Ograniczanie wyników
Czasopisma help
Autorzy help
Lata help
Preferencje help
Widoczny [Schowaj] Abstrakt
Liczba wyników

Znaleziono wyników: 39

Liczba wyników na stronie
first rewind previous Strona / 2 next fast forward last
Wyniki wyszukiwania
Wyszukiwano:
w słowach kluczowych:  data protection
help Sortuj według:

help Ogranicz wyniki do:
first rewind previous Strona / 2 next fast forward last
EN
This study examines the legal and regulatory challenges in deploying artificial intelligence (AI) within anti-money-laundering and counter-terrorist-financing (AML/CFT) systems in Japan (focal case) and in Germany, France, and Poland (purposive comparators). It identifies intra- and cross-jurisdictional gaps; assesses alignment with FATF Recommendations 1 and 15, the GDPR, and the EU AI Act; and distils transferable best practices. Doctrinal legal analysis and normative comparative methodology were employed, with limited functional observations where supervisory practice is documented. Sources include statutes and regulations, supervisory guidance, and case law issued from May 2015–May 2025, notably the EU AML package (Reg. (EU) 2024/1624; Dir. (EU) 2024/1640; Reg. (EU) 2024/1620) and the AI Act (Reg. (EU) 2024/1689), as well as FATF materials and national guidance (BaFin, CNIL/ Tracfin, JFSA). All jurisdictions permit AI in AML/CFT, yet frameworks remain fragmented and under-specified for algorithmic decision-making. Key gaps concern liability for algorithmic outcomes; tensions between transparency/explainability and tippingoff; and safeguards for automated decisions (GDPR Art. 22). Germany/France show higher supervisory maturity (explainability, auditability, DPIA, human-in-the-loop), whereas Japan/Poland rely chiefly on general data-protection duties with limited AML/ AI-specific guidance, indicating the need for governance-heavy, auditable, human-in-the-loop designs. Better coordination of the AML, AI, and data-protection regimes is required to ensure both effectiveness and fundamental-rights protection. Japan could benefit from EU practices by formalising human-in-the-loop requirements for high-impact AML decisions, mandating DPIAs, enhancing auditability/reporting for high-risk models, and expanding regulatory sandboxing. The EU should continue aligning the AI Act with the AML Regulation (via AMLA guidance), clarifying oversight, documentation, and explainability expectations for AML use cases.
EN
The mismatch between modern technological innovations and traditional approaches to information security can significantly affect the effectiveness of database monitoring systems. This paper examines the ethical and legal aspects of database monitoring, taking into account current regulatory requirements and the importance of maintaining data confidentiality. The study also evaluates the use of each tool to determine their effectiveness in real-world conditions, the possibility of improving the functional characteristics of monitoring systems, their adaptation to new technologies and increasing the overall level of information protection.
PL
Niedopasowanie nowoczesnych innowacji technologicznych do tradycyjnych podejść do bezpieczeństwa informacji może znacząco wpłynąć na skuteczność systemów monitorowania baz danych. W niniejszym artykule zbadano etyczne i prawne aspekty monitorowania baz danych, biorąc pod uwagę obecne wymogi regulacyjne i znaczenie zachowania poufności danych. W badaniu oceniono również wykorzystanie każdego narzędziaw celu określenia ich skuteczności w warunkach rzeczywistych, możliwości poprawy cech funkcjonalnych systemów monitorowania, ich dostosowaniado nowych technologii i zwiększenia ogólnego poziomu ochrony informacji.
EN
The construction sector project, from start to finish, can be overwhelming because of the large amount of data produced. This data must be managed effectively to ensure the project’s successful completion. One key way to do this is through data governance (DG), an aspect often overlooked. This study aimed to assess how data governance affects data management in the South African construction industry. A quantitative research approach was used, collecting data from various construction professionals via a Google Forms survey distributed through platforms such as LinkedIn. Participants included quantity surveyors, architects, construction project managers, construction managers, and engineers working in firms based in South Africa’s Gauteng province. A simple random sampling technique was used to ensure equal representation. Out of 300 surveys sent out, 200 were completed and returned. The data was analysed using exploratory factor analysis, standard deviation, and mean item score. The concept of data governance is based on the Data Management Body of Knowledge, which stresses accountability for all data management activities. Findings indicated that data governance mainly influences data management through data maturity assessments and data policies. The study concluded that when these elements are well integrated into data management practices, they can greatly improve the effectiveness of construction project data management, especially when stakeholders are involved in the governance process. Therefore, it is recommended that data policies, such as the Protection of Personal Information Act, be incorporated into construction regulations and codes of practice.
4
Content available Earnings in the data protection industry
EN
Earnings for data protection specialists are becoming increasingly popular and important as more and more organisations realise the need to have specialists who are responsible for protecting their data. In this article we will discuss the earnings of dataprotection professionals, what qualifica-tions and skills are needed to earn well in this field, and what the career and earnings prospects are for professionals in this field. We will also an-alyse the various factors that can affect the salary of data protection spe-cialists, such as experience, industry and present data from the labour market.
PL
Kryptografia postkwantowa oferuje rozwiązania mające na celu ochronę danych przed potencjalnymi zagrożeniami wynikającymi z rozwoju komputerów kwantowych. Niniejszy artykuł analizuje globalne wysiłki i strategie wdrożenia tego rozwiązania, skupiając się na działaniach Unii Europejskiej oraz postępie prac w Polsce. Szczególną uwagę poświęcono projektowi PQ- REACT, który ma na celu rozwój i implementację zaawansowanych algorytmów postkwantowych w systemach teleinformatycznych i infrastrukturze krytycznej.
EN
Post-quantum cryptography offers solutions aimed at protecting data from potential threats arising from the development of quantum computers. This article analyzes global efforts and strategies for implementing this solution, focusing on the actions of the European Union and the progress of work in Poland. Special attention is given to the PQ-REACT project, which aims to develop and implement advanced post-quantum algorithms in telecommunication systems and critical infrastructure.
6
Content available remote Rozwój cyberprzestępczości a poczucie bezpieczeństwa użytkowników Internetu
PL
W artykule przedstawiono wyniki badań nad wpływem cyberprzestępczości na poczucie bezpieczeństwa użytkowników Internetu. W badaniach wykorzystano metodologię wywiadu ankietowego, który przeprowadzono z dwiema grupami respondentów - studentami Akademii Sztuki Wojennej w Warszawie kierunku bezpieczeństwo informacyjne i cyberbezpieczeństwo oraz z żołnierzami Oddziału Specjalnego Żandarmerii Wojskowej niezwiązanymi z obszarem IT. W badaniach dążono do poznania, czy ankietowane grupy społeczne, całkowicie odrębne pod względem kwalifikacji w dziedzinie bezpieczeństwa cybernetycznego, mają świadomość zagrożeń cybernetycznych oraz wiedzę o narzędziach i praktykach stosowanych w celu zapobiegania przestępczości w przestrzeni cybernetycznej. Starano się również zweryfikować poczucie bezpieczeństwa badanych w związku z rozwojem cyberprzestępczości. Wykazano, że rozwój cyberprzestępczości istotnie wpływa na zmniejszenie poczucia bezpieczeństwa użytkowników Internetu.
EN
The article presents the results of research on the impact of cybercrime on the sense of security of Internet users. The research uses the methodology of a survey interview, which was conducted with two groups of respondents - students of the War Studies University in Warsaw, majoring in information security and cybersecurity, and with soldiers of the Special Branch of the Military Police not related to the IT area. The research sought to find out whether the surveyed social groups, completely separate in terms of qualifications in the field of cybersecurity, are aware of cyberthreats and the tools and practices applied to prevent crime in cyberspace. Attempts were also made to verify the respondents’ sense of security in connection with the development of cybercrime. It has been shown that the development of cybercrime significantly reduces the sense of security of Internet users.
EN
The paper presents the legal nature and functions of codes of conduct in EU data protection law. The General Data Protection Regulation (GDPR) contains much more extensive provisions on codes of conduct than previous Directive 95/46/EC, giving them a potentially much more significant role in the EU data protection regime. The GDPR specifies codes of conduct as co-regulatory instruments whose compliance by controllers and processors has significant legal consequences. They are primarily intended to facilitate compliance with the GDPR by controllers and processors from a specific sector or to perform similar processing operations. It is, therefore, essential to identify the legal nature of the codes of conduct, the legal consequences of adhering to them, and their function in the EU data protection model. The theoretical analysis of EU data protection codes of conduct considers legal and regulatory theory perspectives.
EN
Purpose: The paper focuses on a trial of defining the assumptions of the fourth industrial revolution and presenting selected applications of modern Blockchain technology. The aim of this article is to draw attention to the growing importance of modern technologies having a significant impact on the development of the world economy and to show the opportunities of their potential introduction to the market. Design/methodology/approach: The article is both theoretical and empirical. Literature research allowed to determine main pillars that Industry 4.0 is based on. From among them, the invention was selected, which has a wide range of impact both on the production environment and on the society. Findings: The article shows the essence of new technologies in the Industry 4.0 and the selected applications of one of them. The article defines the impact of new technologies on economic development and provides a general research of new technologies in new World Economics. Research limitations/implications: Blockchain network is a dynamically developing technology that can be, used in many different areas of life, unfortunately it is still in its infancy and its implementation is very slow. Practical implications: One of the applications of the Blockchain network is the implementation to production systems that make order management more flexible and guarantee non-failure production which is also encrypted. Social implications: Blockchain technology could redefine how people are using public services as daily bases. Originality/value: The article contains description of new technology in modern economics. The article may be useful for researchers working on that subject and or the practitioners trying develop production or services using such invention for their clients.
EN
The strategic importance of information for the functioning of each economic entity forces entrepreneurs to properly protect them against loss, unauthorized disclosure or unauthorized modification. Hence, organizations build complex security systems taking into account state-of-the-art technical solutions, while belittling often the most important element, which is the human factor. It should be emphasized that it is the intentional or accidental actions of the human that can lead to the loss of information security. In addition, it is also the potential of human capabilities and skills can provide an effective defense against the failure or technical security. The article presents the basic stages of human resource management in the aspect of information security. Complementing these considerations will be the presentation and discussion of the results of surveys aimed at assessing the level of employee awareness in the area of information security.
PL
Czy atak socjotechniczny na jeden adres email pracownika podmiotu sektora energetycznego zagraża cyberbezpieczeństwu? Jeśli jest nieskuteczny, to pewnie nie. A jeśli zaatakowanych zostanie pięć tysięcy adresów? Wtedy to już nie ryzyko, tylko statystyka.
EN
The paper presents algorithms for generating a one-time two-factor authentication passwords where application of trigonometric functions have been considered. To protect the opening of a one-time password, a secret string is read that consists of a sequence of randomly generated characters. The second factor is due to the fact that that the code has a certain validity period. The presented password generators allow the formation of secret words and trigonometric functions that the proposed two-factor authentication method consists of. The algorithm presented was implemented in Java Script. The algorithm includes blocks for checking randomly generated words and functions.
PL
W pracy przedstawiono algorytmy generowania jednorazowych, dwuczynnikowych haseł uwierzytelniających, w których uwzględniono zastosowanie funkcji trygonometrycznych. Aby chronić otwarcie jednorazowego hasła, odczytywany jest tajny ciąg składający się z sekwencji losowo generowanych znaków. Drugi składnik wynika z faktu, że kod ma określony okres ważności. Przedstawione generatory haseł umożliwiają tworzenie tajnych słów i funkcji trygonometrycznych, z których składa się proponowana metoda dwuczynnikowego uwierzytelniania. Przedstawiony algorytm został zaimplementowany w Java Script. Algorytm zawiera bloki do sprawdzania losowo generowanych słów i funkcji.
EN
This document presents a conceptual model of a system for protecting thedata stored in publicly available data storage systems. The main idea was toapply encryption on both the client and server sides that would consequentlyhave a significant impact on data security. The compatibility with existingsystems allows us to deploy the solution fast and at a low cost. The testsconducted on a simplified implementation have confirmed the solution’s validity,and they have shown some possible performance issues as compared to theclassical system (which can be easily bypassed).
PL
W artykule przedstawiono współczesne zagrożenia wynikające z przetwarzania danych osobowych w systemach komputerowych z wykorzystaniem technik Big Data na przykładzie wydarzenia o największej w ostatnich latach wadze – Facebook – sprawa Cambridge Analytica. Dzięki ujawnieniu sprawy opinia publiczna otrzymała informacje o metodach wykorzystywanych w przetwarzaniu danych osobowych, ich potencjalnej skuteczności w marketingu biznesowym i politycznym, a także skali i łatwości dostępu do nich. To, co przez wiele lat było oczywiste dla każdego użytkownika Internetu, że wiele drobnych informacji o jego działalności jest gromadzonych przez dostawców różnego rodzaju usług, stało się oczywistością. Użytkownicy otrzymują obecnie szeroki zakres informacji, dostępny dzięki konsolidacji danych przez kilku głównych potentatów oraz ogromnej, powszechnie dostępnej, mocy obliczeniowej. Pozwala to oddziaływać na zachowanie i postawy osób, których dane dotyczą. Przestraszyło to zarówno zwykłych obywateli, jak i rządy. Artykuł stanowi próbę odpowiedzi na pytanie, czy ogólne, unijne rozporządzenie o ochronie danych może przeciwdziałać istniejącym zagrożeniom.
EN
The article presents contemporary threats resulting from the processing of personal data in computer systems using Big Data techniques on the example of an event with the largest in recent years weight – Facebook – Cambridge Analytica case. Thanks to the disclosure of the case, the public opinion received information about the methods used in the processing of personal data, their potential effectiveness in business and political marketing as well as the scale and ease of access to them. What for many years was obvious to every Internet user, that a lot of small pieces of information about his activity is collected by suppliers of various types of services has become a matter of course. However, users now get information what, by consolidating data from several major tycoons, thanks to the huge computing power commonly available, Big Data techniques, machine processing and artificial intelligence can be done with them. How seriously the behavior and attitudes of the data subjects can be influenced. It frightened both ordinary citizens and governments. The article is an attempt to answer whether the EU General Data Protection Regulation is able to respond to new threats.
14
Content available remote Deriving workflow privacy patterns from legal documents
EN
The recent General Data Protection Regulation (GDPR) has strengthened the importance of data privacy and protection for enterprises offering their services in the EU. Important part of intensified efforts toward better privacy protection is enterprise workflow redesign. It has been already found that the privacy level can be raised with applying the privacy by design principle when re(designing) workflows. A conforming and promising approach is to model privacy relevant workflow fragments as Workflow Privacy Patterns (WPPs) which provide abstract, ‘best practices‘ solution proposals to problems recurring in privacy-aware workflows. WPPs are intended to support process developers, auditors and privacy officers by providing pre-validated patterns that correspond with existing data privacy regulations. However, it is unclear yet how to obtain WPPs with an appropriate level of detail. In this paper, we will introduce our approach to derive WPPs from legal texts and other descriptive regulations. We propose a structure of a WPP, which we derive from pattern approaches from other research areas. We also show the steps for designing a WPP. We think that this approach can be an valuable input towards supporting privacy in enterprises.
EN
Cyber risk assessment for insurability verification has been paid a lot of research interest as cyber insurance represents a new dynamic segment of market with considerable growth potential for insurers. As customer’s practices and processes consistently lead to the final overall result, customer's behaviour has to be described in detail. The aim of the present paper is to design an instrument (questionnaire) for customer’s cyber risk assessment in insurability verification. The method for building an instrument (questionnaire) is empirical research. Empirical research is based on use of empirical evidence. A questionnaire with 11 questions is proposed.
PL
Ocena ryzyka związana z bezpieczeństwem cybernetycznym jest przedmiotem dużego zainteresowania badawczego, ze względu na to, że bezpieczeństwo cybernetyczne stanowi nowy, dynamiczny segment rynku o znacznym potencjale wzrostu dla ubezpieczycieli. Ponieważ praktyki i procesy klienta w ciągły sposób wpływają na końcową ocenę, zachowanie klienta musi być szczegółowo opisane. Celem niniejszego artykułu jest opracowanie instrumentu (kwestionariusza) do oceny ryzyka cybernetycznego klienta w ramach weryfikacji ubezpieczenia. Metoda budowy instrumentu (kwestionariusz) to badania empiryczne. Badania empiryczne opierają się na wykorzystaniu dowodów empirycznych. Zaproponowano kwestionariusz składający się z 11 pytań.
17
Content available Sektor energetyczny i cyberbezpieczeństwo
PL
Rosnące ryzyko cyberataków na sektor dostaw energii stwarza dla operatorów systemów informatycznych infrastruktury energetycznej zagrożenie, którego nie sposób zlekceważyć. Problem cyberbezpieczeństwa w energetyce stał się „tematem okładkowym” („cover-story”) wydania specjalnego magazynu firmy medialnej PennWell - Power Engineering International z października 2014 r. Usytuowanie Polski na geopolitycznej mapie świata i realia podjętego przez polską politykę zagraniczną różnorodnego angażowania się w globalną walkę z terroryzmem skłaniają do przyjrzenia się sytuacji, opisywanej przez analityka PEI w formie poradnika ochrony przedsiębiorstw energetycznych, wykorzystującego i komentującego opinie wielu światowych ekspertów w tej dziedzinie.
Logistyka
|
2015
|
nr 4
8072--8076, CD2
EN
Emergency management information systems commonly use modern ICT technologies. A distributed architecture of these systems and extensive use of computer networks necessitate the need to ensure the integrity and the confidentiality of data at each stage of processing. The basic safety functions are security codes and data encryption ones. The author have made review of cryptographic algorithms and developed a specialized program which implements the selected algorithms. The SafetyBox program uses the following encryption algorithms: BlowFish, Twofish, DES, 3DES, AES-128, AES-192, AES-256. Selecting files to protection is very simple because SafetyBox uses the classic file manager. The program can generate reports in PDF format at the end of the encryption / decryption. SafetyBox also allows you to calculate and verify the checksum of files (CRC32, MD-5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256).
PL
Systemy informatyczne zarządzania kryzysowego często korzystają z nowoczesnych technologii ICT. Rozproszona struktura tych systemów oraz powszechne wykorzystywanie sieci komputerowych wymuszają potrzebę zapewnienia integralności i poufności danych na każdym etapie przetwarzania. Autor dokonał przeglądu algorytmów kryptograficznych i opracował specjalistyczny program SafetyBox, w którym zaimplementował wybrane algorytmy kryptograficzne. Program może być przydatny nie tylko do zabezpieczania danych, ale również do analizy zastosowanych w tym celu metod. SafetyBox korzysta z następujących algorytmów szyfrowania: BlowFish, Twofish, DES, 3DES, AES-128, AES-192, AES-256. Wybór plików do zabezpieczenia jest bardzo prosty ponieważ program wykorzystuje klasyczną przeglądarkę katalogów. Program może generować raporty w formacie PDF po zakończeniu szyfrowania /deszyfrowania. SafetyBox umożliwia również obliczanie i weryfikację sum kontrolnych plików (CRC32, MD-5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256).
EN
The article refers to legal and social problems, which may occur while implementing a biometric system. The research on biometric regulation made by the author while preparing the Ph.D. thesis resulted in nding general rules, which should be followed by legislator to introduce a wellfunctioning and user's friendly biometric system.
PL
W artykule przedstawione zostały zasady tworzenia polityki bezpieczeństwa informacji. Uwzględniono zarządzanie bezpieczeństwem informacji w przedsiębiorstwie, co jest podstawą planów bezpieczeństwa IT. Opisane w artykule elementy polityki bezpieczeństwa a informacyjnego kompleksowo obrazują elementy niezbędne do zapewnienia bezpieczeństwa informacji w przedsiębiorstwie.
EN
The article presents the principles of creating an information security policy. Includes management o of information security in an enterprise which is the basis of IT security plans. Described in the article information security policy elements comprehensively illustrate the elements necessary to ensure the safety of information in an enterprise.
first rewind previous Strona / 2 next fast forward last
JavaScript jest wyłączony w Twojej przeglądarce internetowej. Włącz go, a następnie odśwież stronę, aby móc w pełni z niej korzystać.