Sunday, February 17, 2013

NYT vs Tesla: Sustainability, Electric Cars and Data Audits

On February 10th, the New York Times posted a negative review of the Tesla S Sports car. The article entitled, "Stalled Out on Tesla’s Electric Highway", painted a bleak picture of the ability of the Tesla to keep its charge and travel long distances. This is obviously a big concern for those that would purchase such a car.  The reporter who drove the car noted the following with respect to his experience during the test drive:
  • Charge was dropping faster than anticipated.
  • In order to extend the charge, the reporter reduced the temperature to the point where he was feeling uncomfortable.
  • The reporter barely made it to the next charging station, even though he should have been able to make it (easily) based on the amount of charge indicated at the outset of his journey.
  • Car did not retain its charge overnight after. When the reporter went to sleep it stated 79 miles was required, but in the morning it stated that 25 miles was remaining
  • On another leg of the trip the reporter never made it to the next charge station, even though the driver drove the car at a modest 45 miles per hour. Instead, the car shut down on the road, requiring the reporter to wait 45 minutes for the car to be put on the flat bed truck.

Billionaire Elon Musk, the co-founder and CEO of Tesla and founder of PayPal, was not going to take this review lying down. As it turns out, the Tesla S sports car had data logs recording the drivers actions. So, Elon reviewed the logs and fired back with the following post, disputing the claims of the NY Times article. He noted the following:

  • The temperature was not turned down, but instead turned up to 74 degrees.
  • Insufficient time was spent charging the car (47 minutes instead of 59 minutes).
  • On the last leg of the trip where the car died, the reporter actually missed the recharge station.
  • He drove between 61 and 81 mph, well beyond the 45 mph claimed.
The blog post also points a link to the following article, highlighting that the report had previously noted that electric cars were "dismal, the victim of hyped expectations, technological flops, high costs and a hostile political climate", pointing to the writer's bias against electric cars. 

Of course, the report was also not going to take this rebuttal lying down either. And so he fired back with the following "rebuttal of the rebuttal". (I am not going to summarize what he said, but you can read it there).

The point is who is correct? 

Although Tesla is stating that the reporter has an axe to grind, the same argument can be made against Tesla. That is, they want electric cars to be viewed favourably so that their company succeeds. 

And that's where the importance of data audits and system controls come in.

How do we know the logs that Tesla are using are not tampered with? What are the system controls that are in place to ensure that there is data integrity? 

The importance of this topic goes beyond a tussle between a media outlet and company. What's really being discussed is here is environmental sustainability. The tussle illustrates the increasing importance of data for society to make critical judgments on how to think about sustainability. And this goes to my next question: are assurance practitioners ready to tackle these types of third party reporting challenges? 

As I've mentioned in previous posts, auditing information is skill that goes beyond the actual information being audited. In terms of the Tesla car, audit procedures could be performed to see whether there were controls over the data logs exist to ensure they were not tampered with,  the sensors that report the data generated could also be tested for completeness, accuracy and validity, etc. For example, Musk claims that the car never ran out of energy, where as the reporter (in his rebuttal) claims it did. So is it the reporter right and the sensors wrong? Or the sensors right and the reporter are wrong? You can only know if someone independent of the NYT and Tesla tested the controls. 

As we know from the increased interest in big data (e.g. it was a big part of the last US federal election), these types of disagreements are going to become more common place. It illustrates the financial auditors need to become more proficient in technology and be able to port over their skills from one arena of financial information to sustainability, etc.

However, the world waits for no one. 

Non-accountants have already started to dabble in the world of assurance. Although not an audit per se, CloudAudit  is an attempt by members of the Cloud Security Alliance to allow potential cloud customers to view "audit artifacts" (which I would translate to source documents or audit evidence) maintained by a cloud service provider and gain some comfort over the state system controls at the cloud customer. Consequently, if audit professionals choose to stay on the sidelines and stick to the traditional financial audit, some other tech savvy professional group will be needed to fill this gap.  

Sunday, February 3, 2013

CNET, CES and Crowd-sourced audits: Independence does matter

In a previous post, I looked at how the editorial interference from CBS forced CNET to award the Best in Show category to another contestant because CBS was involved in litigation against the company who actually did win best in show. The perspective that I took was more of a "decision usefulness" perspective: could a reader actually figure out who the real winner is due to the use of disclaimers. 

Others were much more outraged over this lack of objectivity. 

Since my post, Greg Sandoval, a reporter at CNET, has resigned over the controversy (click here to see his tweet).  More importantly, the Consumer Electronics Association (CEA) itselft has taken a firm stand against this move by CBS. As noted in this press release, they have effectively overturned CNET's decision and have awarded the Best in Show to both the Hopper and Razor's Edge (effectively CNET's second choice). They have also are requesting a request for proposal for "a new partner to run the Best of CES awards program". 

Looking at the heart of the issue, the question is how does one maintain independence when reporting on a matter? 

We can take a look at what the Canadian Institute of Chartered Accountants (CICA) and the Canadian Public Accountability Board (CPAB) have written about independence in this publication. On page 7, they cite the International Ethics Standards Board for Accountants (IESBA) and breakdown independence in two categories: 
  • "Independence of mind: The state of mind that permits the expression of a conclusion without being affected by influences that compromise professional judgment, thereby allowing an individual to act with integrity and exercise objectivity and professional skepticism.
  • "Independence in appearance: The avoidance of facts and circumstances that are so significant that a reasonable and informed  third party would be likely to conclude, weighing all the specific facts and circumstances, that a firm’s, or a member of the audit team’s, integrity, objectivity or professional skepticism has been compromised."
The publication also a number of threats to independence. The two probably most relevant are the "self-interest threat" and the "intimidation threat", which I think are probably most relevant to the CNET-CES controversy. Effectively, CBS's objectivity of the reporters was put aside in favour of the self-interest emanating from their litigation against DISH (who makes the Hopper). 

But the more interesting one to explore is the "intimidation threat". And this is most felt by reporters and editors who are pressured to abandon their view in favour of what the parent company wanted. And it speaks to a fundamental flaw in journalism: the press depends on money from the companies and others that they need to write about. The biggest illustration of this is what went down between Fox News and Jane Akre and Steve Wilson when they were forced to stop reporting about the health effects of drinking milk from cows that had been given Monanto's Bovine Growth Hormone. The reporters were fired when they refused to give into the "intimidation threat". They initially won their case under Florida's whistle blower law, but when Fox appealed they lost. The reason? The media has no obligation to tell the truth.  

So the challenge remains as to how does one remain independent when they need to eat and pay their bills in a free market system? Greg took the principled stance as, Jane Akre and Steve Wilson did, but not everyone can afford to pay the prices. People have to pay rent and take care of their families. The reality is that if society really cares about have access to information that has integrity they need to pay for it.

Is it time to have audited standards for the media, similar to the one used for financial information generated by financial companies? 

Although not perfect by any stretch of the imagination - the accounting scandals, a la Enron, serve as an important reminder of the lack of perfection in the system - the way financial information is subjected to testing serves at least as a starting to point as way to understand what needs to be there to ensure the information has integrity. 

Another probably more plausible approach is to leverage crowd sourcing and organize it to enable people comment or blow the whistle on information that is produced in a manner that is inaccurate, incomplete or invalid. The Guardian actually did this for the MPs expenses: they built an app that allowed ordinary users to analyze MPs expenses (if interested check out the Google Docs Spreadsheet with this info). As noted in the article, there was another attempt to build such an app (see here for the alternative). This is both good and bad. It's good in the sense that no one organization has the ability to monopolize such initiatives. However, it is bad in the sense that the efforts of the crowd are effectively divided. Regardless, it does illustrate that the potential for "crowd sourced audits". 

Sunday, January 20, 2013

Unauthorized Access to China? Value of IT Audits and Control Frameworks

Various media sites and blogs, including the BBC, picked up on the story reported by this blog about one enterprising individual who decided to apply what all the major manufacturing companies and service companies are doing: outsource work to cheap labour pools in China (and also India). According to the Verizon post, the individual would basically show his face to work and surf the Internet, while the developers in China were doing all the hard work. Although many have attacked him as being lazy and "scamming" the system, the reality is that many enterprises, such as Appledepend on such strategies for their profitability. Regardless of this debate, it ultimately the individual violated his agreement with the company. (I am assuming that he had a standard terms of employment that required him to do the work assigned to him and not to provide his credentials to unauthorized users).

From Information Security Risk and Control perspective, this story is a good one for IT Audit and Security practitioners to highlight the importance of IT control framework, risk analysis and audits. The company that discovered the issue was reviewing the security logs. As Andrew Valentine notes in the original Verizon security blog post that noted the incident: "In early May 2012, after reading the 2012 DBIR, their IT security department decided that they should start actively monitoring logs being generated at the VPN concentrator. (As illustrated within our DBIR statistics, continual and pro-active log review happens basically never – only about 8% of breaches in 2011 were discovered by internal log review)." Effectively, the DBIR acted a control framework. It illustrated the importance of best practices to those that read it. And this is ultimately the role of IT Control Frameworks. COBIT, Trust Services and ISO 27001/2, all identify the need to log access and review such access.  COBIT 4.1, published by the Information Systems Audit and Control Association (ISACA), identifies the following control in their framework:


DS5.5 Security Testing, Surveillance and Monitoring
"Test and monitor the IT security implementation in a proactive way. IT security should be reaccredited in a timely manner to ensure that the approved enterprise’s information security baseline is maintained. A logging and monitoring function will enable the early prevention and/or detection and subsequent timely reporting of unusual and/or abnormal activities that may need to be addressed."

Trust Services, jointly published by AICPA and the CICA, requires the following (See the Security Principle, 3.2(g) on page 10):
 "The information security team, under the direction of the CIO, maintains access to firewall and other logs, as well as access to any storage media. Any access is logged and reviewed in accordance with the company’s IT policies."

ISO 27001/2 requires "Audit logging" under 10.10.1 See page 5 of this sales document from Splunk, a big data company that analyzes logs. ISO keeps this document confidential and so no direct link to the control could be provided.

The other important aspect of this story is that the individuals who read Verizon's DBIR understood how the control related to a specific risk (if you read the report the information security controls identified are linked to the risks they manage). Consequently, to get buy in, IS assurance professionals need to link the IT controls or  frameworks. Presenting controls in isolation fails to illustrate the importance of such controls. It would be interesting if ISACA could either team with Verizon to publish the next report or actually map the report to its framework.

Finally, Verizon's work illustrates the importance of IT audit. Organizations that want to keep on top of security threats and risks need to have competent security and risk professionals that can investigate and analyze risks when the are identified.


Sunday, January 13, 2013

Auditing the Media: Was CNET's CES coverage complete?

As noted in the Tech News Today (TNT) report on Friday, CNET's parent CBS banned its staff from awarding Dish's "Hopper" an award as part of their reporting the Consumer Electronics Show that just wrapped up last week. As reported by CNN, the bottom of CNET's 'Best of 2013' page notes the following:

"The Dish Hopper with Sling was removed from consideration due to active litigation involving our parent company CBS Corp. We will no longer be reviewing products manufactured by companies with which we are in litigation with respect to such products."

Some may point to this as a legal risk management move: CBS had to stop CNET from awarding this to Dish to avoid it being used against them in court. However,  Ayaz Akhtar, a non-practicing lawyer and host of TNT, noted in his commentary on the issue that CNET awarding a prize would have little impact on the course of litigation  (but listen to the show for the proper context and for how he worded this. He's careful to avoid any misrepresentation and it's not an exact quote).

The real issue, in my humble opinion, is to looking at whether media be relied on to report on issues objectively. One could say that due to the lack of independence of CNET on the matter, makes their reporting of CES lack objectivity. This is the standard of care that a financial auditor is held to when auditing a company. For example, auditors are prevented from holding stock in companies that they audit. Should the media be held to the same standard?


For me this incident illustrates how the concepts of financial information integrity are portable to other arenas, such as understanding news coverage. Financial information produced by companies listed on stock exchanges is subjected intense scrutiny and regulation. Accountants/auditors were required to develop a framework to analyze how financial information can be provided to investors in a reliable that enables them to make effective investment allocation decisions. This financial “information production” process is essentially similar to the “information production” process produced by the media: data is gathered, summarized and presented to the user/reader to make a decision. The latter is the key difference. For example, if someone is going to rely on CNET's CES coverage to understand the best products out there, then they could make an erroneous decision because CNET did not cover dish's product.

The following is a list of audit objectives (i.e. completeness, accuracy, etc) that financial information must meet in order to reliable for decision making purposes.

  • Completeness – is the information presented completed, i.e. everything that is out there is included in the medium
  • Accuracy – is the information congruent with the original event
  • Timely – was the information reported in a timely manner, to be useful to the user
  • Validity – does the information faithfully represent the underlying reality that is presented
Another important concept, especially to media coverage, is the one  of "presentation & disclosure – is the presentation of the information impartial. In financial statements, companies may engage in transactions to alter the presentation of items, e.g. bury accounts payable into accounts receivable so the user won't be able to accurately assess the ratio of current assets to current liabilities. Media has a greater ability to do this. And I don't mean to pick on the CNET people because they at least tried to inform the reader about their bias, but the statement they mentioned is at the bottom and not at the top. That is, some readers may miss it.

Overall, it's hard to say whether that the coverage lacked integrity and more specifically was "incomplete". On the one hand, one could argue their analysis was in complete because they excluded Dish's product. However, they did provide full disclosure although it is buried at the bottom. But one can easily search for Dish's product on the Internet and see what other reviewers are saying (e.g. such as PCMag's review). But it does illustrate that media consumers need to be aware of such risks and do their best to understand where corporate conflicts exist and how such coverage can be biased.









Sunday, January 6, 2013

Social Media & Privacy: The Return of the Village

Some of you with connections to the younger folk may have heard of SnapChat. The promise of the application was that it would allow its users to share images that would be deleted within a few seconds of it being transmitted. Another similar app and function is offered by Facebook called Poke. The hope was that, such an app would protect the privacy of the users by maintaining the confidentiality of the messages sent. However, CNET uncovered (based on the blog, BuzzFeed FWD) that it is quite easy to go around the controls:
"an iPhone user simply has to plug the smartphone into a computer, navigate to the phone's internal storage, and find the folders for Snapchat and Poke where the videos are stored locally. The user can then copy the videos from the phone to the computer to sneak a peek at them. In BuzzFeed's testing, this bug applied only to videos; photos didn't appear to show up."

The workaround, if you will, illustrates something that we know that there is always a way around these controls and therefore they offer limited privacy protection at best. The reality is that once something gets online it's out there forever.

I try to make the next generation of accounting students aware of the risks during the Master's course I teach at the University of Waterloo.  During class, I ask them to pull articles on how posting on Facebook can undermine one's career and professional prospects. (here is a blog that compiles social media faux pas that results in one losing one's job). As the then CEO of Sun Microsystems (now owned by Oracle), Scott McNealy stated (back in 1999), "You have zero privacy anyway.Get over it."

Over the summer, I had some time to think about privacy and social media as I was researching the phenomenon. One of the thoughts that struck me was that social media actually represents the "Return of the Village". Being an urbanite myself. I am used to living in the city or the burbs where people "mind their business". However, that's not how life is in the traditional village. In the village, everybody knows everybody and word gets around quickly about people's affairs. There, just as in the online world, if you don't want anyone to know something don't tell anyone about it. Consequently, privacy has always been limited in a village context. However, as Jeff Jarvis touts in his book Public Parts, there are benefits to living life publicly. In other words, by living in the "online village" we get the benefits of a community that was hard to find living in the more individualistic urban setting. A couple examples that illustrate this concept:

When developing an internal controls strategy around social it is important to keep the human element at the focus of the strategy. As illustrated by SnapChat, technology-centric controls can be easily circumvented. Furthermore, when considering the risks of employees contributing online it is important to remember that it is hard to segment one's professional world in the corporate cubicle with one's personal life. Consequently, governance and controls need to address the personnel rather than relying solely on technological solutions, such as data loss prevention tools. For example, Microsoft relies essentially on its people to police themselves and in order to post things that are in-line with Microsoft's corporate culture. In other words, the techno-centric solutions can supplement governance controls but they don't supplant them. 

In terms of protecting oneself from privacy breaches it requires vigilance. Some totally avoid being a social network for just the reason. That being said such people are in the minority (I poll students annually as to whether they are on Facebook: a handful give it up because it is a waste of time. I've found 1 or 2 people who've given it up for privacy reasons). Other try to mitigate such risks through "social controls". For example, in the Facebook Effect, the author notes how colleges have no cellphone and no camera parties to avoid illegal activities for finding their way online. It may seem like weak control because anyone can sneak a camera into the party. What this misses is really that the control is social in nature: people won't take pictures because they wanted to be invited to the next party!

Ultimately, the real test of social media will be how it is used against people who do not conform to the norm. For example, what would happen if employers discriminate against people who support the Occupy Wall Street movement? If people go along with such discrimination, social media essentially becomes a way to ensure conformity in society. Conversely, if such discrimination is opposed, then it would lead to a more open society as the threat of social sanction (e.g. unable to finding employment) is effectively removed.  

Monday, December 3, 2012

The other DDoS: Denial of Service by DMCA

In information security, the common definition of DDoS is Distributed Denial of Service attack. However, there is a legally sanctioned form of DDoS: DMCA Denial of Service, where a user acting in good faith is 'denied service' because of an alleged infringement of the DMCA. The DMCA (i.e. the Digital Millennium Copyright Act) provides a means to enforce of copyright protections online and was ultimately responsible for killing Napster (who enabled peer-to-peer sharing of  music and other files). Although the Napster case was cut & dry to some (like the Recording Industry), there are some where users are actually acting in good faith, but are taken down through enforcement of such  an Act.

The case that illustrates this issue is the take down of 1.45 million education blogs in October. James Framer, CEO of EduBlogs, noted that "ServerBeach, to whom we pay $6,954.37 every month to host Edublogs, turned off our webservers, without notice, less than 12 hours after issuing us with a DMCA email." He went on to explain what the actual infringement was: "one of our teachers, in 2007, had shared a copy of Beck’s Hopelessness Scale with his class, a 20 question list, totalling some 279 words, published in 1974, that Pearson would like you to pay $120 for." Reading the blog further it turns out that EduBlogs did actually comply with the DMCA request that they received. However, the issue that Pearson had was (a) it was accessible via Google's cache and (b) it was accessible by its Varnish cache. In other words, James Farmer got legally DDoSed: 1.45 million blogs were made unavailable due to ServerBeach rush to comply with the DMCA instead of "calling any of the 3 numbers for us [ServerBeach] have on file".

Edublogs, however, is not the only company to be DDoSed in this manner. Small companies that publish news reports on YouTube or other content sharing sites also face this danger. Take for example Leo Laporte's This Week in Tech (TWIT) new media network, which publishes tech related podcasts and videocasts. The business model of this network resides on him being able to make the video available soon after its airing. Failure to do so will result in the company losing out on ad revenue because the "eyeballs never made it" to the particular show. Consequently, when one of their episodes gets pulled down by Google's robots, or due to request of the copyright holder (as noted here), it jeopardizes the TWIT business model making him another DDoS victim.

From a risk perspective, the risk of such event should be evaluated, especially for businesses that rely on revenues via the distribution of online content. Specifically, the agreement with the third parties that host their content should include provisions that enable them to at least demonstrate compliance prior to be taken down. However, both James Farmer and Leo Laporte have attempted to work with their respective providers to prevent this type of risk. Farmer complied with the request, while Laporte has attempted to contact Google and explain that he is news organization. So this is easier said then done. Laporte hosts the videos on his own servers, however the popularity of YouTube limits the effectiveness of this "backup strategy" (i.e. users won't go to the site to watch the video instead of YouTube). In the end, it may just be an unavoidable cost of relying on such providers.

From a longer-term perspective, it illustrates clash of legacy laws and the capability of the Internet to "network knowledge". This the concept is taken from David Weinbergers's "Too big To Know", who identified how the ability to share, link and debate information on the Internet transforms knowledge into a more fluid state in contrast to the static nature of books. He explains this concept in the following video:

James Farmer implicitly argued this point in his rant against Pearson when he said: "Here’s another idea Pearson, maybe one that you could take from Edublogs, howabout you let this tiny useful list be freely available, and then you sell your study materials / textbooks and other material around that… maybe use  Creative Commons Non Commercial Attribution license or similar to make sure you get some links and business." In other words, Pearson has failed to understand this new world of networked knowledge, where a link to the "offending" list would link to other resources that has Pearson has - enriching both Pearson and those using its publications.


Monday, November 19, 2012

Hurricane Sandy and Disaster Recovery: Cloud to the rescue?

When looking at the aftermath of hurricane Sandy, the most important aspect of the event is the toll it has had on the people. The Atlantic puts the total impact in terms of dollars at $60 billion, with death toll at 123 people. However, those that survived face the challenges brought about by the flooding and living without power for weeks. For example, 4 million remained without power for extended period of time. This of course challenged individuals to keep their frozen food cold and live without technology for that period of time. As for companies, their disaster recovery plans were put to the test. Perhaps the most poignant example was the New York University Langone Medical Center who had to evacuate patients because their backup generators because they were located in the basements, which got flooded. Hospital officials defended their preparedness  but critics pointed out that the backup power generators "are not state-of-the-art".

Samara Lynn of PC Magazine published an article on how Sandy taught organizations valuable lessons from a Disaster Recovery (DR) perspective (she previously painstakingly put together a 4 part series for small and medium sized businesses on DR planning; see here, here, here, and here). Before I read the article, I was expecting a bulleted list of dos and don'ts when it comes DR planning. But what I was surprised to find is that companies are relying on cloud computing service providers to make up for the unavailability of local processing. Examples include:
  • A New York Architectural firm Diller Scofidio + Renfro used Amazon Web Services (AWS) to relocate the company's core applications, enabling users with the proper license configuration to access these applications right from their laptops. Also, the IT Manager, Chris Donnell, used AWS as a remote desktop during the disaster. (I encourage you to read the whole article as it details how Chris was in the middle of an email migration from Outlook to Gmail when Sandy hit; poor guy!). The company also used Panzura to store the data temporarily in the cloud.
  • Ring Central, a cloud-based pbx hosting service, (they sponsor TWIET and other podcasts on the TWIT network) was able to relocate their operations away from the storm. More importantly, they offer near instant recovery of phone support by plugging in a piece of hardware they can "bring in a live extension under 10 minutes". Naturally, there is an increased interest in Ring Central by those that were satisfied with the lengthy recovery times of their providers. 
The article also discusses how a service provider made DR as part of IT outsourcing service and how the key to DR is backup power. 

Although not related directly to cloud, one of the most amazing story that I've heard is how SquareSpace (SQS) kept it's platform up and running. Like the hospital, SQS had its back up generator in the basement and that got flooded. It published this blog post to inform customers of what was happening. However, the real interesting story is the lengths that team went to ensure the site stayed up and running. The team physically took fuel from the basement to the generator of the roof going up 17 flights of stair

Even more amazing was that the founder and CEO, Anthony Casalena, personally helped in this effort. Talk about Tone at the Top