Feeds

The legal risks of uncontrolled IM use

Nest of vipers

  • alert
  • submit to reddit

5 things you didn’t know about cloud backup

White paper Everyone loves instant messaging, the chat-cum-presence tool of choice of the masses. And that love extends to the workplace...IM should overtake email as the preferred method of business communication by the second half of 2010, an IDC survey found last year.

But IM can create enormous headaches for their employers. We have selected this whitepaper from the Reg Library to tell you just how big that headache is.

The legal risks of uncontrolled IM use

This is in spite of the fact that many organizations - President Obama's White House among them - ban the staff use of IM for security and compliance reasons.

Blanket bans such as this may engender a false sense of security, according to this white paper prepared by a London law firm for Messagelabs (reg req'd).

“A younger workforce is adept at using IM and such usage is likely to continue to grow. IM tools are sophisticated and may enter networks, notwithstanding the fact that firewalls are in place, or obvious ports locked down,” the authors write.

A devious lot, the young.

Companies that do embrace IM are often much slower to assess its on their corporate risk profile, and therefore have no agreed policy on its use.

But monitoring staff use of IM is essential, for legal reasons:

A key consideration is that an employer can be liable for the acts of its employees, even if the acts have been expressly forbidden. From this we can conclude that an employer will not necessarily escape liability arising from IM use, even if a) the use of IM is forbidden, or b) the IM software used was not provided by the employer. This is why employers need to take the risks arising from IM seriously, even if they have a policy of forbidding its use, or simply no policy at all.

UK employers can be sued for the actions of their staff under the concept of vicarious liability for harassment; breach of confidentiality; infringement of IP rights; data protection; freedom of information; and defamation. Also they must keep records of IM conversations to comply with sundry regulatory requirements.

So where does Messagelabs fit in with all this? The Symantec subsidiary provides a dedicated hosted IM security service which allows customers to actively monitor and control IM use and in "many cases, provide a defence to actions brought on as a result of use of public IM systems".

The sales spiel is softly spoken and the content is instructive. Recommended.

The legal risks of uncontrolled IM use

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
JLaw, Kate Upton exposed in celeb nude pics hack
100 women victimised as Apple iCloud accounts reportedly popped
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.