- Corporate Risk Analysis: Corporate legal practitioners have long experienced difficulty in matching the risk language of the law to the practices of business. Either the language and concepts of the law are viewed as esoteric 'legal issues' instead of important business concerns, or the risks are expressed in seemingly non-quantifiable forms such as "likely." The project would be to create a framework for one or both of those problems--one that would assist the lawyer in talking contract risk with the client in a way the client will appreciate. This project might either lend itself to a CLE presentation down the road, or an article at the magazine level (Business Law Today).
- Form Software Developer Agreement: It has been sometime (if ever?) since the Committee has issued a plain vanilla software development form agreement -- one which would have both a license element as well as a professional services element. An annotated agreement, which incorporates up-to-date thinking on some of the issues, and explores the negotiating points, would be helpful to many, particularly if it takes into account the diversity of client bases that this Committee's lawyers represent. Done well, with the right amount of substance, this would lend itself well to a book treatment combined with a CD Rom -- or may ultimately be part of a series of forms that this subcommittee and others in the CLC are working on (such as the form Web developer agreement being worked on by another subcommittee).
- Electronic Discovery Monographs: Most of the literature on electronic discovery is written to the litigators -- we feel that there is a lack of material written specifically with the in-house corporate counsel in mind. Rather than dealing with the lawsuit that has already happened, the in-house lawyer is in a better position to practice preventative medicine. Plus, when a problem occurs, the in-house lawyer who is savvy to electronic discovery issues can often provide valuable strategy to the outside lawyer who is less familiar with the company. We envision a series of 3-4 monographs -- 20 pagers or thereabout -- each talking about a particular slice of the e-discovery world. For example, we envision a monograph dedicated to the concept of litigation holds -- the practices that a company must undertake should litigation become likely. Such a monograph should discuss both preparations that might be done well before the problems arise, the costs that will need to be addressed, and how to institute a panic button should it become necessary. Since this project should lead to 3-4 related but different monographs, it lends itself to having a group of 3-4 drafters, each of whom could take an equal role in producing their own monograph, and together they would edit and produce a series of works. This might be publishable as a small book, or could be a candidate for an electronic distribution such as an e-book?
- Information Technology Danger Points in Divestitures: While there is no lack of generalized checklists that M&A practitioners might use in their deals, many of those checklists miss some of the IT-specific tricky points and how to resolve them. For example, if a divested subsidiary is the holder of a patent that is being used by the parent, how should the problems be raised, analyzed, negotiated and resolved? This should not be an attempt to re-write those things that have already been written, but rather it should concentrate on those things that are specific to our member's daily practices, distilling some of those things that we have saved our corporate colleagues from tripping on. A magazine article treatment is probably the best initial treatment for this.
Saturday, April 02, 2005
CAIT Subcommittee Meeting
Don Cohn and Michael Fleming chaired the meeting of the Corporate Aspects of Information Technology subcommittee. The group discussed the upcoming projects for the Spam and Unsolicited Electronic Marketing Working Group, and then began solicitations for new projects. At this point, the group is primarily looking for members who are interested in using one of the following ideas as a springboard for a project, and asks that if you would be interested in taking on leadership of any such project that you get in touch with either Don (donald.a.cohn (a) usa.dupont.com) or Michael (michael.f.fleming (a) gmail.com).
Friday, April 01, 2005
Meanwhile, Back on the Official Site
Props to Jim Frey and his co-horts at the ABA, who have done an outstanding job of putting the Spring Meeting schedule online.
So what you say? That's been done for years, right?
Not so fast, pardner. Look here at the interactive version. The schedule is now organized so you can look up by date, by Committee, or just limited to CLE programs. As you page through the programs, you can find full descriptions and the like, as well as links to the PDF files with the written materials where appropriate.
Best of all -- the thing is now updated in (essentially) real time. The paper slips with the changes to the meetings? No longer needed (although they continue to be posted). You can always check in and see what's next, and if the meeting has been changed, you'll see it online. There's even a section for cancelled meetings, which is updated as news arrives during the meeting.
What's next? I suggest the guys get to work on MYABAMEETING.com -- No longer will I need to transpose the sessions I want to attend from a paper book over to my computer calendar -- I'd like it to help me put together an itinerary for my days at the meeting (pointing out conflicts and the like), and then once I've figured it out, I could upload it all to my computer's calendar and/or phone and/or whatever. And, of course, if any changes occur in my chosen meetings, the thing would buzz my phone to let me know.
(I can dream, can't I?)
In the meantime, outstanding work guys and gals at the Association! Thanks!
So what you say? That's been done for years, right?
Not so fast, pardner. Look here at the interactive version. The schedule is now organized so you can look up by date, by Committee, or just limited to CLE programs. As you page through the programs, you can find full descriptions and the like, as well as links to the PDF files with the written materials where appropriate.
Best of all -- the thing is now updated in (essentially) real time. The paper slips with the changes to the meetings? No longer needed (although they continue to be posted). You can always check in and see what's next, and if the meeting has been changed, you'll see it online. There's even a section for cancelled meetings, which is updated as news arrives during the meeting.
What's next? I suggest the guys get to work on MYABAMEETING.com -- No longer will I need to transpose the sessions I want to attend from a paper book over to my computer calendar -- I'd like it to help me put together an itinerary for my days at the meeting (pointing out conflicts and the like), and then once I've figured it out, I could upload it all to my computer's calendar and/or phone and/or whatever. And, of course, if any changes occur in my chosen meetings, the thing would buzz my phone to let me know.
(I can dream, can't I?)
In the meantime, outstanding work guys and gals at the Association! Thanks!
Google Ups Storage Limits
Wow! Google increased storage limits for GMAIL to something they're calling infinity+1. Check it out.
The Well Turns 20
The Committee's friend Declan McCullagh posts an article on CNET today about the 20th Birthday of The Well. For those of you who aren't familiar with the Well, it was a very influential and very early force in the growth and development of the thing we all know of as the Internet.
Check out the story on CNET and an interesting account about the creation of the Well on the Well itself.
Check out the story on CNET and an interesting account about the creation of the Well on the Well itself.
Wildhorse Saloon
News of the World
(from Mike McGuire, reporting remotely from Minnesota, these stories in Steptoe & Johnson's E-Commerce Law Week, March 26, 2005)
Dear Feds, Send Money or the IT Infrastructure Could Get It
They say money makes the world go 'round . . . And now a group of experts are warning that without a serious cash infusion, the nation's information technology (IT) infrastructure world is at grave risk of being knocked off its axis by a terrorist or criminal attack. In a report entitled, "Cyber Security: A Crisis of Prioritization," the President’s Information Technology Advisory Committee (PITAC) -- an advisory body of IT leaders in academia and industry -- argues that the IT infrastructure of the US is "highly vulnerable to terrorist and criminal attacks." The report, made public on March 18, calls for a drastically increased federal role in supporting the development of new cybersecurity technologies. PITAC warns that short-term solutions to infrastructure vulnerability, like patching or retrofitting software, are inadequate and that only a massive deployment of money and manpower can successfully address the "large structural insecurities" of the nation's IT infrastructure. We've heard such dire warnings before, however, to little discernable effect. But perhaps the current spotlight on identity theft and data security breaches will lend some heft to the argument that the security of the nation's cyber infrastructure deserves at least as much attention as the data it carries.
Bank Regulators Beat Congress to the Punch on Security Breach Notifications
With all the Congressional activity on data security and identity theft these days, it's easy to forget that threats of new legislation are only half the story. In some industries, federal regulators are already setting guidelines for when companies should disclose security breaches. For example, the four federal financial industry regulators have issued "Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice" to instruct financial institutions on when they will be expected to report security breaches of "sensitive customer information" -- whether that information is stored electronically or in paper form. The federal regulators will view a financial institution's failure to comply with the guidance as an unsafe and unsound information security practice.
Dear Feds, Send Money or the IT Infrastructure Could Get It
They say money makes the world go 'round . . . And now a group of experts are warning that without a serious cash infusion, the nation's information technology (IT) infrastructure world is at grave risk of being knocked off its axis by a terrorist or criminal attack. In a report entitled, "Cyber Security: A Crisis of Prioritization," the President’s Information Technology Advisory Committee (PITAC) -- an advisory body of IT leaders in academia and industry -- argues that the IT infrastructure of the US is "highly vulnerable to terrorist and criminal attacks." The report, made public on March 18, calls for a drastically increased federal role in supporting the development of new cybersecurity technologies. PITAC warns that short-term solutions to infrastructure vulnerability, like patching or retrofitting software, are inadequate and that only a massive deployment of money and manpower can successfully address the "large structural insecurities" of the nation's IT infrastructure. We've heard such dire warnings before, however, to little discernable effect. But perhaps the current spotlight on identity theft and data security breaches will lend some heft to the argument that the security of the nation's cyber infrastructure deserves at least as much attention as the data it carries.
Bank Regulators Beat Congress to the Punch on Security Breach Notifications
With all the Congressional activity on data security and identity theft these days, it's easy to forget that threats of new legislation are only half the story. In some industries, federal regulators are already setting guidelines for when companies should disclose security breaches. For example, the four federal financial industry regulators have issued "Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice" to instruct financial institutions on when they will be expected to report security breaches of "sensitive customer information" -- whether that information is stored electronically or in paper form. The federal regulators will view a financial institution's failure to comply with the guidance as an unsafe and unsound information security practice.
Cyberspace CLE Program: Strategies for Modifying Electronic Agreements and Policies
Program: Strategies for Modifying Electronic Agreements and Policies 

(Please forgive the lousy photography...)
Kathy Porter, Chris Kunz, Jason Epstein (A new daddy as of about 36 hours ago! Twice Over!), Kristie Prinz, and Andrew Serwin presented the results of their research (ABA membership required) on how electronic contracts have been (purportedly) modified by various Web site providers.


(Please forgive the lousy photography...)
Kathy Porter, Chris Kunz, Jason Epstein (A new daddy as of about 36 hours ago! Twice Over!), Kristie Prinz, and Andrew Serwin presented the results of their research (ABA membership required) on how electronic contracts have been (purportedly) modified by various Web site providers.
Transferability of Electronic Assets
The Working Group on Transferability of Electronic Assets meeting on Friday morning. 

Mattias Hallendorff and Prof. Linda Rusch (both here from the Twin Cities, continuing the tradition of making sure that any law that actually makes a difference in Cyberspace actually comes out of Minnesota or passes through it...), are continuing the group's thoughts discussed in Palo Alto -- How can we actually create a working and functional system of Electronic Chattel Paper (ECP) that is contemplated under New Article 9 at Section 9-105?
Continuing a collaboration that initiated in Palo Alto with the technology experts at The Open Group, the WG has worked together with the technologists to try to work towards some recommendations. In particular, Mike Jerbic, Chair of The Open Group's Security Forum, has undertaken to work closely with the Working Group. His beat -- data security -- has particular relevance to ECP and its need for (relatively?) unassailable records.
Mike gave an early version of a slide presentation, where he began the effort to get the two worlds talking together. He noted that the tech world has largely concentrated on a concept they term as "command" -- which is fundamentally at odds with the UCC's requirement of "control." Command presumes that if we tell the system to do something, it's actually going to go ahead and do it. Control is not going to be happy with just assuming -- it needs to know that the machine did what it was ordered to do, a concept that is surprisingly foreign to current technology systems. Today, most technology systems rely more on redundancy and other similar concepts of just throwing the kitchen sink at everything to make sure the 'command' gets followed, which makes good sense where bandwidth and storage are cheap. But, for 'control' in the ECP world, the thought is that it needs to be done only once, and that one shot needs to be on target.
There was a lively debate over how to move the lawyers, the bankers, and the technologists to getting off the ball -- or if they should be moved. Prof. Ken Kettering raised a general theme of how the statute is unwilling to take a stand on HOW to get control. While he noted that there may be any number of technology answers that seemingly meet the requirements of the statute, the thousand bishops who might be willing to swear to its leading to control will not necessarily lead to an unassailable legal conclusion of control. He thinks we are being somewhat over-optimistic that any one of our systems will make the jump from good tech to good law.
Others still feel that the issue is not one of black and white, but trying to decide where the financial markets are going to be comfortable with the final system's degree of greyness. There are clear pressures to move this idea forward coming from the finance industries -- and this might push us to the point where we need to do it anyway. The 'pro' group's opinion could be summarized by John Gregory's thought that we need to compare this to the systems we've used in the past, and how we ultimately need to reach some degree of 'comfort' in whether that paper signature means something. The electronic world needs to figure out when the industry will get comfortable -- either for an agency to rate a deal, or for a law firm to offer an opinion.
Dina Moskowitz, Assistant General Counsel at Standard & Poor's (who will be lecturing -- guess where? -- Minnesota this coming month!), noted that law firms offering these opinions will be expected to have SOME degree of ability to do technical due dilligence. The opinion cannot rely on the raw assurances of the vendors. However, there is not going to be an expectation that law firms will become System Analysts -- the use of a good technology framework of analysis, combined with a level of technology understanding, should probably be an adequate basis for a meaningful opinion of counsel.
And, it is that framework that the Working Group is working to create.


Mattias Hallendorff and Prof. Linda Rusch (both here from the Twin Cities, continuing the tradition of making sure that any law that actually makes a difference in Cyberspace actually comes out of Minnesota or passes through it...), are continuing the group's thoughts discussed in Palo Alto -- How can we actually create a working and functional system of Electronic Chattel Paper (ECP) that is contemplated under New Article 9 at Section 9-105?
Continuing a collaboration that initiated in Palo Alto with the technology experts at The Open Group, the WG has worked together with the technologists to try to work towards some recommendations. In particular, Mike Jerbic, Chair of The Open Group's Security Forum, has undertaken to work closely with the Working Group. His beat -- data security -- has particular relevance to ECP and its need for (relatively?) unassailable records.
Mike gave an early version of a slide presentation, where he began the effort to get the two worlds talking together. He noted that the tech world has largely concentrated on a concept they term as "command" -- which is fundamentally at odds with the UCC's requirement of "control." Command presumes that if we tell the system to do something, it's actually going to go ahead and do it. Control is not going to be happy with just assuming -- it needs to know that the machine did what it was ordered to do, a concept that is surprisingly foreign to current technology systems. Today, most technology systems rely more on redundancy and other similar concepts of just throwing the kitchen sink at everything to make sure the 'command' gets followed, which makes good sense where bandwidth and storage are cheap. But, for 'control' in the ECP world, the thought is that it needs to be done only once, and that one shot needs to be on target.
There was a lively debate over how to move the lawyers, the bankers, and the technologists to getting off the ball -- or if they should be moved. Prof. Ken Kettering raised a general theme of how the statute is unwilling to take a stand on HOW to get control. While he noted that there may be any number of technology answers that seemingly meet the requirements of the statute, the thousand bishops who might be willing to swear to its leading to control will not necessarily lead to an unassailable legal conclusion of control. He thinks we are being somewhat over-optimistic that any one of our systems will make the jump from good tech to good law.
Others still feel that the issue is not one of black and white, but trying to decide where the financial markets are going to be comfortable with the final system's degree of greyness. There are clear pressures to move this idea forward coming from the finance industries -- and this might push us to the point where we need to do it anyway. The 'pro' group's opinion could be summarized by John Gregory's thought that we need to compare this to the systems we've used in the past, and how we ultimately need to reach some degree of 'comfort' in whether that paper signature means something. The electronic world needs to figure out when the industry will get comfortable -- either for an agency to rate a deal, or for a law firm to offer an opinion.
Dina Moskowitz, Assistant General Counsel at Standard & Poor's (who will be lecturing -- guess where? -- Minnesota this coming month!), noted that law firms offering these opinions will be expected to have SOME degree of ability to do technical due dilligence. The opinion cannot rely on the raw assurances of the vendors. However, there is not going to be an expectation that law firms will become System Analysts -- the use of a good technology framework of analysis, combined with a level of technology understanding, should probably be an adequate basis for a meaningful opinion of counsel.
And, it is that framework that the Working Group is working to create.
Life of a Prepaid Card presentation
The Committee Forum, this Spring on speaking on Prepaid Card issues. 

Too much great material for me to blog, but I can link you to the materials here. (ABA membership required)


Too much great material for me to blog, but I can link you to the materials here. (ABA membership required)
Subscribe to:
Posts (Atom)