Your bank account is known to anyone you have ever given a cheque to. That may be only a few nowadays but what about that work social club?
If your network logins are not issued with satisfactory security, then that perhaps ought to be a first priority. For those who do not have a network login, then their line manager's confirmation?
Regards
Jim Whitaker
==================================================================================
-----Original Message-----
From: This list is for those interested in Data Protection issues [mailto:[log in to unmask]] On Behalf Of Scourfield, Brenda
Sent: Friday, April 15, 2011 9:05 AM
To: [log in to unmask]
Subject: [data-protection] FW: [data-protection] Bank details and identity verification
Hi Phil,
The only problem I can see is that the first three items anyone could supply. The bank account is the only identifier that the employee could solely know (or you would assume that). I know my husband's bank account and he works here - we could be separated or on verge of a divorce (we aren't !) Our paynumber is on our car parking permit, displayed to the world.
Here, we always use network id and password as logins for anything. IT Security policy states that the password must be kept secure and disciplinary action can be taken if it isn't. Once this is used to identify the person, could they then be given an account ?
Thanks
Brenda
Brenda Scourfield
Team Leader
I.T.
Pembrokeshire County Council
County Hall
Haverfordwest
SA61 1TP
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|