Advertisement
Promo

Security threats Toolkit

BCS attempts cultural shift in data protection

Tom Espiner ZDNet.co.uk

Published: 02 Jun 2009 13:37 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The British Computer Society has launched a data-protection code of practice aimed at getting the public and private sectors to take better care of sensitive information.

The Personal data guardianship code, launched on Monday by BCS in conjunction with the Information Security Awareness Forum (ISAF), is an effort to change how organisations handle personal data.

The code has been given momentum by numerous highly publicised data breaches in the past two years, including the loss of 25 million child benefit-claimant records by HM Revenue & Customs in 2007.

Louise Bennett, BCS chair of the security forum strategic panel, told ZDNet UK on Monday that the government, in particular, needs to understand the principles of data protection. Government departments must also now instigate cultural change following the breaches, so people will automatically take privacy principles into account when embarking on public-sector projects.

"The hardest thing when looking at the data breaches was how you do an effective culture change," said Bennet. "We've produced sheets which go into precisely what the responsibilities of data controllers should be, the roles and responsibilities of data handlers and the rights of data subjects, with examples that can be tailored to the institution."

Read this

Comment: Time lawyers got to grips with encryption

Encryption is playing an increasingly important role, but in law its status is poorly defined. It's time that changed, says Jeremy Phillips

Read more +

Bennett added that the government's plans for more e-enablement for citizens, which are grouped under the rubric 'Transformational Government', have not been properly thought through in terms of technological feasibility and impact on privacy.

"There's a vast amount of work to be done in terms of data-sharing," said Bennett. "[The government] totally underestimates the problems of cleansing data and effectively disposing of it when time has expired."

Assistant information commissioner Jonathon Bamford, the director of data-protection development at the Information Commissioner's Office, said that while the privacy regulator has produced its own guidelines, the BCS initiative was also needed.

"We do provide a lot of guidance, but that comes from a regulator. The BCS guidance comes from the people at the sharp end," Bamford told ZDNet UK. "It sends a message we can't deliver. You'd expect the ICO to say that organisations' reputations are at risk from data breaches, but when they are faced with the BCS saying it, it's different."

The Personal Data Guardianship Code has gone through a lengthy drafting process, the eventual code being the outcome of approximately two years' work by the BCS.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
1 out of 1 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

homer

lets show everyone that labour has compasion[whilst there counting the votes] running upto march/april 2010...http://tinyurl.co...nus very good nb gordon brown said today on our... More

Post a comment

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

Post a comment

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters