Showing posts with label transparency. Show all posts
Showing posts with label transparency. Show all posts

Thursday, June 10, 2010

Technics: Internet Biz Transparency: Google explains and justifies itself on its transparency/privacy policies

It seems the sometimes glorious, sometimes nefarious Google has just set the standard for corporate accountablity in regard to transparency.

Google Explains Security Procedures

by Thomas Claburn,InformationWeek (Jun5,2k10)

In what it describes as a move toward greater transparency, Google has provided details about its security practices in a newly published paper.

In an effort to communicate its commitment to the security of its online services, Google on Friday published a paper that delves into its corporate security strategy. Eran Feigenbaum, director of security for Google's enterprise group, characterizes the paper as an attempt to be more transparent. It would also be fair to characterize the paper as an attempt to counter the perception that Google's online services are somehow less secure than traditional on-premises systems, a claim often made by Google's competitors.

More Security Insights

  • Whitepapers Panic slowly: integrated disaster response and built-in continuity




  • ForwardView: Four Areas of security vital to business health




  • Webcasts:

  • DNS DDOS Threats and Corresponding Mitigation Strategies




  • Spoofing Server2Server Communication: How You Can Prevent It




  • Analytics Breach, Diaries, Virtual Servers, Real Risks




  • Vids

  • Videos



  • Heartland Payment Systems suffered a major security breach at the hands of Russian Hackers. It sent shockwaves through the industry. We talked to CSO Kris Herrin about the attack and what's being done at Heartland and across the industry.

    Feeling comfortable storing data in the cloud involves trusting a cloud services provider and the practices and policies they have in place," said Feigenbaum in a blog post. "In today's ultra-connected, Web-capable world, [and] understanding how data will be protected -- [this concept] is ultimately more meaningful than knowing it [your data, perhaps a company's worth of it] is physically located in one data center or another."

    Google itself put that trust at risk earlier this year when it disclosed that "a highly sophisticated and targeted attack on our corporate infrastructure originating from China, that resulted in the theft of intellectual property from Google."

    China and Google

    Part of Google's response to that incident -- said to be made possible as a result of a previously unrecognized flaw in Internet Explorer 6 -- has reportedly been phasing out the use of Microsoft's Windows operating system at the company, a move that may be motivated by marketing concerns in addition to worries about security.

    But Google's work making potential customers feel comfortable in its cloud isn't done. In March, Yale delayed a planned move to Google Apps for Education over s e c u r i t y concerns. When the City of Los Angeles was considering abandoning its Novell e-mail system for Google Apps and Gmail, similar concerns were raised. The deal ultimately went through but such fears remain.



  • Technotes, by Sportikos



  • Google's paper, Security Whitepaper: Google Apps Messaging and Collaboration Products, should help allay those fears. It describes the company's

    corporate security policies,
    organizational and operational security,
    asset classification and control
    practices,
    personnel,
    physical, and environmental security,
    access control,
    systems development and maintenance, and
    disaster recovery efforts.


    It may not be quite as fun as, say, the comic book Google used to introduce its Chrome browser, but it's likely to help IT decision-makers render more informed judgments about Google's services.

    Dark Reading's Vulnerability Management Tech Center is your portal to all the news, product information, best practices, reports, and other data related to detecting and remediating security vulnerabilities. Check it out now.

    Friday, May 28, 2010

    Tech: Govt Info: Expo in Washington lobbies Fed govt for new digital info policy

    A h+powered expo and conference in Washington DC will lobby for new ideas regarding govt accessiblity and info-transparency, according to the values of the Open Government movement. The event goes under the rubric of "Gov 2.9: Aspiring to greatness in Open Government," according to Governement IT Blog and the email newsletter InformationWeek Government (they have several other newsletters targetting non-govt topics, with information on information of various kinds).

    Gov 2.0: Aspiring To Greatness In Open Government

    Posted by John Foley (editor, InformationalWeek) on May 24, 2010 04:46 PM

    Tim O'Reilly is raising the bar on what he envisions for the open government movement. At this week's Gov 2.0 Expo in Washington, D.C., O'Reilly won't be talking merely about government serving as "a platform" -- that was last year's idea -- but about government as "a platform for greatness."

    It's an ambitious goal for a concept that's still so new and unproven, but O'Reilly, the tech book publisher and Web 2.0 evangelist, is right to think beyond the release of data sets once cordoned off behind the federal firewall, which is only a starting point. He foresees not just new services and applications being delivered from government platforms, but, in some cases, originating from smaller government entities and at lower costs relative to existing services. "There's an opportunity to rethink how certain government programs work," Tim told me in a phone conversation.

    O'Reilly compares "government as a platform" to the iPhone phenomenon in which Apple's smartphone serves as a foundation for thousands of applications created by a thriving ecosystem of third-party developers. Think of how that model might apply to the departments of Agriculture, Energy, Health and Human Services, Transportation, and the EPA -- with thousands of useful new apps and services being offered, but not by the government itself -- and you begin to see the potential.

    The Obama administration unveiled its Open Government Directive in December 2009, and just last month agencies submitted detailed plans on how they will meet the mandate to become more open, participatory, and transparent. You can find a spreadsheet-like dashboard of where federal agencies are in meeting the Directive here. OpenTheGovernment.org has its own audit of agency plans.
    Technotes, by Owlie Scowlie


    Fine and dandy, with all due respect to the visionaries and evangelists of this proposed free-market innovation in digital info-flow: but without the integration of a security-minded stream, the entire advocacy posture becomes glaringly one-sided. Notice that Foley doesn't mention the Department of Homeland Security, but I imagine there are app developers out there with competence to add to the iPhone (and smart phones generally) a few cryptpgraphic ideas, and even apps for notifying local authorities of mischief on the order of the recent attempted terrorism at Times Square. Just a thawt.