lo6 Flashcards
Confidentiality
Information should only be accessed by individuals or groups with the authorisation to do so.
example; An organisation should use protection measures like usernames and passwords to ensure that only authorised people can access the sensitive data. Tiered levels of access or permissions can also limit who has access to the data.
Integrity
Information is maintained so that it is up-to-date, correct and fit for purpose.
example ;Organisations should carry out regular data maintenance to update information (e.g. confirm contact details once a year). If storing data in a spreadsheet or database, record-locking should be used so that only person can edit at a time, preventing the data from becoming incorrect.
Availability
Information is available to the individuals or groups that need to use it. It should only be available to those who are authorised.
example; Staff should have the correct privileges so that they can easily access data when required. Data could be stored online, e.g. cloud storage so that it is available remotely using an internet connection.
Data must also be kept safe from unauthorised access. Staff should not make additional copies of information which could be lost or stolen.