Information Security and Privacy

Measuring Security and Trust in the Online Environment: A View Using Official Data

13-Feb-2008

This paper reviews available official statistics on trust and security in the online environment. It discusses whether security concerns are an obstacle to Internet use and examines how people and companies protect their equipment and networks.

Radio-Frequency Identification (RFID): a Focus on Information Security and Privacy

24-Jan-2008

The increasing deployment of RFID brings significant economic promise. But is RFID sufficiently secure and privacy-friendly? This report clarifies the capabilities and limitations of RFID, identifies the information security and privacy challenges it can raise, and suggests measures and safeguards that can be implemented to address them.

OECD Council adopts recommendation on electronic authentication

06-Jul-2007

The OECD Council has adopted a Recommendation calling on Member countries to establish compatible, technology-neutral approaches for effective domestic and cross-border e-authentication of persons and entities. The key role of e-authentication in fostering trust online and the continued development of the digital economy is reaffirmed. Guidance on e-Authentication has also been developed to assist Member countries and non-Member economies in establishing or amending their approaches with a view to facilitating cross-border authentication.

OECD governments agree on a framework for privacy law enforcement co-operation

13-Jun-2007

Embodied in a new OECD Recommendation, the framework reflects a commitment by governments to improve their domestic frameworks for privacy law enforcement to better enable their authorities to co-operate with foreign authorities, as well as to provide mutual assistance to one another in the enforcement of privacy laws.

The Development of Policies for the Protection of Critical Information Infrastructures (CII)

29-Mar-2007

The 2006 OECD study offers an analysis of the CII security policies in four countries - Canada, Korea, the United Kingdom, and the United States - with a focus on the drivers for and challenges to their development. It examines each country’s definition of the CII, risk management strategies, frameworks and policies, challenges to information sharing, and cross-border cooperation for addressing the risk to the CII. The report also identifies commonalities and differences in policies for protecting the CII across the countries. The study is expanded in 2007 to 3 additional countries.

Evolution in the Management of Country Code Top-Level Domain Names (ccTLDs)

23-Nov-2006

This document quantifies ccTLD registrations and demand; trends in administering ccTLDs; current and ongoing policy and technical issues such as internationalised domain names (IDNs), Whois, or security, and ccTLD managers’ institutional relationships.

Cross-border Enforcement of Privacy Laws

20-Oct-2006

The OECD has undertaken an examination of challenges posed by cross-border aspects of privacy law enforcement. As a first step, a Report on the Cross-border Enforcement of Privacy Laws has been released. It examines the law enforcement authorities and mechanisms that have been established with a particular focus on how they operate in the cross-border context. It describes existing arrangements to address the challenges and identifies a number of issues that require further consideration.

Making Privacy Notices Simple: an OECD Report and Recommendations

24-Jul-2006

Privacy notices are an excellent tool to disclose an organisation's privacy practices and policies. Research suggests, however, that many notices are too lengthy, confusing, and contain complex legal language. This report recommends that privacy notices be short, simple and usable to make it easier for individuals to assimilate the information they contain and to compare the privacy practices of the organisations processing their personal data. Also see the annexes to this document.

Radio-Frequency Identification (RFID): Drivers, Challenges and Public Policy Considerations

13-Apr-2006

RFID touches on several regulatory and/or policy issues with potentially wide-ranging social, economic, as well as national security implications, including international trade, intellectual property rights, standards, spectrum, security, and privacy.

The Promotion of a Culture of Security for Information Systems and Networks

21-Dec-2005

This report is a major information resource on governments’ effective efforts to date to foster a shift in culture as called for in the OECD Guidelines for the Security of Information Systems and Networks: Towards a Culture of Security (2002). It includes a detailed inventory of initiatives to implement the Guidelines in 18 OECD member countries and highlights main findings based on an analysis of common current trends in those countries and progress made since 2003.

Privacy Online

To assist governments, businesses and individuals in promoting privacy protection online at both national and international levels.

Privacy Online: OECD Guidance on Policy and Practice

Security Guidelines

Now available for download in several languages.

OECD Guidelines for the Security of Information Systems and Networks: Towards a Culture of Security (2002)

Privacy Guidelines

Includes the "Declaration on Transborder Data Flows" and the "Ministerial Declaration on the Protection of Privacy of Global Networks".

OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data