Losing the device is a mistake, storing the data 'unencrypted' is negligent. This sounds like insufficient risk management policies to me.
If the staff member did not vialote any policies, he/she should not wear the punishment for this (although I suppose there was a "don't lose things" policy).
A few simple policies could have reduced/prevented the consequences and likelihood of this. E.g. encryption, data transport restriction and/or even a simple device-tethering policy (such as keeping it round your neck or attached to a lanyard...).
Chris Fry
http://www.chris-fry.com
IBM Sponsored Resources
Resources from our Sponsor
- Oracle Exadata vs IBM: Netezza Compared
- Forrester TEI Report
- CIA Whitepaper
- Harnessing the Power of Advanced Analytics
- Tapping into Unleashed Business Potential with Advanced Analytics
- Unlock Analytic Performance with Revolution R for Enterprise and IBM: Netezza Data Warehouse Appliance
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox




