10 Tips for Data Security

Corresponding with Data Privacy Day, Mason, Ohio-based Cintas Corp. offered advice for businesses on how to secure enterprise and customer data.

The top 10 tips to ensure data privacy include:

1. Implement a document management program. Identify the types of documents considered confidential, and train coworkers on responsible information-handling practices. Restrict coworker access to these documents, and discourage printing of confidential data unless essential.

2. Implement a document retention schedule. Identify the amount of time to retain specific documents. Store these documents in a secure place until the retention period expires. A secure place restricts access to coworkers who don¹t have a need to access such files. When the retention period is complete, have the documents shredded by a trusted and certified company.

3. Regularly shred sensitive documents. To protect sensitive information consider a shredding service that destroys business documents onsite on a scheduled basis. These companies place secure storage containers in easily accessible and identifiable locations to make it convenient for employees to shred documents. This limits opportunities for employees to make judgment calls on what documents should be shredded. If in doubt, shred.

4. Keep documents securely offsite. In addition to outside hackers, valuable employee or customer data may also be compromised. To prevent an unauthorized coworker from accessing data, keep non-essential documents offsite, further limiting potential access.

5. Limit acquisition of confidential customer data. Review the type of customer data your business collects. Unless it is integral to the business transaction, avoid collection of information such as customers¹ social security, bank accounts or driver¹s license numbers. If the information needs to be gathered, restrict access only to those coworkers who need the information.

6. Use password protection. Protect files that contain sensitive data, including payroll, customer and financial information with passwords. Make sure your coworkers change passwords on a quarterly basis at minimum with a combination of six to eight numbers and letters in upper and lower case to further the reduce the opportunity for passwords to be compromised.

7. Install and update virus protection software. Virus protection software is the first step in preventing a worm or virus from distributing files or other stored information from a computer over the network. Make sure employees regularly check for software updates so computers are protected against the latest virus threats.

8. Clear data before disposing of old computers. Even if a computer is no longer used, sensitive data is still available on the hard drive. Potential hackers or data thieves could prey on such data. Use software programs to wipe the data or identify a data destruction vendor that will physically destroy the hard drive.

9. Review company credit card statements. Company credit card data can be compromised just as easily as consumer data. Before paying bills, make sure each employee has reviewed each item to prevent unauthorized charges. If unauthorized charges occur, be sure to notify your credit card company all three credit bureaus to protect your credit.

10. Limit use of file sharing programs. While an effective way to collaborate and share documents, file-sharing programs can also expose a computer to hackers. If they must be used, make sure the system is protected by strong firewall and virus protection software that is regularly updated. 

For reprint and licensing requests for this article, click here.
Analytics Security risk Data and information management Policy adminstration Data security Core systems
MORE FROM DIGITAL INSURANCE