Category: IT Glossary

Control function without instructions

In Germany, the tasks and activities of an internal or external data protection officer are governed by Sections 4f and 4g of the Federal Data Protection Act (BDSG). There are also regulations under state law. The data protection officer is responsible for monitoring compliance with the BDSG and other laws (Telemedia Act (TMG) or Telecommunications Act (TKG)). The data protection officer always acts independently and without instructions.

All public authorities, companies and associations must appoint a data protection officer as soon as personal data is processed automatically. 'Automated' is any processing that uses electronic data processing equipment (e.g. PCs) for business processes. Every organization must appoint a data protection officer no later than one month after commencing operations, otherwise it is an administrative offence that can be punished with fines of up to 50,000 euros. The data protection officer either comes 'internally' from the organization or must be appointed 'externally'.

Anyone who cannot fulfill the function of a data protection officer 'from on-board resources' is welcome to use us and our experience 'externally'.

Data protection: good intentions, many loopholes

Data protection must be kept strictly separate from data security, information security or IT security. Data protection in the IT sector is about protecting people's privacy, i.e. their 'informational self-determination'. It is about ensuring that their data is not misused, for example in the case of a flourishing trade in email addresses.

There are legal rules governing the use and processing of personal data, which are set out in the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and the data protection laws of the federal states. The fact that spectacular breaches of data protection occur time and again, despite possible penalties, is primarily due to the 'transnationality' of the internet. A hacker who (apparently) operates from the Christmas Islands or Uzbekistan can hardly be caught under national law.

The best data protection is therefore a high level of data security. There are excellent technical options for preventing the misuse of personal data. Just ask us.

Data Execution Prevention (DEP)

The best-known data execution prevention (DEP) is found on Windows computers. This is a method of preventing the launch of unwanted or malicious program code. DEP does not allow programs to use their own or third-party memory areas in a suspicious manner during their intended execution.

Such attacks using 'executables' are typical for viruses or Trojans that want to gain access to the system. If an attacker succeeds in executing his malicious program code in the system memory, the security and integrity of the system would no longer be guaranteed. If the upstream DEP detects such an illegal access attempt, it terminates the program immediately. The user usually only sees a window pop up informing them that the program has been stopped.

DEP is activated by default on 64-bit systems. It protects the Windows programs and services there. On 32-bit systems, this DEP function must first be activated. It is possible to exclude unsuspicious programs from this monitoring at any time. However, this is done at your own risk.

CTR: 'Click' is the new currency

The good old 'advertising prices' have become pretty irrelevant on the Internet. Advertising is done with banners, and payment is based on the number of mouse clicks. The click-through rate (CTR) has thus become the new key figure in Internet marketing. If, for example, a page with an advertising banner is called up a hundred times and the banner is clicked once, then this 'click-through rate' is one percent. Which would be almost 'sensational', because the CTR figure is usually in the per mille range.
In e-mail marketing, slightly different ratios apply, because the click rate here is defined by the ratio of opened mail and clicks on the internal mail links (so-called 'net click rate').

The CPU: A technical marvel in miniature

It is not without good reason that the CPU is referred to as the 'heart' of a computer. The Central Processing Unit (CPU) is a programmed and miniaturized computing chip which - according to its 'architecture' of semiconductors (or 'transistors') - can process defined computing processes ('algorithms'). CPUs are not only found in computers, but also, for example, in washing machines or ticket machines.

The main components of such a computing core or processor are modules that perform different tasks. At the center is the arithmetic-logic unit (ALU), followed by the control unit, which primarily manages the addresses, as well as several registers and a memory manager (memory management unit or MMU).

Co-processors support the central processing unit in its tasks, for example by performing floating point operations. Today's CPUs are designed as multi-core units, which supports parallel processing and speed when solving tasks. Data lines ('buses') enable communication with other components of the computing system, in particular with the main memory. The 'caches' (intermediate memory) enable rapid further processing of partial results.

The choice of processors used in a company should be based on the tasks to be performed. The most expensive solution is by no means always the best or most efficient. We will be happy to advise you.

CPC: The highest bidder wins

Marketing on the web has become a confusing affair and the old laws no longer apply. The new currency on the web is called cost-per-click (CPR): The advertiser now only pays for those customers who actually call up his offer and no longer for an agency's unique creative service.
With CPC, placement is the new commodity. The advertising for a product on another website is 'auctioned', so to speak, and the amount of the bid determines how prominent an advertising banner appears there. The terms 'affiliate marketing' or 'search engine marketing' (SEM) have become commonplace for this.
If, for example, the homepage 'Heiraten heute' negotiates a banner from the company 'Brautmoden' for a cost-per-click of two euros and integrates this advertising banner on its site, the company 'Brautmoden' pays forty euros to 'Heirat heute' as soon as twenty clicks have been made.
There are also new forms of billing: cost-per-lead (CPL) for each referral, cost-per-order (CPO) for each order, cost-per-sale (CPS) for each sale, etc.

IT compliance: a sea of rules

Anyone who uses IT services on the Internet today for administration or business transactions must comply with a number of legal regulations. These are referred to as IT compliance. Above all, information security, availability, data retention and data protection must be observed.

The laws that must be observed include, among others:

 

  1. The German and Austrian Telecommunications Act
  2. General Data Protection Regulation(GDPR)
  3. The Federal Data Protection Act (BDSG new)
  4. The tax 'Principles of data access and auditing of digital documents (GDPdU)
  5. The law on control and transparency in the corporate sector

 

There are also a number of international regulations (including Basel II, FINRA, IFRS, MIFID and PCI-DSS).

If you want to be sure that your company complies with IT compliance, just ask us.

An 'etiquette' for companies: The Code of Conduct

Essentially, a code of conduct formulates the 'rules of conduct' for companies and their employees. It is an internal guideline that can also have other names such as 'Corporate Behavior' (CB) or 'Guiding Principles'. It is the 'inner law' that everyone in the company has to follow. Violations of these rules can have consequences under employment law.

On the one hand, a code of conduct provides employees with security through a basic orientation for action; on the other hand, the uniformity that these rules enforce conveys a desired uniform corporate image to the outside world.

A code of conduct can be as short and succinct as the Ten Commandments, but it can also regulate every conceivable problem in detail, from dealing with gifts, working hours, data protection and customer relations to anti-corruption measures. The code of conduct is usually embedded in the larger framework of corporate social responsibility (CSR).

Cluster: A network for all occasions

A cluster is a computer network consisting of networked IT machines. Different forms of networking are used depending on the intended use.

A high-availability cluster (HAC) ensures constant availability and a high level of reliability. If a problem occurs in one node of the network, all running services migrate to another node. Both the hardware and software of an HA cluster must be completely free of singular components that could paralyze the system in the event of a failure. A dual design of all components is therefore the minimum rule for HA clusters. The components of such clusters are often geographically separated by several kilometers, so that the system does not fail even in the event of a disaster ('stretched cluster').

Another problem is changing performance requirements. This is where 'load balancing clusters' (LBC) are used, which divide the workload evenly among themselves in the event of increased requirements. Such systems are often installed for cost reasons. Instead of individual expensive high-performance machines, a swarm of networked standard computers divides the changing tasks evenly between them.

High-performance computing clusters (HPC) are used wherever large amounts of data need to be processed. Science is usually the field of application for such a network. Here, a task is divided up among many computers with the help of a decomposition program, each of which takes on subtasks ('jobs'). The speed of the network and the software used are critical factors here. Today, the so-called 'super computers' mostly use an HPC cluster that operates on a Linux basis.

When garbage becomes a problem: Blacklisting

Everyone is familiar with the phenomenon that led to 'blacklisting': that myriad of annoying spam emails that clog up your inbox in the morning. To ward off this unwanted garbage, DNS-based blackhole lists (DNSBL) were created, which match used addresses with suspected cases in real time (with the 'Real Time Blackhole Lists' - RBL). The Domain Name System (DNS) is the information system that can deliver messages to the exact computer required.

A DNSBL therefore keeps a worldwide list of those computers whose addresses in the Internet Protocol (IP) have already attracted unpleasant attention as spammers. As long as the global avalanche only affected computers whose sole purpose in life was to send spam emails, this system worked perfectly and there were hardly any false positives.

Nowadays, however, mass emails are being sent from a fixed location less and less often. In most cases, 'Trojanized computers' are involved in the big game of 'Viagra', 'alleged lottery winnings' or 'strange inheritances from Nigeria'. A malicious program ('Trojan') has then, unnoticed by the owner of the computer, crept onto the hard disk and uses its hardware as a spam slinger.

This is also the problem with blacklisting. In order to be removed from a blacklist ('delisting'), a great deal of effort is required, which often requires a lot of money and nerves. It therefore always depends on which DNSBLs are used by the provider's mail server.

Unfortunately, many providers do not delist for the reasons mentioned above.