What Our Clients Are Saying...
Search Blog

About Imperative
Imperative Information Group is a leading provider of customized employment-related background checks. Our clients can’t afford a cheap background check. That's why all of our reports are researched using information directly from the source. We pride ourselves on not only providing excellent customer service to our clients, but also providing them relevant information on what a reliable background check actually is. Our goal is for our clients to not only know what goes into a successful background check, but also have the knowledge to understand what they are looking at so they don’t feel like they're missing informaiton when making critical hiring decisions.
 

« Previous | Main | Next »

September 01, 2008

Thoughts on HR Data Security

Hrmdata_safety

The August issue of HR Magazine has a cover story concerning breaches of HR data and encouraging HR practioners to be advocates of stricter data protection measures.  It is a good read and don't miss the "Web Extras" resources in the column to the left of the article.

In the past couple of years, we've seen clients suffer data breaches from both internal and external perpetrators. Perhaps the most startling case was an international corporation who used a temp agency to bring in data entry help... and gave the workers access to the HRIS system.

Hundreds of names and SSNs were compromised before the company became aware of the problem. The perpetrator was long gone and his own identity information proved to be false.  Just another reminder that companies need to screen temps as thoroughly as regular employees.

Another significant breach occurred at a branch office of a large accounting office one weekend. Thieves accessed the firm's computer network and paper files. Interestingly, while some internal locks were jimmied open, the external doors, which used a keypad entry system, showed no signs of tampering.

As it turned out, all of the branch offices had the same keypad code. They also all used their buildings' housekeeping service, which was outsourced to the lowest bidder. And, as the housekeeping service routinely sent different staff to clean the offices, an unknown number of individuals outside of the firm had access to the firm's key pad code. Neither the firm nor building management knew who was entering the offices each evening. As it turns out, the housekeeping service used by the building didn't keep good records either. No one ever did background checks on the housekeeping firm nor the individual housekeepers.

It can be surprising how many firms that take their employment security seriously fail to consider the risks posed by contractors and others who have access to their facilities both during and after office hours. Background checks might have prevented this breach.

Our friends at Networking Results provided a quick primer for employers related to network security. I encourage you to take a look at it and make sure you are enforcing these basic disciplines in your company.

Imperative Information Group is a Fort Worth, Texas-based background investigations and business due diligence firm dedicated to clients who can't afford a cheap background check. For more information about Imperative Information Group's services, please contact Micah Taylor at 877-HR-FACTS (877-473-2287) or visit us online at http://www.imperativeinfo.com.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341c0b2a53ef00e554f485b68834

Listed below are links to weblogs that reference Thoughts on HR Data Security:

Comments

Post a comment

Comments are moderated, and will not appear on this weblog until the author has approved them.

If you have a TypeKey or TypePad account, please Sign In.

 

Recent Posts
Websites of Interest
Categories
Archives