« Home | Red Hat servers breached » | Help, there's a resident rootkit in the memory » | Hijack the Internet » | CICT endorses latest anti-cybercrime bill in Congress » | Nuts about Security » | The hackers you must fear... » | OpenBSD Local Exploit » | PRC site flagged by Google » | Newsworthy? » | Busy.. »

RP can’t do without policy on data privacy, security

http://www.mb.com.ph/INFO20080826133382.html

Under no circumstances can the Philippines compete, let alone thrive, in the lucrative outsourcing market and the global marketplace without a fool-proof policy on data protection and security.

This was the clear message sent out by participants in a recent conference dubbed "Mapping the Future of Information Security Forum" organized by the Information Systems Security Society of the Philippines (ISSSP) at a hotel in Makati City.

Anthony Tuason, a director at consultancy firm PriceWaterhouseCoopers, said during his presentation that IT companies, most especially those in the BPO sector, cannot possibly institute "IT governance" — the process of using technology as to management tool to run an organization — in the workplace if security is being disregarded.

"Innovation, value, and performance can be derived from IT governance (and) data privacy and security is one area that helps organizations achieve their IT governance objectives," Tuason said.

Local BPO firms have a huge stake in this issue, Tuason said. "A company must understand both the impact of laws of the country where data originates and the laws of the Philippines where data is processed. Responsibility for compliance with the originating countries’ laws will rest with the company.’

Industry groups such as the Business Processing Association of the Philippines (BPAP) and Philippine Internet Commerce Society (PICS) have urged the government to pass a law governing data privacy and security.

The BPAP has actually partnered with the Commission on Information and Communications Technology (CICT) for a Technical Working Group (TWG) composed of representatives from the private and public sectors that would look into the pending bills on data privacy and security.

The BPAP said that aside from pushing for the passage of the bills, it also would work for the appointment of a "privacy commissioner" who will act as the primary protector of data privacy rights against misuse and abuse by individuals, private organizations, and even the government.

According to the National Cybersecurity Coordinator Virtus Gil, who was also a speaker during the ISSSP confab, the government has already laid down a strategy for national cybersecurity, which deals mostly to security threats against the country.

The program, Gil said, has three goals: to reinforce current policy and operational measures to reduce vulnerability in the cyberspace under Philippine jurisdiction; to nurture a culture of cyber security amongst users and critical sectors; and to strengthen self-reliance in terms of information security technologies and human resources.

Buhay pa pala ISSSP?
We have a National Cybersecurity Coordinator?