|
|
DIGITAL RISK
Do You Know Your Blog Risk Factor?
Blogs let anyone publish their latest thoughts to the world with a click of a button. Make sure your employees are crystal clear on the risks and vulnerabilities of blogs, and what's OK to discuss in a personal blog -- and what isn't.
PAGE 1 of 1 - 2 - 3 - » Next
There are a number of risks and vulnerabilities associated with the use of the social software also known as blogs. To appreciate how likely they are to occur, you must acknowledge that employees will use these blogging tools whether you want them to or not, especially outside of the workplace. The challenge comes in balancing employee rights versus employer responsibilities. There are a number of examples in case law where employers have been held responsible for the acts of their employees.
Some of the more common vulnerabilities include:
- Sending/receipt of inappropriate content
- Release of confidential business information
- Failure to retain cusiness records
- SPIM/phishing/social engineering attacks
- Virus/worm attacks
- Employee Misbehavior
- Viewing innapropriate content
- Misuse of corporate assets
- Release of confidential business information
- Introduction of viruses/worms
- Vulnerability to phishing/social engineering attacks
- Employee misbehavior
Of course, with these vulnerabilities are related business risks that include:
- Litigation
- Sexual harassment claims
- Lost time/productivity
- Network attacks/lost data
- Litigation
- Lost customers
- Lost opportunities
- Bad public relations/press
PAGE 1 of 1 - 2 - 3 - » Next
Christopher Byrne, CISA, IBM CAAD (Lotus Notes & Domino R4, R5, ND6)/IBM CASA (Lotus Notes & Domino R5, ND6), is vice president and practice manager for the information systems audit and assurance practice of The Cayuga Group, LLC located in Athens, Georgia. He has extensive experience conducting management reviews and control self-assessments for a wide range of areas. He is a Certified Information Systems Auditor (CISA), and passed the Uniform CPA Examination in 1995. A member of the Compliance Solutions Advisor Editorial Council, he writes about corporate governance, IS governance, and business control issues on his blog at http://www.controlscaddy.com.
Richard Schwartz is the founder of RHS Consulting in Nashua, NH, a member of Penumbra Group and an IBM Business Partner. He has more than 20 years experience with communication and collaboration technologies, and has been working with, writing, and speaking about Lotus Notes and Domino since 1993. http://www.rhs.com
ARTICLE INFO
Web Edition: 2005 Week 45, Doc #17308
FREE ACCESS
Keyword Tags: Blogs, collaboration, compliance, Compliance, Corporate Compliance, E-Mail, ibm, ibm lotus, it networking, Instant Messaging (IM), messaging, security, training
ADVISORAMA When the gods wish to punish us, they answer our prayers. -- Oscar Wilde
|
|