home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Powered by InformationWeek Business Technology Network
InformationWeek 500 Conference -- September 14-16, 2008 Registed Today!

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Network & Systems Management
F E A T U R E  
Monitoring and Privacy: Is Your Head Still In the Sand?

  June 25, 2001
  By Sean Doherty



Congress enacted the Electronic Communications Privacy Act (ECPA) in 1986 to bring electronic communications within the purview of the FWS (federal wiretapping statute). The FWS now prohibits any person from intentionally intercepting wire, oral or electronic communication or disclosing the contents to any other person. Electronic communication is defined as "any transfer of signs, signals, writing, images, sounds, data or intelligence of any nature transmitted in whole or in part by a wire, radio, electromagnetic, photo electronic or photo optical system."

If, however, an enterprise provides wire or electronic communication services in its ordinary course of business, it is exempt from the FWS.

The business exception to the FWS generally lets employers monitor computers and networks the company owns. Enterprises providing a wire or electronic communication service to the public, however, can monitor and observe network traffic only for "mechanical or service quality-control checks." Once an electronic communication reaches a storage facility, Title II of ECPA, the Stored Wire and Electronic Communications and Transactional Records Act, prohibits intentional, unauthorized access to stored communications.

ECPA defines electronic storage as "any temporary, intermediate storage of a wire or electronic communication incidental to the electronic transmission" and any storage for backup purposes. Entities that provide wire or electronic communications service are exempt, except for public providers, like America Online. This has created a broad exception for employers that provide electronic communication in-house. This may also include anyone authorized by a provider, such as a service provider, to monitor stored messages. Critics, however, caution employers from relying on the exception, since Congress's intent in passing ECPA was to strengthen individual privacy rights.

If Congress intends to strengthen individual privacy rights in the workplace, that intent has not manifested itself into law. In 2000, legislation proposed in both houses of Congress failed to require employers to inform employees if they monitor computer, Internet or telephone use. Although the proposed Notice of Electronic Monitoring Act died in committee, it has resurfaced in the Senate as the Spyware Control and Privacy Protection Act (see "Right to Privacy Legislation" chart, below). This bill sets out to mandate disclosure of information collection through computer software and other means.

Although many state wiretap laws follow the federal law, employers should not engage in electronic monitoring without checking applicable state and common laws on electronic monitoring in the workplace. Several compilations of laws on monitoring are available. LRN, a legal research and analysis firm, offers papers on "Monitoring and Recording of Employee Telephone Calls, Voicemail" and "E-mail: A Federal Law and Fifty State Survey." In addition to the applicable laws, employees expect certain privacy rights, and employers should respect them.

Technology today enables employees to work long hours both in and out of the office. Often, those hours require employees to devote a fair amount of time to personal or family life while on the job. Employees may have to take calls from schools or hospitals during the day to field family emergencies; they may have to coordinate child care with a spouse; and they may need to contact stores, banks and so on. Most workers will make the occasional personal phone call from work or use the office copy machine for a random photocopy. And many people will use an e-mail system for personal as well as work-related mail.



Right to Privacy Legislation

Click here to enlarge

Yet there may be abuse -- in content, purpose and the sheer amount of time spent on such mail. Some people may also surf the Internet to attend auctions and sales or download games and other programs and run them on office computers. Others may harass workers with e-mail, view pornography or even mail corporate secrets to competitors. If you don't monitor the workplace, you may have little concern for the welfare of your employees until one files a harassment suit. And you may have little worry that employees are divulging corporate information until your competitor files a patent with your intellectual property.

If these concerns alone don't keep you up at night, keep in mind how much network bandwidth and Internet access dollars you are losing to such activities. In the past, when companies recognized that equipment was used or abused for purposes other than business, they placed controls on the devices. For instance, many of us now use a code to access long-distance services and photocopy equipment. For the network, the costs are even more daunting. Businesses upgrade wiring, switches, routers and leased lines. For example, 256-Kbps leased lines are upgraded to T1, T3, OC-3 and even OC-12 to handle increased loads. If these loads do not equate to business needs, there's unnecessary overhead that needs to be recognized and reduced. If employees know the network is monitored, the reduction in nonbusiness-related "surfing" can free up bandwidth, increase performance and reduce costs.

Monitoring the corporate network makes good business sense, but doing it responsibly -- by employing up-to-date tools and adhering to an established company policy -- makes better sense. Otherwise, you may find yourself the subject of a lawsuit. For example, a Massachusetts court found that reviewing employees' mail using a supervisor's password violated state law against "unreasonable, substantial or serious" interference with privacy (Restuccia vs. Burk Technology). Employees were permitted to use the e-mail system to send personal communications, and the employer never informed them that messages would be monitored using a supervisor's password.

The federal government has started to address the hard questions of how data is collected, accessed, and transferred or shared (see "Keeping Data Private"). But most U.S. legislative efforts have fallen short of the comprehensive privacy schemes found in Canada and the European Union in favor of allowing enterprises to police their own privacy practices. In response, enterprises have beefed up their privacy policies and appointed privacy officials to ensure that customers are given notice of what information the business collects, how it uses the information and how it discloses that information. But is this enough?

Although legislation is in motion to ensure the public's privacy rights in the information age, little has been done to update the FWS or provide employers with a clear guide to balancing electronic monitoring and privacy. Furthermore, advances in technology continue unabated. Digital convergence and the wedding of voice and data on networks enable both employers and the federal government to monitor network activity, going beyond the scope of the FWS. Today's networks carry voice and data packets that include origin, destination and content on the same channel, and all may be monitored and reported on one device. This has implications for the watcher and the watched.

For example, as enterprises adopt VoIP (voice over IP) on the corporate network, voice traffic will be as easy to monitor as Internet traffic, such as e-mail, FTP, HTTP and telnet. Voicemail will be stored in the same medium as e-mail and susceptible to the same tools now used to scan e-mail messages; the potential to infringe on employees' privacy will be greater than ever. Unfettered and unannounced monitoring that scans both voice and data traffic on the network may cross the lines of respectability and infringe on employees' rights to privacy.

Enterprises need tools that can reduce the risks and costs of doing Internet business. These tools should inform companies when confidential information, such trade secrets and intellectual property, are communicated on the Internet. In addition, these tools should provide the enterprise with information on how its network resources are being used and easily identify abuse. At the same time, the tools should ensure a safe, hospitable environment for employees to engage in productive, creative work and afford them respectability and comfort in the workplace.

The monitoring tools we tested are easily installed on IP networks and provide configuration utilities that will identify how Internet resources like e-mail, FTP, HTTP and telnet are used and the amount of network bandwidth taken up by non-work-related activities. And these tools can be restricted to identifying abuse such as an unauthorized transmission of confidential data or the downloading of offensive and otherwise inappropriate material to meet the expectations of privacy by employees. In addition, some of the tools provide the enforcement mechanisms to curb abuse and maximize network resources for business activities.


   Page: 1 | 2 | 3 | 4 | Next Page





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights