One of the latest trends that are emerging in the contemporary technological landscape is known Cloud Computing. In order to facilitate intercommunication business and promote job development anywhere in the world, companies incorporate this new feature, allowing the use of applications located on a web server with Internet access through . In this sense, for example, an employee of an entity may conduct its business work in the office, such as directly into a sales call, no need to have at all times of their own work tools.
However, all these advantages that this new Web technology can be seen overshadowed by the risks that can imply in case you make a bad tool use or lack of enforcement of security measures relevant enabling extreme protection of information.
In response to the characteristics of this type of technology, special consideration should be taken of the risks inherent therein about the loss of information, lack of integrity, or improper access to it by unauthorized purpose. A
specific legislation, which is primarily intended to protect and regulate the processing of personal data and, therefore, also the business information contained in these web applications or "in the cloud ." This is the familiar rules on data protection, namely the Law 15/1999 of December 13, Protection of Personal Data (Act), and the Royal Decree 1720/2007 of December 21, by approving the regulation development LOPD (RDLOPD). That legislation
provides a series of security measures technical and organizational in order to ensure data security, breach of which may lead to a number of sanctions warranted. Such measures should highlight those eminently technical, such as, for example, the establishment of systems for identification and authentication of users, thus allowing to establish a logical access control information, ie avoiding an improper access by unauthorized personnel for this purpose, the definition of procedures for making backups, at least weekly, or, for example, the establishment of encrypted information when appropriate to transmission over public networks. It is worthwhile emphasizing that such measures under the rules aforesaid, vary depending on the type of data being processed , becoming much more restrictive as data involving or punishable by a higher sensitivity, see for example, health data , union affiliation, religion, beliefs ...
In this sense, it includes the requirement that software products intended for automatic processing of personal data should technical description included in the security level assigned , depending on the type of data being processed.
But not only should be addressed to the local rules, but given the nature of such services is very likely that we find ourselves before an international data transfer, since many web applications will end up placing on foreign servers. The International Data Movement, is regulated in the legislation on data protection, specifically in the Instruction 1 / 2000 of 1 December the English Agency for Data Protection , which as a rule prohibiting the international transfer of data to countries that do not provide a level of protection comparable to that provided in the Data Protection Act, without the prior permission of the Director of the English Agency for Data Protection, subject to certain exceptions under the relevant legislation. Likewise, it also includes the obligation of compliance certain requirements such as the duty of information and notification by the transfer to the English Agency for Data Protection. The
countries that are considered safe because they provide a level of protection comparable to that of the English laws are all states of the European Union and Argentina, Iceland, Liechtenstein, Norway and Switzerland . Moreover, both U.S. organizations are adhering to the "safe harbor" which are special rules to ensure data protection as Canadian entities subject to the scope of the Canadian data protection are considered to have an adequate level of protection and need not seek permission from the Director of the English Data Protection Agency Data.
When hiring a "in the cloud require the supplier should guarantee where they are located on servers that we provide the service, especially when dealing with applications where data are introduced personal character of any kind. Before investment is important to know the situation in which we find, since the breach of data protection measures high carries fines ranging from 60,000 to 600,000 euros . In any case, the safest option always hire the services that we ensure that the servers on which data is stored are located in our country or in one of the countries that provide a level of protection comparable to English law or in the case of the U.S. or Canada, entities that meet requirements to ensure this protection.
0 comments:
Post a Comment