Better keep personal info away from computers


“There’s no good business reason for it.” Litan advocates a few simple steps — Organisations should keep sensitive information only on secure, centralised servers. Workers can access the data from PCs in the office or over private internet connections, but can’t store the records on their own machines to fiddle with them offline. If they absolutely need to analyse data out of the office, the employees should run programs that replace live credit card or Social Security numbers with random “dummy” figures whenever possible, since the actual numbers aren’t always relevant. Following such rules would have prevented the scare that resulted when a laptop with veterans’ data was burgled from an analyst’s home May 3 (it was later recovered with the information apparently unaccessed). The VA inspector general told Congress that the staffer had been bringing data home for policy analysis since 2003. It’s true that encrypting data — scrambling them with private codes — can make whatever is found on a laptop almost impossible to read. But encryption often isn’t turned on by users who think it degrades computer performance. Consider the case of the ING Financial Services adviser who had Social Security numbers and other personal data for 13,000 District of Columbia employees on his laptop — until the computer was stolen from his home last month. ING administers pensions for the district. The adviser had broken ING rules by not having the data encrypted. But the fact that the information was out of the office was not itself a violation. Officials said the adviser had the records because they corresponded to older pension plan participants who were more likely to call him for assistance. The adviser wanted the data on hand for marketing efforts, such as to help decide whom to invite to a seminar.
0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home