<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rossander's Security Reader &#187; Records Retention</title>
	<atom:link href="http://rossander.org/infosec/category/records-retention/feed/" rel="self" type="application/rss+xml" />
	<link>http://rossander.org/infosec</link>
	<description>an Information Security blog for the rest of us</description>
	<lastBuildDate>Mon, 06 Sep 2010 21:03:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Is RAM a &#8220;document&#8221;?</title>
		<link>http://rossander.org/infosec/2010/06/is-ram-a-document/</link>
		<comments>http://rossander.org/infosec/2010/06/is-ram-a-document/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 12:53:23 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Records Retention]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=636</guid>
		<description><![CDATA[A judge ruled that RAM is a discoverable, tangible document.  That decision makes little sense.]]></description>
			<content:encoded><![CDATA[<p> A federal judge in Los Angeles ruled recently that a computer server&#8217;s RAM (<a href=http://en.wikipedia.org/wiki/Random-access_memory>random-access memory</a>) is a tangible document that can be stored and must be turned over in a lawsuit.  The judge is an idiot.</p>
<p> <b>Background</b></br><br />
The case is about copyright infringement.  The Motion Picture Association of America (MPAA) is trying to force TorrentSpy, a file-sharing site, to turn over data about visitors to their website.  TorrentSpy replied that they don&#8217;t keep logs on their users &#8211; they are merely an intermediary, allowing data to pass through their website unscreened.  They essentially said that they have no data to turn over.  Unhappy with that answer, Judge Jacqueline Chooljian ordered TorrentSpy to begin logging user information and to turn that data over to the MPAA.</p>
<p> Unfortunately, the only way that the judge can make that order is to make some real leaps of logic.  Companies are required to cooperate with fact-finding requests for documents.  That&#8217;s what the whole &#8220;discovery&#8221; thing is about.  Our judicial system is based on the assumption that if we can get all the facts on the table, we can quickly figure out who&#8217;s right, who&#8217;s wrong and how to make the victim whole.  (Remember that this is a very different standard from the criminal &#8220;innocent until proven guilty&#8221; rule.)  If you have a document that might be relevant to the case, you are required to produce it to the other side and to the court.</p>
<p> There are a few limits to that broad discovery, however.  You can hold back documents (or parts of documents) that are attorney-client privileged or that contain confidential information like SSNs, medical details, etc as long as those details are not relevant to the case.  You also can not be compelled to produce documents you don&#8217;t have.  Courts are not supposed to be able to force you to create new records or documents just to respond to a discovery request.</p>
<p> TorrentSpy does not log user transactions during their normal operations.  They do so to protect users&#8217; privacy and because they have no operational need for the data in their normal course of business.  MPAA argues that it also makes it easier for people who download pirated material to work in the shadows.  They may be right.  Regardless, TorrentSpy argued that requiring them to turn on logging is the same as requiring them to begin creating new documents just for this case.  From a legal point of view, they&#8217;re right.</p>
<p> The judge got around this by arguing that the data already exists in the computer&#8217;s RAM.  Therefore, she is not asking them to create new documents, merely to produce existing data in a more usable form.  You can read the original order <a href=http://i.i.com.com/cnwk.1d/pdf/ne/2007/Torrentspy.pdf>here</a>.  She does cite some other Ninth Circuit decisions involving RAM but, in my opinion, she is either misreading or misapplying the underlying facts.</p>
<p> RAM is not and can not be considered a &#8220;document&#8221; for the purposes of eDiscovery.  RAM is the ephemeral memory that the computer uses to make calculations and to quickly access the data in other places.  Think of RAM as the one that you carry in your head when adding a column of digits.  (The data on your hard-drive may hold the result of your calculation in a spreadsheet but that&#8217;s a completely different kind of memory.  The hard-drive data generally <i>is</i> reasonably accessible.)  There is no possible way to record the billions of transactions per second that flash through the RAM of even a small computer.  Attempting it would consume more permanent memory than exists in the world.  And, by the way, writing all that content also requires transactional decisions and data that pass through RAM.  The act of recording it spoliates it.</p>
<p> Okay.  The judge is not really an idiot.  She is seeking a justification to force cooperation from a company that&#8217;s not really playing fair.  She wants them to turn on logging.  Logging is cheap and easy &#8211; at least compared to most other electronic discovery activities.  From a social policy point of view, I&#8217;m torn.  TorrentSpy probably should be cooperating and not being stupid about the &#8220;costs of logging&#8221; and the applicability of Dutch privacy law.  On the other hand, TorrentSpy is not being accused of any direct misdeeds.  They are being pulled in as a third-party in MPAA&#8217;s attempt to sue their own customers.  MPAA&#8217;s heavy-handed approach is not winning them any friends.  Whichever side you agree with, though, the judge&#8217;s contortions about the technological facts of RAM to make her rationalization will get used as precedent outside this narrow circumstance.  As the saying goes, &#8220;Bad facts make bad law.&#8221;</p>
<p> The judge&#8217;s decision is already being appealed and has been stayed pending that decision.  Her decision has been upheld once but appeals continue.  On both technological and legal grounds, I sincerely hope that her decision is overturned.  Congress needs to address the problem of compelling cooperation from companies like TorrentSpy but they need to do it cleanly &#8211; a new law, not judicial twisting and rationalization.</p>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2010/06/is-ram-a-document/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shredded documents can be unshredded</title>
		<link>http://rossander.org/infosec/2009/09/shredded-documents-can-be-unshredded/</link>
		<comments>http://rossander.org/infosec/2009/09/shredded-documents-can-be-unshredded/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 14:24:04 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Records Retention]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=516</guid>
		<description><![CDATA[Shredded papers can be be unshredded.  With new scanners and computer algorithms, it's easier than ever.  Here are some tips to make it more difficult.]]></description>
			<content:encoded><![CDATA[<p> Shredding is the ultimate defense, right?  Once it&#8217;s shredded, it&#8217;s gone!</p>
<p> No longer.  It was always vulnerable if your attacker had the shredded chaff and plenty of free time.  Think of the shredded embassy documents from the Iranian Hostage crisis of 1979.  Those students reconstructed the pages with nothing more than scotch tape and patience.  More recently, methamphetamine users have been hired by identity theft ringleaders to do the same thing.</p>
<p> Bill Wilson recently found a number of services which make the &#8220;unshredding&#8221; problem much more manageable.  In the Enron case, the government hired <a href=http://www.churchstreet-technology.com/>ChurchStreet Technology</a> to scan the chaff, then used computer algorithms to piece the documents together.  They claim to take the recovery time from hundreds of hours down to mere minutes.  It&#8217;s expensive but not terribly complicated.</p>
<p> So how do you fully protect your waste paper in this new environment?</p>
<ol>
<li> If you&#8217;re still using a strip-cut shredder, get rid of it now.  Upgrade to a cross-cut that chops the paper into very small bits of chaff.</li>
<li> Feed your pages into the shredder vertically, that is, with the words perpendicular to the shredder blades.</li>
<li> Don&#8217;t have unusual-colored paper.  Or if you do, shred enough of it that it can&#8217;t be easily picked out.  The rule in the army used to be no less than 20 sheets of any given paper type in each shred &#8220;lot&#8221;.</li>
<li> Stir the chaff before disposal.  A careful opponent could exploit the fact that pieces from the same document tend to come out of the shredder close to each other and remain so in the waste bag.  A few quick stirs can randomize the chaff and make reconstruction much harder.</li>
<li> Send the chaff to a paper recycler.  Even the best reconstructors can&#8217;t bring a page back after it&#8217;s been turned into new paper pulp.  Of course, you have to be sure that your waste isn&#8217;t intercepted before it hits the recycler but there are several bonded shredding companies that will do that for you.</li>
</ol>
<p> How much is enough?  It depends on who&#8217;s out to get you.  For most home users and small businesses, step two is probably enough.  If you really have something to hide, consider three and four and look into five when your shredding contract comes up for renewal.  Find the right balance, remembering that identity theft is real but that most of us are not dealing with DoD nuclear secrets.</p>
<p> Bill Wilson writes a weekly newsletter for the Big I Virtual University, an arm of the <a href=http://www.iiaba.net/>Independent Agent&#8217;s Association</a>.  It&#8217;s filled with useful information and includes a technology column in almost every issue.  If you have a small business, you should consider subscribing to his newsletter even if you&#8217;re not in insurance.</p>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2009/09/shredded-documents-can-be-unshredded/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Desktop is evil &#8211; updated</title>
		<link>http://rossander.org/infosec/2008/12/google-desktop-is-evil-updated/</link>
		<comments>http://rossander.org/infosec/2008/12/google-desktop-is-evil-updated/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 20:29:56 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Records Retention]]></category>
		<category><![CDATA[e-discovery]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[electronic discovery]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=6</guid>
		<description><![CDATA[Google Apps Team Edition creates a hole by which your staff could bypass your records retention policies.  Make sure you have the "Network Storage and Backup" category blocked by your webfilter.
]]></description>
			<content:encoded><![CDATA[<p> Google continues to roll out new applications to make sharing information easier.  Kudos to them for some really creative programming.  From a security point of view, though, you have to wonder what they are thinking.</p>
<p> Their Google Apps Team Edition allows employees to sign up for the Google Applications without any assistance or oversight from IT.  Team Edition contains the core applications and collaboration services like the word processor, spreadsheet, Start page, Talk instant messaging and calendar, but does not include Gmail.</p>
<p> In any regulated or litigious industry, this is a recipe for disaster.  You might save a few bucks on word processing and spreadsheet software but you&#8217;re going to pay far more the first time you have to comply with an electronic discovery request or get into a dispute based on the Terms &#038; Conditions of the application.  No only are you putting your confidential data in someone else&#8217;s hands and trusting to the security of their data center with little or no evidence of their worthiness of that trust, you&#8217;re also still exposing all your data to the Google search indexing algorithms.  (For more, see the Tip from <a href=http://rossander.org/infosec/?p=88>April 2007</a>.)</p>
<p> Luckily, you can block the worst aspects of the application/data sharing without having to block off all of the google.com domain.  If your internet filter has a category for filesharing or for &#8220;Network Storage and Backup&#8221;, make sure that category is blocked.  You should also strongly consider blocking any category about &#8220;Web chat&#8221; so you don&#8217;t have to worry about <a href=http://rossander.org/infosec/?p=82>electronic discovery</a> requests for instant messages that you didn&#8217;t properly control.<br />
Read more about Google Apps latest attempt to bypass the business at <a href=http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9061440>ComputerWorld.com</a>.</p>
<hr />
<p> <b>Update</b> to <a href=http://rossander.org/infosec/?p=14>Suing the scareware vendors</a>  (27 Oct 2008)<br />
The Federal Trade Commission has gotten a restraining order against two companies who were marketing <a href=http://rossander.org/infosec/?p=34>scareware</a> software.  It&#8217;s very good to see law enforcement successfully prosecuting these scammers.  Remember, however, that there are lots more out there.  Always be suspicious of pop-up &#8216;alerts&#8217; and ads warning you about &#8220;illegal porn content&#8221; or &#8220;compromised software&#8221; on your computer.  Read more at the <a href=http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt121.shtm>FTC&#8217;s consumer alert page</a>.</p>
<div align=right><small><i>From <a href=http://infosec.westfieldinsurance.com/2008/12/google-desktop-is-evil-updated.html>westfieldinsurance.com</a></i></small></div>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2008/12/google-desktop-is-evil-updated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft disables old file formats</title>
		<link>http://rossander.org/infosec/2008/10/microsoft-disables-old-file-formats/</link>
		<comments>http://rossander.org/infosec/2008/10/microsoft-disables-old-file-formats/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 17:19:15 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Records Retention]]></category>
		<category><![CDATA[electronic discovery]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=16</guid>
		<description><![CDATA[Microsoft is making some old file formats obsolete.  If you're keeping those old files, you may not be able to open them anymore.
]]></description>
			<content:encoded><![CDATA[<p><P>We talked last week about the problems of <A href=http://rossander.org/infosec/?p=17>holding onto old documents</A>. Microsoft just made the problem even more complicated.</P></p>
<p><P>In the Service Pack 3 (SP3) update for Office 2003, Microsoft is blocking a number of older file formats so they can no longer be opened by MS products like Word, Excel or Powerpoint. Microsoft is walking away from it&#8217;s commitment to backwards-compatibility because many of the older file formats had weaknesses that could be exploited by hackers to insert viruses and other malicious code into your computer. By disabling the older formats, Microsoft reduces the vulnerability of the Office applications to some of those kinds of attacks.</P></p>
<p><P>The problem is that if you are keeping old files in their native format as part of your records retention plan, you may no longer be able to open them. (Worse, if you get sued and have to turn over those documents, the courts don&#8217;t care about format compatibilities. You still have the document – it&#8217;s your responsibility to make sure that they can be opened and evaluated.)</P></p>
<p><P>Microsoft has two workarounds for this problem – neither very good.</P></p>
<p><P>The first involves modifying your registry settings so your computer can still open the older formats. That is a high-risk action and I do not recommend it. Not only does it defeat the security advantage of the change, any mistake when editing the registry settings can corrupt your entire computer. Even Microsoft warns against it saying &#8220;Serious problems might occur if you modify the registry incorrectly.&#8221; and &#8220;Modify the registry at your own risk.&#8221;</P></p>
<p><P>The second is to convert all your historical documents to the newer format. Microsoft has some automated tools to help but the conversion process is much more labor-intensive and error-prone than I think Microsoft wants to admit. I would seriously question the business case for converting any but your most critical of official records.</P></p>
<p><P>There is a third option which I consider far better. Take this opportunity to check those old documents against your <a href=http://rossander.org/infosec/?p=82>retention policy</a> and clean out the ones that you should have gotten rid of long ago. For the few that you must retain, make sure that you are keeping your business records in a stable format. Don&#8217;t save files in their native MS Word document format &#8211; convert them to pdf or even tiff. Those formats are simpler and have far fewer holes that a hacker could exploit. They&#8217;re also designed to remain readable across many generations of software.</P></p>
<p><P>Call your IT team for instructions on how to convert an old file to an updated format.</P></p>
<hr />
<p><b>Addendum:</b><br />
Bill Wilson at IIABA&#8217;s <a href=http://www.iiaba.net/vu>Virtual University</a> published the tip above in his newsletter and received the following question.<br />
<i>What are the file extensions that Microsoft has abandoned? I think it would be very helpful to know as we would then be able to do searches for those file types stored on our system. Thank you.</i></p>
<p>As Bill pointed out to the caller, the file extensions alone will not tell you which file formats have been disabled since Microsoft continues to use the same file extensions for the newer versions of it&#8217;s software. (A Word document carries the .doc extension whether it&#8217;s Word 1.2, Word 2003 or any version in between.) Microsoft has a little bit more information about the changes <a href=http://support.microsoft.com/kb/938810/en-us>here</a> but no new answers.</p>
<p>You can read another article about the problem at <a href=http://blog.wired.com/monkeybites/2008/01/microsoft-offic.html>wired.com</a>.<br />
Thanks to Bill for finding those extra links.</p>
<div align=right><small><i>From <a href=http://infosec.westfieldinsurance.com/2008/10/microsoft-disab.html>westfieldinsurance.com</a></i></small></div>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2008/10/microsoft-disables-old-file-formats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Being a packrat costs a lot of money</title>
		<link>http://rossander.org/infosec/2008/10/being-a-packrat-costs-a-lot-of-money/</link>
		<comments>http://rossander.org/infosec/2008/10/being-a-packrat-costs-a-lot-of-money/#comments</comments>
		<pubDate>Mon, 06 Oct 2008 23:55:11 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Records Retention]]></category>
		<category><![CDATA[document lifecycle]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=17</guid>
		<description><![CDATA[Holding onto old paper documents is expense.  Old electronic documents are even more expensive, though the costs are hidden.  Decide carefully what to keep.
]]></description>
			<content:encoded><![CDATA[<p>Holding onto old documents is hard and far more expensive than most people realize.</p>
<p>In the paper world, the paper just keeps piling up.  The paper must be protected from theft and damage (fire and water) and if it&#8217;s ever going to be useful again you need some sort of filing and record-keeping system.  A proper records retention facility is expensive to run.</p>
<p>With electronic documents and cheap memory, many people started to think that we could now hold onto everything.  A two-gigabyte thumbdrive can hold up to the equivalent of 400,000 pages of documents.  That&#8217;s 80 <i>boxes</i> of copy paper.  And, being electronic, I can type in a few keywords and let the computer find the document I want.  No more filing!  Right?</p>
<p>Not by a long shot.  Memory may be cheap but usable storage isn&#8217;t.</p>
<p>Electronic storage costs explode as file formats change over time. For example, a first notice of a claim involving a minor child has to be kept for up to 24 years (the child&#8217;s age of majority plus four). What word processor were you using 24 years ago? What printer was the program compatible with? What operating system did it run on? What drivers did it need to operate? What hardware did it use? When was the last time you even saw a 5¼&#8221; floppy drive, much less an old 8&#8243; floppy? How much can you afford to pay IT to keep a working version of every system and application in the company&#8217;s history?</p>
<p>And that&#8217;s assuming you can find the file in the first place. We are used to thinking of searching as being as easy as Google. In fact, searching for documents is very hard when documents are scattered across ad-hoc structures like personal hard-drives and departmental folders. Solutions that try to solve the ad-hoc storage (like <a href=http://rossander.org/infosec/?p=88>Google Desktop</a>) create new problems, especially around the security of the index.</p>
<p>Keeping old records also exposes you to legal costs down the road. Under the new electronic discovery rules, a company must search through all its old documents just to see if they hold anything that might possibly be relevant to the lawsuit. One class action lawsuit can run into millions of dollars just in search and review costs &#8211; and that&#8217;s even if you don&#8217;t find anything. If you do have a relevant document, now you have to convert it, produce it and defend it from anyone who tries to take your words out of context. That&#8217;s expensive.
<ul>
<li> If your <a href=http://rossander.org/infosec/?p=82>Records Retention Policy</a> doesn&#8217;t explicitly require you to keep the record, don&#8217;t keep it. Throw it away and then you don&#8217;t have to worry about storage or formats. The cost of recreating those few useful things that we lose will be far less than the cost of hanging on to all the rest of the trash.</li>
<li> If you do have to keep a document, think long and hard about what format to save it in. Convert the file to a more stable format such as pdf or even tiff. Those formats are designed to remain readable across many generations of software. Call your IT team for instructions on how to save a file to an alternate format.</li>
</ul>
<div align=right><small><i>From <a href=http://infosec.westfieldinsurance.com/2008/10/being-a-packrat.html>westfieldinsurance.com</a></i></small></div>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2008/10/being-a-packrat-costs-a-lot-of-money/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Metadata &#8211; defined</title>
		<link>http://rossander.org/infosec/2008/07/metadata-defined/</link>
		<comments>http://rossander.org/infosec/2008/07/metadata-defined/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 07:00:00 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Definitions]]></category>
		<category><![CDATA[Records Retention]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=27</guid>
		<description><![CDATA[Metadata is getting a lot of press lately, especially among companies that are wrestling with the new electronic discovery standards issued by the US Supreme Court. But what is it really? Technically, metadata is data about other data. If the customer&#8217;s address is data, the number of entries in your address book is metadata. If [...]]]></description>
			<content:encoded><![CDATA[<p>Metadata is getting a lot of press lately, especially among companies that are wrestling with the new electronic discovery standards issued by the US Supreme Court. But what is it really?</p>
<p>Technically, metadata is data about other data. If the customer&#8217;s address is data, the number of entries in your address book is metadata. If the body of a Word document is data, the date you last opened the file is metadata. If the values in an Excel spreadsheet are data, the formulas in each cell are metadata.</p>
<p>From a legal point of view, metadata is everything about the document that&#8217;s not immediately visible when the document is printed. It includes all the MS Office &quot;properties&quot; like file size, author and character count. It also includes any hidden features such as the old versions that are still buried in the document when you leave the Track Changes option on. It includes formulae in spreadsheets and formatting commands like the print area.</p>
<p>For most normal uses, the metadata about a document is just background. We take it for granted and almost always ignore it. But if your metadata reveals facts that you wanted to keep private, it can be embarrassing and expensive. In one case, a major pharmaceutical company deleted some study data from a report – and got caught when the New England Journal of Medicine looked in the Tracked Changes to show the deleted comments. In another case, a confidential White House policy paper about Iraq was outed when a quick command revealed the report&#8217;s author. In yet another case, officials covered up classified information with black bars, not realizing that readers could easily uncover the text by copying it from under the black and pasting it elsewhere.</p>
<p>When you get into a legal situation, metadata becomes even more important. Metadata is used to show &#8220;who knew it and when they knew it&#8221; – to provide the context around the document in question. Metadata can either clear you or convict you. Because of its importance, metadata must be preserved and unaltered when you are collecting documents that will be used in court. This is hard because routine Windows operations will change the metadata just by opening the file. Make sure that you have the tools you need to keep metadata intact before you get into the lawsuit.</p>
<p>And, of course, be very careful before you post a document publicly. Make sure you clean out the metadata that you don&#8217;t want public.</p>
<div align=right><small><i>From <a href=http://infosec.westfieldinsurance.com/2008/07/metadata---defi.html>westfieldinsurance.com</a></i></small></div>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2008/07/metadata-defined/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Home Shredders</title>
		<link>http://rossander.org/infosec/2007/11/home-shredders/</link>
		<comments>http://rossander.org/infosec/2007/11/home-shredders/#comments</comments>
		<pubDate>Mon, 05 Nov 2007 07:00:00 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Records Retention]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=60</guid>
		<description><![CDATA[How secure are you from identity theft? For all that we are (and ought to be) worried about hackers and other threats to our electronic information, researchers estimate that 55% of all cases of identity theft are based on information from paper. Could someone find credit card numbers, bank account numbers or social security numbers [...]]]></description>
			<content:encoded><![CDATA[<p>How secure are you from identity theft? For all that we are (and ought to be) worried about hackers and other threats to our electronic information, researchers estimate that 55% of all cases of identity theft are based on information from paper. Could someone find credit card numbers, bank account numbers or social security numbers in your trash?</p>
<p>Garbage left at curbside is considered to be in the public domain. That means it&#8217;s not illegal for someone to take items out of your trash. And don&#8217;t think that someone won&#8217;t go through it just because it&#8217;s mixed in with the dirty diapers. In many municipalities, all the waste is opened and manually sorted as part of the area&#8217;s recycling program. In Medina County, for example, your trash is touched by about 20 people between the time you put it in your trash can and it ends at the bottom of the landfill. Your credit card statement is a great temptation.</p>
<p>Home-quality shredders are available for as low as $40. If you don&#8217;t yet have a shredder at home, you need one. We all need to be concerned with how much of our information can be accessed from our mail, including our credit card and bank statements, and any other piece of mail that may provide confidential information. Anything that has your name, address, phone number or any kind of account number on it should be shredded before discarding. Credit cards should be destroyed by cutting the card across the number.</p>
<p>There are two basic kinds of shredders: strip-cut and cross-cut. Most of the cheaper shredders are strip-cut. They cut the pages into strips between 1/8 and 1/4 inches wide. Cross-cut shredders (also called &quot;confetti-cut&quot;) will chop the strips into smaller pieces, and thus provide much greater protection. The other factors commonly used to compare shredders are durability and capacity (how many pages can it shred at a time without jamming).</p>
<p>Note: Keep the shredder unplugged or locked away when young children are around.</p>
<div align=right><small><i>From <a href=http://infosec.westfieldinsurance.com/2007/11/home-shredders.html>westfieldinsurance.com</a></i></small></div>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2007/11/home-shredders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Email can come back to haunt you</title>
		<link>http://rossander.org/infosec/2007/10/email-can-come-back-to-haunt-you/</link>
		<comments>http://rossander.org/infosec/2007/10/email-can-come-back-to-haunt-you/#comments</comments>
		<pubDate>Mon, 29 Oct 2007 07:00:00 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[Records Retention]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=61</guid>
		<description><![CDATA[This Tip was first run in October 2006. This &#34;encore tip&#34; is a reminder to be professional in email. Halloween is a time for scary stories &#8211; tales of vampires and ghouls rising from the dead to terrify innocents &#8211; a time when things that you thought were dead and buried come back to haunt [...]]]></description>
			<content:encoded><![CDATA[<p><em>This Tip was first run in October 2006. This &quot;encore tip&quot; is a reminder to be professional in email.</em></p>
<p>Halloween is a time for scary stories &#8211; tales of vampires and ghouls rising from the dead to terrify innocents &#8211; a time when things that you thought were dead and buried come back to haunt you.</p>
<p>Unfortunately, the analogy between badly written email and the undead is sometimes all too appropriate. A hasty word can return to haunt you long after you hit the send button and thought the conversation was over. Careers have been destroyed, money lost and relationships ruined when an email returned from beyond.</p>
<p>Americans have a bad habit of treating email very casually – as an extension of our last phone conversation or a continuation of the chat in the hallway. We assume that the message is private and that recipient will understand the context and correctly interpret our tone.</p>
<p>In fact, email is more like a <a href=http://rossander.org/infosec/?p=127>postcard</a> &#8211; anyone can read it while it&#8217;s in transit and any of the recipients can save it, forward it or post it to the internet. Electronic copies can remain in archives and electronic message hubs all over the Internet – places that neither the sender nor the recipient can control. Emails can be subpoenaed and forced into the public record. You have no right of privacy in your email, either sent or received. When you write an email, you must assume that it will be read by an unknown and unforeseen audience.</p>
<p>That unknown audience will assume that you carefully crafted and wordsmithed your message (or, if not, that the hurried email is evidence of the writer&#8217;s &#8220;real state of mind&#8221;). They will not believe that you were &#8220;just joking&#8221; and won&#8217;t care that you were trying to dash off a quick note. They will interpret the tone according to their own preconceptions.</p>
<p>Always assume that anything you write will come out at the worst possible time and in the worst possible light. Be professional in your email. Include enough context that the unforeseen reader understands the message. Be personable yet professional in tone. (In particular, <b>never</b> use sarcasm in email.) Never write anything that you would be embarrassed to see on the front page of tomorrow&#8217;s newspaper.</p>
<p>Remember, email can come back to haunt you.</p>
<div align=right><small><i>From <a href=http://infosec.westfieldinsurance.com/2007/10/email-can-come.html>westfieldinsurance.com</a></i></small></div>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2007/10/email-can-come-back-to-haunt-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Create a &#8220;_readme&#8221; for folders</title>
		<link>http://rossander.org/infosec/2007/10/create-a-_readme-for-folders/</link>
		<comments>http://rossander.org/infosec/2007/10/create-a-_readme-for-folders/#comments</comments>
		<pubDate>Mon, 22 Oct 2007 07:00:00 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[Records Retention]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=62</guid>
		<description><![CDATA[Whether you use shared folders or keep files on your personal drive, eventually others in your organization will need to find some of the files that you&#8217;ve created or saved. Electronic searches help some but it&#8217;s still important to file your ad-hoc documents carefully if you ever hope to find them again. In order to [...]]]></description>
			<content:encoded><![CDATA[<p>Whether you use shared folders or keep files on your personal drive, eventually others in your organization will need to find some of the files that you&#8217;ve created or saved. Electronic searches help some but it&#8217;s still important to file your ad-hoc documents carefully if you ever hope to find them again. In order to help the rest of your team members (especially future team members) understand your new filing system, I strongly recommend creating a very small file in each folder describing the:</p>
<ul>
<li>purpose of the folder</li>
<li>owner of the folder</li>
<li>intended audience and users of the folder – who should and should not have access</li>
<li> retention period – how long should we generally keep the documents in the folder<sup>†</sup></li>
</ul>
<p>If you name the file <tt>_readme.txt</tt>, the underline will cause the file to sort itself to the top of the list where everyone can find it. Here&#8217;s an example of one I created to describe the folder where I hold my InfoSec Tips drafts. <a href=http://intranet.westfieldgrp.corp:8001/data/bin/InfoSec/_readmeExample.txt>_readme.txt</a></p>
<p><sup>†</sup> When deciding on the appropriate retention period, refer to your organizational Retention Policy for guidance. And remember that &#8220;forever&#8221; is technically possible but outrageously expensive for electronic documents. Westfield is 159 years old. If they say that a document should be kept &#8220;forever&#8221;, they are handing their IT department a blank check to spend whatever it takes to make sure that the document will still be here in another 159 years. There aren&#8217;t very many documents with that kind of business need. Make your best estimate of the realistic business need for the documents in the folder. Also remember that saying you want to keep a document for 12 months does not mean that it will be automatically deleted. You (or someone in your organization) will still have to clean out the folder when the documents are no longer necessary.</p>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2007/10/create-a-_readme-for-folders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shredding is a Federal requirement</title>
		<link>http://rossander.org/infosec/2007/10/shredding-is-a-federal-requirement/</link>
		<comments>http://rossander.org/infosec/2007/10/shredding-is-a-federal-requirement/#comments</comments>
		<pubDate>Mon, 08 Oct 2007 07:00:00 +0000</pubDate>
		<dc:creator>Mike Rossander</dc:creator>
				<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[Records Retention]]></category>

		<guid isPermaLink="false">http://rossander.org/infosec/?p=64</guid>
		<description><![CDATA[Under Federal Trade Commission regulation, any information about an individual that is derived from a consumer report or is a compilation of such records must be properly destroyed. These days, almost all of customer information has some connection to a consumer report and is covered under this regulation (scroll to pg 32). The regulation does [...]]]></description>
			<content:encoded><![CDATA[<p>Under Federal Trade Commission regulation, any information about an individual that is derived from a consumer report or is a compilation of such records must be properly destroyed. These days, almost all of customer information has some connection to a consumer report and is covered under <a href="http://www.ftc.gov/os/2004/11/041118disposalfrn.pdf" target="_blank">this regulation</a> (scroll to pg 32).</p>
<p>The regulation does not actually require shredding but for most of us, that is the only cost-effective way to comply with the regulation&#8217;s requirements for destruction. Papers in regular trash are exposed to the public and any private information on those papers can be misused by an identity thief. It can cost your customers thousands of dollars to get their identity back and could be considered a violation of federal privacy laws.</p>
<p>I strongly recommend a &quot;shred all paper&quot; policy for your office because there is too much risk that a piece of personal information will be overlooked on the back side of a form or that the page was used for scratch paper while you were on the phone. It&#8217;s also easier to enforce the policy when you have a simple rule like &quot;No office paper may be thrown away in the regular trash.&quot;</p>
<p>Very small offices can get away with a personal shredder. If you&#8217;ve got more than about 10 or 15 people in the office, it&#8217;s probably more cost-effective to contract with a reputable shredding vendor who will pick up and properly dispose of your paper waste. Most of the shredding vendors will provide locked bins where the paper waste can be stored until pickup. Have enough bins to be convenient for staff.</p>
<div align=right><small><i>From <a href=http://infosec.westfieldinsurance.com/2007/10/shredding-is-a.html>westfieldinsurance.com</a></i></small></div>
]]></content:encoded>
			<wfw:commentRss>http://rossander.org/infosec/2007/10/shredding-is-a-federal-requirement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
