Friday, October 28, 2005
A Viking Raid on EU Employee Email Monitoring?
If the NSSR is prosecuted, the case will set a benchmark in determining the extent to which European employers can rely on work-related interests as grounds to access workers' electronic communications. And regardless of the outcome, the case will serve as a reminder to employers of both the precautions that need to be taken in relation to the monitoring of workers' emails and the risks of improperly doing so. Indeed, given the strict treatment of the a public service entity like the NSSR, the ramifications for for-profit corporations could be even more substantial
Steptoe & Johnson LLP. Steptoe & Johnson LLP weekly newsletter
Monday, October 24, 2005
How to Foil a Phish
ID card a recipe for ID fraud
Friday, October 21, 2005
Increased Organized Crime
Wednesday, October 19, 2005
Adopt e-mail authentication
EFF cracks Secret Service code
Password-based Web log-ons not sufficient
Monday, October 17, 2005
MS, Nigeria fight e-mail scammers
Is Privacy of E-Mail Messages possible?
Friday, October 14, 2005
Hold developers liable for flaws
Tuesday, October 04, 2005
Interception of Communications - what now?!
What next? What will be the impact on your business?
Be careful for certain Service Providers that will now all of a sudden sell you 'new' policies.
- This very important Act can not be dealt with in isolation and will have to be implemented, if not already part of your business, in combination with other very important legislation, for example the Electronic Communications and Transactions Act 2002, The Labour Relations Act 1995, and draft Directives that have already been issued to various operators in the Cellular and Telecommunication Industry;
- A single policy is not the solution to all and will it be imperative for your business to review the following:-
- Employment Agreements;
- Independent Contractors Agreements;
- Service Provider Agreements;
- eCommunication Policy (and yes, keep it technology neutral);
- eMail Legal Notice, to be attached to every single email that leaves your business;
- For certain Industries it might be useful to implement a Interception of Communications Policy, e.g. Cellular Operators etc.;
- Records Management Policy, specifically focussing on the retention of certain records for evidential purposes or for example where, as per a specific Directive, your Company is required to retain the records then retention of records as prescribed by law;
- Disciplinary Codes to be reviewed;
- Data Retention Policy
(please take note that the above is not an exhaustive list and will definitely varies from Company to Company)
Again, this should not be an expensive exercise but definitely an exercise that should be executed sooner than later...
For more details, assistance or quote, please feel free to refer to our website and more specifically the section called eCommunications where you can select certain deliverables and request a quote. The eVG Policy Manager (see eVG Services), for implementation of the above mentioned, may also be of interest to your company
Friday, September 30, 2005
Social Engineering - The Weakest Link in InfoSec
Traffic Data Retention vs. Data Privacy
Hopefully our own Law Commission will consider the above when drafting South Africa's own Data Protection legislation.
Thursday, September 29, 2005
ID theft probe at Royal Bank of Canada
Software pirate to pay $1.1 million
Is Skype a Threat?
Another successful Infosec User Group meeting
The following topics were discussed:
- How to value your Information Assets – A paradigm shift from Information Security to Information Risk Management;
- Policies, procedures and tools to successfully implement Password Management;
- Identity Management; and
- A Vulnerability demo taken from the Certified Ethical Hacking course
An interesting question came up during the session : "can one say that there is such a thing as ethical hacking; the law does not differentiate between hacking (malicious intend) and ethical hacking..." - What do you think...