10.06.2013 Views

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Study</strong> <strong>into</strong> <strong>the</strong> implications <strong>of</strong> <strong>Smartphone</strong> operating system security<br />

Table ES5: UK legislation and <strong>Smartphone</strong> security<br />

<strong>Smartphone</strong> security risk Applicable<br />

legislation<br />

Unpatched <strong>Smartphone</strong> Unclear Unclear<br />

Lost and stolen <strong>Smartphone</strong> (leading to<br />

potential loss <strong>of</strong> privacy, identity and<br />

data)<br />

Telephony Financial (Premium Rate<br />

Services) fraud<br />

Loss <strong>of</strong> privacy (due to Spyware and<br />

Malware<br />

Criminal law for<br />

<strong>the</strong>ft<br />

Data Protection<br />

Act<br />

Communications<br />

Act 2003<br />

PhonepayPlus<br />

Code <strong>of</strong> Practice<br />

Data Protection<br />

Act 1998<br />

Communications<br />

Act 2003<br />

Computer<br />

Misuse Act 1990<br />

(Police and<br />

Justice Act<br />

2006)<br />

Financial services (banking) fraud Financial Fraud<br />

Act 2006<br />

Institution Responsible<br />

Shared between:<br />

Police Service<br />

The ICO<br />

FSA<br />

PhonepayPlus<br />

PhonepayPlus<br />

Ofcom<br />

The ICO<br />

Ofcom<br />

CPS<br />

FCA & PRA<br />

National Fraud<br />

Authority (NFA)<br />

Source: Goode Intelligence © 2013<br />

Ofcom has a statutory duty to fur<strong>the</strong>r <strong>the</strong> interests <strong>of</strong> citizens in relation to communications<br />

matters. Ofcom is also guided by a regulatory principle to research markets constantly and<br />

aims to remain at <strong>the</strong> forefront <strong>of</strong> technological developments.<br />

Goode Intelligence believes that current legislation should be sufficient in dealing with<br />

current <strong>Smartphone</strong> security issues. There does not seem to be any major holes in current<br />

legislation that could result in a disparity between <strong>the</strong> technology and <strong>the</strong> governing<br />

framework.<br />

However, this must be constantly reviewed in light <strong>of</strong> emerging, sometimes disruptive,<br />

technology that could alter <strong>the</strong> effectiveness <strong>of</strong> regulation and legislation.<br />

Related to legislation is education (engagement) and enforcement; educating affective<br />

parties as to <strong>the</strong> nature <strong>of</strong> legislation by engaging with all parts <strong>of</strong> <strong>the</strong> ecosystem and<br />

enforcement once <strong>the</strong>re has been a breach (ei<strong>the</strong>r intentional or unintentional).<br />

There is a question on whe<strong>the</strong>r providers <strong>of</strong> <strong>Smartphone</strong> services, including <strong>the</strong> <strong>Smartphone</strong><br />

OS vendors, <strong>Smartphone</strong> OEMs and mobile app developers (including suppliers <strong>of</strong> OTT<br />

services) are adequately regulated.<br />

Goode Intelligence © 2013 P a g e | 24 www.goodeintelligence.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!