Social Mediaのセキュリティ/コンプライアンス対策について、オランダのHilmar Nieropさんが関連情報を整理しています。下記
にNieropさんからの情報を掲載しますので、ご活用下さい。
On the subject of Social Networking (SN), many interesting documents
have been published. For the direct contacts of my international
network I have shared a few documents via the direct PDF-links
mentioned below and uploaded some others to the ‘Social Media
Guidance’ folder of my LinkedIn account (
nl.linkedin.com/in/nierop).
These documents have informational value for all users of social media
in various countries with their distinctive legal and communications
culture. After all, the global use of social media has such an impact
that it provides an international substance which reigns over local
legal form(s), rules and regulations, that are incomplete by nature.
IMPACT OF SOCIAL MEDIA
Social media use is no longer a temporarily hype, but a global trend:
● HCCA & SCCE - Social Networks Survey Report 2009 -
http://www.box.net/shared/static/s0xjifk3z1.pdf
● IISD - SN: Governance for Sustainable Development -
http://www.box.net/shared/static/44dlrpa9an.pdf
● Reuters - The Impact of Social Media on Journalism -
http://www.box.net/shared/static/2ys2t26jf2.pdf
● EU JRC - Study on Use & Impact of Online Networking -
http://www.box.net/shared/static/0tbqb9vekt.pdf
● Ofcom - SN: Attitudes, behaviour and use -
http://www.box.net/shared/static/hpo41q1zsp.pdf
THE NEED FOR STRATEGIES AND POLICIES
The widespread private use by employees is embraced by many businesses
in their communications. Therefore it is advisable not to prohibit the
use of social media completely, but to allow it, albeit under
conditions. Institutions should recognized the use of social media in
its governance, risk and compliance policies, which should be aimed at
mitigating security risks and the risk of misrepresentation,
infringement of intellectual property, unauthorized disclosure of
confidential information, privacy data leakage and identity theft.
● IWGDTT - Privacy in Social Networking Services -
http://www.box.net/shared/static/hnlpyft6vs.pdf
● EU - ENISA - Security Issues and SN Recommendations -
http://www.box.net/shared/static/o825jheibe.pdf
● SNS - Safer Social Networking Principles for the EU -
http://www.box.net/shared/static/f5k1un88nr.pdf
● Scansafe - SN: What Every Business Should Know -
http://www.box.net/shared/static/j8xiun5p4z.pdf
● Boyle, et all - SN: What employers should know -
http://www.box.net/shared/static/sp908uhlmr.pdf
● Vignette - Social Media in the Enterprise -
http://www.box.net/shared/static/kxpa303nxx.pdf
● ATT - The Business Impacts of Social Strategies -
http://www.box.net/shared/static/rp70sbzvv6.pdf
SOCIAL MEDIA COMPLIANCE POLICIES, SOME SAMPLES
● IBM -
http://www.box.net/shared/static/7n2xt3ebzm.pdf
● British Telecom -
http://www.box.net/shared/static/llarpa9dnh.pdf
● Int. Fed. of Red Cross (IFRC) -
http://www.box.net/shared/static/hrjk0nln59.pdf
● The Coca Cola Company -
http://www.box.net/shared/static/1ifmdpdzb2.pdf
● UK CIPR -
http://www.box.net/shared/static/fudf5fx1je.pdf
● WOMMA -
http://www.box.net/shared/static/qxqj2zrd9v.pdf
● US FTC - Principles for Online Behavioral Advertising -
http://www.box.net/shared/static/ssrv55sedo.pdf
● US CIO Council - SN Use by Federal Departments -
http://www.box.net/shared/static/89149s00yu.pdf
PROTECTION OF (FAIR USE OF) INTELLECTUAL PROPERTY:
The policies and procedures on the proper business use of social media
should address the protection of intellectual property, but also
consider and respect the interest of preserving the public domain and
fair use/dealing, of stimulating fair competition and innovation and
of promoting education and scholarship. It should be noted that,
despite the global or ‘cross-jurisdictional’ character of the business
use of social media, these complex issues are organized mostly through
local rules, regulations and legal practices, that diverge
considerably, mainly because of a distinctive rule-based versus
principle-based legal culture.
● US CO - Reproduction by Educators and Librarians -
http://www.box.net/shared/static/b46fmx944a.pdf
● Pillsbury - Considering Fair Use before Takedown Notice -
http://www.box.net/shared/static/vssmlysrpu.pdf
● EFF - Unintended Consequences of the US DMCA -
http://www.box.net/shared/static/9tx8jso4ck.pdf
● EFF - Safe Harbors for Internet Service Providers -
http://www.box.net/shared/static/cnxaskyusi.pdf
● Neil & Winelander - Foreign Defences to US CR claims -
http://www.box.net/shared/static/5afs74btr5.pd
● Wang - International Anti-Circumvention Provisions -
http://www.box.net/shared/static/sb0oxi38bs.pdf
● Gasser - Transposing the EU Copyright Directive -
http://www.box.net/shared/static/o426skfhv7.pdf
● Gasser - Legal Frameworks and Tech. Protection -
http://www.box.net/shared/static/7qf83e6vg0.pdf
● Bäsler - Technological Protection Measures (TPM) -
http://www.box.net/shared/static/25tm7qfqu9.pdf
REGULATORY REQUIREMENTS ON THE USE OF SOCIAL MEDIA
Following the distinction in legal cultures, every regulator of
financial markets and services providers has its own, separate
compliance framework. Nevertheless, many regulators expect or even
require that parties under regulation have supervisory policies,
procedures, systems and internal controls to monitor all electronic
communications technology used by the party and its associated persons
to conduct the business of the party. Furthermore, these regulated
parties are required to make and keep records of such use and
consequently of all content sent or received regardless of the tools
that are used to send it. There is no reason to exclude archiving of
posts to social networking sites from this requirement.
● Osterman - The Impact of New Communications Tools -
http://www.box.net/shared/static/exvkqvcleu.pdf
● Osterman - The Need to Archive SN Content -
http://www.box.net/shared/static/byobpxpzi7.pdf
● US - FINRA - Supervision of Electronic Communications -
http://www.box.net/shared/static/odja4zxt08.pdf
● US - FINRA - Guidance on Social Media Web Sites -
http://www.box.net/shared/static/75ytdooycl.pdf
● US - FINRA - Communications with the Public -
http://www.box.net/shared/static/s16c8jzigp.pdf
If you have any questions, suggestions and comments on the matters
mentioned above, please do contact me. If you want to forward this
message to other persons in interest of this compliance subject,
including your own compliance supervisor, internal controller or IT-
auditor, please feel free do so.
Kind regards,
Hilmar Nierop