Unfortunately you need to deal with connections other than USB, some of
which aren't amenable to the araldite "solution". Unless you're the kind
of organisation whose office is a Faraday cage and removes all
electronics at the door (and they do exist) then you already need to
cope with bluetooth transfer between laptops and mobile phones :-(
Unless you can persuade your users that they don't need/want to take
data home, they'll find ways to do it.
Andrew
--
Andrew Cormack, Chief Regulatory Adviser
JANET(UK), Lumen House, Library Avenue, Harwell Science and Innovation
Campus, Didcot, OX11 0SG, UK
Phone: +44 (0) 1235 822302
Fax: +44 (0) 1235 822399
JANET, the UK's education and research network
> -----Original Message-----
> From: This list is for those interested in Data Protection issues
> [mailto:[log in to unmask]] On Behalf Of Tim Trent
> Sent: 17 November 2008 16:04
> To: [log in to unmask]
> Subject: Re: How to Take Data Security Seriously
>
> Morris, David (Allvac, UK) wrote:
>
>
> I agree with the awareness training. How about showing people
> how to use a bit of free software to encrypt memory sticks and bits
> of laptop hard drives to make it a bit more secure should they
> (almost inevitably) go missing? If it's free, it removes a lot of
> the cost argument from the equation.
>
> The induction one is a good idea... I must talk to our HR
> department...
>
>
> I would suggest a binding HR policy that states that the only USB
> memory devices deployed will be those supplied by the organisation,
> and that the organisation invests in encrypted devices as a matter
> of course. This includes external disk drives.
>
> A policy is useless without sanctions, of course, so this must be
> embedded into the disciplinary process, and it must be inspected
> for.
>
> --
>
> ________________________________
>
>
> Tim Trent - Consultant
> Tel: +44 (0)7710 126618
> web: ComplianceAndPrivacy.com - where busy executives go to find
> the news first
> personal blog: timtrent.blogspot.com/
>
> Marketing by Permission
> <http://feeds.feedburner.com/%7Er/MarketingByPermission/%7E6/1>
>
> Important: This message is private and confidential. If you have
> received this message in error, please notify us and remove it from
> your system. This email and any attachment(s) are believed to be
> virus-free, but it is the responsibility of the recipient to make
> all the necessary virus checks. This email and any attachments to
> it are copyright of Meadowood Associates, owners of Compliance And
> Privacy, unless otherwise stated. Their copying, transmission,
> reproduction in whole or in part may only be undertaken with the
> express permission, in writing, of Meadowood Associates, at
> Meadowood House, 30 Redditch, Bracknell, Berkshire, RG12 0TT.
>
> ________________________________
>
> All archives of messages are stored permanently and are available
> to the world wide web community at large at
> http://www.jiscmail.ac.uk/lists/data-protection.html
>
> Selected commands (the command has been filled in below in the body
> of the email if you are receiving emails in HTML format):
>
> * Leaving this list: send leave data-protection to
> [log in to unmask] <mailto:[log in to unmask]&BODY=LEAVE
> data-protection>
> * Suspending emails from all JISCMail lists: send SET * NOMAIL
> to [log in to unmask] <mailto:[log in to unmask]&BODY=SET
> * NOMAIL>
> * To receive emails from this list in text format: send SET
> data-protection NOHTML to [log in to unmask]
> <mailto:[log in to unmask]&BODY=SET data-protection NOHTML>
> * To receive emails from this list in HTML format: send SET
> data-protection HTML to [log in to unmask]
> <mailto:[log in to unmask]&BODY=SET data-protection HTML>
>
> All user commands can be found at
> http://www.jiscmail.ac.uk/help/commandref.htm and are sent in the
> body of an otherwise blank email to [log in to unmask]
>
> Any queries about sending or receiving messages please send to the
> list owner [log in to unmask]
>
> (Please send all commands to [log in to unmask] not the list
> or the moderators, and all requests for technical help to
> [log in to unmask], the general office helpline)
>
> ________________________________
JANET(UK) is a trading name of The JNT Association, a company limited
by guarantee which is registered in England under No. 2881024
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Science and Innovation Campus, Didcot, Oxfordshire. OX11 0SG
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|