ENGLISH

Cyber Security: Law and Guidance

Book information

Publisher
Bloomsbury Professional
Year
2018
ISBN
9781526505866, 9781526505897, 9781526505880
Language
english
Format
PDF
Filesize
6 MB (5944169 bytes)
Pages
\787
Time added
2023-05-22 05:31:22

Description

Implementing appropriate security measures will be an advantage when protecting organisations from regulatory action and litigation in cyber security law: can you provide a defensive shield? Cyber Security: Law and Guidance provides an overview of legal developments in cyber security and data protection in the European Union and the United Kingdom, focusing on the key cyber security laws and related legal instruments, including those for data protection and payment services. Additional context is provided through insight into how the law is developed outside the regulatory frameworks, referencing the ‘Consensus of Professional Opinion’ on cyber security, case law and the role of professional and industry standards for security. With cyber security law destined to become heavily contentious, upholding a robust security framework will become an advantage and organisations will require expert assistance to operationalise matters. Practical in approach, this comprehensive text will be invaluable for legal practitioners and organisations. It covers both the law and its practical application, helping to ensure that advisers and organisations have effective policies and procedures in place to deal with cyber security. Topics include: Preface Dedication Bibliography Table of Statutes Table of Statutory Instruments Table of Cases 1. THREATS Cyber criminals States and State-sponsored threats Terrorists Hacktivists Script Kiddies 2. VULNERABILITIES An expanding range of devices Poor cyber hygiene and compliance Insufficient training and skills Legacy and unpatched systems Availability of hacking resources 3. THE LAW Introduction International instruments Convention 108 Council of Europe Convention on Cybercrime European and European Union-level instruments The Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR) European Court of Human Rights (ECtHR) and the application of the ECHR to privacy and data protection Case law of the ECtHR (on privacy and security) Treaty of Lisbon and the EU Charter of Fundamental Rights and Freedoms The EU’s General Data Protection Regulation (GDPR) E-privacy Directive and Regulation Payment Service Directive 2 (PSD2) Regulation on electronic identification and trust services for electronic transactions in the internal market (eIDAS) The Directive on security of network and information systems (NIS Directive) UK’s legislation The UK’s Human Rights Act 1998 (HRA) Data Protection Bill (Act) (2018) The Privacy and Electronic Communications (EC Directive) Regulations (PECR) Regulation of Investigatory Powers Act (RIPA, 2000), Data Retention and Regulation of Investigatory Powers Act (DRIPA, 2014), Investigatory Powers Act (IPA, 2016) Computer Misuse Act (CMA) CMA in practice A focus on The Computer Misuse Act Territorial Scope Sections 4 and 5 4. HOW TO DEFEND Active Cyber Defence What is good active cyber defence? Building a more secure Internet Protecting organisations The supply chain, a potential leaky chain in your armour Social engineering, your number one threat Malware, a sneaky nightware Your company website, your continually exposed gateway to the world Removable media and optical media, danger comes in small cheap packages Passwords and authentication, the primary gatekeeper Smartphones, it is in reality a pocket PC Cloud security, more secure than on-premise? Well it depends Patching and vulnerability management, a never-ending battle Governance, risk and compliance, dry but it can work if done properly Protecting our critical national infrastructure and other priority sectors Changing public and business behaviours Managing incidents and understanding the threat 5. PRIVACY AND SECURITY IN THE WORKPLACE Introduction Legal instruments on data protection and security in the workplace Role of the employer The definition of an employee and a workplace Nature of the processed data Legal ground for processing personal data Data protection and security requirements extend to all medias Companies are responsible for the data security practices of their processors Roles of the controller and the processor Training and Awareness Privacy Matters, Even in Data Security Identity and Access Management (IAM) – Limit access to data Remote workers Execution and applicability of the data protection rights 6. SECURITY IN THE BUILT ENVIRONMENT Introduction Programme/Project Security Set up Supply Chain Management NCSC Principle for Supply Chain Security Internal assurance and governance Building Information Modelling Physical Security Electronic Security (including cyber) Cyber Summary 7. THE IMPORTANCE OF POLICY AND GUIDANCE IN DIGITAL COMMUNICATIONS Introduction The Value of policies The Extent of the Issue Key considerations for policy generation Systems Deployment Ownership and Right to Monitor Managed Circulation Use of Digital Communications for Personal Purposes User Guidance Damaging Comments Presentation and Content, Including Confidentiality Constituents of System Abuse Conclusions 8. THE C SUITE PERSPECTIVE ON CYBER RISK Organisational Ramifications of Cyber Risk Assigning Accountability Setting Budgets Building a CxO-Led Cyber Strategy Summary and Outlook 9. CORPORATE GOVERNANCE MIND MAP Disclosing Data Breaches To Investors Fiduciary Duty to Shareholders and Derivative Lawsuits Arising from Data Breaches Trade Secrets Threats Cybersecurity – Security Management Controls IT Strategy Governance Structure Organisational Structures and HR Management IT Policies and Procedures Resource Investments and Allocations Portfolio Management Risk Management IT Controls Personnel and Training Physical Security of Cyber Systems Systems Security Management Recovery Plans for Cyber Systems Configuration Change Management and Vulnerability Assessments Information Protection 10. INDUSTRY SPECIALISTS IN-DEPTH REPORTS Mobile Payments Key technical and commercial characteristics of mobile payments Complex regulatory landscape Key technical characteristics of authentication Key commercial characteristics of mobile payment authentication Information security risks of mobile payments to consumers Information security risks of mobile payments to the payment system Legislative framework governing payment authentication in Europe Regulation of strong consumer authentication Other sources of EU guidance Legislative framework governing payment authentication in the United States Industry standards governing payment authentication do not exist in the context of mobile payments Competition law and mobile payments 00207Conclusion Electric Utilities: Critical Infrastructure Protection and Reliability Standards Electric Utilities as a part of critical infrastructure Electric utilities as a kind of industrial automation and control system Current state and further evolution of electricity infrastructure – Smart Grid Sources of cybersecurity issues for electric power infrastructure Known cyberattacks on electric utilities Why guidelines and standards for the protection of electric utilities matter The recommended practice: improving industrial control system cybersecurity with defence-in-depth strategies by ICS-CERT of the US Department of Homeland Security The electricity subsector cyber-security risk management process by the US Department of Energy The NERC critical infrastructure protection cybersecurity standards The ISA99/IEC 62443 series of standards for industrial automation and control systems security Electricity subsector cyber-security capability maturity model (ES-C2M2) by the US Department of Energy Critical infrastructure cybersecurity framework by the US NIST and implementation guidance for the energy sector Security for Industrial Control Systems guidance by the UK National Cyber Security Centre Manufacturing Introduction: Genba, Greek mythology and cyber security Think Money Group and UK Financial Services Introduction How severe could the impact of a cyber-attack be? How Should Organisations Tackle the Challenge of Cyber Attacks? Regulator Focus within the UK Other Threats and Challenges Facing Retail Banking Appendix 1 Toward Energy 4.0 The Energy Sector: moving to the age of Smart and Digitalised Markets The Ukrainian case The legal developments in the European Union The NIS Directive and Energy The Clean Energy for all Europeans Beyond the US and the EU The sectorial and silos strategies versus the multi-sector horizontal approach An analysis of the energy sub sectors: strengths, weaknesses and law Conclusions and the way forward Aerospace, Defence and Security Sector Introduction Comparing Civilian and Military Cyber Security Sectors The Digital Age and the Digital Battlespace Offensive Cyber Capability Benefit and Threat Opportunities for the ADS Sector Evolution of the Threat Corporations on the Frontline Example of Proliferation – Stuxnet A new weapon Example of Civilian Infrastructure under attack – Ukraine Power Grid Wider concerns Example of Criminal Attacks at Scale – SWIFT Payment Network Performance of the ADS Sector in Cyber Security Notable cyber security events in the ADS sector Cyber Security in non-Government sectors: Missed Opportunity? Banking – in the Emirates Introduction The People: Building a solid team The Process: Building a program In Closing Healthcare Introduction What is Wannacry? What is ransomware? How the Department and the NHS responded Key findings Practical Points: Prevention and Protection Selling or buying your healthcare practice – things to look out for in the due diligence Medical Devices Introduction Conclusions and recommendations 11. SOCIAL MEDIA AND CYBER SECURITY Introduction What is Social Media and why does it matter? Who are the key social media players? Fake News and why it matters The Weaponising of Social Media Digital profiling Data Protection What is to be done? As individuals or individual businesses, what needs to be done? 12. INTERNATIONAL LAW AND INTERACTION BETWEEN STATES Determining if International Humanitarian Law / Law of Armed Conflict applies Applying Principles of IHL and LOAC NATO Responses United Nations Charter Responses Use of force Armed attack and right of self-defence Non-State actors Cyber Norms as the basis for international law UNGGE Cyber Norms Other norms The future for cyber norms Interaction Between States International Challenges of Cyber-crime Criminalising Transnational Cyber-crime Conventions, Treaties and Mutual Legal Assistance Limitations to Mutual Legal Assistance Case Study: Singapore’s interactions with other States on cyber-issues Cooperation in fighting cybercrime Cooperation in joint activities between ASEAN Member States Cooperation through memoranda of understanding Cooperation in developing international and regional norms 13. SECURITY CONCERNS WITH THE INTERNET OF THINGS Introduction How organisations can secure IoT Industry-wide initiatives for IoT security Future IoT Innovations Future Short-Term Challenges Conclusion 14. MANAGING CYBER-SECURITY IN AN INTERNATIONAL FINANCIAL INSTITUTION The liquid enemy: managing cyber-risks in a financial institution The liquid enemy Foreword Cyber risk, the liquid enemy Coding a financial institution approach to cyber-risks Three lines of defence and cyber-risks Riding the waves: some points for a new approach to risk management of cyber-security Definition of ‘cyber-risk’ as stand-alone category Cyber Risk Appetite Deep and Dark webs: Alice’s mirrors Personal data protection issues Conclusion: Cyber-risks in an era of AI continuity 15. EMPLOYEE LIABILITY AND PROTECTION Overview and introduction of the problem What information is confidential? What information will the courts protect? Advice What protection does the EU offer on trade secrets? What is copyright? UK law and Copyright, Designs and Patents Act 1988 What are the categories of protection in UK law? What does the caselaw offer by way of protection on copyright? The EU and the software directive What is the definition of the functionality of computer programs within the software directive? What protection is there if the progam was created by the employee acting in the performance of his duties? What is permitted under the sotware directive? What protection is offered to databases? What protection of databases is available from EU directives? Is there any protection of databases to protect software? The facts What do these cases teach about proection from employees? Employers’ liability What is being directly liable and can the employer be vicariously liable for the conduct of an ex employee? Directors’ liability for breach of confidence In what ways can a directors libility be imposed? What measures, systems and procedures are sufficient to avoid employer liability? Contracts of employment as a means of protection Conclusion 16. DATA SECURITY – THE NEW OIL Data Security in an age when Data is the new Oil UK ICO Data security incident trends Data Security verses Information Security verses Cyber-Security Data Security verses Information Security Information Security (‘InfoSec’) verses Cyber-Security UK Data Security Law Civil Law Data Protection Act 1998 (‘DPA’) General Data Protection Regulation (GDPR) Data Protection Bill (DPB) UK Privacy and Electronic Communications Regulations 2003 (‘PECR’) The Privacy and Electronic Communications Directive 2002/58/EC (the ‘ePrivacy Directive’) and the Proposed ‘ePrivacy Regulation’ Criminal Law Cyber-Dependent Crimes – Offences and Legislation Computer Misuse Act 1990 (CMA) Regulation of Investigatory Powers Act (RIPA) 2000 Investigatory Powers Act 2016 (IPA) Data Protection Act 1998 (DPA) Cyber-Enabled Crimes Cyber-Dependent Crimes – Offences and Legislation The Fraud Act 2006 (Fraud Act) The Theft Act 1968 Conclusion 17. DATA CLASSIFICATION Introduction What is Data? Data Classification The Benefit of the Data Classification Data Classification Process Data Classification: An Example Challenges of Data Classification The Ramification of Failure of Data Classification Scheme Data Classification and Business Impact Analysis (BIA) A Successful Data Classification Program Data Privacy and Security What is Data Security? What is Privacy? Why is Data Security Mistaken for Privacy? Types of Controls Asset Discovery Data Loss Prevention (DLP) Conclusion 18. LIABILITY FOLLOWING A DATA BREACH Liability issues following a cyber-attack The Liability Landscape Technology Threat Actors Evolution of Threats How threat vectors manifest themselves as a potential liability 19. CRIMINAL LAW Introduction Misuse of computers Unauthorised access to computer material – section 1 offence Unauthorised access with intent to commit or facilitate commission of further offences – section 2 offence Unauthorised acts with intent to impair, or with recklessness as to impairing, operation of computer, etc – section 3 offence Unauthorised acts causing, or creating risk of, serious damage – section 3ZA offence Making, supplying or obtaining articles for use in computer misuse offences under section 1, 3 or 3ZA – section 3A offence Jurisdictional issues Malicious Communication and Harassment Cyber-stalking and harassment Trolling Revenge porn Indecent and obscene material Obscene publications and extreme pornography Indecent images of children Data breaches Data Protection Act 1998 Enforcement Criminal offences Defences – section 55(2) Sentencing Data Protection Bill 2018 Fraud Fraud Act 2006 Variants of cyber-fraud Cryptocurrency and Initial Coin Offering fraud The Civil Perspective 20. THE DIGITAL NEXT WAY Cyber Attacks Protecting your business GDPR Steps to update your online security Employee safety Protecting your remote workforce 21. INTELLIGENCE AND THE MONITORING OF EVERYDAY LIFE Introduction Background Surveillance as the Monitoring of Everyday Life Established Surveillance Technologies Technologies of Daily Life Perfect Surveillance Digital Intelligence Privacy and Identity in Digital Intelligence On Privacy and Identity On Digital Privacy Theorising Identity On Identifiers Some Observations on Identifiers Conclusion 22. COLLABORATION: RESULTS? Where we’ve come from and where we’re headed Safety by Design Attempts to standardise Tools of Enforcement Environment of Accountability Accountability The New Standard of ‘Secure’ An Insurmountable Challenge? 23. CYBERSECURITY: THE CAUSE AND THE CURE AND CURE Introduction The Threat Environment Nation States Criminal Groups Hacktivists Insider Threat Securing Your Organisation: Key Controls Asset Inventories Security Testing Network Architecture Integrity Checking Email authentication Patching Third-Party Management Incident Response Training Managing Change Summary 24. MERGERS AND ACQUISITIONS CORPORATE DUE DILIGENCE AND CYBER SECURITY ISSUES The Sins of our Fathers The ‘New Oil’ Un-due Diligence? Warranty and Indemnity Insurance The Observer Effect Oiling the Supply Chain Morrisons and the Disgruntled Insider Conclusions 25. PROTECTING ORGANISATIONS Introduction The UK’s National Cyber Security Strategy Standard Practice PCI DSS Cyber Essentials and Cyber Essentials Plus How Cyber Essentials protects your organisation The Certification Process Cyber Essentials Plus The problem(s) with Cyber Essentials Benefits of Cyber Essentials ISO27001:2013 ISO27001 & ISO27002 Context of the organisation Leadership Planning Support Operation Performance evaluation Improvement Annex A Controls Conclusion 26. PUBLIC PRIVATE PARTNERSHIPS Introduction 27. BEHAVIOURAL SCIENCE IN CYBER SECURITY Introduction Understanding the motivation There is no obvious reason to comply Compliance comes at a steep cost to workers Employees are simply unable to comply How people make decisions Designing security that works Creating a culture of security Conclusion 28. AGILE CYBER SECURITY PROCESS CAPABILITY The Culture Factor Background Introduction Organisation Agility People Process Technology Handshakes, Roles and Responsibilities Discipline Proactive and Reactive Cyber Security Lessons from the Past – The Culture Root Cause Process Capability Define Implement Enable Optimise The Cyber Information Flow From events to the global digital community Foundation Elements of Developing a Playbook Conclusion 29. CYBER SECRET, LIFE SECRETS – ON THE VERGE OF HUMAN SCIENCE Introduction Shades of Secrets Privacy Data Breaches The risk paralysis And then there were bugs Mass Surveillance The Post-Snowden world The world of untrust What’s the solution? 30. A PLAN FOR THE SME Building a small business security risk management plan Where do you start? You are not a big, well known business. Why would anyone attack you? It’s too costly Hasn’t the IT guy(s) already dealt with this issue? Too Complicated? Why you need a formal security program? Current state of security management Security Program Standards and Best Practices Security Program Components It’s really all about risks Case Study Security Risk Management Process 31. CONCLUSION Prevention is Better than Cure Internet of Things will cause more Cyber Attacks and Financial Loss The Rise in Ransonware To Cloud or Not? Can Artificial Intelligence fight back? Appendix 1 Theresa May Speech, Munich Security Conference, February 2018 Appendix 2 Cyber-security lexicon for converged systems Appendix 3 The government’s national response Appendix 4 Sample legal documents Index

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

1809 · PDF