Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts

Wednesday, April 28, 2010

Ethics Opinion on Cloud Computing

After a request from a member of their bar association, The North Carolina Bar studied the ethics of using cloud computing -- also known as Software-as-a-Service or SaaS -- in a law firm, and they've finished drafting a proposed Formal Ethics Opinion on the matter.

The American Bar Association's Legal Technology Resource Center describes SaaS computing as the following:
"SaaS is distinguished from traditional software in several ways. Rather than installing the software to your computer or the firm's server, SaaS is accessed via a web browser (like Explorer or Firefox) over the internet. Data is stored on the vendor's data center rather than the firm's computers."
The North Carolina Ethics Opinion clearly states the central question:
"SaaS for law firms may involve the storage of a law firm's data, including client files..., on remote servers rather than on the law firm's own computers and, therefore, outside the direct control of the firm's lawyers. Given the duty to safeguard confidential client information... may a law firm use SaaS?"
The Ethics Opinion concluded that SaaS computing is acceptable by lawyers and law firms, provided that:

1) "Steps are taken effectively to minimize the risk of inadvertent or unauthorized disclosure of confidential client information and to protect client property, including file information, from risk of loss...

Although a lawyer has a professional obligation to protect confidential information from unauthorized disclosure, the Ethics Committee has long held that this duty does not compel any particular mode of handling confidential information nor does it prohibit the employment of vendors whose services may involve the handling of documents or data containing client information. "

2) The law firm should be able to answer a number of questions, including:
  • Who has access to the data besides the lawyer?
  • Who owns the data -- the lawyer or the SaaS vendor?
  • How does the SaaS vendor, or any third party hosting company, safeguard the physical and electronic security and confidentiality of stored data.
  • Where is the data hosted? Is it in a country with less rigorous protections against unlawful search and seizure?
  • If the SaaS vendor goes out of business, will the lawyer have access to the data and the software or source code?
  • How often and on how many geographically distinct servers does the data get backed up?

As a Legal Process Outsourcing company with years of experience in data security on third party servers, the North Carolina Bar Association's opinion seems entirely pragmatic.
"...the Ethics Committee concludes that a law firm may use SaaS if reasonable care is taken effectively to minimize the risks to the confidentiality and to the security of client information and client files. However, the law firm is not required to guarantee that the system will be invulnerable to unauthorized access."

Friday, March 13, 2009

The Paperless Office and Data Security

There are a number of components to ensuring data security within an LPO. We’ve discussed the importance of onshore servers for housing all data.

One fundamental purpose of the onshore server is to allow offshore access to information without actually capturing that information. Furthering the safeguard against third-party personnel capturing any data is the implementation of the paperless offshore office.

Obviously, the paperless office has no, um, paper. In the event that any paper or writing instruments are occasionally necessary, it is an important requirement to shred the paper at the end of every shift and collect all writing instruments.

But the paperless office goes further than that, encompassing a complete defense against any method of capturing data, including:

• Restricted computer functionality for individual computers with limited user rights and disabled media drives and USB/printer ports
• Secure individual computers with PC firewall and antivirus protection
• External internet access restricted to certain sites/computers within office locations
• Network monitoring and tracking capable of producing audit trail records of all files accessed on the server and logs of all incoming and outgoing mail from the servers
• A secure internet network incorporating Proxy/Firewall NAT and Port filtering
• The prohibition of cell phones and cameras in any area where client work is processed

Friday, March 06, 2009

Onshore Servers and Data Security

During March we’ll be discussing part two of our series Ethical Imperatives For An LPO: Protecting Client Confidentiality. And a key component to protecting confidentiality is data security.

For U.S. attorneys considering the value of outsourcing legal work to an LPO, there is one question that must come first regarding data security: Are the LPO’s servers on U.S. soil?

All other security safeguards come second.

When all data is stored in onshore servers, offshore attorneys are only accessing the data to complete the work, and not holding or storing the data on offshore computers or servers.

Why is this so crucial? Because data stored on servers is subject to the state and federal laws applicable to the physical location of the data. That means for data housed on domestic servers, U.S. law applies. In the rare event of some sort of breach, the originating counsel needs to retain as much recourse as possible, and part of that includes U.S. jurisdiction over the server.

Data stored on offshore servers puts the data beyond the jurisdiction of established U.S. security laws. In this instance, the originating counsel would have uncertain control over investigating and/or enforcing security concerns.

Additionally, while the risk of third-party data security breaches (that’s a lot of syllables to say “hacker”) is the same regardless of the server’s physical location, the United States’ long-arm statutes allow plaintiffs to extend personal jurisdiction throughout the country. Just one more advantage to requiring onshore servers from your LPO.