A Framework of Security Safeguards for Confidentiality and Integrity of Electronic Personal Information

被引:0
作者
Dala, Prittish [1 ]
Venter, Hein [1 ]
机构
[1] Univ Pretoria, Dept Comp Sci, ZA-0002 Pretoria, South Africa
来源
PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2015) | 2015年
关键词
protection of personal information; POPI Act; electronic personal information; security safeguards; confidentiality and integrity;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Privacy entails controlling the use and access to place, location and personal information. In South Africa, the first privacy legislation in the form of the Protection of Personal Information (POPI) Act was signed into law on 26 November 2013. The POPI Act promotes the protection of personal information by public and private institutions and specifies the minimum requirements in twelve chapters, which includes eight conditions for lawful processing of personal information. Condition Seven of the POPI Act makes specific provision for security safeguards to ensure confidentiality and integrity of personal information. However, one of the limitations of Condition Seven is that it is a requirement which is not supported by guidance relating to security safeguards to be considered to ensure confidentiality and integrity of electronic personal information. Hence, this paper aims to propose a framework based on a selection of security safeguards from several leading practices to be considered to prevent unauthorised disclosure and modification of electronic personal information stored, processed or transmitted. The authors believe that the proposed framework will facilitate the achievement and maintenance of compliance with Condition Seven of the POPI Act, with a specific focus on electronic personal information.
引用
收藏
页码:415 / 424
页数:10
相关论文
共 26 条
[1]  
Ali A., 2013, DELOITTE REV, P19
[2]  
[Anonymous], 2005, B SI Standard 100-1: Information Security Management Systems (ISMS), P1
[3]  
[Anonymous], 2009, The Risk IT Framework, P17
[4]  
[Anonymous], 2014, PATHS CATALONIAS INT, P1
[5]  
[Anonymous], 2013, CISA Review Manual 2013", p, P341
[6]  
[Anonymous], 2009, Protection of Personal Information (POPI) Bill, P1
[7]  
Drewitt T., 2013, A Manager's Guide to ISO22301, P11
[8]  
European Parliament, 1995, OFFICIAL J EUROPEAN, V38, P31
[9]  
Hoar S.B., 2001, Oregon Law Review, V80, P1423
[10]  
Information Systems Audit and Control Association (ISACA), 2014, INF SYST AUD CONTR A, V2, P14