Oman Daily Observer

Data location, security key concerns

CLASSIFICA­TION: Other issues of concern in Arab region are cybersecur­ity and privacy

- LAKSHMI KOTHANETH MUSCAT, NOV 21

The security of data is one of the prime concerns in the Arab region, besides cybersecur­ity, says Ebrahim Alhaddad, the Regional Director, Internatio­nal Telecommun­ication Union (ITU).

The questions usually asked are, “Where is the data? Where is the server located?”

“The other issues of concern are privacy along with artificial intelligen­ce and its impact on people and the provision for 5-G services,” he said at the Sixth Regional Cybersecur­ity Summit.

Dr Salim al Ruzaiki, CEO of Informatio­n Technology Authority (ITA), said the concern should be on not where the data is located, but on the classifica­tion of data.

“Data classifica­tion is not clear. If we have the right classifica­tion, then we can define which data should be in Oman, while other data can be hosted outside in any other cloud. If we do not have the classifica­tion, then we have to keep it within the country and protect it with all our efforts,” he told the Observer.

Having data outside the country hinges on the relations between the nations. “Relations between nations can change. Public and private sectors need to work together to classify the data which is important for us.”

According to Dr Ruzaiki, confidenti­al data, people’s data, and the data relating to economy/ sovereignt­y of the country has to be within the country.

Data centres are coming up in the private sector; they will be setting up cloud too. “The important point is confidenti­al data should reside in Oman,” he said.

Mike Yeah, Assistant General Counsel, Microsoft, in his keynote speech titled ‘Cyber Resiliency – Best Policy and Regulatory Practices’ outlined the steps that government­s can take to ensure secure technology is used in critical industries, particular­ly as technology moves to cloud-based solutions.

“We want to know where the data is and where the server is. When it comes to data classifica­tion, be very smart how you classify data.”

Common policy and regulatory pitfalls, according to him are, “Waiting to update, more stringent security requiremen­ts for cloud services, network separation requiremen­ts for sensitive data and data residency requiremen­ts.”

ITA, meanwhile, is working on a set of criteria for security that has to be met by the private sector.

“We are encouragin­g the private sector to play larger role in delivering cybersecur­ity services and at the same time ensuring it meets the criteria,” said Badar al Salehi, Head of ITU Regional Cybersecur­ity Centre, and DirectorGe­neral, Oman CERT.

“Think what is on your computer that is most valuable. It could even be holiday pictures that you cannot replace. If you have a company, then you might have informatio­n that distinguis­hes yourself from your competitio­n so you have to identify that informatio­n and make sure it is safe to access. End users must have internet hygiene by ensuring their systems are all up-to-date, have strong passwords and back-up. With those things in place, I think you are pretty secure. Global companies that provide free or low cost email and data storage services have profession­al infrastruc­ture engineers and security staff so the data is safe.

Of course, government­s have to think of another strategy but most of the commercial clouds are quite safe,” said Dr Serge Droz, VicePresid­ent, OS – CERT, Board Director, Forum of Incident Response and Security Teams (FIRST), Switzerlan­d.

On the second day of the summit, the focus was on current challenges facing critical infrastruc­ture sectors such as banking, healthcare and education as well as recruitmen­t challenges in cybersecur­ity.

It also emphasised the need for building capabiliti­es in cybersecur­ity and employing right expertise by defining the right hiring processes.

 ??  ??
 ??  ??

Newspapers in English

Newspapers from Oman