23 January 2014

Guarding against data breaches

The latest wave of fines levied by the Information Commissioner’s Office (ICO) – such as North East Lincolnshire Council losing a memory stick containing sensitive information about children with special needs – has made many local authorities realise the implications of data protection.

Many councils are now taking steps to understand and establish responsible processes with secure, certified service providers who will ensure they stay out of the ICO’s line of fire.

In Q2 2013 alone, there were 335 data breach incidents according to the ICO, 29 of which were lost or stolen hardware; the top three biggest offenders were health, local government and education.

However, is increased scrutiny and an ever interested media enough to help drive through better policy making in public bodies?

The greater focus on data protection legislation and its enforcement are factors on which those responsible for data should be placing high importance. ADISA (Asset Disposal & Information Security Alliance) has developed a security standard for IT asset disposal companies, which ensures that the asset – and therefore the data – is managed and protected throughout the process until the data itself is sanitised.

It is also working with partners like Stone Group to bridge this huge awareness gap, recently launching a series of education programmes with the University of South Wales. Organisations should not make disposal decisions purely based on the financial returns offered for their redundant IT equipment. Choosing to dispose of IT via anything less than quality approved service providers is negligible and poses an unnecessary risk. Companies don’t buy the cheapest firewalls or antivirus solutions so why should they settle for the cheapest or no-cost disposal service? The data being protected is still the same.

Those organisations looking for IT disposal services should ensure their chosen provider can demonstrate compliance with recognised security standards such as ADISA ITAD and ISO27001, and that data wiping or destruction methods employed are suitable for the classification of data and media type. A visit to the provider’s facilities should also be considered to verify the process and security.

Data wiping – performed by software tested and approved to a national technical standard, such as CESG – will provide secure wiping of data. There are many products available online which do not offer the same assurance.

Ultimately, and legally, the responsibility rests with the organisation from whom the assets and data originated, and liability will remain with them if due diligence has not been applied when selecting their disposal provider.

The absence of an IT asset disposal policy by public sector organisations is no doubt the result of ongoing needs to reduce costs and has placed responsibility with unqualified individuals.

However, it is more necessary than ever that such oversight is eradicated and policies put in place to ensure security and data breaches are a thing of the past. n

Martin Ruston is group compliance manager at Stone Group, and Steve Mellings is founder of ADISA.

This feature first appeared in Local Government News magazine. Register for your free copy here.

Addressing regional inequalities  image

Addressing regional inequalities

Andrew Borland, Chief Innovation Officer at the Virtual Engineering Centre (VEC), University of Liverpool discusses the importance of levelling up for growth.
Banning urban pesticide use image

Banning urban pesticide use

RSPB and PAN are working on a letter from local councillors calling on the Government to introduce a national ban on urban pesticide use. Find out more below.
SIGN UP
For your free daily news bulletin
Highways jobs

Recovery Worker Substance Misuse

Essex County Council
£30931 - £35362 per annum + + 26 Days Leave & Defined Benefit Pension
Recovery Worker Substance MisusePermanent, Full Time£30,931 to £35,362 per annumLocation
Recuriter: Essex County Council

Principal Transport Officer

Old Oak and Park Royal Development Corporation
£63,112 per annum
leading the capital’s largest new regeneration project. Brent Civic Centre (32 Engineers Way, Wembley, HA9 0FJ).
Recuriter: Old Oak and Park Royal Development Corporation

Senior Occupational Therapist

Essex County Council
£43477 - £52302 per annum + Flexible Working, Hybrid, CPD, Gov Pension
The role will be responsible for supporting adults to develop their abilities to enable them to live as independently as possible. This may include England, Essex, Harlow
Recuriter: Essex County Council

Director of Commissioning and Performance

Northumberland County Council
£100,157 - £109,081
We are looking for an individual to help us achieve excellence in adult social care in Northumberland. Northumberland County Council, Morpeth, United Kingdom
Recuriter: Northumberland County Council

Payroll Manager

London Borough of Richmond upon Thames and London Borough of Wandsworth
£46,014 to £55,758 per annum
About the role You will have a set of on-going responsibilities which will vary depending on the needs of the team. The responsibilities include (but not limited to) to
Recuriter: London Borough of Richmond upon Thames and London Borough of Wandsworth
Linkedin Banner

Partner Content

Circular highways is a necessity not an aspiration – and it’s within our grasp

Shell is helping power the journey towards a circular paving industry with Shell Bitumen LT R, a new product for roads that uses plastics destined for landfill as part of the additives to make the bitumen.

Support from Effective Energy Group for Local Authorities to Deliver £430m Sustainable Warmth Funded Energy Efficiency Projects

Effective Energy Group is now offering its support to the 40 Local Authorities who have received a share of the £430m to deliver their projects on the ground by surveying properties and installing measures.

Pay.UK – the next step in Bacs’ evolution

Dougie Belmore explains how one of the main interfaces between you and Bacs is about to change.