Physical Security
On-premises storage of personal information requires NHRIs to ensure the physical security of their
servers, computers, laptops, phones, tablets and any other storage devices like USB sticks. If these
items are stolen or tampered with, the personal information they hold can be compromised. If located
in offices where visitors or contractors are given access, or other unsecured environments, this will
be a significant risk.
(!) Fire, flood, or other natural disasters, lack of maintenance, old equipment past its working
lifespan can all be factors that lead to irretrievable data loss if adequate backups are not
in place.
Cyber Security
Many threats to security of personal information will not come from physical intrusions but rather from
intrusions that are done remotely (i.e. cyber-attack).
There are some basic measures and software tools NHRIs can implement at low cost to mitigate risk
of cyber security threats.
•
Regular software updates and patches: Keeping systems and applications up to date with the
latest security patches to protect against vulnerabilities
•
Encryption: Converting data into a coded format to protect it during transmission or storage.
Encrypted data can only be accessed by authorised parties with the correct decryption key.
There are low-cost encryption tools available.
•
Firewalls: Security systems that monitor and control incoming and outgoing network traffic
based on predetermined security rules, creating a barrier between the trusted internal network
and the internet.
•
Anti-virus and anti-malware software: Programs designed to detect, prevent, and remove
malicious software, such as viruses, ransomware, and spyware.
•
Access control: Implementing user authentication systems (e.g., passwords, biometrics, twofactor authentication) to ensure that only authorised individuals can access sensitive data or
systems. Implementing Privilege Access Management or roles-based access control mechanisms
is an effective way to achieve a good standard of access control.
•
Data loss prevention: Tools that monitor and protect sensitive data to prevent accidental
or intentional leakage of information, such as preventing copying, emailing or printing of
sensitive files.
•
Security policies and procedures: Clear documentation of security policies and procedures,
outlining how data should be collected, accessed, stored, and protected. Policies should be
regularly updated to reflect evolving threats and regulatory changes.
•
Password managers: NHRIs should consider using a reputable password manager with an
organisational account that ensures staff will have secure passwords for their work-related accounts.
Data Protection Guidelines for NHRIs Toolkit
19