Security Profession blog
Comment and discussion about the security industry of interest to the security professional. Blogs will be submitted by (ISC)2's management team and Advisory Board members.
Wednesday 21 May 2008, 5:45 PM
Should We Object to the Recent Tide of Data Legislation?
As a citizen I would want to know if a company had been negligent with my data. I would probably want to see some sort of justice to make sure it doesn’t happen again. As a professional I can appreciate that disclosure can make the victim as well as the company more vulnerable and less secure in the end.
Clearly society needs the ability to properly investigate online criminal activity. A data base could certainly make this easier. But who would have access and what could be the unintended results? The legislators behind Regulation of Investigative Powers Act (RIPA) had not intended to help councils monitor whether parents actually lived in their child’s school catchment area, but this is exactly what Poole Borough Council did.
Legislators will continue to evolve our laws to account for the way in which we now live and work with information. The devil will be in the detail of how laws are written, interpreted and applied, and as experts in the field, information security professionals may well have to play an active role in managing this risk. Rather than objecting it may be better to get involved in shaping the outcome.
John Colley, CISSP
Managing Director, EMEA, (ISC)2 Europe


