By SALIH AHMED ISLAM
1
SOCIAL MEDIA RISK AND THE AUDIT PROCESS
Key Findings
• Organizational social media use is rising and growing increasingly important from a risk management standpoint,
yet formal processes for it remain a rarity.
• Evaluating and monitoring social media risk is or will soon become a key part of audit plans.
• The precise nature of organizational social media risk is rapidly changing, which generates confusion as well as
obstacles internal audit must recognize and address.
I am not sure everyone is trained to understand the risks of social media.
– Director of Auditing, Midsize Hospitality Company
2
RISKS OF A CORPORATE SOCIAL MEDIA PRESENCE
(1/2)
Threats and
Risks Risk Mitigation Techniques
Vulnerabilities
Viruses and malware • Data leakage/theft occurs. • Ensure that antivirus and antimalware controls are
are introduced to the • System downtime occurs. installed on all systems and updated daily.
organizational • Consider using content filtering technology to restrict
• Resources to clean systems
network. or limit access to social media sites.
are required.
• Ensure that the appropriate controls are also installed
on mobile devices, such as smartphones.
• Establish or update policies and standards.
• Develop and conduct awareness training and
campaigns to inform employees of the risks involved
with using social media sites.
Customers and the • Customer backlash/adverse • Engage a brand protection firm that can scan the
enterprise are legal actions occur. internet and search out misuse of the enterprise’s
exposed through a • Customer information is brand.
fraudulent or hijacked exposed. • Provide periodic informational updates to customers
corporate presence. to maintain the awareness of potential fraud and to
• Reputational damage can
happen. establish clear guidelines regarding what information
should be posted as part of the enterprise’s social
• Targeted phishing attacks on
media presence.
customers or employees
occur.
Source: Social Media: Business Benefits and Security, Governance and Assurance Perspectives, ISACA, 2010
3
RISKS OF A CORPORATE SOCIAL MEDIA PRESENCE
(2/2)
Threats and
Risks Risk Mitigation Techniques
Vulnerabilities
Content rights to • The enterprise loses • Ensure that legal and communication teams carefully
information posted to control/legal rights of review user agreements for social media sites that
social media sites are information posted to the are being considered.
unclear or undefined. social media sites. • Establish clear policies that dictate to employees and
customers what information should be posted as part
of the enterprise’s social media presence.
• Ensure that there is a capability to capture and log all
communications (if feasible and appropriate).
A move to a digital • Customers are dissatisfied • Ensure that staffing is adequate to handle the amount
business model may with the responsiveness of traffic that could be created from social media
increase customer received in this arena, presence.
service expectations. leading to potential • Create notices that provide clear windows for
reputational damage for the customer response.
enterprise and customer
retention issues.
Electronic • Regulatory sanctions and • Establish appropriate policies, processes and
communications that fines are issued. technologies to ensure that communications via
may be impacted by • Adverse legal actions are social media that may be impacted by litigation or
retention regulations taken. regulations are tracked and archived appropriately.
or e-discovery are not • Remember that maintaining an archive, depending
effectively managed. on the social media site, may not be a recommended
approach.
4
POLICY RISKS
• Companies without adequate social media policies place themselves at risk of security breaches and reputational
damage among other issues.
• There are a growing number of cases where firms have vague or out-of-date social media policies that are
unenforceable if inappropriate activity takes place.
• Companies should provide their employees real guidance regarding the use of social media sites and should
have very clear policies targeted at issues specific to social networking.
• Companies should develop or update not only their social media policies, but they should also review all their
human resources (HR) and IT policies as many have become outdated in the era of social networking.
Social Media Policy Breach Example
In May 2012, Houston-based fashion retailer Francesca's Holdings Corp. fired their CFO for improperly
communicating company information through social media. The CFO had mentioned the company’s board
meetings, earnings calls and sale of shares multiple times on various social media platforms.
Source: [Link] [Link]
5
SECURITY RISKS
• Employees may intentionally or
inadvertently use social media – whether
on-the-job or at home – in a way that
Phishing poses risks for their employers.
Attacks
• Virus and malware attacks against
organizations have increased because
of employees using Facebook, Twitter,
LinkedIn and other social media in the
workplace. In 2012, Americans spent 74
billion minutes on social media sites
Intellectual (20% of their time).
Property Five Social Malware
Leakage Media • Organizations are most concerned with
Security employees downloading apps or widgets
Risks from social media sites, posting
uncensored content and uncensored
blog entries.
Privacy Physical or
Settings Left Connected
Open to All Threats
Source: [Link]; Global Survey on Social Media Risks,; [Link], [Link]
6
RISK MANAGEMENT FOR SOCIAL NETWORKING
• Who has access to post authorized information about your company?
− That user/account should be identified as the official representative for your company.
• Define the social networking policy.
− This policy states who can/cannot post information about your company and the objective of using
social networking sites.
− What types of information can be shared publicly?
− Are there any approvals required to post information?
− Should the information be publicly available or only to friends/subscribers?
• Identify what types of content are currently being shared that are not authorized and try to mitigate issues
with it.
− Try to get in front of the postings/issues.
• Determine if social networking is working depending on the number of subscribers/users.
− If a program is not providing value to the organization, discontinue it.
7
KEY QUESTIONS TO CONSIDER
• Can mobile commerce solutions be integrated effectively, efficiently and securely with your overall IT
infrastructure and existing management tools?
• Does your IT function maintain and update clear mobile commerce and social media policies that clearly convey
the acceptable use and security requirements of these capabilities to employees who engage in mobile commerce
and/or social media activities? How are these policies monitored and audited?
• How robust are your information security measures? Are these measures applied differently depending on the
sensitivity or importance of the data being processed and stored?
• Is your organization in compliance with all relevant industry standards for security and privacy as well as
applicable laws and regulations?
• Does your organization have efficient systems and processes for monitoring the quality of compliance as well as
processes for monitoring ongoing regulatory issues and anticipating new rules and regulations?
• Is the overall state of your company’s social media security sufficient? How can social media capabilities be
integrated more extensively into appropriate business processes to deliver value?