The Cartoon and Clip of the Week for November 7, 2014
- Revenue: The potential for organizational revenue loss based on reputation damage and confidential information exposure.
- Productivity: The potential for organizational productivity loss based on too much time spent on social networks and use of social networks to undermine management by circumventing established hierarchy and workflow patterns.
- Security: The potential organization information system security compromise based on the introduction of malware into technology systems and uncontrolled exchange of data.
A Simple Framework for Considering Social Media Risk
Detection:
- Do you have a risk related to social media? (Example: Potential or Actual Risk)
- Have you done an impact analysis on how the social media risk might impact the organization? (Example: Acceptable or Unacceptable Risk)
- Have you identified the social media networks that might contribute to social media risk with the organization? (Example: LinkedIn, Facebook, Twitter)
- Have you identified employees that may be using social networks in the workplace? (Example: Individuals, Workgroups, Departments)
- Have you determined the location where social networks are being accessed? (Example: Inside Corporate Firewall, Outside Corporate Firewall)
- Have you established policy or guidance addressing the access of social networks by employees? (Example: Social Media Usage Policy, Corporate Communication Device Usage Policy)
- Do you have a system in place to monitor usage of social media networks? (Example: Active Technology Monitoring, Passive Human Sampling)
- Have you established an individual, workgroup, or department as the lead in assessing social media usage reports? (Example: Director of Human Resources, Office of Compliance, IT Department)