<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://community.printweek.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Girl on print - Business thinking behind the Printing World - All Comments</title><link>http://community.printweek.com/blogs/girl_on_print/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Build: 20611.960)</generator><item><title>re: Keeping a lid on secure data</title><link>http://community.printweek.com/blogs/girl_on_print/archive/2007/12/07/keeping-a-lid-on-secure-data.aspx#309</link><pubDate>Sat, 08 Dec 2007 15:39:35 GMT</pubDate><guid isPermaLink="false">27ca137d-e3f4-4a9a-9635-81050c58a66e:309</guid><dc:creator>Francis Trist</dc:creator><description>&lt;p&gt;The Law of The Land defines responsibilities for the care of data. The Data Protection Act clearly charges organisations that hold personal infomation with its protection.&lt;/p&gt;
&lt;p&gt;This is a simple requirement yet one that leaves many bewildered - often because of the acronym you refer to - &amp;quot;IT&amp;quot;.&lt;/p&gt;
&lt;p&gt;Information Security (IS to give you another acronym) does not implicitly involve IT neither do the controls required to manage it per se.&lt;/p&gt;
&lt;p&gt;What is evidenced by the recent Revenue and customs fiasco is several failings in procedure, notably:&lt;/p&gt;
&lt;p&gt;1 - Had any consideration been given to the consequences of the loss of data of this type and of this order of magnitude? - i.e. was this loss a known risk and was the impact appreciated?&lt;/p&gt;
&lt;p&gt;2 - Had any consideration been given as to how such a risk might be mitigated? - i.e. accepting the need to make this data available to the Audit Office, how might it be done securely?&lt;/p&gt;
&lt;p&gt;3 - Had due consideration been given to the purpose of the request for data on this scale?&lt;/p&gt;
&lt;p&gt;If we assume that the answer to any of the above questions is &amp;quot;yes&amp;quot;, then what communication of process and procedure had been made to those charged with the task and was the effectiveness of any such procedures tested?&lt;/p&gt;
&lt;p&gt;If we again assume that such tests were made, were the findings fed back in to the review of process?&lt;/p&gt;
&lt;p&gt;These few considerations encapsulate the good practice that is promoted by adherence to accepted standards of working - such as those provided for by ISO27001, the international standard on Information Security.&lt;/p&gt;
&lt;p&gt;Whilst in the modern age IT will almost always be involved in data-related processes, it only does so as a mechanism to hold, process and communicate the information in question. In other words, IT considerations are relatively low-level within IS management. &lt;/p&gt;
&lt;p&gt;Successful IS management requires an objective understanding of the potential threats to the data held; a commercial valuation of the consequences of that data being disclosed, lost or corrupted; a commitment to mitigate such threats and a means of monitoring the effectiveness of such mitigation.&lt;/p&gt;
&lt;p&gt;Information Security has already become an implicit component within Industry in many parts of the world. We seem to be lagging rather a long way behind in the UK.&lt;/p&gt;
&lt;img src="http://community.printweek.com/aggbug.aspx?PostID=309" width="1" height="1"&gt;</description></item><item><title>re: News in print is here to stay</title><link>http://community.printweek.com/blogs/girl_on_print/archive/2007/10/19/news-in-print-is-here-to-stay.aspx#263</link><pubDate>Tue, 20 Nov 2007 16:37:08 GMT</pubDate><guid isPermaLink="false">27ca137d-e3f4-4a9a-9635-81050c58a66e:263</guid><dc:creator>will pollard</dc:creator><description>&lt;p&gt;Print and online are not mutually exclusive. Amazon are promoting a digital reader but expect to sell more hard copy as well, probably from the same authors.&lt;/p&gt;
&lt;p&gt;RIT have a project around 'print in the mix' as if print needs to make a case as one option of many.&lt;/p&gt;
&lt;p&gt;Could there be space here for this sort of approach? this is a blog after all.&lt;/p&gt;
&lt;img src="http://community.printweek.com/aggbug.aspx?PostID=263" width="1" height="1"&gt;</description></item></channel></rss>