Jump to content

Recommended Posts

Posted

Morning All,

 

I'm not sure if I'm just missing an obvious or not, but recently received this email from our LEA and not sure whether to believe this or not:

 

All UK organisations must comply with the Data Protection Act when sending client personal-sensitive confidential information from a standard email address which isn’t protected by any technical encryption measures whilst in transit, so that it can’t be intercepted, read or altered by unintended recipients. To ensure compliance with the Data Protection Act 1988 and the privacy of the client ,any emails which contain person-sensitive confidential information must be sent via secure email solutions, or at the very least have a strong password applied to attached documents containing personal information. Arrangements can be made to share passwords under separate cover subject to sender / recipient identity verification.

 

Based on that, doesn't it basically say if it's encrypted you don't need to password protected any documents anymore? But what happens if the encrypted email gets sent to the wrong person, and they as the "valid recipient" (from the emails point of view) decrypt it and read it? Isn't that still a breach?

 

Steve

Posted

It would be a breach if it gets sent to the wrong person. The same way it would be if they get posted to the wrong address.

 

Please can I have a source for that passage please? It would be very handy.

 

Thanks

Posted

So basically useless LEA email, and keep using passworded documents :) At least that way if it's sent to wrong person, and password is given over phone etc the one who received it wrong won't be able to access it.

 

It's from an email so no idea where it's from originally or whether they made the phrasing themselves.

 

Steve

Posted
Are password protected documents secure? Our insurance company say not and will not cover us in there is a loss of data from a password protected document.
Posted
Are password protected documents secure? Our insurance company say not and will not cover us in there is a loss of data from a password protected document.

 

According to ICO :) "Consider whether the content of the email should be encrypted or password protected"

 

How else can you send information over email if not? As obviously not everyone has SecureNet etc

 

Steve

Posted

We basically add any sensitive data to an encrypted Zip file using 7zip and set a huge password. We then send the email to the recipient and have a challenge and response system where they will have to phone the person who sent the email and give details regarding the content of the email and then we release the password to them.

 

Works pretty well.

Posted

Aye that's what I assumed aleach, but just seems a lot of the "recommendations" disagree with that now and "encryption" is all you need to do.

 

Another example from the FCA in their guidelines: https://fca.org.uk/static/documents/data-protection-guide-external.pdf

 

Scanned copy attached to an email, or in text of an email

 

Send the email to a specific person rather than a group

or team email address. If particularly sensitive, you

must encrypt the email. You should check that the

information has arrived. Please note, emails from

Blackberries cannot be encrypted

 

Nothing about passwording it anymore

 

Steve

Posted

"The Act does not define “appropriate”. But it does say that an assessment of the appropriate security measures in a particular case should consider technological developments and the costs involved. The Act does not require you to have state-of-the-art security technology to protect the personal data you hold, but you should regularly review your security arrangements as technology advances. As we have said, there is no “one size fits all” solution to information security, and the level of security you choose should depend on the risks to your organisation."

 

https://ico.org.uk/for-organisations/guide-to-data-protection/principle-7-security/

Posted
Everyone should now be able to get free e-mail encryption by using Office 365 so i'd say that it is no long valid to argue it's not reasonable to have encrypted e-mail.

 

Aye but as I said that doesn't stop someone receiving an email incorrectly and viewing all your data thus causing a breach :) End of day all you need is access to the email account the email was sent to and you have all the data then.

 

Steve

Posted

No that's true, but you can have all the security in the world and that still wont stop you from having a breech, it's the human condition to make mistakes.

 

It's just when legislation states you should take all reasonable steps to reduce risk, you need to take them.

 

Encrypted email used to be difficult to set up, SMBs didn't' always have the expertise to do that, that's reasonable.

It used to be expensive, that's reasonable.

 

Those 2 things are no longer true. So now, IMO, not having encrypted email means you haven't taken all reasonable steps to secure your communications.

Posted
No that's true, but you can have all the security in the world and that still wont stop you from having a breech, it's the human condition to make mistakes.

 

It's just when legislation states you should take all reasonable steps to reduce risk, you need to take them.

 

Encrypted email used to be difficult to set up, SMBs didn't' always have the expertise to do that, that's reasonable.

It used to be expensive, that's reasonable.

 

Those 2 things are no longer true. So now, IMO, not having encrypted email means you haven't taken all reasonable steps to secure your communications.

 

True, as long as you can prove you have taken adequate steps to protect the data by having policy, procedure and training as well as risk assessments then the ICO will be happy enough that you have put in place “appropriate" protection measures.

Posted
Everyone should now be able to get free e-mail encryption by using Office 365 so i'd say that it is no long valid to argue it's not reasonable to have encrypted e-mail.

 

have you any more information on setting this up or actually using it?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...