Benjamin Wright - Posts

 

View:
 
0 0 votes

Not legal advice

I am honored to be referenced in this article! My quotes and references in this article pretty much get the ideas across, although I provide more details and nuances on these ideas in my SANS courses.

My ideas in this article are offered for general public discussion, not legal advice for any particular situation. If you need legal advice, you should consult your own lawyer.

in reference to: Being Unreasonable with Software Vendors — ...
0 0 votes

Tax Audit | Investigation

This "Age of Information" will drown us in all manner of audits and investigations. As the Information Age advances deeper into the 21st Century, ever-enlarging oceans of little records memorialize our every personal, business and political action. The existence of these records will forever entice the "authorities" to demand them for their ever-more-granular audits. It is only natural that state tax authorities want to gather data about and ...

0 0 votes

Data security training

Information security is more than a technical issue. It is more than a management issue. It is also a public relations issue. Senior infosec professionals need training on how to inform interested parties (employees, government, customers, news media, even unwelcome intruders) about IT security policies and incidents.

in reference to:

"The course emphasizes the role of public communications"
- http://blogs.sans. ...
0 0 votes

HR Investigations Law

Internal investigations are becoming more tricky. Many investigations now involve voluminous computer records such as e-mail and text messages, which can be difficult to manage and interpret. At the same time, the law pays growing respect to the privacy of individuals. Investigators must be trained and thoughtful. http://www.facebook.com/Benjamin.Wright.SANS.Legal.Instructor

in reference to:

"person who conducts the investigation should be ...
0 0 votes

Automated Video Recording | Surveillance Legislation

As robot systems become more common in society, law must address what records they can make of humans. Computer records can memorialize much information about a person: video, audio, smells and more. Contract law can help to regulate their digital recordings. http://hack-igations.blogspot.com/2008/01/robot-surveillance-contracts.html

in reference to:

"protect Americans from secret video surveillance, by clarifying that the government has to ...
0 0 votes

Online Legal Declarations

A well-crafted banner for a video conference or virtual meeting can affect the legal status of the event. This video demonstrates a banner for cloaking a meeting with attorney-client privilege status and attorney work product status, where the attorney joins by webcam.

in reference to: http://www.youtube.com/watch?v=9yU-K2BRaCM (view on Google Sidewiki)
0 0 votes

Legal Notices | Interpretation

Information technology provides new methods to communicate legal intent and understanding. In lawsuit e-discovery, for instance, well-placed digital notes (tags) on records can influence the interpretation of the records by a court or other authority.

The insertion of explanatory notes was possible for traditional paper discovery, but the insertion of notes can be more quick and efficient when the records are electronic.
in reference to:
"tags ...
0 0 votes

Corporate Security Policy

ChoicePoint's decision in 2005 to withdraw from a profitable line of business is seen today as a textbook example of a company reacting strategically to the changing law of data security. The law grows more dangerous. Many enterprises have yet to learn the ChoicePoint lesson. http://legal-beagle.typepad.com/security/2010/03/risk-assessment.html

in reference to:

"said it would no longer sell data to private investigators, debt collectors, or ...
0 0 votes

Enterprise legal liability

See discussion in the leading book "Information Security: Managing the Legal Risk," by Nick Gifford. Gifford cites this story of Christopher Maxwell’s botnet attack on Northwest Hospital to analyze how legal liability for a botnet attack (a relatively new phenomenon in society) might apply. http://www.cch.com.au/au/onlinestore/ProductDetails.aspx?ProductID=4135

in reference to:

"effort to make money by controlling network of robot computers"
- ...
0 0 votes

Internet Crime Response by Corporation

Microsoft, a private corporation, appeals to the federal rules of civil procedure to authorize technical steps (a legal hack?) to stop a cyber threat.

"a federal judge granted a temporary restraining order cutting off 277 Internet domains believed to be run by criminals as the Waledac bot." See official Microsoft blog post.

This lawsuit case shows that the civil judicial system has a role to play in limiting the impact and damage caused by ...