rom1984
Members-
Posts
236 -
Joined
-
Last visited
Reputation
1,045 ExcellentAbout rom1984

-
Breach reporting obligations
rom1984 replied to gh5000's topic in Data Protection & Information Handling
It’s quite possible a case office could assign it as P3 and I wouldn’t particular object - It isn’t an exact science and the P rating scale is for guidance, the case officer will apply their own judgment assisted by the scale. For myself, the fact the data was exposed to a professional working within a school, who will be DBS checked etc, I would apply a P4, not withstanding the breach included special category data. To be honest, the way you handle a P3 and P4 would be pretty much the same, if not exactly the same. It’s the P1 and P2H cases where you want to be spending most of your time and resources. -
Breach reporting obligations
rom1984 replied to gh5000's topic in Data Protection & Information Handling
If I was the LA - I probably would not have reported it. If it did report, it would generally get triaged by the ICO investigations team. I was previously at the ICO, and I would probably triage it at the lowest risk rating (P4 rating) You can view the rating system on the FOI reply below, its at page 48. https://ico.org.uk/media/about-the-ico/disclosure-log/4018514/investigations-manual-final-disclosure-redacted-3.pdf The data was sent via secure transfer, and therefore protected in transit. Whilst the school received other pupils data, I would take into consideration it was received and viewed by a trusted professional. On balance, I would have trust the school deleted the data and would not further use the data in a malicious or negligent manner. Presuming the ICO followed that same trail of thought, the breach report would be marked as P4 and either closed or closed with advice around double checking data before it is sent. The ICO may have asked some follow up questions to determine the P rating, such as whether the school who received the incorrect data had actually deleted it. They may have even just put that as part of its closure advice. There is nothing within the original post that would make me feel it would justify a higher P rating, and therefore require a full investigation or warrant any regulation action. -
School Central Record, "SCR" Security
rom1984 replied to soapyfish's topic in Data Protection & Information Handling
If the document was breached and it was reported as a personal data breach then I'd be looking at the security of the document itself, but also the wider security considerations. For example, some of the areas I'd touch on would include: Governance/ISMS: I would be looking at the types of information security policies in place - were senior management directing and taking ownership for the minimum levels of security required, for example, via authorised policies. How often were the policies reviewed, how were they communicated to staff. What roles decides what 'appropriate security' looks like within the school - how was this defined, who decides this, who has ultimate sign-off. Were IT staff given risk tolerance levels to work with - what was the risk tolerance level on the SCR, where was this documented. Classification Policy - I'd be looking at how you classified the data you processed, for example, via a classification policy. Was the classification based on the sensitivity of the data, did the school recognise different personal data requires different levels of security, did the classification level recognise special category data as a higher classification level. What did this mean for security, for example, did data classified as a higher level require additional levels of protection. If so, what were these additional layers (encryption, stronger detection controls etc). What level of classification was the SCR at? Where was this defined. Asset Management - how did the school manage it assets that processed the SCR, was the underlying host OS in support, was it patched and up to date, how did the school manage the lifecycle of assets processing the SCR, who authorised where the SCR could be stored - was the asset appropriate for the SCR Technical Control Selection - what technical controls were applied on the host such as AV/Endpoint protection, allow/deny lists, DLP etc. I'd be splitting this up into preventive and detective controls. For example - could you detect if an unauthorised actor tried to access the document? Could you detect malicious software on the host, did the server have out-going internet access - if so, did it require it? Could you detect the SCR being exfiltrated/copied Access Controls - how did you manage access controls, did you follow the principles of least privilege, was there a policy in place that directed this? How were privileged accounts protected? Risk Management - how did you identify threats to the asset/SCR - was a risk assessment on the asset done, who had final authorisation the asset/SCR was appropriately protected Testing, Reviews and Assurance - what kind of assurance did senior management require that the SCR was appropriately secured - eg Word of mouth, written report, internal audit, external audit, accreditation against Cyber Essentials etc. Who was responsible for ensuring the document was kept up to date, retention policies, were roles and responsibilities defined. How often were access controls reviewed for privileged creep etc, how did you identify vulnerabilities on the hosts Disaster Recovery - what was the backup architecture in place, how often was this tested, when was the last time a test restore was carried out, could a malicious actor access the backup if it was to compromise a privileged account, what would the risks of this be, Staff Education - did staff who assessed the document require any additional training on the sensitivity of the file? If so, what training, how often, It would not necessarily be the case that a negative answer therefore means non-compliance. For example, you might determine the annual 'data protection training' was an appropriate level of training and the staff that accessed the SCR did not need additional training above this. But these are some of the areas that I would potentially explore, depending on how bad the breach was. -
Hi all, I've published some guidance around ransomware and data protection compliance if anyone is interested. Any feedback on areas of improvement or where we could develop it further is welcome! https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/security/ransomware-and-data-protection-compliance/ The initial plan was to look back at the cases from 2020/2021 and describe the main attacker tactics that we saw. However, it kind of developed and spun into a bigger piece where we started to look at the most common question we get. There is a checklist of security considerations included within it - these are typically some of the main areas that we would look at when investigating whether appropriate technical and organisational controls were in place relevant to cyber/information security.
-
- 4
-
-
Cookies can be a type of personal data in some circumstances, for example, a user authentication cookie. I think you are saying in this example they are not. But I think the relevant legislation here is PECR rather the GDPR, although PECR uses the GDPR for some of its definitions - e.g. the definition of consent.
-
Spamming FOI Requests
rom1984 replied to garbage46's topic in Data Protection & Information Handling
I am no FoI expert but I do give my opinion on security matters to case officers who deal with complaints about exemptions so I can give some input on what I would be looking at. For some further input too - advice and guidance from NIST can and does get used in tribunals as an industry standard of best practice. I've citied NIST in many cases including ones at low tier tribunals to support my security assessments. What I would be looking at the organisation to demonstrate is why the release of the information would likely cause a security risk. For example, if an organisation said the release of its photo-copy make and model would cause a security risk, well why, what risks exactly and what is the likelihood of the risk occuring? This isn't formally defined, but I think I’d be looking at where the risks fit into the following: • Impossible - no possible security risks can come of it • Theoretically possible - but unlikely due to resources required (i.e. would involve the attacker creating a zero-day, or would need the attacker to already have gained unauthorised but authenticated access first) • Theoretically possible - and likely (i.e. resources such as a time and effort are unlikely to be a barrier. Compromise would be trivial) • Certain - the release of the information would certainly and without questions cause a our system to be compromised What I would not factor in, is my opinion on whether the release of the information should cause a security risk. As a bad example because its not public sector, but Microsoft argue the release of its source code can cause a security risk because it allows people to view it and identify vulnerabilities. Some people in the security industry disagree with this position. I would not make an assessment on who is right and wrong, the facts of the case are Microsoft do rely on security by obscurity and I can't undermine that because of my own opinion of what I think it right. If the school was taking the position that it lacks good patch management as a reason to do not release make and model, I'd be looking at written statements from the most senior management setting that out. And in addition, why the lack of poor patch management would cause a risk in the context of releasing information about the make and model of a printer, and the likelihood etc as listed above. I couldn’t take the position that the school should be patching, because if its senior management has set out that it does not, then that is the fact of the matter. -
I got the Ooni Fyra last Christmas - I loved it at first but I wish I got the gas one now. I think you can get a convertor so I might look at getting that. Love your setup @supportman!
-
I've got a 57" Weber Kettle with a pizza stone, but never got good results. Bought one of the original Ooni pellet from eBay which is amazing, and looking at getting Ooni Frya @RobD what Kamodo Joe have you got? Been looking at the Joe Jnr too for steaks and one person cooks
-
Free Certified Network Security Specialist - Certified by CNSS
rom1984 replied to MYK-IT's topic in Courses and Training
Great spot thanks! Does anyone know when you purchase the exam if you can do it remotely? -
Access to employees files.
rom1984 replied to JaffaC121's topic in Data Protection & Information Handling
Just checked out the AUP and it says "Where personal use is allowed you should ensure the following: Mark personal emails private or "non-work" in the subject header to differentiate these from business email... We are committed to respecting staff expectations of privacy concerning the use of our ICT Systems and equipment. However, we reserve the right to log and monitor such use." This specific policy is linked it with ISO/IE 27001:2013 - no idea if that helps! We have a "steering group" made of off DPO, Head of Complaints, Head of Governance and Head of IT which makes any decision ref this. Is there anything in the ICOs Employment Practise code that would help? - https://ico.org.uk/media/for-organisations/documents/1064/the_employment_practices_code.pdf -
Access to employees files.
rom1984 replied to JaffaC121's topic in Data Protection & Information Handling
Were asked to mark any emails/folders etc as "personal" if they contain something personal that we wouldn't want the employer to access. It will generally be honoured that these will not be manually accessed (unless there is a good reason not to honour it) -
Your DPO shold be involved, closely, in all data protection matters. So I'd personally expect a DPO to be involved in the writing/improvement of the AUP, especially modifying it to reflect DP compliance. In a perfect work I'd expect something like business manager, DPO, safe guarding link and IT to be involved in it with SLT providing ultimate sign off.
-
New Supplier GDPR Risk Assessment / questions
rom1984 replied to tj2419's topic in Data Protection & Information Handling
I've not got any specific templates but one of the things I like to look at for cloud service providers is if the company is registered on the Cloud Security Alliance's STAR register (Security Trust Assurance and Risk Register). You can search them on this link; https://cloudsecurityalliance.org/star/registry/ It allows an organisation to complete an assessment against the CSA's own cloud security controls. Depending on the type of organisation it is either self-assessed or via a third party audit. You can then use this as proof as your due diligence in regards to the security of the organisation. You can also ask if the organisation follows a particular security model or framework, for example the NCSC Cyber Essentails, ISO2700, NIST 500 etc I also like to see particular KPI or SLA that allow the organisation to monitor the security of the organisation. For example, a policy or procedure that states an annual check on the company to confirm if they are still maintain particular security certifications etc (if relevant). Reference are also a good way to demonstrate due-diligence, so if you know a school that already uses the particular software you can ask them about it from a DP compliance point of view (I.e can you easily delete personal data, does it allow different levels of access etc) Do you believe the new system will be processing personal data that is likely to result in a high risk? If so, as above, you will be required to do the DPIA as a requirement. -
What sort of bike would you recommend for doing this kind of trial? (i.e mountain bike, road bike etc). Really want to get into cycling but I'm too nervous to cycle on the road lol. There are a few trails like this near me but not sure what kind of bike would be appropriate
-
Could some please explain sensitive data...?
rom1984 replied to Koldov's topic in Data Protection & Information Handling
Its the wording of the questions that is some what wrong. Sensitive data is an old DPA98 term. The correct terminology that they are trying to ask about is special category data. Telephone numbers, name, email address etc is personal data. race, ethnic origin, health, biometrics, sex life, sexual orientation trade union membership, religion and politics can also be personal data but is classed as special category data. Special category data is usually more sensitive than "normal" personal data. As such the GDPR says you need to satisfy a special condition under Article 9 as well as your usual lawful basis for processing. It also requires more protection than personal data because there is a greater risk in processing it. The question should say what is special category data.
