Standing Behind Technical Promises

No ratings

Presented at AUScert 2008 by

The information security landscape is shifting from self-regulation and legal complacency to one of regulation and legal activism. Privacy and security are no longer seen as diametric opposites. A middle playing field of personal information security is emerging. The competing tension between protecting anonymity online and accountability for online activities has heightened. Where this tension has traditionally played out in the cyber-criminal foray, we are now seeing similar arguments spilling over into the corporate realm. On the one hand, there is a push for legal protection of anonymous transactions in online activities (see recommendations for the Review of Australian Privacy Law). On the other, new laws have been introduced in an attempt to boost accountability online such as enhanced data retention laws. Accountable conduct for users as well as accountable conduct for corporations (including ISPs, banks, software vendors, and all corporations and organizations who handle personal information). At the same time we are seeing a decline in public trust in using online services. As such, we are headed towards a significant expansion of corporate obligations concerning information security. This presentation will provide an overview of new and future legal obligations in information security. It will examine such trends in the international and Australian framework where appropriate.