Question

In: Accounting

Why should companies have strong policies in place to protect personally identifying information?

Why should companies have strong policies in place to protect personally identifying information?

Solutions

Expert Solution

Personal identifiable information (PII) is an attractive target for hackers and cyber thieves as it is easy to steal and it is easy to sell.

Hence, Protecting PII is a challenge for individuals and businesses. As individuals, we alone are to blame if we expose our own information to risk, but organisations have a far greater liability. Every organisation is built on people and processes, and ultimately it is responsible for the actions of its staff and the effectiveness of the processes that define how PII is protected.

Reasons for loss of PII

A great deal of PII loss is the result of stolen or lost equipment, hard drives or documents. Repeated errors – such as sending information to the wrong recipients due to incorrect fax numbers or email addresses – are common reasons. Other major cause of human errors include misplacement of files, documents or mobile devices.

Online data breaches and cyber attacks were also among the common reasons for PII loss identified by the report. Significantly, they were the most costly type of data breach in terms of monetary penalties.

The consequences of PII theft

Organisations that don’t protect the personally identifiable information of its employees, members or customers put themselves to risks incurring a significant financial cost and reputation damage in the event of a data breach.

How to protect PII

  • Know where your personally identifiable information (PII) is stored – if you do not know where the information to be protected is located, then it is impossible to provide adequate protection.
  • Know who sees your data – a key control for protecting the privacy of data is access control, ensuring that only those who have a business need to access the data have the relevant rights.
  • Create policies for handling data – set rules regarding access to the data, how the data is received, stored and transmitted, what information can be sent within the organisation and what can be passed along to third parties.
  • Educate users – ensure everyone handling PII is aware of the risks and their responsibilities under the DPA. A DPA staff awareness course will help communicate key messages to staff and test their knowledge.
  • Carry out full encryption of desktop and mobile devices – USB sticks, laptops, tablets and mobile phones are major contributors to data loss. Make sure they are encrypted and that you have an appropriate BYOD policy in place.

Related Solutions

Organizations with strong cultures typically have fewer policies. Why is that?
Organizations with strong cultures typically have fewer policies. Why is that?
Identify which of the following, on their own, are personally identifying information (PII) and which are...
Identify which of the following, on their own, are personally identifying information (PII) and which are not personally identifying information (non-PII): Financial information, address of employment, personal telephone number, fingerprints, social security number, geographic indicators, and vehicle id number
Make the case against strong protectionist international trade policies (even if you personally agree with them)....
Make the case against strong protectionist international trade policies (even if you personally agree with them). Who (domestically) is harmed when tariffs are imposed? Explain the mechanism for how tariffs impact those who are harmed. (touch on more than just one group of people)
As a consumer of accounting services, what laws should be put in place to protect the...
As a consumer of accounting services, what laws should be put in place to protect the public? why?
Why is it necessary for business organisations to have policies and procedures and why should employees...
Why is it necessary for business organisations to have policies and procedures and why should employees be aware of the organisation's policies and procedures? If necessary conduct independent research?
What are primary policies that should be enacted to protect women and children? Please explain your...
What are primary policies that should be enacted to protect women and children? Please explain your answer
What are primary policies that should be enacted to protect women and children? Please explain your...
What are primary policies that should be enacted to protect women and children? Please explain your answer.
Why would it be important for policies to be put in place in order to mitigate...
Why would it be important for policies to be put in place in order to mitigate harm? How could one apply categorical and consequentialist moral reasoning to the ethical questions the application raises?
Almost all insurance companies have a reinsurance program in place. Provide 4 reasons why it is...
Almost all insurance companies have a reinsurance program in place. Provide 4 reasons why it is important for a policy holder to make sure that her insurance policy is backed by a strong reinsurance company.
* Should companies be doing more to make the world a better place? Yes or No?...
* Should companies be doing more to make the world a better place? Yes or No? Defend your answer in completeness.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT