F
F
Fortune7772019-03-18 13:55:00
System administration
Fortune777, 2019-03-18 13:55:00

How to ensure data security in a company if an employee is fired?

Yes, I know that the correct answer is: no way) But now I want to ask not only about IT specialists, but in general about everyone: managers, department heads, marketers, and so on. For example, an employee created a content plan document on his disk, and then quit and that's it, there are no accesses, or something else. How can companies protect themselves in advance from this?
As I understand it, all data must be stored in the clouds, and the director should have access to it and limited rights for individuals. And if an employee leaves, they either freeze his access or change all passwords. What other nuances are there?

Answer the question

In order to leave comments, you need to log in

5 answer(s)
S
Sergey, 2019-03-18
@feanor7

The first thing that the IS teacher broadcasts is that everything starts with documents and security in an organization is a set of measures.
1. You, as an information security specialist in your company, develop a threat model, that is, an intruder model.
2. A regulation on information security is being born, or a fairly detailed regulation on a corporate network in which all cases with access are prescribed (it is possible in applications)
3. You can solve some of the measures technically, in one of the departments at the top level it was decided that flash drives would be prohibited (I objected , but no one listened, they gave birth to a whole order), well, they sawed out flash drives from users, after 2 weeks they remembered about the client bank))) well, then you understand yourself
4. Before you start doing something, you and the management must understand what you want to get in end.
I recommend obliging everyone to store working documents on a network ball. The ball is reserved. Upon dismissal, even if the employee rubs his folder, you will restore everything from the backup.
Same with the cloud.

E
Edward, 2019-03-18
@edvardpotter

Any information that a person can see, hear or feel can be stolen. For such things there are mandatory requirements in the contract. Therefore, if, for example, it is proved that such and such a person published / transmitted information that contains a trade secret, then this person can already be held liable.
If you are afraid that the employee will destroy some information that may be useful to the company, then you need to oblige the employee to store all the information on your servers (which will be backed up accordingly)

C
CityCat4, 2019-03-18
@CityCat4

The measures are mainly organizational.
Technically, you can do the following:
- prohibit storage in the clouds (especially in the light of an article on Habré about how myspace has passed data for many years)
- prohibit the use of personal mail (sending to your personal mail through her webmord is the easiest way to steal data)
- prohibit removable media
- in addition to everything else, you can put SMP. It will not protect against the fact of theft, but it will help to establish the fact itself (and then work for other people :))
- store all working materials only on the network, in the area that is backed up daily
- when the chela is dismissed, when the admin signs the bypass - he is at this moment locks the account and shuts down the computer.

R
Ronald McDonald, 2019-03-21
@Zoominger

Absolutely nothing. If a person has a head, then he will collect all the documents, letters and scans that pass through his hands and slowly accumulate them, and you won’t do anything about it, only if you assign a guard to each employee. Spy games in a mishandled Cossack are rare, they usually leak data out of revenge, and this situation can be eliminated if you do not give employees a reason to take revenge on the employer, but this is difficult, for this you need to pay a decent salary and comply with the Labor Code of the Russian Federation.

A
Artem @Jump, 2019-03-18
Tag

Depending on what is meant by safety.

  • When it comes to data leakage - no way. In a sense, of course, it is possible to decide, but this is a set of measures - orders, those. restrictions, physical control of user access to equipment, screening of employees.
  • If we are talking about the destruction of data - elementary. We store all data on a network ball. The employee left, deleted the account, created a new one, gave access to documents.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question