At the present time we do not have any approved encryption*. Which is why we have ordered a stop. Several options are being considered but being non-technical I cannot give any details.
The possibility remains that until we have reviewed this more fully I would, exceptionally, sanction a non-encrypted transfer by removable media in case of necessity - but the delivery method would have to be very secure, and I would require safeguards and confirmation of the return / destruction of the media.
Phillip Bradshaw
Information Manager
Clerk to the Council
Room 111, County Hall
EMail: [log in to unmask]
Phone: 029 2087 3346
Mobile : 07779 284684
Fax: 029 2087 3349
Proactive Publishing Promotes Positive Perceptions
-----Original Message-----
From: This list is for those interested in Data Protection issues [mailto:[log in to unmask]] On Behalf Of Roland Perry
Sent: 27 November 2007 16:10
To: [log in to unmask]
Subject: Re: [data-protection] Data Transfer Guidelines
In message
<[log in to unmask]>, at 14:06:10 on Tue, 27 Nov 2007, "Bradshaw, Phillip"
<[log in to unmask]> writes
>Everyone will have seen the recent news about HMRC?s disastrous loss of
>25 million items of customer personal data. In the light of that, the
>Council?s own procedures are being reviewed and additional guidance
>will be issued to staff shortly. In the meantime all staff are reminded
>that this issue is already covered in the IT Security Policy which
>says: ?The transferring of files between computers via removable media
>? floppy disks, CDs or USB flash drives must be adequately protected
>from unauthorised access either via password protection or encryption.?
>
>In practical terms this means that, until guidance and procedures are
>issued NO customer personal data should be stored for any reason on a
>CD/DVD ROM, USB Flash Drive (or floppy disk if you still have one!)
>unless it has been encrypted.
>
>Anyone who has an operational need to transfer such data (either within
>or outside the Council) using one of these media should take urgent
>advice from ICT ... or the Information Manager ...The approval of a
>Chief Officer will be required, and will only be recommended if the
>transfer is of operational necessity, if the amount and type of data is
>agreed, and if a safe and auditable method of delivery (and eventual
>disposal
I'd be interested to know what encryption methods have been "approved"
as adequate in these circumstances, and whether that involves a PKI, and if so, who in the council is administering it.
--
Roland Perry
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask] All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
**********************************************************************
Privileged/Confidential Information may be contained in this message. If you are not the addressee indicated in this message (or responsible for delivery of the message to such person), you may not copy or deliver this message to anyone. In such case, you should destroy this message and kindly notify the sender by reply email. Please advise immediately if you or your employer does not consent to Internet email for messages of this kind. Opinions, conclusions and other information in this message that do not relate to the official business of the Council of the City and County of Cardiff shall be understood as neither given nor endorsed by it. All e-mail sent to or from this address will be processed by Cardiff County Councils Corporate E-mail system and may be subject to scrutiny by someone other than the addressee.
**********************************************************************
Mae'n bosibl bod gwybodaeth gyfrinachol yn y neges hon. Os na chyfeirir y neges atoch chi'n benodol (neu os nad ydych chi'n gyfrifol am drosglwyddo'r neges i'r person a enwir), yna ni chewch gopio na throsglwyddo'r neges. Mewn achos o'r fath, dylech ddinistrio'r neges a hysbysu'r anfonwr drwy e-bost ar unwaith. Rhowch wybod i'r anfonydd ar unwaith os nad ydych chi neu eich cyflogydd yn caniatau e-bost y Rhyngrwyd am negeseuon fel hon. Rhaid deall nad yw'r safbwyntiau, y casgliadau a'r wybodaeth arall yn y neges hon nad ydynt yn cyfeirio at fusnes swyddogol Cyngor Dinas a Sir Caerdydd yn cynrychioli barn y Cyngor Sir nad yn cael sel ei fendith. Caiff unrhyw negeseuon a anfonir at, neu o'r cyfeiriad e-bost hwn eu prosesu gan system E-bost Gorfforaethol Cyngor Sir Caerdydd a gallant gael eu harchwilio gan rywun heblaw'r person a enwir.
**********************************************************************
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|