rom1984
Members-
Posts
236 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rom1984
-
Breach reporting obligations
rom1984 replied to gh5000's topic in Data Protection & Information Handling
It’s quite possible a case office could assign it as P3 and I wouldn’t particular object - It isn’t an exact science and the P rating scale is for guidance, the case officer will apply their own judgment assisted by the scale. For myself, the fact the data was exposed to a professional working within a school, who will be DBS checked etc, I would apply a P4, not withstanding the breach included special category data. To be honest, the way you handle a P3 and P4 would be pretty much the same, if not exactly the same. It’s the P1 and P2H cases where you want to be spending most of your time and resources. -
Breach reporting obligations
rom1984 replied to gh5000's topic in Data Protection & Information Handling
If I was the LA - I probably would not have reported it. If it did report, it would generally get triaged by the ICO investigations team. I was previously at the ICO, and I would probably triage it at the lowest risk rating (P4 rating) You can view the rating system on the FOI reply below, its at page 48. https://ico.org.uk/media/about-the-ico/disclosure-log/4018514/investigations-manual-final-disclosure-redacted-3.pdf The data was sent via secure transfer, and therefore protected in transit. Whilst the school received other pupils data, I would take into consideration it was received and viewed by a trusted professional. On balance, I would have trust the school deleted the data and would not further use the data in a malicious or negligent manner. Presuming the ICO followed that same trail of thought, the breach report would be marked as P4 and either closed or closed with advice around double checking data before it is sent. The ICO may have asked some follow up questions to determine the P rating, such as whether the school who received the incorrect data had actually deleted it. They may have even just put that as part of its closure advice. There is nothing within the original post that would make me feel it would justify a higher P rating, and therefore require a full investigation or warrant any regulation action. -
School Central Record, "SCR" Security
rom1984 replied to soapyfish's topic in Data Protection & Information Handling
If the document was breached and it was reported as a personal data breach then I'd be looking at the security of the document itself, but also the wider security considerations. For example, some of the areas I'd touch on would include: Governance/ISMS: I would be looking at the types of information security policies in place - were senior management directing and taking ownership for the minimum levels of security required, for example, via authorised policies. How often were the policies reviewed, how were they communicated to staff. What roles decides what 'appropriate security' looks like within the school - how was this defined, who decides this, who has ultimate sign-off. Were IT staff given risk tolerance levels to work with - what was the risk tolerance level on the SCR, where was this documented. Classification Policy - I'd be looking at how you classified the data you processed, for example, via a classification policy. Was the classification based on the sensitivity of the data, did the school recognise different personal data requires different levels of security, did the classification level recognise special category data as a higher classification level. What did this mean for security, for example, did data classified as a higher level require additional levels of protection. If so, what were these additional layers (encryption, stronger detection controls etc). What level of classification was the SCR at? Where was this defined. Asset Management - how did the school manage it assets that processed the SCR, was the underlying host OS in support, was it patched and up to date, how did the school manage the lifecycle of assets processing the SCR, who authorised where the SCR could be stored - was the asset appropriate for the SCR Technical Control Selection - what technical controls were applied on the host such as AV/Endpoint protection, allow/deny lists, DLP etc. I'd be splitting this up into preventive and detective controls. For example - could you detect if an unauthorised actor tried to access the document? Could you detect malicious software on the host, did the server have out-going internet access - if so, did it require it? Could you detect the SCR being exfiltrated/copied Access Controls - how did you manage access controls, did you follow the principles of least privilege, was there a policy in place that directed this? How were privileged accounts protected? Risk Management - how did you identify threats to the asset/SCR - was a risk assessment on the asset done, who had final authorisation the asset/SCR was appropriately protected Testing, Reviews and Assurance - what kind of assurance did senior management require that the SCR was appropriately secured - eg Word of mouth, written report, internal audit, external audit, accreditation against Cyber Essentials etc. Who was responsible for ensuring the document was kept up to date, retention policies, were roles and responsibilities defined. How often were access controls reviewed for privileged creep etc, how did you identify vulnerabilities on the hosts Disaster Recovery - what was the backup architecture in place, how often was this tested, when was the last time a test restore was carried out, could a malicious actor access the backup if it was to compromise a privileged account, what would the risks of this be, Staff Education - did staff who assessed the document require any additional training on the sensitivity of the file? If so, what training, how often, It would not necessarily be the case that a negative answer therefore means non-compliance. For example, you might determine the annual 'data protection training' was an appropriate level of training and the staff that accessed the SCR did not need additional training above this. But these are some of the areas that I would potentially explore, depending on how bad the breach was. -
Hi all, I've published some guidance around ransomware and data protection compliance if anyone is interested. Any feedback on areas of improvement or where we could develop it further is welcome! https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/security/ransomware-and-data-protection-compliance/ The initial plan was to look back at the cases from 2020/2021 and describe the main attacker tactics that we saw. However, it kind of developed and spun into a bigger piece where we started to look at the most common question we get. There is a checklist of security considerations included within it - these are typically some of the main areas that we would look at when investigating whether appropriate technical and organisational controls were in place relevant to cyber/information security.
-
- 4
-
-
Cookies can be a type of personal data in some circumstances, for example, a user authentication cookie. I think you are saying in this example they are not. But I think the relevant legislation here is PECR rather the GDPR, although PECR uses the GDPR for some of its definitions - e.g. the definition of consent.
-
Spamming FOI Requests
rom1984 replied to garbage46's topic in Data Protection & Information Handling
I am no FoI expert but I do give my opinion on security matters to case officers who deal with complaints about exemptions so I can give some input on what I would be looking at. For some further input too - advice and guidance from NIST can and does get used in tribunals as an industry standard of best practice. I've citied NIST in many cases including ones at low tier tribunals to support my security assessments. What I would be looking at the organisation to demonstrate is why the release of the information would likely cause a security risk. For example, if an organisation said the release of its photo-copy make and model would cause a security risk, well why, what risks exactly and what is the likelihood of the risk occuring? This isn't formally defined, but I think I’d be looking at where the risks fit into the following: • Impossible - no possible security risks can come of it • Theoretically possible - but unlikely due to resources required (i.e. would involve the attacker creating a zero-day, or would need the attacker to already have gained unauthorised but authenticated access first) • Theoretically possible - and likely (i.e. resources such as a time and effort are unlikely to be a barrier. Compromise would be trivial) • Certain - the release of the information would certainly and without questions cause a our system to be compromised What I would not factor in, is my opinion on whether the release of the information should cause a security risk. As a bad example because its not public sector, but Microsoft argue the release of its source code can cause a security risk because it allows people to view it and identify vulnerabilities. Some people in the security industry disagree with this position. I would not make an assessment on who is right and wrong, the facts of the case are Microsoft do rely on security by obscurity and I can't undermine that because of my own opinion of what I think it right. If the school was taking the position that it lacks good patch management as a reason to do not release make and model, I'd be looking at written statements from the most senior management setting that out. And in addition, why the lack of poor patch management would cause a risk in the context of releasing information about the make and model of a printer, and the likelihood etc as listed above. I couldn’t take the position that the school should be patching, because if its senior management has set out that it does not, then that is the fact of the matter. -
I got the Ooni Fyra last Christmas - I loved it at first but I wish I got the gas one now. I think you can get a convertor so I might look at getting that. Love your setup @supportman!
-
I've got a 57" Weber Kettle with a pizza stone, but never got good results. Bought one of the original Ooni pellet from eBay which is amazing, and looking at getting Ooni Frya @RobD what Kamodo Joe have you got? Been looking at the Joe Jnr too for steaks and one person cooks
-
Free Certified Network Security Specialist - Certified by CNSS
rom1984 replied to MYK-IT's topic in Courses and Training
Great spot thanks! Does anyone know when you purchase the exam if you can do it remotely? -
Access to employees files.
rom1984 replied to JaffaC121's topic in Data Protection & Information Handling
Just checked out the AUP and it says "Where personal use is allowed you should ensure the following: Mark personal emails private or "non-work" in the subject header to differentiate these from business email... We are committed to respecting staff expectations of privacy concerning the use of our ICT Systems and equipment. However, we reserve the right to log and monitor such use." This specific policy is linked it with ISO/IE 27001:2013 - no idea if that helps! We have a "steering group" made of off DPO, Head of Complaints, Head of Governance and Head of IT which makes any decision ref this. Is there anything in the ICOs Employment Practise code that would help? - https://ico.org.uk/media/for-organisations/documents/1064/the_employment_practices_code.pdf -
Access to employees files.
rom1984 replied to JaffaC121's topic in Data Protection & Information Handling
Were asked to mark any emails/folders etc as "personal" if they contain something personal that we wouldn't want the employer to access. It will generally be honoured that these will not be manually accessed (unless there is a good reason not to honour it) -
Your DPO shold be involved, closely, in all data protection matters. So I'd personally expect a DPO to be involved in the writing/improvement of the AUP, especially modifying it to reflect DP compliance. In a perfect work I'd expect something like business manager, DPO, safe guarding link and IT to be involved in it with SLT providing ultimate sign off.
-
New Supplier GDPR Risk Assessment / questions
rom1984 replied to tj2419's topic in Data Protection & Information Handling
I've not got any specific templates but one of the things I like to look at for cloud service providers is if the company is registered on the Cloud Security Alliance's STAR register (Security Trust Assurance and Risk Register). You can search them on this link; https://cloudsecurityalliance.org/star/registry/ It allows an organisation to complete an assessment against the CSA's own cloud security controls. Depending on the type of organisation it is either self-assessed or via a third party audit. You can then use this as proof as your due diligence in regards to the security of the organisation. You can also ask if the organisation follows a particular security model or framework, for example the NCSC Cyber Essentails, ISO2700, NIST 500 etc I also like to see particular KPI or SLA that allow the organisation to monitor the security of the organisation. For example, a policy or procedure that states an annual check on the company to confirm if they are still maintain particular security certifications etc (if relevant). Reference are also a good way to demonstrate due-diligence, so if you know a school that already uses the particular software you can ask them about it from a DP compliance point of view (I.e can you easily delete personal data, does it allow different levels of access etc) Do you believe the new system will be processing personal data that is likely to result in a high risk? If so, as above, you will be required to do the DPIA as a requirement. -
What sort of bike would you recommend for doing this kind of trial? (i.e mountain bike, road bike etc). Really want to get into cycling but I'm too nervous to cycle on the road lol. There are a few trails like this near me but not sure what kind of bike would be appropriate
-
Could some please explain sensitive data...?
rom1984 replied to Koldov's topic in Data Protection & Information Handling
Its the wording of the questions that is some what wrong. Sensitive data is an old DPA98 term. The correct terminology that they are trying to ask about is special category data. Telephone numbers, name, email address etc is personal data. race, ethnic origin, health, biometrics, sex life, sexual orientation trade union membership, religion and politics can also be personal data but is classed as special category data. Special category data is usually more sensitive than "normal" personal data. As such the GDPR says you need to satisfy a special condition under Article 9 as well as your usual lawful basis for processing. It also requires more protection than personal data because there is a greater risk in processing it. The question should say what is special category data. -
Section 170 of the DPA 2018 Act also makes it a criminal office for someone to knowingly or recklessly obtain personal data without the consent of the data controller. If a parent does this with the idea that it will give them an upper hand within a custody battle they may find it quickly back fires and they end up with a fine and an very unhappy judge. Maybe incorporate this into any DP training so these particular staff are well aware of the consequences.
-
Not my area of expertise but I believe the old DPA 98 had a Section 29 excemption and DPA 2018 does too in Schedule 2 (Exemptions etc from the GDPR) that I think would be applicable here. The exemptions allow a data controller, amongst other things, to; Withhold information or tell individuals how their data is being processed, or, Disclose personal data without applying the usual data protection principles, if, The purpose of applying the exemption was for the prevention or detection of crime, or the apprehension or prosecution of offenders. It is for the data controller making the disclose who is responsible for deciding whether the exemption applies in each case and not the person making the request. The ICO usually champions police forces to use standard forms detailing the reason why disclose is necessary, this then creates a clear audit trail that the data controller can use to demonstrate why they applied the exemption. If a police officer verbally requests information, you can make a pro-active disclose there and then, but it would normally be more appropriate that the police office puts it in writing usiong their own forces template (unless of course there is an immediate threat) The form should usually explain why the specific information is required and you can request a more senior police officer to sign it off. The school can then risk asses the information and decide if they want to apply the exemption. There is no requirement that you must disclose, it is up to the data controller. You may decide to disclose all, part or none. If you are still concerned the disclosure would breach the DPA then you can ask them to obtain a court order.
- 36 replies
-
- 3
-
-
Hi all, My old department is starting to recruit some additional Tech Policy advisors that you can see at https://ico.org.uk/about-the-ico/jobs/vacancies/ There are currently 3 jobs that are at the following scales; Lead Tech Officer Level D - £26-34k Senior Tech Officer Level E - £35-45k Principal Tech Officer Level F - £45-58k They are looking for people with backgrounds in sys admin, IT Project Management, IT security, Network Security. Historically they have struggled to recruit so if in doubt just get your application in! To give an idea of the kinds of jobs I was involved in when I was in the dept; General tech advise to the ICO (i.e. what is ransomware, why should someone encrypt this data, why would this website need to use cookies, what is an access control etc) Completing tech briefings - so we'd pick a tech subject (drones, ransomware, BYOD, IoT, social networking) and then write about it from a security/data protection point of view. Complete tech guidance (IoT, Cloud Security, Encryption etc) Review DPIA's that are tech related. So controllers will ask us to review a DPIA where this is high risk that they can not mitigate, we would then review it and give tech advise. For example we might say that personal data should be encrypted or 2FA should be used. Conference's - give tech related conference. My last one was NHS cyber security so I was talking about what the NHS should be doing to protect personal data, i.e. regular pen test, encryption, access controls etc etc For those that enjoying working within schools we do a lot of work with schools, so whilst you won't be visiting them, you will still maintain some connection to them in light of the amount of advice we give out to them. The ICO as a whole is a great place to work, not just saying it, it really is. They are very tech focused with a big push on cyber security, there looking at funding lots of training, development, certifications. I've worked here for 1 year and I've started home working 2 days a week, have a parking permanent, flexi-time, 2 days off a month flexi leave, 25 days holiday a year, 3 pay raises, 1 promotion. Any questions just ask/pm and I'l be happy to answer or point you in the right direction.
-
I've got to admit I'm not a massive fan of the wording in the original post as it's slightly misleading, although I can see what the school is trying to say. Maybe a reword to something along the lines of; "Failure to comply with the schools information/data security polices and procedures could result in disciplinary action, including dismissal. In some cases you may also be liable for criminal proceedings which could result in individual fines and/or imprisonment." In your DP training you can then expand on what are these "in some case" - for example the examples listed above or non compliance with the Computer Misuses Act.
-
Bit of a yes/no. The GDPR/DPA is to regulate data controllers and processors so the ICO would not enforce against an individual as they do not have a legal framework to do so. The individual is not the controller/processor the organisation is in the schools case. With that said there are criminal offences within the DPA 2018 that could be brought against the individual, they are; False statement made in response to an information notice Destroying or providing false information Unlawful obtaining of personal data Re-identification of de-identified personal data Alteration of personal data to prevent disclose
-
The deputy commissioner of the ICO has just put out a myth busting blog and one of the things he addressed was contacting parents to promote Christmas fairs etc. Looks like he agreed with @enjay of doing it under legitimate interests - great minds think alike https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/12/sleigh-ing-the-christmas-gdpr-myths/
-
For people that require some extra ammunition; https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/12/former-headteacher-prosecuted-for-unlawfully-obtaining-school-children-s-personal-information/ The Deputy Head had personal data of children on a USB drive. He then started at a new school and uploaded the data to their servers. The ICO fined him £700 under Section 55 of the DPA 98.
- 30 replies
-
- 42
-
-
But the school couldn't direct market under legitimate interest or have I misunderstood what you are saying? This is the run through I've got in mind; Public Task - messages relating to the child's education, e.g. Child's detention, schools closed, your child has banged his head etc. Direct marketing - any promotion or advertising e.g. Come to our BBQ/fair, look at our website, donate to our cause etc. These would all require consent. Parent Pay as an example could use the soft in option to advertise additional services via SMS providing it was a similar service they are offering and there is a clear opt out. The school couldn't take the details from Parent Pay though and use them for there own interest as this wouldn't comply with the soft opt in. The school also couldn't get a parents contact details on the proviso that it was to be used, for example, as an emergency contact, and then advertise or promote to them as this wouldn't be a commercial sale so wouldn't comply with soft opt in.
-
Warning PECR/direct marketing isn't my area of expertise but from what I can tell the official guidance would be from the PECR/Direct marketing guides. Direct marketing is defined as the communication of any advertising or marketing material which is directed to a particular individuals. So school closures, lateness, don't park on double yellows etc is not advertising or marketing material. Any promotional material, advertising or marketing such as PTA BBQ, look at our amazing website, come to our fair, would be classed as direct marketing even if you believe there is some greater good for the school. I believe the standard of direct marketing is not "how does this benefit the school or the child?" - the standard is are we promoting or advertising something? If you are advertising or marketing something, then you require consent. There is no legitimate interest / public interest to market to someone. It also says "Not-for-profit organisations need to be aware that the definition of direct marketing will cover any messages that contain marketing elements even if this is not the main purpose of the message." So as in @jmak example this message would contain elements of marketing even though that was not the main purpose of the message. You can do an opt-in asking if parents are happy to receive future marketing from the school so you wouldn't necessarily need to obtain consent every time you send a new message (providing it follows the usual consent standards).
