Understand mechanisms to control organisational IT security Unit 48 I.T. Security Management HND in Computing and Systems Development
Understand mechanisms to control organisational IT security Risk assessment √ Data protection Physical security
Data protection: government regulations company regulations: eg Data Protection Act 1998, Computer Misuse Act 1990; company regulations: eg site or system access criteria for personnel; anti-virus software; firewalls, basic encryption techniques; operational continuity planning; back-up procedures
Data protection: “The number of customers affected and the amount of data potentially stolen is smaller than originally feared…” Dido Harding interview, Sunday Times, 25/10/15 "It wasn't encrypted, nor are you legally required to encrypt it," "We have complied with all of our legal obligations in terms of storing of financial information."
Task You work for a company with a website that takes sensitive customer details over the web including credit card details for purchases, You have returned to work the Monday morning after this article was run in the Sunday Times. Your line manager wants to know if DH is correct and is there a potential cost-saving for your company ie. Can you avoid using encryption? Research facts to support a case either for or against this proposal, write a report for your boss giving your response Remember to include counter arguments Quote relevant legislation Include financial data to support your arguments.