Risks of employee use of RSS
Mike Gotta has a short list of some risks to confidentiality that employee use of RSS (and social bookmarking sites) can develop:
- If these sites (Bloglines, NewsGator Line, del.icio.us and such) are being frequented often by employees, that could be an leading indicator that business and IT workers might benefit from these tools internally. An organization might want to look at Attensa, Kn0wNow or NewsGator and implement a managed solution rather than depend on consumer-oriented sites.
- From a security and risk perspective, organizations might want to consider including a statement within their policies and procedures regarding use of such systems. Security teams may have valid concerns about how such systems increase the surface area exposed by an enterprise to attack.
- Even if the security aspect is deemed to be low, policy makers might also be worried about confidentiality issues if such consumer systems were hacked and subscription information was disclosed to the public. It might be interesting or embarrassing to find out what the employees of a particular organization are reading and bookmarking.
- User generated meta-data used to tag information may disclose project names or other insight to an organization that might aid external parties from a competitive intelligence perspective or for purposes of planning an attack.

