You are currently viewing the ‘Information Security’ Topic

What is “information security law”?

Friday, April 17th, 2009

Information security law is an emerging area of the law which is currently at the same stage of development as so-called "Internet law" or "cyber law" was at in the early 21st century. There is no single law in South Africa that governs all of a company's information security obligations. Rather, ...

Privacy in the workplace - an interview

Friday, March 20th, 2009

Recently Helaine Leggat was one of the guests on Kaya FM to comment on the interception of email, voice, or other communications in the workplace and the right to privacy in the workplace. Caution: The audio files on Michalsons can be large. Most are about 2.5MB in size and last for ...

Infosec versus other concepts (e.g hacking)

Monday, October 27th, 2008

More than protecting against "hacking":Information security involves more than simply protecting against intrusions by "hackers". (Historically the term "hacker" was used to describe an individual with skill and knowledge relating to operating systems and programming, whereas the term "cracker" described a person who intentionally sought access to computer systems or ...

IT Security Podcast

Friday, October 24th, 2008

This IT Security Pubcast focuses on matters of information security and risk in South Africa. Part 1: 00:00:00 - 00:11:34 - 1.4MB Speakers are introduced (including Helaine Leggat from Michalsons) and they discuss an issue they faced involving a leak of confidential information, how they exposed the weakness in the security system ...

Infosec - what are we trying to protect?

Friday, October 24th, 2008

By securing an organisation's information systems and networks, we are trying to protect the same assets organisations have traditionally attempted to protect (or protect against): competitive advantage, business uptime (availability), cash flow, financial loss, preservation of business relations, unforeseen legal and business resumption costs, intellectual property, commercial or public ...

Payment Card Industry Data Security Standard

Sunday, September 14th, 2008

Terminology / Definitions Merchants = Entities directly involved in the processing, storage, transmission and switching of (i) transaction data, (ii) cardholder information, or (iii) both. Service Providers = Entities not directly involved in (i) to (iii) above but includes organisations who (i) provide services to Merchants or (ii) control the security of cardholder data ...

Access to Information (PAI Act): Index (Part 1)

Saturday, September 6th, 2008

This is an index of the legal resources related to the Promotion of Access to Information Act 2 of 2000 as at 6 September 2008. General [EH van Coller De Jure (2006) 39(1) p163 - "Transparency and Access to Documents: A General Principle of European Community Law?"] [M Richter LDD (2005) 9/2 p219 ...

Measures to be taken by companies to guarantee security of Internet transactions

Monday, August 25th, 2008

Section 43(5) of the ECT Act requires the supplier in an electronic transaction to "utilise a payment system that is sufficiently secure with reference to accepted technological standards at the time of the transaction and the type of transaction concerned." If a payment system is breached, the supplier must reimburse ...

How does the law recognise or define digital or e-signatures?

Thursday, August 14th, 2008

The ECT Act defines an electronic signature as data attached to, incorporated in, or logically associated with other data and which is intended by the user to serve as a signature. The ECT Act recognises the contractual freedom of parties to specify whether electronic signatures are required, and if so, ...

Advanced Electronic Signatures?

Monday, August 11th, 2008

Many people are wondering when it will be possible to get and use an advanced electronic signature. An advanced electronic signature is basically an electronic signature that has been accredited. Why would you want one? You could use your advanced electronic signature to sign an electronic document ...