Inside

Showing posts with label Cryptography. Show all posts
Showing posts with label Cryptography. Show all posts

Friday

Tasks of the data protection officer



The data protection officer shall have at least the following tasks: (a) to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions.

Friday

NIST - Cybersecurity Framework draft Update.

Jan. 10. 2017 - The National Institute of Standards and Technology (NIST) has issued a draft update to the Framework for Improving Critical Infrastructure Cybersecurity - also known as the Cybersecurity Framework. 

Sunday

White Paper The State of Information Security Law. By Tom Smedinghoff (Wildman Harrold)

This paper provides information about the expanding duty to provide security and the emergency of a legal obligation for compliance. Abstract: Information security is rapidly emerging as one of the most critical legal and public relations issues facing companies today. As the series of highly-publicized security breaches over the past few years has demonstrated, it is in many respects a time bomb waiting to explode. Creating, communicating, and storing corporate information in electronic form greatly enhances the potential for unauthorized access, use, disclosure, and alteration, as well as the risk of accidental loss or destruction. Concerns regarding corporate governance, individual privacy, accountability for financial information, the authenticity and integrity of transaction data, and the security of sensitive business data are driving the enactment of new laws and regulations designed to ensure that businesses adequately address the security of their own data. This paper discusses these points and provides information about the expanding duty to provide security and the emergency of a legal obligation for compliance (Dec. 2007). Link - In http://resources.sei.cmu.edu/library/asset-view.cfm?assetid=52927

Thursday

New good practice guide by ENISA on disclosing vulnerabilities

ENISA publishes a good practice guide on Vulnerability Disclosure, aiming to provide a picture of the challenges the security researchers, the vendors and other involved stakeholders are confronted with when disclosing software/hardware vulnerabilities. The study gives a glimpse into the complex vulnerability disclosure landscape by taking stock of the current situation, identifying the challenges and good practices and proposes concrete recommendations for improvement.
The main part of the report, describes the main concepts behind vulnerability disclosure along with some figures of the number of vulnerabilities disclosed in the past 13 years. 

Monday

New Data Protection Regulation

New EU data protection legislation, informally agreed on Tuesday and backed by Civil Liberties MEPs on Thursday morning, will create a uniform set of rules across the EU fit for the digital era. It should also improve legal certainty and boost trust in the digital single market for citizens and businesses alike. Clear and affirmative consent to data processing, the right to be forgotten and strong fines for firms breaking the rules are some of the new features. (Link)

Monday

Tuesday

Digital Papers