post that noted the incident: "In early May 2012, after reading the 2012 DBIR, their IT security department decided that they should start actively monitoring logs being generated at the VPN concentrator. (As illustrated within our DBIR statistics, continual and pro-active log review happens basically never – only about 8% of breaches in 2011 were discovered by internal log review)." Effectively, the DBIR acted a control framework. It illustrated the importance of best practices to those that read it. And this is ultimately the role of IT Control Frameworks. COBIT, Trust Services and ISO 27001/2, all identify the need to log access and review such access.  COBIT 4.1, published by the Information Systems Audit and Control Association (ISACA), identifies the following control in their framework:


DS5.5 Security Testing, Surveillance and Monitoring
"Test and monitor the IT security implementation in a proactive way. IT security should be reaccredited in a timely manner to ensure that the approved enterprise’s information security baseline is maintained. A logging and monitoring function will enable the early prevention and/or detection and subsequent timely reporting of unusual and/or abnormal activities that may need to be addressed."

Trust Services, jointly published by AICPA and the CICA, requires the following (See the Security Principle, 3.2(g) on page 10):
 "The information security team, under the direction of the CIO, maintains access to firewall and other logs, as well as access to any storage media. Any access is logged and reviewed in accordance with the company’s IT policies."

ISO 27001/2 requires "Audit logging" under 10.10.1 See page 5 of this sales document from Splunk, a big data company that analyzes logs. ISO keeps this document confidential and so no direct link to the control could be provided.

The other important aspect of this story is that the individuals who read Verizon's DBIR understood how the control related to a specific risk (if you read the report the information security controls identified are linked to the risks they manage). Consequently, to get buy in, IS assurance professionals need to link the IT controls or  frameworks. Presenting controls in isolation fails to illustrate the importance of such controls. It would be interesting if ISACA could either team with Verizon to publish the next report or actually map the report to its framework.

Finally, Verizon's work illustrates the importance of IT audit. Organizations that want to keep on top of security threats and risks need to have competent security and risk professionals that can investigate and analyze risks when the are identified.