From: Pointon, Steve
Sent: Monday, 01 September 2017 10:44 AM
To: Tricia, Portman
Subject: Review of work practices and feedback collected
Dear [Mr Hansen],
This mail is to inform you that review of the work practices has been completed and the feedback from all the respondent has been collected. There has been many areas where the employees took the initiative in suggesting us to make the implementation process more concievable and easy to implement. The feedback collected also led us to learn some of the very basic ideas but with strong relevance. Most of the feedback were on the policy statement which they said should be short, precise and should include actionable words. The other areas of feedback was removing the overlapping of some responsibility to two or more person. They were of the opinion that these should have clear demarcation as to who is responsible for what?
The privacy breach from Brian end should be avoided in the future but these are already currently the part of the procedure in protecting the personal information and has been followed by others. The procedure he should have followed is two steps verification so as to know his customer well and the other one is asking for the UID number so that he could have been certain before sharing any information.
In order to avoid such escalation in the future, I have two suggestion that can avoid such situation. These are: 1. By assigning IT security officer the responsibility to maintain and store data related to personal information.
- Access control standards (including password change standard)
Kind regards