by Jerry Ervin

When information-protection policies are broken

Opinion
Apr 2, 20073 mins

What are some information protection policies that are commonly broken in enterprises? Are these the main policies that I should focus on when training employees on policies regarding company data?

What are some information protection policies that are commonly broken in enterprises? Are these the main policies that I should focus on when training employees on policies regarding company data?

When we look at the policies that are broken from company to company many employees are not aware that they are breaking company policy by sending confidential information through un-secure lines. Senior management upon employment is asked to sign strict confidential agreements. The expectation of privacy is clearly laid out for them and as senior management privy to sensitive corporate information. That same expectation is not as clear to mid-level manager or line staff.

Just a month ago a client called to ask my opinion on a situation. It seems that a junior staff member had found an all staff compensation document in an un-secure area of the intranet. Upon reviewing this document proceeded to forward the information to others some which were not even in the company. They were not aware that normal policy would have been to forward this breech of confidential information to management straight away. They did what I would assume most would do, share the inequity of salary with others.

Regulatory issues are a big concern as well. Privacy advocates are working diligently to maintain that our personal information is secure. Companies are spending millions of dollars a year to secure this information yet, with one click of the mouse by sending a document through the internet what information can be swiped. Just recently we have heard about credit card information being stolen. Congress is currently reviewing privacy policies across the board and creating legislation to protect the consumer from fraud and identity theft.

Yes, we can assume we have very intelligent people working for our company. Yet, there are times when it comes to privacy and confidential corporate information that the company is obligated to spell out the expectations of all staff members, not just the senior executive team; in doing so companies can avoid either information being shared or sent to un-secure accounts such as hotmail or yahoo. Having a privacy policy is good, yet setting clear standards of communication through semi-annual training would be mitigating many of these issues. Training is one of the strongest vehicles a company has to insure that policy and procedures are followed. This isn’t the fun and exciting training, we’ll agree. Yet, it’s the training that will save everyone in the long run from headaches and lawsuits.

About: Jerry Ervin is President of Paragon Strategies; a management training, coaching and strategic meeting facilitation firm in San Francisco.