Ms Joyce Tam, Principal Assistant Secretary for Information Technology and Broadcasting Presentation on Multi-application Smart ID Card to the Information.

Slides:



Advertisements
Similar presentations
General Insurance Statistical Agency (GISA) Presentation to Ontario Conference of Casualty Actuaries November 9, 2005.
Advertisements

Ms Joyce Tam, Principal Assistant Secretary for Information Technology and Broadcasting Presentation on “Developing an E-Government” to IIAC Members Thursday.
Introducing the Administrative Data Research Network Tanvi Desai.
AMSRO Leaders Forum 2014 Presentation by Timothy Pilgrim to AMSRO Sydney, Thursday 20 March 2014.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
1 Entertainment Special Effects Bill Information Technology and Broadcasting Bureau.
© 2003 IBM Corporation Preparing for Privacy Society of Internet Professionals January 19, 2004 Nigel Brown Senior Privacy.
Data-Sharing and Governance Consultation ANALYSIS OF RESPONSES.
PRIVACY COMPLIANCE An Introduction to Privacy Privacy Training.
PUBLIC SECTOR INTERNAL AUDIT IN THE REPUBLIC OF LITHUANIA Mr. Jonas Vaitkevičius Head of Internal Audit and Financial Control Methodology and Monitoring.
1 Review of the Electronic Transactions Ordinance Information Infrastructure Advisory Committee 9 April 2002.
The Health and Social Services Access Card: What will it mean for Australians? Financial Literacy, Banking and Identity Conference 25th and 26th October.
Security Controls – What Works
Institute of Municipal Finance Officers & Related Professions
Electronic Authentication for Flexible Learning Workshop Presentation (5 August 2003) Chris Connolly, CEO, Galexia Consulting.
ITIC PERSPECTIVE ON THE EFFECTIVE IMPLEMENTATION OF THE FCTC PROTOCOL ELIZABETH ALLEN ITIC – JULY 2014.
ZHRC/HTI Financial Management Training
Minnesota Law and Health Information Exchange Oversight Activities James I. Golden, PhD State Government Health IT Coordinator Director, Health Policy.
BRIEFING TO THE PORTFOLIO COMMITTEE ON THE DPSA’S RISK MANAGEMENT STRATEGY PRESENTATION TO THE PORTFOLIO COMMITTEE 12 MAY
Non-immigration Applications for Incorporation into the Smart ID Card Information Technology and Broadcasting Bureau 20 December 2001.
1 Smart Card – EMV – Security – Internet 10 June 2002 Presentation by Mr. Alan Siu Deputy Secretary for Information Technology and Broadcasting Government.
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
Workshop on Health Examination Surveys (HES) Legal and ethical issues Susanna Conti, M. Kanieff, G. Rago Istituto Superiore di Sanità (ISS) (National Public.
Presented by: Act DIRECTOR-GENERAL Date: 04 AUGUST 2015 STATUS/PROGRESS REPORT ON NELSON MANDELA MUSEUM 2015.
Information Sharing Sheila Logan Information Commissioner’s Office Employability Partnership Event Glasgow 13 August 2009.
The University of California UC Financial Management Jim Corkill Controller, Accounting Services & Controls University of California, Santa Barbara November,
NAPHSIS REAL ID Overview June 6, 2007 In support of this key requirement,
1 Office of the Privacy Commissioner for Personal Data Hong Kong SAR Tony LAM Deputy Privacy Commissioner for Personal Data Asian Personal Data Privacy.
Consultation on eco-labelling for fishery products.
Garry Compton Manager Government Authentication ANTA Workshop 05/08/03 Canberra, Australia An update on Commonwealth Authentication.
Manager ethics Business Ethics Infrastructure Slovak University of Technology Faculty of Material Science and Technology in Trnava.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Safeguarding Research Data Policy and Implementation Challenges Miguel Soldi February 24, 2006 THE UNIVERSITY OF TEXAS SYSTEM.
The privacy risks and rewards of distributed identity Conference Presentation (8 September 2003) Surveillance and Privacy 2003, University of New South.
Institutional Review Board Issues for Classroom Research Sharon McWhorter IRB Administrator, The University of Akron (With assistance from Phil Allen,
Introducing the Administrative Data Research Network Tanvi Desai.
1 Office of the Privacy Commissioner for Personal Data Hong Kong SAR Tony LAM Deputy Privacy Commissioner for Personal Data Briefing to Asian Data Privacy.
Indiana Regional Sewer District Association October 26, 2015.
1 Home Affairs Bureau Role in Personal Data (Privacy) Ordinance by NG Hon Wah Principal Assistant Secretary Home Affairs Bureau Hong Kong SAR Government.
Medical Schemes Amendment Bill, 2002 Department of Health Briefing to Portfolio Committee on Health 3 September 2002.
Threat Prevention and Detection (within Critical Infrastructures) under EU Data Protection Legislation– Purpose Specification and Limitation. Laurens Naudts.
Chapter 17: Information Management in Treasury Outline: Basics of E-Commerce EDI Infrastructure Treasury Management Systems (TMSes) Other Issues in Treasury.
E-SIGNED DocFlow SYSTEM in GEORGIAN FINANCIAL SECTOR NANA ENUKIDZE – E-Business Development Consultant.
1 The Privacy Impact Assessment Guidelines Guy Herriges Manager, Information and Privacy Office of the Corporate Chief Strategist, MBS November 2000.
WESTERN PA CHAPTER OF THE AMERICAN PAYROLL ASSOCIATION – NOVEMBER 4, 2015 Risk Management for Payroll.
SADC EMIS EXCHANGE SOUTH AFRICA 17 November 2014 Solveig van Vreden.
Information Sharing & Corporate Governance Dave Parsons, Information Governance Manager, City of Cardiff Council.
Creating a retention schedule 10 July 2014 local.gov.uk/lginformplus.
Privacy and Personal Information. WHAT YOU WILL LEARN: What personal information is. General guidelines for the collection of personal information. Your.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
Reforms in the Albanian Public Procurement System 7 th Regional Public Procurement Forum Tbilisi, Georgia May 16-19, 2011 PUBLIC PROCUREMENT AGENCY 1.
COMMUNITY-WIDE HEALTH INFORMATION EXCHANGE: HIPAA PRIVACY AND SECURITY ISSUES Ninth National HIPAA Summit September 14, 2004 Prepared by: Robert Belfort,
2011 Annual May Workshop The Australian Privacy Law Reform Project: a snapshot Karin Clark 4 May 2011.
Pioneers in secure data storage devices. Users have become more accustomed to using multiple devices, are increasingly mobile, and are now used to storing.
Your partner in service delivery and development
Presentation to Environment Portfolio Committee
BAI PRESENTATION to JOINT OIREACHTAS COMMITTEE on Communications, Climate Action & Environment 8th November
MOBILE INSURANCE AND REGULATORY FRAMEWORKS
Athina Antoniou and Lilian Mitrou
Obligations of Educational Agencies: Parents’ Bill of Rights
UIF ANNUAL REPORT 2005/06 PRESENTATION TO THE PORTFOLIO COMMITTEE
General Data Protection Regulation
GDPR - New Data Protection Regulation
Accreditation Update Regional Municipality of Durham March 15, 2018.
SAPS Audit Committee 26 October 2016.
PRIVACY PRESENTATION TO THE SPRING 2013 CONFERENCE BY HANK MOORLAG
Increasing and Demonstrating value and of Internal Audit
2012 Annual Call Steps of the evaluation of proposals, role of the experts TEN-T Experts Briefing, March 2013.
Student Privacy in the age of big data
Presentation transcript:

Ms Joyce Tam, Principal Assistant Secretary for Information Technology and Broadcasting Presentation on Multi-application Smart ID Card to the Information Infrastructure Advisory Committee Thursday 30 November 2000

Multi-application Smart ID Card Scheme 2 FONG, Ching Ming 出生日期 Date of Birth 女 F Z-A-B-C 簽發日期 Date of Issue (02-00) 方充明

Electronic Authentication Driving Licence Library Card Change of Address Digital Certificate Enhancement of Financial Infrastructure, e.g. e-purse Initial Applications of the Multi-application Smart ID Card 3

We have carried out consultation through the following channels - Legislative Council Security Panel Legislative Council Security Panel Public Hearing Information Infrastructure Advisory Committee District Councils of 18 districts Roving Exhibitions in shopping centres Feedback from the media Public Consultation on the Project 4

Privacy Data Concentration Security Choice of Cardholders Cost of Project Durability of Smart Card Common Areas of Concerns 5

Concerns - The Smart ID Card would infringe data privacy of the cardholders Measures to be taken to address concern - Strict compliance with the Personal Data (Privacy) Ordinance Privacy Impact Assessments (PIA) Close consultation with the Privacy Commissioner Legislative safeguard and introduction of administrative code of practice where necessary Minimal data to be stored on the card Privacy 6

Concerns - Concentration of data on the card may lead to function creep where data would be used for purposes beyond those for which data were originally collected Measures to be taken to address concern - Minimal data to be stored on the card No sharing of databases among different departments Stringent access control to system and database Data on the card to be segregated and encrypted Central monitoring through a steering committee and development of administrative code of practice where necessary Data Concentration 7

Concerns - Smart card is not entirely secure Measures to be taken to address concern - High maturity level of cryptographic technology Adequate risk management measures Experts to conduct security design and audit Compromise of one card will not result in compromise of the whole security regime Minimal data to be stored on the card Sensitive data to be stored in backend systems of Government departments as at present Security 8

Concerns - Cardholders may not have genuine, voluntary and non-discriminatory choice on the additional applications Measures to be taken to address concern - Measures to ensure genuine and non- discriminatory choice Driving licence is likely to be the only possible exception as it would be confusing to have two types of driving licence Choice of Cardholders 9

Concerns - Cost of project at $3.06 billion is expensive Justification The cost is for replacement of the whole ID card system and the individual cards The cost is well-justified by the benefits (higher security level, auto-immigration clearance, greater convenience provided by the additional applications) The cost differential for smart card against non- smart card is about 10% The cost differential for multi-application smart card against immigration-only smart card is also about 10% Cost of Project 10

Concerns Smart card not durable and cannot last for 10 years as purported Measures to be taken to address concern - Strong card materials - Polycarbonate will be used Guaranteed minimum life of 10 years 100, ,000 read/write access Durability of Card 11

Looking Ahead Open Forum organised by Hon. Emily Lau (1 Dec) Motion Debate at Legislative Council (6 Dec) Forum organised for the IT sector by Hon. SIN Chung-kai (Jan) Seeking funding approval from Finance Committee (Jan) System development ( ) Card issue and replacement ( ) * * Essential legislative amendment to be made before card issue 12

Thank you