{"id":5212,"date":"2016-10-18T13:19:54","date_gmt":"2016-10-18T12:19:54","guid":{"rendered":"https:\/\/stevepedwards.today\/DebianAdmin\/?p=5212"},"modified":"2016-10-18T13:19:54","modified_gmt":"2016-10-18T12:19:54","slug":"small-business-data-security-requirements-summary","status":"publish","type":"post","link":"https:\/\/stevepedwards.today\/DebianAdmin\/small-business-data-security-requirements-summary\/","title":{"rendered":"Small Business Data Security Requirements Summary"},"content":{"rendered":"<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_5212\" class=\"pvc_stats all  \" data-element-id=\"5212\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/stevepedwards.today\/DebianAdmin\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n<p><strong>Business Legal requirements under Data Protection Act 1998<\/strong><\/p>\n<p>Identify\/nominate the Data Controller:<\/p>\n<p><a href=\"https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1558\/getting_it_right_-_how_to_comply_checklist.pdf\">https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1558\/getting_it_right_-_how_to_comply_checklist.pdf<\/a><\/p>\n<p><a href=\"https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1575\/it_security_practical_guide.pdf\">https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1575\/it_security_practical_guide.pdf<\/a><\/p>\n<p><a href=\"https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1542\/cctv-code-of-practice.pdf\">https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1542\/cctv-code-of-practice.pdf<\/a><\/p>\n<p><strong>10 practical ways to keep your IT systems safe and secure:<\/strong><\/p>\n<p><em>\"Keeping your IT systems safe and secure can be a complex task and does require time, resource and specialist knowledge. If you have personal data within your IT system you need to recognise that it may be at risk and take appropriate technical measures to secure it. The measures you put in place should fit the needs of your particular business...\"<\/em><\/p>\n<p><strong>1:\u00a0Assess the threats and risks to your business<\/strong><\/p>\n<p><em>What aspects of your business are totally IT dependent? What is the worst case scenario e.g. catastrophic system\/hardware failure (then no current backups\/lost software licenses\/insurance etc) and best actions to prevent that, or then recover from total loss in that worst case? What functionality do you still have with no IT systems - if any?<\/em><\/p>\n<p><strong>2:\u00a0The UK Government,s Cyber Essentials Scheme describes the following five key controls for keeping information secure. Obtaining a Cyber Essentials certificate can provide certain security assurances and help protect personal data in your IT systems.<\/strong><\/p>\n<p>a)\u00a0Boundary firewalls and internet gateways<\/p>\n<p>b)\u00a0Secure configurations (gear dependent - e.g. check for insecure default settings like Admin passwords, open ports)<\/p>\n<p>c)\u00a0Access control - username\/password for relevant access to specific resources<\/p>\n<p>d)\u00a0Malware protection - periodic automated malware scans with reporting set up<\/p>\n<p>e) Patch management and software updates (Windows, Apple and Linux) - set to auto updates as a <strong>general<\/strong> rule \u00a0(systems\/service\/software dependent!! Updates can break stuff!)<\/p>\n<p><strong>3:\u00a0Secure your data on the move and in the office - physical media and data encryption considerations?<\/strong><\/p>\n<p>a)\u00a0The physical security (different to logical data access): e.g. a server\/patch cabinet - fire, theft, flood etc; use of off site backups - hardware\/cloud\/both?; user access to USB stick ports (data theft, virus introduction threats at user account priviledge); network access for unauthorised wifi hub\/device additions?<\/p>\n<p><strong>4:\u00a0Secure your data in the cloud (and devices like work laptops, memory media, storage)<\/strong><\/p>\n<p><a href=\"https:\/\/ico.org.uk\/media\/1540\/cloud_computing_guidance_for_organisations.pdf\">https:\/\/ico.org.uk\/media\/1540\/cloud_computing_guidance_for_organisations.pdf<\/a><\/p>\n<p>Do you use unencrypted cloud backup services??? You client lists, business plans etc. are at risk of a security breach of the provider. Even if encrypted, password hacking may be possible for access to it.<\/p>\n<p><strong>5:\u00a0Back up your data - (storage is cheap now \u00a0- NO excuse for this not to be in place!!)<\/strong><\/p>\n<p>robust multiple data instances backup strategy in place - periodically check your backups WORK!<\/p>\n<p>off site physical media backups security checks and cloud backup provider obligations;<\/p>\n<p><strong>6:\u00a0Train your staff<\/strong><\/p>\n<p>Why security and system use policies are required and need adhering to.<\/p>\n<p><em>\"Accidental disclosure or human error is also a leading cause of breaches of personal data. This can be caused by social engineering,\u00a0sending an email to the incorrect recipient or opening an email attachment containing malware...What can I do? Employees at all levels need to be aware of what their roles and responsibilities are. Train your staff to recognise threats such as phishing emails and other malware or alerting them to the risks involved in posting information relating to your business activities on social networks. You should encourage general security awareness within your organisation. A security aware culture is likely to identify security risks\"<\/em><\/p>\n<p><strong>7:\u00a0Keep an eye out for problems<\/strong><\/p>\n<p><em>\"What can I do? Check your security software messages, access control logs and other reporting systems you have in place on a regular basis. You should also act on any alerts that are issued by these monitoring services. Make sure you can check what software or services are running on your network. Make sure you can identify if there is something there which should not be. Run regular vulnerability scans and penetration tests to scan your systems for known vulnerabilities make sure you address any vulnerabilities identified.\"<\/em><\/p>\n<p><strong>8:\u00a0Know what you should be doing<\/strong><\/p>\n<p>Security policies put in place and knowing why:<\/p>\n<p><em>\"what actions you should put into place should you suffer a data breach. Good incident management can reduce the damage and distress caused to individuals.\"<\/em><\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"mqpptpyQ6M\"><p><a href=\"https:\/\/stevepedwards.today\/DebianAdmin\/basic-security-concepts-principles-for-any-system-or-os\/\">Basic Security Concepts &#8211; Principles For Any System or OS<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"\"Basic Security Concepts &#8211; Principles For Any System or OS\" &#8212; Linux Admin, WebDev, Comms &amp; IT\" src=\"https:\/\/stevepedwards.today\/DebianAdmin\/basic-security-concepts-principles-for-any-system-or-os\/embed\/#?secret=jdfuRXRBR1#?secret=mqpptpyQ6M\" data-secret=\"mqpptpyQ6M\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p><strong>9:\u00a0Minimise your data<\/strong><\/p>\n<p><em>\"The DPA says that personal data should be accurate, up-to-date and kept for no longer than is necessary. Over time you may have collected large amounts of personal data. Some of this data may be out-of-date and inaccurate or no longer useful.\"<\/em><\/p>\n<p><strong>10:\u00a0Make sure your IT contractor is doing what they should be.<\/strong><\/p>\n<p><em>\"Many small businesses outsource some or all of their IT requirements to a third party. You should be satisfied that they are treating your data with at least the same level of security as you would...Ask for a security audit of the systems containing your data. This may help to identify vulnerabilities which need to be addressed. Review copies of the security assessments of your IT provider. If appropriate, visit the premises of your IT provider to make sure they are as you would expect. Check the contracts you have in place. They must be in writing and must require your contractor to act only on your instructions and comply with certain obligations of the DPA Don,t overlook asset disposal if you use a contractor to erase data and dispose of or recycle your IT equipment, make sure they do it adequately. You may be held responsible if personal data gathered by you is extracted from your old IT equipment when it is resold.\"<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_5212\" class=\"pvc_stats all  \" data-element-id=\"5212\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/stevepedwards.today\/DebianAdmin\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n<p>Business Legal requirements under Data Protection Act 1998 Identify\/nominate the Data Controller: https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1558\/getting_it_right_-_how_to_comply_checklist.pdf https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1575\/it_security_practical_guide.pdf https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1542\/cctv-code-of-practice.pdf 10 practical ways to keep your IT systems safe and secure: \"Keeping your IT systems safe and secure can be a complex task and does require time, resource and specialist knowledge. If you have personal data within your IT system <a href=\"https:\/\/stevepedwards.today\/DebianAdmin\/small-business-data-security-requirements-summary\/\" class=\"more-link\">...<span class=\"screen-reader-text\">\u00a0 Small Business Data Security Requirements Summary<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-5212","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"a3_pvc":{"activated":true,"total_views":2,"today_views":0},"_links":{"self":[{"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/posts\/5212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/comments?post=5212"}],"version-history":[{"count":0,"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/posts\/5212\/revisions"}],"wp:attachment":[{"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/media?parent=5212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/categories?post=5212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stevepedwards.today\/DebianAdmin\/wp-json\/wp\/v2\/tags?post=5212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}