6.4 Protection Measures Flashcards
Staff responsibilities
Staff of an organisation will spend most time handling and amending data so the company must have sufficient and effective protection measures in place so that:
staff are confident in their role and know their responsibilities of information security
Staff responsibilities (2)
Certain staff members may be responsible for types of data within an organisation e.g confidential data so:
Assigning specific people to roles ensures that they know what their job is and that they are responsible if data is lost
Staff responsibilities (3)
Organisations need to consider which members of staff have access rights to creating information
Staff responsibilities (3) (question)
Why do organisations need to consider this?
As if data is confidential then:
More people that have access to that data, the higher the risk of it being lost or tampered with
Sensitive data: accessed by those who need to use it as part of their job
Staff responsibilities (4)
Why should staff be trained?
So they know how to adequately handle information including:
Data security techniques
How to protect data from unauthorised access and loss
Disaster & Recovery planning
What are disasters?
Natural disasters
Hardware failure
Software failure
Malicious damage
Disaster & Recovery planning
Before the disaster
All possible risks to be analysed for preparation
Preventative measures e.g flood-proof or storing data in a different area
Staff training to inform employees on what to do in the event of a disaster
Disaster & Recovery Planning
During the disaster
Staff response is important, employees should follow their training, ensuring that data is protected and measures are put in place
Contingency plans such as uploading recent data to cloud storage or security backups
Disaster & Recovery planning
After the disaster
Recovery measures such as backups
Replacement hardware purchased for equipment that is corrupted or destroyed
Software needs to be reinstalled on new hardware
Disaster recovery policies should be updated and improved
Assessments and Effectiveness
What should organisations conduct and why?
Information security risk assessments to ensure that their physical and logical measures are up-to-date and that they provide the most effective methods of protection.
Assessments and Effectiveness
Why test security measures in place?
Identify any weak-points and fix those highlighted vulnerabilities to minimise the extent of external and internal data intrusion
Assessments and Effectiveness
Why implement training drills for the staff?
To provide the staff with experience on:
What should happen if a disaster or:
Substantial data loss occurs so:
That the company is prepared
Organisations security assessment may identify specific cost impact
These are necessary financial expenditures to ensures the security of data and systems such as:
Software - firewalls to be purchased for protected network systems
Hardware - buying secure storage devices and new computer systems
Training - hiring industry experts to train staff on how to keep data secure
Security - hiring staff to protect server rooms