<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NOWHERETOHIDE.ORG &#187; data sharing</title>
	<atom:link href="http://www.nowheretohide.org/category/data-sharing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nowheretohide.org</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 27 Aug 2010 17:57:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Having trouble convincing the boss to spend on Security and Privacy protection? Read on&#8230;</title>
		<link>http://www.nowheretohide.org/2010/01/30/having-trouble-convincing-the-boss-to-spend-on-security-and-privacy-protection-read-on/</link>
		<comments>http://www.nowheretohide.org/2010/01/30/having-trouble-convincing-the-boss-to-spend-on-security-and-privacy-protection-read-on/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 03:35:05 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Information sharing]]></category>
		<category><![CDATA[Law enforcement information sharing]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[cost of data breach]]></category>

		<guid isPermaLink="false">http://www.nowheretohide.org/?p=578</guid>
		<description><![CDATA[The Poneman Institute, considered the pre-eminent research center dedicated to privacy, data protection and information security policy, released its 2009 Ponemon Institute &#8220;Cost of a Data Breach&#8221; Study on January 29, 2010. In the report, they published the results of their fifth annual study on the costs of data breaches for U.S.-based companies. They surveyed 45 companies represnting [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nowheretohide.org/wp-content/uploads/2010/01/COB-2009-Poneman-Study.png"><img class="alignright size-medium wp-image-579" title="COB 2009 Poneman Study" src="http://www.nowheretohide.org/wp-content/uploads/2010/01/COB-2009-Poneman-Study-233x300.png" alt="" width="154" height="204" /></a>The Poneman Institute, considered the pre-eminent research center dedicated to privacy, data protection and information security policy, released its 2009 Ponemon Institute &#8220;Cost of a Data Breach&#8221; Study on January 29, 2010.</p>
<p>In the report, they published the results of their fifth annual study on the costs of data breaches for U.S.-based companies. They surveyed 45 companies represnting 15 various industry sectors&#8211;significant contributors were financial, retail, services and healthcare companies.</p>
<h3>Numbers-wise, the companies they interviewed lost between 5,000 and 101,000 records, at a cost range between $750,000 and $31 million.</h3>
<p>What was really interesting was that the <span style="color: #ff0000;">average per-record cost </span>of the loss was determined <span style="color: #ff0000;">to be $204.00</span>&#8211;and how many records does your law enforcement/public safety agency hold?</p>
<p>Some factors they considered in computing the cost of the breach included:</p>
<ul>
<li>Direct costs - communications costs, investigations and forensics costs and legal costs</li>
<li>Indirect costs - lost business, public relations, and new customer acquisition costs</li>
</ul>
<p>The report also lists a number of causes for the data breaches, such as:</p>
<ul>
<li>82% of all breaches involved organizations that had experienced more than one data breach</li>
<li>42% of all breaches studied involved errors made by a third party</li>
<li>36% of all breaches studied involved lost, misplaced or stolen laptops or other mobile computing devices</li>
<li>24% of all breaches studied involved some sort of criminal or other malicious attack or act (as opposed to mere negligence).</li>
</ul>
<p>You can download the full report here: <a href="http://www.encryptionreports.com/download/Ponemon_COB_2009_US.pdf">http://www.encryptionreports.com/download/Ponemon_COB_2009_US.pdf</a></p>
<p>Thoughts and comments welcomed&#8230;r/Chuck</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2010/01/30/having-trouble-convincing-the-boss-to-spend-on-security-and-privacy-protection-read-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data.gov CONOP &#8211; Five ideas posted to &#8220;Evolving Data.gov with You&#8221;</title>
		<link>http://www.nowheretohide.org/2010/01/02/data-gov-conop-five-ideas-posted-to-evolving-data-gov-with-you/</link>
		<comments>http://www.nowheretohide.org/2010/01/02/data-gov-conop-five-ideas-posted-to-evolving-data-gov-with-you/#comments</comments>
		<pubDate>Sat, 02 Jan 2010 18:57:36 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Open Government]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[transparency]]></category>
		<category><![CDATA[accountability]]></category>
		<category><![CDATA[data.gov]]></category>
		<category><![CDATA[GPRA]]></category>
		<category><![CDATA[OMB PART]]></category>

		<guid isPermaLink="false">http://www.nowheretohide.org/?p=566</guid>
		<description><![CDATA[Following up on my comments and thoughts about the Open Government Directive and Data.gov effort, i just posted five ideas on the &#8220;Evolving Data.gov with You&#8220; website and thought i would cross-post them on my blog as well&#8230;enjoy! r/Chuck 1. Funding &#8211; Data.gov cannot be another unfunded federal mandate Federal agencies are already trying their [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nowheretohide.org/wp-content/uploads/2010/01/data-gov-conop-cover.png"><img class="alignright size-medium wp-image-568" style="border: black 2px solid;" title="data-gov conop cover" src="http://www.nowheretohide.org/wp-content/uploads/2010/01/data-gov-conop-cover-256x300.png" alt="" width="202" height="267" /></a>Following up on my comments and thoughts about the <a href="http://www.whitehouse.gov/open/documents/open-government-directive" target="_blank">Open Government Directive </a>and <a href="http://www.data.gov/" target="_blank">Data.gov </a>effort, i just posted five ideas on the &#8220;<em><a href="http://datagov.ideascale.com/a/panel.do?id=6440" target="_blank">Evolving Data.gov with You</a>&#8220;</em> website and thought i would cross-post them on my blog as well&#8230;enjoy! r/Chuck</p>
<h2>1. Funding &#8211; Data.gov cannot be another unfunded federal mandate</h2>
<p>Federal agencies are already trying their best to respond to a stream of unfunded mandates. Requiring federal agencies to a) expose their raw data as a service and b) collect, analyze, and respond to public comments requires resources. The requirement to make data accessible to (through) Data.gov should be formally established as a component of one of the Federal strategic planning and performance management frameworks (<a href="http://www.whitehouse.gov/omb/mgmt-gpra_gplaw2m/" target="_blank">GPRA</a>, <a href="http://www.whitehouse.gov/omb/rewrite/budget/fy2005/part.html" target="_blank">OMB PART</a>, <a href="http://www.whitehouse.gov/omb/rewrite/budintegration/pma_index.html" target="_blank">PMA</a>) and each agency should be funded (resourced) to help ensure agency commitment towards the Data.gov effort. Without direct linkage to a planning framework and allocation of dedicated resources, success of Data.gov will vary considerably across the federal government.</p>
<h2>2. Strategy &#8211; Revise CONOP to address the value to American citizens</h2>
<p>As currently written, the CONOP only addresses internal activities (means) and doesn&#8217;t identify the outcomes (ends) that would result from successful implementation of Data.gov. In paragraph 1 the CONOP states &#8220;<em>Data.gov is a flagship Administration initiative intended to allow the public to easily find, access, understand, and use data that are generated by the Federal government</em>.&#8221;, yet there is no discussion about &#8220;what data&#8221; the &#8220;public&#8221; wants or needs to know about.</p>
<p>The examples given in the document are anecdotal at best and (in my opinion) do not reflect what the average citizen will want to see&#8211;all apologies to Aneesh Chopra and Vivek Kundra, but I do not believe (as they spoke in the December 8th webcast) that citizens really care much about things like average airline delay times, visa application wait times, or who visited the Whitehouse yesterday.</p>
<p>In paragraph 1.3 the CONOP states &#8220;<em>An important value proposition of Data.gov is that it allows members of the public to leverage Federal data for robust discovery of information, knowledge and innovation</em>,&#8221; yet these terms are not defined&#8211;what are they to mean to the average citizen (public)? I would suggest the Data.gov effort begin with a dialogue of the &#8216;public&#8217; they envision using the data feeds on Data.gov; a few questions I would recommend they ask include:</p>
<ol>
<li>What issues about federal agency performance is important to them?</li>
<li>What specific questions do they have about those issues?</li>
<li>In what format(s) would they like to see the data?</li>
</ol>
<p>I would also suggest stratifying the &#8220;public&#8221; into the different categories of potential users, for example:</p>
<ol>
<li>General taxpayer public, non-government employee</li>
<li>Government employee seeking data to do their job</li>
<li>Government agency with oversight responsibility</li>
<li>Commercial/non-profit organization providing voluntary oversight</li>
<li>Press, news media, blogs, and mash-ups using data to generate &#8216;buzz&#8217;</li>
</ol>
<h2>3. Key Partnerships &#8211; Engage Congress to participate in Data.gov</h2>
<p>To some, Data.gov can be viewed as an end-run around the many congressional committees who have official responsibility for oversight of federal agency performance. Aside from general concepts of government transparency, Data.gov could (should) be a very valuable resource to our legislators.</p>
<p>Towards that end, I recommend that Data.gov open a dialogue with Congress to help ensure that Data.gov addresses the data needs of these oversight committees so that Senators and Congressmen alike can make better informed decisions that ultimately affect agency responsibilities, staffing, performance expectations, and funding.</p>
<h2>4. Data Quality &#8211; Need process for assuring &#8216;good data&#8217; on Data.gov</h2>
<p>On Page 9 of the CONOP, the example of Forbes&#8217; use of Federal data to develop the list of &#8220;America&#8217;s Safest Cities&#8221; brings to light a significant risk associated with providing &#8216;raw data&#8217; for public consumption. As you are aware, much of the crime data used for that survey is drawn from the <a href="http://www.fbi.gov/ucr/ucr.htm#cius" target="_blank">Uniformed Crime Reporting </a>effort of the FBI.</p>
<p>As self-reported on the &#8220;Crime in the United States&#8221; website, &#8220;<em>Figures used in this Report are submitted voluntarily by law enforcement agencies throughout the country. Individuals using these tabulations are cautioned against drawing conclusions by making direct comparisons between cities. Comparisons lead to simplistic and/or incomplete analyses that often create misleading perceptions adversely affecting communities and their residents</em>.&#8221;</p>
<p>Because Data.gov seeks to make raw data available to a broad set of potential users; How will Data.gov address the issue of data quality within the feeds provided through Data.gov? Currently, federal agency Annual Performance Reports required under the Government Performance and Results Act (GPRA) of 1993 require some assurance of data accuracy of the data reported; will there be a similar process for federal agency data made accessible through Data.gov? If not, what measures will be put in-place to ensure that conclusions drawn from the Data.gov data sources reflect the risks associated with &#8216;raw&#8217; data? And, how will we know that the data made available through Data.gov is accurate and up-to-date?</p>
<h2>5. Measuring success of Data.gov &#8211; a suggested (simple) framework</h2>
<p>The OMB Open Government Directive published on December 8, 2009 includes what are (in my opinion) some undefined terms and very unrealistic expectations and deadlines for federal agency compliance with the directive. It also did not include any method for assessing progress towards the spirit and intent of the stated objectives.</p>
<p>I would like to offer a simple framework that the Data.gov effort can use to work (collaboratively) with federal agencies to help achieve the objectives laid out in the directive. The framework includes the following five questions:</p>
<ol>
<li>Are we are clear about the performance questions that we want to answer with data to be made available from each of the contributing federal agencies?</li>
<li>Have we identified the availability of the desired data and have we appropriately addressed security and privacy risks or concerns related to making that data available through Data.gov?</li>
<li>Do we understand the burden (level of effort) required to make each of the desired data streams available through Data.gov and is the funding available (either internally or externally) to make the effort a success?</li>
<li>Do we understand how the various data consumer groups (the &#8216;public&#8217;) will want to see or access the data and does the infrastructure exist to make the data available in the desired format?</li>
<li>Do we (Data.gov and the federal agency involved) have a documented and agreed to strategy that prepares us to digest and respond to public feedback, ideas for innovation, etc., received as a result of making data available through Data.gov?</li>
</ol>
<p>I would recommend this framework be included in the next version of the Data.gov CONOP so as to provide a way for everyone involved to a) measure progress towards the objectives of the OMB directive and b) provide a tool for facilitating the dialogue with federal agencies and Congress that will be required to make Data.gov a success.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2010/01/02/data-gov-conop-five-ideas-posted-to-evolving-data-gov-with-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data.gov needs some &#8220;Tough Love&#8221; if it&#8217;s to be successful</title>
		<link>http://www.nowheretohide.org/2009/12/29/data-gov-needs-some-tough-love-if-its-to-be-successful/</link>
		<comments>http://www.nowheretohide.org/2009/12/29/data-gov-needs-some-tough-love-if-its-to-be-successful/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 00:53:21 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Open Government]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[transparency]]></category>
		<category><![CDATA[data.gov]]></category>
		<category><![CDATA[tough love]]></category>

		<guid isPermaLink="false">http://www.nowheretohide.org/?p=560</guid>
		<description><![CDATA[I just finished commenting on Data.gov on the NIEM LinkedIn Group and thought I would share what I wrote here on my blog. I just finished watching a rerun episode of Tough Love on VH1 and I know some of you will think this is a bit odd, but the show led me to some thoughts about [...]]]></description>
			<content:encoded><![CDATA[<p>I just finished commenting on Data.gov on the <a href="http://www.linkedin.com/groupAnswers?viewQuestionAndAnswers=&amp;gid=1903175&amp;discussionID=10893074&amp;goback=%2Eana_1903175_1262046941854_3_1%2Eanh_1903175" target="_blank">NIEM LinkedIn Group </a>and thought I would share what I wrote here on my blog.</p>
<p>I just finished watching a rerun episode of <a href="http://www.vh1.com/shows/tough_love/season_2/series.jhtml" target="_blank">Tough Love on VH1 </a>and I know some of you will think this is a bit odd, but the show led me to some thoughts about how to give the <a href="http://www.Data.gov " target="_blank">Data.gov </a>project some focus and priority.</p>
<p>You&#8217;re probably wondering what Data.gov has to do with eight beautiful women looking for marriage and long-lasting love, but believe it or not, the show and Data.gov have a lot in common.</p>
<p>In this particular episode of the show, the &#8220;boot camp&#8221; director was focusing on communication skills. He made it very clear to the ladies that communication is very important in making a good first impression with a would be suitor. In the show he counseled the ladies that if they wanted to make a good impression, the ladies would need to:</p>
<ul>
<li>Listen carefully to what their date is telling them about what’s important to them;</li>
<li>Make the conversation about &#8220;them&#8221; on first contact and avoid bragging about yourself; and</li>
<li>Resist the urge to reveal too much information about their own respective private lives.</li>
</ul>
<p>While I will avoid speaking to the validity of this counsel as it applies to love, I would like to suggest that these three rules are also quite relevant in our efforts to have a more transparent, open and collaborative government.</p>
<p>Along these lines, I offer the following three suggestions for Data.gov’s first (transparent, open and collaborative) date with America:</p>
<ol>
<li><span style="text-decoration: underline;">Ask the public (and Congress) what they specifically want to see on Data.gov</span> and the forthcoming dashboard; all apologies to Aneesh Chopra and Vivek Kundra, but I do not believe (as they spoke in the December 8th webcast) that citizens really care much about things like average airline delay times, visa application wait times, or who visited the Whitehouse yesterday. I particualry suggest they work with Congressional Oversight Committees to make Data.gov a tool that Congress can (and will) use.</li>
<li><span style="text-decoration: underline;">Make Data.gov about demonstrating the good things that Federal agencies do that directly impact the general public</span>. It’s no surprise that most agencies do a poor job of explaining to citizens what they do. I suggest reviving the OMB <a href="http://www.whitehouse.gov/omb/expectmore/part.html" target="_blank">Performance Assessment Rating Tool </a>(PART) Program (which appears to have died on the vine with the new administration) and use the performance measures in the Program Results/Accountability section to better communicate the relevant value these agencies deliver to citizens.</li>
<li><span style="text-decoration: underline;">Focus Data.gov data sources and the desire for openness on the critical few measures and metrics that matter to the public</span>. Avoid the urge to just “get the data posted” – not many people will care about how many kilowatt hours of hydroelectric power the Bureau of Reclamation is counting, how many FOIA requests the Department of Justice received, or the Toxic Release Inventory for the Mariana Islands. Information sharing is most successful when it is directly relevant with the person (or agency)with whom you are sharing.</li>
</ol>
<p>I’ll let you know if the next episode is as enlightening as this was. <img src='http://www.nowheretohide.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>r/Chuck</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2009/12/29/data-gov-needs-some-tough-love-if-its-to-be-successful/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Open Government Directive: Another ambiguous, unfunded, and edental mandate?</title>
		<link>http://www.nowheretohide.org/2009/12/17/open-government-directive-another-ambiguous-unfunded-and-edental-mandate/</link>
		<comments>http://www.nowheretohide.org/2009/12/17/open-government-directive-another-ambiguous-unfunded-and-edental-mandate/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 00:10:50 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Information sharing]]></category>
		<category><![CDATA[Open Government]]></category>
		<category><![CDATA[data sharing]]></category>

		<guid isPermaLink="false">http://www.nowheretohide.org/?p=500</guid>
		<description><![CDATA[Before you send me hate mail let me state that I am all for Federal agencies sharing data in the sprit of open government, but we have to do it smart way, making sure that: We fully understand why we want it and are clear about what we are really asking for; We understand the burden involved [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-517" style="border: 0px;" title="whitehouse logo" src="http://www.nowheretohide.org/wp-content/uploads/2009/12/whitehouse-logo-300x204.gif" alt="whitehouse logo" width="231" height="136" />Before you send me hate mail let me state that <span style="text-decoration: underline;">I am all for Federal agencies sharing data in the sprit of open government,</span> but we have to do it smart way, making sure that:</p>
<ol>
<li>We fully understand why we want it and are clear about what we are really asking for;</li>
<li>We understand the burden involved in achieving open government and that we fund the agencies to do it right;</li>
<li>We are clear about the performance questions that we want the [transparent] data to answer;</li>
<li>We have an understanding for how the public will want to see/access the information; and</li>
<li>We are fully prepared to digest and respond to received public feedback .</li>
</ol>
<p>After reading the 3,185 words of the Office of Management and Budget (OMB) <a href="http://www.whitehouse.gov/open/documents/open-government-directive" target="_blank">Open Government Directive </a>(with attachment), I am very sorry to report that IMO <span style="text-decoration: underline;">none of the five critiera (conditions) listed above have been met</span> by the language contained in the document. From what I read:</p>
<ul>
<li>It would appear that <span style="text-decoration: underline;">no one in the approval chain asked any hard questions about the language</span>&#8211;much of the language used is very vague and leaves a lot of room for interpretation (or misinterpretation);</li>
<li>There is no mention of <span style="text-decoration: underline;">how agencies will be funded</span> to build the capacity to meet the additional workload that the requirements of the memorandum are certain to cause.</li>
<li>The focus of the document to &#8220;get agency data on the web&#8221; and &#8220;solicit (direct) public feedback&#8221; appears to be totally <span style="text-decoration: underline;">out of context of any other strategic management, performance assessment, or planning framework</span>.  This appears to ba an end-run around other oversight committees and organizations, like Congress. Will Federal agencies be able to deal with direct feedback from hundreds or thousands of citizens? I am reminded of the old adage &#8220;be careful what you ask for&#8221;&#8230;;</li>
<li>The document tells agencies to &#8220;publish information online in an open format that can be retrieved, downloaded, indexed, and searched by commonly used web search applications;&#8221; however, this can be satisfied in many ways&#8211;.txt, .csv, .doc, .pdf, .html,.xml, etc.&#8211;some formats will make it very <span style="text-decoration: underline;">cumbersome for the &#8220;public&#8221; to view, analyze and understand the data</span>.</li>
<li>Finally, the memorandum sets what I believe to be some very <span style="text-decoration: underline;">unrealistic expectations from both a performance and timeline perspective</span>. For example, how can agencies be expected to review and respond to public input from the web when these same agencies are already overwhelmed with their current day-to-day tasks?</li>
</ul>
<p>Here are a couple examples to ponder:</p>
<p><strong><em>On Page 2 &#8211; &#8220;To increase accountability, promote informed participation by the public, and create economic opportunity, each agency shall take prompt steps to expand access to information by making it available online in open formats&#8221; </em></strong></p>
<ul>
<li>Nowhere in the memorandum are the terms &#8220;accountability&#8221; or &#8220;informed participation&#8221; defined</li>
<li>What does &#8220;create economic opportunity&#8221; really mean?</li>
<li>It would appear that this mandate circumvents established management processes for holding Federal agencies accountable for efficient and effective performance? (OMB,GAO, Congress)</li>
</ul>
<p><em><strong>On Page 3 &#8211; &#8220;Each agency shall respond to public input received on its Open Government Webpage on a regular basis&#8230;Each agency with a significant pending backlog of outstanding Freedom of Information requests shall take steps to reduce any such backlog by ten percent each year.&#8221;</strong></em></p>
<ul>
<li>What do the mean by &#8220;respond to public feedback on a regular basis?&#8221;</li>
<li>All feedback? Some feedback?</li>
<li>What does &#8220;regular basis&#8221; mean? Within 24 hours? Weekly? Annually?</li>
</ul>
<p>If we really want Federal agencies to be more &#8220;open&#8221; with their data and information, we must be willing to commit the effort required to:</p>
<li>Be clear about what we really want them to do;</li>
<li>Give them the funding to do it right;</li>
<li>Drive data openness with specific questions we want answered;</li>
<li>Present the data in a way that the public can easily understand it; and</li>
<li>Be ready and willing to act on the feedback we&#8217;re sure to receive.</li>
<p> </p>
<h3>What are your thoughts and comments on this issue?</h3>
<p>Thanks&#8230;r/Chuck</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2009/12/17/open-government-directive-another-ambiguous-unfunded-and-edental-mandate/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Open letter to Mike Resnick, Sr. Director, Information Sharing Policy, EO of the President</title>
		<link>http://www.nowheretohide.org/2009/08/03/open-letter-to-mike-resnick-sr-director-information-sharing-policy-eo-of-the-president/</link>
		<comments>http://www.nowheretohide.org/2009/08/03/open-letter-to-mike-resnick-sr-director-information-sharing-policy-eo-of-the-president/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 00:51:06 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Evaluation]]></category>
		<category><![CDATA[Information sharing]]></category>
		<category><![CDATA[LEIS]]></category>
		<category><![CDATA[NIEM]]></category>
		<category><![CDATA[Performance Measures]]></category>
		<category><![CDATA[data sharing]]></category>

		<guid isPermaLink="false">http://www.nowheretohide.org/?p=289</guid>
		<description><![CDATA[I just finished reading of your appointment on the FederalNews Radio website. As you begin your review of the state of information sharing and the ISE, I would like to offer up some thoughts as someone who has been an information sharing evangelist for nearly a decade. here are seven points to consider: Resist the urge [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-thumbnail wp-image-295" style="border: 0px;" title="ODNI seal" src="http://www.nowheretohide.org/wp-content/uploads/2009/08/ODNI-seal-150x150.jpg" alt="ODNI seal" width="125" height="125" />I just finished reading of your appointment on the <a href="http://www.federalnewsradio.com/docs/informationsharingmemo.pdf" target="_blank">FederalNews Radio </a>website. As you begin your review of the state of information sharing and the ISE, I would like to offer up some thoughts as someone who has been an information sharing evangelist for nearly a decade. here are seven points to consider:</p>
<ol>
<li><span style="text-decoration: underline;"><strong>Resist the urge to see information sharing as an outcome</strong></span>. Information sharing is a means to an end, not the end itself. Each federal agency, every state and regional fusion center, and all law enforcement intelligence units should have a clear set of information requirements, questions if you will, that information sharing and the intelligence process should work to answer&#8211;hold agencies accountable for having clear and valid requirements. This has been a common practice in the intelligence community for decades and should be a practice for all information sharing elements.</li>
<li><span style="text-decoration: underline;"><strong>Build clear accountability into the information sharing process</strong></span>. Every federal agency, fusion center and law enforcement agency should have one person, preferably an impassioned, well-respected leader, that can ensure that their agencies requirements are  well documented and communicated horizontally across federal boundaries and vertically to local, state, and municipal agencies, and (where applicable) private sector organizations.</li>
<li><span style="text-decoration: underline;"><strong>Establish clear linkage of information sharing to agency operational performance measures</strong></span>. Just as staffing, information technology, facilities, and utilities are seen as strategic resources in a performance-based budget, information sharing must be seen as a resource to be strategically used to help an agency achieve its mission. When measuring the success of information sharing, focus on the extent to which it helped achieve agency goals&#8211;just as counting cases in law enforcement is a misleading way to judge public safety success, counting RFIs, records shared, SARs submitted is not a good way to gauge information sharing success&#8211;successful information sharing can only be measured through the extent to which it helps agencies (at all levels) achieve their operational goals.</li>
<li><span style="text-decoration: underline;"><strong>Discourage agencies from using stovepiped portals for information sharing</strong></span>. All shareable data should be available as a &#8220;service&#8221; for consumer agencies to ingest into their systems and not through a dedicated portal that users will need a discrete login to access. You can read my previous &#8220;<a title="Portal-mania" href="http://www.nowheretohide.org/?p=270" target="_blank">Portal-mania</a>&#8221; blog post for more detail here, but all federal agencies should be required to make their data accessible through National information Exchange Model (NIEM) based web services. This will enable consumer agencies to integrate multiple data streams into their workflow and will reduce the number of websites and portals analysts are required to access to perform their work.</li>
<li><span style="text-decoration: underline;"><strong>Give the same amount of attention to <em>what</em> is shared and <em>how</em> it is shared</strong></span>. Over the last few years, a significant amount of effort has gone into <em>how</em> information is shared at the expense of understanding the depth and breadth of information actually being shared. Many regional and national information sharing efforts still only contain basic levels of information, or worse are just pointer systems that require additional human effort to gain access to the actual record. Encourage agencies to communicate to each other what specific information <em>is</em> being shared, and what is <em>not</em> being shared, and help everyone understand the consequences of their decisions.</li>
<li><span style="text-decoration: underline;"><strong>Encourage maximum use of NIEM and the Information Exchange Package Descriptions (IEPD) contained it its clearinghouse</strong></span>. NIEM has emerged as the dictionary of shareable data elements. When you string together sets of these data elements to satisfy a specific business need, an IEPD is born. The NIEM IEPD clearinghouse contains more than 150 IEPDs, many of which apply to national security, law enforcement and public safety missions. While many federal agencies have pledged their support of NIEM, more effort is needed to ensure that they first seek to use IEPDs already contained in the clearinghouse and do not develop one-off IEPDs designed to meet very narrow applications.</li>
<li><span style="text-decoration: underline;"><strong>Finally, foster a culture of transparency to help communicate an appreciation of personal civil rights and civil liberties</strong></span>.  All information sharing and intelligence operations should engage in proactive efforts to help alleviate any fears that individual privacy and liberties are violated by any of the actions taken by those agencies. In my <a href="http://www.nowheretohide.org/?p=70" target="_blank">September 3, 2009 blog posting </a>I list ten questions a fusion center director should ask of their own intelligence operations. I&#8217;d like to offer up these questions as a beginning framework for any information sharing or intelligence operation. They also serve as a good framework for evaluating the extent to which information sharing and intelligence operations are in fact seriously working to do the right thing.</li>
</ol>
<p>In closing, I hope you can see how these seven points help to frame how you might structure a results oriented evaluation of information sharing across our federal agencies and with our state and regional fusion center, and private sector partners. Taken together <span style="text-decoration: underline;">you will be able to report the extent to which agencies have</span>:</p>
<ul>
<li>Documented their information sharing requirements &#8211; what needs to be shared;</li>
<li>Someone who can be directly held accountable for effective and proper information sharing;</li>
<li>Linked their need for information to specific operational goals and strategies;</li>
<li>Implemented mechanisms that makes it easy for other agencies to access their information;</li>
<li>Ensured that they are sharing the right information (most meaningful) information;</li>
<li>Taken advantage of NIEM as a way to save money and expedite information sharing; and</li>
<li>Taken measures to proactively diffuse public (and media) perceptions of information misuse.</li>
</ul>
<p>I wish you well in your new role as Senior Director for Information Sharing Policy.</p>
<p>Regards,</p>
<p>Chuck Georgo<br />
<a href="mailto:chuck@nowheretohide.org">chuck@nowheretohide.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2009/08/03/open-letter-to-mike-resnick-sr-director-information-sharing-policy-eo-of-the-president/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Portal-mania: They&#8217;re reproducing like bunnies, but they ain&#8217;t as cute</title>
		<link>http://www.nowheretohide.org/2009/07/30/portal-mania-theyre-reproducing-like-bunnies-but-they-aint-as-cute/</link>
		<comments>http://www.nowheretohide.org/2009/07/30/portal-mania-theyre-reproducing-like-bunnies-but-they-aint-as-cute/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 01:16:23 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[CJIS]]></category>
		<category><![CDATA[Law enforcement information sharing]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[fusion center]]></category>
		<category><![CDATA[intelligence center]]></category>
		<category><![CDATA[public safety]]></category>
		<category><![CDATA[portals]]></category>

		<guid isPermaLink="false">http://www.nowheretohide.org/?p=270</guid>
		<description><![CDATA[Stop the portal-mania...make information and analytic capabilities available through web parts, widgets and gadgets.]]></description>
			<content:encoded><![CDATA[<p>I had a conversation with a fusion center director yesterday about portals that really drove home a feeling I had about the recent plethora (read: boatload) of portals that the average analyst person supporting public safety and homeland security has to login to in order to do their jobs. </p>
<p>I&#8217;m paraphrasing a bit, but he basically indicated that the state, local, and private sector organizations in his state told him that they &#8220;DO NOT want to have to log into multiple portals&#8221; to stay informed about criminal and terrorism threats to their state&#8217;s  infrastructure.&#8221; </p>
<p>When you take a closer look at the &#8220;Portal-mania&#8221; that exists, it seems that every agency and multiple programs within a single agency has to have their own portal for accessing the information and analytic tools that agency or program provides; here&#8217;s a quick list of ones I am familar with, (feel free to email me the names of others you know about):</p>
<ol>
<li>DHS HSIN State and Local Community of Interest (SLIC)</li>
<li>DHS Lessons Learned Information Sharing (LLIS)</li>
<li>DHS Automated Critical Asset Management System (ACAMS)</li>
<li>DOJ Regional Data Exchange (R-DEx)</li>
<li>DOJ National Data Exchange (N-DEx)</li>
<li>DOJ eGuardian</li>
<li>DOJ Law Enforcement Online (LEO)</li>
<li>DOJ InfraGard</li>
<li>DOJ National Sex Offender Public Website (NSOPW)</li>
<li>DOJ National Criminal Intelligence Resource Center (NCIRC)</li>
<li>DOJ Regional information Sharing System (RISS)</li>
<li>Private Sector CyberCop</li>
<li>[State] Criminal Justice Information System (CJIS)</li>
<li>&#8230;add to this Department of the Treasury, Department of Transportation, and other federal agency portals</li>
<li>&#8230;and about three-dozen other databases and private sector websites</li>
</ol>
<p>This is nutz! Dedicated portals are so 1990&#8242;s&#8230;we should be able to use the same technology I used to create this website and blog (WordPress and four different plug-in widgets) to make information and advanced analytic capabilities available to Fusion Centers and other public safety users.  I would like to challenge the agencies and programs listed above to make the information and capabilities they offer available  through widgets, web-parts, and gadgets that Fusion Centers and other intelligence/information sharing users can integrate into THEIR portal of choice. </p>
<p>Whether it&#8217;s SharePoint, Oracle, or IBM Websphere, state, local, or private sector organizations should be able to pick and integrate into THEIR selected portal environment from the portal list above the information and capabilities that they need to do their job&#8211;they should not have to access the multiple, stovepiped portals as they do today.</p>
<p>I&#8217;d like to know what you think about this&#8230;Thanks..r/Chuck Georgo</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2009/07/30/portal-mania-theyre-reproducing-like-bunnies-but-they-aint-as-cute/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft Fusion Core Solution: For pain relief, take two webparts and call me in the morning</title>
		<link>http://www.nowheretohide.org/2009/07/13/microsoft-fusion-core-solution-take-two-webparts-and-call-me-in-the-morning/</link>
		<comments>http://www.nowheretohide.org/2009/07/13/microsoft-fusion-core-solution-take-two-webparts-and-call-me-in-the-morning/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 20:12:52 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Information sharing]]></category>
		<category><![CDATA[Law enforcement information sharing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[fusion center]]></category>
		<category><![CDATA[intelligence center]]></category>
		<category><![CDATA[business process]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://nowheretohide.org/wordpress/?p=114</guid>
		<description><![CDATA[Microsoft releases Fusion Core Solution to help Fusion Centers mre effectively ahieve their mission.]]></description>
			<content:encoded><![CDATA[<p>I don&#8217;t usually plug any specific software, but I felt compelled to tell you about something I have been working with Microsoft on for about  the last eight months&#8211;it&#8217;s called the <a title="Fusion Framework" href="http://www.microsoft.com/industry/government/solutions/Fusion_Framework/default.aspx" target="_blank">Fusion Core Solution</a> (FCS). What&#8217;s different about this project is that FCS isn&#8217;t just another application, it is an effort by Microsoft to help fusion centers do more with the many applications they currently own or have plans to invest in. First a bit of background.</p>
<p>Whether you like the idea of a fusion center or not, they are here to stay. At last count, there were about 70 of them, and DHS recently spoke of helping to get even more going.  At their core, I believe a fusion center is responsible for doing three basic things: </p>
<ol>
<li>Accepting and vetting reports of unusual behavior (criminal or terrorism related);</li>
<li>Providing intelligence support to major case and tactical law enforcement operations; and</li>
<li>Proactively supporting federal, state, and local homeland security and community safety objectives. </li>
</ol>
<p>To do this well, the majority of fusion centers in operation today are required to rely on an assortment of manual processes, a patchwork of incompatible software applications, and dozens of disparate information sources. Walk into the typical fusion center today and you&#8217;ll probably find that an analyst answering the phone has to enter the request for their services into one application for management purposes, enter the same information into a second application for sharing purposes, then has to manually bring up and login to anywhere from 5-15 different data sources to search for information related to the service request, then has to open up at least one or more applications to write up  and package up the requested response, and then, more than likely, has to either manually fax it to whomever asked for the information or call them back on the telephone to give them the answer&#8211;a pretty painful and tedious way to work.</p>
<p>Today though, Microsoft announced release of a project that I have been helping them to develop for quite some time&#8211;the <a title="Fusion Framework" href="http://www.microsoft.com/industry/government/solutions/Fusion_Framework/default.aspx" target="_blank">Fusion Core Solution</a>.  Microsoft hopes, through use of Office, SharePoint and ESRI&#8217;s ArcGIS to help ease the pain described above.  The FCS uses SharePoint as a horizontal integration and workflow management platform to help an analyst go from taking in a fusion center service request, to searching for information, to analyzing that information, to producing the intelligence product without having to leave the SharePoint environment at all.</p>
<p>At a non-technical level, the FCS will enable fusion centers to do a couple of pretty cool things:</p>
<ol>
<li>Provides a common look and feel across multiple analytic tools and business processes.</li>
<li>Greatly reduces the number of user names and passwords analyst must remember.</li>
<li>Organizes requests for fusion center services, and tracks progress of fusion center work.</li>
<li>Helps to better document and comply with 28 CFR Part 23, CUI and PCII requirements.</li>
<li>Provides multiple analyst-to-analyst and fusion center-to-fusion center collaboration tools</li>
<li>Helps to keep track of fusion center and extended staff capabilities and availability.</li>
</ol>
<p>From a technical perspective, FCS fully supports NIEM conformant information exchanges and establishes a framework for supporting the service-oriented principles of the Justice Reference Architecture (JRA) as it applies to information and data sharing.</p>
<p>In a nutshell, &#8220;<em>Fusion Core Solution is for a Fusion Center what Microsoft Windows is to a personal computer</em>&#8220;&#8211;you can think of FCS as the &#8220;operating system&#8221; for a Fusion Center.</p>
<p>For more info, check out the <a title="Fusion Framework" href="http://www.microsoft.com/industry/government/solutions/Fusion_Framework/default.aspx" target="_blank">Fusion Core Solution</a> website, or email me.</p>
<p>r/Chuck</p>
<p>Added 8/4/2009: Click <a href="http://www.youtube.com/watch?v=Gb0hF7PrTdk" target="_blank">HERE </a>to see Joe Rozek, Microsoft’s Executive Director of Homeland Security, and Former Senior Director for Domestic Counterterrorism at The White House Office of Homeland Security talk about Fusion Core Solution</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2009/07/13/microsoft-fusion-core-solution-take-two-webparts-and-call-me-in-the-morning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NIEM and JIEM: Two Great Tastes In Justice Information Sharing</title>
		<link>http://www.nowheretohide.org/2009/06/28/niem-and-jiem-two-great-tastes-in-justice-information-sharing/</link>
		<comments>http://www.nowheretohide.org/2009/06/28/niem-and-jiem-two-great-tastes-in-justice-information-sharing/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 03:29:09 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Information sharing]]></category>
		<category><![CDATA[JIEM]]></category>
		<category><![CDATA[LEIS]]></category>
		<category><![CDATA[Law enforcement information sharing]]></category>
		<category><![CDATA[N-DEx]]></category>
		<category><![CDATA[NIEM]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[IEPD]]></category>

		<guid isPermaLink="false">http://nowheretohide.org/wordpress/?p=97</guid>
		<description><![CDATA[Remember the old Reese&#8217;s Peanut Butter Cups commercial? &#8220;You got chocolate on my peanut butter &#8220;&#8230;&#8221;No, you got peanut butter on my chocolate &#8220;&#8230;?  Well, this is one of these stories&#8230; It&#8217;s no secret, the National Information Exchange Model (NIEM) is a huge success.  Not only has it been embraced horizontally and vertically for law [...]]]></description>
			<content:encoded><![CDATA[<p>Remember the old <a title="Reese's Penaut Butter Cups Commercial" href="http://www.youtube.com/watch?v=_nUIlcNoUy4&amp;feature=related" target="_blank"><strong>Reese&#8217;s Peanut Butter Cups</strong> </a>commercial? &#8220;<em>You got chocolate on my peanut butter </em>&#8220;&#8230;&#8221;<em>No, you got peanut butter on my chocolate &#8220;&#8230;</em>?  Well, this is one of these stories&#8230;</p>
<p>It&#8217;s no secret, the <a title="NIEM" href="http://niem.gtri.gatech.edu/niemtools/home.iepd;jsessionid=32B85AF3C783D20966ABEBA8EEBD2D50" target="_blank">National Information Exchange Model </a>(NIEM) is a huge success.  Not only has it been embraced horizontally and vertically for law enforcement information sharing at all levels of government, but it is now spreading internationally.  A check of the it.ojp.gov website lists more than 150 justice-related <a title="IEPD Clearinghouse" href="http://www.it.ojp.gov/framesets/iepd-clearinghouse-noClose.htm" target="_blank">Information Exchange Package Documentation</a> (IEPD) based on NIEM&#8211;it&#8217;s been adopted by N-DEX, ISE-SAR, NCIC, IJIS PMIX, NCSC, OLLEISN, and many other CAD and RMS projects. </p>
<p>For at least the last four years, Search.org has been maintaining the <a title="JIEM Model" href="http://www.search.org/programs/info/jiem/model/" target="_blank">Justice Information Exchange Model</a> (JIEM) developed by Search.org.  JIEM documents more than 15,000 justice information exchanges across  9 justice processes, 75 justice events, that affect 27 different justice agencies. </p>
<p>So if <strong>JIEM</strong> establishes the required <strong>information exchanges</strong> required in the conduct of justice system business activities, and <strong>NIEM</strong> defines the syntactic and semantic model for the data elements within those justice information exchanges&#8230;then&#8230;</p>
<p><em><strong><span style="color: #000000;">Wouldn&#8217;t it make sense for JIEM exchanges to call-out specific NIEM IEPDs? </span></strong></em></p>
<p><em><span style="color: #003366;"><strong><span style="color: #000000;">And vice-versa, wouldn&#8217;t it make sense for NIEM IEPDs to identify the specific JIEM exchanges they correspond to?</span></strong></span></em></p>
<p>Here&#8217;s a diagram that illustrates this&#8230;</p>
<p style="text-align: center;"><img class="size-full wp-image-101 aligncenter" title="niem-jiem-model1" src="http://www.nowheretohide.org/wp-content/uploads/2009/06/niem-jiem-model1.jpg" alt="niem-jiem-model1" width="496" height="245" /></p>
<p>Let me know what you think..</p>
<p>r/Chuck</p>
<p><a href="mailto:chuck@nowheretohide.org">chuck@nowheretohide.org</a> - <a href="http://www.nowheretohide.org">www.nowheretohide.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2009/06/28/niem-and-jiem-two-great-tastes-in-justice-information-sharing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health Info Sharing Beating LE to the Punch</title>
		<link>http://www.nowheretohide.org/2009/06/16/health-info-sharing-beating-le-to-the-punch/</link>
		<comments>http://www.nowheretohide.org/2009/06/16/health-info-sharing-beating-le-to-the-punch/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 02:04:21 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Information sharing]]></category>
		<category><![CDATA[LEIS]]></category>
		<category><![CDATA[Law enforcement information sharing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[standards]]></category>

		<guid isPermaLink="false">http://nowheretohide.org/wordpress/?p=91</guid>
		<description><![CDATA[If you haven&#8217;t heard about the Department of Health and Human Services Federal Health Architecure and CONNECT project, I suggest you pop over to this website where documentation for version 2.0 of the software resides: http://www.connectopensource.org/display/NHINR2/Release+2.0+Home CONNECT is an open source software gateway that connects public and private health orgaizations to the National Health Information [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-93" title="connect" src="http://www.nowheretohide.org/wp-content/uploads/2009/06/connect.gif" alt="connect" width="156" height="55" /></p>
<p>If you haven&#8217;t heard about the <strong>Department of Health and Human Services</strong> Federal Health Architecure and CONNECT project, I suggest you pop over to this website where documentation for version 2.0 of the software resides:</p>
<p><span style="text-decoration: underline;"><span style="color: #810081;"><a href="http://www.connectopensource.org/display/NHINR2/Release+2.0+Home">http://www.connectopensource.org/display/NHINR2/Release+2.0+Home</a></span></span><a href="http://www.connectopensource.org/display/Gateway/CONNECT+Community+Portal"></a></p>
<p>CONNECT is an open source software gateway that connects public and private health orgaizations to the National Health Information Network.  Think of it like a giant peer-to-peer N-DEx, but with an open source &#8220;front-porch&#8221; that drops into each agency and extracts the data from back-end systems.</p>
<p>I&#8217;ll be doing more investigation into the CONNECT project to see if we can adapt it for law enforcement information sharing use&#8211;the closest thing to this on the LEIS side is the FINDER project in orlando, FL.</p>
<p>as always, comments and thoughts welcomed.</p>
<p>r/Chuck</p>
<p><a href="mailto:chuck@nowheretohide.org">chuck@nowheretohide.org</a> - <a href="http://www.nowhretohide.org">www.nowheretohide.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2009/06/16/health-info-sharing-beating-le-to-the-punch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of geeks bearing free online apps&#8230;is your privacy at risk?</title>
		<link>http://www.nowheretohide.org/2009/03/15/beware-of-geeks-bearing-free-online-appsis-your-privacy-at-risk/</link>
		<comments>http://www.nowheretohide.org/2009/03/15/beware-of-geeks-bearing-free-online-appsis-your-privacy-at-risk/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 03:03:34 +0000</pubDate>
		<dc:creator>chuckgeorgo</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[data sharing]]></category>
		<category><![CDATA[intelligence center]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security threats]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[windows live]]></category>
		<category><![CDATA[zoho]]></category>

		<guid isPermaLink="false">http://nowheretohide.org/wordpress/?p=78</guid>
		<description><![CDATA[If you&#8217;re like most folks, you stopped reading the &#8220;fine print&#8221; terms and conditions on free online appliactions like Google Apps, Windows Live, Zoho, and MySpace. I did too, until today. I caught an article  on NetworkWorld.com today entitled &#8220;Privacy groups rip Google&#8217;s targeted advertising plan&#8221; that described how privacy advocates are concerned about Google&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re like most folks, you stopped reading the &#8220;fine print&#8221; terms and conditions on free online appliactions like Google Apps, Windows Live, Zoho, and MySpace. I did too, until today. I caught an article  on <a title="Network World" href="http://www.networkworld.com/index.html">NetworkWorld.com </a>today entitled &#8220;<a title="Privacy groups rip Google's targeted advertising" href="http://www.networkworld.com/news/2009/031109-privacy-groups-rip-googles-targeted.html">Privacy groups rip Google&#8217;s targeted advertising plan</a>&#8221; that described how privacy advocates are concerned about Google&#8217;s foray into the world of behavioral targeting in its DoubleClick advertising business.  So, that got me curious&#8230;what can Google (and others) do with your personal data, files, etc?</p>
<p>I did a quick check of four online appliactions that I use&#8211;Zoho, Windows Live, MySpace and Google Apps&#8211;here&#8217;s what I found.</p>
<ol>
<li><strong><span style="text-decoration: underline;">ZoHo&#8217;s terms of use states:</span></strong>&#8220;<em><span style="color: #ff0000;">We store and maintain files, documents, to-do lists, emails and other data stored in your Account at our facilities in the United States <span style="text-decoration: underline;">or any other country</span></span>. Use of Zoho Services signifies your consent to such transfer of your data outside of your country.  In order to prevent loss of data due to errors or system failures, we also keep backup copies of data including the contents of your Account. Hence <span style="color: #ff0000;"><span style="text-decoration: underline;">your </span></span></em><span style="color: #ff0000;"><em><span style="text-decoration: underline;">files and data may remain on our servers even after deletion</span> or termination of your Account</em>.&#8221;</span><span style="color: #0000ff;"><br />
</span></li>
<li><span style="text-decoration: underline;"><strong>Windows Live had a different twist:<br />
</strong></span>&#8220;<em>Microsoft does not claim ownership of the materials you provide to Microsoft (including feedback and suggestions) or post, upload, input or submit to any Services or its associated services for review by the general public, or by the members of any public or private community, (each a &#8220;Submission&#8221; and collectively &#8220;Submissions&#8221;).  However, <span style="color: #ff0000;">by posting, uploading, inputting, providing or submitting (&#8220;Posting&#8221;) your Submission </span><span style="color: #ff0000;">you are granting Microsoft, its affiliated companies and necessary sublicensees </span>permission to use your Submission in connection with the operation of their Internet businesses (including, without limitation, all Microsoft Services), <span style="color: #ff0000;">including, without limitation, the license rights to: copy, distribute, transmit, publicly display, publicly perform, reproduce, edit, translate and reformat your Submission</span>; to publish your name in connection with your Submission; and the right to sublicense such rights to any supplier of the Services</em>.&#8221;</li>
<li><span style="text-decoration: underline;"><strong>MySpace pretty much mirrors Microsoft&#8217;s terms:<br />
</strong></span>&#8220;<em>After posting your Content to the MySpace Services, you continue to retain any such rights that you may have in your Content, subject to the limited license herein. <span style="color: #ff0000;">By displaying or publishing (&#8220;posting&#8221;) any Content on or through the MySpace Services, you hereby grant to MySpace a limited license to use, modify, delete from, add to, publicly perform, publicly display, reproduce, and distribute such Content </span>solely on or through the MySpace Services, including without limitation distributing part or all of the MySpace Website in any media formats and through any media channels, except Content marked &#8220;private&#8221; will not be distributed outside the MySpace Website</em>.&#8221;</li>
<li><strong><span style="text-decoration: underline;">Google had the best (or worst) of all worlds: </span></strong><span style="text-decoration: underline;">It&#8217;s Privacy Policy states</span> &#8220;<em><span style="color: #ff0000;">Google processes personal information on our servers in the United States of America and <span style="text-decoration: underline;">in other countries</span></span><span style="text-decoration: underline;">.</span> In some cases, we process personal information on a server outside your own country. We may process personal information to provide our own services. In some cases, we may process personal information on behalf of and according to the instructions of a third party, such as our advertising partners</em>.&#8221;<span style="text-decoration: underline;">It&#8217;s Google Apps terms of service states</span> &#8220;<span style="color: #ff0000;"><em>Information collected by Google may be stored and processed <span style="text-decoration: underline;">in the United States or any other country</span> in which Google or its agents maintain facilities</em></span>.&#8221;<span style="text-decoration: underline;">It&#8217;s general terms of service states</span> &#8220;<em>You retain copyright and any other rights you already hold in Content which you submit, post or display on or through, the Services. <span style="color: #ff0000;">By submitting, posting or displaying the content <span style="text-decoration: underline;">you give Google a perpetual, irrevocable, worldwide, royalty-free, and non-exclusive licence to reproduce, adapt, modify, translate, publish, publicly perform, publicly display and distribute any Content which you submit, post or display</span> on or through, the Services</span>. This licence is for the sole purpose of enabling Google to display, distribute and promote the Services and may be revoked for certain Services as defined in the Additional Terms of those Services.</em>.<em><span style="color: #ff0000;"><span style="text-decoration: underline;">You agree that this licence includes a right for Google to make such Content available to other companies, organizations or individuals with whom Google has relationships for</span> the provision of syndicated services, and to use such Content in connection with the provision of those services</span>.</em><em><span style="color: #ff0000;">You understand that Google, in performing the required technical steps to provide the Services </span>to our users, may (a) transmit or distribute your Content over various public networks and in various media; and (b) <span style="color: #ff0000;">make such changes to your Content as are necessary to conform and adapt that Content to the technical requirements of connecting networks, devices, services or media</span>. You agree that this licence shall permit Google to take these actions. You confirm and warrant to Google that you have all the rights, power and authority necessary to grant the above licence.&#8221;</em></li>
</ol>
<p><strong>So, what&#8217;s the moral to this story?  Three things&#8230;</strong></p>
<ol>
<li>Take the time to read the fine print; make yourself and others aware of the privacy and terms of service conditions for these and other (free or fee-based) online appliacations;</li>
<li>If your federal, state or law enforcement agency, fusion center, or other government agency are using any of these services, make sure you have written policies about what can and cannot be posted, stored, or shared through these services; and</li>
<li>Assume anything you do post or share will a) make its way outside of the United States and b) reused in some way for marketing or advertising purposes.</li>
</ol>
<p>Play it safe; don&#8217;t assume your information posted to these services will remain private. Remember, once out, that privacy genie will be nearly impossible to get back in the bottle.</p>
<p>As always, your thoughts and comments are welcomed…r/Chuck</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nowheretohide.org/2009/03/15/beware-of-geeks-bearing-free-online-appsis-your-privacy-at-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
