Enter your Email


Powered by FeedBlitz
Ted Demopoulos Ted's contact info
Ted lives in Durham, New Hampshire, USA, with his wife Margaret, children Jamie, Amelia, Anastasia, and dog Tyler. He consults and gives keynotes on Technology, Security, and Business. He loves flyfishing, ham radio, and great food and wine.

Main Website

Keynote Speeches

Free Articles

securITy Newsletter

More about Ted

Atom/RSS feed

Add to My Yahoo!

Subscribe with Bloglines

Subscribe in NewsGator Online

•Profitable College Speaking Bootcamp

•Striped Bass Fly Fishing

•College Speaker

•Shopping Carts for Blogs and Websites

•Book Reviews

•SANS Network Security 2008

•Need a Shopping Cart?

•Security Laboratory

•Become a Published Author and Public Speaker

•SANS Security Training

•Geekonomics

•Security Thought Leader

UC Berkeley: Personal Data on Laptops

No Effective Security Policy at UC Berkeley?


A stolen laptop that contained personal info of almost 100,000 California university applicants and students, including social security numbers, has been recovered, reports Reuters. That data should NEVER HAVE BEEN ALLOWED ON A LAPTOP.

Many, perhaps most, organizations do a horrible job in protecting people's private information - actually ALL information!

Technology alone is no solution. The data had been allegedly encrypted on the laptop, but my 12 year old nephew probably have accessed it.

Computer/Information Security is a process. It includes:

Security Policy, Procedures, & Technologies.

Companies need a written plan and guidelines, typically called "Security Policy," which everyone should know about and follow. All Companies should have a Security Policy which describes, among other things, how different information is protected. EVERYONE should be required to read and sign this short info security policy document including the CEO, executives, etc.

Procedures are step by step directions for doing things specified by the policy. The policy might say "update anti-virus protection daily," and procedures would describe how.

There should have been Security Policy that did not allow this personal data on (easily stolen) laptops! Maybe there was, but policies also need to audit and enforce compliance to be effective.

This is NOT rocket science, and this loss of personal data is INEXCUSABLE. Yes I'm SHOUTING!! I'm mad when I see such incredible incompetence!!!!!

That said, security is never perfect! It's never absolute.OK, I've calmed down.
Like the bumper sticker says,

"Security Events Occur"

Comments on "UC Berkeley: Personal Data on Laptops"

 

post a comment

      
      

Most Internet users have been targeted by criminal phishing emails, yet less than one third have any idea what phishing is, and only 3.5% have changed their habits due to the threat of phishing!

Risks include Identity Theft, Credit Card fraud, and more.

Download Results (pdf)