Computing – Data Retention Laws to Change

I was quoted by Computing in an article covering the Communications Data Bill. I was talking about the UK adoption of the EU Data Retention Directive (EU DRD) for Internet data, after an 18 month delay to help ISPs get ready. Would have been nice to have my job title and company name printed correctly in the article though…

The full article is available online at:

http://www.computing.co.uk/computing/news/2217202/retention-laws-change-4017535

ZDNet – Communications Data Bill

I was quoted by ZDNet in an article covering the Communications Data Bill. I was talking about the UK adoption of the EU Data Retention Directive (EU DRD) and how it affected the current voluntary data retention regime, but the article also covers the Interception Modernisation Programme (IMP) – although not by name – and the desire for a centralised government controlled database of all communications data records.

The full article is available online at:

http://news.zdnet.co.uk/communications/0,1000000085,39420722,00.htm

Computeractive – Government wants ISPs to log web usage

I was quoted by Computeractive in an article covering the Communications Data Bill. I was talking about the UK adoption of the EU Data Retention Directive (EU DRD) and how it affected the current voluntary data retention regime. Reference to ‘court-ordered warrant’ should have been ‘RIPA Notice’, but I didn’t get to review the article before it was published…

The full article is available online at:

http://www.computing.co.uk/computeractive/news/2216861/isps-hold-onto-customers

ISNow – Enterprise Security

The following introduction was originally published in the BCS Information Security Now Magazine, Spring 2008 issue (Volume 2, Issue 3), which was on the topic of Enterprise Security:

“I feel that to be effective enterprise security needs to have a broad focus; moving beyond a rigid infrastructure and network boundaries to take on a much more holistic view, encompassing how employees actually interact with and use corporate information and resources. No longer should it be limited to company controlled hardware and applications, with its perennial issues of configuration and patch management, access control, onsite support contracts, perimeter and desktop security, in-house application development, but go even wider.

The brave new world has already brought us deperimeterisation, the erosion or blurring of network edges; off-shoring and outsourcing, with control being less direct and more reliant on third party contracts; VoIP, removing boundaries as voice and data merge; virtualisation, bringing issues of properly designing resilience and security into a more logical architecture; online services, such as software as a service (SaaS) and web 2.0, commercially attractive but how do you ensure that your data is protected and available when you want it?

Recent incidents of large-scale information leakage are partly a result of the move towards everything being digital, but without the associated changes needed to staff education and data controls. Increasing use of the social web, instant messaging, online games, messaging boards, blogs, photo sites et al means that users – your staff – expect ready, user controlled, transfer and publishing of information. Businesses need to account for this when those same users are handling your information and data. Shouldn’t this also form part of what we call enterprise security?”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-spring08.pdf

ITNow – 59.5 Second Interview

The following interview with me was originally published in the BCS ITNow Magazine, March 2008 issue (Volume 50, Issue 2), which was on the topic of Security Strategy:

Gareth Niblett is the chairman of the BCS’s Information Security Specialist Group (ISSG).

Who are the BCS-ISSG?

The Information Security Specialist Group (ISSG) is part of the BCS and is open to anyone interested in information security.

What is the aim of the group?

The basic objectives of the BCS-ISSG are to involve our membership and the public by raising awareness of the risks to information systems and by identifying technical and non-technical methods for attaining acceptable levels of security.

The BCS-ISSG also seeks to influence the development of commercially available IT security products and services, and the development of the legislation and standards required to achieve and sustain acceptable levels of security. We work to improve awareness of ethical issues arising from computer misuse and support research into the management of computer risk.

How can people join the group?

Only BCS members are able to join the ISSG, as with other specialist groups, but they will benefit from free membership.

What sort of things does the group do?

We run an annual calendar of events which starts with our AGM in May, then a one day seminar in July, this year to be our 2nd Annual Privacy Day, then our Annual Legal Day in January and finally our annual conference in March.

We contribute to the BCS security magazine, Information Security NOW (ISNOW), and provide printed copies to our members. Also, since 1994, we annually award a David Lindsay Memorial Prize to the student from the Royal Holloway College who, in the opinion of the ISSG, submits the best dissertation on an information security related topic.

When was the group started and how did it come about?

The BCS-ISSG arose in 1983, from recognition that IT colleagues and the public were not well supported on practical information security issues. Individual members often make substantial contributions to other BCS groups, branches and committees, and to a wide range of educational and legislative activities across the world. Our growing membership is drawn from all sectors of the community and we welcome all who wish to share our objectives.

For more information visit:

www.bcs-issg.org.uk

The interview is available online at:

http://itnow.oxfordjournals.org/cgi/pdf_extract/50/2/11

The Blog of Gareth Niblett