Security of business sensitive and confidential Project Information.
Rohit Kumar GoelCybersecurity | IT Consultant| Various ClientsDwarka, New Delhi, Delhi, India
Now Information and data are considered critical assets for the projects, performing organisation and requesting organisation. Most projects during various stages of their life cycle will generate lots of data that may contain both business sensitive/confidential and other information. All business sensitive/confidential information need to be protected at least until such information has a value to the business and its stakeholders.
What is your opinion about how all such sensitive project data/information can be protected adequately especially while Project is still underway and how to ensure that additional effort required to protect such confidential data/information do not act as a barrier or constraint to the project work, speed and the PM team? Saving Changes...
It has to do with the nature of the project and data and all you have for data storing. You need to keep them safe. You may need to prepare an access table and make the access to sensitive data restricted. Saving Changes...
Usually this is not a project-level decision, but rather an organizational data and security policy. That will dictate what control objectives and protective measures the team will need to take with regards to storing, transmitting, sharing or destroying information.
Ideally, this can be done as transparently as possible (technology allowing), but this may not always be feasible and it can become a source of additional effort or frustration, especially when dealing with third-parties on the project who are permitted access to only some but not all of the information.
Kiron Saving Changes...
Sergio Luis ConteHelping to create solutions for everyone| Worldwide based OrganizationsBuenos Aires, Argentina
Data was critical assessts from the ancient times where I started working. No news on that. Complexity on this days is because the amount of different sources where the data resides today, from personal cel phones to distributed servers or cloud. No matter than that nothing new below the sun. You can find lot of papers and serious research on the field. Search into the internet due to there is not enough room here. When you read something remember: behind the truth is allways the truth mainly when you read papers that were created for some solution vendors. Saving Changes...
Drew CraigSr. Agile & Product Coach| VanguardPhiladelphia, Pa, United States
Rules and processes for information security would be set at the organization level, whether direct FTE or in a client-vendor partnership. There would be set criteria and classification standards. This would be available either through the intranet or by contacting IS. Saving Changes...