The InformationWeek -- Blogs

CIOs Uncensored

Topics:   CIOs Uncensored : Content Management : Information Management : Security : Storage

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Keeping Secrets And Finding Clues In Data


Posted by Marianne Kolbasuk McGee, Jun 11, 2008 03:40 PM

Your company (probably) has rules about how frequently systems get backed up, e-mail gets deleted, and other data-retention issues. But would those policies hurt if your company was suddenly yanked into litigation, especially noncompete, patent infringement, or trade-secret cases?


You'd be surprised how rapidly events unfold in intellectual property, or IP, cases, says Joel Mohrman, senior intellectual property litigator in the Houston, Texas, office of national law firm McGlinchey Stafford PLLC.

If a former employee was suspected of taking business secrets to a new employer, would you be ready to "lock-down" e-mail or other systems to find evidence showing information was smuggled out? How would your company discover its smoking gun?

Intellectual property disputes "don't always involve the secrets of a new high-tech widget," Mohrman says. In fact, one of the trade-secret cases lawyers often like to cite involved a new pencil, says Mohrman. That's not exactly bleeding-edge technology, is it?

So, if you're a CIO of a bank getting ready to launch a brand-new financial service, or an insurance firm that tries to keep its client details confidential, or are the tech leader of any other business with valuable information you don't want leaking out, you might consider rethinking your company's data retention policies and procedures from time to time.

"IT people have a fetish about reformatting PCs," says Mohrman. At many companies, as soon as an employee leaves for a new job, the worker's PC is quickly cleaned up and reformatted so that another person can use the hand-me-down, he says.

"These PCs never sit around on a shelf" at some companies, he says. The problem with that resourcefulness (or frugalness) is that the computer could've been a potential "gold mine" of evidence if the company later needs to show that data was stolen, or other unethical or illegal activities occurred, he says.

CIOs need flexibility and vision when considering modifications to data-retention procedures and electronic information-storage policies, he says. CIOs should periodically reassess retention and storage policies with company management, and maybe an attorney and/or a vendor that can help sort out new concerns and issues.

Not that CIOs don't already have enough to worry about, but Mohrman also suggests that tech leaders consider ways of retaining information that's coming in from other sources such as security cameras, electronic-ID card swipes, and even copy machine page-counters. All of those can provide clues on after-hours data theft or other suspicious activities, he says.

Finally, Mohrman advises companies to "develop a culture of confidentiality" in which employees are made aware of the rules in using, sharing, or taking company information. "You don't want to create a police state, but if you ever end up in court, the judge will be looking at how you protect your information," he says.

"If it's confidential, label it confidential. If it's in a file cabinet, lock it. If it's in a computer, consider making it password-protected," he says.

What sorts of changes would you make to your company's rules about data confidentiality and retention?

« Resurrecting Speed | Main | Enterprise 2.0: Power To The People »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
InformationWeek Chief Of The Year:
Call For Nominations
Know a dynamic, future-oriented tech chief? We're looking for the most insightful, innovative, forward-thinking business technology leader to honor as our 2008 Chief Of The Year. "Tomorrow's CIO" is the theme of our InformationWeek 500 Conference, and of a recent in-depth InformationWeek Analytics Report based on our extensive survey. The qualities identified with Tomorrow's CIO—equal parts leadership, vision, business savvy, technology expertise--are what we're looking for in our Chief Of The Year.

Candidates must be CIOs, CTOs, or VP-of-IT level executives. Nominations will be accepted now through Oct. 31, 2008.

Please send your nominations to: cjmurphy@techweb.com.



Sign Up For The CIOs Uncensored Newsletter
Every Thursday, Chris Murphy and his fellow analysts explore the business, strategy, and management issues most important to IT leaders.

Sign up for our free, weekly newsletter today!

Newsletter Archives


Global CIO Video

 

  1. Detecting Scalability Problems With Intel Parallel Universe Portal
  2. Just Say No To SFAQL Parallelism
  3. QuickThread: A New C++ Multicore Library


Join The InformationWeek Group On LinkedIn


                           


  1. Thoughts On The Motorola Droid
  2. Specs For Next Motorola Android Phone Leak
  3. Encryption Is Cloud Computing Security Savior


  1. Microsoft Bing Cashback Not Always A Bargain
  2. Google Buys Ad Start-Up Teracent
  3. Feds Launch Health IT Blog
  4. Full Nelson: Video: San Francisco Goes Open, Transparent
  5. AOL Previews Brand, Trims Workforce
  6. Physicians Question Health IT Stimulus Requirements

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007