Posts

Showing posts with the label security

The case of “Need to know” vs. "Need to protect" - How widely should we share information?

When discussing knowledge sharing and exchange of material and documents with professionals in charge of information classification policies and standards, the question is often what the "default mode" for an organization should be. Should unclassified information such as documents, articles etc, be treated as “for internal use only” or as “public” information? I want to use this post to affirm my strong conviction that any international development organization has an overwhelming interest in making unclassified information by default public unless it is specifically designated as internal to a specified group of people only (a small group within an organization, or members of the organization as a whole). And here is why: Being an actor in the knowledge business calls for an information policy that fosters the distribution of knowledge, not prevents it. The paradigm of “need to know” is right for an organization whose main concern is the preservation of what it has. But dev...

Don't use Facebook - because of security issues! Really?

Since a few months I get the feeling that public (or media) opinion is shifting towards a more critical position regarding online social netwoking applications like Facebook , MySpace , Orkut , etc., mostly because of privacy and security issues. To one extent the emphasis on a more considerate approach to communicating his own data is definitely desirable. Privacy is an issue and we need to be careful to whom we tell what about ourselfs and where we store and publish which data for which purpose. On the other hand however, I have the impression that there is a current tendency to throw out the baby with the bath water. I actually meet more and more people who in a very strict way say that they would never register on any of these networks, sometimes referring to media news about identitiy theft like recently about Facebook . In my opinion, there is a problem with this thinking, at least as far as security is concerned. The issue with the current security cases rather is that lots of ...