Employee Fights against Unlawful activities of Employer

An interesting legal suit is being fought in US which has implications for any honest employee who is in a dilemma when he/she observes that the organization in which he/she works is engaged in unlawful activities or trying to cover up its mistakes for the fear of legal repraisals. (Refer details here)

This is the case of Barbara Peterson, an ex-employee of Woodwinds Hospital in Woodbury.  She was working as a “Patient Advocate” at Woodwinds and alleges that she was ordered to destroy notes and e-mails about incidents that could damage the hospital’s reputation. She instead carried the records home and preserved them as “Evidence” for the negligence of the Hospital in certain issues. She later had resigned from the job as well.

As a “Patient Advocate”, Barbara was responsible  for liasoning between the medical staff and patients and to investigate grievances. According to her version she was asked by her supervisor to clean up the grievance files before an impending accreditation audit and removing of records which showed the hospital in bad light. Though distraught, she removed about 233 pages of information from the hospital records but preserved them under her custody at home. After leaving the hospital she went through a bout of depression and later filed a case against the hospital for infliction of emotional distress and violation of her employee rights.The hospital however denies having instructed Barbara to clean up the records which if proven would be a fraud.

The case is of relevance to many ethical employees who face a dilemma when they observe illegal activities in their employer’s business and feel an obligation to the society to divulge the same. At the same time, “Employee Ethics” , “Privacy Regulations” as well as fear of losing the job etc make it difficult for them to turn into whistle blowers. In the process they may undergo stress and consequential problems.

In most such cases one can envisage a legal fight later between the employee and the employer in which all the evidence related to the incident will be only with the employer and the employee will be left to defend himself/herself against a powerful adversary without proper evidential background.

This case represents one such situation where the employee either in anticipation of such developments or more appropriately in this case faced with the guilt of doing a wrong thing, keeps the information that is considered necessary for his/her self-preservation and presents it as “Evidence” in a court of law. While the act of taking away the property of the employer without authority may be incorrect and punishable under law in normal circumstances,  the “Intention” of such act and “How it is used” on a later day determines whether the act was done for “Self Defense”  or for “Inflicting malicious damage on the employer” or for making a “Wrongful gain”. If it is proved that there was in deed a prima facie  case to believe that an irregularity was indeed being committed by the employer, then his/her conduct becomes more of a “Potential Whistle Blower”.

If any irregularity is proved, then there is a case for even rewarding the employee for his/her sense of commitment to the society which cannot be subordinated to the commercial interests involved in an employment. Any person who is not compliant with law can claim protection under excuses of “Employee Ethics”.

The above case also has relevance to “Company Secretaries” and “Independent Directors” who often come to possess confidential company information that may indicate illegal activities by the employer. In all such cases such Company Secretary or an Independent Director would have to decide whether his duty to the investor should rank higher than his loyalty to the employer.

The debate in this case may also contribute to discussions  on the Wikileaks issue.

Perhaps the Corporate Circles need to debate on this issue.

Naavi

Posted in Cyber Law, Information Assurance, Privacy, Uncategorized | Leave a comment

Security Awareness For every Computer buyer

Government of India is suggesting that a security awareness brochure should be mandatorily inserted in every Computer/Mobile product package delivered to a customer.

Report

Though some have raised “logistic issues”, Naavi.org considers that the proposal is a move in the right direction. It is also possible that the brochure can be sent by manufacturers upon registration of the warranty and also in soft form  as part of the software package  installed .

There could be many other ways to deliver the information package and the objections raised by manufacturers only seem to indicate their unwillingness to undertake the responsibility.

Naavi

Posted in Cyber Law | Leave a comment

Is DDOS a legitimate form of Protest?

The Anonymous group which is known for several DDOS attacks around the world has petitioned  Mr Obama that DDOS should be recognized as a legitimate form of protest.

The group has claimed that DDOS is not a form of “hacking” and is nothing different from “Occupy”  protest. See report here

Though the request is unlikely to be considered by the US Government, it nevertheless gives some food for thought on how do we facilitate genuine forms of protests in Cyber Space.

Naavi has already suggested one form of “Cyber Protest” which is a Cyber Law Compliant form of protest.

Naavi had also earlier suggested in respect of objectionable contents a form of publishing an opposing point of view like a rejoinder. A similar process can also be used for the kind of DDOS protests that Anonymous is now suggesting.

In this form of protest the DDOS attack will only pop out a message which will briefly obscure the content much like the “interstitial advertisements”. Perhaps this system will satisfy both the Anonymous  as well as the regulators.

If Obama administration considers such a request then it will usher in a new era of democratization of the Internet and protection of Human Rights of the Netizens.

Naavi

Posted in Cyber Crime, Cyber Law, Privacy | Leave a comment

Delhi Court issues summons to US Companies

Delhi Metropolitan Magistrate Court has issued summons to 11 US based websites including Facebook and Google for promoting enmity and undermining national integrity. The MHA has been asked to serve the notices.

Other websites who will be summoned include Orkut, You Tube, Yahoo, Blogspot and Microsoft. Report

Naavi

Posted in Cyber Crime, Cyber Law, Uncategorized | Leave a comment

In US, SSN is being removed from Medicare records…

A bill is being passed in US to de-link Social Security Number from medicare ID cards. This is being pushed to avoid Medicare identity theft. Report

The decision follows the observation that medicare security breaches are resulting in loss of social security identity of citizens.

This development appears interesting in the context of India trying to push inclusion of Aadhar numbers in a number of transactions such as Gas connections, Bank accounts, etc. The risk of a gas dealer losing his records which results in Aadhar number being revealed is a risk that looms large on the Citizens of India. Once the aadhar number and details with the gas dealer is known the combined data could be used for various malicious purposes such as stealing the Bank account or Mobile number.

It is necessary for the Government to keep these risks in mind before linking Aadhar numbers with all services as a matter of routine.

During Aadhar registrations in Karnataka I have observed that by default every registrant is being asked to link his Bank account to the Aadhar registration. This is required only for BPL families where benefits are to be routed to the account. Otherwise public should be circumspect in linking their Bank accounts to the Aadhar registration.

Naavi

Posted in Uncategorized | Leave a comment

Dutch Responsible Disclosure Guideline..organizational responsibilites

In continuation of the earlier posts, following are the obligations that the Dutch National Cyber Security Council has imposed on the owners of systems.

According to the guidelines it is necessary for the organization to have a policy on” Responsible disclosure” and publish policies for Responsible disclosure publicly known.

It will also be necessary for the organization to make it accessible for a detector to make a notification. This can be done by a standardized manner, for example, an on-line form, to be used for making of reports. Here, the organization can weigh up to anonymous messages to receive.

  • The organization reserve capacity to adequately notifications can react.
  • The organization takes the report of a vulnerability in receipt and ensures that as soon as possible reaches the department that the message can best assess and may examine.
  • The organization will send an acknowledgment of receipt of the notification, preferably digitally signed to the priority to emphasize the detector. After join the organization and the detector in contact about the further process.
  • The organization shall determine, in consultation with the reporter the deadline by which any publication will take place. A reasonable standard term that can be used for software vulnerabilities is 60 days. The fix vulnerabilities in hardware is difficult to achieve, this may be a reasonable standard period of 6 months may be used.
  • In consultation may be desirable to extend this deadline or shorten if much or little systems rely on the system on which the vulnerability is reported.
  • If a vulnerability is not or difficult to solve, or if there are high costs are involved, may agree to the detector and organizational vulnerability undisclosed.
  • The organization keeps the detector and other stakeholders informed the progress of the process.
  • The organization can convey that the organization detector credits will give, as the reporter wishes, for doing the reporting.
  • The organization may choose to have a detector a reward / appreciation to give for reporting vulnerabilities in ICT products or services, if the detector is on the rules contained in the policy account. The height of the pay may be dependent on the quality of the message.
  • The organization may, in consultation with the notifier agree to the broader IT community about the vulnerability when it is probable that the vulnerability also exists in other places.
  • The organization shall act in the adopted policy about not taking legal action if continued with the policy is adhered.
  • These guidelines may now be construed as a “Best Practice” for organizations for whom this will be applicable and Information Assurance Auditors/consultants may take note of them for implementation of Information Security in an organization.

    More details are available in this translated copy of the brochure:

    Naavi

    [P.S: Kindly excuse some spelling errors on account of unedited translation of the original Dutch document]

    Posted in Cyber Crime, Information Assurance, Uncategorized | Leave a comment