Information and Society
Chapter Four
Property, Privacy and control
4.1. Information as a Property
4.1.1. Major Changes in the Legal Environment
Property refers to Possession. Socially defined ways in which possessions can be
owned and disposed of are gifts, inheritance, barter, Sale. Property law is
formulated for the purpose of prescribing the condition for transfer. Property law
gives owners to control over an item & the ability to sell or license it.
One major change in the information economy is considering information as a
property. It can be owned by individual or by the society. E.g. cultural
information: - it is a collective property. It is produced and shared by every one
in society.
Information always belongs to people in the sense that those who knew
something have used, taught or traded their knowledge for goods and services.
Information as a property involves the right to control the information and gives
full range of protection. Information's good like qualities facilitate ownership. But
exclusive ownership and control is hindered by Intangible features of information
(Reproducibility). This makes information different from traditional good.
Ownership in the areas of electronic information is more difficult. Electronic
information has been removed from the control of their rightful owners because
of the current technology. Due to the technology the information can easily be
reproduced, reworked, transmitted.
In order for information to be sold, law and the social custom must recognize
them as marketable commodities. In this regard several areas of law define
information as a property, but it became difficult to enforce the law. This is
because people consider reading, using or copying some one's information as an
individual right. Therefore, law is inadequate in the areas of property that involve
information.
New legal concepts have been introduced due to considering information as a
property. One of the new legal concept is Information Product Liability. Product
liability laws are laws that hold companies responsible for public safety and
performance “as advertised”. For example If computer Software is considered as
a “good” under the law, Software suppliers could be held liable for damages
caused by Program errors.
Arsi University
1
Information and Society
Computer Professionals could be held liable for malpractices like doctors &
lawyers. Liability insurance is used to protect HW & SW Manufacturers (to cover
the costs of damages their Products might do).
4.1.2. Protecting Information Products
Rights of intellectual property is the means for protecting information Products.
The following are forms of intellectual Property:-
(a) Trade Secret
Trade secret is information about product or process kept secret from
competitors. It includes proprietary information like secret ideas, processes,
designs, formula, techniques, compilations of information (i.e. financial
information, business information, scientific information, engineering
information, etc). Example: Coca Cola formula
Trade secret helps to obtain an advantage over competitors (Competitive
advantage). It is protected through legislation under contract law. The secret is
communicated to as few people as possible. These few people are required to
sign a contract as a condition of their job or business relations that promises not
to reveal the secret. If these people reveal the secret they can be sued for
damages. Once the trade secrete is revealed, whether or not authorized or
intentional or even proper it is no longer protectable as a trade secret.
(b)Patent
Patent right is a form of intellectual property that is ranted to inventors of
innovative processes, machines or devices. It gives the inventor a monopoly in
the use of invention.
A Patent Prohibit others from using the design for 17 years. But it is expensive
and time consuming to obtain it. It requires a full disclosure of the process,
device or the machine being patented to several years in advance of the patent’s
being granted.
Patents protect ideas only when they are implemented in some concrete device.
Patents are not given for abstract intellectual concepts or mental process. Eg.
Mathematical formula …can not be Patented
(C) Copyright
Arsi University
2
Information and Society
In simple terms Copyright is the right to make copies of a work. It is a system of
protection of the original expression of ideas of authors, artists and publishers.
To be copyrightable the work must be a work of authorship, there must be
originality and fixed in a tangible medium. Eg. Unrecorded music is not
copyrightable.
What is not copyrightable?
intangible ideas, concepts
copied ideas, facts, or information
public domain information.
eg. works of government
factual information
Exclusive rights given to authors to control copying & distribution of their work,
modifying their work, display their work publicly, reproducing, perform Publicly
( musical, dramatic, pictorial, sculptural works…).
No one has the right to use copyrighted works in any of the above ways without
the permission of the author.
The Limitations on exclusive Rights mentioned above is the right of FAIR USE. It
is developed in order to protects certain social interest. Like education, news
reporting and commentary (making comments activities of libraries and
archives). This right allows to reproduce the copyrighted work for purposes like
critics, comment, news reporting, teaching and research is not considered as
infringement of copyright.
Factors to be considered in fair use
I. the purpose and character of the use - for commercial /for non profit
educational
II. the nature of the copyrighted work
III. the amount and substantiality of the portion used in relation to the
copyrighted work
IV. the effect of the use upon the potential market for or value of the
copyrighted work.
Copyright in Digital Environment has faced challenges because of increasing
availability of information in electronic format and easiness of reproduction &
distribution due to the technology. Copyright couldn’t adequately protect the
rights and interests of authors in the digital environment.
Arsi University
3
Information and Society
Because of this problem Digital Millennium Copyright Act (DMCA) has developed
to address issues that arise in the electronic environment. It takes copyright
principles in to the digital information age.
The rules of DMCA:
- Prohibit the circumvention of technological protection measures
- Prohibit alteration of Copyright management information imbedded in
digital works
- allowed non-Profit educational institutions to use digital technology for
distance education.
- permit Preservation and storage in a digital format etc .
Ethiopian Case
The following articles of the Ethiopian Constitution consist statements
on intellectual property:
Article 51: Powers and Functions of the Federal Government
No. 19- Federal Government shall patent inventions and protect
copyrights.
Article 55: powers and Functions of House of People’s Representatives
No. 2(e) - the House of Peoples” Representatives shall enact specific laws
on Patent & Copyright.
Article 77- Powers and Functions of Council of Ministers
No. 5- Council of Ministers shall Protect patents and copyright.
The existing copyright law is part of the 1960 civil Code.
- too general- difficult to apply
Ministry of Youth, sports and culture has introduced a new bill providing
copyright protection, but the bill has not been enacted.
Current responsible institution: Patent, Technology & Development Department
Of Ethiopian Science Technology Commission regulates patents & intellectual
property.
4.2. Computer Crime & Security
Computer Crime is criminal act of using a computer. Or its use of a computer
to commit an illegal act. Computer crime includes unauthorized use of the
computer for stealing a user name and password or information by tapping in to
data transmission lines or DBs without payment , money by transferring it from
one bank account to another, goods by diverting the goods to the wrong
Arsi University
4
Information and Society
direction, modifying data, deleting data (an act of vandalism or sabotage),
denying service to authorized users etc. the above stated unauthorized uses of
computers is performed by hackers.
4.2.1 Threats to Information security
Threat is a potential cause of an unwanted event which may result in harm to an
information. From the hacker sitting up until all hours of the night finding ways to
steal the company’s secrets, to the dedicated employee who accidentally hits
the delete key, there are many foes to information security. Due to the many
different types of threats, it is a very difficult to try to establish and maintain
information security. Our attacks come from many different sources, so it is
much like trying to fight a war on multiple fronts. Our good policies can help fight
the internal threats and our firewall and intrusion detection system can help fight
the external threats. However, a failure of one component can lead to an overall
failure to keep our information secure. This means that even if we have well
secured our information from external threats, our end users can still create
information security breaches. Recent statistics show that the majority of
successful compromises are still coming from insiders.
Here are some of Common Information Threats
I. Errors and Omissions
While error and omissions do not get the headlines of international hackers and
the latest work propagating through the e-mail system, it is still the number-one
threat to our systems. Because we cannot deny access to all of the user
community, it becomes difficult to protect our systems from the people who
need to use it day in and day out. To help fight these mistakes, we can use some
of the following security concepts.
The first security concept that will help fight error and omissions is “least
privilege.” If we give our users only the most minimal set of permissions they
need to perform their job functions, then we reduce the amount of information
that can be accidentally contaminated. Using least privilege can create
additional overhead on the support staff members who are tasked with applying
the access controls to the user community.
However, it will be worth the additional changes to keep the integrity of our
information systems.
Another principle that can help is performing adequate and frequent backups
of the information on the systems. When the user causes loss of the integrity of
the information resident on the system, it may be easiest to restore the
Arsi University
5
Information and Society
information from a tape backup made the night [Link] backups are one of
the essential tools of the information security manager and can often be the only
recourse against a successful attack.
II Fraud and Theft
If your end users are not accidentally destroying data but are maliciously
destroying the information, then you may have a completely different type of
attack. For most employees it is difficult to imagine a fellow employee coming
into work every day under a ruse, but it does happen. It becomes very difficult to
find the source of internal attacks without alerting the attacker that you suspect
him of wrong-doing. The best line of defense against fraud and theft by your
internal employees is to have well-defined policies. Policies can make it easier for
the information security manager to collect data on the suspected wrong-doer to
prove what bad acts the employee has performed.
If you have well-defined policies in your organization, the information security
manager can use forensic techniques to gather evidence that will help provide
proof of who performed the attack.
Computer forensics allows a trained person to recover evidence from
computer systems. The first rule of computer forensics is: “do no harm.” This
means that if you are not sure what to do, do not do anything to the system. The
first goal of computer forensics is to leave the system in as pristine condition as
possible.
This may run counter-intuitive to the technology professional whose instincts
want to look at the system to determine exactly what is going on and how it
happened. Every time the technical professional moves the mouse or touches
the keyboard to enter
a command, the system is changing. This makes the evidence gathered from the
system more suspect.
After all, how would one determine what was done by the suspected employee
and what was done by the professional investigating the activity?
There are many places that evidence of the activity may be left. Firewalls,
server logs, and the client workstations are all places that should be investigated
to determine if any evidence remains. When it comes to the client workstation,
the first step in computer forensics is very nontechnical. In this first step the
security or support staff should be contacted to see what details they know
about the system. One of the biggest potential problems would be if the client is
using a hard drive encryption utility.
Arsi University
6
Information and Society
III Malicious Hackers
There are several groups of Internet users out there that will attack information
systems. The two primary groups are hackers and cracker. While common
nomenclature is to call of these groups “hackers,” there are some differences
between the groups. A hacker is a user who penetrates a system just to look
around and see what is possible. The etiquette of hackers is that after they have
penetrated the system, they will notify the system administrator to let the
administrator know that the system has a vulnerability. It is often said that a
hacker just wants security to be improved on all Internet systems.
The next group, the crackers, are the group to really fear. A cracker has no good
manners on breaking into a system. Crackers will damage or destroy data if they
are
able to penetrate a system. The goal of crackers is to cause as much damage as
possible to all systems on the Internet.
The ways a hacker will attack a system can vary tremendously. Each attacker
has his own bag of tricks that can be used to break into a system.
IV. Malicious Code
Malicious code is defined as any code that is designed to make a system perform
any operation without the knowledge of the system owner. One of the fastest
ways to introduce malicious code into a target organization’s protected network
is by sending the malicious code via e-mail.
There are many different types of malicious code. This chapter discusses a few
of the more common ones, including virus, worm, Trojan horse, and logic bomb.
The most commonly thought of type of malicious code is the virus. A virus is a
code fragment, or a piece of code, that can be injected into target files. A virus
then waits, usually until the file is opened or accessed, to spread to another file
where the malicious code is then injected into that file.
There are many different types of viruses; there are viruses that attack the boot
sector of the hard drive, there are file system infectors, there are macro viruses
that use the Office scripting functionality, and there are viruses for all major
operating systems.
Another type of malicious code is the worm. A worm is typically a complete file
that infects in one place on a given system and then tries to replicate to other
vulnerable systems on the network or Internet.
A number of the highly publicized attacks have been worms.
Arsi University
7
Information and Society
Trojan horses are a different type of malicious code and can be quite
deceiving to the end user. A Trojan horse appears to have a legitimate function
on the surface, but also has malicious code underneath. There are a number of
freeware programs on the Internet that allow an attacker to insert malicious code
into most of the common executables. The only way to help stop the Trojan
horses is to educate the end user to not open file attachments unless they know
exactly what the attachment will do.
The final type of malicious code discussed here is the logic bomb.“Logic
bomb” is a generic term for any type of malicious code that is waiting for a
trigger event to release the payload. This means that the code could be waiting
for a period of time (e.g., one month) before it executes. A well-known example
of a logic bomb was the Michelangelo attack. This logic bomb was waiting for
Michelangelo’s birthday before it would trigger the malicious code.
V Denial-of-Service Attacks
As an attacker if you cannot get access to the target network, often the best
thing that you can do is make sure that no one gets access to the network. Enter
the denial-of-service attack. The denial-of-service or DoS attack is designed to
either overwhelm the target server’s hardware resources or overwhelm the
target network’s telecommunication lines. Foryears there were a number of
common “one-to-one” DoS attacks. In theseattacks, the hacker would launch an
attack from his system against the
target server or network. Syn floods, Fin floods, Smurfs, and Fraggles are all
examples of these “one-to-one” attacks. While all these attacks remain
successful on some target networks today, most organizations have
implemented technology to stop these attacks from causing a service disruption
in their organizations.
Zombie hosts are used to create a “many-to-one” attack. These zombie hosts
were devices that were compromised and had code uploaded onto them that
would allow for a master machine to contact them, and have them all release the
DoS attack at the same time. There were tens of thousands of zombie hosts
available and the attacker could use a number of common tools from which to
launch the attack. Some of the common tools were Trinoo, TFN2K, and
stacheldraht. These tools were pretty straightforward to use and allowed an
attacker to release a devastating attack against the target.
The mechanism that has curtailed most DDoS attacks is by trying to minimize
Arsi University
8
Information and Society
the number of zombie-infected hosts available. As soon as a new and better
infection mechanism surfaces, another round of DDoS attacks is sure to spring
up.
IV Social Engineering
Social engineering is the name given to a category of security attacks in which
someone manipulates others into revealing information that can be used to steal
data, access to systems, access to cellular phones, money,or even your own
identity. Such attacks can be very simple or very complex. Gaining access to
information over the phone or through Web sites that you visit has added a new
dimension to the role of the social engineer.
Social engineering is the acquisition of sensitive information or inappropriate
access privileges by an outsider, based upon the building of an inappropriate
trust relationship with insiders. Note that the term “outsider” does not refer only
to nonemployees; an outsider can be an employee who is attempting to
circumvent established policies and standards.
The social engineering exploiter preys on qualities of human nature, such as:
The desire to be helpful. We have trained our employees well. Make
sure the customer is satisfied. The best way to a good appraisal is to
have good responses from those needing assistance. Most of our
employees want to be helpful and this can lead to giving away too
much information.
A tendency to trust people. Human nature is to actually trust others
until they prove that they are not trustworthy. If someone tells us that
he is a certain person, we usually accept that statement. We must
train our employees to seek independent proof. The fear of getting
into trouble.
Too many of us have seen negative reaction by superiors because
verification of identity took too long or because some official was
offended. Management must support all employees who are doing
their assignment and protecting the information resources of the
enterprise.
The willingness to cut corners. Sometimes we get lazy. We post
passwords on the screen or leave important material lying out for
anyone to see.
What scares most companies about social engineers is that the sign of truly
successful social engineers is that they receive what they are looking for without
Arsi University
9
Information and Society
raising any suspicion. It is the bad social engineers we know about, not the good
ones.
A successful defense will require an effective information security architecture,
starting with policies and standards and following through with a vulnerability
assessment process.
[Link] Security
Computer security refers to the protection of computers and the information
contained in them from unauthorized access, damage or modification. It involves
the protection of hardware, software, and information being processed, stored &
communicated.
Computer Security Measures includes:
I. Physical access control.:- This includes using security badges with
photographs, magnetic card readers,(magnetic strips that identify the
individual ) & biological detection methods to restrict access only to
authorized users.
II. Procedural controls use of security guards & locking the computer room-
key is required.
III. Technical controls: - includes
a. Passwords
b. Firewalls. A combination hardware and software buffer
installed between the internal networks and the Internet. A
firewall allows only specific kinds of messages from the
Internet to flow in and out of the internal network. This
protects the internal network from intruders or hackers
who might try to use the Internet to break into those
systems.
c. Cryptography is a coding method in which data is encrypted (in
unreadable format) and decrypted (translated back in to
readable format) using an algorithm . Cryptography is used
to send or store information securely. Strong
authentication using digital signature
d. Closed circuit television surveillance
e. Dial back systems which disconnect external users & calling them
back once their password has been verified.
Arsi University
10
Information and Society
g. Biometric security techniques: (Practical in high security & defiance
organization).
Electronic finger printing scanners read fingerprints of users
every time they press a button with their thumb. The result is
compared against digital files of authorized user fingerprint
records.
Retina scanning a scanner reads the pattern of blood vessels
contained on the back of the human eyeball. The result is
compared against digital files of authorized user blood vessels.
Hand geometry length of figures, thickness of the palm & the
shape of the hand are measured and the results stored for later
comparison.
Signature dynamics focuses on subtle changes in motion and
pressure rather than the appearance of handwriting which can
be forged. The results are compared with records of the
authorized signature
Voice recognition tracks the actual physiology that produces
speech.
Neural Network identification very advanced records are
compiled, based on patterns of nerves in the human face
4.3. Privacy Issues vis-à-vis ICT
Privacy is the right of an individual to be secured from unauthorized disclosure of
information about oneself that is contained in documents or database. It is
freedom from unauthorized intrusion. Individuals have the right to privacy of
data held about themselves and to be anonymous in their interaction with
others.
Privacy is important because individuals can maintain their autonomy and
individuality. People define themselves by exercising power over information
about themselves. It has a functional benefit like Safeguarding safety and peace
of mind. This is good for mental health & creativity. It helps for development of
interpersonal relationships and maintenance of democratic society, etc.
4.3.1 ICT & privacy
ICT is used to invade privacy. This is because:-
The development of ICT is causing exponential growth of personal information
collected and stored by the government and the private sector.
Arsi University
11
Information and Society
o Personal information is usually provided to the government, employers,
insurers, product advertisers, banks, schools, universities, etc.
Private or personal information like income / any financial information, age,
height, weight, family members, marriage status, health information and
genetic information became increasingly public as a result of the technology.
The technology also made these personal information easily accessible and
exposed it to misuse.
With the development of Internet:
o Unauthorized parties can easily monitor one’s activity.
o Personal information can easily be disclosed without the permission of the
individual.
o More and more database can easily be accessed from the Internet.
o powerful search engine and information mining technologies enabled
individuals and institutions:
to electronically cross-link databases containing personal information,
and
to compile extensive information about the person from diverse
sources with a single query.
Connecting your computer to the Internet opens the door for an attack from a
huge number of people on the Internet. Increased use of the Internet exposes
individuals to face identity thieves of:-social security number, address, date of
birth, medical record, etc. In general ICT is a cause for increased invasion of
privacy. It has a negative impact on personal autonomy.
People suffer from humiliation, economic harm and discrimination. Companies
are still making money by selling customer/ personal information.
4.3.2. Factors that contribute to the Invasion of privacy
1. Online communication
"Online communications" are communications over telephone, cable
networks, or wireless systems. Public activities in cyberspace cause invasion
of privacy. Examples of public activities:
a. Newsgroups:- a message is available for anyone to view, copy, and
store. In addition, your name, electronic mail (e-mail) address, and
information about your service provider are usually available for
inspection as part of the message itself.
Arsi University
12
Information and Society
b. Subscriber directories. Most ISPs provide online member directories that
publicly list all subscribers to the service. Some of these directories may
list additional personal information.
c. Domain registration. Many individuals obtain their own website name,
called domain names, for example, [Link]. Domain
registrations are public information. Anyone can look up the owner of a
domain name online by using a service such as [Link]
or [Link]/[Link].
2. Technologies that record virtually all online activities. Some of them are listed
below
(i) Cookies.
Cookies are small text files that Web sites place in your computer to help
your browsers remember specific information. For example, they might store
your passwords and user IDs. Cookies are used so that a Website can
"remember" you the next time you visit it and present you with a customized
page, such as one containing your name.
The web site might also offer you products or ads tailored to your interests,
based on the contents of the cookie data. Most cookies are used only by the web
site that placed it on your computer. But some, called third-party cookies,
communicate data about you to an advertising clearinghouse which in turn
shares that data with other online marketers.
(ii) Web Bugs.
A web bug is a graphic in a web site or an "enhanced" e-mail message that
enables a third party to monitor who is reading the page or message. The
graphic may be a standard size image that is easily seen, or it may be a nearly
invisible one-pixel graphic. The web bug can confirm when the message or web
page is viewed and record the IP address of the viewer. The IP address is a multi-
digit number that uniquely identifies a computer or other hardware device (such
as a printer) attached to the Internet.
(iii)Spyware
A technology that assists in gathering information about a person or
organization without their knowledge. On the Internet, "spyware is a program
Arsi University
13
Information and Society
that is put in someone's computer to secretly gather information about the
user and relay it to advertisers or other interested parties." Spyware is a
cause for public concern about privacy on the Internet.
(iv) Browsers.
Information is transmitted to remote computers by the software you use to
browse web sites. Most web browsers invisibly provide web site operators
with information about your ISP as well as information about other web sites
you have visited. Some web browsers, particularly if they have not been
updated with security fixes, may be tricked into reporting the user’s default e-
mail address, phone number, and other information in the "address book" if
the browser also handles your e-mail.
3. The data gathering and processing practices of commercial firms. Electronic
communication in trading through credit card purchasing and online shopping
or communication by mobile phone
Details of these communications are recorded that allows collection of data at on
unprecedented level of detail. Detailed pictures of customers’ activities can be
built using the current technology.
4. The Government's power to access personal information. Government is also
becoming a potential threat to one's privacy. Government has many tools for
extracting private information from the population and many government
employees have access to this valuable information. A corrupted government
employee could easily misuse the information E.g. - Unauthorized queries in
to taxpayer databases, Employees of the social security administration may
sell confidential government records.
5. Supervisors full access to the employee's activity Due to the development of
ICT. The supervisor can easily monitor every movement and communication
of the employee and this information can be downloaded in to a record of
his/her work habit. What is on the employee's screen and where he/she
wonders on the Internet can also be monitored. The aspects of the personal
life of employees can be monitored while using Internet & e-mail.
4.3.3 Ethiopian Case
The Ethiopian constitution has included article about privacy:
Article 26: Right to Privacy
Arsi University
14
Information and Society
1. Everyone has the right to privacy. This right shall include the right not
to be subjected to searches of his home, person or property, or the
seizure of any property under his personal possession.
2. Everyone has the right to the inviolability of his notes and
correspondence including postal letters, and communications made by
means of telephone, telecommunications and electronic devices.
3. Public officials shall respect and protect these rights. No restrictions
may be placed on the enjoyment of such rights except in compelling
circumstances and in accordance with specific laws whose purposes
shall be the safeguarding of national security or public peace, the
prevention of crimes or the protection of health, public morality or the
rights and freedoms of others.
4.4 Information Policy
4.4.1. Introduction
Information policy is defined as: A set of interrelated principles, laws, guidelines,
rules, regulations, and procedures guiding the oversight and management of the
information life cycle. (production, collection, distribution/dissemination, retrieval
and retirement of information).
Information policy has become one of the most important aspects of public policy
because of:
The growing importance of information as a major factor of production
and wealth creation. Information policy can play a pivotal role in:
industrial and commercial competitiveness;
employment and the creation of high value-added job
opportunities;
lifelong learning and the effectiveness of the education and
training system;
social inclusion and access to services and opportunities;
healthy living and the effectiveness of the National Health
Service;
the efficiency and effectiveness of public services;
participation in the democratic process;
regional development;
Arsi University
15
Information and Society
cultural identity and diversity;
intellectual rights
A growing concern about privacy:
the advances in information technology made the collection,
processing and dissemination of data on individuals very
inexpensive
4.4.2. Areas of concern for a National Information Policy
Three main areas of concern can be identified for a National Information Policy:
i. connectivity,
ii. content and
iii. competencies.
i. Connectivity
Connectivity incorporate ideally three areas which are
a) information networks:- for creating the information networks a policy
should set out a strategic approach to the development of the nation's
information networks. It should provide a framework within which public
and private investment can be planned. It should specify the preferred
approach to regulation to ensure that the networks operate efficiently and
for the public good.
b) Access:- the provision of universal access requires that networks are
available as widely as possible in institutions and homes. The policy
should specify a strategy to ensure access for key organizations and
individuals such as schools, libraries, and those in isolated rural areas.
Pricing strategies should not exclude people from network access.
c) Interoperability:-to ensure interoperability one has to focus on the
different devices making up the ICT. Given the rapidly changing
technological environment, there will be a variety of technologies,
networks and platforms that can be used to deliver information, including
computers, telephones and digital television. The policy should include
provision to ensure that there are no barriers to the citizen from lack of
interconnectivity between the networks.
ii. Content
Content includes the creation of core content, ensuring delivery of this content,
protection of the citizen, and provision of free access to core information.
Arsi University
16
Information and Society
a) Creating of core content:- requires a considerable amount of public
information which has to be provided by public sector institutions together
with the private sector. The policy should, therefore, set out a strategy
that will ensure that public support is available for the development of the
needed information content.
b) Delivery of content:- effective delivery over the networks requires the
development of appropriate information retrieval aids and navigation
tools. Government departments and agencies must look for innovative
ways of presenting information to citizens, cutting across institutional
boundaries. Training and awareness programmes will be required to
ensure target markets are reached efficiently. The policy should indicate
how these issues are to be addressed.
c) Protecting the citizen:- is an Ethical issues that require regulatory
mechanisms. The information policy should address a range of legal and
regulatory issues including privacy and data protection, intellectual
property rights, censorship or fraudulent use of the networks and legal
deposit of intellectual property. The rapid development of e-commerce will
generate further requirements for regulation in the consumer interest. To
ensure the rapid take-up that the Government seeks, the e-envoy will
need to make issues of consumer confidence a priority.
d) Free Access:- to have free access to core information a policy will need to
cover rights of access to information. Individuals already have rights in
some countries to access personal information about themselves and
there are some rights of access to local government information. However
more work will be needed on securing and safeguarding access free at the
point of use to citizenship information that is already in the public domain.
iii. Competencies
Competencies consist of the development of universal information literacy, the
supply of information specialists, and the creation of information strategies for
organizations.
a) universal information literacy:- is to develop universal information literacy
effort is required to develop a base level of information literacy for
everyone. The policy should set out a strategy for the achievement of this.
It should encompass a wide range of skills, including numeracy, literacy,
computer and information retrieval skills. It must be delivered at a variety
of levels throughout the formal and informal education processes, and it
Arsi University
17
Information and Society
should take advantage of the full range of delivery methods now available,
including digital networks.
b) supply of appropriately skilled information specialists. The National
Information Policy must address the need to ensure that there is an
adequate supply of appropriately skilled information specialists to
maximize the value of information for individual users and organizations
through processes of collection, organization and dissemination.
c) Information strategies for organizations. National Information Policy should
establish a framework to promote information strategies for
[Link] departments should develop a comprehensive
set of information policies to maximize the impact that information can
have on consumers and on service providers. Similar approaches are
needed by other publicly funded bodies. Information skills handling should
be explicitly identified in any national initiatives designed to improve
management and human resources skills.
4.4.3. Contributions of information policy
A National Information Policy framework will contribute to modernizing
government: the agenda for a modern government requires that information
flows are managed as effectively as possible within government and between
government and citizens and businesses.
Building a knowledge-driven economy: the planned transformation of
industry and commerce will lace a premium on the effective use of
information and knowledge.
A better environment for e-commerce: better co-ordination is needed
between Government and industry to gain maximum benefit from
existing and proposed programmes. Ambitious targets for electronic
transactions with Government will depend on coordination across
Departments and Agencies.
Improving educational effectiveness: curriculum developments such as
teaching thinking skills will depend for their effectiveness on children
and young people having access to the information they will need to
support their learning; lifelong learners will need co-ordinated guidance
on all the opportunities open to them.
Avoiding social exclusion: many current information developments
could exacerbate social exclusion, further isolating the information
Arsi University
18
Information and Society
have-nots from the rest of society. We need policies to ensure that no-
one is excluded from the benefits of an inclusive information society.
Strengthening our cultural identity: technological development offers
opportunities to articulate and promote minority cultures. At the same
time, the global nature of the cultural communication system puts
national cultures under threat.
Arsi University
19