ATTENTION BANKS USING SOCIAL MEDIA! The day you have been fearing is here!
With the recent release of draft guidance by the FFIEC regarding social media use, social media is now front and center.
Conversations with auditors and examiners is revealing an interesting audit and regulatory expectation - mandatory social media training for all employees and directors.
As social media matures and more and more senior managers and directors feel comfortable with the use of social media, auditors and regulators have begun to look more closely at social media use by organizations. Unfortunately, there still exists in many cases a lack of understanding on the part of internal auditors and examiners in terms of what exactly what and how social media works. This ALWAYS spells trouble for bankers.
As we move forward as an industry in terms of social media adoption financial institutions must focus on three primary areas:
Social Media Risk Assessment
Social Media Policy
Social Media Training
Social Media Risk Assessment
I have previously covered and provided social media risk assessment tools. See my post "Social Media Risk Assessment Process - Part 5." This is one of the most visited posts - with good reason, auditors and regulators expect institutions to conduct a risk assessment before deploying social media.
Social Media Policy
I have also previously covered and provided a sample social media policy. See my post "Sample Social Media Policy for Banks." This is another one of my most visited posts. Even institutions that do not use social media are being required in some cases to have a policy confirming that fact!
Social Media Training
The final piece of the trifecta is Social Media Training. Due to the widespread use of social media within society, auditors and regulators are now treating social media like they do areas such as information security and the Bank Secrecy Act. Increasingly auditors and regulators want to see social media training for all new employees. The thinking is that social media can do some real damage if employees are not aware of the risks. As such, just like information security and money laundering, social media is equally risky. In addition to new employee training, there is an increasing expectation of annual training and director training. All this is new and sudden and many organizations have not been prepared.
In an effort to assist the banking industry, Pan American Bank made available on its YouTube channel a 30 minute social media training video. Pan American Bank does not guarantee that the video will meet auditor or regulator requirements but it is a good starting point for those that need to quickly ramp up their employee and director training relative to social media use.
Check out the video and make use of it for training if it meets your needs. And good luck with your upcoming audits and examinations!
A frequent request is a sample Bank Social Media Policy. Well here it is. This sample policy is bare bones and is intended to be customized for each institution's specific social media strategy.
Enjoy.
BANK
SOCIAL MEDIA POLICY
Bank recognizes the importance of the Internet in the day-to-day
operations of the Bank. From marketing
to reputation management to recruitment of new employees, the Internet plays in
major role in the Bank’s overall strategy.
And now, the Internet is generally synonymous with social media and its
popular social networks such as Facebook and LinkedIn. Use
of Facebook, LinkedIn, blogging, wikis and other online social media vehicles
are commonplace.
This policy is intended to assist employees in
making appropriate decisions about work-related blogging social media
interaction. This policy must be used in
conjunction with other tools provided to employees, including the Acceptable
Use Policy, Employee Guide to Information Security, Human Resources Guide to
Social Media Risks, and related training.
The
lines between work and personal life can become blurred. In general, what you
do on your own time is a personal decision. However, activities in or outside
of work that affect your job performance, the performance of others, or Bank
business interests are a proper focus for Bank policy.
WHAT THE BANK EXPECTS TO GAIN FROM SOCIAL
MEDIA
As a community bank, Bank recognizes the
importance of our employees joining in and helping to shape conversations
regarding the Bank and the communities we serve. Bank is committed to supporting employees
desire to interact knowledgeably and socially on the Internet through social
media.
Contributing
to the online conversations about banking or our communities means being
present where and when they are taking place. As technology tools enable an
easy exchange with community members, governmental representatives, clients,
and the public, we encourage employees to share the insights and expertise
gained through work at Bank. This can be done without first asking permission
provided this guidance is read and followed.
“TARGET” OF THE BANK’S SOCIAL MEDIA EFFORTS
The
Bank’s social media efforts are targeted at several stakeholders:
1.Existing
Customers:
To provide existing customers with information and
conversation/engagement opportunities relative to ongoing activities at the
Bank and in the community. Ultimately,
the goal is to convert a “customer” into an “evangelist” for the Bank.
2.New Customers: To create sufficient
awareness in the local marketplace that results in new customer originations –
deposit, lending, and other services.
The marketplace is full of competitors with similar “commodity” products
and services. Social media allows the
Bank to “humanize” itself and set itself apart from the competition.
3.Media: Social media
provides the Bank with a platform to communicate with the media regarding its
ongoing activities and rich history.
Through social media the Bank can embed video and other media that can
assist the media when developing content.
For example, a bank video can be reposted and potentially result in
viral distribution.
4.Regulatory
Agencies:
Social media provides a channel through which the Bank can highlight
compliance with regulatory requirements.
For example, social media allows the Bank to easily demonstrate its
compliance with the Community Reinvestment Act.
Further, social media provides a convenient mechanism through which to
receive consumer complaints or positive feedback.
5.Community
At-Large:
Social media introduces Bank to the community at-large. The content created on social media provides
an information distribution channel through which interested parties can learn
about Bank.
EMPLOYEE ACCOUNTABILITY
Being
able to share your and the Bank’s activities without prior management approval
means the Bank trusts you to understand that by doing so you are accepting a
higher level of risk for greater rewards. Each Bank employee is personally
responsible for the content he or she publishes on any form of social media. Be
thoughtful about how you present yourself in online social networks.
You
may have identified yourself as a Bank staff member or the Bank as your
employer, either directly or as part of a user profile. If so, ensure your
profile and related content is consistent with how you wish to present yourself
to the Bank’s stakeholders, your business contacts, and your colleagues and
peers.
Senior
management have special responsibility with their Internet presence by virtue
of their high profile position within the Bank, even if they do not explicitly
identify themselves as being affiliated with the Bank. Such senior level staff should assume that
his or her posts will be seen and read by Bank stakeholders and that they will
presumptively associate such posts with the Bank.
Trust
is an essential ingredient in the constructive culture we are striving to
achieve at the Bank. We can’t be there to guide every interaction, so we expect
you to follow these guidelines and advice to help you better balance the risk
vs. reward ratio.
SOCIAL MEDIA OVERSIGHT
The Social Media Manager is responsible for
managing the Bank’s social media strategy.
The Social Media Manager, or an assignee, will provide training and
monitor activity on an ongoing basis.
Inquiries regarding the Bank’s social media strategy must be forwarded
to the Bank’s Social Media Manager.
The Social Media Manager is responsible for
determining “community managers.”
Community managers are employees and third parties that are provided
with authority to act as administrators on the Bank’s behalf. The Social Media Manager must select
individuals as community managers that possess the requisite technical skills
as well as understand the risks associated with social media. All community managers report directly to the
Social Media Manager relative to matters related to social media – regardless
of their role within the Bank.
GENERAL GUIDELINES
These guidelines will help you open up a
respectful, knowledgeable interaction with people on the Internet. They also
protect the privacy, confidentiality, and interests of the Bank and its
customers. Note that these policies and
guidelines apply only to work-related sites and issues and are not meant to
infringe upon your personal interaction or commentary online. Regardless, all employees must determine the
potential impact that “personal” interactions may have upon the Bank and its
customers, vendors, and other stakeholders. Ultimately, employees are held
accountable for ensuring that interaction is appropriate and consistent with
this policy and other Bank guidance.
·The goal is to ensure the Bank’s voice
is part of the larger conversation relating to community banking and the communities
the Bank serves. Do not embark before
understanding the conversation. First, explore the topic being discussed, read
about it and contribute only when input adds or advances the discussion.
Include an especially relevant link, since doing so further connects the Bank
to the wider Web and can result in greater connectivity for the Bank.
·Keep in mind that posts are visible
by all with online access. It may be fine to share your work at the Bank as
part of your participation in the online community, etc., but you DO NOT have
permission to reveal any information that compromises Bank policy or public
positions. By that we mean don’t share
anything that is proprietary and/or confidential to the Bank. For example, it
is not okay to share any content that required a non-disclosure agreement or is
part of a confidential management or Board discussion. Other items that may not be disclosed include
any customer and vendor information that is not publicly available.
·If you are developing
a Web site or writing a blog or making any other social media comment that will
mention Bank and/or our current and potential products, employees, partners,
customers, and competitors, identify that you are an employee of Bank and that
the views expressed on the blog or Web site are yours alone and do not
represent the views of Bank.
·Unless given
permission by your manager, you are not authorized to speak on behalf of the Bank,
nor to represent that you do so.
·If you are developing
a site or writing a blog or making any other social media comment that will
mention our company and / or our current and potential products, employees,
partners, customers, and competitors, as a courtesy to the company, please let
your manager know that you are writing them. Your manager may choose to visit from time to
time to understand your point of view.
·You may not share
information that is confidential and proprietary about the Bank or its
customers. This includes information about upcoming product releases, sales,
finances, number of products sold, number of employees, Bank strategy, and any
other information that has not been publicly released by the company. These are given as examples only and do not
cover the range of what the Bank considers confidential and proprietary. If you
have any question about whether information has been released publicly or
doubts of any kind, speak with your manager before releasing information that
could potentially harm the Bank, or our current and potential products,
employees, partners, and customers. Before embarking on any such endeavor
employees should be familiar with the Bank’s other applicable policies,
including the Acceptable Use Policy, Employee Guide to Information Security,
etc.
·Bank logo and
trademarks may not be used without explicit permission in writing from the Bank.
This is to prevent the appearance that you speak for or represent the company
officially.
·Speak respectfully
about the Bank and our current and potential employees, customers, partners,
and competitors. Do not engage in name
calling or behavior that will reflect negatively on the Bank's reputation. Note
that the use of copyrighted materials, unfounded or derogatory statements, or
misrepresentation is not viewed favorably by the Bank and can result in
disciplinary action up to and including employment termination.
·The Bank encourages
you to write knowledgeably, accurately, and using appropriate professionalism.
Despite disclaimers, your Web interaction can result in members of the public
forming opinions about the Bank and its employees, partners, and products.
·Honor the privacy
rights of our current employees by seeking their permission before writing
about or displaying internal company happenings that might be considered to be
a breach of their privacy and confidentiality.
·You may not sell any
product or service that would compete with any of the Bank's products or
services without permission in writing from the Chief Administrative Officer. This includes, but is not limited to training,
books, products, and freelance writing. If in doubt, talk with your manager or
the Chief Administrative Officer.
·Recognize that you are
legally liable for anything you write or present online. Employees can be
disciplined by the Bank for commentary, content, or images that are defamatory,
pornographic, proprietary, harassing, libelous, or that can create a hostile
work environment. You can also be sued by Bank employees, competitors, and any
individual or company that views your commentary, content, or images as
defamatory, pornographic, proprietary, harassing, libelous or creating a hostile
work environment.
·Media contacts about the
Bank and our current and potential products, employees, partners, customers,
and competitors should be referred for coordination and guidance to the Chief
Administrative Officer. This does not specifically include your opinions,
writing, and interviews on topics aside from the Bank and our current and
potential products, employees, partners, customers, and competitors.
·Make sure that your online
activities do not interfere with your job performance.
·Respecting differences, appreciating
the diversity of opinions and speaking or conducting yourself in a professional
manner is expected at all times. If you aren’t completely confident about what
you intend to share, you should seek management input before you post.
HOW WILL SOCIAL MEDIA BE IMPLEMENTED AT THE
BANK
The
Social Media Manager of the Bank is accountable for determining the Bank’s
Social Media Strategy. The Bank’s use of
social media is largely to develop a “community” of Bank supporters and to
raise awareness of the Bank’s brand.
This is largely done through interaction on mainstream social media
platforms such as Facebook, LinkedIn, Blogger, and Twitter. The specific platforms used may change from
time to time as technology evolves and audiences shift. Regardless, the
guidelines above remain in effect.
Questions regarding the Bank’s use of social media should be directed to
the Social Media Manager.
TYPES OF BANK ACTIVITIES/POSTINGS
The
primary purpose of the Bank’s social media activities is “community
building.” While the Bank will from
time-to-time promote products and services, the primary focus is the creation
of an online community where the Bank can share its history and mission and
where stakeholders can maintain conversations with the Bank. The Bank does not “censor” comments made by
third parties and only removes comments if they are considered obscene,
pornographic or similarly inappropriate.
As such, it is the Bank’s policy to remain transparent and not delete
derogatory comments. Instead, it is the
Bank’s policy to attempt to understand the origin of any derogatory comment in
an attempt to “correct” any error or misunderstanding caused by the Bank. Management is responsible for monitoring
content on an ongoing basis (generally daily).
The
Social Media Manager is responsible for determining “community managers” given
authority to post on behalf of the Bank.
The Social Media Manager is responsible for ensuring that such employees
are “social media savvy” and understand social media risks.
TYPES OF SOCIAL MEDIA USED BY BANK
Currently
the Bank utilizes Facebook, Youtube, Blogger, LinkedIn, and Twitter. These platforms provide for varying types of
interaction. Some are more information
based such as LinkedIn. Others are more
collaborative, such as Facebook.
Currently the Social Media Manager is responsible for managing these
accounts.
OTHER FORMS OF SOCIAL MEDIA
Regardless
of any organization’s use of social media, Internet users can make comments
that affect the Bank on locations outside of the Bank’s social media
sites. As such, the Bank utilizes Google
Alerts and SocialMention.com to monitor (listen) to conversations in social
media and on Web sites that may affect the Bank. Such reports are delivered directly to the Social
Media Manager on an ongoing basis. The Social
Media Manager is responsible for determining appropriate action, if any.
TRAINING
On
at least an annual basis the Bank will provide social media training to all
personnel. The training is intended to
convert employees into social media evangelists while ensuring safe and sound
use of social media. Compliance with the
guidelines noted above will largely ensure that employees act in a manner
consistent with Bank expectations.
AUDIT
The
Bank’s social media activities will be audited as part of the Bank’s normal
internal audit schedule. Auditors will
audit as appropriate. For example,
audits related to IT, consumer compliance, fair lending and CRA may all contain
a social media component.
80% maintained formal written social media policies in 2012
64%
maintained formal written social media policies in 2011
43%
maintained formal written social media policies in 2012
The survey also found that in 2012, 54% of investment advisers prohibit personal social media sites such as Facebook to be used for business purposes. Further, in 2012, 54% of investment adviser firms audit for compliance with social media policies.
This data suggests that the regulated financial services industries have realized the ubiquity of social media - not only in the personal lives of employees and clients, but in the financial services industries.
With so few investment advisers maintaining formal written social media policies, the regulatory expectation, AKA Best Practice, will be for every regulated firm to not only maintain such policies but also test for compliance with the policies.
Ahhhh. The fifth and final part of this series on the Social Media Risk Assessment Process ("SMRAP"). I hope you've enjoyed the series up to this point. I know I've enjoyed bringing it to you.
This last segment is all about completing the SMRAP. I've created a fairly basic yet effective social media risk assessment model. As you will note from the graphic below, my model uses the concept of "Threat/Vulnerability" pairs to isolate weaknesses that can result in disaster. In a nutshell, here's the deal: there are threats and there are vulnerabilities.
Threats are actions or events that can cause harm to the organization. For example, when it comes to social media risks, an example of a threat is the disclosure of confidential customer information over social media.
Vulnerabilities are simply weaknesses in the system. They are the chinks in the armor. Vulnerabilities are what enable the threats to take form. For example, a vulnerability related to the threat above could be a lack of understanding of social media-related information security risks by employees.
Therefore, using the same threat example above, a way for the threat to manifest or occur can be due to a lack of adequate employee training. In other words, an employee does not know that it is a bad idea to post confidential employee information on social media sites and as such, the employee post information or takes part in conversations that reveal confidential customer information.
This is what I refer to as the Threat/Vulnerability pair. A threat creates havoc and a vulnerability permits the threat to wreak havoc. It must be noted that threats in of themselves are fairly harmless. Without a vulnerability threats have no life.
STEP 1: Determine the threats that apply to the organization's social media environment. I have created a social media risk assessment template that contains the majority of "high level" organizational threats. You can download the social media risk assessment document here.
STEP 2: Determine the vulnerabilities (weaknesses) that can create an environment in which the threats can manifest. In some cases a threat will have only one vulnerability associated with it. However, in the majority of cases there will be multiple vulnerabilities associated with each threat. If you inspect the template social media risk assessment you will see multiple vulnerabilities per threat (see graphic above).
STEP 3: Once the threats and vulnerabilities have been identified it is time to determine the internal controls that are in place. Internal controls are the practices and processes that will keep the vulnerability from turning the threat into a reality. The template provided contains common controls. It is not likely that every organization will have every control listed. The greater the number and breadth of controls in place, the less likely the threat will take place. Each control should be listed on the risk assessment as shown in the template document.
STEP: 4: Based upon the internal controls in place and the nature of the threat and vulnerability, the organization must determine the likelihood that the threat will take place. A sample Likelihood Matrix is such as the one shown below is contained in the template.
STEP 5: Next, the organization must determine the severity of the effect of the threat if it were to manifest based upon the existing controls. Similar to the Likelihood Matrix, the template contains a Severity Matrix such as the one below.
STEP 6: Finally, the organization uses both the Likelihood of Occurrence and the Impact of Severity to determine the Risk Level. The template also contains a matrix to assist in the determination of risk.
STEP 7: After completing the social media risk assessment it should be reviewed. Considerations in the review include a risk level that is too high relative to the organization's risk appetite. For example, it may be the policy that all "moderate" and "high" risk areas be reviewed with senior management to discuss further internal controls that can be implemented to reduce the risks. It is generally a good idea to summarize the risk assessment process and deliver a report to the organization's Audit Committee and possibly the Board of Directors. Along with the report may be recommendations or action items that will be taken to increase the number of internal controls to reduce the overall risk. Once such action items are completed the organization can again perform the risk assessment to determine if the internal controls have been effective in reducing the risk level.
It must be noted that there are many ways to conduct a risk assessment. This method is just one. There is no right or wrong methodology as long as the end result provides an assessment of the residual risk and considers all of the practical threats.
I encourage you to take this template and turn it into your own. I also ask that you return to this post with you recommended revisions/enhancements to the template so that others may also benefit.
The Social Media Risk Assessment Process ("SMRAP") should be incorporated as a component of the organization’s overall risk management strategy.
Generally, a revised social media risk assessment should be conducted on an annual basis. The fundamental basis of the SMRAP is to balance the Bank’s desire and need to utilize social media with other factors associated with doing business. The organization must recognize that some risk must be accepted to make use of social media business. The organization must also recognize that some social media risks exist regardless of the organization's social media strategy. As such, the risk assessment program provides a practical approach to efficiently and cost-effectively identifying risks associated with social media use - regardless of the look and feel of the organization's social media strategy.
Risk assessments help ensure that employees comply with the organization's requirements as outlined in its social media policy, code of conduct and other related policies. The SMRAP also raises employee awareness regarding social media risks associated with their business unit’s use of social media. Additionally, the SMRAP assists the organization in making informed decisions about the need for additional risk mitigation controls.
The SMRAP can be conducted by a centralized department or rolled out to departments and sites on a decentralized basis. Each organization must determine how to best disseminate the SMRAP. The goal of the SMRAP is to identify threats and vulnerabilities posed by social media. This may be difficult to do through a centralized approach if the organization is large and/or spread out geographically.
Those responsible for performing the SMRAP must determine each threat and associated vulnerabilities. For each vulnerability the manager must determine the controls in place to prevent the vulnerability from exploiting severity of impact upon the organization and determine the likelihood of the vulnerability exploit occurring given existing internal controls. It is important to note that this process requires a certain level of subjectivity. As such, the success or failure of the SMRAP hinges upon the knowledge and understanding of the individual(s) performing the SMRAP. As such, the organization should select individuals with experience in assessing risks and business impact. The use of junior staff to conduct the SMRAP may under- or overestimate the conclusions - unless the staff are well supervised. Part 5 of this series will describe an easy manner to document the SMRAP.
Once the risk level is determined for each threat/vulnerability pair, organizations may consider additional controls for moderate- and high-risk levels. After the control enhancements have been incorporated, the risk threat/vulnerability pair is re-evaluated to determine the residual risk after the control is implemented.
The outcome of the SMRAP process is the mitigation of risk to acceptable levels, thereby providing adequate protection to the organization. As such, to the extent that moderate- and high-risk levels exist after the implementation of mitigating controls, a discussion of the threat should be elevated to senior management for further discussion. It is important to note that operating under moderate- or high-risk levels is not uncommon. However, under such circumstances it is important to ensure that the appropriate parties are aware of the risks in order to ensure that all options have been considered as well as to ensure that all parties are aware of the risks. This awareness is crucial for line units - particularly during periods of duress. Consider it a form of CYA!
In cases in which additional controls must be implemented to mitigate moderate and high risks, the organization should consider the development of a formal written action plan that documents the controls. The action plan should include the steps to be taken, the time frame for completion and the individuals responsible for implementation of the controls.
It is highly recommended that the SMRAP be evaluated by the appropriate parties within the organization. This may include the CEO, CIO, IT Steering Committee, Compliance Committee, Audit Committee and the Board of Directors. The purpose of the review should be to share the strengths and weaknesses of the organization’s social media strategy from a risk perspective. Identified organizational vulnerabilities should be addressed with the appropriate personnel for the purpose of implementing corrective actions.
The SMRAP focuses on strategic and operational issues. Organizational vulnerabilities are weaknesses related to the organization’s policies or practices that can result in the manifestation of a threat. Part 5 of this series will drill down into specific threats and vulnerabilities. Part 5 of this series will provide as a template the most common threats and vulnerabilities. However, the framework that will be introduced in Part 5 provides sufficient flexibility to allow the user of the SMRAP to customize the process with organization-specific threats and vulnerabilities.
Risk is the possibility of an act or event occurring that would have an adverse effect on the organization. Risk can also be the potential that a given threat will exploit vulnerabilities to cause loss of, or damage to, the organization. Risk is generally measured by a combination of severity and likelihood of occurrence.
A threat is an action or event that might jeopardize the organization. It is a sequence of circumstances and events that allow a human (disgruntled employee, etc.) or other agent (virus, Trojan horse, etc.) to cause a misfortune by exploiting vulnerabilities. A vulnerability is a weakness that allows a threat to manifest itself.
Considerations to keep in mind when determining threats:
Determining the legal implications and contingent liability associated with any identified risks. For example, if hackers successfully access the organization’s Facebook account and use it to subsequently attack followers/friends, the organization may be liable for damages incurred by the party that is attacked.
Capability and motivation are important attributes of threats. Threats need both attributes (capability and motivation) to be credible. For example, a skilled hacker seeking access to a Facebook account is considered a credible threat because the hacker has the capability (skills) and motivation (financial/ideological gain from the use of the organization's Facebook account).
Interested parties. Serious hackers, interested computer novices, dishonest vendors or competitors, disgruntled current or former employees, organized crime rings or even agents of espionage pose a potential threat.
Poor security program/poor employee security awareness. Hackers often exploit well-known weaknesses in creating secure passwords.
Internal controls are mechanisms that enable the organization to achieve its business objectives. With appropriate controls in place the organization is able to effectively mitigate the risk posed by a threat. With respect to social media, internal controls are designed to meet three main objectives:
Confidentiality: Preventing the disclosure of sensitive information;
Integrity: Preventing unauthorized modifications to information and maintaining internal and external consistency; and,
Availability: Ensuring that the systems are working and that the data is accessible to users as required.
In addition to requiring the documentation of threats and vulnerabilities, the SMRAP also requires the documentation of associated controls. To maintain an effective social media risk assessment process the organization must ensure that the organization has adequately considered the implementation of the following types of controls:
Preventative Controls: These controls are established to avoid occurrences of unwanted events. This type of control may include passwords, policies, procedures, security awareness program, etc. These controls are considered “proactive.”
Detective Controls: These controls alert and identify violations after the fact. These controls can include social media monitoring and other information that provides notification after the event has occurred. These controls are considered “reactive.”
Corrective Controls: These controls are intended to remedy unauthorized events and to restore the original controls. For example, the ability to reset the custodian of a social media account that has been locked-out due to some adverse event is considered a corrective control.
Deterrent Controls: These controls discourage violations. For example, a policy statement that states that violators may be terminated for non-compliance with the social media policy is considered a deterrent control.
Part 4 of this series will begin discussion on the risk assessment process.
The first step in the Social Media Risk Assessment Process ("SMRAP") is to identify the social media-related threats that can adversely affect the organization. While these threats can be technology-based, they are most dangerous when they originate from human acts.
The ubiquitous use of social media has brought social media-related threats to the forefront. Among the threats associated with social media are:
Disclosure of Confidential Customer Information by Employees;
Disclosure of Confidential Company Information by Employees;
Systems Outages Due to Social Media-Based Virus/Malware Infections;
Remediation Expenses Related to
Social Media-Based Virus/Malware Infections;
Loss of Branding Content Contained on Social Media Platforms;
Lawsuits Related to Alleged Improper Use of Social Media in the Hiring Process;
Lawsuits Related to Alleged Improper Use of Social Media in the Termination Process;
Loss of Opportunity to Hire Star Employees Due to Information Contained on Social Media Platforms;
Spam/Malware/Virus Attacks Against Social Media Platform Friends/Followers; and,
Excessive/Inappropriate Use of Social Media by Employees.
The SMRAP in and of itself does not assure adequate protection against social media-related risks. Rather, the SMRAP is part of the organization’s overall Risk Management Program that includes the written policies, guidelines, employee awareness/training and an independent review of the organization’s social media practices.
The SMRAP concludes with a determination of the adequacy of existing controls relative to the identified threats and vulnerabilities. The SMRAP allows management to determine the need for additional controls to reduce the Bank’s risk exposure.
Since threats and vulnerabilities change over time, the SMRAP must be updated and reviewed on a regular basis to ensure the appropriateness and effectiveness of the controls in place. Updates are minor changes to the existing risk profile. These include changes resulting from the implementation and/or removal of a control, or when the effectiveness of a control changes. Updates occur when the following events take place:
New control is implemented;
An incident highlights a minor discrepancy in the current risk profile (i.e., the likelihood or severity of a threat requires minor adjusting or the effectiveness of a control requires adjustment);
A risk is no longer applicable; and,
A new risk emerges.
The SMRAP should generally occur on an annual basis. The SMRAP should also take place when the following occurs:
Increase in security risks/exposures due to an event or series of events (i.e., significant change in organization's social media strategy, development/implementation of in-house social network, etc.);
Cumulative updates indicate the need for a review;
Changes in regulatory requirements; and,
Serious social media-related incident.
The results of the initial SMRAP and periodic SMRAP updates should be provided to the appropriate party within the organization such as the organization's Audit Committee and Board of Directors.
Part 3 of this series will discuss risks, threats and vulnerabilities.
Do you hear that? There it is again. Did you hear it that time?! Oh man, it's worse than I thought. The bank examiners are updating their examination procedures to include "social media" and the industry is not ready for it. What does that mean? Low Hanging Fruit Time. Noooooooooo....
This post is about the development of a Social Media Risk Assessment Process (“SMRAP”). The SMRAP provides organizations with a systematic approach to evaluating exposure to social media-related risks. The SMRAP focuses on five components: Threats, Vulnerabilities, Controls, Likelihood of Occurrence and Impact.
Social Media Risk Assessment Matrix
The SMRAP is intended to achieve one basic goal: the protection of the organization's reputation.
Management is responsible for ensuring that systems and data are adequately protected. Historically this has related to the systems and data maintained within the organization's walls. Unfortunately, as an organizations are increasingly moving to third-party social media platforms such as Facebook, Twitter and LinkedIn (and for good reasons), management must now take measures to adequately controls risks related to external systems.
Management is also responsible for protecting the organization's reputation from intentional and unintentional acts that may cause harm to the organization. Unfortunately, reputational harm can come from many directions, including public outcry (think Bank of America's debit card debacle or Occupy Wall Street).
An organizational key business objective is to maintain a set of policies and procedures that protect and mitigate against risks related to day-to-day operations. Social media risks have become part of the day-to-day risks of any organization. As has been previously stated, organizations cannot determine whether or not to participate in social media. Social media happens. And it has been happening for some time. The question is whether or not management has realized this fact and has moved to mitigate the risks before the risks mitigate the organization.
The SMRAP is used to identify, evaluate, document, monitor and manage social media risks. Through the SMRAP the organization is able to identify and prioritize social media-related risks and develop appropriate risk management strategies. Such strategies include the establishment of appropriate policies and the selection of cost-effective controls that implement the policies.
Part 2 of this series will begin the process of identifying the social media threats that must be evaluated as part of a risk assessment process.
The Australian newspaper titled its coverage of the story, "Bank Threatens Staff with Sack Over Social Media Comments." The gist of the story is this...Commonwealth Bank published a social media policy that essentially "deputized" employees with the mission of reporting and eliminating any adverse social media comments - or possibly face the executioner (Human Resources Manager).
According to the published story, "bank employees have been told they must immediately notify their manager if they become aware of 'inappropriate or disparaging content and information stored or posted by others', including non-employees, in the 'social media environment'."
The policy holds employees accountable for the actions of third parties. According to The Australian report, the policy state: "For example, your friend could post an inappropriate comment about the group on your Facebook page or create a blog about the group."
As if holding employees accountable for the acts of others isn't bad enough, the policy then goes on to state that "failure to comply with this policy is a serious disciplinary matter and may result in disciplinary action being taken against you, which may include the termination of your employment."
Sounds to me like whoever drafted this policy did not have a good understanding of how social media works. But even worse, this person did not know the advantages that comes with openly addressing criticism.
Back on December 17th I posted "Firing An Employee Bad Mouthing the Company on Social Media? Better Think Twice." While the December 17th post relates primarily to U.S. incidents, there is much that applies to any locale. As such, it was no surprise when the Australian Finance Sector Union demanded suspension of the bank's new social media policy, accusing it of trying to restrict freedom of expression.
Quite honestly, I was shocked when I heard about this incident. At this stage in the game most corporations should at least know the basics of social media and employee relations - or at least ask someone that does before putting out such a draconian policy. On the other hand, I suppose this need for education bodes well for me as just last month I released a new book, "Human Resources Guide to Social Media Risks" (shameless plug!).
I hate to break it to Commonwealth Bank but they just made it onto every social media consultant's Powerpoint deck. I'm sure the story does not end here. Let me know what you think and hear.
One of the most commonly discussed issues regarding social media and business is whether employees should be permitted to access social media platforms during the work day. The Internet is full of debate for and against employee use of social media. Critics state that employee use of social media at work will result in a waste of the organization’s valuable resources as well as potentially endanger the organization. Detractors state that employee use of social media can harm the organization as a result of thoughtless social media interactions that disclose trade secrets and other confidential information. Further, these opponents state that employees also create legal liability as a result of the potential for disparaging, harassing, and other comments that give rise to legal action by fellow employees and third parties.
Proponents of social media acknowledge that risks exist but that the potential benefits outweigh the risks so long as the risks are well managed. Supporters of employee use of social media point to social media’s ability to significantly increase brand awareness in an effective and economical manner. Also touted is the potential that social media has for increasing sales as a result of an effective social media marketing initiative that includes employees as brand ambassadors. Other benefits include increased goodwill for organizations that act in an honest and transparent manner as well as the benefit to the organization for developing a communal environment that listens to the outside world.
Employee use of social media is not right for all organizations. Some organizations may find it beneficial relative to business development, branding, and customer service. On the other hand, organizations may determine that the workforce has no business use for social media. Whether or not an organization embarks on a strategy that permits employee use of social media is dependent upon the organization’s mission, goals, and appetite for risk. To the extent that an organization decides to permit employee use of social media in the workplace, it must ensure that employee social media usage is managed properly.
Employee use of social media can be an extremely effective tool when properly used. Conversely, a poorly managed employee-based social media effort can create nothing but headaches for an organization. Regardless of an organization’s position regarding employee social media use, a formal, written social media policy is essential to protect the organization.
Early last week I received a phone call from a consultant working for a boutique financial services consulting firm who was conducting research on a social media best practices document for a bank client. The fellow seemed bright and well informed. I was actually surprised that the firm he was working for was getting involved in the social media space. I'm surprised not so much because of their involvement in social media but more so because they tend to focus on the traditional banking/finance stuff. I'm not sure what this means for the early wave of social media consultants...but that's a story for a different day.
Anyway, one of the questions this consultant posed had to do with the regulatory risk associated with social media. My response was that I felt that regulators would likely give a social media implementation little more than lip service and so long as an appropriate risk assessment and policy was in place, the examiners would look no further. I told this consultant that given the current focus of the regulatory agencies, I would be surprised if they considered social media at all. But better safe than sorry.
I followed that up by stating to the consultant that the regulatory risk was the least of a bank's worries. While there may be some regulatory implications related to the use of social media, it is insignificant compared to the larger reputational risk posed by social media.
Earlier today I picked up the November/December issue of Western Banking Magazine. In the Consider This section of the magazine was an article that I wish I had read prior to speaking with this consultant because I think it would have laid it out very neatly for him. I've quoted this section of the magazine below.
"One out of eight respondents to the Travelers Global Technology business unit survey indicated that they post work-related information on social media websites. In fact, 30 percent feel it is acceptable to post information online about their employers as long as they believe it is true. Survey results also showed that more than 75 percent of those who post anything personal online said they were 'not at all' or 'not very concerned' about information posted online causing professional damage.
The growth of social media and the lack of awareness among employees and employers on how social media are changing the corporate landscape could increase a company's risk exposure. The Travelers survey results also indicate that two-thirds of respondents say their companies do not have a policy in place for social media usage, or they are not aware that one exists."
If you have followed this blog you know that I am a stickler for risk assessments and policies. My recommendation is to get the bank's internal auditor or product manager to prepare and present a social media risk assessment to executive management and the board of directors. This should be treated just like any other new product/service implementation.
My next recommendation is to enhance the bank's Acceptable Use Policy to include the social media policy - rather than create an entirely new policy. The bank's information security policy can also be used in lieu of the AUP.
If you have no idea where to begin with a social media policy, begin with my earlier post (Pain Free Social Media Policy). You will be able to get a customized policy up and running in no time.
As I stated above, regulatory risk is the least of your worries. What you want to do is make sure your employees know the rules of engagement - because, whether or not your bank has a social media strategy of its own, chances are your employees are out there potentially putting your good name at risk.