The post Data Protection Around the World appeared first on Kaluma.
]]>The European data protection laws are considered to be the most comprehensive. This is due to the European Union and the European Economic Area adopting the 1995 Data Protection Directive. In 2012 the General Data Protection Regulation (GDPR) was tabled, to provide a more comprehensive data protection framework. It strives to meet the information security needs of a more globalised, technologically developed world. Various amendments have been made and it is expected that this regulation will come into effect in 2016.
In January 2014, Europe proposed new laws and regulations on cybersecurity in order to bolster the existing legislation, including:
The E-Privacy Directive (2002/58/EC)
The European Critical Infrastructures Directive (2008/114/EC)
The Data Protection Directive (1995/46/EC)
The new directive establishes a Computer Emergency Response Teams (CERTs) in each of the 23 member states. It also prescribes that all member states must adopt their own security frameworks.
The Chronicle of Data Protection reports that 2015 was a turning point in data privacy regulation in Asia. Throughout 2014, data protection regulation was implemented in Singapore and Malaysia, the Chinese consumer protection law was amended and Hong Kong’s Privacy Commissioner for Personal Data continued to drive privacy regulation. Japan is in the process of amending its Personal Information Protection Act (PIPA) and South Korea has implemented strict restrictions and regulations.
Do you do business in Europe or Asia? Do you know which data protection practices apply to you?
To protect your organisation’s information security, and to ensure data protection compliance, contact Kaluma for customised software solutions that support the unique requirements of your organisation’s data security: CLICK HERE.
Image courtesy of hyena reality at FreeDigitalPhotos.net
The post Data Protection Around the World appeared first on Kaluma.
]]>The post The Crucial Incident Response Plan appeared first on Kaluma.
]]>The Plan should offer an organized approach to addressing and managing the consequences of a breach or security attack. This is essential to mitigating the negative effects of a security breach, providing an ordered plan to follow, rather than grasping for possible solutions in the heat of the moment.
The Security Incident Response Plan typically starts with preparation (the drafting of the Plan and its on-boarding to relevant staff). If an incident has occurred, the Plan dictates that the incident be detected and identified, contained, mitigated and eradicated, remediated and recovered, and – finally – measured. If any weak points are identified, the Plan should be adjusted accordingly, in preparation for the possibility of a new incident arising.
This requires that the Plan not only exist, but that it is well known and implemented throughout the organisation.
Does your organisation have an Incident Response Plan? Do you know what it says?
To protect your organisation’s information security, and to ensure data protection compliance, contact Kaluma for customised software solutions that support the unique requirements of your organisation’s data security: CLICK HERE.
Image courtesy of Stuart Miles at FreeDigitalPhotos.net
The post The Crucial Incident Response Plan appeared first on Kaluma.
]]>When a security incident occurs, but does not involve the theft or compromising of personal information, it is not considered a breach. These incidents usually take the form of impersonation or denial of service (where a user is blocked from accessing their own machine or network).
The post Incident vs Breach: Responding to an IT Threat appeared first on Kaluma.
]]>Incident vs Breach: In order to respond to an IT or data threat effectively, it is important that the IT department dealing with the threat understands what the threat entails.
In simplified terms, a breach is always an incident, but not all incidents are breaches.
A breach occurs when sensitive, personal information is leaked, hacked or released (whether accidentally or through illegal action). This would involve access to personal information which should be confidential, such as; social security or identity numbers, medical records, contact details, etc. Specific legal definitions are applied in this case.
When a security incident occurs, but does not involve the theft or compromising of personal information, it is not considered a breach. These incidents usually take the form of impersonation or denial of service (where a user is blocked from accessing their own machine or network).
The response should reflect the severity of the incident/breach, considering safety concerns, loss of personal data, exposure of data, legal requirements and violations, interruption of services, etc. The major difference in response is that, in terms of a breach, the organisation is under legal obligation to report the breach. With regards to an incident that isn’t a breach, it does not have to be reported.
The first and most crucial step in responding to a threat is determining whether it is a breach or incident. If the incident isn’t reported because it was accidentally labelled a mere incident and not a breach, serious regulatory and reputational consequences will be the result.
Can your IT department differentiate between an incident and a breach?
Is it equipped to respond appropriately?
To protect your organisation’s information security, and to ensure data protection compliance, contact Kaluma for customised software solutions that support the unique requirements of your organisation’s data security: CLICK HERE.
Image courtesy of Hyena Reality at FreeDigitalPhotos.net
The post Incident vs Breach: Responding to an IT Threat appeared first on Kaluma.
]]>The post Optimising Compliance through IT Audits appeared first on Kaluma.
]]>IT audits play a critical role in the strategic development of the company, from an IT perspective. It also ensures that a written report is available to be reviewed when required, offering reliable information on demand. From this information, the company will be able to ascertain whether its IT systems are fully protected and properly managed, reducing risks and increasing efficiencies.
By conducting an IT audit, an evidentiary audit trail is created, which provides a detailed set of records of the actions taken or occurrences within the company during a specific period of time. This allows the company to evaluate what went wrong in instances of a breach, enabling it to reconstruct a particular event.
Customised web applications are hugely beneficial to the IT audit process, both in terms of ease of use and accuracy. The only way to guarantee compliance is to have a full record of what was done when. An automated system is the key to capturing accurate and efficient compliance evidence.
Is your IT audit and compliance evidence up to date?
To protect your organisation’s information security, and to ensure data protection compliance, contact Kaluma for customised software solutions that support the unique requirements of your organisation’s data security: CLICK HERE.
Image courtesy of Stuart Miles at FreeDigitalPhotos.net
The post Optimising Compliance through IT Audits appeared first on Kaluma.
]]>The post Security Training; Key to Minimising Data Breaches appeared first on Kaluma.
]]>Data security training entails inculcating a deeper understanding of: what constitutes personal data and information; the principles of data protection in line with legislation and company policy; risk management techniques; and the consequences of a breach, both from a company perspective and legally. Through this training, staff should be made fully aware of the duties that they should fulfil to remain firmly within legal data protection parameters.
On a practical level, training should include educating staff about the how to keep information secure, the importance of maintaining the integrity of the information, and ensuring the security of laptops, tablets and cellphones that contain personal data (especially those that are taken home on a daily or weekly basis).
It is essential that this training is adapted to each continent, country, industry, organisation and department to ensure its relevance. In this manner, uncertainties and ambiguities will be avoided.
Are your employees aware of their data protection duties?
To protect your organisation’s information security, and to ensure data protection compliance, contact Kaluma for customised software solutions that support the unique requirements of your organisation’s data security: CLICK HERE.
Image courtesy of Stuart Miles at FreeDigitalPhotos.net
The post Security Training; Key to Minimising Data Breaches appeared first on Kaluma.
]]>The post Achieving Security Awareness appeared first on Kaluma.
]]>In terms of information technology security awareness, it is essential that every person in every organisation is aware of the company’s internal security processes, as well as the national and international compliance processes. If this level of awareness is not created, the organisation will be susceptible to cyber and informational crime. In many instances of hackings and data breaches, the cause is cited as employee error. While, in some cases, this is due to a deliberate “inside job”, in many it occurred merely because the staff member was not fully aware of the security policy requirements.
When on-boarding a staff member, provide them with security policies and procedures in a format that they can understand, backed up by online or visual examples, to ensure that they grasp the security awareness concept. Implementing software to track compliance will go a long way to ensure awareness is achieved throughout the organisation.
What is the level of security awareness in your organisation?
To protect your organisation’s information security, and to ensure data protection compliance, contact Kaluma for customised software solutions that support the unique requirements of your organisation’s data security: CLICK HERE.
Image courtesy of Pixomar at FreeDigitalPhotos.net
The post Achieving Security Awareness appeared first on Kaluma.
]]>The post The Value of Ironclad Security Policies appeared first on Kaluma.
]]>
When a policy is tailor-made for your business, it offers great benefits, such as: a reliable, documented structure and instructions to follow; guidelines to function according to; easing the decision making process; a clear outline of duties and accountabilities to refer back to; and so on.
An ideal policy will include sections such as: a well-defined scope; roles and responsibilities; timelines; actions required; the consequences if the guidelines are not followed; and references to other policies or procedures. It is also essential that the document outlines how it will be applied and enforced, or it will be ineffectual.
Do you have an ironclad policy?
To protect your organisation’s information security, and to ensure data protection compliance, contact Kaluma for customised software solutions that support the unique requirements of your organisation’s data security: CLICK HERE.
Image courtesy of Stuart Miles at FreeDigitalPhotos.net
The post The Value of Ironclad Security Policies appeared first on Kaluma.
]]>The post The Devastating Impact of Data Breaches appeared first on Kaluma.
]]>Organisations across the globe all fear the day they hear the words “data breach”; defined as the release of information that is supposed to be secure, to the public, either intentionally or unintentionally.
In 2015 alone, innumerable data breaches have occurred, with every type of organisation – from the IRS to Anthem, eBay, Home Depot and Target (World’s Biggest Data Breaches in 2015) – being at risk. According to CRN, devastating breaches have already occurred throughout 2015.
Some of the top 10 breaches are listed as:
1. The Multi-Bank Cyberheist
When? February 2015
What? A billion-dollar bank cyberheist was discovered, affecting as many as 100 banks around the world.
How? Phishing and gaining access to resources such as employee account credentials and privileges.
2. Anthem
When? Revealed February 2015, occurred December 2014
What? Eighty million patient and employee records possibly accessed, including information such as names, dates of birth, social security numbers, healthcare ID numbers, physical and email addresses, employment and income data, and more.
How? The data was not adequately encrypted (according to the Wall Street Journal, it hadn’t been encrypted at all).
3. CareFirst BlueCross BlueShield
When? May 2015
What? Over a million healthcare members’ personal details (names, birth dates, email addresses) and subscriber information compromised. Luckily password encryption prevented social security numbers from being hacked.
How? Hacked
4. LastPass
When? June 2015
What? Cyberattack compromising email addresses, password reminders, server per user salts and authentication hashes.
How? Uncertain.
5. Harvard University
When? July 2015
What? One of eight higher education breaches, although it remains unclear what data was accessed by the hackers.
How? Uncertain.
6. Army National Guard
When? July 2015
What? Possible exposure of the social security numbers, home addresses and personal information of nearly a million current and former National Guard members.
How? Improperly handled data transfer to a non-accredited data center, by a contract employee.
7. The Hacking Team
When? July 2015
What? The Hacking Team supplies spyware to governments across the globe. The breach of its system resulted in the publication of more than a million incriminating emails.
How? Uncertain.
How secure is your data?
CLICK HERE to learn more about the management, implementation and compliance requirements – for government regulations, industry standards, best practices and corporate policies.
Image Courtesy of Rob Pongsajapan at Flickr
The post The Devastating Impact of Data Breaches appeared first on Kaluma.
]]>The post Kaluma’s Executive Briefing on The British Data Protection Act (DPA) appeared first on Kaluma.
]]>Data protection is a global problem – the Internet is speeding up globalisation at an alarming rate and personal information is available in abundance, at the click of a button. If you do business in the United Kingdom (UK), then it is essential that you comply with the Act, which is enforced by the Information Commissioner (ICO).
The ICO is required to execute his/her duties by promoting good practice in handling personal data, giving advice regarding data protection when required, keeping a register of business that have confirmed their information-processing activities, assisting in dispute resolution and enforcing compliance. In certain cases, this may lead to the ICO prosecuting offences.
The Act sets out particular rights and duties that businesses must follow when storing and processing personal information. While some limited exemptions exist, these are not blanket exemptions and ignorance of where the exemption ends and the duties begin will not remove the consequences of contravention.
Do you know what these rights and duties are? Do you know whether you are exempt?
If you don’t, or if your staff don’t, you may land yourself in hot water.
CLICK HERE to view the latest Kaluma eBook for an overview of the Act.
The post Kaluma’s Executive Briefing on The British Data Protection Act (DPA) appeared first on Kaluma.
]]>The post The Value of Information Security appeared first on Kaluma.
]]>“Information security” – with the advent of the digital age, this term has taken on an entirely new meaning. Data is captured, stored and used in electronic format, making it highly susceptible to security breaches and the misuse of the information.
The term is defined as the practice of defending information, whether electronic of physical, from unauthorised use. This is achieved through the application of sound operational practices, guided by policy (does your organisation have a policy?) to protect information at all levels; while being captured, processed, shared or stored.
In terms of IT information security, the risk is exponential and strict compliance with IT Security Policy is required to avoid hefty penalties.
Not sure what IT Security Policy entails? It’s best to find out – ignorance does not remove accountability.
Whether the information you hold is susceptible to use, disclosure, disruption, perusal, inspection, recording or destruction, it is essential that you are aware of the compliance requirements for information security in your industry.
In many instances, innovative software can be used to ensure operational compliance with internal security policies, national and international regulations and industry best practices. After all, compliance is a requirement, not an option – and the cost of non-compliance is high.
CLICK HERE to learn more about the management, implementation and compliance requirements – for government regulations, industry standards, best practices and corporate policies.
The post The Value of Information Security appeared first on Kaluma.
]]>