Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Laws & Regulations Require Security & Privacy Training & Awareness | Main | Outsourcing and Customer Service Thoughts... »

FISA Change Gives Telecoms Immunity; Headaches Ahead For Businesses?

In case you didn't hear about it yet, President Bush just signed into law changes to the U.S. Foreign Intelligence Surveillance Act (FISA) that, among other things, grants immunity to telecom companies that cooperate with the secret warrantless wiretap program.

I have not yet had a chance to read the complete ''FISA Amendments Act of 2008'' , but from the analysis I've read so far, and the overview from the press releases from the white house and other government groups, the changes could have a significant impact to basically all organizations.

I can understand WHY the congress wanted to remove liability to telecoms for cooperating with investigations, but HOW it was done shows complete disregard for legitimate privacy concerns and also removes all accountability for not only the telecoms for their eavesdropping activities, but also provides for no accountability on the part of the government or law enforcement agencies, at least from what I've seen so far.

The government wrote the law in such a way that businesses will be left holding the bag for the bad, mistaken, irresponsible, or inappropriate actions the government and law enforcement agencies take with individuals' personally identifiable information(PII) and other information that was collected during surveillance justified by this new FISA Amendments Act of 2008.

  • When collected information on individuals is involved in a privacy breach, who will be held liable? Held responsible?
  • When collected information on individuals is involved in a privacy breach, will the individuals involved even be notified?
  • When individuals want someone to pay for the misuse or crime that occurs with the PII collected from surveillance, and they can't get restitution from the government or the telecoms, will the businesses, whose networks were unknowingly being bugged, be taken to court and held responsible?

There are so many more questions to ask...I need to find time to read through the complete new amendment carefully...

However, it would seem that this new amendment would encourage organizations to strongly encrypt all the data flowing throughout, and outside of, their networks to ensure surveillance activities could not collect sensitive data for which they could possibly later be held liable.

Yes, I know...that could lead to yet another bill that would try and forbid businesses from encrypting data sent through networks, but I really doubt a law like that would pass in this age of mounting privacy breaches. Especially when growing numbers of laws state that encryption is a good way to protect sensitive information.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/760

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.