Publications
The impact of changes to Australian Privacy Law on Small Businesses
The Australian Law Reform Commission (ALRC) is reviewing Australia's privacy laws to see whether they are sufficient and relevant in today's world. One of the major changes anticipated is that the Privacy Act may soon apply to previously exempt small businesses. This paper discusses who will be affected by this change and some of the changes businesses would need to make to comply with the new law.
Securing the virtual team
Todays business environment is becoming increasingly mobile, and along with the advantages of a flexible workforce come some security challenges. Companies must ensure that their sensitive information and systems are protected from a whole new range of threats. This paper walks you through the issues, and provides some practical advice on how to secure your organisation's virtual team.
Mergers and Acquisitions
Protecting your information assets during the sale of a business unit - or a merger with another organisation - can be a tricky business. This discussion paper guides you through some of the things the parties involved need to look out for, and provides advice on how to minimise your risk during this period.
Demystifying key management
The increasing use of cryptography in business applications has resulted in an increase in the number of keys used within an organisation. They need to be managed properly to ensure that key material does not fall into the wrong hands, and that keys with expiry dates are renewed before they expire and block access to your website or some other business critical system. This paper explains what is meant by key management, how to identify your keys, and how to protect them.
What is PKI?
This paper provides some insight into public key infrastructure and technology more generally. It is targeted at people who are new to the area or have read a little and are thoroughly confused by the myriad terms and acronyms.
PKI In-sourcing versus Outsourcing: A Discussion of the Relative Merits
One of the more common questions Castelain are asked to provide advice on is whether or not an organisation should outsource its PKI infrastructure. A lot depends on the organisation and its tolerance for risk! This paper outlines some of the complex arguments for and against and lists issues that need to be considered in negotiating outsourcing PKI systems.