yes. you’re in the right room.. hi! i’m david (hi david!)

31
Yes. You’re in the right room.

Upload: damon-ross

Post on 21-Jan-2016

213 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Yes. You’re in the right room.

Page 2: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Hi!

Page 3: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

I’m David(Hi David!)

Page 4: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

I’m a lawyer.

Page 5: Yes. You’re in the right room.. Hi! I’m David (Hi David!)
Page 6: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

I’m a lawyer.

Page 7: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Today we’re going to talk

about:

Page 8: Yes. You’re in the right room.. Hi! I’m David (Hi David!)
Page 9: Yes. You’re in the right room.. Hi! I’m David (Hi David!)
Page 10: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

• Major laws• Legal guide• Contract issues• Toolkit

Roadmap

Page 11: Yes. You’re in the right room.. Hi! I’m David (Hi David!)
Page 12: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Major laws

• Computer Fraud and Abuse Act - 18 USC 1030• Wiretapping – 18 USC 2511• Stored Communications Act (email) – 18 USC 2701• Destruction of communication devices – 18 USC 1362• Patriot Act – amends many laws• RICO• Foreign Intelligence Surveillance Act (FISA)• Medical Computer Crime Act• State laws

Page 13: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Major laws

Knowledge

Exceeding authority

Infrastructure that is not public / open

Disclosure / retention of data

Page 14: Yes. You’re in the right room.. Hi! I’m David (Hi David!)
Page 15: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Major laws

CFAA – up to 20 years

SCA – 5 years in the absence of malice

Wiretapping – 5 years

Page 16: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Major laws

Penalty considerations• Potential and actual loss• Sophistication and planning involved• Purpose of offense• Intent• Impact on privacy rights• National security • Interference with critical infrastructure• Threat to public health

Page 17: Yes. You’re in the right room.. Hi! I’m David (Hi David!)
Page 18: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Legal guide

Scope

Permission

Third parties

Access

Page 19: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Legal guide

Scope

• What is the customer trying to protect?

• Systems to be protected

• Limitations on testing

• Types of information processed

Page 20: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Legal guide

Permission

• Methods to be used

• Types of customers serviced

• Categories of information held

• Data to be retained

• Data to be purged

Page 21: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Legal guide

Third parties

• Who are customer’s third party vendors?

• Does customer contract allow testing?

• Will you use third parties?

• Consider law enforcement and prosecutorial priories

Page 22: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Access

• Document data to which you have access

• Limit the number of employees who have access to data

• Create and implement access policies

• Require written notice

Legal issues

Page 23: Yes. You’re in the right room.. Hi! I’m David (Hi David!)
Page 24: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Contract

Permission

Scope of access

Indemnification

Termination issues

Page 25: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Contract

Permission and Scope of AccessCustomer grants Company full and unlimited access to the information and systems set out on the Statement of Work (Access). Access is only limited by the express statements set out in the Statement of Work. Company agrees to keep complete and accurate records of its activities related to Access. Company shall be entitled to produce these records should it be alleged that Company has exceeded the Access authorized by Customer.

You must have express permission

Page 26: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

IndemnificationCustomer hereby releases and agrees to indemnify and defend Company, and any and all directors, officers, employees, contractors and agents of Indemnitee (collectively, the “Indemnitees”) from and against any and all liabilities, claims, losses, damages, costs, and expenses, including reasonable attorneys’ fees arising out of or in any way relating to the activities set out on the Statement of Work. This indemnification obligation shall extend to claims brought by customers of Customer and any third party claiming injury of any sort from the activities set out in the Statement of Work. In addition, the indemnification obligation shall extent to any charges brought against Company by a law enforcement or regulatory entity of any type based on the activities contemplated in this Agreement.

Contract

Indemnification must be broad and extend to end users / law enforcement

Page 27: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Termination

Contract

Upon termination or expiration of this Agreement, Company shall delete all data and provide Customer with written confirmation of this deletion. Company shall also instruct any entities who have had access to the data to also delete it and provide Customer with written certification of this deletion. The security obligations set out in this Agreement relating to the data shall survive termination or expiration of this Agreement until such time as the data is completely deleted by Company. Company shall require this provision, or one similarly protective of Customer’s rights in all its contracts with suppliers or other vendors who provide aspects of the Services. Company may keep copies of data created pursuant to this Agreement, subject to this paragraph

When agreement terminates, your rights

terminate.

Page 28: Yes. You’re in the right room.. Hi! I’m David (Hi David!)
Page 29: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Toolkit

Determine how services will be used

Evaluate customer’s data structure

Understand end user’s data

Determine the type of data you may retain

High risk regulatory areas

Disposition of data on termination

Page 30: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

surveymonkey/source12

Page 31: Yes. You’re in the right room.. Hi! I’m David (Hi David!)

Thanks for coming!

W: dsnead.comT: @wdsneadpc