The outsourcing of various information system functions by another
country outside of the U.S. can present some risks that an
unauthorized third party could gain access to customer’s information
because they might not have the same standards as the employing
company or country. Not every country has the same privacy
regulations. The offshore company might not train their employees in
correct handling of customer information. This could possibly become
an issue if decrypted data becomes visible during processing or while
the information is being displayed on computer screens. Furthermore,
there are also risks of failing security controls while sensitive
information is being transmitted. The use of VPNs, virtual private
networks, which use encryption and authentication as a means to
safely transfer information via the internet, can pose an issue.
Because firewalls, which a company uses for security reasons, cannot
analyze encrypted data. Some companies might choose to decrypt
the data before it passes through the firewall into the company’s
network, which could lead to a privacy breach (Romney et. al, 2020).
Though it has to be noted that these risks are also present if the
information system functions are outsourced within the U.S.
Companies are supposed to protect customer’s information from
unauthorized access and disclosure. The AICPA and CICA have
established the generally accepted privacy principles. Companies
have to create procedures and guidelines on the privacy protection of
their customer’s information and also the gathered information on
them through third parties. They also need to notify their customers
before these are being gathered so they can consent to the collection
and also the company’s privacy policies and procedures. The amount
of collection can only be to the extent necessary to fulfill the privacy
policies and not more. The information can only be disclosed to third
parties, who have to have the same standard of security measures if
the customer consents to this. Additionally, customer’s personal
information should only be used as described in the agreed upon
privacy policies and customers should always be able to access their
information and be able to edit these. The information needs to be
secured by the company, for example by encryption, and have to
ensure that all policies are being followed (Romney et. al, 2020).
References: