Resources and news on illegal downloads

Opinion
Oct 26, 20042 mins

* Internet resources covering illegal downloads and acceptable-use policies

A reader recently asked about legal liability of managers in a corporation where users are downloading copyrighted music using peer-to-peer networks without permission of the copyright holders. She asked who would investigate such breaches of the law and whether the presence of an acceptable-use policy would affect the outcome of possible prosecutions.

As I understand the situation, failure to exercise due diligence in establishing, monitoring and enforcing effective security policies governing acceptable use of copyrighted materials can lead to serious problems. Managers as well as employees may be accused of trafficking in stolen intellectual property and face lawsuits and fines.

An article by Vanessa Blum in the _Legal Times_ summarized the state of prosecutions for Internet piracy in June: https://tinyurl.com/5vbgj

She reported that the U.S. Attorney General had formed a task force to attack piracy of intellectual property. Discussions included possible increases in the frequency of criminal prosecutions and the use of civil lawsuits similar to those of the Recording Industry Association of America (RIAA).

In Europe, the equivalent of the RIAA, the International Federation of the Phonographic Industry (IFPI) filed lawsuits against 247 people, mostly large-scale abusers, in March: https://tinyurl.com/44kk2

In Australia, “five disc jockeys, a record store and its director” were ordered to pay $140,000 (Australian) to the legal owners of music which they had pirated (cited in a posting by “ThailandDJ” on a discussion board at https://tinyurl.com/43jow).

For good background reading on security policies in general, see the resources at the SANS Security Policy Project and its AUP in particular:

SANS

https://www.sans.org/resources/policies/

Acceptable Use Policy (PDF)

https://www.sans.org/resources/policies/Acceptable_Use_Policy.pdf

Acceptable Use Policy (DOC)

https://www.sans.org/resources/policies/Acceptable_Use_Policy.doc

If you are developing security policies, do invest in Charles Cresson Woods’ _Information Security Policies Made Easy_, which is now in its 10th edition: https://www.informationshield.com/ispmemain.htm

See also the “Guide to Internet Usage and Policy” from ZIXcorp and “How to write an Acceptable Use Policy (AUP)” from SurfControl:

ZIXcorp guide

https://www.webspy.com/files/articles/iauguide.pdf

SurfControl guide

https://www.surfcontrol.com/general/assets/whitepapers/AUP_Booklet_10011_uk.pdf