<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>EPC's Computer Recyling Blog &#187; cintas</title>
	<atom:link href="http://blog.epcusa.com/tag/cintas/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.epcusa.com</link>
	<description>A blog about EPC, computer recycling, data security, and other IT related mess</description>
	<lastBuildDate>Thu, 22 Jul 2010 15:49:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>10 Tips for Protecting Business Data</title>
		<link>http://blog.epcusa.com/2010/02/10-tips-for-protecting-business-data/</link>
		<comments>http://blog.epcusa.com/2010/02/10-tips-for-protecting-business-data/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 21:16:30 +0000</pubDate>
		<dc:creator>Brian Wahoff</dc:creator>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[cintas]]></category>
		<category><![CDATA[data privacy day]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[Red Flag]]></category>
		<category><![CDATA[retention]]></category>
		<category><![CDATA[shredding]]></category>

		<guid isPermaLink="false">http://blog.epcusa.com/?p=395</guid>
		<description><![CDATA[How do you protect confidential business data? Here are 10 basic steps you can take to improve your data security program.


Related posts:<ol><li><a href='http://blog.epcusa.com/2009/03/stimulus-bill-significantly-modifies-hipaa-regulations/' rel='bookmark' title='Permanent Link: Stimulus Bill significantly modifies HIPAA regulations'>Stimulus Bill significantly modifies HIPAA regulations</a> <small>Buried within the huge American Recovery and Reinvestment Act (a.k.a,...</small></li>
<li><a href='http://blog.epcusa.com/2010/01/5-questions-to-ask-your-data-destruction-company/' rel='bookmark' title='Permanent Link: 5 Questions to ask your Data Destruction Company'>5 Questions to ask your Data Destruction Company</a> <small>When you replace your computers, what happens to the data...</small></li>
<li><a href='http://blog.epcusa.com/2009/03/data-destruction-is-one-pass-overwriting-enough/' rel='bookmark' title='Permanent Link: Data Destruction: Is One Pass Overwriting Enough?'>Data Destruction: Is One Pass Overwriting Enough?</a> <small>There is some controversy regarding data destruction in the IT...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.epcusa.com/wp-content/uploads/2010/02/paper_shredder_privacy.jpg"><img class="alignnone size-full wp-image-396" title="paper_shredder_privacy" src="http://blog.epcusa.com/wp-content/uploads/2010/02/paper_shredder_privacy.jpg" alt="Data Privacy Day is Jan 28" width="520" height="182" /></a>In honor of <a href="http://dataprivacyday2010.org/">Data Privacy Day</a> (January 28), <a href="http://cintas.com">Cintas</a> published 10 tips for protecting confidential business data. This list is a good starting point to creating your own data security program. I will list the tips below with additional recommendations on each. Many of these tips are written with paper documents in mind, but nearly all apply to digital storage as well. To see the see the original list, see <a href="http://www.your-story.org/cintas-issues-top-10-tips-for-protecting-business-data-in-honor-of-data-privacy-day-89656/">Cintas&#8217; site</a>.</p>
<ol>
<li><strong>Implement a document management program</strong>. This falls in the category of &#8220;identify your treasures.&#8221; Make a list of the different types of documents you need to keep &#8211; invoices, receipts, contracts, etc. Next determine who needs access to these documents in order to do their job. Identify security measures needed to maintain privacy of the data. Lastly, train <strong>all</strong> employees on responsible information-handling. Many certifications like PCI and Red Flag require this secure document management training to be compliant.<span id="more-395"></span></li>
<li><strong>Implement a document retention schedule. </strong>Building on #1, you should identify how long each type of document should be kept. Have a procedure to remove expired documents from storage and destroy them securely. If you process a large volume of documents, consider contracting the shredding to a trusted third-party.</li>
<li><strong>Regularly shred sensitive documents. </strong>For documents that do not need to be retained, provide storage containers in convenient locations for documents that need to be shredded and have them emptied regularly. Make destruction rules simple on employees &#8211; when in doubt, shred it.</li>
<li><strong>Keep documents securely offsite.</strong> This requirement should be balanced by the document management program. For documents that must be stored but are not required for frequent business processes consider storing them offsite. If you have a small amount of documents, a safe-deposit box might suffice. For larger amounts of documents, consider off-site data storage companies like those used for tape backup and disaster recovery services.</li>
<li><strong>Limit acquisition of confidential customer data. </strong>If information is not integral to the business process, see if you can limit your exposure by not asking for the information. Once you have it, you are responsible for securing it. Follow a need-to-know policy on release of private customer data to employees.</li>
<li><strong>Use password protection.</strong> Most document formats that can be password protected can also be cracked easily. So you must consider document password protection as a simple deterrent. Instead consider disk based encryption like <a href="http://www.truecrypt.org/">TrueCrypt</a> for file storage and PGP for files that have to be emailed.</li>
<li><strong>Install and update virus protection software.</strong> They refer to this software as virus protection software, but make sure your software protects against all forms of malware and not just viruses. I personally like <a href="http://www.microsoft.com/Security_Essentials/">Microsoft Security Essentials</a> due to its price point, its light footprint, and <a href="http://lifehacker.com/5433229/microsoft-security-essentials-ranks-as-best+performing-free-antivirus">its effectiveness</a>. Keeping anti-malware software up-to-date is a good first line defense, but does  not replace security awareness training.</li>
<li><strong>Clear data before disposing of old computers.</strong> We consider this process to be instrumental to a <a href="http://www.epcusa.com/security/">good security program</a> (surprise, surprise). Use data destruction software like <a href="http://www.blancco.com/">Blancco</a>, <a href="http://www.dban.org/">dBan</a>, or <a href="http://www.killdisk.com/">KillDisk</a> to ensure that no data can be recovered from your machines after you are done with them. If you contract this service out, here are <a href="http://blog.epcusa.com/2010/01/5-questions-to-ask-your-data-destruction-company/">5 questions you should ask a data-destruction company.</a> As smartphones like Blackberries and the iPhone get used by companies in larger numbers, do not forget about wiping them as well.</li>
<li><strong>Review company credit card statements.</strong> Corporate credit accounts can be compromised as easily as consumer ones. Make sure your security program includes a review of credit card billing for fraudulent charges.</li>
<li><strong>Limit use of file sharing programs.</strong> File sharing programs can be a breeding ground for malware, and if used inappropriately can be a mechanism to expose business data. Using tools like <a href="http://www.spiceworks.com/">Spiceworks</a> you can easily generate reports to see exactly where a particular program is installed.</li>
</ol>
<p>In general, if you don&#8217;t need it, don&#8217;t store it. If you aren&#8217;t sure, don&#8217;t store it and ask the customer for it when needed.</p>
<p><a href="http://www.your-story.org/cintas-issues-top-10-tips-for-protecting-business-data-in-honor-of-data-privacy-day-89656/">Cintas Issues Top 10 Tips for Protecting Business Data in Honor of Data Privacy Day</a></p>


<p>Related posts:<ol><li><a href='http://blog.epcusa.com/2009/03/stimulus-bill-significantly-modifies-hipaa-regulations/' rel='bookmark' title='Permanent Link: Stimulus Bill significantly modifies HIPAA regulations'>Stimulus Bill significantly modifies HIPAA regulations</a> <small>Buried within the huge American Recovery and Reinvestment Act (a.k.a,...</small></li>
<li><a href='http://blog.epcusa.com/2010/01/5-questions-to-ask-your-data-destruction-company/' rel='bookmark' title='Permanent Link: 5 Questions to ask your Data Destruction Company'>5 Questions to ask your Data Destruction Company</a> <small>When you replace your computers, what happens to the data...</small></li>
<li><a href='http://blog.epcusa.com/2009/03/data-destruction-is-one-pass-overwriting-enough/' rel='bookmark' title='Permanent Link: Data Destruction: Is One Pass Overwriting Enough?'>Data Destruction: Is One Pass Overwriting Enough?</a> <small>There is some controversy regarding data destruction in the IT...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.epcusa.com/2010/02/10-tips-for-protecting-business-data/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
