Although it does not show on the balance sheet as an asset, the data stored on the PC or PC Network can be invaluable to a business small or large.
Here we look at some of the issues to consider when reviewing the security of your computer systems.
Good access controls to the computers and the computer network minimise the risks of data loss.
Access controls can be divided into two main areas:
Logical access
An example of logical access would be that all staff will probably need access to e-mail and calendar software, but not all staff will need to access the accounts package.
Some software packages also have internal logical access controls to prevent employees exceeding their authorisation for example in an accounting package it may be desirable that all users can access supplier details and post purchase invoices but it may be that only some of these users also have access to supplier payment routines.
Passwords
Passwords are one of the measures which can be used to implement access controls. However to be at all effective they should:
Data backup is an essential process for security and needs to be undertaken on a regular basis. There are a number of points to consider.
Data file locations
Where the key applications data files are stored needs to be determined. This is relatively easy if there is only one PC involved but in a network environment some data files might be stored on the server and other data files stored on local drives.
Backup strategy
There is likely to be a need for two parallel backup procedures; one to cover a complete systems backup and another to cover backing up of individual applications’ data files.
Complete systems backup
On a network some form of server backup software should be used to take a complete copy of the network drive(s). This can normally be set to run overnight. However, you will need to understand how to use and maintain this software.
Key areas to consider include:
The person responsible needs to be able to:
Finally, be aware that some backup utilities only take a mirror image of the hard disc. In this case, the whole of the hard disc has to be restored even if there is a problem with just one file or just one folder.
Applications backup
Many accounting and payroll packages have their own backup routines. It is a good idea to use these (as well as a network backup) on a regular basis and always just before period end updates.
Local PCs
Remember that some users will have applications data files exclusively on their local drives (such as payroll data) and these will all require their own regular backup regime.
Backup media
There are about half a dozen different types of backup media available from the writable CD capable of storing up to 1gb, through the DVD reader/writer (5gb) up to the mighty external hard drives (1000gb). Most server backups will use either tape cartridges or CD/DVD reader/writers. For more temporary forms of backup, or just moving large files around, a memory stick or USB pen (1gb) might be considered.
Backup frequency
A cycle of backups should be retained for a period of time (probably going back at least 12 months). Overwriting the same backup disc/tape day after day is not advised.
As with backup, there are a number of issues to consider.
The prevalence of e-mail viruses and unsolicited spam means that all systems require software to filter these items out of the system. This software will require regular updating, along with any relevant software repairs (patches) to the PC operating and network systems.
Additional network security in the form of firewall software is also required.
All employees should know and understand the firms’ security procedures and the consequences of abusing these. You might wish to refer to our factsheet which sets out a model internet and e-mail access policy.
Data Security
Staff dealing with personal data also require training in the principles of data protection and good information handling practices. Staff specifically involved in marketing also need to be aware of the Privacy and Electronic Communications Regulations 2003.
Most businesses process personal data to a greater or lesser degree. If this is the case, then notification under the Data Protection Act is required. That will then mean on-going compliance with the principles of information handling and information security. We can help you with this process to ensure compliance.
As well as the Data Protection Act, there are various other regulations, which have a bearing on data security. These include:
We can provide help in the following areas:
Top of page
For information of users: This material is published for the information of clients. It provides only an overview of the regulations in force at the date of publication, and no action should be taken without consulting the detailed legislation or seeking professional advice. Therefore no responsibility for loss occasioned by any person acting or refraining from action as a result of the material can be accepted by the authors or the firm.
10.1 The jargon de-mystified
10.2 E mail/internet an acceptable use policy
10.3 Choosing an accounting package
10.4 Data security
1. Starting up in business
2. General business
3. Corporate and Business Tax
4. VAT
5. Employment Issues
6. Employment and Related Matters
7. Personal Tax
8. Capital Taxes
9. Pensions
10. ICT
11. Specialist Areas
Sign up for our newsletter, sent by post monthly, or browse our newsletter archive.
Webcam – click on the link to see the view of St Magnus Cathedral taken from our Kirkwall office
Current Tax Data
Tax Calculators
Helpsheets
Contact Us
Crunchers Bookkeeping
New client enquiry
Our Standard Terms of business include a guarantee of satisfaction. If you are not completely satisfied with the service we have provided, you do not need to pay us.