Friday, 17 February 2012

Digital Content & SOX compliance



SOX
The Sarbanes–Oxley Act of 2002 was put in place by the US government to protect investors in public companies following a series of corporate and accounting scandals perpetrated in the late 90’s and early 00’s which included Enron, Tyco International, Adelphia, Peregrine Systems and WorldCom. These scandals, which cost investors billions of dollars when the share prices of affected companies collapsed, shook public confidence in the nation's securities markets.
Much has been written about these scandals and also SOX and what is now required of Public Companies and their stakeholders to secure societies confidence in the Markets and keep corporate officers and employees out of jail. This piece concerns itself with a specific set of challenges relating to Digital Content used in a public company or for that matter any company.

Section 404, 802 & Digital Content
Section 404 of the Act “Assessment of Internal Controls” & Section 802 “Criminal Penalties for influencing US Agency Investigation” are key sections relating to the effectiveness of the act and the actions and processes public companies must take or put in place.

In particular section 404 is concerned with the prevention and detection of fraud and error and the adequacy of controls required. The integrity, authenticity and provenance of digital content (data, text, Audio, Video etc.) must be secured and be non repudiable. We know that digital content is much easier to change than paper based content and public companies must find cost effective solutions to assure trust and confidence in their management and control of Digital content. Section 404 focuses on content authenticity and integrity

Section 802: “ Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both”. This brings home the importance of being able to identify fraudulent, malicious or even just simple errors that may be part of an audit or evidential chain and required to establish trust and confidence in digital data/content. Section 802 in addition to the focus above in section 404 also brings attention to the history and flows of the digital content.

How can public companies identify and prevent fraud or error in their digital content cost effectively?

1.       Identify & List the company’s digital assets (versions, time lines etc.)
2.       Perform a Risk analysis and identify those critical digital assets
3.       Identify those critical digital content types and forms that must be protected and controlled through their life cycle.

Sample critical Digital Assets
·         Contractual documentation
·         Policy & Procedure documents and records
·         Intellectual Property
·         Trademarks and copyright
·         Financial reports
·         HR& employee  records
·         Performance Management records
·         Software applications
·         Software logs
·         Databases
·         Recorded telephone conversations
·         Recorded conference calls(Audio/Video)
·         Images, Photographs, Videos

Identify& implement appropriate software controls as a solution to the digital content/asset protection such as Digiprove.

What are the core features that a simple software solution must have?

·         Establish the authenticity and integrity of digital content on entry into the company’s digital world whether created within that world or entering externally whether it be via an electronic communications or scanned solution. (This can be achieved by creating a unique digital fingerprint of the content and meta data such as date, time, location, ownership)
·         Maintain full confidentiality of this digital content in that it does not get sent externally outside the companies own controlled digital world to be certified.
·         Create an audit trail for the defined digital content and any actions taken on that content.
·         Be able to verify the provenance of any digital content once it has been certified and verify if it has been tampered with.

Digiprove products tick all the boxes:

Selfprotect – a simple SaaS on-line service for content and communications
Autoprotect – a simple background utility that automatically protects the identified files and folders.
Completeprotect – includes digital log event certification and audit trail along with autoprotected content. (New Product)
Signasure – enables and protects documents with all types of digital signatures (New Product)
Brokerprove – A standalone solution for SME professional service providers
Embedprotect – A software developer’s kit that enables Digiprove technology to be quickly integrated into a company’s business applications



HR Digital Content & SOX compliance



SOX
The Sarbanes–Oxley Act of 2002 was put in place by the US government to protect investors in public companies following a series of corporate and accounting scandals perpetrated in the late 90’s and early 00’s which included Enron, Tyco International, Adelphia, Peregrine Systems and WorldCom. These scandals, which cost investors billions of dollars when the share prices of affected companies collapsed, shook public confidence in the nation's securities markets.
Much has been written about these scandals and also SOX and what is now required of Public Companies and their stakeholders to secure societies confidence in the Markets and keep corporate officers and employees out of jail. This piece concerns itself with a specific set of challenges relating to HR  Digital Content used in a public company or for that matter any company, and the role of HR in ensuring best practice for digital content relating to the management of the primary asset of the company “It’s staff”

Section 404, 301,806 & Digital Content
Section 404 of the Act “Assessment of Internal Controls”

In particular section 404 is concerned with the protection of corporate assets. HR in the context of the overall goals of SOX “To protect investors in public companies” contribute to internal controls relating to people that could create significant financial risk for the organisation including employment law litigation and fraud. Employment contract clauses such as non-disclosure, non-solicit, non-compete, IPR & confidential information protection and performance standards are all critical as are the HR processes to control and manage any exposure. Training is another area of importance such as specific job skills, health & safety, and legal obligations the integrity of the training and training records are also central to avoiding potential litigation whether it be commercial, employment law or product/professional indemnity financial exposures. Add to this that rules and policies relating to procurement, expense reporting and commissions all create potential fraud opportunities then we can see HR their processes and digital content make a significant contribution to SOX compliance.

Section 301 & 806: are also key sections where HR digital content is fundamental to compliance and in fact may produce important digital evidence for internal or external scrutiny. The sections refer to the “Whistle-blower” requirements which are usually managed by HR. Creating a trusted Whistle-blower process with integrity may involve digital content of many types including databases, documents, audio and video records. HR must ensure that the process is fair and transparent, it protects the rights of all parties and that there is avoidance of retaliation litigation risk. Not only that but once whistle-blower reports an incident everything in the system becomes potential evidence so as ediscovery finds this evidence the digital forensic chain must be secured.

How can HR in public companies identify and prevent litigation & financial risk?

1.       Identify & List the company’s HR digital assets (versions, time lines etc.)
2.       Perform a Risk analysis and identify those critical digital assets
3.       Identify those critical digital content types and forms that must be protected and controlled through their life cycle.
4.       Ensure that whistle-blowers procedures are digital and evidential friendly
5.       Put in place adequate digital evident and asset authenticity and integrity controls






Identify& implement appropriate software controls as a solution to the digital content/asset protection such as Digiprove.

What are the core features that a simple software solution must have?

·         Establish the authenticity and integrity of digital content on entry into the company’s HR digital world whether created within that world or entering externally whether it be via an electronic communications or scanned solution. (This can be achieved by creating a unique digital fingerprint of the content and meta data such as date, time, location, ownership)
·         Maintain full confidentiality of this HR digital content in that it does not get sent externally outside the companies own controlled digital world to be certified.
·         Create an audit trail for the defined HR digital content and any actions taken on that content.
·         Be able to verify the provenance of any HR digital content once it has been certified and verify if it has been tampered with.

Digiprove products tick all the boxes:

Selfprotect – a simple SaaS on-line service for content and communications
Autoprotect – a simple background utility that automatically protects the identified files and folders.
Completeprotect – includes digital log event certification and audit trail along with autoprotected content. (New Product)
Signasure – enables and protects documents with all types of digital signatures (New Product)
Brokerprove – A standalone solution for SME professional service providers
Embedprotect – A software developer’s kit that enables Digiprove technology to be quickly integrated into a company’s business applications


Monday, 6 February 2012

Data Protection & Digital Content in HR: How To Draft A Policy


We know that the aim of a data protection policy is to ensure that employees are aware of their own rights, and of their obligations concerning personal data processed by their employer.  The purpose of a data protection act is to enforce compliance from employers to make sure they carry out their obligations to the employee. So, who is a data protection policy for, and what exactly can it do that benefits a HR department?

A data protection policy is not only for the benefit of full time employees. It could be used to protect contract workers, agency staff and other kinds of workers too. In the HR department, it is particularly important that employee data is protected; especially considering it’s the department that all major employment decisions go through. This kind of data requires high security and proof of authenticity.

How do we go about formulating a data protection policy?

A lot goes into designing a data protection policy, but here are a couple of points to get you started. A general data protection policy should:

·         Identify a person within the organization who will have responsibility for ensuring that the employer complies with data protection regulations. This person will usually be a senior figure in the HR department.

·         It should ensure that employees are fully aware of any data held about them, and that they understand how this data could be used and disclosed. It is normal practice that an organization will use personal data like salary and pensions, and this will be held on an electronic device. The depth of this data could go further, for example employers may keep health records for reference.

It is vital that employee data held on organizational systems can be transparent and trustworthy. That’s where Autoprotect comes in as an asset to the HR department in maintaining legitimacy of files, and supporting their data protection policy.

The above are just two points about what a data protection policy should enforce. For further information, make sure to keep your eyes on our blog.


Wednesday, 1 February 2012

Socitm Seminar "Fri Feb 10th" Park Ave Hotel, Belfast

Efficiency – the tools of the trade

Park Avenue Hotel, Belfast

Friday 10th February 2012



Agenda


  9:30am           Registration

10:00am           Welcome and opening remarks
Joe Dolan, Chair SOCITM NI

10:10am           Reducing the Cost of your Telecommunications Infrastructure
- meeting your audit and governance requirements
                        Ger Connery, Sentel


10:50am           ITIL – Sustainable Efficiency, Effectiveness & Value in IT Services
            Bill Heffernan, Principal ITSM consultant SureSkills



11:20am           T E A   A N D   C O F F E E


11:40am           Implementing LEAN in a customer services environment
                        Jonathan Wilson, The Gem


12:10pm           Work of the Performance and Efficiency Delivery Unit (PEDU)
Richard Pengally, Performance and Efficiency Delivery Unit



12:30pm           Closing Remarks
Joe Dolan, Chair SOCITM NI
  
L U N C H
        
         
To reserve a place, please contact the branch secretary: Marie McCrory
To find out more about Socitm NI, please visit: http://www.socitm.net
To become a member of Socitm NI  https://www.socitm.net/forms/form/12/join_socitm


Monday, 23 January 2012

Compliance & Value of digital signatures

Under the Electronic Commerce Act 2000 of Ireland, electronic communications are equally valid with paper-based communications. Electronic signatures are valid if the receiving party consents to the use of an electronic signature.  The definition of an electronic signature in this legislation is very broad: "electronic signature, an advanced electronic signature, an electronic signature based on a qualified certificate, an electronic signature created by a secure signature creation device or other technological requirements relating to an electronic signature"

There is however one caveat - where there is a legal obligation to retain original documentation e.g. Financial Advisor needs to keep client instructions for 7 years, the electronic record can meet this requirement, provided that:
  • there exists a reliable assurance as to the integrity of the information from the time when it was first generated in its final form, whether as an electronic communication or otherwise,
  • where it is required or permitted that the information be presented— if the information is capable of being displayed in intelligible form to a person or public body to whom it is to be presented,
  • if, at the time the information was generated in its final form, it was reasonable to expect that it would be readily accessible so as to be useable for subsequent reference,
  • where the information is required or permitted to be presented to or retained for a public body or for a person acting on behalf of a public body, and the public body consents to the information being presented or retained in electronic form, whether as an electronic communication or otherwise, but requires that it be presented or retained in accordance with particular information technology and procedural requirements— if the public body's requirements have been met and those requirements have been made public and are objective, transparent, proportionate and non-discriminatory, and
  • where the information is required or permitted to be presented to or retained for a person who is neither a public body nor acting on behalf of a public body— if the person to whom the information is required or permitted to be presented or for whom it is required or permitted to be retained consents to the information being presented or retained in that form.
However Digiproving does have the following real advantages:
  1. When added to electronically signed document at the same time the document is signed, it meets any statutory obligation in relation to retention of original documents
  2. Offers an irrefutable assurance that the document has not been altered either accidentally or deliberately since its creation
  3. Offers an irrefutable timestamp certifying the time of creation of the document (And location information if it is available on the device)
  4. It meets the requirements for retention of records (In digital format), thus creating less dependence on paper records.
Items 2 & 3 are important because not only do they provide comfort to the receiving party (who must after all consent to the use of e-communications) of the integrity of the document, they remove all reasonable doubt (whether in a court case or otherwise) that a document could have been altered.  Other safeguards such as archiving and time stamping logs may be circumvented by any software engineer or gifted amateur, or indeed by malicious design.

Finally the legislation describes an "advanced electronic signature based on a qualified certificate".  I am pretty certain this means what is usually referred to as a Digital Signature, based on PKI using CAs such as Verisign (such as what is implemented in Adobe and there are many examples like this I think An Post have something as well).  This has one particular legal advantage in that it is recognised as a witnessed signature, and appears to be a requirement in applying signatures to documents that require witnessing. Cryptographically it is a very secure solution.  However it comes with a major overhead - everyone who signs has to have a Digital ID (or digital certificate) from a recognised CA.  There is (as you would expect) a whole process involved in proving your identity to the CA, and of course an annual cost.  Despite massive promotion by companies like RSA and Baltimore in the late 90s this technology did not succeed.

For more information

http://www.digiprove.com/

http://www.brokerprove.com/ for financial advisors

Thursday, 19 January 2012

Financial Trading Irish Development beyond the Efficient Market Hypothesis

Why Fractal Market Hypothesis is more relevant to the Efficient Market Hypothesis an interesting paper as an outcome of the collaboration between the DSP research group in DIT led by Dr Jonathan Blackledge and CEO of TradersNow who have taken the core Algorithm research and created a set of trading Algorithms for Foreign Exchange initially. These Algorithms give statistical advantage such as 73% exit efficiencies to FX Traders.

Paper

Wednesday, 14 December 2011

3 Company Update

Digiprove: Is a content security company focused on Digital Content authentication and integrity, with many applications. It’s a SaaS model and the initial product http://www.digiprove.com/ has 5000 users. We have a beta release of Digiprove Autoprotect (Runs in background, and automatically connects to our “Proof Engine” to certify new or changed content), Digiprove Signature (Enables any electronic signature while maintaining security and compliance) & a Software Development kit. My contribution so far has been to refocus on the B2B segment and enable the technology to be embedded in other software applications and products cheaply and quickly using the SDK. We have integrated with applications in Financial Services, HR , ICT , and have partners now working on applications in ecommerce (merchant services), eDiscovery, DRM and DAM. SDK provided for free and revenues are based on monthly subscription based on volume of “Proof Engine” transactions with attractive revenue share for partners. I am exec chairman of the company.


TradersNow:- Is a spin out from the Dublin Institute of technology and has developed a Trading Algorithm based on Fractals and the work of Global leader in the field of maths and DSP, Dr Jonathan BLackledge who is part of the team. The algorithm can be used in automated trading on the financial markets and gives a significant and scientifically proven advantage on FX currency pair trades (Our beach-head sector). We are just completing R & D and I am defining the B2B and B2C business model with the team so we can build the on-line solution for Q1 launch. I am interested in any introductions to have a friendly chat with trading experts purely to help me further understand the markets (Professional or Private Traders).  www.tradersnow.com

Holignment:- On-Line Organisation Maturity Diagnosis and Frameworks (The CMMI of the OD world), has  engaged with Beta partners in Europe & Asia and is working on a small number of  multinational  opportunities. In addition we have been working with IBM and social connections supporting the OD and people side of gaining traction for collaboration platform deployments (Pre Revenue) www.collaborationip.yolasite.com.