<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Managing the use of ephemeral Instant Messaging applications in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/58948#M865</link>
    <description>&lt;P&gt;Keep in mind that IM is restricted in various sectors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a story on a broker running afoul of FINRA's text messaging regulations:&amp;nbsp;&amp;nbsp;&lt;A href="https://www.smarsh.com/blog/thought-leadership/FINRA-increases-scrutiny-of-brokers-text-messages-for-business#:~:text=FINRA%20suspended%20a%20broker%20for,settlement%20finalized%20earlier%20this%20month" target="_blank"&gt;https://www.smarsh.com/blog/thought-leadership/FINRA-increases-scrutiny-of-brokers-text-messages-for-business#:~:text=FINRA%20suspended%20a%20broker%20for,settlement%20finalized%20earlier%20this%20month&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Fri, 05 May 2023 17:30:13 GMT</pubDate>
    <dc:creator>DHerrmann</dc:creator>
    <dc:date>2023-05-05T17:30:13Z</dc:date>
    <item>
      <title>Managing the use of ephemeral Instant Messaging applications</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/57953#M823</link>
      <description>&lt;P&gt;Managing the use of ephemeral Instant Messaging applications (IM apps) for business communications is difficult:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IM apps can be considered as an information security risk for reasons like privacy, confidentiality or data retention in case of legal disputes.&lt;/P&gt;&lt;P&gt;On the other hand, in some regions IM apps have become the primary channel for conducting business and communicating with customers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How does your organization balance this?&lt;/P&gt;&lt;P&gt;Do you prohibit IM apps, do you define use cases or do you accept the risk?&lt;/P&gt;&lt;P&gt;Please choose your option and provide just 3 answers regarding your current practice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm interested in the use of ephemeral Instant Messengers which are not centrally managed by your own corporate IT, such as WhatsApp, Line, Hike or WeChat.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FORBID - My organization prohibits the use of IM apps in a business context&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Did you define strict policies against it&lt;/LI&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Yes&lt;/LI&gt;&lt;LI&gt;No&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Did you implement technology to prevent these apps from being installed or used&lt;/LI&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Yes&lt;/LI&gt;&lt;LI&gt;Not yet, but planning to&lt;/LI&gt;&lt;LI&gt;No&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Do you follow a COPE (Corporate Owned, Personally Enabled) mobile device strategy?&lt;/LI&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Yes&lt;/LI&gt;&lt;LI&gt;No&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DEFINE - My organization defines the use of IM apps in business context, allowing but a few justified exceptions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Did you define allowed use cases at policy level?&lt;/LI&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Yes&lt;/LI&gt;&lt;LI&gt;No&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Did you create an exception process?&lt;/LI&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Exceptions are approved by Corporate Board level&lt;/LI&gt;&lt;LI&gt;Exceptions are approved by other level of management&lt;/LI&gt;&lt;LI&gt;No&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Did you implement supporting technology (for e.g. central backups or monitoring)?&lt;/LI&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Yes&lt;/LI&gt;&lt;LI&gt;Not yet, but planning to&lt;/LI&gt;&lt;LI&gt;No&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACCEPT - My organization accepts the risks&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Did leadership accept the risk?&lt;/LI&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Risk accepted by Corporate Board level&lt;/LI&gt;&lt;LI&gt;Risk accepted by other level of management&lt;/LI&gt;&lt;LI&gt;No&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Did you implement supporting technology (for e.g. central backups or monitoring)?&lt;/LI&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Yes&lt;/LI&gt;&lt;LI&gt;Not yet, but planning to&lt;/LI&gt;&lt;LI&gt;No&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 22 Mar 2023 12:51:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/57953#M823</guid>
      <dc:creator>JungH</dc:creator>
      <dc:date>2023-03-22T12:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Managing the use of Instant Messaging applications</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/57954#M824</link>
      <description>&lt;P&gt;I'll start:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FORBID&lt;/P&gt;&lt;P&gt;1a&lt;/P&gt;&lt;P&gt;2b&lt;/P&gt;&lt;P&gt;3b&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 13:28:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/57954#M824</guid>
      <dc:creator>JungH</dc:creator>
      <dc:date>2023-03-21T13:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Managing the use of Instant Messaging applications</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/57959#M825</link>
      <description>&lt;P&gt;I suppose I'm going to say define your terms.&amp;nbsp; So you could argue for example that MS Teams has an IM function in it or that Slack is just an IM application.&amp;nbsp; What about Linkedin messaging?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 15:37:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/57959#M825</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2023-03-21T15:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Managing the use of Instant Messaging applications</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/58004#M826</link>
      <description>&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for pointing this out, I'll edit the first post accordingly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm interested in the use of ephemeral Instant Messengers which are not centrally managed by your own corporate IT, such as WhatsApp, Line, Hike or WeChat.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 12:50:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/58004#M826</guid>
      <dc:creator>JungH</dc:creator>
      <dc:date>2023-03-22T12:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Managing the use of Instant Messaging applications</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/58007#M827</link>
      <description>&lt;P&gt;Whilst we ban IMs like WhatsApp on corporate devices, our staff have personal mobiles and can set-up group within that platform themselves.&amp;nbsp; Generally, this then becomes a conduct matter in that non public topics should not be discussed in any potentially public fora.&amp;nbsp; It is the same principal as would apply to conversations in public places, allowing yourself to be shoulder surfed, using your mobile to discuss matters on a crowded train etc.&amp;nbsp; So often better to treat these are misconduct issues rather than try to impose technical controls on platforms that you do not control.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 14:28:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/58007#M827</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2023-03-22T14:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Managing the use of ephemeral Instant Messaging applications</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/58948#M865</link>
      <description>&lt;P&gt;Keep in mind that IM is restricted in various sectors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a story on a broker running afoul of FINRA's text messaging regulations:&amp;nbsp;&amp;nbsp;&lt;A href="https://www.smarsh.com/blog/thought-leadership/FINRA-increases-scrutiny-of-brokers-text-messages-for-business#:~:text=FINRA%20suspended%20a%20broker%20for,settlement%20finalized%20earlier%20this%20month" target="_blank"&gt;https://www.smarsh.com/blog/thought-leadership/FINRA-increases-scrutiny-of-brokers-text-messages-for-business#:~:text=FINRA%20suspended%20a%20broker%20for,settlement%20finalized%20earlier%20this%20month&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 17:30:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Managing-the-use-of-ephemeral-Instant-Messaging-applications/m-p/58948#M865</guid>
      <dc:creator>DHerrmann</dc:creator>
      <dc:date>2023-05-05T17:30:13Z</dc:date>
    </item>
  </channel>
</rss>

