information security

Information Security Team: Your task force for securing information and responding to incidents

A group of people working together can achieve a goal more quickly and effectively that one person working alone. Information security law compliance is difficult and requires an information security team of people to do it properly. Your team should [...]

By |2018-01-18T15:00:45+02:00January 16th, 2018|Categories: POPI and Data Protection|Tags: , , , |

Information has Value – Secure it the right way

Information has value for a number of reasons, and it is important to secure information. Doing this the right way should be one of your top priorities. If you don’t secure it the right way, you risk infringing the rights [...]

Information Security Laws or Privacy Laws – What is appropriate security?

Information security laws (many of which are also privacy laws) across the globe require you to secure the personal data that you process. The General Data Protection Regulation (GDPR) in Europe, the Data Protection Act in the United Kingdom, and the [...]

Information Technology Act or IT Act: Data Protection in India

With a population of 1.3 billion people and a Gross Domestic Product of 2.6 trillion US Dollars, India is a market rich in data, personal and private information. Data protection in India is important because many organisations have a global [...]

By |2022-12-15T10:41:27+02:00January 10th, 2017|Categories: POPI and Data Protection|Tags: , , |

Appointment of the Information Regulator for POPI and PAIA

Today, 7 September 2016,  the South African National Assembly voted in favour of the appointment of the Information Regulator for POPI and PAIA. Parliament voted for the five nominated candidates to run the newly-formed office of the Information Regulator. This is not [...]

By |2019-06-28T13:53:07+02:00September 7th, 2016|Categories: POPI and Data Protection|Tags: , , , |

“Fraudulent” access to an IT system containing unprotected public data

Is it an offence to access data that is freely available on the Internet? Many of us would think that it isn’t if the data is accessible to the public. Can a person use public data (that may include public [...]

PCI DSS Compliance

Interested in PCI DSS compliance? Do you need to comply with the Payment Card Industry (PCI) Data Security Standard (DSS)? A merchant, service provider or bank that processes any cardholder data, needs to know about PCI DSS and what is means [...]

Electronic signatures and cryptography

Digital signatures, digital certificates, and advanced electronic signatures are all types of electronic signatures that use cryptography to authenticate the identity of the person signing and to secure their electronic signature. They are all very reliable, but they each [...]

By |2022-12-07T11:17:39+02:00January 14th, 2014|Categories: Electronic Signature Law|Tags: , |

Forensic IT and the Law

Forensic IT and computer forensics is big business. There are now many forensic investigators. Especially because most business documents are created electronically nowadays. The need for electronic evidence is not confined to obvious cybercrime events such as hacking, fraud and [...]

By |2019-08-20T13:53:57+02:00May 22nd, 2012|Categories: Cybercrime|Tags: , , |

Map of International Crypto and Encryption Laws

We found this International Crypto laws and regulations map captured from several sources. It is interesting to see how Google Maps has been used to help people find cryptography laws in different jurisdictions. One interesting thing to note is just [...]

By |2022-11-15T16:58:25+02:00May 16th, 2009|Categories: POPI and Data Protection|Tags: , , |

Measures to be taken by companies to guarantee security of Internet transactions

Section 43(5) of the ECT Act requires the supplier in an electronic transaction to "utilise a payment system that is sufficiently secure with reference to accepted technological standards at the time of the transaction and the type of transaction concerned." [...]

Information Security Policies support Compliance

Information Security policies support compliance in many ways. Vicarious liability Beyond sensitising employees to the risks posed by technology, information security policies minimise the organisation's exposure to vicarious liability for unauthorised or unlawful acts carried out by employees during the [...]