<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Nerds On Site Blog &#124; Business Technology Partners &#124; IT Support &#187; Information</title>
	<atom:link href="http://www.nerdsonsite.com/blog/tag/information/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nerdsonsite.com/blog</link>
	<description>Nerds On Site - Local Nerds... Powered by a Global TEAM</description>
	<lastBuildDate>Sat, 04 Feb 2012 01:11:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>Nerds On Site Client Podcast. We interview Nerds On Site SME clients about what they do and how they make sure of technology to increase their business productivity!</itunes:summary>
	<itunes:author>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile.jpg" />
	<itunes:owner>
		<itunes:name>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:name>
		<itunes:email>nerdcast@nerdsonsite.com</itunes:email>
	</itunes:owner>
	<managingEditor>nerdcast@nerdsonsite.com (Nerds On Site Blog | Business Technology Partners | IT Support)</managingEditor>
	<copyright>Copyright 2009 Nerds On Site Inc.</copyright>
	<itunes:subtitle>Nerds On Site - Local Nerds... Powered by a Global TEAM</itunes:subtitle>
	<itunes:keywords>nerds on site, nerds, nerd, podcast, client</itunes:keywords>
	<image>
		<title>Nerds On Site Blog | Business Technology Partners | IT Support &#187; Information</title>
		<url>http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile_128.jpg</url>
		<link>http://www.nerdsonsite.com/blog</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
		<item>
		<title>Every Business Should Have an Information Management Plan (Part 2):</title>
		<link>http://www.nerdsonsite.com/blog/2009/11/26/every-business-should-have-an-information-management-plan-part-2/</link>
		<comments>http://www.nerdsonsite.com/blog/2009/11/26/every-business-should-have-an-information-management-plan-part-2/#comments</comments>
		<pubDate>Thu, 26 Nov 2009 12:58:39 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Information]]></category>
		<category><![CDATA[Management Plan]]></category>

		<guid isPermaLink="false">http://nerdsonsite.com/blog/?p=4921</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2009/11/26/every-business-should-have-an-information-management-plan-part-2/' addthis:title='Every Business Should Have an Information Management Plan (Part 2): '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>What is &#8220;Sensitive Information&#8221;? This second part part of a multi-part series on creating an information management plan for business clients. Basically, any information that your client would not want posted on the bulletin board is potentially sensitive information. Many clients will say that they to not have that much sensitive data on their systems. [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2009/11/26/every-business-should-have-an-information-management-plan-part-2/' addthis:title='Every Business Should Have an Information Management Plan (Part 2): ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2009/11/26/every-business-should-have-an-information-management-plan-part-2/' addthis:title='Every Business Should Have an Information Management Plan (Part 2): '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2009%2F11%2F26%2Fevery-business-should-have-an-information-management-plan-part-2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2009%2F11%2F26%2Fevery-business-should-have-an-information-management-plan-part-2%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>What is &#8220;Sensitive Information&#8221;?</strong></p>
<p>This second part part of a multi-part series on creating an information management plan for business clients.</p>
<p>Basically, any information that your client would not want posted on the bulletin board is potentially sensitive information. Many clients will say that they to not have that much sensitive data on their systems. This may be true, but there are some questions we have to ask them.</p>
<div id="attachment_4923" class="wp-caption alignright" style="width: 245px"><img class="size-medium wp-image-4923  " title="Information" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/bigstockphoto_Piece_of_information_2700836-235x300.jpg" alt="Do you have sensitive information?" width="235" height="300" /><p class="wp-caption-text">Do you have sensitive information?</p></div>
<p>- Do you process any &#8220;keyed&#8221; credit card transactions or take any credit card information over the telephone? If so, is the credit card information ever written on a piece of paper? What happens to that paper after the transaction is processed? (The PCD DSS requires that the paper be shredded immediately in a crosscut shredder) What controls (written policies, supervision, etc,) are in place to ensure that this happens?</p>
<p>- Is any credit card information kept on file, either on paper or in an electronic form? The PCI DSS requires that access to such records be controlled. The PCI DSS also clearly states that the 3-digit security code on the back of the card MUST NOT be recorded or stored &#8211; it should not be written down in a paper file or stored electronically, even in an encrypted form.</p>
<p>- Do you process payroll or keep any employee files (practically every employer does maintain employee information, even if they contract payroll to a third-party)?</p>
<p>- Do you maintain customer or client lists that you do not share with all everyone in the business and/or the public?</p>
<p>- Do you maintain financial records for clients or business partners?</p>
<p>- Do you maintain client or patient records that you are required by law to protect (examples would be PIPDEDA in Canada, HIPAA for health information in the US, GLBA for financial records in the US &#8211; every country has laws requiring protection for certain types of records. You need to research laws in your country)?</p>
<p>- Do you maintain records about ongoing projects, bids, company process, or other information that you have developed, &#8220;company secrets&#8221;, ways that you do things, etc. that you would not want to be made public?</p>
<p>- Do you have internal or external correspondences or documents (emails, internal memos, etc.) that you would not want to share with everyone in your organization?</p>
<p>Most businesses clients will answer &#8220;yes&#8221; to one or more of these questions. If there are no controls in place to protect sensitive data, it should be assumed that ANYONE who wants to could access that data. All businesses have SOME controls in place &#8211; our job is the determine what controls ARE in place and what controls SHOULD be in place, based on the answers to the questions above.<br />
<strong><br />
Next:</strong> Data Classification</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p><strong><br />
</strong></p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>November 26, 2009</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2009/11/26/every-business-should-have-an-information-management-plan-part-2/' addthis:title='Every Business Should Have an Information Management Plan (Part 2): ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2009/11/26/every-business-should-have-an-information-management-plan-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

