<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : Data Privacy</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx</link><description>Tags: Data Privacy</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Do Enterprises know where they store personal data? </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/18/do-enterprises-know-where-they-store-personal-data.aspx</link><pubDate>Wed, 18 Mar 2009 10:03:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88435</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/18/do-enterprises-know-where-they-store-personal-data.aspx#comments</comments><description>&lt;p&gt;Apparently most of enterprises don&amp;#39;t, at least based on this survey, called &amp;quot;&lt;a href="http://www.pwc.com/extweb/insights.nsf/docid/0E50FD887E3DC70F852574DB005DE509/$File/Safeguarding_the_new_currency.pdf"&gt;Safeguarding the Currency of Business&lt;/a&gt;&amp;quot;, where they found that &amp;quot;71 percent of organizations queried said they did not have an accurate inventory of where personal data for employees and customers is stored&amp;quot;.&lt;/p&gt;
&lt;p&gt;This has strong implications (among other things ...) from a privacy perspective, in particular from a consent and revocation management angle - as also currently highlighted in a recent HP Labs report of ours (&amp;quot;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-49.html"&gt;On the Management of Consent and Revocation in Enterprises: Setting the Context&lt;/a&gt;&amp;quot;). &lt;/p&gt;
&lt;p&gt;Hopefully we will explore how to tackle some of the related issues in the &lt;a href="http://www.encore-project.info/"&gt;UK TSB EnCoRe project&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88435" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx">Data Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Storage/default.aspx">Storage</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Personal+data/default.aspx">Personal data</category></item><item><title>Research Study: Huge Amount of Sensitive Data Still on Redundant Computer Hard Disk</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/05/research-study-huge-amount-of-sensitive-data-still-on-redundant-computer-hard-disk.aspx</link><pubDate>Wed, 05 Nov 2008 15:35:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86504</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/05/research-study-huge-amount-of-sensitive-data-still-on-redundant-computer-hard-disk.aspx#comments</comments><description>&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;
&lt;p&gt;This interesting &lt;a href="http://www.sciencedaily.com/releases/2008/11/081105083549.htm"&gt;article&lt;/a&gt;, called &amp;quot;Identity Theft Risks: Huge Amount of Sensitive Data Still on Redundant Computer Hard Disk&amp;quot; provides an overview of a research study to be published soon - warning about the risk of data left on devices to be decommissioned:&lt;/p&gt;
&lt;p&gt;&amp;quot;Ongoing research to be published in the International Journal of Liability and Scientific Enquiry suggests that there is a huge amount of sensitive data still on redundant computer hard disks. These devices are often disposed of or sold into the second-hand market by corporations, organizations, and individuals with the data intact. The report&amp;#39;s authors say that this data represents a significant level of risk for commercial sabotage, identity theft, and even political compromise, and suggest that better education is essential to reduce the risk of harm. ...&lt;/p&gt;
&lt;p&gt;The 2007 study is being made available in its entirety through the International Journal of Liability and Scientific Enquiry. The team is now completing the 2008 analysis and will announce those results shortly as well. However, the initial results for the 2008 study show that there is still a long way to go regarding the decommissioning of computer hard disk drives. The team expects that the complete 2008 study will be made available for publication by the end of the year.&amp;quot;&lt;/p&gt;
&lt;p&gt;This is an area where &amp;quot;classic&amp;quot; identity management (based on control points) shows its limits. The explicit management of IdM strategic policies, related processes and risks should be a key part of &amp;quot;identity management&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;&amp;quot;Identity Analytics&amp;quot;&lt;/a&gt; could also be of some help here, to understand the implications of policies and possible strategic decisions (given specific IT and IdM frameworks), along with exploring investment trade-offs.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;/span&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86504" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx">Data Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Gartner’s Report: Top Seven Cloud-computing Security Risks</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/04/gartner-s-report-top-seven-cloud-computing-security-risks.aspx</link><pubDate>Fri, 04 Jul 2008 12:45:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83599</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>3</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/04/gartner-s-report-top-seven-cloud-computing-security-risks.aspx#comments</comments><description>&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;I tend to agree with the outcomes of a recent Gartner’s Report on the top seven cloud-computing security risks. &lt;/font&gt;&lt;a href="http://www.networkworld.com/news/2008/070208-cloud.html?hpg1=bn"&gt;&lt;font face="Times New Roman" size="3"&gt;A related article&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt;, by Jon Brodkin, provides a nice overview and summary of the key taking points of this report:&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;span style="mso-ansi-language:EN;"&gt;&lt;font face="Times New Roman" size="3"&gt;“Cloud computing is fraught with security risks, according to analyst firm Gartner. Smart customers will ask tough questions, and consider getting a security assessment from a neutral third party before committing to a cloud vendor, Gartner says in a June report titled “&lt;/font&gt;&lt;a href="http://www.gartner.com/DisplayDocument?id=685308"&gt;&lt;font face="Times New Roman" size="3"&gt;Assessing the Security Risks of Cloud Computing&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;.”&amp;nbsp; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;Cloud computing has “unique attributes that require risk assessment in areas such as data integrity, recovery and privacy, and an evaluation of legal issues in areas such as e-discovery, regulatory compliance and auditing,” Gartner says.”&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;In particular I believe that the aspects related to “privileged user access”, “regulatory compliance” and “data location/data segregation/privacy management” are potential key issues that, if not properly addressed, can expose organizations (and users) to high risks.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83599" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx">Data Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/report/default.aspx">report</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/security+risks/default.aspx">security risks</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Cloud+computing/default.aspx">Cloud computing</category></item><item><title>Do CIOs care about Data Privacy?  </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/27/do-cios-care-about-data-privacy.aspx</link><pubDate>Thu, 26 Jun 2008 17:23:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83451</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/27/do-cios-care-about-data-privacy.aspx#comments</comments><description>&lt;font face="Times New Roman" size="3"&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;Apparently they don&amp;#39;t, &lt;/span&gt;at least based on a recent Ernst &amp;amp; Young report, whose outcomes have been summarised in &lt;a href="http://www.dofonline.co.uk/governance/audit-chiefs-still-lax-on-data-privacy6637.html"&gt;this article&lt;/a&gt; &lt;span class="small"&gt;written by Adrie van der Luijt &lt;/span&gt;:&lt;/p&gt;&amp;nbsp; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;“IT fraud and data privacy fail to sound the alarm for CIOs and internal audit chiefs, a survey shows. Sixty-five per cent internal audit chiefs do not recognise data privacy and IT fraud as a serious threat to their business.&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;A survey, released by Ernst &amp;amp; Young, found that internal audit chiefs ranked corporate breaches and data privacy regulation sixth in their top ten IT risks for the organisation, while for CIOs it barely made it onto the list at just ninth. &lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;In addition just 14 per cent of internal audit chiefs said that their staff had been trained in fraud investigation. …”&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;I would be interested in having a look at this survey, if only I could find a copy online …&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/p&gt;&lt;/font&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83451" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/CIO/default.aspx">CIO</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx">Data Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/survey/default.aspx">survey</category></item></channel></rss>