Return to Jive Software

397 Views 2 Replies Last post: Feb 25, 2009 3:32 PM by Roxy RSS
Roxy Novice 4 posts since
Aug 11, 2008
Currently Being Moderated

Feb 9, 2009 10:14 AM

How do you deal with confidential information in attachments and audit logs?

We have a developer community forum for customers and partners (hereafter referred to as user).  It is hosted and moderated by our company, and it is not open to the public, so the user must have a valid account created for them in order to access the forum.

 

As part of assisting the users, we sometimes will ask for audit logs or example code.  Sometimes these logs or sample code will contain authentication information (e.g. URLs, session ID, username, password).  How do you handle that, if at all?  Is the stance that if the user posts information that could harm them, that is their responsibility?

 

Taking it a step further, what if the user posts an audit log file that contains customer data (e.g. first & last name, email address, phone number, mailing address, etc.)?   This information is "buried" in the attachement/audit log, but it's still out there and could be abused if it fell into the wrong hands.

 

I know there's the Forum Access Agreement which include clauses like, "You must bear all of the risks associated with your use of the Forum, including without limitation the risk that you will be provided with erroneous information, or poor advice, and the risk that you will infringe upon third party rights."  But I am curious to see if others face this situation and if they just let the Forum Access Agreement cover it, or if there are other ways that organizations are handling this situation?

 

Thanks!

kmackin99 Novice 1 posts since
Feb 25, 2009
Currently Being Moderated
Feb 25, 2009 1:37 PM in response to: Roxy
Re: How do you deal with confidential information in attachments and audit logs?

This is a grey area that requres a  lot of care.  I would make partners and users sign an NDA, or "rechannel" logs and such to another pipeline that's private and not post them.

 

Kelly

More Like This

  • Retrieving data ...

Bookmarked By (0)