HMRC building
The KTN hope the guidelines will prevent information loses on the scale of HMRC
R E L A T E D   C O N T E N T
ADVERTISEMENT

Cyber Security KTN issues privacy guidelines

Businesses should examine privacy implications at all stages of a project lifecycle

Tom Young, Computing 23 Apr 2008
ADVERTISEMENT

Businesses must meet privacy requirements at four stages of any project lifecycle that may involve personal information, according to a report from the Cyber Security Knowledge Transfer Network (KTN).

In order to protect customer and employee details, privacy must examined at the initiation, planning, execution and closure of a generic project lifecycle.

This will ensure organisations comply with any future guidelines as well as current ones, according to Nigel Jones, head of KTN.

"Trying to engineer privacy as an afterthought never works," he said. "This is the only way organisations can be sure they are doing the right thing."

The paper recommends that:

- At the project initiation stage high level privacy objectives need to be set - project owners need to be aware of applicable privacy laws and regulations, such as the EU Data Protection Directive and the US Safe Harbour agreement.

- Technology envisaged for use by the project should also be subject to a high level review to ensure that appropriate privacy controls can be implemented.

- At The project-planning stage technologies such as encryption should be considered to protect consumer and client data on storage media, and Privacy Imapct Assessments should be carried out.

- Audits and change control procedures should continue after the closure of a project to ensure privacy requirements are continually addressed.

- Organisations should ensure that a senior role is established with overall responsibility for privacy, and ensure that responsibility is not delegated, as in the case of the HM Revenue and Customs lost discs fiasco.

- When a project is decommissioned all relevant information needs to be carefully destroyed.

- Customers should also as far as possible be given the choice of opting out of services that require the collection of additional personal information.

- Systems should have strong access controls, to ensure that personal information is only accessed by those who are authorised to do so. Access should be logged, and logs regularly audited.

- Where possible, personal information should be stored together with metadata that describes it and its intended use.

- Organisations should implement transparent procedures for remediation of errors in personal information, or privacy breaches.

The Cyber Security KTN is run by QinetiQ on behalf of the government’s Technology Strategy Board.

See also:

Richard ThomasOffice will be given ability to spot check central government  22 Apr 2008
ICO logoControversial system must be opt in and keep information anonymous, says ICO  10 Apr 2008
BT logoInformation Commissioner's Office wants experts to scrutinise the technology  07 Apr 2008
jonathan bamfordBut Office of Government Commerce rejects use of assessments as standard  06 Mar 2008
Marks and Spencer shopWatchdog rules loss of 26,000 employees' details on unencrypted laptop breaks the law  25 Jan 2008

All Privacy & Data
Tags: Government, Security, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
London, United Kingdom | Deloitte
Technology and Systems Consulting Event - LondonWith the right balance, you'll achieve great things. Join our Consulting practice and have the opportunity to balance your technical and business consulting skills to bring out the best ... more >
Oxford, Oxfordshire, United Kingdom | University of Oxford
Senior Business Analyst - Oxford University - £34,793 - £45,397   Business Services & Projects (BSP) Are you an experienced Business Analyst with the skills to improve the efficiency of Oxford University's business systems? The ... more >
London, United Kingdom | Utilyx
Senior Business Analyst - London Highly professional individual capable of working at senior / board level with blue chip clients - shaping and driving the analysis and design of their energy management solutions Proven capability ... more >
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
More jobs
Job zone
Job of the week
Related jobs
Search for a job
 
Try our Advanced search