NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Policy
Slice by Program

Toothless legislation blamed for recent security breaches

By: Nestor E. Arellano, senior writer, ITWorldCanada.com(04-11-2007)

The recent controversy over stacks of documents containing personal information on Rogers Communications' customers being discovered in a downtown parking lot has once again brought the issue of client confidentiality into sharp focus.

Rogers said an employee of a company it hired to sell cable TV and high-speed Internet access, misplaced forms containing the names, addresses, phone numbers, social insurance numbers and driver's license numbers of around 300 to 400 people.

The documents were discovered by a bystander in a parking lot near Ryerson University in Toronto.

The blunder underscores inadequate security policies and practices on the part of Rogers, and alerts us to the need for stringent privacy legislation, according to Canadian observers.

"This lack of strict security measures is worrisome for consumers," according to Joe Greene, vice-president, security research, IDC Canada Inc., in Toronto.

"This breach adds another layer of mistrust," he said. "Rogers said the forms did not include credit card information, but there was enough data out there to create bogus IDs and run up some bills."

Rogers said the recovered data would have been stored and eventually destroyed by the third-party firm.

The telecom company characterized the slip as an isolated incident that is being investigated internally.

However, a security expert for a Canadian IT and business process services firm, noted a number of other companies have lost sensitive client information in the recent past.

"This is happening often because Canadian privacy laws have no teeth," according to Philippe Giroux, director for security solutions, CGI Group Inc. in Montreal.

"We may have the laws," Giroux said, "but have you heard of anyone being fined or punished?" He said there is a strong need [to impose] fines and penalties on companies that fail to protect their clients' personal information.

Giroux's concerns echo those made by other analysts and privacy advocates.

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) had rued the absence of clear requirements for companies to notify their clients of security breaches.

Last week's incident, Greene said, could give Rogers a black eye if the company is not quick to announce corrective action.

Another Toronto-based analyst agrees. The best move for Rogers, at this moment would be to investigate the incident and come out publicly with a plan to remedy the situation and prevent another breach, according to Stefan Dubowski, managing editor of Canadian telecom research at Ottawa-based Decima Reports Inc.

Some three years ago, Dubowski recalled, the BMO Financial Group faced potential disaster when two of its discarded servers containing customer data ended up on the online auction block at eBay.

However, Toronto-based BMO claimed it won back customer confidence by contacting affected customers immediately and taking steps to remedy the situation.

IDC's Greene said the Rogers incident was most probably the result of poor security procedures.

He said if a firm wanted to get rid of its data, it could either destroy the information internally or make sure a third-party hired to do the job was under close supervision. While Rogers blamed an employee of a third-party firm, Greene said the ultimate responsibility for what happens to its clients' information is with Rogers.

Giroux said many companies hire a third-party to handle their data to cut costs and free up internal personnel for business-oriented tasks.

"This could be an effective strategy, but it adds another layer of complexity to data management," he said.

For companies that choose to get outside help for data management and destruction, Giroux has the following advice:

- Develop an internal security policy and map out a comprehensive data management plan that protects both your company and your clients

- Devise an information asset classification system, differentiate the types of data in your possession, and develop appropriate means of dealing with each type

- Get appropriate departments involved in security planning. Make sure the IT security and privacy departments are aware of data that the company is handling and;

- Check out the third-party. Do a background check on any outside company that touches your data. Determine if the company passed an audit from a neutral organization or was it involved in security slip.

Related content:

Data security becoming political issue

Privacy watchdogs flag new crime of the century

Privacy experts push for breach law

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada