« Question on complex passwords | Main | Vista views »

Data handling security

KingS

I'm starting off this week with a task to create a better method of assessing risks around data handling. I think that this is an aspect of security sometimes overlooked in the rush to mitigate risks in other areas: and while we do our utmost to ensure that infrastructure elements are being protected and that unauthorised access to data to taken care of, the actual handling of the data itself can leave itself open to exposure.

I'm splitting the assessment into three distinct areas: storage, transport, and disposal\destruction. I'll be looking into not only electronic transport of data (e.g. by email) but also physical transport such as when data is despatched using a courier service. I'll also be looking at storage on removable media such as memory sticks. First and foremost will be a look at the processes in place for marking-up data correctly and also data ownership. This also requires there to be a high level of awareness in place over when data should be marked-up with a classification and what classification to make use of.

It's an important exercise and it'll be interesting to see what variations there are across our global business in how this subject is handled.

Bookmark and Share


TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/2949

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on February 5, 2007 11:12 AM.

The previous post in this blog was Question on complex passwords.

The next post in this blog is Vista views.

Many more can be found on the main index page or by looking through the archives.