We help to protect your own
Internet security is just like home security. You think about the risks and decide what you want to do about them. This site intention is to give you information about risks first of all and ways to meet them. Unfortunately, there is no way, yet, to get insurance against hackers taking over your PC (just like insurance against common burglary). You have to think about the risks and decide what to do yourself.

SOHO Data Defence

Small and medium business and Privacy regulations in Australia

In addition to all those dangers that awaits every one on the Net, such as computer hijacking, identity theft, productivity and indirect business losses, business in Australia has legal obligation to keep securely all personal data it has. Some small businesses with turnover less than 3 million dollars do not have to comply with the Federal Privacy Act. States have their own privacy legislation (State of Victoria has Information Privacy Act). If you want to verify do privacy legislation's apply to your business please ask appropriate state or federal Privacy Commissioner office or your legal advisor.

Privacy legislation require many things from private businesses but I want to bring up one aspect: Principle 4 - Data security, from National Privacy Principles. It requires organisation to take reasonable care to protect private information. Every business to which privacy legislation apply should think is it taking reasonable care about private information it stores.

What could reasonable care include? It would include technical and organisational means.

From Information System technology side it would be something like these:
  • It definitely has to include properly maintained anti virus product, so the most active sort of malicious software would not be able access private information
  • It has to include professionally configured and monitored firewall, to prevent unauthorised access to private information from the outside
  • It would include (most probably) storing private information in encrypted form, especially if it resides on easily removable carrier, such as floppy disk, CD-ROM or laptop hard drive.
From organisational side it would include:
  • Specific section in company policy or security policy or even special policy on collecting, storing, handling and destroying of private information
  • Means to verify that policy has been enforced

Are you sure that your business is compliant ?

Site news:
  • Site is back and will be updated regularely!
  • Updated: New link in Standards; Why XP SP2 is a MUST, News, Links to free Anti virus added, Dangers updated, Link to the new Personall Firewall review, IPSec advice
  • Added: MS Security Readiness Kit link added , Protection against Computer Hijacking,
  • Energy Secretary fires nuclear security chief apparently for bad information security. More here.
    13 January 2006
    No big virus out breaks for long time.
    3 January 2006