Share these talks and lectures with your colleagues
Invite colleaguesPreparing for the implementation of reporting requirements from new EU and UK product and cyber security legislation
Abstract
This paper analyses the reporting requirements of upcoming European Union (EU) and UK cyber security and product security regulation. The assumption is that more regulation is forthcoming. The objective of the paper is to present ideas on how an organisation can prepare itself for reporting even when it is not known what must be reported, how and to whom. The paper asserts that it is possible to create a system which can be used for such reporting.
The full article is available to subscribers to the journal.
Author's Biography
Gaus Rajnović Damir (Gaus) Rajnović has been actively involved in the computer security arena, mainly incident response and coordination, since 1993. He joined Cisco a few months before the Y2K event and spent the next 13 years working on product security-related matters within Cisco and in the industry as a whole. Gaus currently works for Panasonic as a Senior Cyber Security Manager for the European region. This encompasses product security (design and vulnerability handling) and internal IT security. Additionally, he is part of the team that formulates Panasonic policies and strategies for the European Union (EU) region in areas of security and privacy. His external engagements are focused on improving general security and product security through organisations such as the Forum of Incident Response and Security Teams (FIRST) and the Global Forum on Cyber Expertise (GFCE). Additionally, Gaus acts as a subject matter expert in standard-setting organisations such as the International Organization for Standardization (ISO) and the Internation Telecommunication Union (ITU), where he works on standards related to cyber security, product security and vehicle cyber security engineering. He was an invited lecturer for the MSc Information Technology Security course at Westminster University in 2007–09 and the author of a book Incident Response and Product Security published by Cisco Press.