ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Asia urged to strengthen data-breach laws

Victoria Ho ZDNet Asia

Published: 28 Sep 2007 09:37 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Governments in Asia need stronger data-breach laws to ensure businesses improve the security of their customer data, according to a senior CA executive.

Jerry Cox, CA's director of security sales for the Asia-Pacific region, including Japan, said in an interview: "Strong laws would force a company to disclose security breaches often involving the loss of customer data."

This, Cox explained, would protect the people whose data was compromised. Strong data-breach laws will also ensure companies take data security more seriously, especially if there are penalties in the form of monetary fines, or risks of reputation damage due to public disclosure.

According to Cox, Japan and Korea are ahead of most parts of Southern Asia in establishing such laws.

"In Japan, companies pay for security breaches in the form of an 'apology fine', sometimes per user account affected, which can amount to millions of dollars," he said. "Unfortunately, most of Southern Asia is not at [the] level [of Japan] yet."

Cox said California is an example where strict data-breach laws are "driving good security practices". California's law — SB 1386 — requires businesses to disclose data-security breaches to residents if their unencrypted personal information is compromised. Other US states have since introduced similar laws, and the UK is moving in that direction.

Noting that the penalties in Asia are often disproportionately low to the crime committed, Cox said: "In Singapore, spammers can be fined. But you've got half the population online, so it's a bigger crime than it seems, and the penalties should be more severe."

Cox added: "In the United States, the penalty for spamming is jail".

On what would be a long-term measure to protect data, Cox suggested educating people to be more careful and aware of "sound security practices".

Cox also highlighted the importance of establishing a good security foundation before implementing "higher level" security measures such as identity management.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Explaining what constitutes a foundation of "sound" network security, Cox said that putting up firewalls and antivirus protection, as well as building policies around user permissions, should be established before implementing ID management.

Companies that do not have a good foundation risk the failure of automated security processes such as ID management. Compared to their western counterparts, more companies in the region are going down this path, Cox warned, noting how easily available such technologies are in Asia.

"While the United States went with the evolution of security tools, companies in Asia have a lot to choose from, even if their organisations are not ready," said Cox. Unlike many Asian companies, those in the US "grew" their security implementations with the sophistication of the tools available over time, he said.

He added that enterprise security policies may not be as developed in Asia, and estimates companies in this region to be "five to seven" years behind their US counterparts, despite having access to the latest technology.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Systems Administrator (CCTV)

We have an expanding 1,300 strong Force working with the community and other partners to promote a safe, peaceful and crime-free environment in the ...

Web Project Manager/Web Services Architect 150 - 180 p/d 12months

Knowledge of, JavaScript, ; Familiarity with scripting languages such as J2EE, Power Shell, Python or Perl; Familiar with the MS technologies such as ...

Sales Executive x2 Northern EMEA IT Sales, OTE ,!

Each sales executive will have target accounts within their region and look to expand business through those. They have headquarters in the United ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment