LO6 6.4 Protection measures Flashcards
Staff access rights
- limits are placed on staff access to information
-usernames and passwords at log on stage
-password protected databases and files - staff only access what they need
Responsibilities of staff
trained to handle info including basic data security techniques
Disaster and recovery planning
-policy for dr should be in place
-disasters include natural disasters, hardware failure, software failure and malicious damage
3 prats to a DR policy
Before the disaster 1. all possible risks should be analysed
prevention measures taken
staff training
During the disaster 2. staff response - follow their training to ensure data is protected
contingency plans
After the disaster 3.recovery measures should be followed
replacement hardware
software needs to be reinstalled
DR policies should be updated and improved
Information security risk assessment
carried out on organisations data
involve staff who have access
look at possible breaches for electronic and paper records
Effectiveness of protection measures
updates required on a regular basis
backups should be tested