Showing posts with label Data Privacy and Protection. Show all posts
Showing posts with label Data Privacy and Protection. Show all posts

Thursday, September 19, 2019

Data Security and Facebook

An online report published by CNET on September 4, 2019 identified that at least 419 million records  of phone numbers tied with Facebook accounts appeared in databases online. The report was based on the revelation by TechCrunch

The exposure identified 133 million users from US alone and another 18 million and 50 million records from UK and Vietnam respectively.  The flaw as highlighted is Lack of Password protection on the server by Facebook. Records were identified with Demographic details also.

Now the big question, does this impact my privacy and security of my data online (read facebook data too)? Answer to this is pretty simple - if your demographic data and phone number is available example - sex, country and phone number (along with Facebook's Unique User ID) it is pretty much a compromise of your personal information leaving you vulnerable to certain cyber attacks. The data can also be misused to forge your identity with the modern mechanics of hacking.

This certainly is a big mess here by the team at Facebook to have left a critical server without password, the first baseline defense mechanism to check against unauthorized access. Though the very next day or so Facebook reverted with a statement that the data has been scrapped and is no more exposed to the open web. But from the time that server would have been put in place to the time the data was reported to be exposed and the steps by Facebook to scrap the data, do you think that the data would not have been compromised?  In all probabilities it would have been.

Though this is not the first time that such exposure or compromise has been reported. We keep on hearing such cases almost every other day.  The corporates accumulate our data for their business benefits and then miss out on the aspects of security to be deployed.  As per Facebook, this server probably served the purpose of searching a person on Facebook using the Phone Number of that person. My question here is why should the Phone Number search for Facebook user be activated in the first place? That itself is a breach of privacy and compromise of data that has been provided to a service provider as a security feature for secondary authentication.  

Facebook may state that they have this feature of find by phone to be controlled by the user and if user doesn't want to have this feature on, they can restrict it. Based on this aspect, I had a few discussions with a few facebook users and majority of them (close to 65%) didn't have an idea that they can control this feature of Search by Phone.  

So, the question still looms - "Should Corporates be allowed to Introduce Features that may pose Security and Privacy threats to the users?"

Saturday, September 9, 2017

Equifax Data Breach

Almost 2 years from the time we all witnessed the Experian Data Breach, we are at the stage where we all are informed about the Equifax Data Breach. Now, with almost half of the US Consumers are probably hit by this breach, Equifax made a statement that not all information was compromised. Well, if Name, SSN, Driving License details (though not in all cases) are compromised and the hackers have those details, what is Equifax trying to convey? More so, with where Equifax stands, does it have any way to explain the attack that was carried out over 2 months (May - June 2017) and Equifax could only uncover it somewhere in July? Doesn't this highlight the level of security measures or the loopholes that exist in the overall system configurations and more so in monitoring the traffic as well as transactions? Didn't Equifax CISO review the Experian Hack and the ways he could have directed the team to act swiftly to ensure that they don't fall in the similar trap? Sad, but true, they indeed fell in that sinkhole that was waiting for them and no one else can be blamed but for their Not So Productive approach.
So, where do we go from here? Should we accept the registration with Equifax's "Trusted ID Premier" service for Next Year "Free"? Would that be enough for them to prove their commitment to protect consumer from any sort of fraud? or wait, isn't this in itself a cony capitalism step by Equifax to exploit the situation from there to charge us $19.95 a months there after until we cancel the service? It is important to note that the hackers wouldn't use that information on immediate basis for they would also know that just like "Experian's Protect My ID" service for free, Equifax may also float that service free (which they indeed did). In most probability, the hackers may sell the database at a premium to the fraudsters and the, the fraudsters at a convenient time exploit the vulnerable. Probably the Theft Protection cover being offered free for one year would be blown away by then. More so, I would not recommend you to sign for Equifax's free service as if you do that you would surrender your right to join a Class Action Suite should that happen. 
Consider the specific situation where the frauds that would happen few months down the line during the tax filing period when the information hacked could actually be used for impersonation and tax filing "AS". That is the type of fraud that an ID Protection service would not be able to prevent and the consumer would be just left in a situation running from pillar to post to get the situation corrected. 

The impact of this breach on consumers can only be estimated at this time. There is no confirmed way to identify the long term impact on any of the consumer with compromised identity; until the compromise makes a landfall on that consumer's account.

This however is not the first breach at Equifax or a group company, thanks to the horses blinds that they have put up assuming that the Data Security is prime for them. If we are horrified with the news that this data breach lasted two months and they uncovered this only after 2 months and waited another 4 to 6 weeks to make the disclosure, please search about the TALX breach that was reported to have started back in April 2016 and continued for almost a year. Quite a number of W2 data was compromised then too. Equifax didn't learn a lesson from that either.

Now, that's a sad story from the Organization that is tasked to store our data, but is not sincere enough to really secure that data. Certainly, the business of the Organization is to compile and store the data to be used for marketing and cross selling purpose. The accessibility of data needs to be maintained by them to be able to make more money than ever. But, shouldn't the federal and state legislators ensure that the organizations or kind are regulated and made responsible for such breach? Shouldn't there be a commitment by the US legislatures to have a regulations in the lines of GDPR and ensure that the requirement to disclose have a stringent deadline (72 hrs in case of GDPR). What most of the US states have is "reasonable time period" or at the max 30 to 90 days. Gracious God that's a lot of time for the hackers to misuse the data leaving hardly any space for the consumer to step up and protect their interest.

From a consumer point of view what can be done? Most of the consumers would think the same and am sure most of them would sign in to the Trusted ID Premier for one year thinking that is the best step forward. But, as mentioned above that would just prove to be another marketing stunt for Equifax rather than a permanent fix. After 1 year (or the time period they offer for...may be 2 years), even if half of who sign in for the service sign out, Equifax would make millions per month charging them the fee. 

Am sure once the news spreads further, most of the consumers would start wondering or what should be done now? I would suggest to visit https://www.consumer.ftc.gov/blog/2017/09/equifax-data-breach-what-do#comment-256824 and consider the following steps that are detailed there - 
  1. Place a Credit Freeze with your Bankers. This will make it hard for the hackers to act as you, but they can still misuse your credit cards
  2. Limit and Monitor your Credit Card statement
  3. Monitor your Credit Scores and reports on a regular basis. There are a few that may provide free service and updates; Evaluate them and make a decision. Alternatively, obtain your 3 bureau credit report from annualcreditreport.com (limited once a year though)
  4. Consider placing a Fraud Alert on your files if you chose not to go for Credit Freeze. This would indicate to the institutions to verify that it indeed is you who is requesting for account opening or for credit services
  5. Ensure that you file your taxes promptly as soon as you get your W2 in hand. You shouldn't delay filing your returns as that may be a costly delay should a fraudster file them as you. And ensure that this step is repeated every year as you never know when your information may be misused.
-----------------------
P.S. - Would Transunion pick a cue from the Experian and Equifax Hacks to ensure that they are up-to the mark with the measures to Secure our Data? 

Tuesday, October 13, 2015

Experian Hack

It has been almost a month that Experian reported a breach in which 15 million T-mobile customer accounts were said to be compromised. The information included names, addresses, email ids, social security numbers and few more details of the T-mobile customers in USA. Though Experian was quick to react before the information could have been misused to that effect, yet it was a scary news for those 15 million individuals and others who are T-mbile customers or those who have accounts with any of the service providers who use Experian as the Credit verification agency.  

For those who think they are not impacted, they need to rethink about not getting worried because Experian is one Credit Reporting Agency and if its systems can be compromised, then the other Credit Agencies  too can be. What does that mean to common man? Well, take control of your information that is stored, processed and transmitted by the Credit Reporting Agencies (TransUnion & Equifax included). 

As a reaction to the hack, Experian announced two year free Identity Theft protection service "ProtectMYID" for affected T-mobile customers.  Now, the big question that arises here is - "Why is it a reactive announcement and why is it that they otherwise are charging to monitor misuse of our information that they store/process/transmit?" Isn't it just logical to ensure that they or the service providers from whom we obtain the service should actually be providing this service as a complimentary service? Also, why should Experian provide us this service free only for 2 years? Is there a logical conclusion by them that the hackers will not misuse the data after two years?  Well, I guess they are just trying to shrug off their responsibility to protect our information available on their systems.  First of all they had their systems configured in a manner that got compromised and then they are offering something to show off to the world that they care.  Not something that I would buy with any sort of logic, though I would be the first person to avail immediate patch work offer from them to ensure data regarding myself and my family is not misused impacting my Credit Ratings.

So what does that mean for the Federal Regulators like FDIC should first look at amending the Fair Credit Reporting Act (FCRA) or State Regulations like Consumer Credit Reporting Agencies Act (as referred in California) need to be amended to ensure that the Credit Reporting Agencies are legally bound to secure Consumer Information.  At the same time, the Credit Rating Agencies must consider reviewing their current Security Architectures for access provisions and data flows to identify the possible loopholes that may leave enough space for data compromise like Experian. A composite review is the mandate of time and certainly the Audit reports by independent Auditors must be submitted to the regulators.  This needs to be a time bound activity to ensure that the Credit Reporting Agencies take required remedial measures to ensure that they step up the security provisions and ensure that such future breaches are thwarted right at the attempt level itself rather than letting it to be a news post breach.  It certainly is an important step to be proactive in securing the data and information rather than taking reactive measures that sometimes may result in an organization getting booted from business.

The Experian Breach should not be looked at just limited to T-mobile or Experian for that matter, the industry should take it as an alarm for the future attacks that hackers may be planning to gain more information and if they could get through the doors of Experian, they may get through the doors of other such agencies.  It is important that proactive measures and steps are taken to secure Consumer Data / Information for which these organizations are custodians, not the owners.  
____________________________________
Disclaimer: The views expressed above are solely of the Author and are not endorsed by any organization, individual or industry body for that matter.

Tuesday, September 22, 2015

Indian National Encryption Policy

It is interesting to note that the Government of India's Department of Engineering and Information Technology has issued National Encryption Policy for public comment.  And today the first addendum for the same has been issued for the people to refer to.  However, when it comes to the overall policy, it has been left out pretty lopsided. When I say Lopsided, I mean from the subjectiveness & perspective dependence that has been maintained throughout the Policy.

I would not get into those micro level details where the industry's who's who is making some or other comment on the types of services that would be covered and the type of data user as well as business would need to be retained for 90 days.  That's a very low level speculative inference that would differ from person to person and from perspective to perspective. My initial view was same and I also took to twitter for that :)

What my assessment of the Policy is the lacuna that is maintained by not aligning it to the industry standards and not basing it on the prevailing trends.  For that matter, one of the key aspect that I find missing is the way the Committee should have taken cognizance of the "Heart Bleed" as well as "Poodle" vulnerabilities that led to the demise of SSL as an Encryption Standard. It should have been noted that the PCI-Council has declared that SSL is no more a supported standard for encryption and that TLS 1.2 is the deficto standard until next such notification. Indian National Encryption Policy has this void in it to align itself with the latest, thought he vision and mission state so.  The policy goes anywhere else than stay around the vision and mission.

I am surprised to actually read the reference of SSL in the Policy at the time the world is moving to TLS 1.2 and the bigwigs of industry have already moved to the other side of adopting TLS 1.2.  Moreover, TLS 1.3 is already being eyed as it is slated for release by next year. We have already seen the advent of SHA3 earlier this year and the Policy still sticks around to 3DES and RC4. It needs to be noted that RC4 already has been vulnerable to attacks and can be actually be used to get some hand on the information encrypted using the encryption standard (Read - Article on Security Week - Dated March 2015). Moving on to the 3DES, it is not at all considered strong enough to protect the data and when the Target Breach happened, it was identified that 3DES was deployed and there was a lot of scrutiny on that move as to when AES was available why 3DES was used?

So, when the industry is basing their opinion on the micro issues of what to store how to store, where to store and talking about the data security & integrity from a different angle, my real concern is the coverage of obsolete standards and technologies as part of the overall Policy and basing the policy on those obsolete standards and technologies.  I am not sure why the Trade Pundit's or the bloggers in social media have not raised this issue till now.

Certainly, in its current format the Policy itself would be obsolete in not more than 6 months and that would call for next round.  But would DeitY listen to the Gen Next or are we still going to hear from the "Experienced" folks who missed to evaluate the latest and greatest developments??

Would you hear the voice of Young India or would this also go the TRAI way???

Sunday, November 2, 2014

Data Privacy Acts - Where the World needs to Converge

Data Privacy in today's world has crossed over from a requirement dependent on one agency or organization to be the global phenomenon.  Today the data traverses across the countries as well as continents at the speed unimaginable in past. In a flash of second, the data originating from EU may be transferred to China and may be who knows to another country from where a Hacker might be sitting and listening to the data traffic.

Let's take an example of some other countries say India and Brazil, both being third countries and both engaged in Off-shoring of services.  In this context we will talk about the  scenario where an Indian IT company providing services to a multinational client located in US, Australia and EU would have its service locations in India, US, Brazil and Germany.

In the scenario highlighted above, all the geographies / countries involved do have one or other kind of Data Privacy Law, let's examine them -

  1. European Union - EU Data Privacy Directive - EC/95/46
  2. United States - State Data Privacy Laws (enacted in 48 States), Country level Data Privacy Law pending with Senate
  3. Australia - Privacy Act 1988 (National Security Legislation Amendment Act (No. 1) 2014)
  4. Brazil - No definitive law covering Data Privacy, though Privacy requirements have been dealt with under various different legislation
  5. India - Telegraph Act 1885 amended in 2004, Indian IT Act 2000 (Amendment Act 2008) and few others cover a part of Privacy, but no comprehensive law exists
  6. Germany -  Bundesdatenschutzgesetz (BDSG), The German Federal Data Protection Act in line with EU Data Privacy Directive (Germany for that matter is part of EU and hence the European Data Privacy Directive is the base)
Now if we look at the above list, we will find that there is no commonality among the Privacy Laws across the countries / geographies except for the German Privacy Laws and the EU Data Privacy Directive.  

Coming back to our scenario, there would be no issues of data transfer between any EU nation and Germany, But with the data traversing across multiple borders, the Data Security Officer would have a nightmare to meet the compliance requirements that would include - 
  1. Safe Harbor - to ensure compliance between US State Data Privacy Laws as well as EU Data Privacy Directive
  2. Standard Contractual Clauses (SCCs)- to ensure compliance requirements are addressed when transferring data from EU Nations to India, Brazil and Australia.  It must be noted that SCCs would need to be executed for each EU nation and that would mean multiple SCCs to be executed.
Such scenarios are very much prevalent today and these just add to the complexities.  The organizations though have the options to file for Binding Corporate Rules or BCRs providing them the overall cover to transfer data, but it serves to be an expensive step from Business Perspective and its easier to sign multiple SCCs. All this ends up in complexities to be handled by the Data Security Officers or the Privacy Officers. So, what is the way to handle such complex situation and to avoid complexities to be handled by the Data Security Officers or the Privacy Officers?

If we take a closer look at the current prevailing situation, we will find that it is the disparity in the Privacy and Data Security Laws across the countries / geographies.  Though the Safe Harbor sort of options are available, but then that is also a self certification / attestation case.  

I personally would prefer a better option like the one between EU nations and Switzerland, Guernsey, Isle of Man, Israel etc. In such cases, we see that the EU Commission has identified the adequacy of Data Privacy Laws and adequate Protection of Personal Information / Data. In this scenario, the sole reason of the mutual trust is for the similarity of the Privacy and Data Protection Directives.

Now, if a small group of nations can have the required similarity in the Data Privacy and Protection requirements, why can't the rest of the world follow the suite. With the world converging for the global trade there is a higher degree of requirement for the bilateral trust for the Privacy and Protection of Data and for that common agenda needs to be driven. Organizations like WTO, OECD and other similar organizations may lead this effort to bring the governments together and develop Common Criteria for Data Privacy and Protection.  With the need of the time, the World needs to converge at these Common Criteria and the respective Governments must issue directives to regulate Protection of Personal Data / Information as per these Common Criteria.

Tuesday, April 22, 2014

Need to Security Private Information - Requirement in India

Unique Identification Authority of India (UIDAI) data center in Bangalore is reported to have got a cover of 65 star guards from multi-skilled security agency, the Central Industrial Security Force (CISF) - Your identity is guarded by 65 armed men (article on times of India).

It indeed is a commendable step by the authorities, but my question here is - Is this measure enough to secure the Identity and avert the threat from identity theft? Actually Speaking NO and the reasons that attribute to the answer NO are -
  1. The personal information of an average Indian is scattered across the Government Offices, Public and Private Banks and other Financial Institutions to a large extent.  More scary portion is the availability of this information on papers across the offices
  2. There is no defined mechanism to destroy the paper work by the various organizations and agencies.  Many a times some or other people from various organizations sell of these as waste papers to the scrap dealers.  There have been various incidents in past where papers with critical and sensitive information have been located with the road side vendors (bhel puri and other chat senders)
  3. There is no defined guideline by the Government of India on how to use / dispose / destroy the information whether in paper or on computers
  4. There are no set standards in India with respect to destruction or recycling of magnetic / optical media that may contain sensitive / private / identity information.  Such media may be Hard-Drives, Pen-Drives, Backup Tapes, CDs, DVDs, SD Cards etc among others
  5. Nasscom has also not worked to this effect to advice with any standard guidelines to be utilized to this effect
Saying all this, we should not actually be cheering the news as published as it is the least of the measures that is required at deployment.  Another aspect to look at is - Has Government also provisioned a DR site for the UIDAI Data Center? Is that location also guarded with similar set of Security Personnel?  Unless we get that information, I guess this news is just a hogwash,

If you feel I am trying to belittle Government's efforts, then well I am not.  But my effort is to sensitize that there are additional steps required by the Government to ensure that the information related to the Identity of Indians as well as tourists / visitors to India is treated as sensitive and private.  Adequate measures as detailed below need to be put in place to ensure that such information is treated in fair and just manner - 
  1. Enact a Data Privacy Law - Government needs to take immediate measures to ensure that the Data Privacy Law is enacted and enforced to set the expectations on dealing with Private and Sensitive Data.  The Information that needs to be treated as private and sensitive should include - Aadhar Number (as part of the UIDAI effort), PAN Card numbers (from Income Tax Authorities), Voter ID (from election commission), Ration Card, Passports and any other similar set of documents and information that can help establish the identity of any individual
  2. Define Data Handling Guidelines - As part of the Data Privacy Law, Government must define the treatment of information classified as Private and Personal in a manner cognizant to safeguard the Identity of person holding it
  3. Define Data Destruction Guidelines - As part of the Data Privacy Law, Government must also define how the data no more needed is to be destroyed.  For the data on paper and optical media for that matter must be destroyed by using shredders. The data on magnetic media for that matter must be destroyed by using programs that would over-write the data multiple times using different algorithms and thus rendering data as unreadable
  4. Define Consent Requirement - Often this is one of the most overlooked case where the private and personal information of any individual is circulated / shared for commercial benefits.  There are cases where the Customer Relationship Officers or the Marketing Staff carries over the contact and similar other information to the next organization without consent of the Data Owners.  It needs to be noted that the receiving Organizations / Agencies are Data Custodians and not Data Owners, meaning they can use data for their internal processing purpose only.  For sharing or using data for any other reason than intended reason should not be permitted without consent from the Data Owners (Data Owner is the person about whom the information is)
  5. Define Agreement Forms - Government must ensure that the Agreement forms used for the purpose of providing services are defined only for those services for which the Information is obtained.  Such Agreements must not any Clause or Fine Prints like "Organization / Agency may use this information for any of the required processing as may be deemed required by the organization / agency.
These are the basic steps to be taken to ensure Data Privacy & Protection.  These needs to be enforced along with the Indian IT Security Act 2008 Amendment Act to ensure that adequate Information Security Risks are addressed including the identity theft and information compromise.....



Sunday, May 12, 2013

$45 Million Heist with Prepaid Card Duplication: Lessons Learned

In my previous post "$45 Million Heist with Prepaid Card Duplication", I had highlighted the questions that creep up in our mind as general readers or followers of the news.  Those questions are basically something that need to be dealt with or answered for a meaningful conclusion of the investigation.

However, from the Risk Management perspective and the ongoing compliance enforcement, there are few critical lessons learned if the GRC world is watching this incident from that perspective.  

It was really amazing to learn the way these scammers came along together and indulged in such a widespread scam to cover 27 countries as reported.  Here is the first lesson learned - 
  • Organize your move and collateral to ensure that Risks are covered at all times. This can be achieved only when you have a sound Risk Management Framework to document All the possible Risks and monitor them on an ongoing basis
Banking organizations across the 27 countries failed to identify the large chunk of withdrawals from their ATMs. Here is the second lesson learned - 
  • Banks need to put a governing policy to monitor the cash withdrawals from their ATMs. They need to closely review the Cash withdrawal pattern from various ATMs they own. This would help raise the red flag faster
Payment Processors failed to maintain their security measures in-line with those required for Banking Organizations. Here is the third lesson learned - 
  • Payment Processors must ensure that they deploy layered security to ensure that the Databases are always hosted in the most secure zone and preferably be protected by host based IPS systems that would raise alarms on detecting any anomalous behavior
Card Networks failed to raise the alarm too and rather delisted a given payment processor that was breached.  This is certainly an act of washing out once own hands of the responsibility. Fourth lesson learned here - 
  • Card Networks need to ensure that they control the limits once defined. Meaning, once a Payment Processor or Bank has defined transaction limit on a given Pre-Paid Card, it needs to be populated to the Card Network. This should be a One Time one way update.  Generally a Pre-Paid Card user is not worried with the limits set on the card as they use cards for limited set of transactions only.  So if there is a change in the Transaction limit from the Payment Processor or Bank, the Card Network should over-write it....(this may seem to be insensible to many, but would help avoid such heists in future)
The entire Banking System across the reported 27 Countries failed to detect the heist and report it. here is the Fifth Lesson learned - 
  • The Banking system across world would need to develop a Governance mechanism to share daily charge back reports and highlight the cases that they seem are alarming. This would help the target banks to react faster than not and help avoid such mass scale heists
Few other lessons learned - 
  1. Payment processors and Banks to ensure that they have transaction monitoring systems deployed specifically for the Pre-Paid Cards as with the change in the Guard on Debit and Credit Cards, Scammers would focus on less secure cards
  2. Payment processors and Banks to develop systems to ensure that Risk Management Function is made responsible to review the anomalous behavior as noted in the transaction monitoring systems and as received in the charge back reports
  3. Information Security Mechanisms are beefed up across all the Payment Processors and Across the Payment Networks to help thwart such attempts in future
  4. Though Pre-Paid Cards are not related to any person in particular and hence they are not treated at par with the other Bank Cards, it it critical that Data Protection Regulations do cover these Cards. PCI Council too must ensure that they have comprehensive steps taken to this effect and bring the Pre-Paid Cards under the Scanner of PCI-DSS. They should also ensure that the Applications used for the Purpose are brought under the Scanner of PA-DSS.
------------------------------------------------------------------------------------------------------------

Friday, September 7, 2012

BYOD Program & Controls Requirement - II

As I wrote the previous Post - BYOD Program & Controls Requirement I received the comment on WFH, but I am certainly not covering that in this article, as that is a separate topic of discussion. What is more interesting that broke out as a discussion point with a colleague over a cup of coffee.  The discussion actually presented a counter argument to the Jump Server configuration.  

While in the discussion, I was very much inclined to and well still am that an organization as the first step to BYOD program should define the set of machines that they would allow.  It is pretty much important for the organization to define whether they are going to allow.  The Deep Dive on the topic reveals that the selection of devices would prompt additional thought process or should I say depending on the Support Strategy for the BYOD program the organization needs to define what devices would be allowed.

The various strategies would revolve around user experience v/s technological deployments. If an organization would like to restrict user experience and go with technological deployments that would ensure Data Security and related controls, the organization would then need to restrict the BYOD to Laptops and Desktops (may be or when its WFH). In this case the controls would be around the set of controls that have already been discussed in the previous post as mentioned above.

In case the organization would select User Experience then the organization would need to ensure that they provide support to any device and enhance the Mobility aspect of the user.  This decision however needs to be based on the following decisions - 
  1. What applications would be supported for BYOD and what level of modifications / application changes would need to be carried out?
  2. What level of Security would be needed to extend the support to the devices?
  3. What would be the application support, would it be Browser based only or Client based with a part of the program sits on the client side
  4. Would VPN security be extended to these Devices that would be supported?
There are many more questions that need to be answered for a Successful BYOD program. The Organization would additionally need to check if One Device One Number sort of Program be adopted or not. If the organization would decide to implement this program for increased mobility they need to ensure the Soft Phone Support. 

The BYOD Program as it seems is not actually an easy decision to take as the organization would require to answer many other questions and Specifically that would help them ensure mitigating Risks and meeting Compliance Requirements in Operationally Effective and Efficient Manner




Monday, May 30, 2011

Data Privacy and Protection in India - Letter to Mr. Salman Khursheed

Below was the Letter that I had written to the Law Minister when he was not in-charge and he had asked me to provide the details so that he could have spoken to the then Law Minister Mr. Kapil Sibbal.  Interestingly, after the conversation, I had another round of telecon with the officials and then I sent the mail.  The Govt after a couple days had declared that India is Going in For Data Privacy and Protection regime....

May be coincidental!!! but the mail was written on May 29, 2011 and Govt declaration came in June 1st week :) 


Posted from Drafts on November 25, 2011
______________________________________________________________

Dear Mr. Salman Khursheed,

Please refer to our discussion on the Sets of "We the People" show of NDTV 24/7.  Highlight of the Discussion post the show was the requirement of Data privacy and Protection in India, and you had told me to write a mail to you and you would take it forward with Mr. Sibal, our Law Minister.  However, what I would like to Highlight here is the requirement of Data Privacy and Protection also involves following Ministries -
  1. Information and Broadcasting Ministry
  2. Ministry of IT and Telecom
  3. Human Resource Ministry
  4. Ministry of External Affairs
Well if we actually look at the requirement, the Data Protection is need of the Hour for India.  It would not just help India in being one of the Nations who have strong support for Securing the personal interest of its Law Abiding Citizens by protecting their Personal as well as Sensitive Information.

I had written Post on my blog with respect to this and same is as below.  I hope it would help understand the current lacuna in the Indian IT Act 2000 (amendment Act 2008) and the need to go for a Data privacy and Protection Act -

It is quite interesting to note that when it comes to the Cyber Laws, Indian IT Act 2000 (amended by Information Technology Amendment Bill 2006, passed in Lok Sabha on Dec 22 and in Rajya Sabha on Dec 23 2008 and reinstated at Indian IT Act 2008) is one of the best Cyber Laws in the world.  Incidentally,  India was just the 12th nation when the act was initially put to effect in the year 2000.  However, the Act fails to provide any point with regards to the Privacy of Personal Information.  Today when Identity Theft is one of the prime concerns in the Digital Space, India is lacking big time on the Ensuring the Integrity and Protection of Information as stored, processed and transmitted using information technology and the allied systems.

An Analysis of the Personal Data Protection Law in India by CRID - University of Namur (Submitted to Commission of the European Communities, Directorate General Justice, Freedom and Security) identified the specific lacunae as present in this area.

CRID evaluated Indian Regulatory Scenario in its 71 pager report covering the aspects of  -
  •    Federal Structure
  •    Constitution of India
  •    Judicial System
  •    Administrative Tribunals System
  •    Competence to Legislate on Data Protection
  •    Influence of International Norms
  •    General Legal Protection of Human Rights
  •    Data Protection Legislation
  •    The Right to Privacy in India
  •    Statutory Safeguards of Privacy and Data Protection Interest Outside Data Protection Legislation
  •    The Information Technology Act, 2000
  •    The Amendments to the IT Act 2000
The evaluation of Indian Regulatory / Legal environment around Privacy and / or Protection of Data has been referenced to the Article 25 of Directive 95/46/EC that regulates the transfer of personal data from Member States of the European Union (EU) to "third countries" – i.e., countries outside the EU (and EEA). According to Art. 25(1), transfer of personal data "may take place only if the third country in question ensures an adequate level of protection".

Salient Observations by CRID are -
  • Section 3.1.2.1 on page 30 states - No Such Concept as "Personal Data"
  • Para 2 of the section further elaborates - "The IT Act doesn't provide for any definition of personal data"
  • Section 3.1.4.2 b) states - The research found no express provision in the IT Act requiring data to be kept accurate and up-to-date
  • Para below that (again referred as 3.1.4.2) states - The research haven't found any provision in the IT Act requiring processed and transferred data to be adequate, relevant and not excessive.
  • Section 3.1.4.3 establishes under the Head Principle of Transparency, the Information Technology Act, 2000 has no equivalent provision to the EU Privacy Directive's Articles 10 and 11
  • Section 3.1.4.4 establishes that no specific provision requires particular security requirements that are appropriate to the risks presented by the processing of personal data. Moreover, the IT Act lacks a provision ensuring that personal data should only be processed on the instructions from the controller
  • Section 3.1.4.5 establishes that the IT Act does not provide for any of the principles related to access, rectification and opposition by individual data subjects.
  • Section 3.1.4.6.The principle of Restriction on Onward Transfers establishes that  The IT Act does not provide for such a principle
Through and through, the report highlights the areas where India Lacks in addressing Privacy and / or protection of Personal Data.  The report conclude "Given the absence of any general data protection Act, no Data Protection Authority has been established in India."

The points mentioned above certainly make a point that thought our Cyber Law is one of the Best, but it still is not the Best.  It needs to address the requirements on the lines of European Data Privacy Directive.  Moreover, the one place where India lacks is the general and overall lack of Understanding of its Cyber Laws by the Law Enforcement as well as Justice & Care Departments. A defined action plan needs to be implemented by the Law Makers to ensure that the intent and coverage of the Laws as defined and passed by the apex council are precipitated to the required levels in a manner to increase its Effectiveness and the Efficiency.

अभिनंदनीय
मयंक त्रिवेदी
लक्ष्यहीन जीवन दीशाविहीन एवं व्यर्थ है

Data Privacy and Protection -India's Need and Corporate Reaction

I have already written earlier on this issue -
Blackberry Encryption and Threat to National Security
Information Security - What India Needs
VOIP and Risk of Data Privacy and Protection
Issue of Data Protection & Privacy in India

However, this time I have come back to write on this issue again post my interaction that I recently had with one of the Honorable Central Minister, who happened to point me towards the Indian IT Act 2000 & Indian IT Act Amendment 2008.  When I highlighted the gaps in the issue, he directed me to write to him in this respect and in turn he would take it up with the Respective Minister to look into the issue.  I was a bit lazy and a bit too tide up with the office routine and the actionable took a back seat from my end.

But a recent incident where I was interacting with few Information Security Managers / Officers of various organizations, I was shocked to note the remarks "All Data and Information in organization is Secured and Privacy and Protection is of Prime importance for all the Data and Information."  What Shocked me there was the Statement "ALL DATA"  I was forced to think -
  1. How would ALL DATA and Information" be subject to Privacy and Protection?
  2. Why would one try to protect Data and Information that is inconsequential?
  3. What cost was the CISO trying to look at when making an statement about ALL Data?
Interesting conversation, as the discussion proceeded further on Private / Personal Data v/s Publicly available Data and replies were like, "Need to protect all data at any cost".  I was curious, so I raised the question on Access Control with them as well as Laptop Encryption trying to get a pointer on their thinking.  Replies were like, we have strong Authentication Mechanism where each user has to have minimum 8 characters complex password and needs to change it every 42 days. "Every 42 Days?? Ain't that Windows Default Setting??" I was expecting may be Two Factor or One Time password types, but plain password control, now that was somewhat shocking..... And on Laptop encryption, the reply was more shocking - "All our Executives are made aware of the Data and Information Security policy and they have to sign NDA, so we don't think we need to invest in that type of Control". Wow, what confidence and what trust on the Mobile Work Force.  Interesting Conversation!!!!.

The Discussion led further to the base on which the controls are deployed and the answer was another interesting answer - "We have strict access authorization policy to have access to Information that is classified as per the organization's Information Classification policy." Interesting, as there was no mentioning of Data Classification as when probed on that side, the answer was "We Protect Information, Data Classification is not as important as Information Classification".  I was like "EXCUSE ME!!!! Data when processed provides you relevant information to make right decisions or pointers to right decision", but I maintained a tight lipped approach as I was trying to know the thought process that represents the Industry reaction.....

Though this was a closed group discussion, I was forced to think of the state of affairs that prevails in India with respect to Data Privacy and Protection.  The Country needs it very Badly as the Mobile Phone User Community is fed up of Pesky Calls, for the Mobile Companies or their agents somewhere sell Data to get that extra money. reminds me of one such case, when recently my bank people called me up for upgrade to my Credit Card and I said ok, within few hrs I got a call from another MNC Bank whom I never interacted asking me if I have any interest in another Credit Card that would be Free for Life Time and it would also help me avail a Loan of another 2 million Rupees without much documentation.  Shocking ain't it as the executive calling me up knew my Name, the organization I work with and few of my other Demographic Details that certainly are Classified as "Private Data".

So What am I highlighting and What should we be targeting?  I know the base and cases I highlighted have become too long that you might be loosing interest, But I thought they were required.  What India needs is a Strong Drive from the Information Governance perspective.  It is required for the Industry and Government both to make a unified move to get the Data Privacy and Protection Framework in Place along with a National Data Privacy and Protection Policy.  Just like the Mobile Phone "National Do Not Disturb Database" there should be a National level database to register / de-register for Opt-in or Opt out for various Promotional Mails and calls.

If Industry can make use of the CIBIL sort of facility to its benefit, then Why Not put something that protects the Interest of the Customers??  Government for that matter needs to take a Proactive step forward and initiate this with no further delay

Tuesday, December 7, 2010

VoIP and the Risk of Data Privacy and Protection

Just finished reading "Encrypted Phone Calls & Skype Security" by a fellow blogger and a technocrat Friend Mukesh Kesharwani. Indeed pretty interesting and well covered stuff no doubts and that is what we expect from Mukesh.

However, when I look in from my Risk and Compliance Corner, the concern of using Skype in Corporate Network still looms large and Rings the Bell in my head... Can't do away with that as for me the Data Privacy and Protection (be it in any form) is primer.

Some of you might have read my previous post on this when I had written about the Blackberry Security and Issue of National Security.  I would reiterate those concerns in the case of Skype Usage also.  For most of the cases, if Skype is used for Corporate purpose, the corporates would try to cut the cost and try and use the retail version of Skype that's available to one and all with access to Internet.  In this case, I am sure that as and when the Security Agencies get access to the Data exchanged on Skype, though the sorts of agreement it now has with Research in Motion (the Company that owns the Blackberry Brand), there would be a High Risk to the Confidential and Business Critical Data that would be shared using Skype and mind it that may include files shared or voice communication.  Certainly if a company is using Skype, it would also use the VOIP facility to ensure that the Cost of Communication stays low.  

I would still suggest to take a step at a time in this arena to ensure that the Corporate Risk related to Data Privacy and Protection does not get High "Particularly when the Country DOES NOT have a Data Protection and Data Privacy Regime".  When I highlighted that risk in my previous blog, certainly there were few high profile cases of Data leak, but now we have the example of Telephone Tapes in which the conversations were taped in by an enforcement agency authorities to investigate some case, but the tapes went to Public Domain and now to the Apex Court.  

I still would be not too happy to hear from the Corporates Adopting Public Domain technologies for handling Corporate Affairs and Exchange Business Critical and/or Business Sensitive information over such channels.  Unless, the Govt comes around with a Data Privacy and Protection Regulation to ensure that the information stays where it is supposed to be and is not leaked out in a domain where it may be utilized in a fashion to cause material damage to the Corporate Affairs or so......

The Risk Remains High till such time....