Kevin ColemanSubject Matter Expert, Author, Speaker and Strategic Advisor| - InsightsPa, United States
In the initial planning of a project, do you review and determine what, if any, sensitive information will be a part of the project? Saving Changes...
Sort By:
Dr.Vijayakumar RamasamySenior Project Manager| RnD Project Management/NPIKuala Lumpur, Malaysia
Yes, especially when it involves external design/manufacturing team. We also got determine the right proprietary tag for related documents (eg confidential/restricted..etc) , NDA..etc. Saving Changes...
arlene trimbleAssistant IT Director| Local GovernmentAlamo, Ca, United States
Yes. Sensitive information needs to be discussed upfront as well as confidentiality and security issues so that risks can be identified and managed as necessary.
If you plan to store sensitive information, you need to also discuss how to enter, display, and retrieve this type of information and the permissions necessary.
If you are implementing a third party system, you need to make sure that the third party system or vendor has the necessary and current security certification or privacy compliance attestation or certificate. I agree the third party vendors need to sign an NDA or Business Associate Agreement. In some organizations I have worked for, third party companies are also required to be insured for a certain $ amount as well. Saving Changes...
Rubaiyyaat AakbarHead of IT and Cybersecurity| DocDocSingapore, Singapore
Yes of course should be part of requirement analysis to cover information classification, information security requirement, access control etc and also included in communication plan to ensure appropriate target audience. Saving Changes...
Michael AdamsSolutions Architect| LANLLos Alamos, Nm, United States
We do that in my office. The problem I encounter most often, however, is that people have developed specific processes to keep sensitive information private, and they have come to believe the process is a requirement, rather than the security of the information. It can be challenging to have them consider alternative means of keeping sensitive information private outside of their already defined process. Saving Changes...
Joanna NewmanHead of Innovation and Transformation , Telecoms| VodafoneCholderton, United Kingdom
Yes and agree the process to contain / reference it Saving Changes...
Of course you would. Why the question? Saving Changes...
Kevin ColemanSubject Matter Expert, Author, Speaker and Strategic Advisor| - InsightsPa, United States
@ Tim PM - The reason for the post was a project document that I read that contained information that a competitor would love!! The info was not identified and their were no marking on the doc to indicate it contained sensitive info. Also it was pointed out to me that this is not part of any public methodology. Saving Changes...