executive summary
Protecting Personal Information: A Guide for Businesses
Small Business Administration
Companies keep sensitive personal information in their les—names, social security num- bers, credit card or other account data—that identi es customers or employees. This infor- mation often is necessary to ll orders, meet payroll, or perform other necessary business functions. However, if sensitive data falls into the wrong hands, it can lead to fraud, identity theft, or similar troubles. Given the high cost of a security breach—losing your customers’ trust and perhaps even defending yourself against a lawsuit—it is just plain good business to safeguard personal information.
Protect the Information That You Keep
What’s the best way to protect the sensitive, personal information your company needs to keep? It depends on the kind of information and how it’s stored. The most effective data
security plans deal with four key elements: physical security, electronic security, password
management, and employee training, all of which are discussed below.
Physical Security
Many data compromises happen the old-fashioned way—through lost or stolen paper docu- ments. Often, the best defense is a locked door or an alert employee. Here are some helpful ways to protect information from falling into the wrong hands:
First of all, store paper documents or les, as well as CDs, oppy disks, Zip drives, tapes, and backups containing personally identi able information, in a locked room or in a locked le cabinet. Limit access to employees with a legitimate business need. Control who has a key, and the number of keys. Then require that les containing personally identi able in- formation be kept in locked le cabinets except when an employee is working on the le. Remind employees not to leave sensitive papers out on their desks when they are away from their workstations, to put les away, log off their computers, and lock their le cabinets and of ce doors at the end of the day.
Next, implement appropriate access controls for your building. Tell employees what to do and whom to call if they see an unfamiliar person in the of ce or elsewhere on the premises. If you maintain off-site storage facilities, limit employee access to those with a legitimate business need. Know if and when someone accesses the storage site. For example, if you ship sensitive information using outside carriers or contractors, encrypt the information and keep an inventory of the information being shipped. Also, use an overnight shipping service that will allow you to track the delivery of your information.
Electronic Security
Computer security isn’t just the realm of your IT staff. Make it your business to understand the vulnerabilities of your computer system, and follow the advice of experts in the eld. To do this, identify the computers or servers where sensitive personal information is stored. Make sure, too, that you identify all connections to the computers where you store sensitive information. These may include the Internet, electronic cash registers, computers at your branch of ces, computers used by service providers to support your network, and wireless devices like inventory scanners or cell phones.
Moreover, encrypt all sensitive information that you send to third parties over public networks (like the Internet), and consider encrypting sensitive information stored on your computer network or on disks or portable storage devices used by your employees. It is a smart idea to encrypt e-mail transmissions as well—within your company if they con- tain personally identifying information. In addition, regularly run up-to-date anti-virus and anti-spyware programs on individual computers and on servers on your network. Check expert websites (such as www.sans.org) and your software vendors’ websites regularly for alerts about new threats and to learn about implementing new policies for installing vendor- approved patches to correct problems.
Most important of all, scan the computers on your network to identify and pro le the operating system and open network services. If you nd services that you don’t need, disable them to prevent hacking or other potential security problems. For example, if e-mail service or an Internet connection is not necessary on a certain computer, close the ports to those services on that computer to prevent unauthorized access to that machine. When you receive or transmit credit card information or other sensitive nancial data, use Secure Sockets Layer (SSL) or another secure connection that protects the information in transit.
Pay particular attention to the security of your Web applications—the software used to give information to visitors to your website and to retrieve information from them. Web
applications may be particularly vulnerable to a variety of hacker attacks. In one variation called an “injection attack,” a hacker inserts malicious commands into what looks like a legitimate request for information. Once in your system, hackers transfer sensitive infor- mation from your network to their computers. Be on guard against these attacks by more closely scrutinizing requests.
Password Management
Also essential to any business’s security is password protection. You can control access to sensitive information by requiring your employees to use “strong” passwords. Techni- cal security experts advise that the longer the password, the better. Because simple pass- words—like common dictionary words—can be easily guessed, insist that your employees choose passwords with a mix of letters, numbers, and characters. Require an employee’s user name and password to be different, and insist on frequent changes in passwords. Lock out users who don’t enter the correct password within a designated number of log-on at- tempts. Password-activated screen savers can lock employee computers after a period of inactivity.
Another wise move is to warn employees about possible calls from identity thieves at- tempting to deceive them into giving out their passwords by impersonating members of your IT staff. Let employees know that calls like this are always fraudulent, and that no one should be asking them to reveal their passwords. Set up clear and effective procedures through which employees can communicate with IT staff.
When installing new software, make sure your company immediately switches vendor- supplied default passwords to a more secure strong password and cautions employees against transmitting sensitive personally identifying data—social security numbers, passwords, ac- count information—via e-mail. Unencrypted e-mail is not a secure way to transmit any information.
Employee Training
Your data security plan may look great on paper, but it’s only as strong as the employees who implement it. Take time to explain the rules to your staff, and train them to spot secu- rity vulnerabilities. Periodic training emphasizes the importance you place on data security practices. A well-trained work force is a company’s best defense against identity theft and data breaches.
You can also create a “culture of security” by implementing a regular schedule of employee training. Update employees as you nd out about new risks and vulnerabilities. Make sure training extends to employees at satellite of ces and to temporary help and seasonal workers as well. If employees don’t attend, consider blocking their access to the network. If you train employees to recognize security threats, you can cut down on the risks such thefts pose. Tell your employees how to report suspicious activity and publicly reward employees who alert you to vulnerabilities.
Finally, ask every new employee to sign an agreement to follow your company’s con - dentiality and security standards for handling sensitive data. Make sure these most recent members of your work force understand that abiding by your company’s data security plan will be an essential part of their duties. And regularly remind all employees of your company’s policy—and any legal requirement—to keep customer information secure and con dential.