Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Which Way to Go? Mac Leopard and .Mac or Google Services? | Main | Issues in Ajax Application Security »

'Good' Spyware for Tracking Employees

I think a lot of us expect employers to monitor emails and block inappropriate content, it just seems like the norm these days. I don't have a problem with this, employers are responsible for and liable for too much to not know what is going on in their network. I haven't gotten used to the idea of "good" spyware for monitoring activity (one exception is when I did a project for the U.S. Army, I expected everything I did would and should be monitored). Take the case of a former employee of the University of British Columbia who was canned, in part, using data collected by employer installed spyware. Here a piece from The Province:

The University of B.C. wants the right to keep using "spyware" to monitor its employees' Internet use.

And the university -- which used the software to fire a worker who surfed non-work-related websites for hours a day -- has gone to court to challenge an anti-spyware order by B.C.'s privacy commission.

Michel Mandono, an engineering technician in UBC's botany department, was fired in February 2005 for "repeated theft of time" as well as failure to perform his work, excessive lateness, dishonesty and breach of trust.

The use of spyware for internal monitoring may not be widespread now but I suspect as awareness grows about security threats from insider abuse, the practice of monitoring will grow.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/495

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net