You are using an outdated browser. Upgrade your browser today for a better experience of this site and many others.

Call 01795 428 928 - Email info@ctaccounts.com

Data security - access

Storing and gaining access to personal data on computers, networks and systems is an ever-changing area. We look at the important information to consider.

The key issues to consider when reviewing the storage of and access to personal data on computers and networks. If your business is in the Kent area we, at CT Associates, can provide you with assistance or any additional information required.

Many businesses are now completely reliant on the data stored on their network servers, PCs, laptops, mobile devices and cloud service providers. Some of this data is likely to contain either personal information and/or confidential company information.

Here we look at some of the issues to consider when reviewing the security of your computer systems with respect to access controls. The General Data Protection Regulation (GDPR) sets out the security principle, which states you must take ‘appropriate technical and organisational measures’ when securely processing personal data. This is also repeated as the 6th Principle of the Data Protection Act (DPA) 2018, which enhances the GDPR and also states a ‘requirement that personal data be processed in a secure manner’.

For this reason preventing unauthorised or accidental access to the personal data you process is an important step towards compliance.

Access security

Good access controls to the computers and the network minimises the risk of data theft or misuse.

Access controls can be divided into two main areas:

  • physical access - controls over who can enter the premises and who can access personal data
  • logical access - controls to ensure employees only have access to the appropriate software, data and devices necessary to perform their particular role.

Physical access

As well as having physical access controls such as locks, alarms, security lighting and CCTV there are other considerations, such as how access to the premises is controlled.

Visitors should not be allowed to roam unless under strict supervision.

Ensure that computer screens are not visible from the outside.

Use network policies to ensure that workstations and/or mobile devices are locked when they are unattended or not being used.

Ensure that if a mobile device is lost it can be immobilised remotely.

Mobile devices being small are high-risk items so sensitive data should always be encrypted and access to the service should be controlled via a pin number or password.

It may be necessary to disable or restrict access to USB devices and optical readers and writers.

It may be necessary to block network ports via Radius servers, or other network hardware, to prevent unauthorised equipment being plugged into the network via a cable.

Finally, information on hard-copy should be disposed of securely.

Logical access

Logical access techniques should be employed to ensure that personnel do not have more access than is necessary for them to perform their role.

Sensitive data should be encrypted and access to this data controlled via network security, access control lists and user profiles.

Access to certain applications and certain folders may also need to be restricted on a user-by-user basis.

Finally, it may be necessary to lock down certain devices on certain machines, either via group policy in Windows, or a third-party management application.

Passwords

A password policy consisting of a username and password is good practice.

These help identify a user on the network and enable the appropriate permissions to be assigned.

For passwords to be effective, however, they should:

  • be relatively long (i.e. eight characters or more)
  • contain a mixture of alpha, numeric and special characters (such as &^”)
  • be changed regularly through automatic password renewal options
  • be removed or changed when an employee leaves
  • be used on individual files such as spreadsheets or word processed documents which contain personal information
  • be encrypted within your systems using a strong encryption algorithm

and should NOT

  • be a blanket password (i.e. the same for all applications or for all users)
  • be written on ‘post it’ notes that are stuck on the keyboard or screen
  • consist of common words or phrases, or the company name.
  • be sent via email, unless it is just a temporary password (with no supporting information such as, what it is for and what the username is)
  • not be stored as plain text within your systems.

Auditing access

Whilst not a legal requirement of the GDPR, the logging and monitoring of data (and the changes made upon it) will go a long way to supporting compliance with Article 32 of the GDPR.

Auditing your data processing will allow you to review, report and prove:

  • who has accessed the data and when
  • how often the data is accessed and whether this amount of access is appropriate
  • in the event of accidental data loss, review what changes have been made and by whom.

Whilst both the GDPR and DPA 2018 do not state the exact measures you need to undertake, you should consider using a technical solution that is appropriate to your needs and that of the data you are processing.

How we can help

If your business is in the Kent area we can provide help in the following areas:

  • defining and documenting data security and access procedures
  • performing a security/information audit
  • training staff in security principles and procedures.

Please contact us at CT Associates if you would like any help in any of these areas.

CTA have been a massive help with our small business growth, not only have they saved us money with their advice they are also very approachable and always happy to help. We feel confident and secure using their services. We'd highly recommend them to anyone needing an accountant.

Kelly @ Enhance ICE

They have a wonderful team, and really do set your mind at ease when looking after your accounts. Notably Khush, Janet, Donna and Sandra have all been so kind and helpful. When you have CT Associates as your accountants you really feel they go out of their way to understand your business and meet your needs. I cannot recommend CT Associates enough!

Emma @ HEM Clinic

We have worked with CTA the past 8 years, the staff & in particular Khush have been really helpful in assisting us in sorting out all our accounting needs & have given us outstanding service each year we have worked together.

I have personally recommended CTA to a number of individuals & companies & would continue to do so, their friendly staff are always on hand to answer any questions we may have & always return everything on time. We are very lucky to be working with such a professional company & cannot recommend them highly enough to anyone looking for assistance with their accounts.

Scott & Craig @ Pro Soccer

Working with Khush and team at CT Associates is like a breath of fresh air. Good value service, with minimal fuss. Highly recommended.

Chris @ DDS Int.

I have used CT Associates for my business accounting for the last 8 years and have always found Khush and the team provide a high standard of service and great value for money.

Lee @ Smythe & Walter

CTA have been my accountants since I started my company and have always provided excellent advice plus a super, thorough service.

Pat @ Safety Services

The Team at CT Associates have been a great support to our business over the last 5 years. They are always at the end of the phone and very quick to respond to any queries or concerns. Everyone is very friendly, helpful and supportive - a great Team – thank you.

Sally @ Care and Choice

I approached CTA to handle our firms accountancy needs 2 years ago following a recommendation, I have always found their work excellent, they are professional, efficient and helpful and Khush offers us help and advice when we need it.

They all count in this firm 😊

I would highly recommend their services and look forward to many more years of working with them all.

Emma @ Oliver’s Personnel

CTA are awesome to work with. Khush and his team do a great job and are always accessible for advice when I need it!

Tom @ TLP

We have been with C.T. Associates since its inception 13 years ago and have never looked back.

The staff are friendly and helpful while maintaining a very professional service.

We highly recommend C.T. Associates for all of your accounting needs.

Jacqueline @ Acorn

I have been a client of CT Associates for nearly twenty years in all that time they have never let me down. They are the cornerstone of my business. Their staff are supportive, helpful and efficient. Their advice is indispensable and plays a critical part in the success of my business. I can thoroughly recommend this excellent service.

D M Averley @ Pilscare

The professional support given to me in starting up and running my companies has been excellent. I could have not asked for better customer service – thank you CT Associates.

Captain Hadnett @ Albatross Sailing & Marine Masterclass