Information Resources Security
Date: November 19, 2003Source: Computer Crime Research Center
By:
Fast development of automation processes, introduction of computers into all spheres of present-day life resulted in some specific problems. Effective protection of the information and reliable means of its processing are some of such problems.
Variety of ways for accessing information, significant amount of qualified experts, wide use of special facilities in social production allow offender to carry out certain actions. These actions threaten to information security both in local and global scales. Infringer may perform these actions practically at any moment and any place.
Growth of decentralization and distributed data processing, that occurred recently, made problems of information security more urgent for national economy [1]. Solving of this problem assumes a complex of actions. First of all they are actions of the government, like developing of information documentation and classification system and ways of protection. Also they include regulation of data access and providing responsibility for violations of information safety.
State policy in sphere of informatization and forming information resources should be aimed at creating conditions for effective and high-quality information supplies allowing to solve strategic and operational tasks of social and economic development.
Basic directions of the state policy in sphere of information are:
• maintaining conditions for development and protection of all forms of information property;
• forming and protecting of state information resources;
• creating and developing governmental and local information systems and networks, maintaining their compatibility and interaction in unified information space;
• creating of conditions for high-quality and efficient information supply of people, public authorities, organizations and funds on the basis of the state information resources;
• maintaining national security in sphere of information, and also realization of rights of citizens, organizations under informatization conditions;
• assistance to forming of the market of information resources, services, information systems, technologies, means of their maintenance;
• forming and realizing the united scientific technical and industrial policy in sphere of informatization in view of a modern global level of information technologies development;
• support of projects and programs of informatization;
• creating and improving of investment strategy and mechanism of development stimulation and information projects realization;
• developing of the legislation in sphere of information processes, informatization and information security.
Information documenting - an obligatory condition for inclusion of information in information resources. Documenting is carried out in the order established by public authorities, responsible for the organization of office work, standardization of documents and files.
The document received from information system, gets validity as it was signed by official in the order established by the law. The validity of the document stored, processed and transmitted with the help of telecommunication and computer based systems, can be proved true by electronic digital signature [2].
The validity of electronic digital signature is admitted at presence of software in information system. This software identifies the signature, and observes the established mode of its use. The right to certify the identity of the electronic digital signature is exercised on the basis of license.
Information resources can be governmental and non-governmental. As element of property structure they can be owned by people, public authorities, local governments, organizations and funds. Any truck concerning the property right on information resources is regulated by the corresponding civil law.
Information resources are the separate documents and document files in information systems (libraries, archives, funds, databanks, and other information systems).
Information processes are the processes of collecting, processing, accumulating, storing, searching and distributing of information.
Information system is an ordered set of documents (document files) and information technologies, also with use of computer and communication facilities that realize information processes.
Individuals and legal entities are the proprietors of those documents, document files, created at their expense, purchased by them on legal basis, received as donation or inheritance.
The state has the right to buy out documentary information from individuals or legal entities in case of referring of this information to the state secret.
The owner of the information resources that contain data, related to the state secret, has the right to dispose it only by authority of corresponding public authorities. Subjects that present documentary information without fail to public authorities and organizations do not forfeit the rights to use it. The documentary information presented without fail to public authorities and organizations by legal entities irrespectively of their legal-organizational form or patterns of ownership and citizens form the information resources in joint possession of the state and subjects, presenting this information.
Information resources can be an article of trade, except the cases provided for by the corresponding law. The property right on means of information processing does not create the property right on the information resources that belong to other owners. The documents processed in the order of services rendering or in joint use of processing means, belong to their owner. Belonging and mode of the derivative product created in this case are adjusted by the contract.
State information resources. Forming of the state information resources is carried out by individuals, public authorities, local governments, organizations and funds.
Documents that belong to individuals and legal entities can be included, at owner’s will, in structure of the state information resources by the rules established for corresponding information systems.
State information resources are open and public. The only exception is documented information attributed by the law to a category of restricted access.
Documented information with restricted access on conditions of its legal mode is divided into information related to the state secret, and confidential.
Personal data is related to a category of confidential information. Collecting, storage, use and distribution of information on private life, also information that breaks personal or family secret, privacy of letters, telephone conversations, post, cable and other messages of individual without his consent, except it is performed on the basis of court order, are not permitted.
The personal data cannot be used for purpose of causing property and moral harm to people, difficulties of their rights and liberties realization. Restriction of civil rights on a basis of information using concerning their social origin, racial, national, language, religious and party belonging is forbidden and punished according to the law.
Information is data on persons, subjects, facts, events, phenomena and processes irrespective of their representation form.
Informatization is organizational, social and economic, scientific and technical process. It concerns optimal conditions creation for satisfaction of information needs and realization of rights of citizens, public authorities, local governments, organizations, funds on the basis of maintenance and usage of information resources.
Information on people (personal data) - data on facts, events and circumstances concerning life of a citizen, allowing to identify his personality.
Natural persons and legal entities that have information on people, receiving and using it, bear responsibility for infringement of protection, processing and order of use of this information according to the legislation.
It is important to consider possible infringements of legitimate rights and interests of citizens while solving legal problems during introduction of modern information technologies. Such issues occur due to unfair behavior of users, e.g. unauthorized use of information (unauthorized official or stranger) or its intentional distortion [3].
Process of improving democracy assumes further development of rights guarantees for all citizens from possible abuses on the part of officials. As in field of information protection, still there is a lot of uncertainty about the person.
Certainly the trend of growing number of information types on the person accrued by data banks is objective, it is determined by increase of a role of information in solving global manufacture and welfare problems. However it is obvious that collected data should be limited: first, by the most necessary data only; second, by real possibility of making harm to legitimate interests of citizens on whom information is collected. Appearance of large electronic information systems accumulating huge files of such data, allows to create rather concrete image of the person and to develop the corresponding control system. It is possible to create such system not only for the separate person, but also for group of...
Add comment
Email to a Friend
Next