Information Security and Common Sense Richard Henson University of Worcester November 2008.

Slides:



Advertisements
Similar presentations
Information Security and Common Sense Richard Henson University of Worcester October 2008.
Advertisements

Copyright © 2012, Big I Advantage®, Inc., and Swiss Re Corporate Solutions. All rights reserved. (Ed. 08/12 -1) E&O RISK MANAGEMENT: MEETING THE CHALLENGE.
Drive in Rain.
Emotions and Driving Emotions affect our every thought and action. We are not able to separate ourselves from our emotional state. We drive as we are.
ADMINISTRATION REVISION – BLOCK 2 HEALTH AND SAFETY.
Implications and Security Issues of the Internet By Neelesh Patel.
District 1220 Assembly 2006 Health and Safety HEALTH AND SAFETY For Rotary District 1220 and its Member Clubs.
The Health and safety Act, is an act to make further provision for securing the health and safety and welfare of persons at work.For protecting others.
Copyright © 2014 Merck Sharp & Dohme Corp., a subsidiary of Merck & Co., Inc. All rights reserved. In practice, how do we recognize a potential Privacy.
PRIVACY COMPLIANCE An Introduction to Privacy Privacy Training.
CLOSE TO AUSTRIA “Young drivers who are confronted with stories of severe road accidents presented by people of the same age are less likely to engage.
1 Enterprise Security Your Information Security and Privacy Responsibilities © 2008 Providence Health & Services This information may be replicated for.
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
CLOSE TO AUSTRIA Risk Prevention for beginning Drivers “Young drivers who are confronted with stories of severe road accidents presented by people of the.
Computer Viruses. Where the name came from This is a phrase coined from biology to describe a piece of software that behaves very much like a real virus.
Backing up data By Alicia stewart.
Health and Safety.
BUSINESS CONTINUITY PLANNING FOR SMALL TO MEDIUM ENTERPRISES Presented and written by Jamie Whitford-Robson Corporate Business Continuity Lead.
New Data Regulation Law 201 CMR TJX Video.
Occupational health and safety
Information Security Decision- Making Tool What kind of data do I have and how do I protect it appropriately? Continue Information Security decision making.
Why Improve Road Transport Enforcement in Europe? Ellen Townsend European Transport Safety Council.
Law Additional Exercise ANSWERS. Question #1 (a) Any one of: gain unauthorised access (1st) to computer material (1) gain (unauthorised) access to computer.
INFO1 – Practical problem solving in the digital world
Cloud Computing Characteristics A service provided by large internet-based specialised data centres that offers storage, processing and computer resources.
Imapact of I.T on International Commerce: Management of transnational corporations and Business Concentrations.
PRIVACY, SECURITY & ID THEFT PREVENTION - TIPS FOR THE VIGILANT BUSINESS - SMALL BUSINESS & ECONOMIC DEVELOPMENT FORUM October 21, WITH THANKS TO.
Data Protection STFC Presentation to PPD Senior Staff 26/11/2009 FoI/DP team.
The Global Road Safety Partnership is hosted by Work Related Road Safety Ken Shaw – Global Road Safety Partnership Department of Disaster Prevention and.
Data Security Project PROJECT WRAP-UP Timeline – July 2011 through December 2012 Project Charge – Compile resources and best practices for the proper handling.
Computer Security! Emma Campbell, 8K VirusesHackingBackups.
DIRECT WORKS FORUM 10 June 2008 Andy Ballard. COMMON LAW MANSLAUGHTER Effectively – Death by gross negligence Test – (a) was a (common law) duty of care.
Viruses Hackers Backups Stuxnet Portfolio Computer viruses are small programs or scripts that can negatively affect the health of your computer. A.
The health and safety act was introduced to protect the welfare of people of the workplace. Before being introduced in 1974 it was estimated that 8.
SECURITY OF DATA By: ADRIAN PERHAM. Issues of privacy; Threats to IT systems; Data integrity; Standard clerical procedures; Security measures taken to.
COMP1321 Digital Infrastructure Richard Henson University of Worcester December 2012.
Presented by Simon Protano FinstSMM DSA ADI National Business Manager 3 rd April 2007 IOSH Merseyside Branch Presentation to Driving on Company Business.
James McQuillen. Data protection Act 1998 The main aim of it is to protect people's fundamental rights and freedom to a particular right to privacy of.
COMP3371 Cyber Security Richard Henson University of Worcester September 2015.
IT Security Policy: Case Study March 2008 Copyright , All Rights Reserved.
GOLD UNIT 4 - IT SECURITY FOR USERS (2 CREDITS) Bailey Ryan.
Anika Massey.  There are three main types of business:  Traditional  Online  Transportation.
Objectives  Legislation:  Understand that implementation of legislation will impact on procedures within an organisation.  Describe.
ICT Legislation  Copyright, Designs and Patents Act (1988);  Computer Misuse Act (1990);  Health and Safety at Work Act (1974);  EU Health and Safety.
Operational Issues. Operational Changes It is important to organisations to ensure that they abide by the Law when caring for the safety of their employees,
Information Security January What is Information Security?  Information Security is about the physical security of our equipment and networks as.
FEELING SAFE TRAVELLING AROUND. Welcome & Introductions.
Objectives By the end of this presentation you will know: What risk assessment is; Where the need for risk assessment comes from; and The principles behind.
D5 Health and safety. Fleet Operator Recognition Scheme (FORS) FORS is important to our company because.
Safe Speed presents... Driver quality - The essential foundation of all road safety.
Cell Phones and Driving
Welcome to the ICT Department Unit 3_5 Security Policies.
Handling Personal Data & Security of Information Paula Trim, Information Officer, Children’s Strategic Services, Mon – Thurs 9:15-2:15.
Pioneers in secure data storage devices. Users have become more accustomed to using multiple devices, are increasingly mobile, and are now used to storing.
USB flash drive A flash drive consists of a small printed circuit board carrying the circuit elements and a USB connector, insulated electrically and protected.
COMP3357 Managing Cyber Risk
Richard Henson University of Worcester February 2017
Handling Personal Data
Cyber Crime and its implications for citizens and businesses in the Information Society Richard Henson Senior Lecturer in Computing University of Worcester.
Data Protection Session
Richard Henson University of Worcester September 2016
Teaching Internet Safety
Copyright, Designs and Patents Act 1988
Information management and communication
COMP3357 Managing Cyber Risk
Driver quality - The essential foundation of all road safety
It’s not just business as usual
Presentation transcript:

Information Security and Common Sense Richard Henson University of Worcester November 2008

Yes, good Information Security IS common sense… n as is safely driving a motor car…

“Where did it all go Wrong?” n “End User” Computing n Rapid Advances in Technology n Confusion about legislation n Lack of policy or inconsistent implementation of policy n Data handling training issues

Safe Storage of Organisational Information n Before Digital Data… n Paper in a Locked, Fireproof Cabinet, in a locked room…

Use of Digital Data within Organisations in the early days n BIG Computers –centralised resources & storage –Terminal-only access to data –Printing only via centralised resource n Data processing areas private…

The Rise of End User Computing n 1980s… n The PC offered the possibility of organisational data in the hands of “non professionals”… –network administrators and some academics predicted that there would be big problems… –few people listened… THEY SHOULD HAVE!

Have we been down this road before? n Days of “mainframe” or “centralised” computing… comparable to mass transport systems (e.g. stage coach, railways, bus) –“professional” drivers –people driven about

Example of Technological Change causing rapid Cultural Change; systems inadequate n Also true of the coming of the motor car…

Result of “the motor car” cultural change… n Transport became personalised –those handling motor vehicles were often a menace to other road users –many accidents, injuries, lives lost

Systems catch up with cultural change… n Professional bodies ineffective n ALL DRIVERS only controlled through the use of legislation –on cars… minimum standards –and on drivers…had to be 17 to drive…

Then more cultural change… n And then more legislation –Driving Test –National Speed Limit –Safer cars

Are roads safe today? n Despite increases in traffic, UK road deaths been falling consistently for many years –safer cars? –better driving? –tougher penalties? So a cultural problem CAN be brought under control…

The Challenges of “End User Computing” n In early 1990s, immediate workplace computer-related threats to SMEs were… –RSI –eye strain –EU Health & Safety legislation (1992) –Floppy disks… »because viruses could stop computers functioning!

The Hidden Threat n Lot of changes with the coming of the PC… n but the threat to personal data from removable media NOT fully acknowledged –floppy disks could only hold small amounts of data… –Data Protection Act, 1984, only a civil offence »end-user computing for business use not anticipated…

Digital Data and the Law n Data Protection Act updated in 1998 –did not address the problems associated with putting the end user in control »digital data can be easily carried around –two big technological advances »Writeable CDs.. n meant removable media could now carry huge amounts of personal data »The Internet… n allowed organisational networks to link to the world… n and unlimited amounts of data to be potentially taken off organisational machines…

Too much focus on the Internet? n Internet (mis)use caused data losses –and damaged reputations… n In the face of media horror stories… –organisations steered clear of the Internet for sending data –saw writing to CD as the safe way to go –didn’t acknowledge that data copied to a CD tends to stay there…

The USB stick n Employees had been happily copying data to writeable CD… even writeable DVD… –MUST have been data losses! –So what? Not a Health & Safety issue! Data Protection Act max penalties not enough of a deterrent to even focus minds on reading it… n USB stick encouraged –People had problems using writeable CDs –even more convenient –stored even more data –less bulky to carry around (!!!) n It was a disaster waiting to happen –perhaps the only surprise was that it took so long…

The New Law n Finally (2008) legislation being updated to acknowledge the problem –New term of “Data Recklessness” embedded into Data Protection legislation »serious penalties!!! –Information Commissioner’s Office (ICO) has increased powers.. »FURTHER changes expected during the Parliamentary Session Information Commissioner Richard Thomas

So… why such a long wait? n Again… back to the motor car n Original Highways Act? –law in 1835 –only substantially updated in… 1959 –Why then? had become »a matter of public concern n Equally, Data Protection now –A MATTER OF PUBLIC CONCERN –latest surveys: by 2007 as concerned about privacy as they are about terrorism!

What are the consequences for Organisations? Need to get serious about data protection, or risk the wrath of the Information Commissioners OfficeNeed to get serious about data protection, or risk the wrath of the Information Commissioners Office one recent sufferer was…one recent sufferer was… Richard Branston, Virgin Media (3383 customer records went missing)Richard Branston, Virgin Media (3383 customer records went missing) Would you want to be next???Would you want to be next???

What to do? n Apply common sense? n Now (from 2007) an International Standard for organisations to follow: –ISO –based on British Standard BS7799 »UK leading the world in design… »but not implementation! –any organisation achieving this quality standard gains in two crucial ways: »unlikely to lose data through “recklessness” »can use the ISO “kitemark” to show potential customers that their personal data is being properly looked after

Is getting ISO cost-effective? n BIG question –even before… »“credit crunch” arrived »data recklessness became law n Cost overhead of ISO quantifiable –intensive, highly focussed courses –paperwork deliberately customisable to meet the needs of large and small organisations n If data is lost, what of the cost overhead of: –bad press? –disgruntled customers? –hefty fines?

Is Good Information Security Common Sense? n YES… –just as driving safely is common sense n BUT… –even good drivers could fall asleep at the wheel n What would the roads be like today if: –1835 Highways Act was still in force unchanged? –no-one had to pass a driving test? n QUESTIONS???