First standard set for UK data protection

By Tom Espiner, ZDNet Asia
Friday, June 05, 2009 11:56 AM

The first standard for the management of personal information in the United Kingdom has been published by the British Standards Institute.

BS 10012, published on Tuesday, specifies requirements for a personal-information management system (PIMS), which organizations can use to maintain and improve compliance with the Data Protection Act (DPA).

The BSI said the standard can be used by organizations of any size or sector to create data-management systems.

Procedures and systems formulated to the standard would combine staff training and awareness, risk assessment, data-sharing procedures, retention and disposal of data, and disclosure to third parties.

Data-protection expert Louise Townsend, a senior associate at Pinsent Masons, said that in light of recent security breaches, both public- and private-sector organizations would find this standard useful.

"We think government departments will take this seriously, but we also have a number of retail clients who will take this seriously as well," Townsend told ZDNet Asia's sister site ZDNet UK on Thursday.

"On the back of security breaches, organizations can say: 'We recognize this is a concern'. This is a formal standard organizations can work towards which will help their public-facing side, and help internally manage risks."

Townsend said that, while lawyers frequently audit companies for data-protection purposes, organizations have nothing tangible they can show to customers after the audit "other than a legal bill".

The standard is available for download from the BSI at a cost of £50 (US$82) for BSI members or £100 (US$164) for non-members.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web