Safest Places On the Web
Computerworld -
The security breaches at ChoicePoint Inc. and LexisNexis Group have us all asking the same questions: Where is my data safe? And how do I know? These are the questions I recently set out to answer, and I found some surprising results.
First, the bad news. There still isn't one widely recognized seal of approval that says a company has top-notch privacy and security. The padlock symbol on your Web browser means the session is encrypted, and Web security seals such as ScanAlert Inc.'s "Hacker Safe" mark say the Web site is protected against all known vulnerabilities. But these methods don't address the broader, organizational security practices at issue in the ChoicePoint and LexisNexis incidents.
So how do we know where our data is safe? The best answer I found is this: We need to look for privacy policies that address the Safe Harbor privacy principles negotiated by the U.S. Department of Commerce and the European Union. Why? Because these principles represent best practices in privacy and security, and companies that publicly commit to them are at great legal risk if they don't adhere to them. A solid privacy policy is our best guarantee of data safety.
So which companies meet this criterion? I reviewed the privacy policies of the top 50 most-visited Web sitesas measured by Jupiter Researchand the Forbes 100 largest companies in the world. It's an admittedly small sample, so I also asked Truste and my privacy professional counterparts in other organizations for their recommendations.
What did we find? This is where the surprises sprang up. (See accompanying charts.)
The largest U.S. companies are better than their European counterparts about including the European privacy principles in their online privacy notices. The EU considers the U.S. an "inadequate" destination for personal data, but you couldn't tell it by reading corporate privacy policies. Among the Forbes 100, U.S. companies comply with an average of 3.9 of the seven EU Safe Harbor principles, compared with 2.3 for EU companies.
Another surprise was the mediocre scores of the privacy policies on the most-visited U.S. Web sites. Visitors to these popular sites apparently aren't deterred by their general lack of strong privacy commitments. The typical top-50 site posts a privacy notice that addresses only 4.4 of the EU Safe Harbor principles.
I wasn't surprised that the companies with the strongest privacy policies are concentrated in the financial and technology industries, where profits depend on consumer trust in data privacy. Seventeen of the top 20 sites hail from these sectors.
I also wasn't surprised that several companies outside the Forbes Global 100 made the final list. It's easier for a smaller company to consistently enforce a strong privacy policy than for a large corporation operating in several markets and jurisdictions to do so.
Additional Resources


White Papers & Webcasts
Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...
Data Protection and Disaster Recovery with iSCSI and VMware
Data protection and disaster recovery are top of mind for any IT manager, and the challenges of complexity and cost remain as obstacles....
ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Subscribe to Computerworld
