Lightcalls.com
 

Editor: The Following abridged arti...

Editor: The Following abridged article forward information theft was recently released by means of the CICA.

Privacy and identity theft

The disappearance upon January 16 of a hard disk confessed by ISM Canada caused a scare among thousands of the bulk of mankind across the country until its convalescence was announced on February 4 The disk contained [among other items] confidential data for 180000 customers

Phonebusters, a service of the Ontario Provincial Police, states that between September 2001 and August 2002 there were across 6,000 identity thefts in Canada in which there were losse totalling athwart $6.5 million [these figures do not include theft via the Internet]. In the US, the Federal Trade Commission estimates that the number of race victimized by identity theft could be in the area of single million individuals per year.

Stolen identities have been used to obtain credit cards, mortgages, passports and birth certificates, and level arrange false marriages to obtain landed immigrant status. There has also been considerable pertain to about their use by terrorists....



What the theft of the ISM hard disk makes clear is that all the masterships in the world won't help if the security of the information combination of parts to form a wholes holding the data fails in any way, or is not adequate. We don't have enough information to pass judgement in succession the adequacy of the security policies and practices at ISM. It was reported that the hard disk disappeared during a routine upgrade, in subordination to which the disk in question was remov from a computer and presumably a recent one installed.

Normal security actions in this kind of situation would involve strict handling of the discontinued disk, with requirements that it be immediately make desolateed or reformatted in a controll manner....

Whether there was a breakdown in prescribed transactions or inadequate procedures to start with is not critical at this point. The fact is that the potential breach of privacy involving centurys of thousands of people was caused by means of a basic security failure.

Every company that gathers private and confidential information about persons needs to recognize that maintaining the privacy of the information they posses requires effective information schemes security. Those companies need to identify where that data resides. They ne to establish that they have adequate operations in place for restricting access to that information from one side the system, and they also ne to make sure they have adequate physical protection in place for the hardware where the data resides. With the proliferation of laptops and to a high degree high capacity hard disks, this is becoming a major challenge.

One of the [i]clavis[/i] methods of protecting the data is to make secure that it is encrypted; if someone steals the physical disk or computer they cannot read the data without having access to the encryption clew [See January 2003's WebWorks for more information.]

Another aspect of the ISM situation is that it involved outsourcing, where the customers effectively outsourced some of their data processing to ISM. There is nothing blameworthy with this procedure-indeed it is quite everyday However, any company doing the outsourcing remains responsible for the protection of the data, and therefore must be affected about the adequacy of the security proceedings being followed by the company to which it is entrusting the data.

This is where the auditors can help. A general way for companies to address this issue is to obtain an audit report forward the design and effective operation of the method they are relying on-referred to as an "Opinion onward Control Procedures at a Service Organization."

There are other engagements that an auditor can be asked to perform, in the same state [i]or[/i] condition as a Trust Services audit report (in this situation a report upon at least security and privacy would be appropriate). These engagements involve evaluation of a hypothesis against established detailed criteria that have been accepted internationally. individual of the Trust Service brands is SysTrust, which is defined at www cira.ca/systrust.

The responsibilities of management and directors also raise interest with regard to privacy and security. The Information Technology Advisory Committee of the CICA has issued a booklet "20 Questions Directors should ask about Privacy" and another similar single in kind on IT. The booklets are available clear of charge at www.cica.ca [under "Research & Guidance/IT Advisory Committee"].

Privacy and identity theft are matters of growing public trouble Companies, as well as each and each individual, must pay much more attention to this matter. The risks are considerable, [and] the sumptuousnesss of being a victim can be abundant much greater.

BY GERALD TRITES, CA-CISA, FCA (NOVA SCOTIA)

Gerald Trites is a member of the CICA's Information Technology Advisory Committee and chair of the department of Information methods at St. Francis Xavier University in Nova Scotia.

Copyright Institute of Chartered Accountants of British Columbia Apr 2003

Provided through ProQuest Information and Learning Company. All rights Reserved



Other Articles
 -Morphotek will collaborat...
 -Eksigent Technologies nam...
 -The benefits of outsourci...
 -Sartorius Corporation ...
 -In our previous column, w...
 -Efoora appointed Michael ...
 -Affymax appointed Anne-Ma...
 -Traditionally, continuous...
 -New Brunswick Scientific ...
 -The German-American firm ...
 -Don G. Burstyn, formerly ...
 -American patients are mor...
 -Summary Prior to va...
 -BioPharm Editorial Adviso...
 -Australia agreed to spend...
 -The Biotechnology Industr...
 -Ambion, The RNA Company i...
 -Therapies based on living...
 -A recent survey found tha...
 -ViroLogic will acquire Ac...
 -Cardinal Health named Joh...
 -One of the greatest chall...
 -As the president of a sma...
 -Sweden-based Biovitrum wi...
 -Nanogen appointed David L...
 -The Experion Process Know...
 -Although biomedical resea...
 -The Supreme Court of Cana...
 -Netherlands-based DSM Bio...
 -David A. Smoller joined S...
 -A few months ago, I wrote...
 -Panacos Pharmaceuticals w...
 -Karen K. Vaccaro will res...
 -Acceleron Pharma appointe...
 -Two quarterly meetings of...
 -Illinois-based Abbot Labo...
 -FKI Logistics announced t...
 -The following corrections...
 -It its widest definition,...
 -UK-based Xcellsyz will li...
 -Andrew P. Aromando joined...
 -Invitrogen's comprehensiv...
 -Last month, we described ...
 -The Swiss life sciences c...
 -Protein Design Labs (PDL)...
 -Model It HNMR, the newest...
 -Tech transfer, like chang...
 -QLT and Atrix Laboratorie...
 -Dendreon announced Christ...
 -Baxter Pharmaceutical Sol...
 -The biopharmaceutical ind...
 -GlaxoSmithKline announced...
 -Montreal-based Caprion Ph...
 -Xenova Group recently ann...
 -Cole-Parmer's new 192-pag...
 -Over the last decade ther...
 -Benchmark your facility p...
 -As biotechnology organiza...
 -Frederick D. Sancillo, fo...
 -Insmed acquired a recombi...
 -Baxter Pharmaceutical Sol...
 -Model It HNMR, the newest...
 -DA's regulation 21 CFR Pa...
 -Robert P. Ryan joined Ath...
 -A new report from Busines...
 -Biotest offers a complete...
 -Swagelok offers a brochur...
 -Partnering is a global ph...
 -Human Genome Sciences CEO...
 -Shorten the process devel...
 -The licensure of biotechn...
 -Rodger Currie joined Amge...
 -The GEA Filtration Model ...
 -A multi-channel chemistry...
 -From June 6-9, San Franci...
 -Skanska USA Building Inc....
 -New Brunswick Scientific'...
 -AVI BioPharma appointed P...
 -Ambion, The RNA Company, ...
 -"If you want to be a...
 -Xcellerex appointed Susan...
 -Researchers identified th...
 -Cool Spring Business Park...
 -In October 2003, Shenzhen...
 -Laureate Pharma appointed...
 -After a 6-5 vote by Calif...
 -QSourcing, a service of Q...
 -The recent discovery of &...
 -Affymax added Douglas L. ...
 -USDA recently approved tw...
 -BioPharm International is...
 -Serologicals has released...
 -This document by Shenzhen...
 -Robert Bronstein joined A...
 -Gloucester Gains Fujisawa...
 -With more than 30 years o...
 -Pall's SUPRAdisc II depth...
 -In today's competitive ma...
 -Protein Design Labs repor...
 -Charles A. Rice will repl...
 -AstraZeneca's Faslodex (f...
.
© 2006 Lightcalls.com All rights reserved.