Managing Access to Data Print

  • 0

Controlling information rather than systems.

WHY IT DIFFERS

Access to a system does not necessarily mean access to everything in it.

WHAT TO ESTABLISH

What data exists How sensitive each kind is Who needs each

WHAT CATEGORIES USUALLY MATTER

Personal data about customers and staff Financial information Commercially sensitive material Credentials and keys

WHY PERSONAL DATA FIRST

It carries legal obligations and the consequences of exposure fall on individuals.

WHAT TO ESTABLISH

Who has access to personal data, and whether they need it.

WHAT TO LIMIT

Access to what the role requires, rather than to entire datasets.

WHAT TO ESTABLISH ABOUT EXPORTS

Who can extract data in bulk.

WHY

Bulk export is how large amounts of data leave.

WHAT TO CONSIDER

Restricting or logging it.

WHAT TO ESTABLISH ABOUT COPIES

Where data is copied to.

WHY

Access controls on the original are defeated by copies elsewhere.

WHAT TO IDENTIFY

Spreadsheets and extracts held locally Data in test environments Data shared with third parties Backups

WHY TEST ENVIRONMENTS SPECIFICALLY

They frequently contain real data with weaker controls.

WHAT TO ESTABLISH

That test environments use data that is not real, or that they are protected equally.

WHAT TO ESTABLISH ABOUT SHARING

How data is transferred and to whom.

WHAT TO AVOID

Sharing through personal accounts and unmanaged services.

WHAT TO LOG

Access to sensitive data, where feasible.

WHY

It is what allows a breach to be scoped.

WHAT TO REVIEW

Who has access to each category, periodically.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot