10.07.2015 Views

1E9Ct5D

1E9Ct5D

1E9Ct5D

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

contact IT if they get a message that their computer or applications need updating.2. Implement Appropriate Policies.It is critical that a company or firm have and implement an Acceptable Use Policy, aNon-Disclosure Policy, a Records Management Policy, and a Code of Conduct relatedto data management and information security. A best practice involves having thesepolicies reviewed annually by a data security and policy compliance consultant to insurethey are current with the legal, business, and IT landscapes. 333. Make Annual Security Awareness Training Mandatory.It is also recommended that employees attend annual mandatory security awarenesstraining. The training can be a time to update employees on key security efforts, recentdata breach trends, and to take any questions.4. Keep the Workforce Regularly Updated.Between annual security awareness trainings, employees need to be kept regularlyupdated about security issues. For example, updates could include security bulletins orupdates on an internal company website. Employees should also know who to call withinformation security questions or notices of potential data breach attempts.5. Screen, Audit, and Monitor Company Vendors.For many companies, third-party vendors with privileged access to corporate data pose33 Judy Selby, What to do about high data breach costs, Law Technology News (June 10, 2013),http://www.lawtechnologynews.com/id=1202603594623?slreturn=20141106235933 (last visited Jan.13, 2015).March 6, 2015 19 © 3-6-2015 ALFA International Business Litigation P.G.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!