Friday, 23 November 2007

Can we salvage something from this?

Can we get the government on board with some of the thinking in the real world about data security after this calamitous data loss?
After a series of security breaches involving databases of Credit Card data the card issuers started working on security standards, these have now coalesced into PCI DSS a minimum security standard that you have to adhere to if you want to process credit card data, full stop. Very soon this will be a non-negotiable requirement, play ball or don't get paid. Should the banking industry now produce a similar standard for those holding bank account details. Either your systems conform to x level of security or you don't get to use BACS or set up direct debits etc. The government would probably ask for many years and give much money to those such as EDS and Capita in order to get compliant, but wouldn't it all be worth it?
On the other hand from the geek half of the real world I am thinking of sending them a guide to how asymmetric cryptography works. With some recommendations on key lengths to use.

2 comments:

Jennifer Beals said...

Absolutely! It’s always possible to salvage something from a challenging situation, especially when you have the right support. In my experience with ghostwriting services, I’ve found that even the roughest drafts can be transformed into something exceptional with a bit of guidance and expertise.

jeffmiller said...

This raises an important point about making security standards mandatory instead of optional. Stronger regulations could help prevent future data breaches and rebuild public trust. Just as an autobiographical medical book highlights the value of transparency and learning from real experiences, organizations should treat every security failure as an opportunity to improve systems and accountability.