Controlling information rather than systems.
WHY IT DIFFERS
Access to a system does not necessarily mean access to everything in it.
WHAT TO ESTABLISH
What data exists How sensitive each kind is Who needs each
WHAT CATEGORIES USUALLY MATTER
Personal data about customers and staff Financial information Commercially sensitive material Credentials and keys
WHY PERSONAL DATA FIRST
It carries legal obligations and the consequences of exposure fall on individuals.
WHAT TO ESTABLISH
Who has access to personal data, and whether they need it.
WHAT TO LIMIT
Access to what the role requires, rather than to entire datasets.
WHAT TO ESTABLISH ABOUT EXPORTS
Who can extract data in bulk.
WHY
Bulk export is how large amounts of data leave.
WHAT TO CONSIDER
Restricting or logging it.
WHAT TO ESTABLISH ABOUT COPIES
Where data is copied to.
WHY
Access controls on the original are defeated by copies elsewhere.
WHAT TO IDENTIFY
Spreadsheets and extracts held locally Data in test environments Data shared with third parties Backups
WHY TEST ENVIRONMENTS SPECIFICALLY
They frequently contain real data with weaker controls.
WHAT TO ESTABLISH
That test environments use data that is not real, or that they are protected equally.
WHAT TO ESTABLISH ABOUT SHARING
How data is transferred and to whom.
WHAT TO AVOID
Sharing through personal accounts and unmanaged services.
WHAT TO LOG
Access to sensitive data, where feasible.
WHY
It is what allows a breach to be scoped.
WHAT TO REVIEW
Who has access to each category, periodically.