73
Putting Your Practice on Cloud 9

Putting your practice on cloud 9

Embed Size (px)

Citation preview

Page 1: Putting your practice on cloud 9

Putting Your Practice on Cloud 9

Page 2: Putting your practice on cloud 9

2

Cloud  Compu*ng

So.ware-­‐as-­‐a-­‐Service

Web Application

ASP

Page 3: Putting your practice on cloud 9

3

Page 4: Putting your practice on cloud 9

4

Page 5: Putting your practice on cloud 9

5

Page 6: Putting your practice on cloud 9

tradi*onal  compu*ng  model

The  Internet Local  Area  Network

Page 7: Putting your practice on cloud 9

so.ware-­‐as-­‐a-­‐service  model

The  Internet Local  Area  Network

Page 8: Putting your practice on cloud 9

typical  small  law  office

Page 9: Putting your practice on cloud 9

tradi/onal  so1ware  distribu*on

Page 10: Putting your practice on cloud 9

cloud  compu/ng

Page 11: Putting your practice on cloud 9

whycloud computing?

Page 12: Putting your practice on cloud 9

You need to delivera better experience to your clients

Page 13: Putting your practice on cloud 9

13

We’re screwed.

Page 14: Putting your practice on cloud 9

14

There is a profound message here for lawyers—when thinking IT and the Internet, the challenge is not to automate current working practices that are not efficient. The challenge is to innovate, to practice law in ways that we could not have done in the past.

Page 15: Putting your practice on cloud 9
Page 16: Putting your practice on cloud 9
Page 17: Putting your practice on cloud 9

It’s not just what you sell

It’s how you sell it

47%53%

Page 18: Putting your practice on cloud 9

Deliver a cloud experience to your clients

Page 19: Putting your practice on cloud 9

inno

vato

rs 2

.5%

early

ado

pter

s 13.

5%

early

maj

ority

34%

late

maj

ority

34%

lagg

ards

16%

Page 20: Putting your practice on cloud 9
Page 21: Putting your practice on cloud 9

21

up  and  running  fast

Page 22: Putting your practice on cloud 9

22

save  money

Page 23: Putting your practice on cloud 9

23

cash  flow

Page 24: Putting your practice on cloud 9
Page 25: Putting your practice on cloud 9

ethics of cloud computing

Page 26: Putting your practice on cloud 9

North  Carolina  State  Bar  Ethics  Inquiry

•2011  FEO  6  "Subscribing  to  So.ware  as  a  Service  While  Fulfilling  Confiden*ality  and  Preserva*on  of  Client  Property"

•First  ethics  opinion  in  North  America  specifically  focused  on  use  of  cloud  compu*ng  in  a  law  firm

Page 27: Putting your practice on cloud 9

Inquiry  #1

Is  it  within  the  Rules  of  Professional  Conduct  for  an  attorney/law  7irm  to  use  online  ("cloud  computing")  

practice  management  programs  (e.g.,  the  Clio  program)  as  part  of  the  practice  of  law?    These  are  instances  where  the  software  program  is  accessed  online  with  a  password  and  is  not  software  installed  on  a  computer  within  the  

5irm's  of5ice.

Page 28: Putting your practice on cloud 9

North  Carolina  Proposed  Formal  Ethics  Opinion

Yes,  provided  steps  are  taken  effectively  to  minimize  the  risk  of  inadvertent  or  unauthorized  disclosure  of  con5idential  client  

information  and  to  protect  client  property,  including  5ile  information,  from  risk  of  loss.

Page 29: Putting your practice on cloud 9

Other  States  Following  Suit• Pennsylvania  Formal  Opinion  2011-­‐200

• California  Formal  Opinion  No.  2010-­‐179

• Alabama  State  Bar  Ethics  Opinion  2010-­‐02

• Arizona  State  Bar  Formal  Opinion  09-­‐04

• Nevada  State  Bar  Formal  Opinion  No.  33

• New  York  State  Bar  Associa*on  Opinion  842  of  2010

• Iowa  Op.  11-­‐01

• Oregon  Formal  Op.  2011-­‐188

• Vermont  Advisory  Ethics  Op.  2010-­‐6

• Massachuse[s  MBA  Ethics  Opinion  12-­‐03  

29

Page 30: Putting your practice on cloud 9

ABA  20/20  Ethics  Commission

•Examining  how  a  lawyer’s  ethical  responsibili*es  apply  to  cloud  compu*ng

•Recommenda*ons  adopted  in  August  2012

30

Page 31: Putting your practice on cloud 9

ABA  20/20  Ethics  Commission

•The  development  of  a  centralized,  user-­‐friendly  website  that  contains  con*nuously  updated  and  detailed  informa*on  about  confiden*ality-­‐related  ethics  issues  arising  from  lawyer’s  use  of  technology,  including  the  latest  data  security  standards.

•Amendments  to  several  Model  Rules  of  Professional  Conduct  and  their  Comments  to  offer  specific  guidance  and  expecta*ons  rela*ng  to  technology.

31

Page 32: Putting your practice on cloud 9

ABA  20/20  Ethics  Commission

32

The  Commission  concluded  that  competent  lawyers  must  have  some  awareness  of  basic  features  of  technology.  To  make  this  point,  the  Commission  is  recommending  an  amendment  to  Comment  [6]  of  Model  Rule  1.1  (Competence)  that  would  emphasize  that,  in  order  to  stay  abreast  

of  changes  in  the  law  and  its  practice,  lawyers  need  to  have  a  basic  understanding  of  technology’s  bene5its  and  risks.

Page 33: Putting your practice on cloud 9

ABA  20/20  Ethics  Commission

33

Proposed  new  Model  Rule  1.6(c)  would  make  clear  that  a  lawyer  has  an  ethical  duty  to  take  reasonable  measures  to  protect  a  client’s  con7idential  information  from  inadvertent  disclosure  and  

unauthorized  access.  This  duty  is  already  implicit  in  Model  Rule  1.6  and  is  described  in  several  existing  comments,  but  the  Commission  concluded  that,  in  light  of  the  pervasive  use  of  technology  to  store  and  transmit  con5idential  client  information,  this  obligation  should  be  stated  explicitly  in  the  black  

letter  of  Model  Rule  1.6.

Page 34: Putting your practice on cloud 9

ABA  Model  Rules  of  Professional  Conduct

34

“ When transmitting a communication that includesinformation relating to the representation of a client, thelawyer must take reasonable precautions to prevent theinformation from coming into the hands of unintendedrecipients. This duty, however, does not require that thelawyer use special security measures if the method ofcommunication affords a reasonable expectation ofprivacy.” (Emphasis added)Comment 17, Rule 1.6

Page 35: Putting your practice on cloud 9

security of cloud computing

Page 36: Putting your practice on cloud 9

36

Security

Encryption

Data Privacy

Data Availability

Terms of Service

Page 37: Putting your practice on cloud 9

encryption

Page 38: Putting your practice on cloud 9

terminology

•Secure  Sockets  Layer  (SSL)ØIndustry  standard  protocol  for  securing  Internet  communica*ons

ØBanks,  e-­‐commerce  sites  (Amazon.com,  etc.)  all  use  SSL  for  secure  communica*ons

Page 39: Putting your practice on cloud 9

without  ssl

Informa*on  exchanged  is  insecure

Please  give  me  my  bank  account  balance

$2,031.34

Your  Computer Your  Bank’s  Server

Page 40: Putting your practice on cloud 9

with  ssl

11010001110

01101010001010110101010100101010

Your  Computer Your  Bank’s  Server

Informa*on  exchanged  is  encrypted  for  security

Page 41: Putting your practice on cloud 9

Firefox:

A  sealed  lock  icon  indicates  a  secure  connec*on

Internet  Explorer:

verifying  ssl  connec*ons

Safari:

Page 42: Putting your practice on cloud 9
Page 43: Putting your practice on cloud 9

server  security

Are  third-­‐party  audits  being  performed?

Page 44: Putting your practice on cloud 9

server  security

Page 45: Putting your practice on cloud 9

server  security

Page 46: Putting your practice on cloud 9

endpoint  security

Page 47: Putting your practice on cloud 9

HIPAA

47

Page 48: Putting your practice on cloud 9

password  security

[email protected]

passwordsmithlaw07121954

Page 49: Putting your practice on cloud 9

49

Page 50: Putting your practice on cloud 9

50

Page 51: Putting your practice on cloud 9

privacy

Page 52: Putting your practice on cloud 9

privacy

•Does  the  SaaS  provider  have  a  published  privacy  policy?•Need  to  ensure  you  own  your  data•The  private  client  informa*on  stored  with  your  SaaS  provider  cannot  be  used  for  any  other  purposes

Page 53: Putting your practice on cloud 9

facebook  privacy  policy You hereby grant Facebook an irrevocable, perpetual, non-exclusive, transferable, fully paid,

worldwide license (with the right to sublicense) to (a) use, copy, publish, stream, store,

retain, publicly perform or display, transmit, scan, reformat, modify, edit, frame,

translate, excerpt, adapt, create derivative works and distribute (through multiple tiers),

any User Content you (i) Post on or in connection with the Facebook Service or the promotion

thereof subject only to your privacy settings.

You may remove your User Content from the Site at any time. If you choose to remove your User

Content, the license granted above will automatically expire, however you acknowledge that

the Company may retain archived copies of your User Content.

Page 54: Putting your practice on cloud 9

How  is  sensi*ve  informa*on  being  handled?

TRUSTe

“TRUSTe’s   program   requirements   are   based   upon   the   Fair  

Informa*on   Principles   and   OCED   Guidelines   around   no*ce,  

choice,   access,   security,   and   redress   -­‐   the   core   founda*ons   of  

privacy  and  building  trust.    Sealholders  are  required  to  undergo  a  

rigorous   review   process   to   assess   the   accuracy   of   privacy  

disclosures  and  compliance  with  TRUSTe’s  requirements  in  order  

to  obtain  cer*fica*on.”

Page 55: Putting your practice on cloud 9

data availability

Page 56: Putting your practice on cloud 9

56

Page 57: Putting your practice on cloud 9

57

Page 58: Putting your practice on cloud 9

58

Page 59: Putting your practice on cloud 9

59

Page 60: Putting your practice on cloud 9

Data  Loca/on

•Where  is  main  data  center(s)•Is  data  backed  up  to  mul*ple  offsite  loca*ons?

Page 61: Putting your practice on cloud 9

external  backup  provisions

•Can  you  perform  an  export  of  your  data?

Comma  Separated  Values  (CSV)

Extensible  Markup  Language  (XML)

Microso1  Excel  (XLS)

Page 62: Putting your practice on cloud 9

business  con*nuity

What  if  the  SaaS  provider  goes  out  of  business?

Page 63: Putting your practice on cloud 9

op*on  1:  data  export

Cross  your  fingers  and  hope  you’re  up  to  date…

Comma  Separated  Values  (CSV)

Extensible  Markup  Language  (XML)

Microso1  Excel  (XLS)

Page 64: Putting your practice on cloud 9

If  it  isn’t  automated  you’ll  forget  to  do  it

Page 65: Putting your practice on cloud 9

op*on  2:  data  escrow

saas  provider escrow  provider

saas  user

Page 66: Putting your practice on cloud 9

terms of service /service level agreement

Page 67: Putting your practice on cloud 9

terms  of  service

•Easily  accessible,  published  ToS?•Outlines  the  condi*ons  under  which  you  agree  to  use  the  service  

•Ensure  you’ve  reviewed  and  accepted  your  provider’s  terms  of  service

Page 68: Putting your practice on cloud 9

service  level  agreement

•SLA•Outlines  guaranteed  up*me  percentages•E.g.  99.9%•Usually  providers  for  some  kind  of  compensa*on  if  down*me  exceeds  SLA  guarantee

Page 69: Putting your practice on cloud 9

data center security

Page 70: Putting your practice on cloud 9

70

Page 71: Putting your practice on cloud 9

71

Page 72: Putting your practice on cloud 9

72

Page 73: Putting your practice on cloud 9

Thank You