You are using an outdated browser. Upgrade your browser today for a better experience of this site and many others.
Tel: 01527 831991 (*) info@pinfields.co.uk
It is our tradition of forward thinking that ensures you always get the perfect answer
The key issues to consider when reviewing the storage of and access to personal data on computers and networks. If your business is in the Worcestershire area we, at Pinfields, can provide you with assistance or any additional information required.
Many businesses are now completely reliant on the data stored on their network servers, PCs, laptops, mobile devices and cloud service providers. Some of this data is likely to contain either personal information and/or confidential company information.
Here we look at some of the issues to consider when reviewing the security of your computer systems with respect to access controls. The General Data Protection Regulation (GDPR) sets out the security principle, which states you must take ‘appropriate technical and organisational measures’ when securely processing personal data. This is also repeated as the 6th Principle of the Data Protection Act (DPA) 2018, which enhances the GDPR and also states a ‘requirement that personal data be processed in a secure manner’.
For this reason preventing unauthorised or accidental access to the personal data you process is an important step towards compliance.
Good access controls to the computers and the network minimises the risk of data theft or misuse.
Access controls can be divided into two main areas:
As well as having physical access controls such as locks, alarms, security lighting and CCTV there are other considerations, such as how access to the premises is controlled.
Visitors should not be allowed to roam unless under strict supervision.
Ensure that computer screens are not visible from the outside.
Use network policies to ensure that workstations and/or mobile devices are locked when they are unattended or not being used.
Ensure that if a mobile device is lost it can be immobilised remotely.
Mobile devices being small are high-risk items so sensitive data should always be encrypted and access to the service should be controlled via a pin number or password.
It may be necessary to disable or restrict access to USB devices and optical readers and writers.
It may be necessary to block network ports via Radius servers, or other network hardware, to prevent unauthorised equipment being plugged into the network via a cable.
Finally, information on hard-copy should be disposed of securely.
Logical access techniques should be employed to ensure that personnel do not have more access than is necessary for them to perform their role.
Sensitive data should be encrypted and access to this data controlled via network security, access control lists and user profiles.
Access to certain applications and certain folders may also need to be restricted on a user-by-user basis.
Finally, it may be necessary to lock down certain devices on certain machines, either via group policy in Widnows, or a third-party management application.
A password policy consisting of a username and password is good practice.
These help identify a user on the network and enable the appropriate permissions to be assigned.
For passwords to be effective, however, they should:
and should NOT
Whilst not a legal requirement of the GDPR, the logging and monitoring of data (and the changes made upon it) will go a long way to supporting compliance with Article 32 of the GDPR.
Auditing your data processing will allow you to review, report and prove:
Whilst both the GDPR and DPA 2018 do not state the exact measures you need to undertake, you should consider using a technical solution that is appropriate to your needs and that of the data you are processing.
If your business is in the Worcestershire area we can provide help in the following areas:
Please contact us at Pinfields if you would like any help in any of these areas.