Memorandum by Symantec
ABOUT SYMANTEC
Symantec is a world leader in providing solutions
to help individuals and enterprises assure the security, availability,
and integrity of their information. Headquartered in Cupertino,
Calif., Symantec has operations in more than 40 countries.[12]
Symantec welcomed the publication of the House
of Lords report into Personal Internet Security in August 2007.
Since its publication the report has encouraged discussion around
the responsibility of security on the Internet and has helped
to highlight and raise greater awareness of the need to fight
e-crime in the UK. In preparation for the forthcoming debate on
the Committee's findings Symantec appreciates the opportunity
to provide additional input to the Committee.
The aim of the following submission is to provide
supplementary evidence in response to the recommendations made
by the Committee and the Government's response to the Committee's
report on three key issues:
Data security breach notification
law.
Establishment of a Police Central
e-Crime Unit.
DATA SECURITY
BREACH NOTIFICATION
LAW
It is suggested that the recent high profile
incidents of personal data loss has prompted wide discussion in
the UK on the level of security given to personal information
shared, processed, stored and transmitted electronically. Incidents
where personal sensitive information, such as financial, contact
and employment information, and sensitive identity related data
has been lost, stolen, accessed or disclosed without authorisation,
are leading to questions and increasingly, demands for answers,
by citizens as to what happens if their data is involved in such
incidents. Gaining and maintaining the trust and buy-in of citizens
that their data is secure and protected therefore represents a
potential risk to the future development of innovative, higher
value added online services and will be a key challenge going
forward for organisations and the Government.
Symantec, therefore, welcomed the Committee's
recommendation for the introduction of data breach notification
law in the UK as a matter of urgency. While the Government's recognition
that such a suggestion warrants further discussion and consideration
is understood and accepted, the view that the introduction of
notification initially within the UK would not "lead to an
improvement" or have an impact on the safety and protection
of personal information is, we feel, debatable.
The development and introduction of an appropriately
drafted data breach notification legal requirement is seen as
an important incentive to increase levels of security and also
help raise greater awareness, and reassurance, of how personal
data is protected online. It is also suggested that a data breach
notification law could help to raise citizen's awareness of the
risks their data is being open to and therefore enable them to
take appropriate action where necessary. By being given information,
citizens can become more empowered to make informed decisions
and take measures to protect their identities that may be at risk.
Such activities may include monitoring financial accounts for
discrepancies, not responding to potential phishing emails related
to a data breach or simply ensuring personal information is not
disclosed unnecessarily. It can be argued that the action of presenting
an individual with a data breach notification letter, for example,
could mean that individuals become more aware of the situation
and by being fully informed are able to take action they see as
appropriate to protect their identity or personal information
going forward.
Based on the evidence given in its response,
regarding the disjointed approach taken across US States to the
introduction of data breach laws, the Government's concerns and
questions expressed as to the positive impact of the data breach
legislation in the US are understood. However, it should be recognised
that if introduced, a data breach notification requirement would
simply be an addition to the already effective existing Data Protection
legal framework in place in the UK and across Europe. The current
European Data Protection law effectively protects the lifecycle
of personal data from its collection and processing to its storage.
However, the current legal framework does not address circumstances
where data is lost or stolen. A legal gap therefore exists that
needs to be closed particularly in light of the increase in incidents
of data being lost or stolen occurring in Europe. Closing this
gap would not only complement the current Data Protection legislation
but also serve to enhance the security of data throughout its
complete lifecycle.
Symantec does agree with the Government that
given the potential impact of legislation in this area it is important
that the move towards data breach notification is one which is
carefully considered. This is vital to ensure that a clearly defined
legal framework and appropriate operational procedures are established
that is workable and not burdensome on either citizens or industry.
For example, there is further discussion needed on how a data
breach notification requirement in the UK would work in practice;
fundamentally in the event of a breach what immediate action would
an organisation have to take. This includes the definition of
an incident that would be considered a "breach" of data
and the level of seriousness a breach would have to be to trigger
a notification obligation; in addition, as identified by the Government's
response, whether companies would be required to notify the Information
Commissioner's Office (ICO) before alerting customers. This raises
the question of whether the decision to notify customers will
rest with the ICO or with the organisation itself. These definitions
are a vital part of any data breach legal framework and must be
clearly defined so that companies clearly understand when a data
breach notification requirement would be triggered. Also any legal
requirement that is drafted should include a safe harbour provision
to ensure that in the event of a data breach, organisations that
can demonstrate an adequate level of data security are relieved
from liability and possible legal or financial penalties for the
breach.
Nevertheless Symantec welcomed the Government's
recognition that any data breach notification requirement should
not apply solely to communication provider "in isolation".
Recent incidents of data loss in other key sectors, such as finance
and retail, indicates a strong argument that companies in all
sectors, public and private, that are processing and storing individuals
personal data electronically should be required to comply with
a data breach notification law. In the latest Symantec Internet
Security Threat Report, published in September 2007, education
was the highest sector for data breaches that could lead to identity
theft with 30 per cent. This was followed by government (26 per
cent), healthcare (15 per cent) and the finance sector (14 per
cent). The Government's review that if a data breach law is introduced
in the UK it should not impact solely any one sector is therefore
supported by Symantec.
Given that the European Commission's proposals
to introduce a data breach notification law for the communication
sector may not come into force until at least late 2009 early
2010, it is suggested that further consideration and discussion
is needed on the need for the UK to become a pioneer and lead
the way in Europe but introducing an appropriate, and reasonable,
data breach notification requirement in the UK and not wait possibly
for five years for the European legislative process to introduce
breach notification that will only impact one sector. Symantec
believe that an appropriate data breach notification law could
be effective if applied to all sectors that are processing and
storing individual's personal data. However, the steps currently
being taken by the European Commission to introduce an appropriate
data breach notification requirement across Europe is seen as
a step in the right direction.
ESTABLISHMENT OF
A POLICE
CENTRAL E
-CRIME UNIT
The Committee's acknowledgment that the Internet
has become a powerful and critical tool in the UK's national infrastructure
is reflective of the in-depth investigation and consideration
the Committee has given to this important topic. Symantec agrees
with the Committee that industry, end users and the Government
all need to be doing more to ensure the protection of this resource.
In particular Symantec endorses the Committee's recommendation
supporting the creation of a Police central e-Crime Unit. The
Government's response that consideration was being given to the
business case for creation of a dedicated law enforcement unit
for e-crime along the lines proposed by the Committee is also
encouraging. However, while it is understood that the National
Fraud Reporting Centre has been given additional funding in the
recent Comprehensive Spending Review to develop a strong "anti-fraud
culture", in addition to further investment for policing
and a more strategic approach to be taken towards "cutting
crime", e-crime was noticeable by its absence in the Government's
spending plans published back in October 2007. As we now move
into March 2008 it is still not clear whether the business case
for the creation of a Police central e-Crime unit will be supported
both operationally and more importantly financially.
In its response, the Government acknowledged
that national co-ordination for policing in this area could bring
benefits to the fight against e-crime in the UK. This view is
supported as is the comment that for the creation of any new unit
there must be a clearly defined need in order to ensure an effective
response. It is agreed that an e-Crime policing unit would need
to have clearly defined aims, objectives and goals. However, Symantec
believe there is a clear need for a national police presence in
the fight against e-crime in the UK.
The recent shift in the online threat environment
towards computer related attacks being motivated, not by notoriety,
but by economic gain has resulted in individual users, as well
as companies, becoming front line targets for cyber criminals.
Individuals are increasingly targeted by attacks designed to steal
confidential information that can be used to commit fraud and
theft. It is understood that such crimes must be investigated
and prosecuted as traditional crimes (such as fraud) merely conducted
using a new tool (technology). However, it must be recognised
that policing resources, focus and training are needed to effectively
investigate and address these modern technological enabled crimes.
This is why there is a clear need for the creation of a central
e-crime police unit that can support law enforcement efforts.
The UK is currently one of the most effective and best placed
countries in addressing cyber crime. In order for this reputation
to continue however, Symantec believe more training and more resources
are needed by UK police not just in London but across the whole
of the UK. The introduction of a dedicated national e-Crime policing
unit would be a step in the right direction to enhancing the UK
police's ability to respond to e-crime effectively; at a time
when concerns regarding online security risks, arising from spam,
phishing, social networking sites and online data theft, may be
preventing citizens gaining the full benefits from the Internet.
For example results of a recent Get Safe Online campaign survey,
to which Symantec is a leading sponsor, indicates that almost
one in three UK internet users[13]
will not conduct banking online due to their fears about safety
and security.
VENDOR LIABILITY
When the Committee's findings were published
in August 2007, Symantec welcomed the Committee's recognition
of the importance of ensuring interoperability, consumer choice
and a competitive landscape in the information security market.
However, the view that software companies should be liable for
ineffective products and services offered to users is nevertheless
challenged. There is also concern at the Government's response
to the Committee which suggested that there is "scope"
for further discussion of this issue at the European level. Symantec
believe extending the product liability regime of the European
Consumer Sales Directive, as discussed in the European Commission's
Green Paper, to digital content including software could result
in reducing consumer choice and risks the opposite effect of reducing
users' security and privacy.
The Committee's suggestion in this area does
not take into account the complexity of the IT industry. Essentially
software companies cannot be liable for what they do not effectively
control. For example, how the customer installs, configures, uses
and updates its software. Effective security is a combination
of a layered security approach, processes, people and technology.
An approach whereby the liability burden is placed on software
providers therefore runs the risk of simply putting the burden
only on technology and ignores all the other components. Also,
it is doubtful that companies would be prepared to take liability
for their products unless they can assume a level of control on
how the interoperability takes place and ensure it does not affect
their applications This may lead to technology providers using
more privacy-invasive technologies to control not only the interoperability
allowed but possibly user actions in order to avoid or limit liability.
Ultimately, an approach along those lines could fundamentally
impact the control users have on their computer. It could also
result in more and more closed platforms and a potential situation
where one dominant provider could dictate what can be installed
and may limit the choices of consumers to "approved content".
This could have a negative impact on competition in the market
and risks creating monocultures in information security terms
which, as explained to the Committee in our written and oral evidence,
could create a single point of failure across the Internet's infrastructure.
As a result there is real concern that the introduction of vendor
liability could have the unintended consequences of reducing consumer
choice and negatively impacting the level of information security
that users currently enjoy. If vendors have to absorb product
liability in their business models then the current innovation
environment of open and interoperable platforms will be radically
shifted.
Symantec remains supportive of the overall objectives
of the Committee in trying to support Internet users and ensure
there is an adequate level of protection for users against online
threats. The Government's recognition that the debate around vendor
liability should not prevent innovation in the market or lead
to a reduction in the quality of software is welcomed. However,
it is argued that by following a legislative path discussed by
the Committee that may lead to the introduction of vendor liability
could very well result in the situation that the Government agrees
must be prevented.
March 2008
12 www.symantec.com Back
13
Get Safe Online Survey Published November 2008 www.getsafeonline.org. Back
|