Sunday, February 3, 2013

CNET, CES and Crowd-sourced audits: Independence does matter

In a previous post, I looked at how the editorial interference from CBS forced CNET to award the Best in Show category to another contestant because CBS was involved in litigation against the company who actually did win best in show. The perspective that I took was more of a "decision usefulness" perspective: could a reader actually figure out who the real winner is due to the use of disclaimers. 

Others were much more outraged over this lack of objectivity. 

Since my post, Greg Sandoval, a reporter at CNET, has resigned over the controversy (click here to see his tweet).  More importantly, the Consumer Electronics Association (CEA) itselft has taken a firm stand against this move by CBS. As noted in this press release, they have effectively overturned CNET's decision and have awarded the Best in Show to both the Hopper and Razor's Edge (effectively CNET's second choice). They have also are requesting a request for proposal for "a new partner to run the Best of CES awards program". 

Looking at the heart of the issue, the question is how does one maintain independence when reporting on a matter? 

We can take a look at what the Canadian Institute of Chartered Accountants (CICA) and the Canadian Public Accountability Board (CPAB) have written about independence in this publication. On page 7, they cite the International Ethics Standards Board for Accountants (IESBA) and breakdown independence in two categories: 
  • "Independence of mind: The state of mind that permits the expression of a conclusion without being affected by influences that compromise professional judgment, thereby allowing an individual to act with integrity and exercise objectivity and professional skepticism.
  • "Independence in appearance: The avoidance of facts and circumstances that are so significant that a reasonable and informed  third party would be likely to conclude, weighing all the specific facts and circumstances, that a firm’s, or a member of the audit team’s, integrity, objectivity or professional skepticism has been compromised."
The publication also a number of threats to independence. The two probably most relevant are the "self-interest threat" and the "intimidation threat", which I think are probably most relevant to the CNET-CES controversy. Effectively, CBS's objectivity of the reporters was put aside in favour of the self-interest emanating from their litigation against DISH (who makes the Hopper). 

But the more interesting one to explore is the "intimidation threat". And this is most felt by reporters and editors who are pressured to abandon their view in favour of what the parent company wanted. And it speaks to a fundamental flaw in journalism: the press depends on money from the companies and others that they need to write about. The biggest illustration of this is what went down between Fox News and Jane Akre and Steve Wilson when they were forced to stop reporting about the health effects of drinking milk from cows that had been given Monanto's Bovine Growth Hormone. The reporters were fired when they refused to give into the "intimidation threat". They initially won their case under Florida's whistle blower law, but when Fox appealed they lost. The reason? The media has no obligation to tell the truth.  

So the challenge remains as to how does one remain independent when they need to eat and pay their bills in a free market system? Greg took the principled stance as, Jane Akre and Steve Wilson did, but not everyone can afford to pay the prices. People have to pay rent and take care of their families. The reality is that if society really cares about have access to information that has integrity they need to pay for it.

Is it time to have audited standards for the media, similar to the one used for financial information generated by financial companies? 

Although not perfect by any stretch of the imagination - the accounting scandals, a la Enron, serve as an important reminder of the lack of perfection in the system - the way financial information is subjected to testing serves at least as a starting to point as way to understand what needs to be there to ensure the information has integrity. 

Another probably more plausible approach is to leverage crowd sourcing and organize it to enable people comment or blow the whistle on information that is produced in a manner that is inaccurate, incomplete or invalid. The Guardian actually did this for the MPs expenses: they built an app that allowed ordinary users to analyze MPs expenses (if interested check out the Google Docs Spreadsheet with this info). As noted in the article, there was another attempt to build such an app (see here for the alternative). This is both good and bad. It's good in the sense that no one organization has the ability to monopolize such initiatives. However, it is bad in the sense that the efforts of the crowd are effectively divided. Regardless, it does illustrate that the potential for "crowd sourced audits". 

Sunday, January 20, 2013

Unauthorized Access to China? Value of IT Audits and Control Frameworks

Various media sites and blogs, including the BBC, picked up on the story reported by this blog about one enterprising individual who decided to apply what all the major manufacturing companies and service companies are doing: outsource work to cheap labour pools in China (and also India). According to the Verizon post, the individual would basically show his face to work and surf the Internet, while the developers in China were doing all the hard work. Although many have attacked him as being lazy and "scamming" the system, the reality is that many enterprises, such as Appledepend on such strategies for their profitability. Regardless of this debate, it ultimately the individual violated his agreement with the company. (I am assuming that he had a standard terms of employment that required him to do the work assigned to him and not to provide his credentials to unauthorized users).

From Information Security Risk and Control perspective, this story is a good one for IT Audit and Security practitioners to highlight the importance of IT control framework, risk analysis and audits. The company that discovered the issue was reviewing the security logs. As Andrew Valentine notes in the original Verizon security blog post that noted the incident: "In early May 2012, after reading the 2012 DBIR, their IT security department decided that they should start actively monitoring logs being generated at the VPN concentrator. (As illustrated within our DBIR statistics, continual and pro-active log review happens basically never – only about 8% of breaches in 2011 were discovered by internal log review)." Effectively, the DBIR acted a control framework. It illustrated the importance of best practices to those that read it. And this is ultimately the role of IT Control Frameworks. COBIT, Trust Services and ISO 27001/2, all identify the need to log access and review such access.  COBIT 4.1, published by the Information Systems Audit and Control Association (ISACA), identifies the following control in their framework:


DS5.5 Security Testing, Surveillance and Monitoring
"Test and monitor the IT security implementation in a proactive way. IT security should be reaccredited in a timely manner to ensure that the approved enterprise’s information security baseline is maintained. A logging and monitoring function will enable the early prevention and/or detection and subsequent timely reporting of unusual and/or abnormal activities that may need to be addressed."

Trust Services, jointly published by AICPA and the CICA, requires the following (See the Security Principle, 3.2(g) on page 10):
 "The information security team, under the direction of the CIO, maintains access to firewall and other logs, as well as access to any storage media. Any access is logged and reviewed in accordance with the company’s IT policies."

ISO 27001/2 requires "Audit logging" under 10.10.1 See page 5 of this sales document from Splunk, a big data company that analyzes logs. ISO keeps this document confidential and so no direct link to the control could be provided.

The other important aspect of this story is that the individuals who read Verizon's DBIR understood how the control related to a specific risk (if you read the report the information security controls identified are linked to the risks they manage). Consequently, to get buy in, IS assurance professionals need to link the IT controls or  frameworks. Presenting controls in isolation fails to illustrate the importance of such controls. It would be interesting if ISACA could either team with Verizon to publish the next report or actually map the report to its framework.

Finally, Verizon's work illustrates the importance of IT audit. Organizations that want to keep on top of security threats and risks need to have competent security and risk professionals that can investigate and analyze risks when the are identified.


Sunday, January 13, 2013

Auditing the Media: Was CNET's CES coverage complete?

As noted in the Tech News Today (TNT) report on Friday, CNET's parent CBS banned its staff from awarding Dish's "Hopper" an award as part of their reporting the Consumer Electronics Show that just wrapped up last week. As reported by CNN, the bottom of CNET's 'Best of 2013' page notes the following:

"The Dish Hopper with Sling was removed from consideration due to active litigation involving our parent company CBS Corp. We will no longer be reviewing products manufactured by companies with which we are in litigation with respect to such products."

Some may point to this as a legal risk management move: CBS had to stop CNET from awarding this to Dish to avoid it being used against them in court. However,  Ayaz Akhtar, a non-practicing lawyer and host of TNT, noted in his commentary on the issue that CNET awarding a prize would have little impact on the course of litigation  (but listen to the show for the proper context and for how he worded this. He's careful to avoid any misrepresentation and it's not an exact quote).

The real issue, in my humble opinion, is to looking at whether media be relied on to report on issues objectively. One could say that due to the lack of independence of CNET on the matter, makes their reporting of CES lack objectivity. This is the standard of care that a financial auditor is held to when auditing a company. For example, auditors are prevented from holding stock in companies that they audit. Should the media be held to the same standard?


For me this incident illustrates how the concepts of financial information integrity are portable to other arenas, such as understanding news coverage. Financial information produced by companies listed on stock exchanges is subjected intense scrutiny and regulation. Accountants/auditors were required to develop a framework to analyze how financial information can be provided to investors in a reliable that enables them to make effective investment allocation decisions. This financial “information production” process is essentially similar to the “information production” process produced by the media: data is gathered, summarized and presented to the user/reader to make a decision. The latter is the key difference. For example, if someone is going to rely on CNET's CES coverage to understand the best products out there, then they could make an erroneous decision because CNET did not cover dish's product.

The following is a list of audit objectives (i.e. completeness, accuracy, etc) that financial information must meet in order to reliable for decision making purposes.

  • Completeness – is the information presented completed, i.e. everything that is out there is included in the medium
  • Accuracy – is the information congruent with the original event
  • Timely – was the information reported in a timely manner, to be useful to the user
  • Validity – does the information faithfully represent the underlying reality that is presented
Another important concept, especially to media coverage, is the one  of "presentation & disclosure – is the presentation of the information impartial. In financial statements, companies may engage in transactions to alter the presentation of items, e.g. bury accounts payable into accounts receivable so the user won't be able to accurately assess the ratio of current assets to current liabilities. Media has a greater ability to do this. And I don't mean to pick on the CNET people because they at least tried to inform the reader about their bias, but the statement they mentioned is at the bottom and not at the top. That is, some readers may miss it.

Overall, it's hard to say whether that the coverage lacked integrity and more specifically was "incomplete". On the one hand, one could argue their analysis was in complete because they excluded Dish's product. However, they did provide full disclosure although it is buried at the bottom. But one can easily search for Dish's product on the Internet and see what other reviewers are saying (e.g. such as PCMag's review). But it does illustrate that media consumers need to be aware of such risks and do their best to understand where corporate conflicts exist and how such coverage can be biased.









Sunday, January 6, 2013

Social Media & Privacy: The Return of the Village

Some of you with connections to the younger folk may have heard of SnapChat. The promise of the application was that it would allow its users to share images that would be deleted within a few seconds of it being transmitted. Another similar app and function is offered by Facebook called Poke. The hope was that, such an app would protect the privacy of the users by maintaining the confidentiality of the messages sent. However, CNET uncovered (based on the blog, BuzzFeed FWD) that it is quite easy to go around the controls:
"an iPhone user simply has to plug the smartphone into a computer, navigate to the phone's internal storage, and find the folders for Snapchat and Poke where the videos are stored locally. The user can then copy the videos from the phone to the computer to sneak a peek at them. In BuzzFeed's testing, this bug applied only to videos; photos didn't appear to show up."

The workaround, if you will, illustrates something that we know that there is always a way around these controls and therefore they offer limited privacy protection at best. The reality is that once something gets online it's out there forever.

I try to make the next generation of accounting students aware of the risks during the Master's course I teach at the University of Waterloo.  During class, I ask them to pull articles on how posting on Facebook can undermine one's career and professional prospects. (here is a blog that compiles social media faux pas that results in one losing one's job). As the then CEO of Sun Microsystems (now owned by Oracle), Scott McNealy stated (back in 1999), "You have zero privacy anyway.Get over it."

Over the summer, I had some time to think about privacy and social media as I was researching the phenomenon. One of the thoughts that struck me was that social media actually represents the "Return of the Village". Being an urbanite myself. I am used to living in the city or the burbs where people "mind their business". However, that's not how life is in the traditional village. In the village, everybody knows everybody and word gets around quickly about people's affairs. There, just as in the online world, if you don't want anyone to know something don't tell anyone about it. Consequently, privacy has always been limited in a village context. However, as Jeff Jarvis touts in his book Public Parts, there are benefits to living life publicly. In other words, by living in the "online village" we get the benefits of a community that was hard to find living in the more individualistic urban setting. A couple examples that illustrate this concept:

When developing an internal controls strategy around social it is important to keep the human element at the focus of the strategy. As illustrated by SnapChat, technology-centric controls can be easily circumvented. Furthermore, when considering the risks of employees contributing online it is important to remember that it is hard to segment one's professional world in the corporate cubicle with one's personal life. Consequently, governance and controls need to address the personnel rather than relying solely on technological solutions, such as data loss prevention tools. For example, Microsoft relies essentially on its people to police themselves and in order to post things that are in-line with Microsoft's corporate culture. In other words, the techno-centric solutions can supplement governance controls but they don't supplant them. 

In terms of protecting oneself from privacy breaches it requires vigilance. Some totally avoid being a social network for just the reason. That being said such people are in the minority (I poll students annually as to whether they are on Facebook: a handful give it up because it is a waste of time. I've found 1 or 2 people who've given it up for privacy reasons). Other try to mitigate such risks through "social controls". For example, in the Facebook Effect, the author notes how colleges have no cellphone and no camera parties to avoid illegal activities for finding their way online. It may seem like weak control because anyone can sneak a camera into the party. What this misses is really that the control is social in nature: people won't take pictures because they wanted to be invited to the next party!

Ultimately, the real test of social media will be how it is used against people who do not conform to the norm. For example, what would happen if employers discriminate against people who support the Occupy Wall Street movement? If people go along with such discrimination, social media essentially becomes a way to ensure conformity in society. Conversely, if such discrimination is opposed, then it would lead to a more open society as the threat of social sanction (e.g. unable to finding employment) is effectively removed.  

Monday, December 3, 2012

The other DDoS: Denial of Service by DMCA

In information security, the common definition of DDoS is Distributed Denial of Service attack. However, there is a legally sanctioned form of DDoS: DMCA Denial of Service, where a user acting in good faith is 'denied service' because of an alleged infringement of the DMCA. The DMCA (i.e. the Digital Millennium Copyright Act) provides a means to enforce of copyright protections online and was ultimately responsible for killing Napster (who enabled peer-to-peer sharing of  music and other files). Although the Napster case was cut & dry to some (like the Recording Industry), there are some where users are actually acting in good faith, but are taken down through enforcement of such  an Act.

The case that illustrates this issue is the take down of 1.45 million education blogs in October. James Framer, CEO of EduBlogs, noted that "ServerBeach, to whom we pay $6,954.37 every month to host Edublogs, turned off our webservers, without notice, less than 12 hours after issuing us with a DMCA email." He went on to explain what the actual infringement was: "one of our teachers, in 2007, had shared a copy of Beck’s Hopelessness Scale with his class, a 20 question list, totalling some 279 words, published in 1974, that Pearson would like you to pay $120 for." Reading the blog further it turns out that EduBlogs did actually comply with the DMCA request that they received. However, the issue that Pearson had was (a) it was accessible via Google's cache and (b) it was accessible by its Varnish cache. In other words, James Farmer got legally DDoSed: 1.45 million blogs were made unavailable due to ServerBeach rush to comply with the DMCA instead of "calling any of the 3 numbers for us [ServerBeach] have on file".

Edublogs, however, is not the only company to be DDoSed in this manner. Small companies that publish news reports on YouTube or other content sharing sites also face this danger. Take for example Leo Laporte's This Week in Tech (TWIT) new media network, which publishes tech related podcasts and videocasts. The business model of this network resides on him being able to make the video available soon after its airing. Failure to do so will result in the company losing out on ad revenue because the "eyeballs never made it" to the particular show. Consequently, when one of their episodes gets pulled down by Google's robots, or due to request of the copyright holder (as noted here), it jeopardizes the TWIT business model making him another DDoS victim.

From a risk perspective, the risk of such event should be evaluated, especially for businesses that rely on revenues via the distribution of online content. Specifically, the agreement with the third parties that host their content should include provisions that enable them to at least demonstrate compliance prior to be taken down. However, both James Farmer and Leo Laporte have attempted to work with their respective providers to prevent this type of risk. Farmer complied with the request, while Laporte has attempted to contact Google and explain that he is news organization. So this is easier said then done. Laporte hosts the videos on his own servers, however the popularity of YouTube limits the effectiveness of this "backup strategy" (i.e. users won't go to the site to watch the video instead of YouTube). In the end, it may just be an unavoidable cost of relying on such providers.

From a longer-term perspective, it illustrates clash of legacy laws and the capability of the Internet to "network knowledge". This the concept is taken from David Weinbergers's "Too big To Know", who identified how the ability to share, link and debate information on the Internet transforms knowledge into a more fluid state in contrast to the static nature of books. He explains this concept in the following video:

James Farmer implicitly argued this point in his rant against Pearson when he said: "Here’s another idea Pearson, maybe one that you could take from Edublogs, howabout you let this tiny useful list be freely available, and then you sell your study materials / textbooks and other material around that… maybe use  Creative Commons Non Commercial Attribution license or similar to make sure you get some links and business." In other words, Pearson has failed to understand this new world of networked knowledge, where a link to the "offending" list would link to other resources that has Pearson has - enriching both Pearson and those using its publications.


Monday, November 19, 2012

Hurricane Sandy and Disaster Recovery: Cloud to the rescue?

When looking at the aftermath of hurricane Sandy, the most important aspect of the event is the toll it has had on the people. The Atlantic puts the total impact in terms of dollars at $60 billion, with death toll at 123 people. However, those that survived face the challenges brought about by the flooding and living without power for weeks. For example, 4 million remained without power for extended period of time. This of course challenged individuals to keep their frozen food cold and live without technology for that period of time. As for companies, their disaster recovery plans were put to the test. Perhaps the most poignant example was the New York University Langone Medical Center who had to evacuate patients because their backup generators because they were located in the basements, which got flooded. Hospital officials defended their preparedness  but critics pointed out that the backup power generators "are not state-of-the-art".

Samara Lynn of PC Magazine published an article on how Sandy taught organizations valuable lessons from a Disaster Recovery (DR) perspective (she previously painstakingly put together a 4 part series for small and medium sized businesses on DR planning; see here, here, here, and here). Before I read the article, I was expecting a bulleted list of dos and don'ts when it comes DR planning. But what I was surprised to find is that companies are relying on cloud computing service providers to make up for the unavailability of local processing. Examples include:
  • A New York Architectural firm Diller Scofidio + Renfro used Amazon Web Services (AWS) to relocate the company's core applications, enabling users with the proper license configuration to access these applications right from their laptops. Also, the IT Manager, Chris Donnell, used AWS as a remote desktop during the disaster. (I encourage you to read the whole article as it details how Chris was in the middle of an email migration from Outlook to Gmail when Sandy hit; poor guy!). The company also used Panzura to store the data temporarily in the cloud.
  • Ring Central, a cloud-based pbx hosting service, (they sponsor TWIET and other podcasts on the TWIT network) was able to relocate their operations away from the storm. More importantly, they offer near instant recovery of phone support by plugging in a piece of hardware they can "bring in a live extension under 10 minutes". Naturally, there is an increased interest in Ring Central by those that were satisfied with the lengthy recovery times of their providers. 
The article also discusses how a service provider made DR as part of IT outsourcing service and how the key to DR is backup power. 

Although not related directly to cloud, one of the most amazing story that I've heard is how SquareSpace (SQS) kept it's platform up and running. Like the hospital, SQS had its back up generator in the basement and that got flooded. It published this blog post to inform customers of what was happening. However, the real interesting story is the lengths that team went to ensure the site stayed up and running. The team physically took fuel from the basement to the generator of the roof going up 17 flights of stair

Even more amazing was that the founder and CEO, Anthony Casalena, personally helped in this effort. Talk about Tone at the Top

Saturday, November 3, 2012

Can we live in the cloud? Prof Jeff Jarvis intends to find out

On This Week in Google (TWIG) episode 169, Jeff Jarvis, professor of journalism at CUNY, announced that he will be attempting to live only in the cloud and abandoning the comforts of offline desktops.  He recently moved to the Android eco-system (i.e. for his mobile device and tablet), which he accredits to Google's wide range of services from maps to Google Docs. Taking it to "whole nother level", Jeff is planning to live only in the cloud once he gets his hands on Samsung's ultra-cheap Chromebook, which is expected to retail for $249. The Chromebook (as its names suggests) is based on Google's Chrome OS, where the OS is basically the Chrome browser. Here's the ad in case you missed it:


As illustrated in the ad, the concept is that the Chromebook is something that everyone and anyone can use. The premise is: if you primarily do everything in the browser, then you really don't need a full laptop. A few years ago, as Leo Laporte pointed out in the episode, this experiment by the way of netbooks failed. Does Jeff have a fighting chance or will Leo tell Jeff "I-told-you-so" after Jeff experiment ends? Well, I think Jeff does have a fighting chance. Firstly, cloud computing has matured significantly since netbooks have hit the scene. Secondly, people are now accustomed to using tablets and smartphones as a way to get things done.

In a way the Chromebook represents an intersection between the trend of cloud computing and thin client devices and taking technology back to the early years of computing, where users had to "dial-in" from their "dumb terminals" into powerful mainframes. Except the Chromebook,smartphones, and tablets are replacing the dumb terminals, while the cloud computing service providers are replacing the mainframe.

Why should information security & privacy professionals care about this?

It is really about the price point. If Jeff Jarvis can successfully move to the cloud with this device, it means that the economics of the consumerization of IT has arrived. Think of a 10-person small business that is starting up. It really just needs email and office productivity apps for their clients. The IT cost would be $2500 for the hardware and then recurring cost of $500 a year for the Google Apps. The traditional  Dell laptop + MS Office license would cost about $6480 upfront + the cost of an email server + the IT resources an effort to maintain/patch the laptops and the server.

In terms of data redundancy, one could argue that all the data is on the cloud so it's actually safer. Theoretically, if the owner loses their Chromebook, they can just change their password and then the Chromebook is essentially just a "dumb" piece of hardware with no data. And as illustrated by these stats, this is no small benefit. Of course, cloud computing does have its risks as mentioned on a previous blog post and this publication (which I co-authored for the CICA). It's not that the risks in the cloud are insurmountable, but they are different then the ones we are accustomed to dealing with.

From a usability and information risk perspective I would ask these questions to Jeff Jarvis about his experiment:

  • Printing: What are the hiccups in terms of producing and printing formatted documents? What I am thinking about are the mundane things like resumes, reports and the like. 
  • Working with Luddites: How do you work with others that are not in the cloud? Sometimes working with a colleague the most efficient way to transfer a number of documents is via USB, especially when the other party does not have Internet access (e.g. think of locked down company laptops). 
  • Handling Sensitive Data: What is the sensitivity of the data that is being on the cloud? For example, we keep private things like tax files that contain SSNs, SINs, income, etc offline. So how would one keep such things private or is it matter of just living in public? For readers that are unfamiliar with Jeff Jarvis, he takes "what's the harm approach and has written two books (click here and here) on the topic of being more open and social with one's information. But I hope he can appreciate not everyone uses his "privacy settings" :)
  • Trusting cloud providers: What due diligence does someone do before trusting a cloud provider? I suppose this is a "leading question".  Accounting associations in Canada (i.e. the CICA) and the US (AICPA) have established Service Organization Control (SOC) Reports. These reports replaced the SAS 70 Type II reports in the US and Section 5970 Reports in Canada. So do you need this type of assurance before dealing with companies? Going back to the tax return example, one solution would be to use cloud-based tax services. But how do you establish trust that this information is appropriately. One may attribute my repetitive use of the tax return info to the fact that I am an accountant. However, to be fair Gina Trapani on a previous episode of TWIG did point out an accountant should not be putting tax info on the cloud unless it was encrypted. 
  • Securing data on the lost Chromebook. If the Chromebook is lost, what are the precautionary measures the person has to take? In other words, the theory meet reality. 
  • Making local backups:  Currently, we back from offline to the cloud, but how does this work in reverse? The reason this is important is illustrated by Mat Honan's Apple iCloud account getting hacked and watching helplessly as his data got deleted
  • Working without internet access: How many times does the lack of internet access due to being in a subway or non-WiFi become an obstacle to being productive?
  • Working through cloud outages: What happens if there is a disruption at the cloud provider or underlying infrastructure? Jeff lives in NY (and judging by his tweets; he's doing okay), so he does have some experience dealing with such a scenario given the disaster brought to his area by Hurricane Sandy. 

Assuming Jeff actually does gets his Samsung Chromebook and goes through with this experiment, I will post an update to this post.