Solved

data sharing with 3rd parties - non technical question

Posted on 2013-12-02
5
451 Views
Last Modified: 2013-12-06
Do the organisations you work for have any requirements to share data with 3rd parties, for whatever reason?

I am trying to establish who in your organisations keep track on any data sharing agreements with 3rd parties - and whether you keep a central list of all data sharing - or any risks you can share in not keeping tabs on data sharing agreements? i.e. no central oversight of data sharing agreements with 3rd parties - whats the risk?

albeit not a tech question with your jobs handling data I assume you may be the ones who have to get data ready for sharing with 3rd parties, hence may have some insight in this area.
0
Comment
Question by:pma111
  • 2
  • 2
5 Comments
 
LVL 76

Accepted Solution

by:
slightwv (䄆 Netminder) earned 250 total points
ID: 39690321
We have MOU's with all outside parties that receive our data and with parties that supply data to us.

If you don't have some 'legal' document that outlines the terms then the receiving parties can do whatever they want with the data.  Like sell it, give it to competing organizations, etc...

If your company needs to share it with someone, they need to dictate what can and cannot be done with it.
0
 
LVL 3

Author Comment

by:pma111
ID: 39690323
Also interested if your data sharing policies formally state any security measures that need to be used when transferring data. I think in the UK their is the context of subject access whereby members of the public can ask an organisation what data they hold about them and why and by law this has to be provided.
0
 
LVL 3

Author Comment

by:pma111
ID: 39690337
Thanks slightwv - I was also interested in the risks of not having anyone in your company not having complete corporate oversight on what data is shared with whom, and any risks associated with not having a corporate oversight of what data sharing you have coming in/going out the organisation.

I appreciate you have to have the rules on what the data can be used for etc.

Does someone in your organisation keep tabs on what data sharing is going on?
0
 
LVL 76

Expert Comment

by:slightwv (䄆 Netminder)
ID: 39690391
We have many lawyers that do many things...  I can't go into great detail about my employer.

Most organizations also have a document data flow somewhere.  If data is shared, then that is data flow (even if it is on CD and mailed).  It should be documented.

As far as the risks go:  If the data is worth collecting and storing in the first place, is it not worth protecting?

A lot depends on the data itself.  Imagine how many companies would LOVE to get their hands on their competitors data.

Just internally, do you let all employees know what all other employees are making?  Not a great idea.  Access and dissemination of payroll data should be documented just like any other data.
0
 
LVL 23

Assisted Solution

by:David
David earned 250 total points
ID: 39690398
In the American culture, at least, people are very prone to sue -- almost as if you just look at them funny.  Mis-use of someone's else property (data), and/or privacy violations (personally identifiable information) is illegal, to some degree or another.  So to your last comment, corporate governance should prescribe what is, and what is not, permitted.

Our security policy calls for data in transit, and at rest, to be encrypted.  For example, the transfer might utilize a virtual private network with an encrypted tunnel, rather than the traditional FTP exchange.  Another good approach is for the target system to pull data up (only), rather than accepting pushed data.

Lastly, a very overlooked aspect is to determine data retention -- and its consequent destruction.  For example, you may have to keep email for some number of years -- but it would be very unwise to simply put your backup media out in the day's trash.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

CCModeler offers a way to enter basic information like entities, attributes and relationships and export them as yEd or erviz diagram. It also can import existing Access or SQL Server tables with relationships.
International Data Corporation (IDC) prognosticates that before the current the year gets over disbursing on IT framework products to be sent in cloud environs will be $37.1B.
Via a live example, show how to restore a database from backup after a simulated disk failure using RMAN.
This video explains what a user managed backup is and shows how to take one, providing a couple of simple example scripts.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now