Human Resource Controls in Data Security
In many companies, most, if not all, employees may be equipped with desktop and/or portable devices with access to the company network and data. This can present a risk to data security. As a result, companies may want to consider features of its recruitment and hiring processes to help control and preserve the integrity and confidentiality of their data. The features companies use may depend on several factors, including legal or contractual requirements. Having your recruitment or hiring program reviewed by legal counsel prior to implementing can assist you in confirming compliance with any applicable laws, regulations or other legal requirements. Some potential human resource controls for data security can include:
Job descriptions
Prior to interviewing job candidates, consider developing a job description that references your data security policy and describes any specific job responsibilities related to protecting the network or data. Having detailed job descriptions with clear job requirements related to data security can help you outline these aspects of the job for a job candidate and reinforce the importance of data security.
Pre-employment background screening
Perform background checks to confirm the candidate’s credentialing and qualifications. Depending on the security requirements for the job position, you also may want to consider performing other pre-employment screening, such as credit history and criminal background checks. Federal and state laws may stipulate whether, when and how pre-employment screening can be conducted. Consult with your legal counsel as to jurisdictional requirements for pre-employment screening and what actions, if any, you can take based on the results of the information gathered.
To the extent permitted, a similar screening process can be considered for any contracted third-party consultants. Your service agreement or contract can specify any requirements you may have, and the consultants’ obligations for compliance. See Travelers Risk Control article Third-Party Cyber Security Vendor Management for additional information.
Based on the security requirements of job positions, you can also conduct periodic post-hire background checks. Again, consult with your legal counsel as to jurisdictional requirements for post-hire screening and what actions, if any, you can take based on the results of the information gathered.
Terms and conditions of employment
All employees
Request confirmation of compliance with data security responsibilities and adherence to rights regarding copyright laws and data protection legislation in the terms and conditions of employment.
Include an agreement for the return of all company equipment or information upon termination of employment.
Sensitive data access agreements
Incorporate confidentiality or non-disclosure agreements for hires that will have access to sensitive information.
For personnel that will be involved in the development of proprietary programs, software or applications, include a non-compete agreement.
Disciplinary process
Establish a written disciplinary action process to address employees who have conducted information security infractions.
Terminating access privileges
Implement access controls for reassigned, terminated or non-authorized employees or contractors. A process that permits you to immediately terminate access features on employee IDs, revoke system access, and change or disable passwords that the terminated employee used to access the network or data can help you control unauthorized access to data and company resources.
Require employees to promptly return all company equipment and data upon termination of employment. See Travelers Risk Control article Cyber Security Policies for additional information.
On a periodic basis, have business managers confirm that only authorized and active employees and contractors have access to their department information.