Intuitive Japanese Calligraphic Ideogram Intuitive Systems: Leadership for the 21st Century: online strategies and communications

The Business Blog at Intuitive.com

Dave Taylor
Dave Taylor has been involved with the online world since 1980 and is recognized globally as an expert on both technical and business issues. He has been published over a thousand times, launched four Internet-related startup companies, has written twenty business and technical books and holds both an MBA and MS Ed. He's a columnist for the Boulder Daily Camera and Linux Journal and frequently appears in other publications both online and in print. Additionally, Dave maintains four weblogs: The Business Blog at Intuitive.com, Ask Dave Taylor, Dave On Film, and GoFatherhood. Based in beautiful Boulder, Colorado, Dave is an award-winning speaker, sought after conference and workshop participant and frequent guest on radio and podcast programs, as well as active member of his community and busy single father to three children.

Data security and the CLEAR airport security card

As regular readers know, I wrote a blog post a week or so ago about applying for a CLEAR card [see Biometrics and my application for the CLEAR card] and in that writeup I had one big question: with all the biometric data collected, how does the company ensure that it's safe and secure?

I just got an update from CLEAR Vice President Mark Neirick addressing my security concerns. Here's what he says:


CLEAR recognizes that with the information provided by its members comes the expectation and trust that CLEAR will appropriately protect it. A key difference between the current system and that of the previous Verified Identity Pass system is that personal data is not distributed to remote systems such as kiosks or mobile systems.

CLEAR encrypts all data in transmission to ensure security in transit. CLEAR uses a variety of security protocols and procedures to secure the data collected including: AES 256, virtual private networks, SFTP, SSL, and TLS. In many cases these protocols and procedures are combined for even higher levels of protection.

Our secure data center uses extensive physical and logical security protections including access control, personnel screening, video surveillance, intrusion detection, and others. The data stored on the CLEARcard is encrypted with 2 separate security keys. The fingerprints and iris images collected are converted to templates prior to being stored on the CLEARcard. These templates can be used for positive matching against the original biometric but cannot be used to reverse engineer the source biometric.

Other than our technical security standards, tools, and procedures, the CLEAR privacy and security policies help ensure the integrity of the information we collect and protect. These policies include screening requirements for key employees and contractors, data management policies, and mandatory training all focused on ensuring the highest levels of protection for our member's data.


Is it sufficient? I will say that it's something that the company needs to address head on. Responses to my previous article about CLEAR demonstrate clearly that people are leery of trading their personal data - particularly biometric data -- against the convenience of passing through airport security more rapidly.

What do you think? Is this response from Mark sufficient to alleviate your anxieties in this regard?

Posted by Dave Taylor at November 8, 2011 3:41 PM

Comments
There are no comments on this article yet.
Insider's Guide to Blogging
Before you leave a comment, a tip: If you're interested in blogging, you should sign up for my Blogsmart News so you can stay up to date on the latest insider tips and ideas for your Internet business and marketing efforts. Sign up right now and you'll get a free copy of my "Insider's Guide to Blogging" ebook too!
 
Post a comment




Because I value your thoughtful opinions, I encourage you to add a comment to this discussion. Don't be offended if I edit your comments for clarity or to keep out questionable matters, however, and I may even delete off-topic comments.



RDF XML GeoURL Add to My Yahoo!

Valid CSS!