Showing posts with label social media policy. Show all posts
Showing posts with label social media policy. Show all posts

Saturday, March 9, 2013

Quick and Dirty (and Effective) Social Media Training Tool

ATTENTION BANKS USING SOCIAL MEDIA!  The day you have been fearing is here!

With the recent release of draft guidance by the FFIEC regarding social media use, social media is now front and center.

Conversations with auditors and examiners is revealing an interesting audit and regulatory expectation - mandatory social media training for all employees and directors.

As social media matures and more and more senior managers and directors feel comfortable with the use of social media, auditors and regulators have begun to look more closely at social media use by organizations.  Unfortunately, there still exists in many cases a lack of understanding on the part of internal auditors and examiners in terms of what exactly what and how social media works.  This ALWAYS spells trouble for bankers.

As we move forward as an industry in terms of social media adoption financial institutions must focus on three primary areas:

  1. Social Media Risk Assessment
  2. Social Media Policy
  3. Social Media Training
Social Media Risk Assessment

I have previously covered and provided social media risk assessment tools.  See my post "Social Media Risk Assessment Process - Part 5."  This is one of the most visited posts - with good reason, auditors and regulators expect institutions to conduct a risk assessment before deploying social media.

Social Media Policy

I have also previously covered and provided a sample social media policy.  See my post "Sample Social Media Policy for Banks."  This is another one of my most visited posts.  Even institutions that do not use social media are being required in some cases to have a policy confirming that fact!

Social Media Training

The final piece of the trifecta is Social Media Training.  Due to the widespread use of social media within society, auditors and regulators are now treating social media like they do areas such as information security and the Bank Secrecy Act.  Increasingly auditors and regulators want to see social media training for all new employees.  The thinking is that social media can do some real damage if employees are not aware of the risks.  As such, just like information security and money laundering, social media is equally risky.  In addition to new employee training, there is an increasing expectation of annual training and director training.  All this is new and sudden and many organizations have not been prepared.

In an effort to assist the banking industry, Pan American Bank made available on its YouTube channel a 30 minute social media training video.  Pan American Bank does not guarantee that the video will meet auditor or regulator requirements but it is a good starting point for those that need to quickly ramp up their employee and director training relative to social media use.

Check out the video and make use of it for training if it meets your needs.  And good luck with your upcoming audits and examinations!

Sunday, August 19, 2012

Sample Social Media Policy for Banks

A frequent request is a sample Bank Social Media Policy.  Well here it is.  This sample policy is bare bones and is intended to be customized for each institution's specific social media strategy.

Enjoy.


BANK SOCIAL MEDIA POLICY

Bank recognizes the importance of the Internet in the day-to-day operations of the Bank.  From marketing to reputation management to recruitment of new employees, the Internet plays in major role in the Bank’s overall strategy.  And now, the Internet is generally synonymous with social media and its popular social networks such as Facebook and LinkedIn.  Use of Facebook, LinkedIn, blogging, wikis and other online social media vehicles are commonplace.

This policy is intended to assist employees in making appropriate decisions about work-related blogging social media interaction.  This policy must be used in conjunction with other tools provided to employees, including the Acceptable Use Policy, Employee Guide to Information Security, Human Resources Guide to Social Media Risks, and related training.

The lines between work and personal life can become blurred. In general, what you do on your own time is a personal decision. However, activities in or outside of work that affect your job performance, the performance of others, or Bank business interests are a proper focus for Bank policy.

WHAT THE BANK EXPECTS TO GAIN FROM SOCIAL MEDIA

As a community bank, Bank recognizes the importance of our employees joining in and helping to shape conversations regarding the Bank and the communities we serve.  Bank is committed to supporting employees desire to interact knowledgeably and socially on the Internet through social media.

Contributing to the online conversations about banking or our communities means being present where and when they are taking place. As technology tools enable an easy exchange with community members, governmental representatives, clients, and the public, we encourage employees to share the insights and expertise gained through work at Bank. This can be done without first asking permission provided this guidance is read and followed.

“TARGET” OF THE BANK’S SOCIAL MEDIA EFFORTS

The Bank’s social media efforts are targeted at several stakeholders:

1.    Existing Customers:  To provide existing customers with information and conversation/engagement opportunities relative to ongoing activities at the Bank and in the community.  Ultimately, the goal is to convert a “customer” into an “evangelist” for the Bank.

2.    New Customers:  To create sufficient awareness in the local marketplace that results in new customer originations – deposit, lending, and other services.  The marketplace is full of competitors with similar “commodity” products and services.  Social media allows the Bank to “humanize” itself and set itself apart from the competition.

3.    Media:  Social media provides the Bank with a platform to communicate with the media regarding its ongoing activities and rich history.  Through social media the Bank can embed video and other media that can assist the media when developing content.  For example, a bank video can be reposted and potentially result in viral distribution.

4.    Regulatory Agencies:  Social media provides a channel through which the Bank can highlight compliance with regulatory requirements.  For example, social media allows the Bank to easily demonstrate its compliance with the Community Reinvestment Act.  Further, social media provides a convenient mechanism through which to receive consumer complaints or positive feedback.

5.    Community At-Large:  Social media introduces Bank to the community at-large.  The content created on social media provides an information distribution channel through which interested parties can learn about Bank.

EMPLOYEE ACCOUNTABILITY

Being able to share your and the Bank’s activities without prior management approval means the Bank trusts you to understand that by doing so you are accepting a higher level of risk for greater rewards. Each Bank employee is personally responsible for the content he or she publishes on any form of social media. Be thoughtful about how you present yourself in online social networks.

You may have identified yourself as a Bank staff member or the Bank as your employer, either directly or as part of a user profile. If so, ensure your profile and related content is consistent with how you wish to present yourself to the Bank’s stakeholders, your business contacts, and your colleagues and peers.

Senior management have special responsibility with their Internet presence by virtue of their high profile position within the Bank, even if they do not explicitly identify themselves as being affiliated with the Bank.  Such senior level staff should assume that his or her posts will be seen and read by Bank stakeholders and that they will presumptively associate such posts with the Bank.

Trust is an essential ingredient in the constructive culture we are striving to achieve at the Bank. We can’t be there to guide every interaction, so we expect you to follow these guidelines and advice to help you better balance the risk vs. reward ratio.

SOCIAL MEDIA OVERSIGHT

The Social Media Manager is responsible for managing the Bank’s social media strategy.  The Social Media Manager, or an assignee, will provide training and monitor activity on an ongoing basis.  Inquiries regarding the Bank’s social media strategy must be forwarded to the Bank’s Social Media Manager.

The Social Media Manager is responsible for determining “community managers.”  Community managers are employees and third parties that are provided with authority to act as administrators on the Bank’s behalf.  The Social Media Manager must select individuals as community managers that possess the requisite technical skills as well as understand the risks associated with social media.  All community managers report directly to the Social Media Manager relative to matters related to social media – regardless of their role within the Bank.

GENERAL GUIDELINES

These guidelines will help you open up a respectful, knowledgeable interaction with people on the Internet. They also protect the privacy, confidentiality, and interests of the Bank and its customers.  Note that these policies and guidelines apply only to work-related sites and issues and are not meant to infringe upon your personal interaction or commentary online.  Regardless, all employees must determine the potential impact that “personal” interactions may have upon the Bank and its customers, vendors, and other stakeholders. Ultimately, employees are held accountable for ensuring that interaction is appropriate and consistent with this policy and other Bank guidance.


·         The goal is to ensure the Bank’s voice is part of the larger conversation relating to community banking and the communities the Bank serves.  Do not embark before understanding the conversation. First, explore the topic being discussed, read about it and contribute only when input adds or advances the discussion. Include an especially relevant link, since doing so further connects the Bank to the wider Web and can result in greater connectivity for the Bank.

·         Keep in mind that posts are visible by all with online access. It may be fine to share your work at the Bank as part of your participation in the online community, etc., but you DO NOT have permission to reveal any information that compromises Bank policy or public positions.  By that we mean don’t share anything that is proprietary and/or confidential to the Bank. For example, it is not okay to share any content that required a non-disclosure agreement or is part of a confidential management or Board discussion.  Other items that may not be disclosed include any customer and vendor information that is not publicly available. 

·         If you are developing a Web site or writing a blog or making any other social media comment that will mention Bank and/or our current and potential products, employees, partners, customers, and competitors, identify that you are an employee of Bank and that the views expressed on the blog or Web site are yours alone and do not represent the views of Bank.

·         Unless given permission by your manager, you are not authorized to speak on behalf of the Bank, nor to represent that you do so.

·         If you are developing a site or writing a blog or making any other social media comment that will mention our company and / or our current and potential products, employees, partners, customers, and competitors, as a courtesy to the company, please let your manager know that you are writing them.  Your manager may choose to visit from time to time to understand your point of view.

·         You may not share information that is confidential and proprietary about the Bank or its customers. This includes information about upcoming product releases, sales, finances, number of products sold, number of employees, Bank strategy, and any other information that has not been publicly released by the company.  These are given as examples only and do not cover the range of what the Bank considers confidential and proprietary. If you have any question about whether information has been released publicly or doubts of any kind, speak with your manager before releasing information that could potentially harm the Bank, or our current and potential products, employees, partners, and customers. Before embarking on any such endeavor employees should be familiar with the Bank’s other applicable policies, including the Acceptable Use Policy, Employee Guide to Information Security, etc. 

·         Bank logo and trademarks may not be used without explicit permission in writing from the Bank. This is to prevent the appearance that you speak for or represent the company officially.

·         Speak respectfully about the Bank and our current and potential employees, customers, partners, and competitors.  Do not engage in name calling or behavior that will reflect negatively on the Bank's reputation. Note that the use of copyrighted materials, unfounded or derogatory statements, or misrepresentation is not viewed favorably by the Bank and can result in disciplinary action up to and including employment termination.

·         The Bank encourages you to write knowledgeably, accurately, and using appropriate professionalism. Despite disclaimers, your Web interaction can result in members of the public forming opinions about the Bank and its employees, partners, and products.

·         Honor the privacy rights of our current employees by seeking their permission before writing about or displaying internal company happenings that might be considered to be a breach of their privacy and confidentiality.

·         You may not sell any product or service that would compete with any of the Bank's products or services without permission in writing from the Chief Administrative Officer.  This includes, but is not limited to training, books, products, and freelance writing. If in doubt, talk with your manager or the Chief Administrative Officer.

·         Recognize that you are legally liable for anything you write or present online. Employees can be disciplined by the Bank for commentary, content, or images that are defamatory, pornographic, proprietary, harassing, libelous, or that can create a hostile work environment. You can also be sued by Bank employees, competitors, and any individual or company that views your commentary, content, or images as defamatory, pornographic, proprietary, harassing, libelous or creating a hostile work environment.

·         Media contacts about the Bank and our current and potential products, employees, partners, customers, and competitors should be referred for coordination and guidance to the Chief Administrative Officer. This does not specifically include your opinions, writing, and interviews on topics aside from the Bank and our current and potential products, employees, partners, customers, and competitors.

·         Make sure that your online activities do not interfere with your job performance.

·         Respecting differences, appreciating the diversity of opinions and speaking or conducting yourself in a professional manner is expected at all times. If you aren’t completely confident about what you intend to share, you should seek management input before you post.


HOW WILL SOCIAL MEDIA BE IMPLEMENTED AT THE BANK

The Social Media Manager of the Bank is accountable for determining the Bank’s Social Media Strategy.  The Bank’s use of social media is largely to develop a “community” of Bank supporters and to raise awareness of the Bank’s brand.  This is largely done through interaction on mainstream social media platforms such as Facebook, LinkedIn, Blogger, and Twitter.  The specific platforms used may change from time to time as technology evolves and audiences shift. Regardless, the guidelines above remain in effect.  Questions regarding the Bank’s use of social media should be directed to the Social Media Manager.

TYPES OF BANK ACTIVITIES/POSTINGS

The primary purpose of the Bank’s social media activities is “community building.”  While the Bank will from time-to-time promote products and services, the primary focus is the creation of an online community where the Bank can share its history and mission and where stakeholders can maintain conversations with the Bank.  The Bank does not “censor” comments made by third parties and only removes comments if they are considered obscene, pornographic or similarly inappropriate.  As such, it is the Bank’s policy to remain transparent and not delete derogatory comments.  Instead, it is the Bank’s policy to attempt to understand the origin of any derogatory comment in an attempt to “correct” any error or misunderstanding caused by the Bank.  Management is responsible for monitoring content on an ongoing basis (generally daily).

The Social Media Manager is responsible for determining “community managers” given authority to post on behalf of the Bank.  The Social Media Manager is responsible for ensuring that such employees are “social media savvy” and understand social media risks.

TYPES OF SOCIAL MEDIA USED BY BANK

Currently the Bank utilizes Facebook, Youtube, Blogger, LinkedIn, and Twitter.  These platforms provide for varying types of interaction.  Some are more information based such as LinkedIn.  Others are more collaborative, such as Facebook.  Currently the Social Media Manager is responsible for managing these accounts.

OTHER FORMS OF SOCIAL MEDIA

Regardless of any organization’s use of social media, Internet users can make comments that affect the Bank on locations outside of the Bank’s social media sites.  As such, the Bank utilizes Google Alerts and SocialMention.com to monitor (listen) to conversations in social media and on Web sites that may affect the Bank.  Such reports are delivered directly to the Social Media Manager on an ongoing basis.  The Social Media Manager is responsible for determining appropriate action, if any.

TRAINING

On at least an annual basis the Bank will provide social media training to all personnel.  The training is intended to convert employees into social media evangelists while ensuring safe and sound use of social media.  Compliance with the guidelines noted above will largely ensure that employees act in a manner consistent with Bank expectations.

AUDIT

The Bank’s social media activities will be audited as part of the Bank’s normal internal audit schedule.  Auditors will audit as appropriate.  For example, audits related to IT, consumer compliance, fair lending and CRA may all contain a social media component.

Wednesday, July 18, 2012

Social Media Policies Everywhere in Among Investment Advisors

The Investment Adviser Association, ACA Compliance Group and Old Mutual Asset Management released the 2012 Investment Management Compliance Testing Survey Report.  The report found that among the investment advisers surveyed:


  • 80% maintained formal written social media policies in 2012
  • 64%  maintained formal written social media policies in 2011
  • 43%  maintained formal written social media policies in 2012
The survey also found that in 2012, 54% of investment advisers prohibit personal social media sites such as Facebook to be used for business purposes.  Further, in 2012, 54% of investment adviser firms audit for compliance with social media policies.


This data suggests that the regulated financial services industries have realized the ubiquity of social media - not only in the personal lives of employees and clients, but in the financial services industries.

With so few investment advisers maintaining formal written social media policies, the regulatory expectation, AKA Best Practice, will be for every regulated firm to not only maintain such policies but also test for compliance with the policies.

Thursday, March 1, 2012

Social Media Risk Assessment Process - Part 5

Ahhhh. The fifth and final part of this series on the Social Media Risk Assessment Process ("SMRAP").  I hope you've enjoyed the series up to this point.  I know I've enjoyed bringing it to you.

This last segment is all about completing the SMRAP.  I've created a fairly basic yet effective social media risk assessment model.  As you will note from the graphic below, my model uses the concept of "Threat/Vulnerability" pairs to isolate weaknesses that can result in disaster.  In a nutshell, here's the deal:  there are threats and there are vulnerabilities.


Threats are actions or events that can cause harm to the organization.  For example, when it comes to social media risks, an example of a threat is the disclosure of confidential customer information over social media.

Vulnerabilities are simply weaknesses in the system.  They are the chinks in the armor.  Vulnerabilities are what enable the threats to take form.  For example, a vulnerability related to the threat above could be a lack of understanding of social media-related information security risks by employees.

Therefore, using the same threat example above, a way for the threat to manifest or occur can be due to a lack of adequate employee training.  In other words, an employee does not know that it is a bad idea to post confidential employee information on social media sites and as such, the employee post information or takes part in conversations that reveal confidential customer information.

This is what I refer to as the Threat/Vulnerability pair.  A threat creates havoc and a vulnerability permits the threat to wreak havoc.  It must be noted that threats in of themselves are fairly harmless.  Without a vulnerability threats have no life.


STEP 1:  Determine the threats that apply to the organization's social media environment.  I have created a social media risk assessment template that contains the majority of "high level" organizational threats.  You can download the social media risk assessment document here.

STEP 2: Determine the vulnerabilities (weaknesses) that can create an environment in which the threats can manifest.  In some cases a threat will have only one vulnerability associated with it.  However, in the majority of cases there will be multiple vulnerabilities associated with each threat.  If you inspect the template social media risk assessment you will see multiple vulnerabilities per threat (see graphic above).

STEP 3:  Once the threats and vulnerabilities have been identified it is time to determine the internal controls that are in place.  Internal controls are the practices and processes that will keep the vulnerability from turning the threat into a reality.  The template provided contains common controls.  It is not likely that every organization will have every control listed.  The greater the number and breadth of controls in place, the less likely the threat will take place.  Each control should be listed on the risk assessment as shown in the template document.

STEP: 4:  Based upon the internal controls in place and the nature of the threat and vulnerability, the organization must determine the likelihood that the threat will take place.  A sample Likelihood Matrix is such as the one shown below is contained in the template.


STEP 5:  Next, the organization must determine the severity of the effect of the threat if it were to manifest based upon the existing controls.  Similar to the Likelihood Matrix, the template contains a Severity Matrix such as the one below.


STEP 6: Finally, the organization uses both the Likelihood of Occurrence and the Impact of Severity to determine the Risk Level.  The template also contains a matrix to assist in the determination of risk.


STEP 7:  After completing the social media risk assessment it should be reviewed.  Considerations in the review include a risk level that is too high relative to the organization's risk appetite.  For example, it may be the policy that all "moderate" and "high" risk areas be reviewed with senior management to discuss further internal controls that can be implemented to reduce the risks. It is generally a good idea to summarize the risk assessment process and deliver a report to the organization's Audit Committee and possibly the Board of Directors.  Along with the report may be recommendations or action items that will be taken to increase the number of internal controls to reduce the overall risk.  Once such action items are completed the organization can again perform the risk assessment to determine if the internal controls have been effective in reducing the risk level.

It must be noted that there are many ways to conduct a risk assessment.  This method is just one.  There is no right or wrong methodology as long as the end result provides an assessment of the residual risk and considers all of the practical threats.

I encourage you to take this template and turn it into your own.  I also ask that you return to this post with you recommended revisions/enhancements to the template so that others may also benefit.

Enjoy.

Wednesday, February 22, 2012

Social Media Risk Assessment Process - Part 4

The Social Media Risk Assessment Process ("SMRAP") should be incorporated as a component of the organization’s overall risk management strategy.  

Generally, a revised social media risk assessment should be conducted on an annual basis.  The fundamental basis of the SMRAP is to balance the Bank’s desire and need to utilize social media with other factors associated with doing business.  The organization must recognize that some risk must be accepted to make use of social media business.  The organization must also recognize that some social media risks exist regardless of the organization's social media strategy.  As such, the risk assessment program provides a practical approach to efficiently and cost-effectively identifying risks associated with social media use - regardless of the look and feel of the organization's social media strategy.



Risk assessments help ensure that employees comply with the organization's requirements as outlined in its  social media policy, code of conduct and other related policies.  The SMRAP also raises employee awareness regarding social media risks associated with their business unit’s use of social media.  Additionally, the SMRAP assists the organization in making informed decisions about the need for additional risk mitigation controls. 

The SMRAP can be conducted by a centralized department or rolled out to departments and sites on a decentralized basis.  Each organization must determine how to best disseminate the SMRAP.  The goal of the SMRAP is to identify threats and vulnerabilities posed by social media.  This may be difficult to do through a centralized approach if the organization is large and/or spread out geographically.


Those responsible for performing the SMRAP must determine each threat and associated vulnerabilities.  For each vulnerability the manager must determine the controls in place to prevent the vulnerability from exploiting severity of impact upon the organization and determine the likelihood of the vulnerability exploit occurring given existing internal controls.  It is important to note that this process requires a certain level of subjectivity.  As such, the success or failure of the SMRAP hinges upon the knowledge and understanding of the individual(s) performing the SMRAP.  As such, the organization should select individuals with experience in assessing risks and business impact.  The use of junior staff to conduct the SMRAP may under- or overestimate the conclusions - unless the staff are well supervised.  Part 5 of this series will describe an easy manner to document the SMRAP.



Once the risk level is determined for each threat/vulnerability pair, organizations may consider additional controls for moderate- and high-risk levels.  After the control enhancements have been incorporated, the risk threat/vulnerability pair is re-evaluated to determine the residual risk after the  control is implemented. 

The outcome of the SMRAP process is the mitigation of risk to acceptable levels, thereby providing adequate protection to the organization.  As such, to the extent that moderate- and high-risk levels exist after the implementation of mitigating controls, a discussion of the threat should be elevated to senior management for further discussion.  It is important to note that operating under moderate- or high-risk levels is not uncommon.  However, under such circumstances it is important to ensure that the appropriate parties are aware of the risks in order to ensure that all options have been considered as well as to ensure that all parties are aware of the risks.  This awareness is crucial for line units - particularly during periods of duress.  Consider it a form of CYA!

In cases in which additional controls must be implemented to mitigate moderate and high risks, the organization should consider the development of a formal written action plan that documents the controls.  The action plan should include the steps to be taken, the time frame for completion and the individuals responsible for implementation of the controls.

It is highly recommended that the SMRAP be evaluated by the appropriate parties within the organization.  This may include the CEO, CIO, IT Steering Committee, Compliance Committee, Audit Committee and the Board of Directors.  The purpose of the review should be to share the strengths and weaknesses of the organization’s social media strategy from a risk perspective.  Identified organizational vulnerabilities should be addressed with the appropriate personnel for the purpose of implementing corrective actions.


The SMRAP focuses on strategic and operational issues.  Organizational vulnerabilities are weaknesses related to the organization’s policies or practices that can result in the manifestation of a threat.  Part 5 of this series will drill down into specific threats and vulnerabilities.  Part 5 of this series will provide as a template  the most common threats and vulnerabilities.  However, the framework that will be introduced in Part 5 provides sufficient flexibility to allow the user of the SMRAP to customize the  process with organization-specific threats and vulnerabilities.

Tuesday, February 21, 2012

Social Media Risk Assessment Process - Part 3

Risk is the possibility of an act or event occurring that would have an adverse effect on the organization.  Risk can also be the potential that a given threat will exploit vulnerabilities to cause loss of, or damage to, the organization.  Risk is generally measured by a combination of severity and likelihood of occurrence.

A threat is an action or event that might jeopardize the organization.  It is a sequence of circumstances and events that allow a human (disgruntled employee, etc.) or other agent (virus, Trojan horse, etc.) to cause a misfortune by exploiting vulnerabilities.  A vulnerability is a weakness that allows a threat to manifest itself. 



Considerations to keep in mind when determining threats:

  • Determining the legal implications and contingent liability associated with any identified risks.  For example, if hackers successfully access the organization’s Facebook account and use it to subsequently attack followers/friends, the organization may be liable for damages incurred by the party that is attacked.
  • Capability and motivation are important attributes of threats.  Threats need both attributes (capability and motivation) to be credible.  For example, a skilled hacker seeking access to a Facebook account is considered a credible threat because the hacker has the capability (skills) and motivation (financial/ideological gain from the use of the organization's Facebook account).
  • Interested parties.  Serious hackers, interested computer novices, dishonest vendors or competitors, disgruntled current or former employees, organized crime rings or even agents of espionage pose a potential threat.
  • Poor security program/poor employee security awareness.  Hackers often exploit well-known weaknesses in creating secure passwords.

Internal controls are mechanisms that enable the organization to achieve its business objectives.  With appropriate controls in place the organization is able to effectively mitigate the risk posed by a threat.  With respect to social media, internal controls are designed to meet three main objectives:

  • Confidentiality:  Preventing the disclosure of sensitive information;
  • Integrity:  Preventing unauthorized modifications to information and maintaining internal and external consistency; and,
  • Availability:  Ensuring that the systems are working and that the data is accessible to users as required.

In addition to requiring the documentation of threats and vulnerabilities, the SMRAP also requires the documentation of associated controls.  To maintain an effective social media risk assessment process the organization must ensure that the organization has adequately considered the implementation of the following types of controls:

  • Preventative Controls:  These controls are established to avoid occurrences of unwanted events.  This type of control may include passwords, policies, procedures, security awareness program, etc.  These controls are considered “proactive.”
  • Detective Controls:  These controls alert and identify violations after the fact.  These controls can include social media monitoring and other information that provides notification after the event has occurred.  These controls are considered “reactive.”
  • Corrective Controls:  These controls are intended to remedy unauthorized events and to restore the original controls.  For example, the ability to reset the custodian of a social media account that has been locked-out due to some adverse event is considered a corrective control.
  • Deterrent Controls:  These controls discourage violations. For example, a policy statement that states that violators may be terminated for non-compliance with the social media policy is considered a deterrent control.

Part 4 of this series will begin discussion on the risk assessment process.

Monday, February 20, 2012

Social Media Risk Assessment Process - Part 2

The first step in the Social Media Risk Assessment Process ("SMRAP") is to identify the social media-related threats that can adversely affect the organization.  While these threats can be technology-based, they are most dangerous when they originate from human acts.


The ubiquitous use of social media has brought social media-related threats to the forefront.  Among the threats associated with social media are:

  • Disclosure of Confidential Customer Information by Employees;
  • Disclosure of Confidential Company Information by Employees;
  • Systems Outages Due to Social Media-Based Virus/Malware Infections;
  • Remediation Expenses Related to  Social Media-Based Virus/Malware Infections;
  • Loss of Branding Content Contained on Social Media Platforms;
  • Lawsuits Related to Alleged Improper Use of Social Media in the Hiring Process;
  • Lawsuits Related to Alleged Improper Use of Social Media in the Termination Process;
  • Loss of Opportunity to Hire Star Employees Due to Information Contained on Social Media Platforms;
  • Spam/Malware/Virus Attacks Against Social Media Platform Friends/Followers; and, 
  • Excessive/Inappropriate Use of Social Media by Employees.

The SMRAP in and of itself does not assure adequate protection against social media-related risks.  Rather, the SMRAP is part of the organization’s overall Risk Management Program that includes the written policies, guidelines, employee awareness/training and an independent review of the organization’s social media practices.


The SMRAP concludes with a determination of the adequacy of existing controls relative to the identified threats and vulnerabilities.  The SMRAP allows management to determine the need for additional controls to reduce the Bank’s risk exposure. 



Since threats and vulnerabilities change over time, the SMRAP must be updated and reviewed on a regular basis to ensure the appropriateness and effectiveness of the controls in place.  Updates are minor changes to the existing risk profile.  These include changes resulting from the implementation and/or removal of a control, or when the effectiveness of a control changes.  Updates occur when the following events take place:

  • New control is implemented;
  • An incident highlights a minor discrepancy in the current risk profile (i.e., the likelihood or severity of a threat requires minor adjusting or the effectiveness of a control requires adjustment);
  • A risk is no longer applicable; and,
  • A new risk emerges.

The SMRAP should generally occur on an annual basis.  The SMRAP should also take place when the following occurs:

  • Increase in security risks/exposures due to an event or series of events (i.e., significant change in organization's social media strategy, development/implementation of in-house social network, etc.);
  • Cumulative updates indicate the need for a review;
  • Changes in regulatory requirements; and,
  • Serious social media-related incident.

The results of the initial SMRAP and periodic SMRAP updates should be provided to the appropriate party within the organization such as the organization's Audit Committee and Board of Directors. 


Part 3 of this series will discuss risks, threats and vulnerabilities.


Series:
Social Media Risk Assessment Process - Part 1

Sunday, February 19, 2012

Social Media Risk Assessment Process - Part 1

Do you hear that?  There it is again.  Did you hear it that time?!  Oh man, it's worse than I thought.  The bank examiners are updating their examination procedures to include "social media" and the industry is not ready for it.  What does that mean?  Low Hanging Fruit Time.  Noooooooooo....   


This post is about the development of a Social Media Risk Assessment Process (“SMRAP”).  The SMRAP provides organizations with a systematic approach to evaluating exposure to social media-related risks.  The SMRAP focuses on five components: Threats, Vulnerabilities, Controls, Likelihood of Occurrence and Impact.

Social Media Risk Assessment Matrix

The SMRAP is intended to achieve one basic goal: the protection of the organization's reputation.

Management is responsible for ensuring that systems and data are adequately protected.  Historically this has related to the systems and data maintained within the organization's walls.  Unfortunately, as an organizations are increasingly moving to third-party social media platforms such as Facebook, Twitter and LinkedIn (and for good reasons), management must now take measures to adequately controls risks related to external systems.



Management is also responsible for protecting the organization's reputation from intentional and unintentional acts that may cause harm to the organization.  Unfortunately, reputational harm can come from many directions, including public outcry (think Bank of America's debit card debacle or Occupy Wall Street).

An organizational key business objective is to maintain a set of policies and procedures that protect and mitigate against risks related to day-to-day operations.  Social media risks have become part of the day-to-day risks of any organization.  As has been previously stated, organizations cannot determine whether or not to participate in social media.  Social media happens.  And it has been happening for some time.  The question is whether or not management has realized this fact and has moved to mitigate the risks before the risks mitigate the organization.

The SMRAP is used to identify, evaluate, document, monitor and manage social media risks.  Through the SMRAP the organization is able to identify and prioritize social media-related risks and develop appropriate risk management strategies.  Such strategies include the establishment of appropriate policies and the selection of cost-effective controls that implement the policies.

Part 2 of this series will begin the process of identifying the social media threats that must be evaluated as part of a risk assessment process.

Sunday, February 6, 2011

Your Neighbor Hates the Bank....You're Fired!

About once per year there occurs a social media-related event that gets the social media talking heads (myself included), well, talking.

This year's first nominee for the 2011 Social Media "Oh No You Didn't" Award goes to Commonwealth Bank in Australia.

The Australian newspaper titled its coverage of the story, "Bank Threatens Staff with Sack Over Social Media Comments."  The gist of the story is this...Commonwealth Bank published a social media policy that essentially "deputized" employees with the mission of reporting and eliminating any adverse social media comments - or possibly face the executioner (Human Resources Manager).


According to the published story, "bank employees have been told they must immediately notify their manager if they become aware of 'inappropriate or disparaging content and information stored or posted by others', including non-employees, in the 'social media environment'."


The policy holds employees accountable for the actions of third parties.  According to The Australian report, the policy state:  "For example, your friend could post an inappropriate comment about the group on your Facebook page or create a blog about the group."


As if holding employees accountable for the acts of others isn't bad enough, the policy then goes on to state that "failure to comply with this policy is a serious disciplinary matter and may result in disciplinary action being taken against you, which may include the termination of your employment."


Sounds to me like whoever drafted this policy did not have a good understanding of how social media works.  But even worse, this person did not know the advantages that comes with openly addressing criticism.


Back on December 17th I posted "Firing An Employee Bad Mouthing the Company on Social Media?  Better Think Twice."  While the December 17th post relates primarily to U.S. incidents, there is much that applies to any locale.  As such, it was no surprise when the Australian Finance Sector Union demanded  suspension of the bank's new social media policy, accusing it of trying to restrict freedom of expression.


Quite honestly, I was shocked when I heard about this incident.  At this stage in the game most corporations should at least know the basics of social media and employee relations - or at least ask someone that does before putting out such a draconian policy.  On the other hand, I suppose this need for education bodes well for me as just last month I released a new book, "Human Resources Guide to Social Media Risks" (shameless plug!).


Human Resources Guide to Social Media Risks


I hate to break it to Commonwealth Bank but they just made it onto every social media consultant's  Powerpoint deck.  I'm sure the story does not end here.  Let me know what you think and hear.

Sunday, December 26, 2010

Social Media Use in the Workplace

One of the most commonly discussed issues regarding social media and business is whether employees should be permitted to access social media platforms during the work day. The Internet is full of debate for and against employee use of social media. Critics state that employee use of social media at work will result in a waste of the organization’s valuable resources as well as potentially endanger the organization. Detractors state that employee use of social media can harm the organization as a result of thoughtless social media interactions that disclose trade secrets and other confidential information. Further, these opponents state that employees also create legal liability as a result of the potential for disparaging, harassing, and other comments that give rise to legal action by fellow employees and third parties.

Proponents of social media acknowledge that risks exist but that the potential benefits outweigh the risks so long as the risks are well managed. Supporters of employee use of social media point to social media’s ability to significantly increase brand awareness in an effective and economical manner. Also touted is the potential that social media has for increasing sales as a result of an effective social media marketing initiative that includes employees as brand ambassadors. Other benefits include increased goodwill for organizations that act in an honest and transparent manner as well as the benefit to the organization for developing a communal environment that listens to the outside world.

Employee use of social media is not right for all organizations. Some organizations may find it beneficial relative to business development, branding, and customer service. On the other hand, organizations may determine that the workforce has no business use for social media. Whether or not an organization embarks on a strategy that permits employee use of social media is dependent upon the organization’s mission, goals, and appetite for risk. To the extent that an organization decides to permit employee use of social media in the workplace, it must ensure that employee social media usage is managed properly.

Employee use of social media can be an extremely effective tool when properly used. Conversely, a poorly managed employee-based social media effort can create nothing but headaches for an organization. Regardless of an organization’s position regarding employee social media use, a formal, written social media policy is essential to protect the organization.

Saturday, November 28, 2009

Social Media-Related Regulatory Examinations On The Horizon?

Early last week I received a phone call from a consultant working for a boutique financial services consulting firm who was conducting research on a social media best practices document for a bank client. The fellow seemed bright and well informed. I was actually surprised that the firm he was working for was getting involved in the social media space. I'm surprised not so much because of their involvement in social media but more so because they tend to focus on the traditional banking/finance stuff. I'm not sure what this means for the early wave of social media consultants...but that's a story for a different day.



Anyway, one of the questions this consultant posed had to do with the regulatory risk associated with social media. My response was that I felt that regulators would likely give a social media implementation little more than lip service and so long as an appropriate risk assessment and policy was in place, the examiners would look no further. I told this consultant that given the current focus of the regulatory agencies, I would be surprised if they considered social media at all. But better safe than sorry.



I followed that up by stating to the consultant that the regulatory risk was the least of a bank's worries. While there may be some regulatory implications related to the use of social media, it is insignificant compared to the larger reputational risk posed by social media.



Earlier today I picked up the November/December issue of Western Banking Magazine. In the Consider This section of the magazine was an article that I wish I had read prior to speaking with this consultant because I think it would have laid it out very neatly for him. I've quoted this section of the magazine below.


"One out of eight respondents to the Travelers Global Technology business unit survey indicated that they post work-related information on social media websites. In fact, 30 percent feel it is acceptable to post information online about their employers as long as they believe it is true. Survey results also showed that more than 75 percent of those who post anything personal online said they were 'not at all' or 'not very concerned' about information posted online causing professional damage.

The growth of social media and the lack of awareness among employees and employers on how social media are changing the corporate landscape could increase a company's risk exposure. The Travelers survey results also indicate that two-thirds of respondents say their companies do not have a policy in place for social media usage, or they are not aware that one exists."


If you have followed this blog you know that I am a stickler for risk assessments and policies. My recommendation is to get the bank's internal auditor or product manager to prepare and present a social media risk assessment to executive management and the board of directors. This should be treated just like any other new product/service implementation.



My next recommendation is to enhance the bank's Acceptable Use Policy to include the social media policy - rather than create an entirely new policy. The bank's information security policy can also be used in lieu of the AUP.

If you have no idea where to begin with a social media policy, begin with my earlier post (Pain Free Social Media Policy). You will be able to get a customized policy up and running in no time.

As I stated above, regulatory risk is the least of your worries. What you want to do is make sure your employees know the rules of engagement - because, whether or not your bank has a social media strategy of its own, chances are your employees are out there potentially putting your good name at risk.