Re: data center requirements
Damiano Verzulli <[email protected]> Sat, 04 Dec 2004 18:00:06 +0100
| Newsgroups | gmane.linux.usage.government |
|---|---|
| Message-ID | <[email protected]> |
Marius Andreiana wrote: > Hi > > Are there any laws in your country specifying requirements for a "data > center" ? We're trying to define this in a new romanian law about > electronic documents. Sorry Marius, but I don't understand. Are you going to define requirements for a "data-center" or, viceversa, you're going to define rules to manage electronic documents? IMHO these are two very different issues. In Italy, for example, we have laws (...and technical rules related to such laws) dealing with digital-signature or certified e-mail. So, basically, if an Italian public-entity needs to exchange electronic documents with another public-entity it has to use a "such-rules-compliant" e-mail system. The same applies if you're a private company (or a phisical person) and you want to (electronically) exchange document with the PAs. (BTW: things are much more complex but... concepts stated above should give you an idea of the whole cooncept). At the other end, we have also some laws dealing with the "Security" in terms of "data-management" so, for example, if you're an Internet Service Provider and you're running a mail-server, you're "forced" to keep the mail-server LOG for at least 5 or 10 years. The same applies to the log of the authentication server and all the technical infrastructure used to keep-track of activities. Obviously you're forced to properly backup your data... and on so (disaster-recovery). Also, here we have some laws stating that if you're a company (or even a phisical person) and you're managing/archiving some "data" related to other people/companies (names, addresses, dates of birth, telephone numbers and so on...) you've to: - carefully store such information in such a way that they should not be (easily..) lost (=> firewall, antivirus, and so on...); - carefully identify "who" have access to such infos and "why"; - yearly produce a document that carefully explain what's the "workflow" of data within your organization. As you can see, noone (at least here, in Italy) state _HOW_ a datacenter should be built. The problem in _not_ the datacenter. The problem is the "information" (...managed _also_ within datacenters) and the exchange of information. As have been said by William, ======================================================= The technology should be independent of the law. There are many laws about documents and data in the United States. Laws should be about legalities and not technicalities. ======================================================= As Romania is going to run in the "EU" direction... it should worth the effort to get in touch with IDA http://europa.eu.int/ida the Agency of the European Union whose mission is the "Interchange of Data between Administrations" all around Europe. As you can see, IDA has even an OpenSourceObservatory http://europa.eu.int/ida/oso that, even if not directly related to "laws", can be _VERY_ useful in choosing the right technology to adopt within your public information systems (that, if I'm right, is going to be totally rebuilt _from_scracth_!). As usual, maybe I've only added complexity to your original question. Sorry, if this is the case.... Anyway, for any further information, don't hesitate to contact me/us again. With best regards, Damiano -- Damiano Verzulli e-mail: [email protected] --- possible?ok:while(!possible){open_mindedness++} --- "...Science, after all, is ultimately an Open Source enterprise..." 'Open Sources: Voices from the Open Source Revolution' - Introduction [http://www.openresources.com/documents/open-sources/main.html]