|
Success in information security work depends first and foremost on developing good basic working practices and establishing procedures to ensure that they are maintained. It is also important to create a security-conscious atmosphere and establish a disciplined approach.
If confidential information is to be handled, it is essential that the people chosen for the job are absolutely reliable. They should be security screened to a level equal to the highest level of confidential information they are likely to be asked to work on. Access to information should be restricted to that which the individual ‘needs to know’ to do his job. Particularly sensitive material should be split into sections that only authorised staff can handle; no member of staff should have access to all the information.
Furthermore, security measures will only be effective if staff are properly trained. It is essential that they understand the problem. This can be achieved with in-house training. The individual users must be trained how to use the network, how to handle confidential information, making back-ups etc. Employees can be taught what to do to counter certain threats, what they should not do, whom they can call and where they can get help. It is also very important to encourage employees to report incidents so that steps can be taken to prevent any further damage.
New or temporary employees should be given introductory training, during which data security and data integrity can be explained. It might also be useful to consider including a clause on security and confidentiality obligations in employees’ contracts.
Related posts:
Related posts brought to you by Yet Another Related Posts Plugin.