SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> IT Workplace >> Human Resources Issues

Watching the watchdog within corporate walls

Watching the watchdog within corporate walls

By:  Mari-Len De Guzman  On: 29 Mar 2007 For: ComputerWorld Canada Creator

Surveillance tools for logging and monitoring employee activities for security and compliance are getting increased attention in the enterprise, but a recent high-profile incident indicates that the same technology may also be putting organizations at risk

COMMENT ON THIS ARTICLE

Surveillance tools for logging and monitoring employee activities for security and compliance are getting increased attention in the enterprise, but a recent high-profile incident indicates that the same technology may also be putting organizations at risk.

Earlier this month, an employee at retail giant Wal-Mart, reportedly a systems technician, was fired for conducting unauthorized recording of communications between Wal-Mart’s PR department and a New York Times reporter.

The incident brought into question the kinds of technology organizations deploy to facilitate system health checks, employee monitoring and compliance. The issue also puts forth issues around governance and acceptable-use policies that accompany or should accompany those technologies.

Thus emerges the question, ‘Who is watching the watchdog?’ Although Wal-Mart was mum on the details, at least one IT security specialist viewed the incident as a case of “human nature running amok — a legitimate investigation that got out of hand.”

“I believe that what we are seeing here is symptomatic of a larger issue facing the security and privacy community,” said ComputerWorld (U.S.) blogger Perry Carpenter, an information security and privacy expert. Carpenter previously worked at Wal-Mart as part of its IT security group.

“Lets’ face it, the cloak-and-dagger aspect of penetration testing and investigation has a certain appeal to it. Without proper and strict oversight, the employee engaged in these activities can easily give in to natural human curiosity and step over the line of acceptable and authorized behaviour,” Carpenter wrote on his blog.

When organizations deploy tools such as employee activity logging and monitoring, penetration testing and other similar exercises, the IT department is typically the custodians and users of these tools. Where some organizations often fail is in having the right process and policies in place to ensure that these devices are used accordingly, and not abused, said Adel Melek, global leader for privacy and security services at Toronto-based professional services firm Deloitte.

“In many instances, organizations are fast into deploying these new technologies without fully understanding the ramifications that would be associated with the business process,” Melek said.

For instance, when an IT staffer is tasked to conduct workplace surveillance, such as monitoring and logging of e-mails and other communications, there needs to be a check-and-balance procedure to ensure that the IT personnel is not using those surveillance tools beyond what has been authorized.

In the Wal-Mart case, what seems to have been missing was oversight, said Carpenter. “Just because the tools can be used appropriately in one context does not automatically mean that they should be used in other contexts (i.e. corporate investigations),” he pointed out.


Sign up for our Newsletters












Print |  Views: 588   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mari-Len De Guzman Mari-Len De Guzman is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Why SOA needs a governance framework
Why SOA needs a governance frameworkWhen developers are able to write software code once and have that code re-used by many disparate systems for a variety of functions, the potential for cost savings are tremendous but so are the chances of creating a 'lawless' environment
Privacy can't mean anonymity anymore
Privacy can't mean anonymity anymoreProtecting anonymity is a fight that can't be won, a high-rank U.S. intelligence official says
Canadian IT execs embrace telecommuting
Canadian IT execs embrace telecommutingWireless technologies and Internet applications that make it easier to be productive outside the office are empowering a remote access workforce, companies tell Robert Half Technology. Find out how many cite improved employee morale
ShmooCon 4
last weekend was the 4th annual shmoocon. tickets for the event sell out very quickly as they limit attendance. this year, 1200 self-proclaimed hackers came to the event that promised “less moose than ever”. far from the formality of a regular conference, shmoocon runs talks by researchers presenting new findings and new tools. attendees are encouraged t
Dan Swanson's Security Resources: #14
risk management – where the rubber hits the road.
“The Myth of Intuitive Software”
http://www.zdnetasia.com/techguide/webde…a great piece about software that is hard to use, and should be. the author laments the death of training users on new systems/software, with organizations wanting so
blog comments powered by Disqus