Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Georgia on my Security Mind... | Main | Vermont Incident Demonstrates Many Security Snafus »

Another Email Oops...

Last Thursday it was reported that the Social Security numbers of the 1,250 teachers and school administrators in the Connecticut Technical High School System were mistakenly sent via e-mail to staff

"The e-mail was sent to the system's 17 principals...to inform them about a coming workshop.  The file with the Social Security numbers was attached to the e-mail by mistake".

"At least one principal...then forwarded the e-mail to 77 staff members without opening the attachment containing the Social Security numbers."

A few important lessons here...

  • Humans are the weakest link in the information security chain...train them well...often...and in many ways.  Mistakes will still happen, but individuals will be more alert with good education by your organization.
  • You may be tired of hearing me beat the encryption drum...but the beat goes on...if the file had been strongly encrypted, the data would have been unreadable by the recipients (at leash those without the decryption key...which you would hope would be virtually all of them), making this a non-incident.  Encrypt confidential data not only in motion, but also at rest.
  • Confidential data in unstructured forms is highly vulnerable to being compromised.
  • Once you send an email, you might as well consider it has been sent out into the wild...depending upon the email system and features used, you typically have no control over where the email is forwarded to; in this instance at least 94 people now have the SSNs of 1,250 people...and if any of them have also forwarded the email...the possibilities are exponential.

Technorati Tags




TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/44

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.