Guide to the TechWeb Network


The InformationWeek -- Blogs
CIOs Uncensored

Topics:   CIOs Uncensored

  • Email this page E-mail this page
  • |  Print this page Print this page
  • |   Bookmark and Share

The CIO And Privacy: Liable, Culpable, Or Merely Responsible?


Posted by John Soat, Jan 4, 2008 06:26 PM

Or maybe all of the above. What exactly is the CIO's role and responsibility in protecting the digital privacy of customers, partners, and employees and the security of proprietary corporate data? Where does the privacy buck stop?

Jim Haskin, the CIO of Websense, a company that markets Web-filtering technology, has his own opinion on the CIO's potential exposure when it comes to privacy problems. "Liability is a specific term," Haskin says. "Culpability might be better."

The specifics of liability concerning the loss or exposure of personal data have been spelled out in legislation such as Sarbanes-Oxley and HIPAA, he says, and that's a good thing. "In this rapidly changing environment, there is a role for legislation that constitutes reasonable business practices" around privacy, he says.

Maybe because of the business he's in, Haskin's more concerned with corporate data privacy than consumer data privacy. The security of consumer data -- or lack thereof -- has been driving the privacy conversation up till now, Haskin points out. It's also driving most of the privacy legislation pending in Congress, legislation that's primarily concerned with notifying consumers when there's been a breach of their personal data.

"I'm not mitigating consumer data," Haskin says. "That's the one that's gotten all the publicity." But companies need to protect all their valuable data, in all its forms and vectors, he says. Companies should be equally concerned with protecting proprietary corporate data and intellectual property, everything from inventions and formulas to marketing plans and business strategies.

In fact, public companies should consider it a fiduciary responsibility, which puts the onus and obligation for security and privacy of that data at the board level. And that's where the federal government comes in. Haskin stops short of advocating the "L" word -- legislation -- but he does believe that the federal government should have a hand in "setting standards for what needs to be protected."

Just like public companies have to have security policies, they should be required to have policies and procedures in place to guard valuable "unique and proprietary data" that, if compromised, would lead to financial exposure for a company: loss of brand loyalty, loss of market share, loss of IP, and/or loss of consumer confidence. "I think there is a need at a very high level to define the categories and types of data that should be protected," Haskin says.

Once again, he stops short of advocating legislation. "You don't want to get down to the 'how,' " he says, but standards need to be defined "on the federal level rather than the state [level], just from a complexity standpoint."

Does that take the responsibility for data security and privacy off the CIO? Not necessarily, Haskin says. But for him, it's a corporate obligation, and that means the privacy buck ultimately should stop at the board level.

What do you think? Are CIOs liable for data privacy breaches? And does that keep you up at night?


« Goodbye Google, Hello Startups | Main | Microsoft Gives Bloggers A Free Ride At CES (Literally) »



Tomorrow's CIO: Do you have what it takes?
Find out at the 2008 InformationWeek 500 Conference
Sept. 14-16, St. Regis Resort, Monarch Beach, Calif.


Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




InformationWeek Chief Of The Year:
Call For Nominations
Know a dynamic, future-oriented tech chief? We're looking for the most insightful, innovative, forward-thinking business technology leader to honor as our 2008 Chief Of The Year. "Tomorrow's CIO" is the theme of our InformationWeek 500 Conference, and of a recent in-depth InformationWeek Analytics Report based on our extensive survey. The qualities identified with Tomorrow's CIO—equal parts leadership, vision, business savvy, technology expertise--are what we're looking for in our Chief Of The Year.

Candidates must be CIOs, CTOs, or VP-of-IT level executives. Nominations will be accepted now through Oct. 31, 2008.

Please send your nominations to: jsoat@techweb.com.



CIOs Uncensored Video



  1. Google Explains Why It Nixed Bluetooth And GChat From Android SDK
  2. Engineering Drawings, TV Spot Of The G1 Android Phone Surface
  3. Cost Of An Official Unlocked 3G iPhone: $1,649
  4. Early Thoughts On The Palm Treo Pro Not Flattering
  5. The Touchscreen BlackBerry Storm Emerges


  1. Broadcom Says Qualcomm In Contempt On Patents
  2. Dell's Profit Drops As IT Spending Slowdown Spreads
  3. FBI Arrests Blogger Over Online Music Sharing
  4. Best Western CIO Scott Gibson On The Data Breach That Wasn't
  5. Google Unveils Android's App Store
  6. Oracle Ties Middleware To Eclipse Workbench

 
 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007
AUGUST 2007
JULY 2007
  JUNE 2007
MAY 2007
APRIL 2007
MARCH 2007
FEBRUARY 2007
JANUARY 2007
DECEMBER 2006
NOVEMBER 2006