Read up on the latest ideas and technologies from companies that sell hardware, software and services. Understanding Email Marketing: A Guide for SMBs
Market Trends: Multienterprise/B2B Infrastructure Market | Worldwide | 2008
Choices in Storage Architecture for Oracle Environments
Why Security SaaS Makes Sense Today
Did you GET the memo? Getting you from Web 1.0 to Web 2.0 Security
Still Sneaking In: The Threats Your Security Tools Aren't Telling You About
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Radicati Market Quadrant 2008 on Corporate Web Security
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Canadian data breach notification guidelines -- jointly created by the Information and Privacy Commissioners for British Columbia and Ontario -- have made their way to the land down under.
Last week, Australian Privacy Commissioner Karen Curtis released the Voluntary Information Security Breach Notification Guide, which aims to assist organizations in effectively responding to information security breaches. The draft guide credits voluntary guidelines by both the Privacy Commissioners of Canada and New Zealand.
"We had worked with the New Zealand privacy commissioner and showed her our breach notification assessment tool," Ann Cavoukian, Information and Privacy Commissioner of Ontario, said. "She took it and developed one in New Zealand similar to ours. It's great to see Australia follow suit." The jointly created Canadian breach notification guide was created in December 2006 and outlines steps on when and how to notify affected individuals.
"When you're notifying somebody of a breach relating to their data, you've got to be perfectly clear and concise," Cavoukian said. "In regards to the preferred method of notification, we think direct contact either by phone, letter or in person are the most effective methods."
As for what to include in the notification, the assessment tool advises organizations provide a general description of what happened without a lot of legal jargon, outline the steps taken thus far (and will be taken in the future) to control or reduce the harm, and the steps the individual can take to further protect themselves.
"You've got to be practical and do things as quickly as possible," Cavoukian said. "You need to contain the damages, get the notices out, fix the problem and prevent it from reoccurring. You've also have to be practical about it and notify people in a way that's not full of legal legalese and provides clear notice as to what you're doing."
Currently, Australia's privacy legislation does not specifically require an agency or organization to notify individuals, or even the privacy commissioner, of a data breach. However, an amendment to the Australian Privacy Act to require mandatory data breach notification is under way.
The same story is playing out in Canada. Last year, the federal government recommended that data protection laws -- specifically the Personal Information Protection and Electronic Documents Act (PIPEDA) -- be amended to include requirements for companies to notify individuals when their personal information was subject to a security breach.
Cavoukian hopes the breach notification assessment tool, along with the influence it is having on the other side of globe, will inspire the federal government to implement an effective and common sense approach on breach notification.
"They're certainly aware of our guidelines, so I'm sure it's food for fodder for them," she said. "We've had very good feedback on our guidelines and I'm sure it'll be one of the things that they take into consideration."
But some organizations such as the University of Ottawa's Canadian Internet Policy and Public Interest Clinic (CIPPIC) want the government to go even further. Responding to an Industry Canada request for public consultation on data security laws earlier this year, CIPPIC recommended that mandatory reporting of data breaches to a publicly-accessible electronic registry is the most effective way to persuade corporations to shore up their potential security risks.
Computerworld Member Login
Prioritizing Services with IT Service Management (ITSM)
Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)
To be repeated on:
Thursday 4th, September 2008
11:00am EST (Sydney Australia)
Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.
Attend and discover:
- How to deliver value to your business through ITSM
- Best practice ITSM implementation
- Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
- If service-oriented ITSM is best for your business
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Viva la Verticals! Key to Vendor Growth is Through Vertical Market Opportunities, Says IDC 2008-09-05 11:05:00+10
F-Secure delivers fastest protection in the online world 2008-09-04 16:50:00+10
NETGEAR expands ProSafe team as business-class products take off in SME market 2008-09-04 16:27:00+10
Rogue security apps dominate Fortinet's Aug 2008 IT threat report 2008-09-04 16:00:00+10
Adaptec Intelligent Power Management Reduces Storage Power Consumption Up to 70 Percent 2008-09-04 11:28:00+10
Web Security SaaS: The Next Generation of Web Security
Discover the latest web security SaaS solutions. Learn how to increase overall security effectiveness and reduce the burden on your IT department. Uncover the security challenges facing SMB environments today and identify the critical elements that can provide you with lower-cost and easier-to-manage web security solutions.








