<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Ogalaws</title>
	<atom:link href="http://ogalaws.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ogalaws.wordpress.com</link>
	<description>Selected topics in law, and strategic consulting.</description>
	<lastBuildDate>Tue, 21 May 2013 13:25:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ogalaws.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Ogalaws</title>
		<link>http://ogalaws.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ogalaws.wordpress.com/osd.xml" title="Ogalaws" />
	<atom:link rel='hub' href='http://ogalaws.wordpress.com/?pushpress=hub'/>
		<item>
		<title>BYOD: Policy with Trust, or Ignore and Bust?!</title>
		<link>http://ogalaws.wordpress.com/2013/05/21/byod-policy-with-trust-or-ignore-and-bust-2/</link>
		<comments>http://ogalaws.wordpress.com/2013/05/21/byod-policy-with-trust-or-ignore-and-bust-2/#comments</comments>
		<pubDate>Tue, 21 May 2013 13:24:54 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Bring Your Own Device (BYOD)]]></category>
		<category><![CDATA[BYOD Policy Guidelines]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=530</guid>
		<description><![CDATA[Gone forever, are the days when businesses could afford to adopt a laissez-faire attitude and let employees set their own pace to adopt and deploy Commercial off the Shelf (COTS) technologies and tools without solid central oversight.  In addition to anti-harassment, customer and vendor relations, travel and expense accounts, and as otherwise advisable for regulatory [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=530&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Gone forever, are the days when businesses could afford to adopt a laissez-faire attitude and let employees set their own pace to adopt and deploy Commercial off the Shelf (COTS) technologies and tools without solid central oversight.<span>  </span>In addition to anti-harassment, customer and vendor relations, travel and expense accounts, and as otherwise advisable for regulatory compliance, policies became necessary for computer hardware, then computer software, mobile phones, and social media usage.<span>  </span>Now, a policy is also needed for the use of personal devices for business purposes – or Bring Your own Device (BYOD), where and when the employer so allows for same.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Whether a single policy will be written with separate and distinct sections for each of these sub-elements, or separate policies will be written for each one, is a matter of case-by-case decision for each employer.<span>  </span>However, many elements will be common to more than one of these policies, and ignoring or avoiding a BYOD policy can lead to “quite” a bust.<a title="" href="#_ftn1" name="_ftnref1">[1]</a></span><span>  </span>The essence of a BYOD policy &#8211; to be implemented with employee buy-in, input, and trust, can have (depending on the size, scope of operations, and headcount of the employer) up to 11 (“eleven”) core elements that must be addressed.<span>  </span>I will now introduce these below.</p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="text-decoration:underline;"><span style="font-family:'Times New Roman', 'serif';">CORE ELEMENTS OF A BYOD POLICY</span></span><span style="font-family:'Times New Roman', 'serif';">:</span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">1.<span>         </span>S-ystems and Products.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">At the bare minimum, you must let all of your staff know which operating systems (Windows OS version(s), Mac OS, Linux kernel<a title="" href="#_ftn2" name="_ftnref2">[2]</a></span>), and which products (phones, tablets, laptops, desktops), will be supported as the designated personal work “device” under that BYOD policy.<span>  </span>It should not be a free-for-all with an anything goes and everything must be supported mentality.<span>  </span>That is a recipe for open revolt in the IT department for the undue configuration and compatibility challenges that this would impose.</p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">2.<span>         </span>P-rivacy.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">This is tricky, but it must be addressed.<span>  </span>To the extent that work information is accessible through the device or held on the device, then passwords must be shared with the employer.<span>  </span>Any employee who has a problem with this should quietly back-out of the policy, or ensure that nothing “untoward” is found or left on the device; because that password access should include acceptance of random audits and monitoring to ensure: (i) security protocols are being followed; (ii) comingling of personal and business data is not the norm; and (iii) employees are not engaging in other activities, including illicit activities, that might subject the BYOD (work) device to legal impoundment, or the data thereon to compulsory disclosure.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">3.<span>         </span>E-fficiency Enhancements.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Having likely configured the device to “play nice” with legacy systems and be interoperable across the employer’s IT space, there will be restrictions on what a device owner can and cannot load onto the device, post-configuration.<span>  </span>The BYOD policy should specify whether individuals can download updates on their own (some notifications can be malicious), or use an enterprise update and install function with regular logins and daily backups and syncs to a hard site.<span>  </span>This goes for both system upgrades as well as protective software (antivirus and antimalware).<span>  </span>Another question the policy might address, after taking an initial inventory of all programs and utilities on the device, is which ones can stay and which ones must go, as well as whether or not any favourite games or other utilities – sometimes hurriedly made with inadvertent vulnerabilities, and often needing far too much in the nature of system access and Admin. controls to “function properly” – can be added.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">4.<span>         </span>C-are and Custody.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">It should be heavily-stressed, that once a device has been proposed and accepted for inclusion under the policy, then the “owner” of the device is beholden to the data owner (being the employer, in the case of business proprietary information), and to the data subject (including the client or customer in the case of Personally Identifiable Information, and Personal Health Information and the like), for the care and custody of both the device, and all data that is on the device or accessible by means of the device.<span>  </span>The device “must” remain in the “sole” care and custody of the employee, and can no longer be used by a child to play games during downtime on a long journey, or as a reward for completing homework on time.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">5.<span>         </span>I-nformation.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">This section should remind employees that they will still need to adhere to any internal rules that required them to show a business need for any data before they could access it; as well as enforcing any Identity and Access Management procedures, and continued segregation of duties for working data (create, access, update, store, share, send, shred); system data (upload, download, wipe); and logs (write, access, edit, collate, wipe).<span>  </span>Tie-ins with other policies on information (confidentiality including passwords and proper screensaver and automatic sleep mode usage, social media usage, and regarding audits and internal investigations) can also be made here, or in other sections of the BYOD policy.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">6.<span>         </span>A-ccountability.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Appropriate logs should be maintained of all data accessed through and residing on the device, at all relevant times.<span>  </span>This will help track and assess the degree of loss, control the damage, tailor an appropriate response to the breach population, and otherwise comply with regulatory imperatives in the case of any data breach or corruption, or any device loss.<span>  </span>Of course, the “only” copy should never be held on just one portable device without it also being backed-up in several secure physical locations.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">7.<span>         </span>L-egal.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">While the employer will certainly lay-out those things for which the employee will be responsible, in terms of policy violation, it should also take the opportunity to list those things for which it will neither accept nor assume responsibility.<span>  </span>Whether or not ultimately successful should a claim or claims arise, these might include distracted driving or walking or flying or riding, repetitive stress syndrome, and unlawful or antisocial behaviour (bullying, cyberbullying, sexting, IP infringement, or online defamation).</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Clear defense and indemnification provisions would not be out of order; along with: (i) some form of funding for the employer’s personal device use; (ii) stated and mutually understood to be consideration for accepting the policy as a binding agreement; and (iii) coupled with some employee contribution therefrom into a pool from which BYOD, privacy, and other advisable liability insurance coverages would be secured with the employer as beneficiary.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">8.<span>         </span>I-mplementation.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Here, the employer would give additional rationales for the policy, its scope, its purpose, and its importance to the organization as a whole and its mission, in particular.<span>  </span>Along with a preamble at the start of the policy, this section would be key to achieving buy-in at all levels, and for demonstrating the entity’s commitment at the highest levels, to ensuring that the policy was both welcome and workable.<span>  </span>Any staggered implementation or other pertinent details on how the policy would be managed and modified from time to time or with changing laws &#8211; and with employee input, might also be disclosed. A few words on enforcement, and the reporting and investigation of suspected policy violations should also be included here.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">9.<span>         </span>Z-one of Control.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">This section would further delineate a “zone of control” (ZOC) within which the employer reserves a right to act with or without notice to employees, and that the employees accept that as a bargained-fact.<span>  </span>This ZOC would include matters with regard to internal investigations (it is not always best to warn a target); for reasons of Law Enforcement &amp; National Security (with or without stating specific provisions, but reminding all subscribers/adherents to a BYOD policy that laws of the employer’s originating jurisdiction – including export restrictions and generalized trade or directed sanctions &#8211; may also apply); and in the case of contingencies (for example, where employees in areas under actual, threatened, or suspected terror attack, or who’se devices show impending travel further afield than authorized, may find that sensitive data has been remotely wiped from those devices, or that they have been remotely locked, as a security precaution).<span>  </span>Less draconian but still useful in ZOC, of course, are wide and public sms alerts.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">10.<span>       </span>E-ncyption.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Encryption has recently been touted as the be all and end all of security solutions with regard to data in static situ, in mobile situ, and in transit – whether by email or as accessible through some Cloud platform.<span>  </span>While it is true that encryption has a part to play, what is the use of it when the device has a stored profile that contains one or several of the “current” encryption keys?<span>  </span>In addition, some jurisdictions may offer safe harbors that limit or even avoiding breach disclosures when the lost or stolen data is sufficiently encrypted or anonymized to make it indecipherable, and moving the protection closer to or onto the data itself, may also serve to limit the ability of an intruder that penetrates the outer layer(s) of enterprise protection, to retrieve and retreat with, anything useful from within the firewall or data stream.<span>  </span>Some have called this a “Secure Breach” state.<a title="" href="#_ftn3" name="_ftnref3">[3]</a></span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">11.<span>       </span>D-ecommissioning and Disposal.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Both disposal of the data, and the decommissioning or disposal of the device need to be better and closely managed.<span>  </span>Deletion does not always remove every trace of the data.<span>  </span>Indeed, sometimes it is very easy to recover in the right hands, and with the appropriate tools.<span>  </span>There must be an accepted understanding that devices will not be traded-in for upgrades or environmental credits without first being run through a wringer (in-house or outsourced) to ensure that they are truly clean.<span>  </span>As the BYOD phenomenon gains pace, stability, and defined structures, a burgeoning business in such “outsourced pre-cleans” will likely develop.<span>  </span>The results of lax cleans prior to disposal range from the embarrassing,<a title="" href="#_ftn4" name="_ftnref4">[4]</a></span> to the quite disastrous.<a title="" href="#_ftn5" name="_ftnref5">[5]</a></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="text-decoration:underline;"><span style="font-family:'Times New Roman', 'serif';">SUMMARY</span></span><span style="font-family:'Times New Roman', 'serif';">:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">BYOD adds significantly more attack surface to an entity’s vulnerability matrix, and offers myriad additional attack vectors.<span>  </span>The IT security space is constantly expanding ever further beyond the proverbial firewall, and evolving by running adaptation to meet multiple generations of threat at a time.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">A BYOD policy that addresses and covers the above points in sufficient depth and detail can still be and remain relevant, and protect both the employer and the employer’s data while educating the workforce.<span>  </span>But, this schema is by no means presented or intended as the last word, because change is a pure constant.</span></p>
<p class="MsoNormal">************************************************************************</p>
<p class="MsoNormal" style="text-align:justify;"><span style="text-decoration:underline;"><span style="font-family:'Times New Roman', 'serif';">Author</span></span><span style="font-family:'Times New Roman', 'serif';">:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and <i>GRC</i> – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.<span>  </span>He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.). <i>Please See</i>: </span><a href="http://www.ogalaws.com/"><span style="font-family:'Times New Roman', 'serif';color:blue;">http://www.ogalaws.com</span></a></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.<span>  </span><i>Please See</i>: </span><a href="http://www.simprime-ca.com/"><span style="font-family:'Times New Roman', 'serif';color:blue;">http://www.simprime-ca.com</span></a></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Backed by courses in management, organizational behaviour and micro-organizational behaviour, and a Certificate in Field Security from the United Nations Department of Safety and Security (UNDSS), in New York, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law &amp; Policy (National Security aspects).</span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic <i>IMPRIME</i> Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</span></b></p>
<p><b><i><span style="text-decoration:underline;"><span style="font-size:11pt;font-family:'Times New Roman', 'serif';">This article does not constitute legal advice or create any lawyer-client relationship.</span></span></i></b></p>
<div>
<hr align="left" size="1" width="33%" />
<div id="ftn1">
<p class="MsoFootnoteText"><a title="" href="#_ftnref1" name="_ftn1">[1]</a> <i>See e.g.</i> DoD IG Audit Report: DODIG-2013-060.<span>  </span><i>Information Assurance, Security, and Privacy: Improvements Needed with Tracking and Configuring Army Commercial Mobile Devices</i>.<span>  </span>Published by United States Department of Defence, March 26, 2013, on dodig.mil.<span>  </span>Online: &gt;<a href="http://www.dodig.mil/pubs/report_summary.cfm?id=5082">http://www.dodig.mil/pubs/report_summary.cfm?id=5082</a>&lt;</p>
</div>
<div id="ftn2">
<p class="MsoFootnoteText"><a title="" href="#_ftnref2" name="_ftn2">[2]</a> Open source elements and compilations should always be used with caution, as licensing protocols will differ.</p>
</div>
<div id="ftn3">
<p class="MsoFootnoteText"><a title="" href="#_ftnref3" name="_ftn3">[3]</a> SafeNet.<span>  </span><i>A New Security Reality: The Secure Breach</i>.<span>  </span>Published in 2013, on safenet-inc.com.<span>  </span>Online: &gt;<a href="http://www2.safenet-inc.com/securethebreach/downloads/secure_the_breach_manifesto.pdf">http://www2.safenet-inc.com/securethebreach/downloads/secure_the_breach_manifesto.pdf</a>&lt;<span>  </span></p>
</div>
<div id="ftn4">
<p class="MsoFootnoteText"><a title="" href="#_ftnref4" name="_ftn4">[4]</a> Shaun Waterman – The Washington Times.<span>  </span><i>Selling state secrets to North Korea? Japan sold hi-tech ship without wiping data</i>.<span>  </span>Published April 29, 2013, on washingtontimes.com.<span>  </span>Online: &gt;<a href="http://www.washingtontimes.com/news/2013/apr/29/japans-coast-guard-sold-hi-tech-ship-north-koreans/%3c">http://www.washingtontimes.com/news/2013/apr/29/japans-coast-guard-sold-hi-tech-ship-north-koreans/</a>&lt;<span>  </span></p>
</div>
<div id="ftn5">
<p class="MsoFootnoteText"><a title="" href="#_ftnref5" name="_ftn5">[5]</a> Amar Toor.<span>  </span><i>NASA Accidentally Sells Off Computers With Sensitive Data</i>. <span> </span>Published December 8, 2010 on switched.com.<span>  </span>Online: &gt;<a href="http://www.switched.com/2010/12/08/nasa-accidentally-sells-off-computers-with-sensitive-data/">http://www.switched.com/2010/12/08/nasa-accidentally-sells-off-computers-with-sensitive-data/</a>&lt;<span>  </span></p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/530/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/530/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=530&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/05/21/byod-policy-with-trust-or-ignore-and-bust-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>Individual (allegedly) Wreaks Havoc with Former Employer – Another Teachable Moment in Infosec.</title>
		<link>http://ogalaws.wordpress.com/2013/05/16/individual-allegedly-wreaks-havoc-with-former-employer-another-teachable-moment-in-infosec-2/</link>
		<comments>http://ogalaws.wordpress.com/2013/05/16/individual-allegedly-wreaks-havoc-with-former-employer-another-teachable-moment-in-infosec-2/#comments</comments>
		<pubDate>Thu, 16 May 2013 02:44:16 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[disgruntled employee hacks back in]]></category>
		<category><![CDATA[IT change of control]]></category>
		<category><![CDATA[onboarding and offboarding]]></category>
		<category><![CDATA[segregation of duties]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=516</guid>
		<description><![CDATA[The story recently broke of an employee (former employee) who had high-level system access as a “software programmer and system manager”.  The allegation is that he retaliated after being passed-over for promotions, which led to his resignation in December, 2011; with a final day of work in January, 2012.[1]  According to a Criminal Complaint in [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=516&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>The story recently broke of an employee (former employee) who had high-level system access as a “software programmer and system manager”.  The allegation is that he retaliated after being passed-over for promotions, which led to his resignation in December, 2011; with a final day of work in January, 2012.<a title="" href="#_ftn1" name="_ftnref1"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:11pt;font-family:'Times New Roman', 'serif';">[1]</span></span></span></a>  According to a Criminal Complaint in the incident as filed by the Federal Bureau of Investigation (FBI) in the District Court for the Eastern District of New York, the accused had worked there for several years, and was actually “<i>one of two employees who were primarily responsible for ensuring that the software that drove the company’s manufacturing business—including its production planning, purchasing, and inventory control—operated efficiently</i>”,<a title="" href="#_ftn2" name="_ftnref2"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:11pt;font-family:'Times New Roman', 'serif';">[2]</span></span></span></a> showing just how much free system access he really had.  The estimate puts a cost to the former employer of his alleged activities at some $90,000.00 in damages.  Admittedly, it could have been significantly more than this.  That number is not insignificant.  However, we may or may not ever come to know whether it stopped there due to self-imposed limitation(s), or inability to do anything more destructive or wide-ranging due to security impediments.</p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">On to the questions:</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span class="comment-body"><span style="font-family:'Times New Roman', 'serif';">1. When someone with that kind of access departs, is it now necessary to change every single password of every single employee? </span></span></p>
<p class="MsoNormal" style="text-align:justify;"><span class="comment-body"><span style="font-family:'Times New Roman', 'serif';">2. Is that the same if you have high IT turnover?  Things can get pretty hectic in that case!</span></span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Bob<a title="" href="#_ftn3" name="_ftnref3"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:11pt;font-family:'Times New Roman', 'serif';">[3]</span></span></span></a> was an “<i>ongoing insiders</i>”.  The current accused is therefore a “<i>former insider</i>” and not a “<i>pure outsider</i>”, if looking at the situation from a purist perspective.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">3. Which of these three (ongoing insiders, former insiders, and pure outsiders) is now classified as the greater threat to employers and/or businesses in general?</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';"> </span></p>
<p><span class="comment-body"><span style="font-family:'Times New Roman', 'serif';">There is a sometimes quite intense ongoing debate on whether outside threats or inside threats are greater; but both sides of the debate, and naysayers who disdain such reductionism <i>per se</i> or prefer to focus on purer forms of quantification and categorization, all agree that the state of Infosec/Cybersec is complex and accelerating at a breakneck pace.  Events will doubtless continue to present teachable moments.  I say that an inside the firewall/outside the firewall categorization is helpful in quantifying the potential harm from various threat vectors on available attack surfaces, and planning to address them on a constant and consistent basis.  However, I also think that all threats can be adequately considered when: (a) you focus on achieving <span style="text-decoration:underline;"><em>buy-in</em></span> to the need for security protocols and adherence thereto at all levels of the organization; (b) you <em><span style="text-decoration:underline;">budget accordingly</span></em> for training, ERP, and the staff and tools to deal with the threat universe; and (c) you assiduously enforce <em><span style="text-decoration:underline;">best practices</span></em>, even when it makes (for some) their accessing of preferred apps. or sites inconvenient to impossible, or slows people down a little.  I call this cubing the B.<br />
</span></span></p>
<p class="MsoNormal" style="text-align:justify;"><span class="comment-body"><span style="font-family:'Times New Roman', 'serif';">The above-referenced and linked allegations remain allegations.  All parties are innocent until proven guilty in a court of law.</span></span></p>
<p><span style="font-family:'Times New Roman', 'serif';">**********************************************************</span></p>
<p class="MsoNormal"><span style="text-decoration:underline;"><span style="font-family:'Times New Roman', 'serif';">Author</span></span><span style="font-family:'Times New Roman', 'serif';">:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and GRC – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.).  <i>Please See</i>: </span><a href="http://www.ogalaws.com"><span style="font-family:'Times New Roman', 'serif';color:blue;">http://www.ogalaws.com</span></a></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: </span><a href="http://www.simprime-ca.com/"><span style="font-family:'Times New Roman', 'serif';color:blue;">http://www.simprime-ca.com</span></a></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Times New Roman', 'serif';">Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-family:'Times New Roman', 'serif';">Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic IMPRIME Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</span></b></p>
<p class="MsoNormal" style="text-align:center;" align="center"><b><i><span style="text-decoration:underline;"><span style="font-family:'Times New Roman', 'serif';">This article does not constitute legal advice or create any lawyer-client relationship.</span></span></i></b></p>
<div>
<hr align="left" size="1" width="33%" />
<div id="ftn1">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[1]</span></span></span> Mosi Secret.  <i>Ex-Worker Created Havoc With Hacking, U.S. Says</i>.  Published by The New York Times on nytimes.com, May 2, 2013.  Online: &gt;<a href="http://www.nytimes.com/2013/05/03/nyregion/ex-programmer-pleads-not-guilty-in-long-island-computer-hacking-case.html?_r=0&amp;adxnnl=1&amp;goback=.gde_1864210_member_238092418&amp;adxnnlx=1367770722-HJ313lwkhryqnKSNK09oJA&amp;pagewanted=print">http://www.nytimes.com/2013/05/03/nyregion/ex-programmer-pleads-not-guilty-in-long-island-computer-hacking-case.html?_r=0&amp;adxnnl=1&amp;goback=.gde_1864210_member_238092418&amp;adxnnlx=1367770722-HJ313lwkhryqnKSNK09oJA&amp;pagewanted=print</a>&lt;</p>
</div>
<div id="ftn2">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[2]</span></span></span> Federal Bureau of Investigation (FBI).  <i>Press Release.  Long Island Software Programmer Arrested for Hacking into Network of High-Voltage Power Manufacturer</i>.  Published by the FBI on fbi.gov, May 2, 2013.  Online: &gt;</p>
<p class="MsoFootnoteText"><a href="http://www.fbi.gov/newyork/press-releases/2013/long-island-software-programmer-arrested-for-hacking-into-network-of-high-voltage-power-manufacturer">http://www.fbi.gov/newyork/press-releases/2013/long-island-software-programmer-arrested-for-hacking-into-network-of-high-voltage-power-manufacturer</a>&lt;</p>
</div>
<div id="ftn3">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[3]</span></span></span> Ekundayo George.  <i>Cybersecurity: the Enemy is also (perhaps even more so), Within – the case of “Bob”</i>.  Published January 17, 2013, on ogalaws.com.  Online: &gt;<a href="http://ogalaws.wordpress.com/2013/01/17/cybersecurity-the-enemy-is-also-perhaps-even-more-so-within-the-case-of-bob/">http://ogalaws.wordpress.com/2013/01/17/cybersecurity-the-enemy-is-also-perhaps-even-more-so-within-the-case-of-bob/</a>&lt;</p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/516/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/516/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=516&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/05/16/individual-allegedly-wreaks-havoc-with-former-employer-another-teachable-moment-in-infosec-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>Tweaking Regulation FD for the social media age &#8211; is it time for a fuller Restatement?</title>
		<link>http://ogalaws.wordpress.com/2013/04/24/tweaking-regulation-fd-for-the-social-media-age-is-it-time-for-a-fuller-restatement-2/</link>
		<comments>http://ogalaws.wordpress.com/2013/04/24/tweaking-regulation-fd-for-the-social-media-age-is-it-time-for-a-fuller-restatement-2/#comments</comments>
		<pubDate>Wed, 24 Apr 2013 01:46:18 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Securities Regulation]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[AP tweet hacked]]></category>
		<category><![CDATA[best practices "hashtags" disclosure rules]]></category>
		<category><![CDATA[disclosing material nonpublic information]]></category>
		<category><![CDATA[Fake White House bomb tweet]]></category>
		<category><![CDATA[Netflix SEC Regulation FD]]></category>
		<category><![CDATA[Regulation Fair Disclosure Restatement]]></category>
		<category><![CDATA[Regulation FD for social media]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=500</guid>
		<description><![CDATA[In August, 2000, the United States Securities and Exchange Commission (the “Commission”) first published Regulation FD (17 C.F.R. §243.100 et seq.),[1] which read in pertinent part, that: (a) Whenever an issuer, or any person acting on its behalf, discloses any material nonpublic information regarding that issuer or its securities to any person described in paragraph [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=500&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;--></p>
<p><!--[if gte mso 9]&gt;--></p>
<p>In <b>August, 2000</b>, the United States Securities and Exchange Commission (the “Commission”) first published Regulation FD (17 C.F.R. §243.100 et seq.),<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[1]</span></sup></sup> which read in pertinent part, that:</p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(a) Whenever an issuer, or any person acting on its behalf, discloses any material nonpublic information regarding that issuer or its securities to any person described in paragraph (b)(1) of this section, the issuer shall make public disclosure of that information as provided in § 243.101(e): </span></i></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt 1.5in;"><a name="a_1"></a><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1) Simultaneously, in the case of an intentional disclosure; and</span></i></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt 1.5in;"><a name="a_2"></a><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(2) Promptly, in the case of a non-intentional disclosure.<sup><b><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[2]</span></sup></b></sup>  (Emphasis added)</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">In <b>August, 2008</b>, the Commission issued guidance that permitted the above disclosures to be made through company websites,<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[3]</span></sup></sup> with certain caveats and conditions.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Recently, on <b>April 2, 2013</b>, the Commission has again taken a step to address the advancements of (not so new anymore) media in allowing publicly-traded companies and other issuers to disclose material nonpublic information through the Facebook and Twitter<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[4]</span></sup></sup> social networking channels.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[5]</span></sup></sup></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">“We do not wish to inhibit the content, form, or forum of any such disclosure, and we are mindful of placing additional compliance burdens on issuers.  In fact, we encourage companies to seek out new forms of communication to better connect with shareholders”</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[6]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Here now, we have a treble conundrum – (a) what is the order of precedence of the many “forms of communication” or channels now available to issuers for such information releases; (b) which channels will each issuer even use; and (c) will/should there be any distinction in channels used by any issuer or any group or industry of issuers, for releases of different types of information??</span></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">“We believe that company disclosure should be more readily available to investors in a variety of locations and formats to facilitate investor access to that information. […] A company’s website is an obvious place for investors to find information about the company, and a substantial majority of large public companies already provide access to their Commission filings through their websites”</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[7]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">It therefore behooves the Commission to now go a little bit further in mandating that issuers – (a) define such an ordering or precedence of channels; (b) state which channels that they will use; and (c) address any distinctions in channel use for releases of different types of information.  Such mandate or guidance would better fit Regulation FD to the times and accord with the Commission ethos on disclosure, generally, and social media, specifically.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">            <b><span style="text-decoration:underline;">Currently Available Channels.</span></b></span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">In no particular order, I count 22 (“twenty-two”) channels through which issuers can make statements or otherwise regularly or occasionally disseminate information; whether or not material or public.  These are Blogs, Press Releases, Annual Reports, interim Regulatory Filings, Websites, RSS feeds, email alerts, sms/texts, Facebook, YouTube, Twitter, Teleconferences, Webinars, News Conferences, EDGAR, Annual Shareholder Meetings, and Electronic Shareholder Forums.  The foregoing number 17, and so the remaining 5 (“five”) channels will be introduced and described in more detail, below.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">            <b><span style="text-decoration:underline;">Suggested Macro-level (group) Ordering.</span></b></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">I would start by organizing these channels into 3 (“three”) groups:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) a <span style="text-decoration:underline;">Static Foundational group</span> (SF) of 4 channels – where information once placed, is generally there for the duration, and the medium can also serve as a repository for prior releases of information.  The four items here, would be the issuer’s <i>main Website</i> (with or without an attached static blog), the issuer’s <i>main Facebook page</i> (whether or not interactive), <i>EDGAR</i> (publicly accessible, United States Securities and Exchange Commission’s “Electronic Data Gathering, Analysis and Retrieval” system for issuer filings), and the issuer’s <i>Annual Reports</i> (which once released with their audited financial statements, are seldom amended or re-stated without very good cause);</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(ii) a <span style="text-decoration:underline;">Live Regulated group</span> (LR) of 6 channels – where the speakers are known and often seen, and the format is often interactive.  This includes the <i>Teleconference</i> (such as one with market Analysts), the <i>Webinar</i>, the <i>News Conference</i> (whether strictly for media or for all comers), the <i>Annual Shareholder Meeting</i>, and interactive <i>Electronic Shareholder Forums</i>.  A sixth channel in this group is the <i>interim Regulatory Filing</i>.  Although not interactive and possessing qualities of the SF group, interim Regulatory Filings can be more easily amended and can be either regular or irregular in their appearance, as per the specific filer or the industry of the filer.  I place them here because even though they are non-interactive, they are more “live regulated” than “static foundational”; similarly, Electronic Shareholder Forums are both interactive and virtual, but still highly regulated under applicable Securities Laws;</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iii) a <span style="text-decoration:underline;">Virtual Responsibility group</span> (VR) of 7+5 channels– where the speaker, author, or poster can be anyone specifically or apparently authorized to speak by or on behalf of the issuer, the audience is not restricted to persons with a direct interest in the issuer or the business of the issuer, and the consequences for material mis-statements or intentionally and misleadingly incomplete disclosures can be broad, international, and damaging in the extreme.  Despite these dangers, the medium is virtual and may potentially “go viral” with a quickness, and so self-regulation and corporate responsibility are more the norm.  This group includes <i>Twitter</i> (with a current character limit that cannot possibly accommodate both the message and all necessary and advisable disclaimers), <i>YouTube</i> (where hundreds of thousands, or even millions of “hits”/“views” can precede adult supervision and removal of the content in question), interactive or standalone <i>blogs</i>, <i>RSS feeds</i>, <i>email alerts</i>, <i>sms/texts</i>, and print or electronic <i>Press Releases</i>.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">The five remaining VR channels in an “EVR” sub-category, standing for “Enhanced” or heightened responsibility, are “C-suite” outlets, being:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) 2 channels in SF-C (<i>personal Facebook pages</i> and <i>personal websites</i>);</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(ii) 2 channels in VR-C (<i>personal Twitter accounts</i>, and <i>personal blogs</i>);</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iii) 1 grouped channel in LR-C (<i>book signings, CEO roundtables, economic fora, and outside and often-unscripted and unaccompanied conferences and other speaking engagements</i>).</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">            <b><span style="text-decoration:underline;">Suggested Micro-level (specific) Ordering?</span></b></span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">There appears to be good Commission precedent, indeed a preference, for using multiple sites, or ranking multiple channels as <i>“recognized channels of distribution”</i> for the dissemination of information.  As stated in the 2008 interpretive guidance on use of issuer websites:</span></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">“[…] where disclosure of information is required under the Exchange Act, we have allowed companies to make such information available to investors on their web sites with their web sites serving, depending on the circumstance, as a supplement to EDGAR, as an alternative to EDGAR, or as a stand-alone method of providing information to investors independent of EDGAR”</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[8]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Hence, on one interpretation of this sentence, so long as there is a central or reference site as a recognized channel on which the data is publicly posted and accessible, the data can also be posted elsewhere, on other similarly recognized channel(s) “reasonably designed to provide broad, non-exclusionary distribution of the information to the public”.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[9]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">            <span style="text-decoration:underline;">REFERENCE SITE</span> (Static Foundational):</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">For reference sites, I would suggest that co-equality be given to EDGAR, the issuer’s main website, and the issuer’s main Facebook page.  In this way, any or all could be used, deemed, and construed as categorically authoritative.  EDGAR, due to the regulatory filings made there; the issuer’s main website, due to its centrality and expected diligent maintenance; and the issuer’s main Facebook page, due to its popularity as a means to engage in 2-way communication with shareholders, customers, and the public at large.  This triple redundancy also covers for instances where either or both of EDGAR and the issuer’s main website may be inaccessible due to maintenance or unwanted intrusion, in which event a Facebook alert might be speedily issued and significant information releases in the interim period would rapidly there migrate; with the corollary for the issuer’s main website when both EDGAR and Facebook are unavailable.  Of course, issuers will need to ensure that their Facebook pages are pre-set to be fully open and accessible, including for those page visitors who are not Facebook subscribers – as there are still some people who have yet to sign-up, or who were signed-up but have now left.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">The Commission notes that issuers with large Analyst followings and market capitalizations may need to do little to alert the market to new postings on their websites, which will be rapidly picked up and disseminated by the financial press, but that those issuers with less of a following or market capitalization “may need to take more affirmative steps so that investors and others know that information is or has been posted on the company’s web site and that they should look at the company web site for current information about the company”.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[10]</span></sup></sup>  As an example for purposes of this proposal and comment, that might be a blog post, email alert, RSS feed, or tweet (in the VR group) detailing and alerting to the material as already posted on that issuer’s main website; or perhaps a teleconference, news conference, or interim regulatory filing (in the LR group) undertaking to post the materials on the issuer’s main website or another Reference Site at or by a set date and time.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">In the words of the Commission:</span></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">“If the information is important, companies should consider taking additional steps to alert investors and the market to the fact that important information will be posted – for example, prior to such posting, filing or furnishing such information to us or issuing a press release with the information. Adequate advance notice of the particular posting, including the date and time of the anticipated posting and the other steps the company intends to take to provide the information, will help make investors and the market aware of the future posting of information, and will thereby facilitate the broad dissemination of the information”</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[11]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">            <span style="text-decoration:underline;">VIRTUAL</span> (Virtual Responsibility, and Enhanced Virtual Responsibility):</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">It is important to state that blogs were specifically in the contemplation of the Commission when the 2008 guidance was issued, with the Commission opining at note 60, that <i>“[f]or purposes of Regulation FD, a posting on a blog, by or on behalf of the company, would be treated the same as any other posting on a company&#8217;s web site. The company would have to consider the factors outlined above to determine if the blog posting could be considered “public””</i>.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[12]</span></sup></sup>  A blog may highlight additional data on the Reference Site with appropriate wording, but a tweet will need to be very narrowly-tailored as a mere “tombstone” announcement or pointer arrow, in order to avoid attendant liability for omission of material facts in electronic and other disclosures under antifraud and related provisions of the Securities Act (1933), the Securities Exchange Act (1934) and their related Rules and Regulations as amended; and other applicable laws.  So long as the URL is correctly referenced by that tweet, then there should be no misstatement of material fact.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">In addition, the Commission was already considering the use of CEO blogs as far back as 2000, when it wrote: <i>“Company-sponsored “blogs,” which can include CEO blogs and investor relations blogs, among others, are recent additions to company web sites”</i>.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[13]</span></sup></sup>  The argument can therefore be made that based on this earlier guidance, a CEO blog with a large subscription base is analogous to an issuer’s main blog, and that a CEO Facebook page with a similarly large subscriber base is also akin to the issuer’s main Facebook page.  Hence, rather than competing, each may be considered and treated as a <i>“recognized channel of distribution”</i> in this VR group.  The Commission did not explicitly state or imply this reasoning, but from a cumulative reading of their guidance and a review of the specific facts of the Netflix Investigation, such an argument if made today, should certainly have strong merit.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">            <span style="text-decoration:underline;">LIVE</span> (Live Regulated):</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">As stated earlier, the speakers at a news conference or at an annual shareholders’ meeting are always seen, and very often quite well-known to the audience.  So too, the corporate author of an interim regulatory filing is easily discernible – even if the document is filed by accountants, auditors, or legal counsel.  Things can be a little different with electronic shareholder forums, where nobody is seen or heard – but their words are; with teleconferences, where the speaker is a disembodied voice; and with webinars, where audience members may or may not know enough about the presenters to be able to put a name to a face.  However, due to their very public nature and the likelihood that anything or everything said will be rapidly analyzed and acted-upon by investors, all of these live instances are tightly regulated when involving issuers.  There are legal and commonsense limits on: (i) what may be said that is not certain (speculation and inaccuracy); (ii) what may be predicted that is not guaranteed (earnings estimates and guidance, whether qualitative or quantitative); (iii) work or negotiations recently commenced or in progress (contract negotiations that may or may not close, significant milestones projected or reached, and significant contracts or other engagements secured); and (iv) the type and extent of disclaimers that must accompany forward-looking data, in general.  Thanks to the open-access that members of the public have to EDGAR, interim regulatory flings can also be picked-up, analyzed, and acted-upon quite rapidly.  As a result, the importance of ensuring that information publications and disseminations in all channels of this group are accompanied by one or more of (a) alerts to their release; or (b) timely publication and dissemination of the same actual information through either or both of the other channel groups (SF or VR), is shown here with the greatest of clarity.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">            <span style="text-decoration:underline;">Channel Disclosure Sequencing</span>:</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Now, knowing what is where, let us consider the following relationship matrix for this schema.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<table class="MsoNormalTable" style="border-collapse:collapse;" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">SF</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">LR</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">VR</span></p>
</td>
</tr>
<tr>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">First Disclosure</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
</td>
</tr>
<tr>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">SF</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">1</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">2=</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">2=</span></p>
</td>
</tr>
<tr>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">LR</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">2=</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">1</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">2=</span></p>
</td>
</tr>
<tr>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">VR</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">2=</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">2=</span></p>
</td>
<td style="width:95.75pt;padding:0 5.4pt;" valign="top" width="128">
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">1</span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Following this sequencing table:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) Where information is first disclosed in a Static Foundational (SF) channel, alerts as to this disclosure (whether intentional or unintentional) should be timely posted or the original information should be disclosed, in either or both of a Live Regulated (LR) channel and a Virtual Responsibility (VR) channel (including the three Enhanced Virtual Responsibility channels).</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(ii) Where information is first disclosed in a Live Regulated (LR) channel, alerts as to this disclosure (whether intentional or unintentional) should be timely posted or the original information should be disclosed, in either or both of a Static Foundational (SF) channel and a Virtual Responsibility (VR) channel (including the three Enhanced Virtual Responsibility).</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iii) Where information is first disclosed in a Virtual Responsibility (VR) Channel (whether or not “Enhanced”), alerts as to this disclosure (whether intentional or unintentional) should be timely posted or the original information should also be disclosed, in either or both of a Static Foundational (SF) channel and a Live Regulated (LR) channel.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Each case must be judged on its own merits, as the Commission so rightly states.  However, with the ability to interlink and cross-post or simul-post on social media accounts, it is not impossible for a Facebook or blog-happy C-Suite member to simultaneously or shortly thereafter tweet a quick link of the posting that can be caught by and posted on, the issuer’s main website, blog, or Facebook page – with or without an added human intermediary, but hopefully with prior clearance as to both postings, by the IR Director and legal counsel.  However, if a selective (VR tweet) disclosure of material non-public information follows a selective (webinar Q&amp;A or other unscripted LR) disclosure of the same, then the third SF group (Form 8-K in EDGAR, the issuer main website, and the issuer main Facebook page) will remain open for a corrective and “public” disclosure within the prescribed time limits, before greater liabilities and penalties can accrue.</span></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">“Indeed, one of the key benefits of the Internet is that companies can make information available to investors quickly and in a cost-effective manner”</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[14]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">It is notable that a number of print media houses are transitioning fully or preferably to an online format, making the speed at which they can issue story updates (and analyst updates in the financial press) as gleaned from issuer sources and sites, that much faster.  In addition, a tweet or a Facebook update costs practically nothing, financially, and the effort with the limited character content of the former, is negligible.  However, to follow-up on that short message, can be quite a challenge at times.  The speed of dissemination advantage for the disseminator, should not come at the expense of public convenience, or lead to confusion in that investors cannot determine where to look first, or where to look for the most definitive and most frequently and recently updated statement of a relevant situation, or guidance on an issuer’s financial position.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Channel Usage and Ranking for Disclosures</span></span><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">:</span></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">“We emphasize for issuers that the steps taken to alert the market about which forms of communication a company intends to use for the dissemination of material, non-public information, including the social media channels that may be used and the types of information that may be disclosed through these channels, are critical to the fair and efficient disclosure of information. Without such notice, the investing public would be forced to keep pace with a changing and expanding universe of potential disclosure channels, a virtually impossible task”</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[15]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">As the Commission had so rightly concluded, in order for this schema to function properly (i.e. to avoid forcing the investing public to spend time scrambling through channels in search of that information, while missing opportunities), issuers and non-issuers alike will need to state which of the 22 channels they will regularly use for their material and general disclosures in the three channel categories, in what order those channels might best be consulted, and which types of regulated information will be disseminated on which disclosure channels.  This sounds complicated, but categorizing the universe of potential regulated information – both day-to-day and for special situations, will likely assist.  I would propose just four such non-exhaustive categories of regulated information: (1) Availability of channels; (2) Market financial data; (3) Pending, planned, or public events; and (4) Significant public announcements.  To avoid repetition, these will be defined further in the below draft format of a re-stated Regulation FD.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><b><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Collective “<i>hashtags</i>” Rules for these 22 Channels.</span></span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">In order to work towards steady compliance with the various standards that may be applicable to the making of statements, generally, and information management in particular (always consult legal counsel for your specific situation and jurisdiction), entities – issuers and non-issuers alike, might further consider the <i>“hashtags”</i> rules, which read as follows.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">H</span></span></i></b><b><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">—ardware and bandwidth</span></i></b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> considerations and ERP should be tailored to such factors as issuer market capitalization, number of shareholders, and likelihood of an event that might precipitate a spike in web traffic;</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">A</span></span></i></b><b><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">-ccess and acceptance logs</span></i></b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> (with periodic counts and inventory of linkers, likers, subscribers, and followers and so forth), to show the degree to which a site is accessed by investors, the markets, and the media (all being and remaining subject to the <i>“do not track me”</i>, or <i>“please forget me”</i>, and other such evolving digital rights that may butt against it), may also be desirable to establish and maintain;</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">S</span></span></i></b><b><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">-Structure, Sincerity, and Security</span></i></b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">, means that the policies and procedures at the issuer should be designed to ensure: (i) <i><span style="text-decoration:underline;">Structure</span></i> &#8211; appropriate disclosure controls and procedures should be in place and enforced, and only certain persons should be authorized and trained to release information and represent the issuer online, and monitored and re-trained as needed on an ongoing basis; (ii) <i><span style="text-decoration:underline;">Sincerity</span></i> &#8211; facts and figures should not be released unless verifiable or otherwise justifiable, and positions should not be taken that are subject to serious challenge as insincere or in violation of applicable securities or other law; and (iii) <i><span style="text-decoration:underline;">Security</span></i> &#8211; significant care should be taken to guard against hacking and spoofing, hijack, DDoS attack and the like, as well as premature or inappropriate information release, the posting of damaging messages by activists<span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[16]</span></span></span> or disgruntled employees as purportedly from the issuer, or other lapse or mishap;</span></p>
<p class="MsoNormal" style="text-align:justify;margin:0 1in .0001pt;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">“Since all communications made by or on behalf of a company are subject to the antifraud provisions of the federal securities laws, companies should consider taking steps to put into place controls and procedures to monitor statements made by or on behalf of the company on these types of electronic forums”</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[17]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">H</span></span></i></b><b><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">-yperlinks</span></i></b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> should be: (i) avoided if to information an issuer knew or should have known was materially false or misleading; and (ii) otherwise used with linking explanations or rationales, responsibility disclaimers (to the extent a linking issuer wasn’t involved or “<span style="text-decoration:underline;">entangled</span>” in the preparation of the linked information), content disclaimers (to the extent a linking issuer does not explicitly or implicitly endorse, approve, or otherwise “<span style="text-decoration:underline;">adopt</span>” the linked information), and (iii) if possible, exit notices or standalone intermediate screens preceding access to linked data offsite;<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[18]</span></sup></sup></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">T</span></span></i></b><b><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">-raditional channels and Talking-points</span></i></b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">, means that the issuer should continue to use traditional channels alongside social media channels, in order to: (i) properly control and coordinate its Public Relations and Investor Relations (PR/IR) functions; (ii) maintain consistency of message, brand, and information release procedures across all channels used; and (iii) retain the capacity and credibility to speedily correct erroneous information released, and make the necessary subsequent public releases, following the intentional or inadvertent release of material nonpublic information.<sup><sup><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[19]</span></sup></sup>  Failure to maintain use of traditional channels may subject an issuer to allegations of discrimination or lack of notice by those “non-avid” new media users, or those who prefer primary reliance on print and broadcast media for their news &amp; current affairs;</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">A</span></span></i></b><b><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">-lways date</span></i></b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">- (and where advisable, also time-) stamp new releases, or as “last modified”; and archive older material separately, but in searchable or browsable format, so as to avoid any confusion regarding the precedence of the data and statements contained therein, and to maintain safe harbor protections against re-publication of previously published and posted (historical) materials or statements – absent some “affirmative restatement or reissuance” of same, which may invoke antifraud legal proscriptions and an affirmative duty to clarify and/or update them;</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">G</span></span></i></b><b><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">-enerate distance</span></i></b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">, always, from third-party posts and statements in online and interactive fora such as Shareholder fora, especially mis-statements; and always remind other participants that silence does not equate agreement, consent, or endorsement, and of the forum’s terms of use (which should never precondition usage on participant waiver of their securities law protections);</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">S</span></span></i></b><b><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">-ummaries, Propriety, Overviews, and Tombstones</span></i></b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">, means that each and all of these should be appropriately delineated as such (with titles, added explanatory language and terms, or website placement and display in close proximity to hyperlinks to the underlying material, where appropriate), and clear directions to readers on where and how to access the underlying information on which they are based.  In addition, the propriety (of content, manner, and timing) should always be vetted prior to release in seeking the advice of counsel, which is an indicia of good faith and best efforts in attempting compliance with Regulation FD; and any other data necessarily disclosed so as to make those summaries not materially misleading, confusing, or incomplete, should be disclosed with the release, or timely thereafter with prior notice to expect it – especially (if possible) within the limited character sets of tombstone releases via Twitter.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">A Restated Regulation FD, as re-vamped per the above considerations, may well resemble the following markup:</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">*************************************************</span></p>
<p class="MsoNormal"><b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">§ 243.100 General rule regarding selective disclosure. </span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(a) Whenever an issuer, or any person acting on its behalf, discloses any material nonpublic information regarding that issuer or its securities to any person described in paragraph (b)(1) of this section, the issuer shall make public disclosure of that information as provided in § 243.101<i><span style="text-decoration:underline;">(k).</span></i>  <s>(e)</s>: </span></p>
<p class="MsoNormal" style="text-align:justify;"><s><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1) Simultaneously, in the case of an intentional disclosure; and </span></s></p>
<p class="MsoNormal" style="text-align:justify;"><s><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(2) Promptly, in the case of a non-intentional disclosure</span></s><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">. </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(b) </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_1"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1) Except as provided in paragraph (b)(2) of this section, paragraph (a) of this section shall apply to a disclosure made to any person outside the issuer: </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_1_i"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) Who is a broker or dealer, or a person associated with a broker or dealer, as those terms are defined in Section 3(a) of the Securities Exchange Act of 1934 (15 U.S.C. 78c(a)); </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_1_ii"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(ii) Who is an investment adviser, as that term is defined in Section 202(a)(11) of the Investment Advisers Act of 1940 (15 U.S.C. 80b-2(a)(11)); an institutional investment manager, as that term is defined in Section 13(f)(6)of the Securities Exchange Act of 1934 (15 U.S.C. 78m(f)(6)), that filed a report on Form 13F (17 CFR 249.325) with the Commission for the most recent quarter ended prior to the date of the disclosure; or a person associated with either of the foregoing. For purposes of this paragraph, a “person associated with an investment adviser or institutional investment manager” has the meaning set forth in Section 202(a)(17) of the Investment Advisers Act of 1940 (15 U.S.C. 80b-2(a)(17)), assuming for these purposes that an institutional investment manager is an investment adviser; </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_1_iii"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iii) Who is an investment company, as defined in Section 3 of the Investment Company Act of 1940 (15 U.S.C. 80a-3), or who would be an investment company but for Section 3(c)(1) (15 U.S.C. 80a-3(c)(1)) or Section 3(c)(7) (15 U.S.C. 80a-3(c)(7)) thereof, or an affiliated person of either of the foregoing. For purposes of this paragraph, “affiliated person” means only those persons described in Section 2(a)(3)(C), (D), (E), and (F) of the Investment Company Act of 1940 (15 U.S.C. 80a-2(a)(3)(C), (D), (E), and (F)), assuming for these purposes that a person who would be an investment company but for Section 3(c)(1) (15 U.S.C. 80a-3(c)(1)) or Section 3(c)(7) (15 U.S.C. 80a-3(c)(7)) of the Investment Company Act of 1940 is an investment company; or </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_1_iv"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iv) Who is a holder of the issuer&#8217;s securities, under circumstances in which it is reasonably foreseeable that the person will purchase or sell the issuer&#8217;s securities on the basis of the information. </span></p>
<p class="MsoNormal"><a name="b_2"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(2) Paragraph (a) of this section shall not apply to a disclosure made: </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_i"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) To a person who owes a duty of trust or confidence to the issuer (such as an attorney, investment banker, or accountant); </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_ii"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(ii) To a person who expressly agrees to maintain the disclosed information in confidence; </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_iii"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iii) In connection with a securities offering registered under the Securities Act, other than an offering of the type described in any of Rule 415(a)(1)(i) through (vi) under the Securities Act (§ 230.415(a)(1)(i) through (vi) of this chapter) (except an offering of the type described in Rule 415(a)(1)(i) under the Securities Act (§ 230.415(a)(1)(i) of this chapter) also involving a registered offering, whether or not underwritten, for capital formation purposes for the account of the issuer (unless the issuer&#8217;s offering is being registered for the purpose of evading the requirements of this section)), if the disclosure is by any of the following means: </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_iii_A"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(A) A registration statement filed under the Securities Act, including a prospectus contained therein; </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_iii_B"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(B) A free writing prospectus used after filing of the registration statement for the offering or a communication falling within the exception to the definition of prospectus contained in clause (a) of section 2(a)(10) of the Securities Act; </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_iii_C"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(C) Any other Section 10(b) prospectus; </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_iii_D"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(D) A notice permitted by Rule 135 under the Securities Act (§ 230.135 of this chapter); </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_iii_E"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(E) A communication permitted by Rule 134 under the Securities Act (§ 230.134 of this chapter); or </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="b_2_iii_F"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(F) An oral communication made in connection with the registered securities offering after filing of the registration statement for the offering under the Securities Act. </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[65 FR 51738, Aug. 24, 2000, as amended at 70 FR 44829, Aug. 3, 2005; 74 FR 63865, Dec. 4, 2009; 75 FR 61051, Oct. 4, 2010; 76 FR 71877, Nov. 21, 2011]</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">§ 243.101 Definitions.</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">This section defines certain terms as used in Regulation FD (§§ 243.100 -243.103).</span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="a"></a><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(a) Availability of channels.  “Availability of channels”, means with regard to any or all of the channels identified and defined under this § 243-101 wherein material nonpublic information and general company information may be discussed or disclosed, their status as available to the public for access, attendance, and consultation along with any restrictions or pre-conditions, or reasons for their non-availability to the extent it is known and/or prudent, with projected timelines for resumption of availability.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(b) Categories of regulated information.  “Categories of regulated information” as defined under this § 243-101, collectively and individually means, as described herein:</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1) Availability of channels.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(2) Market financial data.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(3) Pending, planned or public events.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(4) Significant public announcements.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(c) Channels.  “Channels”, collectively and individually means:</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1) A static foundational group, including as of or by the entity, a corporate website, a corporate blog, an annual report, and the Commission’s Electronic Data Gathering, Analysis and Retrieval (EDGAR) system.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(2) A live and regulated group, including as of or by the entity, any teleconference, webinar, news conference, annual shareholder meeting, electronic shareholder forum, or interim regulatory filing including restatements of interim and annual reports, that occurs between annual reports.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(3) A virtual responsibility group, including Twitter, YouTube, blogs, RSS feeds, email alerts, sms/texts, and print or electronic press releases.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(4) An enhanced virtual responsibility group, including as of or by the entity, any twitter account, blog, Facebook page, or personal website of a senior official or so closely identified with a senior official by sufficient members of the public to require its inclusion here, as well as any senior official book signing, roundtable, economic forum, or outside conference or speaking engagement.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Note (channels):</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">The Commission recognizes and notes that this listing is not exhaustive and remains subject to change with existing and developing technologies and business practices, and company Boards of Directors are encouraged to use their own business judgment in assessing which additional channels they will place in these above categories either as and when they appear or occur or arise, or before they appear or occur or arise.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(d) Channel usage and ranking for disclosures.  “Channel usage and ranking for disclosures”, shall mean the listing by an issuer of which of the channels identified herein it shall use for disclosing both general information and categories of regulated information, as well as for making general communications to investors, consumers, the markets and the public.  This listing shall be accompanied by a ranking of where to look first, second, third, and so forth, in issuers’ crafting and maintenance of systems that are reasonably designed to provide broad, non-exclusionary distribution of information to the public.  Such a channel usage and ranking for disclosures will prevent investing and other interested members of the public from having to scramble through multiple channels as defined herein, in search of critical and  time-sensitive categories of regulated information that others can more easily find and use to guide their decision-making.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(e)</span></span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> <s>(a)</s> <i>Intentional</i>. A selective disclosure of material nonpublic information is “intentional” when the person making the disclosure either knows, or is reckless in not knowing, that the information he or she is communicating is both material and nonpublic.</span></p>
<p class="MsoNormal"><a name="b"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(f)</span></span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> <s>(b)</s> <i>Issuer</i>. An “issuer” subject to this regulation is one that has a class of securities registered under Section 12 of the Securities Exchange Act of 1934 (15 U.S.C. 78l), or is required to file reports under Section 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. 78o(d)), including any closed-end investment company (as defined in Section 5(a)(2) of the Investment Company Act of 1940) (15 U.S.C. 80a-5(a)(2)), but not including any other investment company or any foreign government or foreign private issuer, as those terms are defined in Rule 405 under the Securities Act (§ 230.405 of this chapter). </span></p>
<p class="MsoNormal"><a name="c"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(g) Long weekend.  “Long weekend”, shall mean a weekend that due to a fixed or floating celebration or holiday or festive event recognized as a United States federal holiday, is at least 3 (“three”) days in length to add a Friday or a Monday or both, and during the full business days or the partial business days of which long weekend any 2 (“two”) of the New York Stock Exchange (NYSE) for all physically-trade securities, the National Association of Securities Dealers Automated Quotation (NASDAQ) system for securities of issuer’s regulated by the Commission, and the Chicago Board Options Exchange (CBOE) for all trading activities, are closed for business.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(h) Market financial data.  “Market financial data” means any earnings, financial projections and data, any changes to earnings or financial projections and data, any significant or notifiable trades or movements in the securities or instruments of the entity, and any and all regulatory filings with the United States Securities and Exchange Commission (SEC) or other domestic or foreign body of the same or similar competence.  This listing is not exhaustive and company Boards of Directors are encouraged to use their own business judgment in assessing which additional events and elements they will place in this category either as and when they appear or occur or arise, or before they appear or occur or arise.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) Pending, planned, and public events.  “Pending, planned, and public events” means any meeting of the Board of Directors or Shareholders, any public appearance or speaking engagement of a senior official of the entity as defined under this § 243.101, where material information may be discussed or disclosed (which engagement’s initial notification and the eventual attendance of persons may be conditioned on appropriate security considerations, advisories, and precautions), any real or virtual meeting with Analysts, any teleconference or press conference, any meeting of shareholders, and any other happening, prior to its happening, that the entity wishes to publicize or is required to publicize, subject to appropriate security considerations, advisories, and precautions.  This listing is not exhaustive and company Boards of Directors are encouraged to use their own business judgment in assessing which additional events and elements they will place in this category either as and when they appear or occur or arise, or before they appear or occur or arise.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(j)</span></span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> <s>(c)</s> Person acting on behalf of an issuer. “Person acting on behalf of an issuer” means any senior official of the issuer (or, in the case of a closed-end investment company, a senior official of the issuer&#8217;s investment adviser), or any other officer, employee, or agent of an issuer who regularly communicates with any person described in § 243.100(b)(1)(i), (ii), or (iii), or with holders of the issuer&#8217;s securities. An officer, director, employee, or agent of an issuer who discloses material nonpublic information in breach of a duty of trust or confidence to the issuer shall not be considered to be acting on behalf of the issuer. </span></p>
<p class="MsoNormal"><a name="d"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><s><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(d) Promptly. “Promptly” means as soon as reasonably practicable (but in no event after the later of 24 hours or the commencement of the next day&#8217;s trading on the New York Stock Exchange) after a senior official of the issuer (or, in the case of a closed-end investment company, a senior official of the issuer&#8217;s investment adviser) learns that there has been a non-intentional disclosure by the issuer or person acting on behalf of the issuer of information that the senior official knows, or is reckless in not knowing, is both material and nonpublic. </span></s></p>
<p class="MsoNormal"><a name="e"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(k)</span></span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> <s>(e)</s> Public disclosure. </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="e_1"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1) Except as provided in paragraph <del>(e)</del> <span style="text-decoration:underline;">(k)(3) and paragraph (k)(4)</span> of this section, an issuer shall make the “public disclosure” of information required by § 243.100(a) by furnishing to or filing with the Commission a Form 8-K (17 CFR 249.308) disclosing that information. </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="e_2"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(2) An issuer shall be exempt from the requirement to furnish or file a Form 8-K if it instead disseminates the information through another method (or combination of methods) of disclosure <i><span style="text-decoration:underline;">in accordance with its channel usage and ranking for disclosures and section (k)(3) or (k)(4), as appropriate,</span></i> that is reasonably designed to provide broad, non-exclusionary distribution of the information to the public.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Intentional Disclosures.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><a name="f"></a><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(3) Where the issuer becomes aware that material non-public information has been intentionally disclosed as defined in § 243.100(a), the issuer shall:</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) First make the information that was intentionally so disclosed available on a static foundational site:</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(A) Within 2 (“two”) hours if the original information was disclosed between 9:00 a.m. and 11:00 a.m. Eastern Standard Time on any trading day;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(B) Within 30 (“thirty”) minutes if the original information was disclosed between 11:00 a.m. and 3:00 p.m. Eastern Standard Time on any trading day;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(C) Within 1 (“one”) hour after the immediate next market opening, if the original information was disclosed between 3:00 p.m. and 6:00 p.m. Eastern Standard Time on any trading day;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(D) Within a reasonable time but not later than 2 (“two”) hours after the immediate next market opening, if the original information was disclosed between 6:00 p.m. and 9:00 a.m. Eastern Standard Time on any sequence of days that includes at least one trading day;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(E) Within the duration of that trading day where a trading day is expanded and more than 2 (“two”) full hours of that expanded trading day remain, or otherwise as under section (C) or (D) as appropriate;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(F) Within 72 (“seventy-two”) hours whether or not that sequence of days includes a trading day, if the original information was disclosed after the markets have closed or outside the preceding available timelines, or otherwise when commencement of the next trading day due to a long weekend or other eventuality is actually or projected to be in excess of 72 (“seventy-two”) hours distant;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(aa) Where an issuer has credible information verifiable by a third party that the intentional release of material nonpublic information has occurred as a result of technological malfeasance or intrusion, purported whistleblower action, activist leak, or criminality and otherwise qualifies under this section, the issuer may invoke this section in its public statements and refrain from the corrective disclosure required under this Regulation FD if it shall within 72 (“seventy-two”) hours of such a release apply to the Commission for a Commission Standalone Determination (CSD), and the Commission shall within an additional 72 (“seventy-two”) hours issue a binding determination with a manner and time for action and compliance, that either:</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1.1) the issuer shall not make the additional or corrective disclosures due to their potential to unduly publicize the workings of a pending internal investigation or law enforcement activity; to disclose a critical vulnerability in the national security or critical infrastructure; to potentially and adversely impact upon the fiscal viability or key activities of an issuer involved in functions of critical infrastructure or national security; or to adversely impinge upon competition or any pending merger, acquisition, or reorganization.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1.2) the issuer shall make the additional or corrective disclosures;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1.3) the issuer shall not make the additional or corrective disclosures pending further direction by the Commission on receipt by the Commission sine die of guidance on the issuer’s eligibility under (F)(aa)(1.1), from any or all of the Director of National Intelligence (DNI), or the Department of Homeland Security (DHS), the Federal Trade Commission (FTC), or the Presidency;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(ii) In any and all of (k)(3)(i)(A) through (k)(3)(i)(F) except (k)(3)(i)(F)(aa), the issuer shall also disclose on either or both of a live regulated channel and a virtual responsibility channel, notification of the location and the actual availability or pending availability of that material nonpublic information or a corrective disclosure within 12 (“twelve”) hours of the original release, whether or not the release occurs during a trading day or over a weekend or long weekend.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iii) In the case of (F)(aa), the issuer shall also disclose on either or both of a live regulated channel and a virtual responsibility channel, notification of the location and the actual availability or pending availability of the notification or other relevant information within 12 (“twelve”) hours before or after its original application for a CSD, and within 2 (“two”) hours after receipt of each subsequent item of guidance or direction from the Commission, whether or not the initial release occurs, or the CSD application or subsequent guidance or direction is received, during a trading day or over a weekend or long weekend.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Note: (Compliance burden):</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">With the advent and wide availability of mobile productivity tools and applications, the Commission does not see it as an undue burden for an issuer to be required to post material nonpublic information or any corrective disclosure after the intentional or unintentional release of material nonpublic information, either or both of which may well already be readily available to the senior officer responsible for the corrective disclosure as an email attachment or other portable document, to a given channel after a trading day or over a weekend or Long Weekend.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Non-intentional Disclosures.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(4) Where the issuer becomes aware that there has been a non-intentional disclosure of material non-public information as described in § 243.100(a), the issuer shall:</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) First alert investors to the non-intentional disclosure on either or both of a live regulated channel and a virtual responsibility channel, along with the anticipated location on a static foundational channel and a timeline for the pending availability of that material nonpublic information or any corrective disclosure on a static foundational channel, within 6 (“six”) hours of the original release on any trading day, and within 12 (“twelve”) hours of the original release on any weekend or Long Weekend;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(ii) The issuer shall thereafter make the information that was unintentionally disclosed, available on a static foundational site:</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(A) Within 2 (“two”) hours if the original information was disclosed between 9:00 a.m. and 11:00 a.m. Eastern Standard Time on any trading day;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(B) Within 30 (“thirty”) minutes if the original information was disclosed between 11:00 a.m. and 3:00 p.m. Eastern Standard Time on any trading day;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(C) Within 1 (“one”) hour after the immediate next market opening, if the original information was disclosed between 3:00 p.m. and 6:00 p.m. Eastern Standard Time on any trading day;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(D) Within a reasonable time but not later than 2 (“two”) hours after the immediate next market opening, if the original information was disclosed between 6:00 p.m. and 9:00 a.m. Eastern Standard Time on any sequence of days that includes at least one trading day;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(E) Within the duration of that trading day where a trading day is expanded and more than 2 (“two”) full hours of that expanded trading day remain, or otherwise as under section (C) or (D) as appropriate;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(F) Within 72 (“seventy-two”) hours whether or not that sequence of days includes a trading day, if the original information was disclosed after the markets have closed or outside the preceding available timelines, or otherwise when commencement of the next trading day due to a long weekend or other eventuality is actually or projected to be in excess of 72 (“seventy-two”) hours distant;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(aa) Where an issuer has credible information verifiable by a third party that the intentional release of material nonpublic information has occurred as a result of technological malfeasance or intrusion, purported whistleblower action, activist leak, or criminality and otherwise qualifies under this section, the issuer may invoke this section in its public statements and refrain from the corrective disclosure required under this Regulation FD if it shall within 72 (“seventy-two”) hours of such a release apply to the Commission for a Commission Standalone Determination (CSD), and the Commission shall within an additional 72 (“seventy-two”) hours issue a binding determination with a manner and time for action and compliance, that either:</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1.1) the issuer shall not make the additional or corrective disclosures due to their potential to unduly publicize the workings of a pending internal investigation or law enforcement activity; to disclose a critical vulnerability in the national security or critical infrastructure; to potentially and adversely impact upon the fiscal viability or key activities of an issuer involved in functions of critical infrastructure or national security; or to adversely impinge upon competition or any pending merger, acquisition, or reorganization.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1.2) the issuer shall make the additional or corrective disclosures;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1.3) the issuer shall not make the additional or corrective disclosures pending further direction by the Commission on receipt by the Commission sine die of guidance on the issuer’s eligibility under (F)(aa)(1.1), from any or all of the Director of National Intelligence (DNI), or the Department of Homeland Security (DHS), the Federal Trade Commission (FTC), or the Presidency;</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iii) In any and all of (k)(4)(ii)(A) through (k)(4)(ii)(F) except (k)(4)(ii)(F)(aa), the issuer shall also disclose on either or both of a live regulated channel and a virtual responsibility channel, notification of the location and the actual availability or pending availability of that material nonpublic information or a corrective disclosure within 12 (“twelve”) hours of the original release, whether or not the release occurs during a trading day or over a weekend or long weekend.</span></span></i></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iv) In the case of (F)(aa), the issuer shall also disclose on either or both of a live regulated channel and a virtual responsibility channel, notification of the location and the actual availability or pending availability of the notification or other relevant information within 12 (“twelve”) hours before or after its original application for a CSD, and within 2 (“two”) hours after receipt of each subsequent item of guidance or direction from the Commission, whether or not the initial release occurs, or the CSD application or subsequent guidance or direction is received, during a trading day or over a weekend or long weekend.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><s><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(f) Senior official. “Senior official” means any director, executive officer (as defined in § 240.3b-7 of this chapter), investor relations or public relations officer, or other person with similar functions. </span></s></p>
<p class="MsoNormal"><a name="g"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(l) Senior official.  “Senior official” means for purposes of this Regulation FD (§§ 243.100 -243.103) and with regard to an issuer, any member of the board of directors, any executive officer charged with overall administration or operations, any officer in charge of a principal business unit or division or function, including without limitation, contingencies, finance, human resources, information or technology systems, international operations, investor relations, legal affairs, logistics, marketing, public relations, regulatory compliance, sales, or any significant project or initiative or policymaking function, whether styled as a director, or a president or a vice-president, or otherwise, and including other senior officials with the same or similar functions in any subsidiary of the issuer, as well as the issuer and the issuer representative or issuer representatives as the case may be in a business combination or joint venture or consortium or coalition in which the issuer or a subsidiary of the issuer holds an overall voting position or a right to the gross or net receivables in excess of 15% (“fifteen”) percent of the total in any class or sub-class of instrument, whether or not contingent, evidencing a right to such voting position or a right to share in the gross or net receivables of a business combination or joint venture or consortium or coalition.  Any other officer or employee or authorized agent  of the issuer who is not a senior official by title or function but who has established what the issuer or a third-party may reasonably consider to be a significant following, readership, subscriber base or like status in the social or professional mileu whether through or as a demonstrably recognized channel of distribution for matters of or relating to the issuer, shall also be considered and treated by the issuer as a senior official for purposes of this Regulation FD.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(m)</span></span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> <s>(g)</s> Securities offering. For purposes of § 243.100(b)(2)<del>(iv)</del> [<em><span style="text-decoration:underline;">iii</span> - Dodd Frank, 10.4.2010</em>].</span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="g_1"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(1) Underwritten offerings. A securities offering that is underwritten commences when the issuer reaches an understanding with the broker-dealer that is to act as managing underwriter and continues until the later of the end of the period during which a dealer must deliver a prospectus or the sale of the securities (unless the offering is sooner terminated); </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="g_2"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(2) Non-underwritten offerings. A securities offering that is not underwritten: </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="g_2_i"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(i) If covered by Rule 415(a)(1)(x) (§ 230.415(a)(1)(x) of this chapter), commences when the issuer makes its first bona fide offer in a takedown of securities and continues until the later of the end of the period during which each dealer must deliver a prospectus or the sale of the securities in that takedown (unless the takedown is sooner terminated); </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="g_2_ii"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(ii) If a business combination as defined in Rule 165(f)(1) (§ 230.165(f)(1) of this chapter), commences when the first public announcement of the transaction is made and continues until the completion of the vote or the expiration of the tender offer, as applicable (unless the transaction is sooner terminated); </span></p>
<p class="MsoNormal" style="text-align:justify;"><a name="g_2_iii"></a><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(iii) If an offering other than those specified in paragraphs (a) and (b) of this section, commences when the issuer files a registration statement and continues until the later of the end of the period during which each dealer must deliver a prospectus or the sale of the securities (unless the offering is sooner terminated). </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(n) Significant public announcement.  “Significant public announcement” means any announcement or notification to the public that could be reasonably considered to impact the market in share price or trading volume of the securities of the issuer or otherwise impact upon the decision of any person or entity to invest or not invest in the issuer, including if internal to the issuer or an affiliate of the issuer any environmental events, legal and regulatory actions, investigations, incidents involving internal controls, or cyber incidents, and if external to the issuer and its affiliates but that the Board of Directors reasonably determines may have an impact in the chain of supply or the markets of the issuer or on the operations of the issuer, then any of the above events of any other entity or party or group or affiliation of entities or parties in any combination, in any place or jurisdiction, including any political event or events.  This listing is not exhaustive and Boards of Directors are encouraged to use their own business judgment in assessing which additional events and elements they will place in this category either as and when they appear or occur or arise, or before they appear or occur or arise.</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">(o) Trading day.  “Trading day” is defined as running from 9:30 a.m. to 4:00 p.m. Eastern Standard Time from Monday through and including Friday, in accordance with the regular business hours of the physical New York Stock Exchange (NYSE) in New York City, United States of America.  Any earlier cessation of trading on a trading day or any curtailment or expansion of a trading day whether planned or unplanned, shall be treated for purposes of this Regulation FD, as provided in this Regulation FD (§§ 243.100 &#8211; 243.103).</span></span></i></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">§ 243.102 No effect on antifraud liability. </span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">No failure to make a public disclosure required solely by § 243.100 shall be deemed to be a violation of Rule 10b-5 (17 CFR 240.10b-5) under the Securities Exchange Act.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">********************************************</span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><b><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Possible Approaches for Issuers and Non-issuers, alike.</span></span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Whether or not utilizing the above-presented schema and/or channel ordering, it would be prudent for issuers and non-issuers alike, to adopt some sort of channel usage and ranking for their disclosures, and post the same to standalone hard links or prominently within the legal &amp; disclaimers sections of their Static Foundational channels (website, Facebook, filings).</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">“We have since encouraged “honest, carefully considered attempts to comply with Regulation FD”</span></i><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">.  (Securities and Exchange Commission in <span style="text-decoration:underline;">Release No. 34-69279</span> of April 2, 2013, at page 2,<span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[20]</span>  citing to Report of Investigation Pursuant to Section 21(a) of the Securities Exchange Act of 1934: Motorola, Inc., <span style="text-decoration:underline;">Release No. 34-46898</span> (Nov. 25, 2002)).<span style="font-size:12pt;font-family:'Times New Roman', 'serif';">[21]</span></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Adopting the spirit of the foregoing (whether or not it becomes law), may become one such honest and carefully considered attempt to comply with Regulation FD in which investors and members of the general public can see the sequence of channels through which the most accurate, relevant, and timely words of an issuer or any other company might be disseminated, and consult these in order of precedence to determine the most current state of affairs.  Such an approach may assist in limiting certain liabilities for companies as they provide alerts to, release to, materially disclose to, update, and otherwise educate investors, market intermediaries, customers, and the public.  This will help stabilize markets at volatile times; growing Regulation FD compliance by ensuring no investor is unduly favored or unfairly disadvantaged in accessing <i>“material nonpublic information”</i> from or about a company; whether or not it is an “Issuer”.</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">**********************************************************</span></p>
<p class="MsoNormal"><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Author</span></span><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, public finance and state Blue Sky laws, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and GRC – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.).  <i>Please See</i>: <a href="http://www.ogalaws.com">http://www.ogalaws.com</a></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: <a href="http://www.simprime-ca.com/">http://www.simprime-ca.com</a></span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</span></p>
<p class="MsoNormal"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic IMPRIME Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</span></b></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';"> </span><b><i><span style="text-decoration:underline;"><span style="font-size:12pt;font-family:'Times New Roman', 'serif';">This article does not constitute legal advice or create any lawyer-client relationship.</span></span></i></b></p>
<hr align="left" size="1" width="33%" />
<div id="ftn1">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[1]</span></span></span> General Rule Regarding Selective Disclosure, also known as “<i>Regulation FD”</i> (Fair Disclosure).</p>
</div>
<div id="ftn2">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[2]</span></span></span> <i>Id</i>.</p>
</div>
<div id="ftn3">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[3]</span></span></span> United States Securities and Exchange Commission.  <i>Commission Guidance on the Use of Company Web Sites, Release No. 34-58288 (Aug. 7, 2008) (2008 Guidance)</i>.  Online: &gt;<a href="http://www.sec.gov/rules/interp/2008/34-58288.pdf">http://www.sec.gov/rules/interp/2008/34-58288.pdf</a>&lt;</p>
</div>
<div id="ftn4">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[4]</span></span></span> United States Securities and Exchange Commission.  <i>Report of Investigation Pursuant to Section 21(a) of the Securities Exchange Act of 1934: Netflix, Inc., and Reed Hastings.  <span style="text-decoration:underline;">Release No. 34-69279</span> / April 2, 2013</i>.  Online: &gt;<a href="http://www.sec.gov/litigation/investreport/34-69279.pdf">http://www.sec.gov/litigation/investreport/34-69279.pdf</a>&lt;</p>
</div>
<div id="ftn5">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[5]</span></span></span> <i>Id</i>. at 1, 4. This journey began when on July 3, 2012, Reed Hastings who is the Netflix CEO, posted the following on his personal Facebook page just before 11:00 a.m., Eastern time:</p>
<p class="MsoFootnoteText" style="text-align:justify;margin:0 103.5pt .0001pt 1in;"><i>Congrats to Ted Sarados, and his amazing content licensing team.  Netflix monthly viewing exceeded 1 billion hours for the first time ever in June.  When House of Cards and Arrested Development debut, we’ll blow these records away.  Keep going, Ted, we need even more!</i></p>
<p class="MsoFootnoteText" style="text-align:justify;">As (i) Netflix had not previously advised shareholders that the CEOs Facebook page would be used to make such announcements; because (ii) the CEO had not used his personal Facebook page to make such company-related announcements in the past; and (iii) as the Facebook announcement was neither accompanied by nor shortly thereafter followed by any Press Release, any announcement on the main Netflix Facebook page or website, or any interim Regulatory Filing (e.g. Form 8-K, which is an omnibus interim Regulatory Filing format), the Commission took issue and commenced an investigation.  Of note, the share price stood at $70.45 at the time of posting, and the markets closed 2 hours later at 1:00 p.m. for the 4<sup>th</sup> of July holiday.  Even though Reed Hastings had 200,000 + subscribers to his personal Facebook page at the time (including shareholders, analysts, bloggers, and reporters), the posted message only diffused slowly through regular and online social channels.  Despite this, the Netflix share price had still risen to $81.72 at the close of the first trading day after the July 4<sup>th</sup> holiday break.</p>
</div>
<div id="ftn6">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[6]</span></span></span> <i>Id</i>. at 5.</p>
</div>
<div id="ftn7">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[7]</span></span></span> United States Securities and Exchange Commission.  <i>Commission Guidance on the Use of Company Web Sites, Release No. 34-58288 (Aug. 7, 2008) (2008 Guidance)</i>, at 8-9.  Online: &gt;<a href="http://www.sec.gov/rules/interp/2008/34-58288.pdf%3c">http://www.sec.gov/rules/interp/2008/34-58288.pdf&lt;</a></p>
</div>
<div id="ftn8">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[8]</span></span></span> <i>Id</i>. at 12.</p>
</div>
<div id="ftn9">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[9]</span></span></span> <i>Id</i>. at 25.</p>
</div>
<div id="ftn10">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[10]</span></span></span> <i>Id</i>. at 21.</p>
</div>
<div id="ftn11">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[11]</span></span></span> <i>Id</i>. at 23.</p>
</div>
<div id="ftn12">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[12]</span></span></span> <i>Id</i>. at 26.</p>
</div>
<div id="ftn13">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[13]</span></span></span> United States Securities and Exchange Commission.  <i>Commission Guidance on the Use of Company Web Sites, Release No. 34-58288 (Aug. 7, 2008) (2008 Guidance)</i>, at 41.  Online: &gt;<a href="http://www.sec.gov/rules/interp/2008/34-58288.pdf">http://www.sec.gov/rules/interp/2008/34-58288.pdf</a>&lt;</p>
</div>
<div id="ftn14">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[14]</span></span></span> <i>Id</i>. at 6.</p>
</div>
<div id="ftn15">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[15]</span></span></span> United States Securities and Exchange Commission.  <i>Report of Investigation Pursuant to Section 21(a) of the Securities Exchange Act of 1934: Netflix, Inc., and Reed Hastings.  <span style="text-decoration:underline;">Release No. 34-69279</span> / April 2, 2013, at 7</i>.  Online: &gt;<a href="http://www.sec.gov/litigation/investreport/34-69279.pdf">http://www.sec.gov/litigation/investreport/34-69279.pdf</a>&lt;</p>
</div>
<div id="ftn16">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[16]</span></span></span> <i>See e.g.</i> CBC News.  <i>Fake White House bomb report causes brief stock market panic: Associated Press Twitter account hacked</i>.  Posted (and occurring) on April 23, 2013.  Online: &gt;<a href="http://www.cbc.ca/news/business/story/2013/04/23/business-ap-twitter.html">http://www.cbc.ca/news/business/story/2013/04/23/business-ap-twitter.html</a>&lt;</p>
</div>
<div id="ftn17">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[17]</span></span></span> <i>Supra</i> note 13 at 40-41.</p>
</div>
<div id="ftn18">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[18]</span></span></span> <i>Id</i>. at 32.</p>
</div>
<div id="ftn19">
<p class="MsoNormal"><span class="MsoFootnoteReference"><span style="font-size:10pt;"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[19]</span></span></span></span><span style="font-size:10pt;"> <i>See generally</i> </span><i><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">In the Matter of Secure Computing Corporation and John McNulty</span></i><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">, <span style="text-decoration:underline;">Release No. 34-46895</span> / November 25, 2002.  Online: &gt;</span><a href="http://www.sec.gov/litigation/admin/34-46895.htm"><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">http://www.sec.gov/litigation/admin/34-46895.htm</span></a><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">&lt; ; <span style="text-decoration:underline;">Litigation Release No. 17860</span> (<i>Securities and Exchange Commission v. Siebel Systems, Inc.</i> (Civil Action No. 1:02-CV02330 (JDB)).  Online: &gt;</span><a href="http://www.sec.gov/litigation/complaints/comp17860.htm"><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">http://www.sec.gov/litigation/complaints/comp17860.htm</span></a><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">&lt; ; <i>In the Matter of Siebel Systems, Inc.</i>, <span style="text-decoration:underline;">Release No. 34-46896</span> / November 25, 2002.  Online: &gt; </span><a href="http://www.sec.gov/litigation/admin/34-46896.htm"><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">http://www.sec.gov/litigation/admin/34-46896.htm</span></a><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">&lt; ;</span> <i><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">In the Matter of Raytheon Company and Franklyn A. Caine</span></i><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">, <span style="text-decoration:underline;">Release No. 34-46897 </span>/ November 25, 2002.  Online: &gt; </span><a href="http://www.sec.gov/litigation/admin/34-46897.htm"><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">http://www.sec.gov/litigation/admin/34-46897.htm</span></a><span style="font-size:10pt;font-family:'Times New Roman', 'serif';">&lt; </span></p>
</div>
<div id="ftn20">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[20]</span></span></span> <i>See Supra</i> note 15.</p>
</div>
<div id="ftn21">
<p class="MsoFootnoteText"><span class="MsoFootnoteReference"><span class="MsoFootnoteReference"><span style="font-size:10pt;font-family:'Calibri', 'sans-serif';">[21]</span></span></span> United States Securities and Exchange Commission.  <i>Report of Investigation Pursuant to Section 21(a) of the Securities Exchange Act of 1934: Motorola, Inc.  <span style="text-decoration:underline;">Release No. 34-46898</span> / November 25, 2002.  Online: &gt;</i><a href="http://www.sec.gov/litigation/investreport/34-46898.htm%3c">http://www.sec.gov/litigation/investreport/34-46898.htm&lt;</a></p>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/500/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/500/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=500&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/04/24/tweaking-regulation-fd-for-the-social-media-age-is-it-time-for-a-fuller-restatement-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>“e-Solid”: Constraints to Cloud Come-up, under the Current Nigerian System &amp; Status-Quo.</title>
		<link>http://ogalaws.wordpress.com/2013/04/12/e-solid-constraints-to-cloud-come-up-under-the-current-nigerian-system-status-quo/</link>
		<comments>http://ogalaws.wordpress.com/2013/04/12/e-solid-constraints-to-cloud-come-up-under-the-current-nigerian-system-status-quo/#comments</comments>
		<pubDate>Fri, 12 Apr 2013 04:15:31 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Nigerian Constitution and Regulations]]></category>
		<category><![CDATA[Outsourcing and Cloud Computing]]></category>
		<category><![CDATA[Cloud in Nigeria]]></category>
		<category><![CDATA[Cybersecurity in Nigeria]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=480</guid>
		<description><![CDATA[Comment in the discussion chain: Data Centers and Disaster Recovery in Nigeria. Started by moderator Christopher Odutola of the Linked in group: Cloud Computing, Virtualization and Disaster Recovery in Nigeria. Online: http://www.linkedin.com/groups/Data-Centers-Disaster-Recovery-in-3785575.S.43550562?view=&#38;srchtype=discussedNews&#38;gid=3785575&#38;item=43550562&#38;type=member&#38;trk=eml-anet_dig-b_pd-pmt-cn&#38;ut=1tsF8girXdkBI1 ********** Thank you, all for your highly knowledgeable and astute comments in this discussion so far.  We all know that as Nijas, we [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=480&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Comment in the discussion chain: <i>Data Centers and Disaster Recovery in Nigeria</i>.</p>
<p>Started by moderator Christopher Odutola of the Linked in group: <span style="text-decoration:underline;">Cloud Computing, Virtualization and Disaster Recovery in Nigeria</span>.</p>
<p>Online: <a href="http://www.linkedin.com/groups/Data-Centers-Disaster-Recovery-in-3785575.S.43550562?view=&amp;srchtype=discussedNews&amp;gid=3785575&amp;item=43550562&amp;type=member&amp;trk=eml-anet_dig-b_pd-pmt-cn&amp;ut=1tsF8girXdkBI1">http://www.linkedin.com/groups/Data-Centers-Disaster-Recovery-in-3785575.S.43550562?view=&amp;srchtype=discussedNews&amp;gid=3785575&amp;item=43550562&amp;type=member&amp;trk=eml-anet_dig-b_pd-pmt-cn&amp;ut=1tsF8girXdkBI1</a></p>
<p>**********</p>
<p>Thank you, all for your highly knowledgeable and astute comments in this discussion so far.  We all know that as Nijas, we have the talent and we have the skills to get things done – as you all show.  However … na conditions!!  I think 6 factors need to be addressed to some extent before the cloud can gain more credibility and traction in Nigeria, and even in Africa, and become “<b><i>e-Solid</i></b>”.</p>
<p><b><span style="text-decoration:underline;">“E”nergy</span></b> is number one.  Data centers need cooling (especially below the equator), and drives need energy to spin, access memory, and provide those virtual instances.  The idea of generators in series has merit, but I would say turbines are better – with all the natural gas we have flaring.  I always wonder why none of our unemployed Engineers have built scalable and modular mini-re refineries that can be used in the Niger Delta instead of all these open air burns; as used to feed or as combined with, modular and scalable mini-power stations.  We do have the labour, craftsmen, engineers, and natural resources.  Perhaps some of your banking and industrial contacts can be interested in seed funding.  Such machines will get plenty of interest in similarly challenged parts of the world.  It will take quite an effort to string functioning power lines everywhere, or bury them where there are already more people than spare ground.  I think localized modularity is the way to go, as opposed to regional and national power grids.</p>
<p><b><span style="text-decoration:underline;">“S”ecurity</span></b> has many facets.  One the one hand, it is the day to day matter of traveling to work while avoiding roadblocks, armed robbers, militants or <em>les beaucoup-harmers</em>, and drivers of trucks with no brakes, or of buses full of people and tankers full of petroleum or chemicals, who are not in their right minds due to some substance or other.  The 24/7 nature of IT will require people to travel back and forth at odd times,  unless you are there on 7-12 day on, and 7-12 day off shifts, or something like that.  Even then, you will have to switch-out at some point, and face the travel hazards.  The other facet of security is data security.  Are the sys-admins selling off data sniffed in transit; is the data entirely managed within Nigeria or are portions of the cloud external and therefore subjecting the data to the laws and sniffing of other jurisdictions; are Nigerians adequately protected from identity theft and loss of funds in the case of financial data transfers through the cloud?  These are all areas where Nigerian laws are pretty far behind, due to other priorities of our dear leaders – state and federal, and legislators.</p>
<p><b><span style="text-decoration:underline;">“O”versight</span></b> is also highly important.   There are a plethora of regulatory bodies, associations, commissions, and parastatals in Nigeria that have overlapping and complementary functions.  When people in position wake and realize that there is money to be made from taxing, regulating, and licensing the cloud, there will be a rush to assert jurisdiction.  Will it be from NCC (due to communications), CBN (due to financial transactions in the cloud), FRSC (due to data transportation on the information highway), NIMASA for the undersea telecommunications cables, each and every state government (due to data center location), EFCC (due to the potential problems within their competence), or any combination of the security agencies, due to the potential national security implications.  How easily can the Corporate Affairs Commission define which of the above types of business the CSP/CSV is engaging in, and how many lawsuits, pleas to the President, and examples public rudeness and misbehavior at the highest levels will Nigerian have to endure from those many competing regulatory interests?  I think a massive rationalization and realignment of Nigeria’s regulatory landscape is long overdue, but it may not happen while there are so many who benefit from the current alphabet soup of a conjoint twin octopus at a grand buffet, still eating to their heart’s content.  Other countries have established central fora, fusion centers, and similar councils where many bodies work together for the same goal.  In our case, that may take some time to achieve.</p>
<p><b><span style="text-decoration:underline;">“L”egal</span></b> is the logical follow-on, here.  There can be a self-regulatory body established for cloud service providers that enforces standards amongst peers, coordinates training and best practices, and works to lobby the government where and when needed.  Or, providers in the space can continue to work independently and accept whatever laws and regulations – no matter how contradictory, policy-somersault-laden, or otherwise non-conducive to sane and sustained business – are handed down from above.  Tips can be taken from what transpires with regard to the cloud outside Nigeria, but we should not be so fast to adopt things full force, that might not quite fit with our unique context.  We have seen many examples of this, as well as cases where countries accepted Constitutions and laws drafted by outsiders that were just plain wrong.</p>
<p>For example, the Warsaw Convention limits liability to air carriers in the case of a lost luggage, persons, or goods.  The Hamburg Rules perform a similar function with regard to carriage of goods by sea.  Those work well and are generally accepted for important service industries, when coupled with insurance.  Obviously, some lawyers can always be found to sue, despite the caps!  Attitudes change, however, when the protection is given to specialized industries and interests.  You have for example the Nuclear Liability Act in Canada, and the Price-Anderson Nuclear Industries Indemnity Act, in the United States – both limiting the liability of civilian nuclear installations for any incidents.  Most recently, on top of the refusal or inability of the United States Food and Drug Administration to force the labeling of genetically modified foods and food ingredients, President Obama still signed a Monsanto Protection Act on March 28, 2013 &#8211; <a href="http://rt.com/usa/monsanto-bill-blunt-agriculture-006/">http://rt.com/usa/monsanto-bill-blunt-agriculture-006/</a>.</p>
<p>A time may well come when the cloud industry becomes so large and all-pervasive that it will merit similar protections for all the data breach and failings we see with it in the western world – the first adopters.  However, if this happens in Nigeria before deposit insurance is taken and managed seriously (towards fewer vanishing premiums), a national identity system is firmly in place (towards fewer unusually expensive ghost workers), and business insurance and industry best practices are firmly adhered to, someone may pull a Cyprus without the government involvement.  The supposedly un-hackable Bitcoin was recently pilfered, and government should not help itself to personal bank accounts just because someone tells it to.  If the industry itself is protected, but the protection is not there or woefully inadequate for customers/consumers, some major problems could very well result.</p>
<p><b><span style="text-decoration:underline;">“I”nfrastructure</span></b> also needs a lot of work – whether roads and rails, buildings within which mobiles may or may not function, encryption and security of data in transit against SQL insertion and other malware exploits, and a lot more attention to such basic security as keeping programs and systems patched and up to date.  BYOD can mean both bring your own device and bring your own destruction, depending on what the device owner is knowingly or unknowingly carrying within it, or something to which the device attaches.  It is no secret that many government websites in Africa (not just Nigeria) are Trojan-laden.  This needs to be fixed, before Nations are cut-off from the outside and just go dark, due to the increasingly powerful antivirus and anti-malware programs that just block access to swathes of e-Estate, due to the real or alleged vulnerabilities that they represent.  Come on, guys and gals, we need to be able to reach you …. and there is no guarantee that VOIP will remain unaffected.  I cannot count the number of times that my system has refused to go somewhere – <i>somewhere legitimate thank you</i> – and then, I had to decide whether or not to disable the meguard and go there anyway.  This trend is already well-underway.  Even with all or most of the cell towers up, there should be backups in hard lines and satellites, because towers can still be taken down.  We need to get our act together and put in the kind of backup and redundancy of critical infrastructure that gives people a greater sense of confidence that things will work and continue to work when they are needed most.   With the near total absence of landlines, what happens to emergency calls when the cloud-based cellular service goes down?  Our infrastructure needs some serious work if we are to have the necessary bandwidth for greater cloud uptake (by SMBEs and conglomerates), deployment (in SaaS, PaaS, and IaaS configurations), and uptake (by the public and the powers that be); along with the other deficiencies here identified.</p>
<p><b><span style="text-decoration:underline;">“D”isaster</span></b> prevention, planning, response, and recovery is an obviously-ignored competence at the higher levels in Nigeria, due to the abundance of buildings and homes in flood plains – recurrently lost; the lack of an organized, national ambulance and air and water ambulance service – let alone fully-equipped, staffed, and functioning medical and dental facilities and pharmacies; poor attention to building standards, and road and rail traffic, maritime, and aviation vessel quality and facility maintenance; and the preponderant fire brigade approach with promises and prayers when things go horribly wrong.  Even where the cloud is proprietary, such as the example of your own VM instance on campus or at work, commonsense and best practices still advise the use in any combination, of <span style="text-decoration:underline;">off-cloud backup</span> (such as having your digital photos both in the cloud and on a physical USB stick that can create a mirror collection with rapid and relative ease – so long as not corrupted or lost), a <span style="text-decoration:underline;">substitute or backup cloud</span> (such as also storing them in another location and with another vendor,  perhaps as sent email attachments due to the current almost unlimited email storage capacity), <span style="text-decoration:underline;">offsite backup</span> (on a portable hard drive at a second physical location), and perhaps <span style="text-decoration:underline;">physical hardcopy prints</span> that can be laboriously scanned and uploaded, again, if and when all else fails.  Multiple redundancies are keys to data availability, reliability, and replicability, and all of the above need to be addressed before that can be more fully guaranteed with the appropriate high-uptime SLAs.</p>
<p>&nbsp;</p>
<p><span style="text-decoration:underline;"><strong>SUMMARY:</strong></span></p>
<p>In summary, unless the Nigerian cloud industry members, vendors, and workers want to be misled by the kind of <i>absentee and not quite technically competent as it is supposed to be or claims to be leadership</i> that has characterized so much of our experience in recent memory, they (and other like-minded professional bodies tired of waiting to be disappointed, yet again), will step-up to take the lead in their own best professional and practical interests, and the interests of all Nigerians at home, abroad, and as yet unborn, to organize, strategize, and familiarize themselves with global best practices, apply only what makes most sense with regard to local idiosyncrasies, and work to build local workarounds and custom solutions to the Nigerian situation that can waylay &amp; workaround the kind of Bigman and Bigwoman jealousy, grandstanding, and other examples of feferity and insincerity that I alluded to above; better insulating their businesses from marauders to make them <i>e-Solid</i>.</p>
<p>That’s my <del>N</del> 100;<s></s></p>
<p>I hope it helps.</p>
<p>************************************************************************</p>
<p><span style="text-decoration:underline;">Author</span>:</p>
<p>Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and <i>GRC</i> – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.). <i>Please See</i>: <a href="http://www.ogalaws.com/">http://www.ogalaws.com</a></p>
<p>He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: <a href="http://www.simprime-ca.com/">http://www.simprime-ca.com</a></p>
<p>Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</p>
<p><b>Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic <i>IMPRIME</i> Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</b></p>
<p align="center"><b><i><span style="text-decoration:underline;">This article does not constitute legal advice or create any lawyer-client relationship.</span></i></b></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/480/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/480/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=480&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/04/12/e-solid-constraints-to-cloud-come-up-under-the-current-nigerian-system-status-quo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>To Gatto from Zubulake: 2 Thumbs-up for Better Information Governance/Anti-Spoliation.</title>
		<link>http://ogalaws.wordpress.com/2013/03/31/to-gatto-from-zubulake-2-thumbs-up-for-better-information-governanceanti-spoliation/</link>
		<comments>http://ogalaws.wordpress.com/2013/03/31/to-gatto-from-zubulake-2-thumbs-up-for-better-information-governanceanti-spoliation/#comments</comments>
		<pubDate>Sun, 31 Mar 2013 20:36:43 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Business of Business]]></category>
		<category><![CDATA[Litigation & Discovery/eDiscovery]]></category>
		<category><![CDATA[Chief Judge Randall R. Rader]]></category>
		<category><![CDATA[eDiscovery]]></category>
		<category><![CDATA[ESI]]></category>
		<category><![CDATA[Gatto]]></category>
		<category><![CDATA[Information Governance]]></category>
		<category><![CDATA[Judge Shira A. Scheindlin]]></category>
		<category><![CDATA[Zubulake Revisited]]></category>
		<category><![CDATA[Zubulake V]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=473</guid>
		<description><![CDATA[SPOLIATION PARLAY: The Virginia wrongful death litigation of Lester v. Allied Concrete, in which cost sanctions[1] were awarded for spoliation of online evidence,[2] has a new compatriot in the New Jersey case of Gatto v. United Airlines.[3]  Counsel should be mindful when advising clients with regard to electronic evidence, and Judges are taking note and [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=473&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><b><span style="text-decoration:underline;">SPOLIATION PARLAY</span></b><b>:</b></p>
<p>The Virginia wrongful death litigation of <i>Lester v. Allied Concrete</i>, in which cost sanctions[1] were awarded for spoliation of online evidence,[2] has a new compatriot in the New Jersey case of <i>Gatto v. United Airlines</i>.[3]  Counsel should be mindful when advising clients with regard to electronic evidence, and Judges are taking note and increasingly ready to issue both adverse inference “spoliation instructions” along with steep monetary sanctions for spoliation of evidence due to a failure of Information Governance generally, and of document retention practices, specifically; especially in that exponentially expanding category of Electronically Stored Information (ESI).</p>
<p>One member of the Gartner Group has defined <b>Information Governance</b>, as “[…] <i>the specification of decision rights and an accountability framework to encourage desirable behavior in the valuation, creation, storage, use, archival and deletion of information.  It includes the processes, roles, standards and metrics that ensure the effective and efficient use of information in enabling an organization to achieve its goals</i>”.[4]</p>
<p>Focusing on the last 7 words of this definition “enabling an organization to achieve its goals”, winning the case should not come at the expense of sanctions that lead to a lost case, that wipe-out the award from a victory, or that leave the winner of a pyrrhic victory in the negative after paying a sanctions award to the losing but smiling party.  In at least one of the above cases of <span style="text-decoration:underline;">Lester</span> and <span style="text-decoration:underline;">Gatto</span>, Counsel had apparently advised the client to “clean-up” their Facebook, or something like that.  It is vitally important that Counsel get to grips and up to date with the expanding offerings of online social media tools, and their impacts on the litigation landscape, the document retention matrix, the scope of Professional Responsibility, and the cost of sanctions for spoliation and failures to produce.</p>
<p>“<b>Spoliation</b> is the destruction or significant alteration of evidence, or the failure to preserve property for another&#8217;s use as evidence in pending or reasonably foreseeable litigation”.[5] [emphasis added].</p>
<p><b><span style="text-decoration:underline;">THE STANDARDS, TODAY</span></b><b>:</b></p>
<p>As shown in <span style="text-decoration:underline;">Mosaid</span>,[6] <span style="text-decoration:underline;">Zubulake</span>,[7] and <span style="text-decoration:underline;">Goodyear</span>,[8] Not all Judges and Magistrate Judges, will see mere adverse inference instructions, which allow the errant side to still try their luck, enough of a deterrent.[9]  Indeed, with a January 15, 2010 opinion entitled <span style="text-decoration:underline;">Zubulake Revisited: Six Years Later</span>,[10] Judge Scheindlin clarified her thoughts on Information Governance and Discovery (e-Discovery) of Electronically Stored Information (ESI) by providing several solid, useful, bright line rules distinguishing between ESI lapses as negligence, willfulness, and gross negligence.</p>
<p>“[…], it is well established that <i>negligence</i> involves unreasonable conduct in that it creates a risk of harm to others, but <i>willfulness</i> involves intentional or reckless conduct that is so unreasonable that harm is highly likely to occur.”[11]</p>
<p>“<i>Gross negligence</i> has been described as a failure to exercise even that care which a careless person would use”.[12]</p>
<p>In addition to her analysis, Judge Scheindlin issues a clear caveat as follows “<i>[t]hese examples are not meant as a definitive list.  Each case will turn on its own facts and the varieties of efforts and failures is infinite</i>”.[13]  However, applying the above standards to specific steps of the litigation process, she continues in what I here condense and present as a handy cheat-sheet.</p>
<p>1. <span style="text-decoration:underline;">Preservation of Relevant Information</span>.</p>
<p>“A failure to preserve evidence resulting in the loss or destruction of relevant information is surely negligent, and, depending on the circumstances, may be grossly negligent or willful”.[14]</p>
<p>2. <span style="text-decoration:underline;">Intentional Hampering Acts</span> (*<i>author’s terminology</i>).</p>
<p>“[…] the intentional destruction of relevant records, either paper or electronic, after the duty to preserve has attached, is willful”.[15]</p>
<p>3. <span style="text-decoration:underline;">Issuance of a Litigation Hold</span>.</p>
<p>“Possibly after October, 2003, when <i>Zubulake IV</i> was issued, and definitely after July, 2004, when the final relevant <i>Zubulake</i> opinion was issued, the failure to issue a <i>written</i> litigation hold constitutes gross negligence because that failure is likely to result in the destruction of relevant information”.[16]</p>
<p>4. <span style="text-decoration:underline;">Collection and Review</span>.</p>
<p>“[…] depending on the extent of the failure to collect evidence, or the sloppiness of the review, the resulting loss or destruction of evidence is surely negligent, and, depending on the circumstances may be grossly negligent or willful.  For example, the failure to collect records – either paper or electronic – from key players constitutes gross negligence or willfulness as does the destruction of email or certain backup tapes after the duty to preserve has attached”.[17]</p>
<p>5. <span style="text-decoration:underline;">Litigation Dragnets</span> (*<i>author’s terminology</i>).</p>
<p>“By contrast, the failure to obtain records from <i>all</i> employees (some of whom may have had only a passing encounter with the issue in the litigation), as opposed to key players, likely constitutes negligence as opposed to a higher degree of culpability”.[18]</p>
<p>6. <span style="text-decoration:underline;">Additional Preservation Measures</span> (*<i>author’s terminology</i>).</p>
<p>“[…] the failure to take all appropriate measures to preserve ESI likely falls in the negligence category”.[19]</p>
<p>7. <span style="text-decoration:underline;">Assessing the Relevance and Prejudice of Spoliated Evidence</span> (*<i>author’s terminology</i>).</p>
<p>“[…] for more severe sanctions – such as dismissal, preclusion, or the imposition of an adverse inference – the court must consider, in addition to the conduct of the spoliating party, whether any missing evidence was relevant and whether the innocent party has suffered prejudice as a result of the loss of evidence”.[20]</p>
<p>8. <span style="text-decoration:underline;">Presumptions of Relevance; Jury Instructions</span> (*<i>author’s terminology; emphasis added</i>).</p>
<p>“Where a party destroys evidence in <b>bad faith</b>, that bad faith alone is sufficient circumstantial evidence from which a reasonable fact finder could conclude that the missing evidence was unfavourable to that party”.[21]</p>
<p>In the extreme, <b>willful or bad faith conduct</b> can bring jury instructions “that certain facts are deemed admitted and must be accepted as true”; in the mid-range, <b>willful or reckless conduct</b> may bring jury instructions imposing a “mandatory but rebuttable” presumption.[22]</p>
<p>At the baseline-level, an instruction may issue that “<i>permits</i> (but does not require) a jury to <i>presume</i> that the lost evidence is both relevant and favorable to the innocent party.  If it makes this presumption, the spoliating party’s rebuttal evidence must then be considered by the jury, which must then decide whether to draw an adverse inference against the spoliating party”.[23]</p>
<p>9. <span style="text-decoration:underline;">Fitting the Sanction to the Conduct/Misconduct</span> (*<i>author’s terminology</i>).</p>
<p>“It is well accepted that the court should always impose the least harsh sanction that can provide an adequate remedy.  The choices include – from least harsh to most harsh – further discovery, cost-shifting, fines, special jury instructions, preclusion, and the entry of default judgment or dismissal (terminating sanctions).  The selection of the appropriate remedy is a delicate matter requiring a great deal of time and attention by a court.”[24]</p>
<p>10. <span style="text-decoration:underline;">When Terminating Sanctions are Appropriate</span> (*<i>author’s terminology</i>).</p>
<p>“However, a terminating sanction is justified in only the most egregious cases, such as where a party has engaged in perjury, tampering with evidence, or intentionally destroying evidence by burning, shredding, or wiping out computer hard drives”.[25]</p>
<p><b><span style="text-decoration:underline;">THE TAKEAWAY</span></b><b>:</b></p>
<p>♦<b><span style="text-decoration:underline;">A</span></b>ctively backup (all ESI systems of the client, of Counsel, and of the agents for each);</p>
<p>♦<b><span style="text-decoration:underline;">B</span></b>e comprehensive (in coverage scope: in-house systems, mobiles, external providers);</p>
<p>♦<b><span style="text-decoration:underline;">C</span></b>ommunicate duties (in advance and ongoing: Counsel to client; client to Counsel);</p>
<p>♦<b><span style="text-decoration:underline;">D</span></b>iligently enforce (client for Counsel oversight; Counsel to confirm compliance);</p>
<p>♦<b><span style="text-decoration:underline;">E</span></b>ducate fully your employees and agents (client-side, Counsel-side, and outside);</p>
<p>♦<b><span style="text-decoration:underline;">F</span></b>ix snafus, logjams, and communications failures as fast and fully as possible;</p>
<p>♦<b><span style="text-decoration:underline;">G</span></b>et professionals involved in your <i>Information Governance</i> plans <span style="text-decoration:underline;">very</span> early.</p>
<p>ESI is here to stay, and expanding in depth and breadth at an extreme pace; e-Discovery has caught-up, and is keeping up – at least in the Second Circuit and the Districts it comprises, and also in the United States Court of Appeals for the Federal Circuit.[26]  Counsel should follow-suit!</p>
<p>************************************************************************</p>
<p><span style="text-decoration:underline;">Author</span>:</p>
<p>Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and <i>GRC</i> – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.). <i>Please See</i>: <a href="http://www.ogalaws.com/">http://www.ogalaws.com</a></p>
<p>He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: <a href="http://www.simprime-ca.com/">http://www.simprime-ca.com</a></p>
<p>Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</p>
<p><b>Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic <i>IMPRIME</i> Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</b></p>
<p align="center"><b><i><span style="text-decoration:underline;">This article does not constitute legal advice or create any lawyer-client relationship.</span></i></b></p>
<div>
<hr align="left" size="1" width="33%" />
<div>
<p>[1] <span style="text-decoration:underline;">Lester v. Allied Concrete</span>, (Case No. CL08-150, and Case No. CL09-223), Final Order dated October 21, 2011 (Va. Cir. Ct. 2011). Online: &gt;<a href="http://www.scribd.com/doc/78439131/Lester-v-Allied-Concrete-CL08-150-102111-Final-Order">http://www.scribd.com/doc/78439131/Lester-v-Allied-Concrete-CL08-150-102111-Final-Order</a>&lt; The amount of the final sanction was a fees award of $722,000.00.</p>
</div>
<div>
<p>[2] <span style="text-decoration:underline;">Lester v. Allied Concrete</span>, (Case No. CL08-150, and Case No. CL09-223), Ruling dated September 1, 2011 (Va. Cir. Ct. 2011).  This ruling granted <i>inter alia</i>, a motion for sanctions (the party deleted Facebook photos then the account, and later swore under oath to never having done so, with their legal counsel further attesting that the client did not own a Facebook account); all after the other side had gotten wind of the account and requested production.  Online: &gt;<a href="http://valawyersweekly.com/vlwblog/files/2011/09/Lester-Hogshire-order.pdf">http://valawyersweekly.com/vlwblog/files/2011/09/Lester-Hogshire-order.pdf</a>&lt;</p>
</div>
<div>
<p>[3] <span style="text-decoration:underline;">Gatto v. United Air Lines, Inc</span>., No. 10-cv-1090, 2013 U.S. Dist. LEXIS 41909, slip op. at 11 (D.N.J. Mar. 25, 2013).  Ruling dated March 25, 2013.  Once again, a Facebook account had been improperly deleted after a production request and Order.  The Judge, here, (stating at note 1 on page 5 of the Judgement that there was no difference to him between mere “account deactivation” and “permanent account deletion” with regard to spoliation: “[…]<i>as either scenario involves the withholding or destruction of evidence [.]</i>”), ruled that an adverse inference instruction to the jury would suffice, and declined to impose a monetary sanction.  Online: &gt;<a href="http://www.technologylawsource.com/uploads/file/GattovUnitedAirLinesCaseNo10-cv-1090-DNJ.pdf">http://www.technologylawsource.com/uploads/file/GattovUnitedAirLinesCaseNo10-cv-1090-DNJ.pdf</a>&lt;</p>
</div>
<div>
<p>[4] Debra Logan, Research VP, Gartner Research.  <i>What is information Governance?  And Why is it So Hard?</i> Published on blogs.gartner.com, January 11, 2010.  Online: &gt;<a href="http://blogs.gartner.com/debra_logan/2010/01/11/what-is-information-governance-and-why-is-it-so-hard/">http://blogs.gartner.com/debra_logan/2010/01/11/what-is-information-governance-and-why-is-it-so-hard/</a>&lt;</p>
</div>
<div>
<p>[5] This definition was laid down by United States Circuit Judge Joseph M. McLaughlin, writing the February 12, 1999 judgement of a unanimous 2<sup>nd</sup> Circuit panel in <span style="text-decoration:underline;">West v. Goodyear Tire &amp; Rubber Co.</span>, 167 F3d 776, 779 (1999).  There, the 2<sup>nd</sup> Circuit remanded a case on finding that outright dismissal of Plaintiff’s negligence action for spoliation (disposing of the allegedly malfunctioning device) was too draconian a sanction.  It was followed by the Southern District of New York with United States District Judge Shira A. Scheindlin’s July 20, 2004 ruling in <em><span style="text-decoration:underline;">Zubulake v. UBS Warburg LLC</span></em>, 229 F.R.D. 422 (2004) – <i>sometimes also styled Zubulake V</i> &#8211; an employment discrimination case involving spoliation by failure to preserve and produce backup email tapes, that was itself a precedent in the guidance the Judge issued for future electronic discovery practices; as well as by the New Jersey District Court with the December 7, 2004 ruling of United States District Judge William J. Martini, in <span style="text-decoration:underline;">Mosaid Technologies v. Samsung Electronics</span>, 348 F.Supp.2d 332, 335 (D.N.J. 2004), also involving the spoliation of electronic evidence where the failure to specifically mention “emails” within/alongside a request for the production of “documents”, should not have permitted the non-production and willful destruction of those emails.</p>
</div>
<div>
<p>[6] <i>Id</i>. Online: &gt;<a href="http://www.clearwellsystems.com/e-discovery-blog/wp-content/uploads/2012/07/Mosaid-Technologies-Inc-v-Samsung-Electronics-Co-Ltd.pdf">http://www.clearwellsystems.com/e-discovery-blog/wp-content/uploads/2012/07/Mosaid-Technologies-Inc-v-Samsung-Electronics-Co-Ltd.pdf</a>&lt;</p>
</div>
<div>
<p>[7] <i>Supra</i> note 5.  Online :&gt;<a href="http://billdanielslaw.com/Forum/wp-content/uploads/2010/07/Zubulake-v-UBS-Warburg-LLC1.pdf">http://billdanielslaw.com/Forum/wp-content/uploads/2010/07/Zubulake-v-UBS-Warburg-LLC1.pdf</a>&lt;</p>
</div>
<div>
<p>[8] <i>Supra</i> note 5.  Online: &gt;<a href="https://bulk.resource.org/courts.gov/c/F3/167/167.F3d.776.98-7324.html">https://bulk.resource.org/courts.gov/c/F3/167/167.F3d.776.98-7324.html</a>&lt;</p>
</div>
<div>
<p>[9] <i>See contra</i>, <span style="text-decoration:underline;">Gatto</span>, at note 3, <i>supra</i>, and accompanying text.</p>
</div>
<div>
<p>[10] Zubulake Revisited: Six Years Later (January 15, 2010 Amended Opinion and Order of United States District Judge Shira A. Scheindlin, in) <span style="text-decoration:underline;">Pension Committee of the University of Montreal Pension Plan v. Banc of America Securities, LLC</span>, No. 05 Civ. 9016 (SAS), 2010 WL 93124 (S.D.N.Y. Jan. 11, 2010).  Online: &gt;<a href="http://ralphlosey.files.wordpress.com/2010/01/05cv9016-january-15-2010-amended-opinion.pdf%3c">http://ralphlosey.files.wordpress.com/2010/01/05cv9016-january-15-2010-amended-opinion.pdf</a>&lt;</p>
</div>
<div>
<p>[11] <i>Id</i>. at page 7 of the 88 page Amended Opinion and Order.</p>
</div>
<div>
<p>[12] <i>Id</i>. at page 8.</p>
</div>
<div>
<p>[13] <i>Id</i>. at page 10.</p>
</div>
<div>
<p>[14] <i>Id</i>. at pages 8-9.</p>
</div>
<div>
<p>[15] <i>Id</i>. at page 9.</p>
</div>
<div>
<p>[16] <i>Id</i>. at page 9.</p>
</div>
<div>
<p>[17] <i>Id</i>. at page 10.</p>
</div>
<div>
<p>[18] <i>Id</i>. at page 10.</p>
</div>
<div>
<p>[19] <i>Id</i>. at page 10.</p>
</div>
<div>
<p>[20] <i>Id</i>. at page 14.</p>
</div>
<div>
<p>[21] <i>Id</i>. at page 15.</p>
</div>
<div>
<p>[22] <i>Id</i>. at pages 21-22.</p>
</div>
<div>
<p>[23] <i>Id</i>. at page 22.</p>
</div>
<div>
<p>[24] <i>Id</i>. at pages 19-20.</p>
</div>
<div>
<p>[25] <i>Id</i>. at pages 20-21.</p>
</div>
<div>
<p>[26] <i>See</i> Ekundayo George.  <i>GRC: Governance (Part 2)</i>.  Published on ogalaws.wordpress.com, October 29, 2012, at note 12 and accompanying text.  Online: &gt;<a href="http://ogalaws.wordpress.com/category/regulatory-and-government-affairs/governance-risk-compliance-grc-and-sanctions/">http://ogalaws.wordpress.com/category/regulatory-and-government-affairs/governance-risk-compliance-grc-and-sanctions/</a>&lt;  Model e-Discovery Order for patent litigation, as presented to the Eastern District of Texas Judicial Conference on September 27, 2011, by the Honourable Randall R. Rader, Chief Judge of the United States Court of Appeals for the Federal Circuit.</p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/473/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/473/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=473&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/03/31/to-gatto-from-zubulake-2-thumbs-up-for-better-information-governanceanti-spoliation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>Gobble-Gobble Security: Facetiously “Visioning-out” the full Software as a Service (SaaS) Trajectory.</title>
		<link>http://ogalaws.wordpress.com/2013/03/28/gobble-gobble-security-facetiously-visioning-out-the-full-software-as-a-service-saas-trajectory/</link>
		<comments>http://ogalaws.wordpress.com/2013/03/28/gobble-gobble-security-facetiously-visioning-out-the-full-software-as-a-service-saas-trajectory/#comments</comments>
		<pubDate>Thu, 28 Mar 2013 16:45:44 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Outsourcing and Cloud Computing]]></category>
		<category><![CDATA[Cyberbunker]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[Distributed Denial of Service]]></category>
		<category><![CDATA[Implanted device]]></category>
		<category><![CDATA[RFID]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Spamhaus]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=464</guid>
		<description><![CDATA[I would say there are essentially 7 (“seven”) stages in this trajectory, being: (i) SaaP; (ii) SaaS; (iii) SaaR; (iv) S3aUR; (v) PcSS; (vi) SaEE/SaEA; (vii) PC3S. Kindly allow me to explain. SaaP – Software as a Product: (i) Software was originally a product, although many in the younger generations may have little to no [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=464&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I would say there are essentially 7 (“seven”) stages in this trajectory, being:</p>
<p>(i) SaaP;</p>
<p>(ii) SaaS;</p>
<p>(iii) SaaR;</p>
<p>(iv) S<sup>3</sup>aUR;</p>
<p>(v) PcSS;</p>
<p>(vi) SaEE/SaEA;</p>
<p>(vii) PC<sup>3</sup>S.</p>
<p>Kindly allow me to explain.</p>
<p><span style="text-decoration:underline;">SaaP – Software as a Product</span>:</p>
<p>(i) Software was originally a product, although many in the younger generations may have little to no recollection of those days.  It was separately shrink-wrapped and sold first in hard copy format, on disks (you might recall the almost never-ending deluge in your snail mail of all those free and unsolicited AOL, Earthlink, and MSN discs of yore), amongst others; and then, it moved online, with click-wrap licensing.</p>
<p><span style="text-decoration:underline;">SaaS – Software as a Service</span>:</p>
<p>(ii) Software as a Service developed with the outsourcing trend, and it has actually been with us for at least a good decade.  Value-added through offshoring, near-shoring, and contracting-out for the design of software to run CAD and CAM applications (as well as the machines on which to run them), all after first hiring the outside management consultants to advise on how to better streamline and align critical line and staff functions to increase ROI, boost productivity, and maximize shareholder value.</p>
<p><span style="text-decoration:underline;">SaaR – Software as a Right</span>:</p>
<p>(iii) Although many don’t quite see it – due to the fact that Stage 4 is already taking the limelight ahead of its time – Stage 3 is when we start to see <i>Software as a Right</i> (SaaR).  Software is becoming a right because cost-cutting has led to several European and North American governments cutting funds for hardcopy libraries, both public and at educational institutions.  As this happens, older collections are being shredded to save space and funds (sometimes with and sometimes without ensuring that they are first put to the expensive process of scanning and digitization, and very often without any public disclosure, comment, or opportunity for interested parties and departments to offer to raise the funds or find the space to preserve them).  As more and more knowledge goes online and becomes accessible only for a fee (see the recent moves of certain provides of news and commentary to dispense with the printed versions of their publications); and as more and more public government services (information, forms, e-filing, e-refunds) and even private sector services (banking, customer service, event and school registration and RSVP), then software becomes a right, to the extent that people need it for access to these essentials of daily living.</p>
<p><span style="text-decoration:underline;">S<sup>3</sup>aUR – Software and Systemic Security at Undue Risk</span>:</p>
<p>(iv) We are now seeing multiple, concatenating, and overlapping tangible and virtual instances of Software and Systemic Security at Undue Risk in multiple Availability Zones (AZ), due to hacking and malware, Advanced Persistent Threats (APT), insider fraud and disgruntled employees,[1] apparent personal grudges,[2] blatant BYOD misuse, and just bad design, mismatched configuration, or absent/inactive management.  There are climatic and other intervening “exigent events”.  However, the argument will always be made that these (including climate change), were predictable, and could therefore have been better planned for and their effects, controlled.</p>
<p><span style="text-decoration:underline;">PCSS – Persistent Cloud Security Systems</span>:</p>
<p>(v) As a result of Stage 4, discussions have already commenced and are well underway,[3] on how to best structure,[4] roll-out, and govern a Persistent Cloud Security (PCSS) that (a) works in real-time, (b) is networked to involve end-users, private sector providers, and public sector actors of various profiles, and (c) is truly multinational and achieves massive regulator and government buy-in to work consistently and predictably with common rule or principles to drill down on, rein-in, and prosecute actors in the under-most belly, of the <i>Deep Web</i>.[5]  Monitoring as a Service, Alerts as a Service, and like offerings will not, alone, suffice to stem Stage 4s insecurity tsunami.</p>
<p><span style="text-decoration:underline;">SaEE/SaEA – Software as Embedded Enabler or Enhancement/Appendage or Augmentation</span>:</p>
<p>(vi) Of course, being a non-Wizard, I cannot say what term precisely, will be used.  It is possible, just as is the current case with the Phase 2 SaaS variants, that different terms will be used by different providers and commentators, unless and until some sort of standardization is agreed-upon.  The need for constant updates, patches, and other communications with the thin, thick, and virtual clients running all of this massively-dispersed computing power, whether by pull-down or push-out from the update source, will eventually start to fall too far behind the developing threats and vulnerabilities presented.  At that point, one or more governments may “force” this Stage 6.</p>
<p>There are already “some” people experimenting with themselves by embedding RFID chips, and the agriculture industry has lots of experience on their use with farm animals.  Anecdotal stories on the internet about additional experimentation by early-adopters with pets, children, and the elderly, are yet to be proven for the most part …. I think?!  A number of nations are reportedly also spending copious amounts of declared and undeclared moneys on brain-mapping, brainwave scanning, and methods to understand, predict, and control human brainwaves and human behavior without being detected.</p>
<p>Whatever the case, once the critical point of the implantation quotient is achieved or nearly-achieved, there may come a time when governments “mandate” that people embed or append the software through a chip implantation of some sort.  This will be resisted on a number of fronts and may cause unrest in several jurisdictions.  However, judging by the way some governments can tend to proceed with their plans despite the protests of millions, the effects on their citizens, and the horror of other nations, things may still get pretty ugly.</p>
<p>As we have already seen in the case of consumer products (from smokeables, through manufactured goods and automobiles, to even fresh food), not all dangers in end-use and the potential side-effects that could and should have been disclosed, were disclosed.  Let us therefore hope that these “implants” do not create a globe of rabid zombies under the remote control of whoever can hack the system best, or hostages to brain-frying hacktivists.</p>
<p><span style="text-decoration:underline;">PC<sup>3</sup>S – Pure Collectivized Communications Culture System</span>:</p>
<p>(vii) Then, once everyone who counts or wants to count, is wired-up (or at least, all who want to be able to eat &amp; drink, fully &amp; freely exercise inalienable rights, or buy &amp; sell in a fully-tracked, value-stacked, government-backed, and supposedly hard-to-crack, pay as you go system with monthly user fees and transaction levies (<i>ePayment only in a cashless society, with interest-bearing pay-day-loans preferred so as to keep everyone happily hard at work for their own self-serving purposes</i>) that by definition includes all but the “obvious terrorists”, we <span style="text-decoration:underline;">will</span> have that Stage 7, in a <i>Pure Collectivized Communications Culture System</i>.  If software becomes embedded to get around hacking, then who is to say that a person’s brain will actually be able to remain free and clear of the hackers; or that interested parties with the access (such as corrupt insiders), will resist the temptation to hack someone’s brain for profit, or to create a robot on demand”, with credible and provable amnesia?  A number of 20<sup>th</sup> and 21<sup>st</sup> Century books and movies may quickly come to mind.[6]</p>
<p><span style="text-decoration:underline;">SUMMARY</span>:</p>
<p>Of course, all of this is a work of fiction and can never happen in this modern world …. except of course, for those stages in these above 7, that have already taken place, or that are …. “<b><i>something of a work in progress, by someone, somewhere, for some specific purpose, and at the behest and request of some sort of sponsor</i></b>”!  It is said that being fore-warned is to be fore-armed, but nobody really remembers things they read on the internet, unless there is some sensual stimulant or celebrity endorsement, right?</p>
<p>************************************************************************</p>
<p><span style="text-decoration:underline;">Author</span>:</p>
<p>Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and <i>GRC</i> – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.). <i>Please See</i>: <a href="http://www.ogalaws.com/">http://www.ogalaws.com</a></p>
<p>He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: <a href="http://www.simprime-ca.com/">http://www.simprime-ca.com</a></p>
<p>Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</p>
<p><b>Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic <i>IMPRIME</i> Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</b></p>
<p align="center"><b><i><span style="text-decoration:underline;">This article does not constitute legal advice or create any lawyer-client relationship.</span></i></b></p>
<div>
<hr align="left" size="1" width="33%" />
<div>
<p>[1] <i>See e.g.</i> Ekundayo George.  <i>Cybersecurity: the Enemy is also (perhaps even more so), Within – the case of “Bob”</i>. Published on ogalaws.wordpress.com, January 17, 2013.  Online: &gt;<a href="http://ogalaws.wordpress.com/2013/01/17/cybersecurity-the-enemy-is-also-perhaps-even-more-so-within-the-case-of-bob/">http://ogalaws.wordpress.com/2013/01/17/cybersecurity-the-enemy-is-also-perhaps-even-more-so-within-the-case-of-bob/</a>&lt;</p>
</div>
<div>
<p>[2] See Adam Edelman/New York Daily News.  <i>Cyberbunker hosting site said to be dropping virtual ‘nuclear bomb’ on Internet with massive, global denial of service attack</i>.  Published Wednesday, March 27, 2013 on nydailynews.com.  Online: &gt;<a href="http://www.nydailynews.com/news/national/internet-nuked-massive-ongoing-cyber-attack-experts-article-1.1300372">http://www.nydailynews.com/news/national/internet-nuked-massive-ongoing-cyber-attack-experts-article-1.1300372</a> &lt;  It is “alleged” that a private dispute of some sort between Cyberbunker (a Dutch internet hosting <span style="text-decoration:underline;">business</span> that will take all-comers, “<i>except child porn and anything related to terrorism</i>”), and The Spamhaus Project (a <span style="text-decoration:underline;">non-profit</span> centred in London and Geneva, but with operating nodes in ten nations, that “<i>works to help email providers filter out spam</i>”), has led to the largest DDOS in history with a data stream attack magnitude of 300 billion bits per second, when 50 billion bits would suffice to bring-down the online service of many significant online businesses, including major banks.  The fact that most people have seen no significantly noticeable disruptions due to this “attack”, just goes to show the added resilience built into the system since this kind of attack was first noticed, understood, and responded to by industry and regulators. Personally, I saw some emails come through on device group “A”, but they were delayed on others – thankfully, nothing time-sensitive, and I was aware of them due to my own system of redundancies in having those multiple email access points and service providers.  Microsoft also just switched a “massive” few more users over to Outlook, so that may have also played a part in my own delayed email receipt.  In any case, investigations are ongoing into the source of the current and sustained attacks, but as with others, the true perpetrators may remain hidden.  <i>See Infra</i>, note 5.  <i>See also</i> The Spamhaus Project homepage.  Online: &gt; <a href="http://www.spamhaus.org/organization/">http://www.spamhaus.org/organization/</a>&lt;; The Cyberbunker Data Centers homepage.  Online:  &gt;<a href="http://www.cyberbunker.com%3c">http://www.cyberbunker.com</a>&lt; (the Cyberbunker website was verified by this author as unreachable online, at the time this SaaS Visioning-out article posted).</p>
</div>
<div>
<p>[3] <i>See e.g.</i>  Ekundayo George.  <i>Data Protection and Retention in the Cloud: Getting it Right</i>, at Note 17.  Posted March 11, 2013, on ogalaws.com.  Online:&gt; <a href="http://ogalaws.wordpress.com/2013/03/11/data-protection-and-retention-in-the-cloud-getting-it-right/%3c">http://ogalaws.wordpress.com/2013/03/11/data-protection-and-retention-in-the-cloud-getting-it-right/</a>&lt;</p>
</div>
<div>
<p>[4] <i>See e.g</i>. Mikael Ricknäs, IDG News Service.  <i>AWS takes aim at security conscious enterprises with new appliance</i>.  Published on itworld.com, March 27, 2013.  Online: &gt;<a href="http://www.itworld.com/cloud-computing/349894/aws-takes-aim-security-conscious-enterprises-new-appliance?goback=.gde_1864210_member_226976359%3cb">http://www.itworld.com/cloud-computing/349894/aws-takes-aim-security-conscious-enterprises-new-appliance?goback=.gde_1864210_member_226976359</a>&lt;  Amazon Web Services has introduced a standalone, secondary cloud-based system to manage cryptographic keys that will be used in the cloud, with limited AWS access through “strict” separation of administrative and operational duties between the vendor and the client, and segregation and limitation of access according to business need.  SOD best practices are thus clearly translated into the cloudsphere.</p>
</div>
<div>
<p>[5] <i>See</i> Gil David.  <i>The Dark Side of the Internet</i>.  Published on israeldefence.com, December 1, 2012.  Online:</p>
<p>&gt;<a href="http://www.israeldefense.com/?CategoryID=483&amp;ArticleID=1756">http://www.israeldefense.com/?CategoryID=483&amp;ArticleID=1756</a>&lt;  This article provides a fairly good overview of what we are all dealing with on a daily basis, with regard to the Deep Web.  I will post at a later date, regarding some of my thoughts on how this might spur and/or impact upon, that promised “<i>Internet of Things</i>” to come.</p>
</div>
<div>
<p>[6] I think I will also have to post at a later date on what might constitute “work”, when machines do so much of one type of work, and many of the other types are outsourced to someone, somewhere else.  As automation really took hold on a massive scale in the industrial west (Japan, Europe, North America, South Korea) in the 1960s and 1970s, much was said about the coming leisure society as machines did so much, that people would have more time on their hands to relax and actually enjoy life.  Now, the “<i>massively unemployed, migrating mass populations</i>” in almost all geographic zones and nations, mean something clearly went very wrong.  We are a few steps away from chaos; one that may well start in the European Union &#8211;or with one or more of its “<i>pending former</i>” members.  Should this happen and spread as political leaders continue making very bad calls, Anonymous, Environmentalists, Occupy, and the Anti-Globalization folks will look like child’s play, even when first combined and then multiplied.</p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/464/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=464&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/03/28/gobble-gobble-security-facetiously-visioning-out-the-full-software-as-a-service-saas-trajectory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>Ctrl-Shift-Del: 2013’s Top 5 Technology Trends for Consumers.</title>
		<link>http://ogalaws.wordpress.com/2013/03/16/ctrl-shift-del-2013s-top-5-technology-trends-for-consumers/</link>
		<comments>http://ogalaws.wordpress.com/2013/03/16/ctrl-shift-del-2013s-top-5-technology-trends-for-consumers/#comments</comments>
		<pubDate>Sat, 16 Mar 2013 02:22:24 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Change Management]]></category>
		<category><![CDATA[e-Commerce]]></category>
		<category><![CDATA[2013 Top 5 Technology Trends for Consumers]]></category>
		<category><![CDATA[Bring Your Own Device (BYOD)]]></category>
		<category><![CDATA[End User Legal Authority]]></category>
		<category><![CDATA[End User Leveraged Ability]]></category>
		<category><![CDATA[End User License Autonomy]]></category>
		<category><![CDATA[EULA]]></category>
		<category><![CDATA[multi-taneous]]></category>
		<category><![CDATA[PWC 2013 Top 10 Technology Trends for Business]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=450</guid>
		<description><![CDATA[RATIONALE: I was recently reading the PWC/Digital IQ Report, entitled “2013 Top 10 Technology Trends for Business”,[1] when I deduced that something was missing.  Rather than say that the venerable PWC were wrong in omitting something (who am I?), I thought it better to perhaps bring my views to light with a separate but related [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=450&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><span style="text-decoration:underline;">RATIONALE</span>:</p>
<p>I was recently reading the PWC/Digital IQ Report, entitled “<i>2013 Top 10 Technology Trends for Business</i>”,[1] when I deduced that something was missing.  Rather than say that the venerable PWC were wrong in omitting something (<i>who am I?</i>), I thought it better to perhaps bring my views to light with a separate but related story; hence this blog post with a title that plays-on that of the PWC Report.</p>
<p>The PWC/Digital IQ Report identifies and presents those 2013, top 10 tech. trends for business, as: (1) Pervasive computing; (2) Cybersecurity; (3) Big Data mining and analysis; (4) Private Cloud; (5) Enterprise social networking; (6) Digital delivery of products and services; (7) Public Cloud infrastructure; (8) Data visualization; (9) Simulation and scenario modeling; and (10) Gamification.[2]</p>
<p><span style="text-decoration:underline;">IDENTIFICATION</span>:</p>
<p>One might say that these are, each and all, complete in and of themselves.  However, the additional trends for consumers that they inspire, should, I feel, be presented as either:</p>
<p>(a) <i>additional</i> trends (numbered 11 through 15) <i>for businesses</i> (considering the business-to-consumer/business-to-business implications and possibilities); or</p>
<p>(b) as <i>separate &amp; distinct</i> (numbered one through five), <i>consumer specific</i> trends.</p>
<p>These 5, are: (v) Accelerated lived experience; (w) BYOD; (x) Crowdsourcing; (y) Distance education; and (z) End-User legal authority/license autonomy/leveraged ability (EULA3, or cubed).  Hence, choosing (b) – <i>presented as separate and distinct, consumer-specific trends</i>, I detail them below.</p>
<p><span style="text-decoration:underline;">SPECIFICS</span>:</p>
<p><b>Accelerated Lived Experience:</b></p>
<p>(v) The speed at which information now moves has led to an accelerated lived experience, for everyone.  Anything and everything posted in a social media setting can be shared instantaneously, with millions of people all over the world.  And, once something is released into the wild of the web, it can “never” be taken back.  Legally, there are archives of webpages, tweets, blogs, pictures, videos, and postings – <i>even the deleted ones</i> &#8211; kept by licensed players within the internet superstructure; technically, there are vast storehouses (server farms) sifting through everything that is uploaded to, sent across, and downloaded from the internet by many governments around the world, and their functionaries; and individually and collectively, people and groups – both criminal and law-abiding – can surf, send, and select for download or copy/paste at their pleasure.  We are almost at a stage of constant reaction to external initiators, and always on the lookout for the next <i>trending thing</i> with heightened anxiety, heart rates, and hyper-dilated pupils.  The jolt of electricity from AC/DC (alternate current/direct current) is now equated by the constant, (almost intravenous in some case for those who cannot turn-off or put-down the smartphone), stimulus experienced by the always connected/always online (AC/AO) generation.</p>
<p><b>BYOD:</b></p>
<p>(w) <i>Bring Your Own Device</i>, is the new policy in an increasing number of workplaces, that allows employees to bring their own devices to work, or use them remotely for work.  Despite the real dangers of allowing sometimes uncleared (inherently unsecure, or running old and unpatched operating systems), incompatible (incorrectly configured), or unnecessarily vulnerable (inadequate virus and spyware protections, or already loaded with exploits-in-waiting) tech. tools to connect and send to, and source valuable personal data, customer information, intellectual property and trade secrets from, a work network, this trend is likely to continue.[3]  BYOD has the potential to enable significant savings for the organization in not having to constantly acquire, distribute, and manage ever newer devices for its sometimes vast army of employees.  However, it can also import liabilities for anything from: failing to properly train employees in, monitor, and enforce a responsible BYOD usage policy – along with a social media usage policy; negative publicity in employee pushback against the employer’s attempts to overly-regulate their private use of private property, despite its incidental business application; and legal exposure in preventable data breach, or employee loss of personal data on an unsecured device that was misplaced or stolen.  Should the employer’s insurer or the employee’s insurer pay for the ensuing liabilities when a personal laptop, used for business, is lost or stolen when an employee is on vacation (or stress leave), but finishing-off some work?</p>
<p><b>Crowdsourcing:</b></p>
<p>(x) Having so many people, in so many different places, with myriad perspectives and experiences, enables a whole new world of crowdsourcing.  This can range from personal networking sites that allow one to rapidly get information on a specific subject from a variety of sources or thought and knowledge leaders; through groups, blogs, and list serves that are more targeted and which people join or subscribe to at their pleasure; to news media sites that invite people to post their images, videos, or opinions on a variety of current and historical issues, or disasters and other developing events of significance.  Of course, there is no guarantee that some or all such crowd sources are correct, accurate, or honest.  There have also been instances of late, involving “<i>massaged</i>” evidence; old footage from somewhere else presented as current footage from a hot location; and cases in which people with their own agendas have either directly impersonated, or hacked the accounts and credentials of others – not to mention those “crashing” glitzy events who could easily be mistaken for legitimate participants, if presented with the right caption to an unwitting audience (not aware of, or even so far gone as to not believe), the original footage.  Crowd-sourced “<i>fodder</i>” is best taken with a good dose of skepticism, and at least a little salt; lest one join the ranks of those who are so easily fooled, all of the time.  On the converse side, business use of crowdsourcing within the organization may defeat itself if not properly managed. The digital suggestion box, if too full, will see management applying that very same filtering-type software, already adept at sniffing through servers full of resumes, to sift through and sort the suggestions.  Good ones, as always, may still be filtered-out by the wrong or imprecise <i>Big Data</i> analytical tools.</p>
<p><b>Distance Education:</b></p>
<p>(y) This trend, thankfully, is not quite as controversial.  However, the accreditation and quality of an increasing collection of online courses, degree and certificate programs, and institutions, is a fast-developing concern.  Accredited Professionals who cannot always travel so easily to attend presentations they need for continuing education credits or that are otherwise of interest to them, can more conveniently sit and watch the webcast, or listen to the teleconference from the comfort of their own homes and offices; or even when on the road (to the extent, of course, that it does not lead them into distracted driving, boating, flying, riding, or otherwise).  As technology continues to develop and regulatory accreditation issues and concerns are resolved, this trend can only continue; including, of course, greater use of <i>learning-on-demand</i>, (like already pervasive delivery of video and audio content on-demand), as digitized in a Cloud for later, <i>multi-taneous</i>,[4] ever-replicable access.   Additionally, education need not be so formal, as someone can gain knowledge from virtually any video, blog post, or seminar – posted from anywhere and available everywhere (that does not have filtering or blocked sites) that they find online in their own identified field of pre-existing, related, or newly-created interest.</p>
<p><b>End-User Legal Authority/ License Autonomy/ Leveraged Ability (EULA3, or cubed):</b></p>
<p>(z) In the olden days (dating myself a little here), computer software was released and “sent” by snail-mail in shrink-wrapped packages.  Opening the package constituted acceptance of the manufacturer/ publisher End-User License Agreement (EULA).  Once you had broken the <i>shrink-wrap</i> packaging, it could prove difficult to impossible, to say that you had not accepted the EULA, or to try to return the software and get a refund if you had not otherwise fulfilled the warranty requirements, where they even existed.  Then, with the growth of online commerce/eCommerce, this turned into a <i>click-wrap</i> scenario, which still exists, somewhat.  By clicking on the appropriate “I accept” box or boxes, you accept the terms of use, EULA, and other conditions and prerequisites to download the software, access the site, utilize the online service, fully activate a device, or register its warranty, as appropriate.  Today, we have an increasing prevalence of shareware with licenses that are not quite free, but in the creative commons (too detailed for fuller presentation here); we have devices that are sold as locked but that can be unlocked – whether or not legally; contract hackers and programmers who work for a fee are available online, or through friends-of-friends; and stolen devices still under contract or EULA can be relatively easily wiped of data, re-programmed, and re-purposed with new Sim (Subscriber Identity Module) cards or software; whether right next door or on the other side of the world.</p>
<p>Users and developers of shareware, including “apps.” available for download and use on various trusted and not so trusted sites, now have added and significant <i><span style="text-decoration:underline;">legal authority</span></i> to use and further develop or customize them (screensavers, fonts, skins, and avatars)  to their own liking.</p>
<p>Those using un-locked devices – <i>howsoever obtained</i> – have a significant degree of <i><span style="text-decoration:underline;">license autonomy</span></i>, as they can be free from multi-year contracts; they can sometimes be free from geographic restrictions on where they can use their smartphones or play their DVDs; and they can also be free (whether through active choice or by default setting, depending on the jurisdiction) from having add-ons bundled with initial programs (EU), from having their location automatically tracked by the service provider (opt-out), and from the compulsory download of automatic updates that may conflict with programs and applications installed on the device since its initial purchase or acquisition.  Of course, an original purchaser would already have known of the manufacturer/developer caveat that the item might not work as originally envisaged if automatic updates were not accepted.  However, the later purchaser or recipient of dubious propriety, might have the device wiped and/or locked, and/or tagged on him or her when searching for an update online.  Life as lived in a certain way, will always have its risks, for those who dare there stay!</p>
<p>The increasing online prevalence of tools and technologies enabling groups to collaborate, individuals to innovate, and everyone to share almost anything from everywhere, with everyone at any time, provides us all with significant <i><span style="text-decoration:underline;">leveraged ability</span></i>.  This has ranged from simple apps. (for almost anything thinkable and unthinkable); through online groups, archives, fora, encyclopedias, and societies (ditto); to the ever-expanding plethora of additionally leveraging SaaS, PaaS, IaaS, and NaaS[5] offerings.</p>
<p><span style="text-decoration:underline;">END-STATE</span>:</p>
<p><i><span style="text-decoration:underline;">Control</span></i> once held by the manufacturer and copyright holder over the consumer and what he or she could legitimately do with the former’s intellectual property has been reduced, in cases to zero; this massive <i><span style="text-decoration:underline;">Shift</span></i> of power to the consumer from the variety of choices, service options, and delivery channels available to them and in constant competition for market share; has now served to virtually <i><span style="text-decoration:underline;">Delete</span></i> the EULA as once known, with end-users experiencing significant legal authority, license autonomy, and leveraged ability.  “<i>No contract</i>”; “<i>unlocked</i>”; “<i>number portability</i>”; “<i>free wifi</i>”; “<i>roaming included</i>”; “<i>unlimited data package</i>”- these are the <i>new</i> and standard terms, <i>now</i>!!</p>
<p>Apparently, these terms are all here to stay (and get even better in favour of the now-empowered consumer), to the extent that data-flows and internet flexibility are not slowly or suddenly throttled by sometimes competing security and IPR (Intellectual Property Rights) interests, and so long as PWCs <i>2013 Top 10 Technology Trends for Business</i>[6] continue to enable &amp; expand these <i>2013 Top 5 Technology Trends for Consumers</i> that I have identified above, in this post.</p>
<p>************************************************************************</p>
<p><span style="text-decoration:underline;">Author</span>:</p>
<p>Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and <i>GRC</i> – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.). <i>Please See</i>: <a href="http://www.ogalaws.com/">http://www.ogalaws.com</a></p>
<p>He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: <a href="http://www.simprime-ca.com/">http://www.simprime-ca.com</a></p>
<p>Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</p>
<p><b>Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic <i>IMPRIME</i> Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</b></p>
<p align="center"><b><i><span style="text-decoration:underline;">This article does not constitute legal advice or create any lawyer-client relationship.</span></i></b></p>
<div>
<hr align="left" size="1" width="33%" />
<div>
<p>[1] PricewaterhouseCoopers LLP.  <i>Digital IQ – 2013 Top 10 Technology Trends for Business</i>.  Results of the 5<sup>th</sup> Annual, PwC Digital IQ Survey.  Published on pwc.com, in 2013.  Online: &gt;<a href="http://www.pwc.com/us/en/advisory/2013-digital-iq-survey/top-10-technology-trends-for-business.jhtml">http://www.pwc.com/us/en/advisory/2013-digital-iq-survey/top-10-technology-trends-for-business.jhtml</a>&lt;</p>
</div>
<div>
<p>[2] <i>Id</i>.</p>
</div>
<div>
<p>[3] <i>See e.g.</i> Ekundayo George.  <i>What about hospital BYOD?</i>  Published on ogalaws.wordpress.com, October 7, 2012.  Online: &gt;<a href="http://ogalaws.wordpress.com/2012/10/07/med-tech-byod-is-really-catching-on/">http://ogalaws.wordpress.com/2012/10/07/med-tech-byod-is-really-catching-on/</a>&lt;</p>
</div>
<div>
<p>[4] I have not seen the word used in this specific context before, and so I thought I might as well use it here.  It stands for “<i>simultaneous access in multiple locations on multiple platforms or devices</i>”; as possible through an intermediary Cloud Services Provider with a high and demonstrably reliable SLA, given industry outages to date, or a robust private/hybrid Cloud capable of running multiple and adequately buffered instances at once – providing the user (read thin- or rich- “<i>client device</i>”), can access adequate bandwidth and memory (as applicable), and a stable power supply.</p>
</div>
<div>
<p>[5] <i>See e.g</i>. Ekundayo George.  <i>Data Protection and Retention in the Cloud: Getting it Right</i>.  Published on ogalaws.wordpress.com, March 11, 2013.  I further define these 4 (“four”) SaaS service offerings here, at notes 1 through 5 and accompanying text.  Online: &gt; <a href="http://ogalaws.wordpress.com/2013/03/11/data-protection-and-retention-in-the-cloud-getting-it-right/">http://ogalaws.wordpress.com/2013/03/11/data-protection-and-retention-in-the-cloud-getting-it-right/</a>&lt;</p>
</div>
<div>
<p>[6] <i>Supra</i> note 1.</p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/450/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=450&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/03/16/ctrl-shift-del-2013s-top-5-technology-trends-for-consumers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>Data Protection and Retention in the Cloud: Getting it Right.</title>
		<link>http://ogalaws.wordpress.com/2013/03/11/data-protection-and-retention-in-the-cloud-getting-it-right/</link>
		<comments>http://ogalaws.wordpress.com/2013/03/11/data-protection-and-retention-in-the-cloud-getting-it-right/#comments</comments>
		<pubDate>Mon, 11 Mar 2013 03:25:43 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Outsourcing and Cloud Computing]]></category>
		<category><![CDATA[ABA Active Cyber Defense]]></category>
		<category><![CDATA[cloud data protection]]></category>
		<category><![CDATA[PCI-DSS]]></category>
		<category><![CDATA[verizon 2012 Data Breach Investigation Report (DBIR)]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=440</guid>
		<description><![CDATA[Much attention is focused on the “Triple A” of Cloud services, namely: Availability all the time (Service Level Agreements and uptime claims); Appropriate access controls (passwords and authentication); and Alteration protection and audit trails, which is especially critical in terms of eDiscovery, and responsibility in ensuring the entity’s ability to effectively backup, recover, and archive [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=440&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Much attention is focused on the “<i>Triple A</i>” of Cloud services, namely: <span style="text-decoration:underline;">Availability all the time</span> (Service Level Agreements and uptime claims); <span style="text-decoration:underline;">Appropriate access controls</span> (passwords and authentication); and <span style="text-decoration:underline;">Alteration protection and audit trails</span>, which is especially critical in terms of eDiscovery, and responsibility in ensuring the entity’s ability to effectively backup, recover, and archive its data on a regular basis, and to restore its data on-site or off-site after the fact of a contingency event.</p>
<p>Whether you are thinking of a far-flung transnational operator or a small business, the following are 8 (“eight”) factors to <b>constantly revisit</b> in <i>getting it right</i> when considering or indulging in cloud services.</p>
<p>1.   <b><span style="text-decoration:underline;">Backup Cloud</span>:</b> If you have critical functionalities that have moved completely or almost completely to a cloud-based solution (SaaS,[1] PaaS,[2] Iaas,[3] NaaS[4]),[5] then it is highly-advisable to have a backup cloud.  Whether this is done as a failover provision (not always easy to coordinate the two providers), or the running of parallel instances (such as accessing a standalone data archive with staggered replication between those two or more remote access nodes, so permitting them to jointly recover the entire data set should access to the central archive suddenly cease), is ultimately the consumer’s decision.  It is important to remember in the former scenario, however, that if it is not working or suddenly stops working, then it might not be able to failover on its own, without external intervention.  This is especially true if the stoppage is due to a utility outage, climatic event, or human action (terrorism, error, criminality, or hacktivism).</p>
<p>2.   <b><span style="text-decoration:underline;">Effective Version Controls</span>:</b> Backup, recovery, and replication processes can be configured in a variety of ways, from the guarantee that a single newer version replaces a single older one, to cases where multiple older versions are retained and disposed-of in sequence as new ones are stored.  Mishaps or mis-alignments in this process can lead to sometimes irretrievable loss of valuable data, which must be avoided.  It may well be true that short of <i>walking hard drives and zip drives</i>, many modern “losses” may still be recoverable.  However, with the increasing complexity and sensitivity of the back-end tools, and the difficulty and active management required to get them to work well together (within promised SLA parameters) for enough of the time, the costs can be prohibitive.  Doing it right the first time, should always be the goal.</p>
<p>3.   <b><span style="text-decoration:underline;">Security Consciousness</span>:</b>  There is significant current media and government focus (here in North America and Canada) on the topic of hacking and data exploitation.  One report,[6] indicates that while 54% and 20% respectively of all 2012 breaches were in the accommodation and food services industries, and the retail trade industry,[7] external threats accounted for 95% of all breaches.[8]  With regard to the actors, 83% of breaches against all organizations reporting, were by organized criminal groups,[9] and the descending-order ranking of breach motivation for exploits at large organizations, was: financial or personal gain (71%); disagreement or protest (25%); fun, curiosity, or pride (23%); and grudge or personal offence (2%).[10]  The disgruntled current or former employee with a grudge, is <i>apparently</i> less of a threat than the current employee in deep financial distress, who himself or herself is also <i>apparently</i> less of a threat than the totally unknown but well-financed and staffed criminal organization or state actor that wants access at almost any cost, to the treasure-chest of information on your servers or on the servers of your Cloud Services Provider (CSP).  However, “apparently” is just that, because the reality is joint or co-opted action.  In stating that 65% of internal agent breaches were through a cashier, teller, or waiter, the report also found that “<i>[t]hese individuals, often solicited by external organized gangs, regularly skim customer payment cards on handheld devices designed to capture magnetic stripe data.  The data is then passed up the chain to criminals who use magnetic stripe encoders to fabricate duplicate cards</i>”.[11]  The threat landscape is deep, diverse, and dynamic.  Forewarned with this knowledge, you should have no choice but to be security conscious, spurring you on to craft strategies appropriate to your industry, entity, and V5,[12] to protect your client and other critical data, systems, and processes against compromise, criminality, and a completely unrecoverable disaster.</p>
<p>4.   <b><span style="text-decoration:underline;">Traditional (off-Cloud) Backup</span>:</b> Whether the cloud package is offsite, uses in-house accessories, or is a hybrid solution, off-cloud backup may still be an option – whether in addition to or as an alternative for, a backup cloud.  An offline backup sequence that occurs weekly, daily, or several times during the day depending on the interplay (V5)[13] of data <i>Volume</i> (sheer amount), <i>Velocity</i> (speed of its change), <i>Variety</i> (by operating division, product line, client, transaction, trade or other event, analytical element or matrix of elements in the case of big data, and so forth), <i>Value</i> (its criticality to the core functionality, as well as its full replicability on short-order), and <i>Vulnerability</i> (susceptibility to internal, external, and developing threats), with tapes transported, maintained, and regularly tested for their usability, offsite, is a highly-advisable redundancy.  In the event that the primary workspace is compromised and cloud connectivity interrupted, a well-prepared and practiced entity may – <i>far more swiftly and smoothly than the competition</i> &#8211; be able to recover from an initial adverse event or sequence of same, and resume operations in an alternate location using the backup tapes, staff able to reach that location if telecommuting remains unavailable, and either pre-positioned or called-in equipment; as available through an expanding group of contingent offsite emergency recovery solution/outcome providers.</p>
<p>5.   <b><span style="text-decoration:underline;">Data Retention Policies</span>:</b> Be aware of, and attune your operations to, applicable data retention policies.  Courts in the United States have, to date, proven more eager than Canadian courts to sanction parties for failing to preserve, protect, and produce data that they should have kept by law, and didn’t, or data that they could have had to present at a court or regulatory proceeding, but couldn’t, due to its initial non-retention.  There may be specific rules pertinent to your industry (such as food, or financial services and the PCI-DSS), your activity (such as Intellectual Property filing/prosecution, and healthcare), or your jurisdiction (differing in Canada and the European Union, for example).</p>
<p>6.   <b><span style="text-decoration:underline;">Advisable (and accelerating) Best Practices</span>: </b>Having your data resident (whether by bald custody or actual control, in accordance with your Cloud Services Agreement) in the pocket of a third-party, has its obvious risks.  There are also several more subtle ones, which I have canvassed at some length elsewhere in my several blogs on the cloud and outsourcing in general.  It used to be the fact that: (i) the lawmakers would write a law either creating a new regulator or authorizing an existing regulator to act; (ii) proposed regulations would be published for comment; (iii) final regulations would issue; and (iv) tests in court would help to better define and refine them.  Now, everything is in reverse.  An event leads to tests in court, the regulator makes a knee-jerk reaction to try and restore sanity in the interim, there is a public outcry (either here, or earlier in this reversed process), and then a law is passed; which may start the entire sequence again if the law is too broad, not broad enough, or has some adverse effect on a specified/protected group or interest.  “Best Practices in the Cloud” must for now, remain a still-evolving paradigm, so watch your <i>prose</i> (know what you draft and sign), listen to <i>those-in-the- know</i> (pay attention to ongoing doings, debates, and developments), and <i>stay on your toes</i> (be nimble and adaptive, and keep an open mind in this rapidly-changing service space).</p>
<p>7.   <b><span style="text-decoration:underline;">Transferring Risks</span>: </b><i>Insure thyself!</i>  The costs of privacy practices, data breach liability, and similar lines of insurance have come down due to a modicum of standardization, and increased prevalence and awareness of their value from breach announcements occurring in several industries and jurisdictions; despite apparent best efforts.  Business interruption insurance has long been an option, and now, there are contingent event recovery services that can provide pre-packaged, tailored recovery solutions for a fixed monthly price; which is akin to insurance.  Risks can be transferred (insurance), shared (pooling), accounted for (planning), and limited (due diligence and best practices).  However, they can never be fully eliminated.  Be prepared, practice and game a variety of disaster and other contingency scenarios within your organization on a regular basis – whether actually or as tabletop exercises,[14] and expect the unexpected!  Utilities fail; climatic events don’t discriminate; and irrational actors, opportunists, state actors, hacktivists, and criminals all remain predictable in one respect: they <i><span style="text-decoration:underline;">will</span></i> act!</p>
<p>8.   <b><span style="text-decoration:underline;">Alert and Notification Protocols</span>:</b> There is really no substitute for a solid system of internal controls. Pre-employment background checks, segregation of duties, authentication and access logging, counterparty due diligence, and strictly enforced policies, are all critically important.  Only 2% of 2012 breaches for misuse were as a result of inappropriate web or internet usage (surfing the wrong type of site, for example), whilst 43% were the result of abusing system access or privileges, and 50% were the result of using unapproved hardware or devices on work systems[15] (whether with BYOD, or as a workaround on strict network controls or prohibitions).  Having, properly configuring, and diligently checking logs is key to risk management.  However, the report also notes the rising challenge to proper data protection and retention from Anti-forensics[16] – <i>especially when someone else is handling functions, now outsourced on a Cloud, that were formerly done in-house</i>.  Cloud Security and Cybersecurity will, for now, remain as moving targets; even with current calls in the United States for laws empowering private actors to jointly take immediate steps (preserving evidence, curtailing breaches, or tracking sources, deeper structures, and sponsors of security events),[17] while regulators and Law Enforcement and National Security (LENS) actors either get up-to-speed, or use their own customized tools for some parallel or complementary actions.[18]</p>
<p>&nbsp;</p>
<p><b>CONCLUSION:</b></p>
<p>We all know the adage that asks why re-invent the wheel?  I think the Payment Cards Industry Standards Council has already done a very good job in establishing the framework for its members to follow in their data protection and retention efforts as they “process, transmit, or store” that data;[19] which with “access” &#8211; presupposed by those first three options, also constitute the majority, if not the totality, of functions that can currently be performed in/via the Cloud.</p>
<p>I also think that the 6 categorical elements of that PCI-DSS Standard,[20] are broadly applicable in other industries; especially with cloud-based or cloud-dependent entities and service models.  To allow for proper tailoring, the 12 sub-elements can of course remain customizable within each of the SaaS, PaaS, IaaS, and NaaS sub-spaces.</p>
<p>There are many avenues that CSPs can pursue in efforts to self-regulate before something, perhaps more draconian than they had wanted, comes down firmly from the lawmakers and/or regulators above; whether with or without the precursor hue &amp; cry following an adverse incident.</p>
<p>Perhaps they may find something in the above that is worthy of trying.[21]</p>
<p>************************************************************************</p>
<p><span style="text-decoration:underline;">Author</span>:</p>
<p>Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and <i>GRC</i> – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.). <i>Please See</i>: <a href="http://www.ogalaws.com/">http://www.ogalaws.com</a></p>
<p>He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: <a href="http://www.simprime-ca.com/">http://www.simprime-ca.com</a></p>
<p>Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</p>
<p><b>Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic <i>IMPRIME</i> Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</b></p>
<p align="center"><b><i><span style="text-decoration:underline;">This article does not constitute legal advice or create any lawyer-client relationship.</span></i></b></p>
<div>
<hr align="left" size="1" width="33%" />
<div>
<p>[1] Software as a Service (SaaS), including “<i>tools for processing, analysis, accounting, CRM, and back-office functions</i>”.</p>
</div>
<div>
<p>[2] Platform as a Service (PaaS), including tools “<i>for email, online backup, or desktops-on-demand</i>”.</p>
</div>
<div>
<p>[3] Infrastructure as a Service (IaaS), including “<i>tools for collaboration, integration, and visualization</i>”.</p>
</div>
<div>
<p>[4] Network as a Service (NaaS), including advanced virtualization tools, such as bandwidth-on-demand for multiple Virtual Private Networks (VPN)-on-demand, and for cloud-to-cloud networking on demand.</p>
</div>
<div>
<p>[5] <i>See generally</i>, Ekundayo George, at (f).  <i>In who’se pocket is your data packet? – International Data Governance</i>.</p>
<p>Published February 6, 2013 on ogalaws.wordpress.com.  Online: &gt;<a href="http://ogalaws.wordpress.com/2013/02/06/in-whose-pocket-is-your-data-packet-international-data-governance/">http://ogalaws.wordpress.com/2013/02/06/in-whose-pocket-is-your-data-packet-international-data-governance/</a>&lt;</p>
</div>
<div>
<p>[6] Verizon.  <i>2012 Data Breach Investigations Report (DBIR)</i>.  Published 2012, by Verizon.com.  Online: &gt;<a href="http://www.verizonenterprise.com/resources/reports/rp_data-breach-investigations-report-2012-ebk_en_xg.pdf?__ct_return=1%3c">http://www.verizonenterprise.com/resources/reports/rp_data-breach-investigations-report-2012-ebk_en_xg.pdf?__ct_return=1</a>&lt;.  The report also discloses an error rate of +/- 4 percent.</p>
</div>
<div>
<p>[7] <i>Id</i>. at 11.</p>
</div>
<div>
<p>[8] <i>Id</i>. at 18.</p>
</div>
<div>
<p>[9] <i>Id</i>. at 20.</p>
</div>
<div>
<p>[10] <i>Id</i>. at 19.</p>
</div>
<div>
<p>[11] <i>Id</i>. at 21-2.</p>
</div>
<div>
<p>[12] <i>Infra</i>, note 13.</p>
</div>
<div>
<p>[13] The <i>V5 interplay</i>, is the mix of data <b>volume</b>, <b>velocity</b>, <b>variety</b>, <b>value</b>, and <b>vulnerability</b> that determines the how, where, and how often you back it up; amongst other distinct operations and/or management tasks.</p>
</div>
<div>
<p>[14] I have proposed a number of permanent executive positions for the C-Suite in modern business, including a Chief Contingency policies, plans, and practices Officer (CCO) with line and staff responsibility for all-hazards contingency affairs.  <i>See e.g</i>. Ekundayo George, at (i).  <i>10/4: the “C–Suite” in 2013 and beyond; who should really be there?  </i>Published November 21, 2012 on ogalaws.wordpress.com.  Online: &gt;<a href="http://ogalaws.wordpress.com/2012/11/21/104-the-c-suite-in-2013-and-beyond-who-should-really-be-there/">http://ogalaws.wordpress.com/2012/11/21/104-the-c-suite-in-2013-and-beyond-who-should-really-be-there/</a>&lt;</p>
</div>
<div>
<p>[15] Verizon.  <i>2012 Data Breach Investigations Report (DBIR)</i>, at 35.  Published 2012, by Verizon.com.  Online: &gt;<a href="http://www.verizonenterprise.com/resources/reports/rp_data-breach-investigations-report-2012-ebk_en_xg.pdf?__ct_return=1%3c">http://www.verizonenterprise.com/resources/reports/rp_data-breach-investigations-report-2012-ebk_en_xg.pdf?__ct_return=1</a>&lt;.</p>
</div>
<div>
<p>[16] <i>Id</i>. at 55.</p>
</div>
<div>
<p>[17] American Bar Association (ABA).   <i>National Security Experts Discuss Options for ‘Active’ Cyber Defense</i>.  Published February 11, 2013, by ABA Division for Communications &amp; Media Relations, on abanow.org.  (Link to full podcast is available at bottom of page).  Online:</p>
<p>&gt;<a href="http://www.abanow.org/2013/02/national-security-experts-discuss-options-for-active-cyber-defense/%3c">http://www.abanow.org/2013/02/national-security-experts-discuss-options-for-active-cyber-defense/</a>&lt;</p>
</div>
<div>
<p>[18] <i>Supra</i> note 15, at 52.  Fully 59% of breaches at all organizations in 2012 (10% for large organizations), were “only” discovered by the target when it was notified of the breach, by an arm of law enforcement/national security.  Notification by third-party as a result of that third-party’s fraud detection measures came next, at 26% and 8% respectively.</p>
</div>
<div>
<p>[19] PCI Security Standards Council.  <i>PCI DSS Quick Reference Guide &#8211; Understanding the Payment Card Industry.  Data Security Standard version 2.0</i>. <i>For merchants and entities that store, process or transmit cardholder data</i>.  Published 2010 on pcisecuritystandards.org, by PCI security Standards Council LLC.  Online:  &gt;<a href="https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Quick%20Reference%20Guide.pdf%3c">https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Quick%20Reference%20Guide.pdf</a>&lt;</p>
</div>
<div>
<p>[20] <i>Id</i>. at 8.  These six categorical elements of the PCI Data Security Standard (DSS), are: (i) Build and maintain a secure network; (ii) Protect cardholder data; (iii) Maintain a vulnerability management program; (iv) Implement strong access control measures; (v) Regularly monitor and test networks; (vi) Maintain an information security policy.</p>
</div>
<div>
<p>[21] <i>Supra</i> note 15, at 58.  With regard to PCI DSS in the context of the 2012 Data Breach Investigation Report (DBIR), we read:</p>
<p><i>“Overall, the standard attempts to set a bar of essential practices for securing cardholder data.  Nearly every case that we have seen thus far has attributes of its breach that could have been prevented if the control requirements had been properly implemented.  Of course, there is no way to be certain that new and different tactics could not have been used by the perpetrators to circumvent a compliant entity’s controls”.</i></p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/440/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=440&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/03/11/data-protection-and-retention-in-the-cloud-getting-it-right/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>In who’se pocket is your data packet? – International Data Governance.</title>
		<link>http://ogalaws.wordpress.com/2013/02/06/in-whose-pocket-is-your-data-packet-international-data-governance/</link>
		<comments>http://ogalaws.wordpress.com/2013/02/06/in-whose-pocket-is-your-data-packet-international-data-governance/#comments</comments>
		<pubDate>Wed, 06 Feb 2013 23:17:29 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Outsourcing and Cloud Computing]]></category>
		<category><![CDATA[cloud server jurisdiction]]></category>
		<category><![CDATA[Cloud Snooping]]></category>
		<category><![CDATA[data governance]]></category>
		<category><![CDATA[duqu]]></category>
		<category><![CDATA[Foreign Intelligence Surveillance Act (FISA)]]></category>
		<category><![CDATA[stuxnet]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=435</guid>
		<description><![CDATA[Having practiced law in the United States and still keeping a discerning eye on the occasional changes in U.S. National Security and other laws, I wrote, quite some time ago,[1] that it was important for anyone and everyone migrating to a cloud platform or not even “thinking” they used one, to be aware of such [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=435&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Having practiced law in the United States and still keeping a discerning eye on the occasional changes in U.S. National Security and other laws, I wrote, quite some time ago,[1] that it was important for <i>anyone and everyone</i> migrating to a cloud platform or not even “<i>thinking</i>” they used one, to be aware of such things as where their data stood, slept, or transited.  Now, it seems that more Canadians are aware of the need for this, with a recent article in the Ottawa Citizen newspaper drawing attention to the “near-open-access” to any and all data on U.S. servers,[2] no matter who the owner is, or where in the world they physically sit,[3] or are legally domiciled.[4]  If something is already comfortably in your own pocket where you can sense it and hear it jingle-jangle as you walk and talk, then only in the most extraordinary circumstances will someone ask you not to adjust it or look at it at your leisure, and actually have you comply.</p>
<p>&nbsp;</p>
<p>I still believe that the Cloud “<i>is</i>” a positive development and that it “<i>can</i>” be a productive platform – especially in terms of backup and redundancy, or in disasters and emergency situations, as was recently proposed in New Jersey.[5]  However, this worthy end-state can only be reached, when:</p>
<p>(a)    <i>Properly governed</i> by the appropriate regulators in a more globally cooperative fashion;[6]</p>
<p>(b)   <i>Used</i> with eyes wide open by both vendors and clients, and with proper regard to their rights and duties regarding third parties;</p>
<p>(c)    <i>Balanced</i> with enterprise, agency, and personal best practices, and insurance coverage appropriate to the data, users, risks[7] and regulations, and custodians;</p>
<p>(d)   <i>Legal counsel</i> sufficiently aware of the Cloud’s advantages and disadvantages to advise you, can draft or review your Cloud Services Agreements, or negotiate them from the outset, if the latter option is actually made available to you by the Vendor;</p>
<p>(e)    <i>Industry Vendors</i> agree to some degree of stabilization and standardization, and a modicum of synchronization in exigent situations that adequately respects local laws;</p>
<p>(f)    <i>Companies</i> in that space, begin – <i>in addition to the current rules on breach disclosure, notification, and remediation</i> – to be more open in educating the public on some of the potential Cloud hazards, as well as on the potential benefits of the many and evolving cloud-based offerings now available, including: <span style="text-decoration:underline;">SaaS</span> ~ Software as a Service (tools for processing, analysis, accounting, CRM, and back-office functions); <span style="text-decoration:underline;">UaaS</span> ~ Utilities as a Service (providing video, audio, and gaming on demand); <span style="text-decoration:underline;">PaaS</span> ~ Platforms as a Service (for email, online backup, or desktops-on-demand); and <span style="text-decoration:underline;">IaaS</span> ~ Infrastructure as a Service (tools for collaboration, integration, and visualization).</p>
<p>&nbsp;</p>
<p>As a work in progress the Cloud space is not a perfect thing, but it “<i>is</i>” a growing and increasingly popular and pervasive one, and it should now be obvious that those who do not even “<i>think</i>” they need to know about the Cloud, should actually be paying the most attention to its growth and diffusion into more and more facets of their work, lives, and free- or down-time.</p>
<p>************************************************************************</p>
<p><span style="text-decoration:underline;">Author</span>:</p>
<p>Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and <i>GRC</i> – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.). <i>Please See</i>: <a href="http://www.ogalaws.com/">http://www.ogalaws.com</a></p>
<p>He is an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: <a href="http://www.simprime-ca.com/">http://www.simprime-ca.com</a></p>
<p>Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</p>
<p><b>Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic <i>IMPRIME</i> Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</b></p>
<p align="center"><b><i><span style="text-decoration:underline;">This article does not constitute legal advice or create any lawyer-client relationship.</span></i></b></p>
<div>
<p>&nbsp;</p>
<hr align="left" size="1" width="33%" />
<div>
<p>[1] <i>See</i> Ekundayo George.  <i>To Cloud or Not to Cloud: What are Some of the Current, Most Pertinent Pros and Cons?</i> Text at points (c) and (d) under “<i>Disadvantages (potential)</i>”.  Published on ogalaws.com, December 28, 2011.  Online: &gt;<a href="http://ogalaws.wordpress.com/2011/12/28/to-cloud-or-not-to-cloud-what-are-some-of-the-current-most-pertinent-pros-and-cons/">http://ogalaws.wordpress.com/2011/12/28/to-cloud-or-not-to-cloud-what-are-some-of-the-current-most-pertinent-pros-and-cons/</a>&lt;</p>
</div>
<div>
<p>[2] Ian Macleod, The Ottawa Citizen.  <i>Cloud computing law puts Canadian users at risk of snooping by American spies</i>.  Published on ottawacitizen.com, February 2, 2013.  Online: &gt;<a href="http://www.ottawacitizen.com/business/Cloud+computing+puts+Canadian+users+risk+snooping+American/7907562/story.html">http://www.ottawacitizen.com/business/Cloud+computing+puts+Canadian+users+risk+snooping+American/7907562/story.html</a>&lt;</p>
</div>
<div>
<p>[3] The Telegraph.  <i>US authorities can spy on the iCloud without a warrant</i>.  Published on telegraph.com, January 30, 2013.  Online: &gt;<a href="http://www.telegraph.co.uk/technology/news/9836715/US-authorities-can-spy-on-the-iCloud-without-a-warrant.html">http://www.telegraph.co.uk/technology/news/9836715/US-authorities-can-spy-on-the-iCloud-without-a-warrant.html</a>&lt;</p>
</div>
<div>
<p>[4] Of course, some people have proclaimed that increasing encryption is the answer to protecting one’s privacy online.  However, considering the facts that: (i) the United States (although not the only place where they are made) puts severe restrictions on the export of certain technologies including those for encryption; (ii) it is commonly known in the security and technology fields that certain nations have an ability to “pre-etch” backdoors into their chips; (iii) external attacks may be targeted at specific hardware, software, or “<i>usage/speech</i>” by means of little known vulnerabilities, through the growing family of tools that now includes Stuxnet, Duqu, Flame, and Gauss, as well as the “Anonymous” entity, and others now in existence or still as yet unknown; and (iv) certain promoters of greater encryption have tended to receive greater regulatory attention …. this may be a little hard.</p>
</div>
<div>
<p>[5] Katie Eder.  <i>Experts consider how to address communications challenges ahead of next Sandy</i>.  Published on njbiz.com, February 5, 2013.  Online:  &gt;<a href="http://www.njbiz.com/article/20130205/NJBIZ01/130209911/Experts-consider-how-to-address-communications-challenges-ahead-of-next-Sandy">http://www.njbiz.com/article/20130205/NJBIZ01/130209911/Experts-consider-how-to-address-communications-challenges-ahead-of-next-Sandy</a>&lt;</p>
</div>
<div>
<p>[6] David Kravets.  <i>Internet Safe From Globalized Censorship as UN Treaty Fails</i>.  Published on wired.com, December 14, 2012.  Online: &gt;<a href="http://www.wired.com/threatlevel/2012/12/united-nations-internet/%3c">http://www.wired.com/threatlevel/2012/12/united-nations-internet/</a>&lt; Many naysayers had predicted that the goal of this conference was UN-domination of the internet, but its failure might have actually been due to the reluctance or outright refusal of certain nations, to submit to limits on extraterritorial surveillance.</p>
</div>
<div>
<p>[7] Terry Collins and Anne D’Innocenzio, The Associated Press.  <i>Twitter hackers nab data on 250,000 accounts</i>.  Published on ottawacitizen.com, February 2, 2013.  Online: &gt;<a href="http://www.ottawacitizen.com/business/Twitter+hackers+data+accounts/7911027/story.html">http://www.ottawacitizen.com/business/Twitter+hackers+data+accounts/7911027/story.html</a></p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/435/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/435/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=435&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/02/06/in-whose-pocket-is-your-data-packet-international-data-governance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
		<item>
		<title>Cybersecurity: the Enemy is also (perhaps even more so), Within – the case of “Bob”.</title>
		<link>http://ogalaws.wordpress.com/2013/01/17/cybersecurity-the-enemy-is-also-perhaps-even-more-so-within-the-case-of-bob/</link>
		<comments>http://ogalaws.wordpress.com/2013/01/17/cybersecurity-the-enemy-is-also-perhaps-even-more-so-within-the-case-of-bob/#comments</comments>
		<pubDate>Thu, 17 Jan 2013 16:04:15 +0000</pubDate>
		<dc:creator>Ogalaws</dc:creator>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Access monitoring]]></category>
		<category><![CDATA[Audit logs]]></category>
		<category><![CDATA[Bob outsourced to China]]></category>
		<category><![CDATA[Cyber Insecurity]]></category>
		<category><![CDATA[Employee as worst enemy]]></category>
		<category><![CDATA[Employee Screening]]></category>
		<category><![CDATA[IT Employee Best Practices]]></category>
		<category><![CDATA[Outsourced Cybersecurity]]></category>
		<category><![CDATA[The case of Bob]]></category>

		<guid isPermaLink="false">http://ogalaws.wordpress.com/?p=430</guid>
		<description><![CDATA[Much ado has been made about the hacking threat from overseas, with regard to cybersecurity.[1]  Indeed, several commentators repeatedly reinforce that belief.[2]  The truth, however, is that Information Technology and Information Systems (IT/IS) employees and contractors, right here in North America, might be the greatest danger and the weakest link in the chain.  The story [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=430&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Much ado has been made about the hacking threat from overseas, with regard to cybersecurity.[1]  Indeed, several commentators repeatedly reinforce that belief.[2]  The truth, however, is that Information Technology and Information Systems (IT/IS) employees and contractors, right here in North America, might be the greatest danger and the weakest link in the chain.  The story recently surfaced of a man who had outsourced his many software development contracts at several different employers, to offshore developers in China.[3]  He provided them with all his access codes and scripts, and was basically absent at work.  For how long he did this, or how much additional data those <i><span style="text-decoration:underline;">sub-contractors</span></i> were able to access and potentially download from those employers, and who they were … we may never fully know!</p>
<p>&nbsp;</p>
<p>As I have stated at length,[4] you need to take a comprehensive approach to Cybersecurity that also watches the employees and contractors at your back, while you are watching the outsiders in front of you.  In scanning only those 180 degrees left to right, and those 180 degrees north to south at your front, you are missing exactly that same size of iceberg at your back.  You must engage in strict Segregation of Duties, initial background checks, datalogs and audit trails, constant network monitoring, and other actions.</p>
<p>&nbsp;</p>
<p>Apparently, only one of his employers noticed a problem, and sought (outsourced) a deeper look.  Even then, why did it take so long for them to discover that: (i) the credentials assigned to a domestic worker; (ii) were accessing the system out of work hours, almost non-stop; (iii) from a place where the worker was not last noted to have traveled?  There needs to be more of a focus on internal security, employee access logging (where and when, for how long, and how frequently), and real-time system access audits.</p>
<p>&nbsp;</p>
<p>Clearly, it seems that some U.S. employers are still far from having a <span style="text-decoration:underline;">serious</span> approach to Cybersecurity.[5]</p>
<p>******************************************************************************</p>
<p><span style="text-decoration:underline;">Author</span>:</p>
<p>Ekundayo George is a sociologist and a lawyer, with over a decade of legal experience including business law and counseling (business formation, outsourcing, commercial leasing, healthcare privacy, Cloud applications, social media, and Cybersecurity); diverse litigation, as well as ADR; and regulatory practice (planning and zoning, environmental controls, landlord and tenant, and <i>GRC</i> – governance, risk, and compliance investigations, audits, and counseling) in both Canada and the United States.  He is licensed to practice law in Ontario, Canada, as well as in New York, New Jersey, and Washington, D.C., in the United States of America (U.S.A.). <i>Please See</i>: <a href="http://www.ogalaws.com/">http://www.ogalaws.com</a></p>
<p>He is also an experienced strategic and management consultant; sourcing, managing, and delivering on high stakes, strategic projects with multiple stakeholders and multidisciplinary teams.  <i>Please See</i>: <a href="http://www.simprime-ca.com/">http://www.simprime-ca.com</a></p>
<p>Backed by courses in management, organizational behaviour, and micro-organizational behaviour, Mr. George is also a writer, tweeter and blogger (as time permits), and a published author in Environmental Law and Policy (National Security aspects).</p>
<p><b>Hyperlinks to external sites are provided to readers of this blog as a courtesy and convenience, only, and no warranty is made or responsibility assumed by either or both of George Law Offices and Strategic <i>IMPRIME</i> Consulting &amp; Advisory, Inc. (“S’imprime-ça”), in whole or in part for their content, or their accuracy, or their availability.</b></p>
<p><b><i><span style="text-decoration:underline;">This article does not constitute legal advice or create any lawyer-client relationship.</span></i></b></p>
<div>
<p>&nbsp;</p>
<hr align="left" size="1" width="33%" />
<div>
<p>[1] Mark Clayton, Staff writer.  <i>Cyber security in 2013: How vulnerable to attack is US now?</i>  Published on csmonitor.com, January 9, 2013.  Online: &gt;<a href="http://www.csmonitor.com/layout/set/print/USA/2013/0109/Cyber-security-in-2013-How-vulnerable-to-attack-is-US-now-video">http://www.csmonitor.com/layout/set/print/USA/2013/0109/Cyber-security-in-2013-How-vulnerable-to-attack-is-US-now-video</a>&lt;</p>
</div>
<div>
<p>[2] Ed Beeson/The Star-Ledger.  <i>N.J. businesses should brace for higher cyber security costs, complexity, experts warn</i>.  Published on nj.com, January 15, 2013.  Online: &gt;<a href="http://www.nj.com/business/index.ssf/2013/01/nj_businesses_should_brace_for.html">http://www.nj.com/business/index.ssf/2013/01/nj_businesses_should_brace_for.html</a>&lt;</p>
</div>
<div>
<p>[3] Claire Gordon.  <i>Man Reportedly Outsources His Own Job To China &#8212; Then Spends His Time Watching Cat Videos.</i></p>
<p>Published on jobs.aol.com, January 16, 2013.  Online: &gt;<a href="http://jobs.aol.com/articles/2013/01/16/man-outsources-his-own-job-china/">http://jobs.aol.com/articles/2013/01/16/man-outsources-his-own-job-china/</a>&lt;</p>
</div>
<div>
<p>[4] Ekundayo George.  <i>Cybersecurity (the Nitty-Gritty; and what is Cyberspace?): A Different, Flexible Approach</i>.</p>
<p>Published on ogalaws.wordpress.com, December 9, 2011.  Online: &gt;<a href="http://ogalaws.wordpress.com/2011/12/09/cybersecurity-the-nitty-gritty-a-different-flexible-approach/">http://ogalaws.wordpress.com/2011/12/09/cybersecurity-the-nitty-gritty-a-different-flexible-approach/</a>&lt;</p>
</div>
<div>
<p>[5] More details about the May, 2012 discovery of that employee are available here.  <i>See</i> Andrew Valentine.  <i>Case Study: Pro-active Log Review Might Be A Good Idea</i>.  Published on verizonbusiness.com, January 14th, 2013.  Online: &gt;<a href="http://securityblog.verizonbusiness.com/2013/01/14/case-study-pro-active-log-review-might-be-a-good-idea/#more-2659">http://securityblog.verizonbusiness.com/2013/01/14/case-study-pro-active-log-review-might-be-a-good-idea/#more-2659</a>&lt;</p>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ogalaws.wordpress.com/430/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ogalaws.wordpress.com/430/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ogalaws.wordpress.com&#038;blog=26809769&#038;post=430&#038;subd=ogalaws&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ogalaws.wordpress.com/2013/01/17/cybersecurity-the-enemy-is-also-perhaps-even-more-so-within-the-case-of-bob/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/eafabccdb7db7422774545c3f9cca279?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ogalaws</media:title>
		</media:content>
	</item>
	</channel>
</rss>
