Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
NEWS
This week’s edition of Information Law weekly highlights includes a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
NEWS
This week’s edition of Information Law weekly highlights includes a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
CHECKLISTS
This Flowchart illustrates how to manage a data protection breach (including a cybersecurity breach) under the EU General Data Protection Regulation (EU GDPR). It reflects personal data breach reporting and recording requirements under the EU GDPR together with data breach management guidance issued by the Irish Data Protection Commission (DPC). It maps out a data breach process, providing guidance and links to relevant precedents for each stage of that process. See Precedents: Ireland—Personal data breach plan, Ireland—Data breach report form—internal and Ireland—Data breach assessment and action plan, which guide you through each stage of this workflow. Note 1—assemble data breach team The first step is to assemble your data breach team. Consider who within the organisation would be best placed to react swiftly to the breach and who should be involved with the subsequent investigation (it may also involve externals).The DPC’s data breach notification guide offers practical advice on managing data breaches and navigating the mandatory notification regime introduced by the EU GDPR. It underscores the necessity for organisations to have procedures in place for breach detection,
PRACTICE NOTES
You must have appropriate security in place to prevent personal data being accidentally or deliberately compromised. Information security is wider than cybersecurity (the protection of your networks and information systems from attack), as information security also covers things like physical and organisational security measures. This Practice Note reflects requirements in the UK General Data Protection Regulation (UK GDPR) and ICO expectations, as set out in the ICO’s A guide to data security. The CIA triad The ICO guidance specifically refers to the ‘CIA triad’: confidentiality, integrity and availability. If any of the three elements is compromised, there can be serious consequences—for you as a data controller and for the individuals whose data you process. You are also required to ensure the resilience of your processing systems and services. Resilience refers to: • whether your systems can continue operating under adverse conditions, eg a physical or technical incident, and • your ability to restore them to an effective state See the range of tools available in subtopic: Business continuity plan. The
NEWS
The European Union Agency for Cybersecurity (ENISA) has called for feedback on its draft technical guidance for the cybersecurity measures set out in Commission Implementing Regulation (EU) 2024/2690 (the Network and Information Systems 2 (NIS 2) Implementing Act). The NIS2 Implementing Act sets out technical and methodological requirements for cybersecurity management, with ENISA’s draft guidance offering advice, tips, examples of evidence, and tables to assist in assessing and implementing these requirements. The deadline for submitting feedback is 9 December 2024.
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information and defamation.
NEWS
This week’s edition of Information Law weekly highlights includes a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. These highlights focus on key topics including data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
PRACTICE NOTES
ARCHIVED: This Practice Note has been archived and is not maintained. It sets out key dates and information relating to the EU’s Network and Information Systems Directive (NIS Directive), Directive (EU) 2016/1148 which is repealed under Directive (EU) 2022/2555 (NIS 2 Directive). It includes strategy documents, consultations, progress reports as well as opinions and guidance issued by a range of organisations on its development, reform and repeal. For the key steps of the legislative procedure of NIS 2 Directive, see Practice Note: The EU NIS 2 Directive—timeline. Key developments Date Institution Summary 10 May 2018 - Commission Implementing Regulation (EU) 2018/151 became directly applicable. 9 May 2018 - The deadline for Member States to transpose the NIS Directive, Directive (EU) 2016/1148, into their national laws. 19 February - Commission Implementing Regulation (EU) 2018/151 entered into force. 30