23 January 2014

Guarding against data breaches

Guarding against data breaches image

The latest wave of fines levied by the Information Commissioner’s Office (ICO) – such as North East Lincolnshire Council losing a memory stick containing sensitive information about children with special needs – has made many local authorities realise the implications of data protection.

Many councils are now taking steps to understand and establish responsible processes with secure, certified service providers who will ensure they stay out of the ICO’s line of fire.

In Q2 2013 alone, there were 335 data breach incidents according to the ICO, 29 of which were lost or stolen hardware; the top three biggest offenders were health, local government and education.

However, is increased scrutiny and an ever interested media enough to help drive through better policy making in public bodies?

The greater focus on data protection legislation and its enforcement are factors on which those responsible for data should be placing high importance. ADISA (Asset Disposal & Information Security Alliance) has developed a security standard for IT asset disposal companies, which ensures that the asset – and therefore the data – is managed and protected throughout the process until the data itself is sanitised.

It is also working with partners like Stone Group to bridge this huge awareness gap, recently launching a series of education programmes with the University of South Wales. Organisations should not make disposal decisions purely based on the financial returns offered for their redundant IT equipment. Choosing to dispose of IT via anything less than quality approved service providers is negligible and poses an unnecessary risk. Companies don’t buy the cheapest firewalls or antivirus solutions so why should they settle for the cheapest or no-cost disposal service? The data being protected is still the same.

Those organisations looking for IT disposal services should ensure their chosen provider can demonstrate compliance with recognised security standards such as ADISA ITAD and ISO27001, and that data wiping or destruction methods employed are suitable for the classification of data and media type. A visit to the provider’s facilities should also be considered to verify the process and security.

Data wiping – performed by software tested and approved to a national technical standard, such as CESG – will provide secure wiping of data. There are many products available online which do not offer the same assurance.

Ultimately, and legally, the responsibility rests with the organisation from whom the assets and data originated, and liability will remain with them if due diligence has not been applied when selecting their disposal provider.

The absence of an IT asset disposal policy by public sector organisations is no doubt the result of ongoing needs to reduce costs and has placed responsibility with unqualified individuals.

However, it is more necessary than ever that such oversight is eradicated and policies put in place to ensure security and data breaches are a thing of the past. n

Martin Ruston is group compliance manager at Stone Group, and Steve Mellings is founder of ADISA.

This feature first appeared in Local Government News magazine. Register for your free copy here.

Sutton Councils IoT pilot project image

Sutton Council's IoT pilot project

David Grasty, head of digital strategy & portfolio for Kingston and Sutton Councils, outlines how in-home sensors have improved the safety of vulnerable residents living in social housing.
For your free daily news bulletin
Highways jobs

Director of Children's Safeguarding and Care 

Gloucestershire County Council
Up to £116,391, plus relocation support
We are looking to fill this vital role at a very important time for us.  Our children’s services team is on an important journey of... Gloucestershire
Recuriter: Gloucestershire County Council

Corporate Director

Ceredigion County Council
£97,294 - £104,086
We are looking to recruit an ambitious and truly transformational leader to support the delivery of modernised and sustainable services to... Penmorfa, Porthmadog
Recuriter: Ceredigion County Council

Street Works Co-ordinator

Lincolnshire County Council
£21,153 - £23,791
Do you want to make a difference to how Street Works are managed within Lincolnshire? Lincolnshire
Recuriter: Lincolnshire County Council

Community Co-ordinator (Health inequalities)

Brent Council
£32,418 - £34,209 p.a. inc.
The successful candidate will have evidenced experience of working in a community environment. Brent, London (Greater)
Recuriter: Brent Council

Homelessness Prevention and Relief Officer

Brent Council
£32,418 - £34,209 p.a. inc. (pro-rata)
You must have an understanding of homelessness legislation, and an ability to learn legislation quickly with training, coupled with... Brent, London (Greater)
Recuriter: Brent Council

Public Property

Latest issue - Public Property News

This issue of Public Property examines how how flexible workspaces can lead the way in regeneration for local authorities, Why local authority intervention is key to successful urban regeneration schemes and if the Government’s challenge of embracing beauty is an opportunity for communities.

The March issue also takes a closer look at Blackburn with Darwen Council's first digital health hub to help people gain control over health and care services.

Register for your free digital issue