Information Security and Privacy

The OECD Working Party on Information Security and Privacy (WPISP) develops policy options to sustain trust, information security and privacy in the global networked society. This page is directly accessible at www.oecd.org/sti/security-privacy

What's new

Policy brief: The future of the Internet economy

06-Jun-2008

Major changes are affecting the scope and scale of the Internet. As a result, the Internet is increasingly high on the policy agenda in many OECD and non-OECD countries. This policy brief reviews likely future developments in the Internet economy and how policy-makers can help the Internet to adapt to evolving requirements caused by convergence, continue to drive innovation, and be trustworthy.

Malware: A Security Threat to the Internet Economy

29-May-2008

Malware has evolved from occasional “exploits” to a multi-million dollar criminal industry. This report informs policy makers about the evolution and impact of malware, as well as the counter-measures being taken. It concludes with suggestions for greater co-operation across the various international communities addressing malware.

Economics of malware: Security decisions, incentives and externalities

29-May-2008

While originating in criminal behaviour, the magnitude and impact of the malware phenomenon is also influenced by the decisions and behaviour of legitimate market players. This working paper is based on qualitative empirical research into the incentives of market players when dealing with malware.

At a Crossroads: "Personhood" and Digital Identity in the Information Society

03-Mar-2008

This paper discusses the relationship between the development of digital identity management and the concept of personhood, and the broader links to trust in the information society. It concludes that more investigation is needed to address gaps in international data protection in light of the emergent identity infrastructure.

Measuring Security and Trust in the Online Environment: A View Using Official Data

13-Feb-2008

This paper reviews available official statistics on trust and security in the online environment. It discusses whether security concerns are an obstacle to Internet use and examines how people and companies protect their equipment and networks.

Radio-Frequency Identification (RFID): a Focus on Information Security and Privacy

24-Jan-2008

The increasing deployment of RFID brings significant economic promise. But is RFID sufficiently secure and privacy-friendly? This report clarifies the capabilities and limitations of RFID, identifies the information security and privacy challenges it can raise, and suggests measures and safeguards that can be implemented to address them.

OECD Council adopts recommendation on electronic authentication

06-Jul-2007

The OECD Council has adopted a Recommendation calling on Member countries to establish compatible, technology-neutral approaches for effective domestic and cross-border e-authentication of persons and entities. The key role of e-authentication in fostering trust online and the continued development of the digital economy is reaffirmed. Guidance on e-Authentication has also been developed to assist Member countries and non-Member economies in establishing or amending their approaches with a view to facilitating cross-border authentication.

OECD governments agree on a framework for privacy law enforcement co-operation

13-Jun-2007

Embodied in a new OECD Recommendation, the framework reflects a commitment by governments to improve their domestic frameworks for privacy law enforcement to better enable their authorities to co-operate with foreign authorities, as well as to provide mutual assistance to one another in the enforcement of privacy laws.

OECD Workshop on Digital Identity Management (IDM) - Trondheim, Norway

from 08-May-2007 to 09-May-2007

This workshop, organised by the OECD and hosted by the Norwegian Ministry of Education and Research and Ministry of Government Administration and Reform, brought together experts from government, industry and civil society to explore the main information security and privacy issues surrounding digital identity management. Proceedings are available.

APEC TEL and the OECD hosted joint workshop on malware

from 22-Apr-2007 to 23-Apr-2007

This workshop, held in Manila, Philippines, was the first part of joint work on the subject of malware being undertaken by the Asia Pacific Economic Cooperation (APEC) Telecommunications and Information Working Group (TEL) and the OECD. Proceedings are available.

See more news and events… Top of page

OECD Guidance and Reports on RFID

RFID guidance and reports

The Future Internet question

Tell leaders what you think!

Keep informed!

Keep abreast of the latest in ICT policy.

Receive your copy of OECD Information and Communication Policy News

Privacy Online

To assist governments, businesses and individuals in promoting privacy protection online at both national and international levels.

Privacy Online: OECD Guidance on Policy and Practice

Security Guidelines

Now available for download in several languages.

OECD Guidelines for the Security of Information Systems and Networks: Towards a Culture of Security (2002)

Privacy Guidelines

Includes the "Declaration on Transborder Data Flows" and the "Ministerial Declaration on the Protection of Privacy of Global Networks".

OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data