Print

Print



From: Lawrence Serewicz
Sent: 13 January 2012 15:29
To: 'Trish-louise Bailey'; [log in to unmask]
Subject: RE: [data-protection] Intriguing way to report a databreach? Put a data breach reporting address in the document's metadata?

That sounds like a good idea.  What is the way to contact? Do you have a designated contact point? I have trawled a number of sites looking for where to report a data breach, but so far I have not seen any. I would guess that the best alternative is to report it to the contact centre, but is that the right address?

For example, you could get a breach that involves a specific weblink. If you send the link through the link, but a number of people clicking that link may confuse the issue.  While this is not insurmountable, it would have an effect on an investigation. At the same time, sending to a contact centre may mean more people become aware of it than need to know.

I would be interested to know how others approach the "out of hours" breach reporting and whether such things can wait until the next business day.

Lawrence


From: This list is for those interested in Data Protection issues [mailto:[log in to unmask]] On Behalf Of Trish-louise Bailey
Sent: 13 January 2012 15:23
To: [log in to unmask]<mailto:[log in to unmask]>
Subject: Re: [data-protection] Intriguing way to report a databreach? Put a data breach reporting address in the document's metadata?

When I implemented security incident management procedure at my organisation this is the one thing that crossed my mind.  Our Comms Team has already got a rota for 24hr contact should they be needed by our CEX or Snr Mgr for any reason, so I tapped into this that if an incident happens outside of working hours they are to call the 24hr "hotline" so to speak.

Sent from my iPhone
Trish-louise Bailey
07545 445799
[log in to unmask]<mailto:[log in to unmask]>



________________________________


Help protect our environment by only printing this email if absolutely necessary. The information it contains and any files transmitted with it are confidential and are only intended for the person or organisation to whom it is addressed. It may be unlawful for you to use, share or copy the information, if you are not authorised to do so. If you receive this email by mistake, please inform the person who sent it at the above address and then delete the email from your system. Durham County Council takes reasonable precautions to ensure that its emails are virus free. However, we do not accept responsibility for any losses incurred as a result of viruses we might transmit and recommend that you should use your own virus checking procedures.

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
     All archives of messages are stored permanently and are
      available to the world wide web community at large at
      http://www.jiscmail.ac.uk/lists/data-protection.html
     If you wish to leave this list please send the command
       leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
 Any queries about sending or receiving messages please send to the list owner
              [log in to unmask]
  Full help Desk - please email [log in to unmask] describing your needs
        To receive these emails in HTML format send the command:
         SET data-protection HTML to [log in to unmask]
   (all commands go to [log in to unmask] not the list please)
    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^