Over the weekend a former employee of ours got
into our servers, copied files and made some small modifications, nothing
major just nuisance stuff - but enough to piss me off.
Today after gathering all the log file data i
decided to ring the police.
What the Computer Crimes Section told me was a
bit of an eye opener;
Former staff members are allowed back inside your
servers and are able to copy and modify information at will - because they
were once allowed to.
The only way they can be charged criminally is if
they gain access to your system via another means other than a known username
and password (it doesnt even matter if it wasnt their username and password -
any will do).
The only way other than changing every password
on your system is to have a watertight employment contract, advising them
that they have no access rights to your system after their period of
employment ends, this contract must also outline the ownership of the
intellectual property they create whilst employed - this must be signed
by both parties. If they gain access to the system outside of their
employment then its a criminal act.
We didnt have this in place, and our contract was
full of wholes when dealing with the ownership of the code he created for
us.
We can of course go after him via civil action -
but he hasnt got anything, so it would be a waste of time - i would have much
preffered a criminal conviction.
A bitter lesson learned
Does anyone have a contract of this nature that
they would like to share?
Steve Soars
www.i-redlands.net
Interactive Redlands
Shop 2 Cleveland Town Square
Cnr
Queen & Bloomfield Sts
Cleveland QLD 4163
[p] 07 3821-5800
[f] 07
3821-5811
"what we do in
life
echoes an eternity"
---
You are currently subscribed to cfaussie as:
[EMAIL PROTECTED]
To unsubscribe send a blank email to
[EMAIL PROTECTED]
MX Downunder AsiaPac DevCon -
http://mxdu.com/
---