Hi people here is the scenario,,,,
I work for a large DVD,Video,CDROM, and music CD replication company, recently our managing Director approached me and asked me to do a risk assesment on how easy it is with access to a CD or DVD that we produce to then get that data off site. OK ive thought of the obvious ones:- portable HDD and mp3 players, FTP and e-mail ect. So my first question is apart from the obvious ones are there any other ways of getting data off site? and my second question would be how do we enforce this? a classic example is contractors come on site with laptops these laptops are usually towards the top of the range so they are well equiped firewire, cd writers ect. we have a large factory floor producing thousands of dvds ect. 1 could easily go missing and end up in the laptops drive. so we cant ban laptops ect as they are integral parts of the working environment and we cant take specifications of each laptop that comes through the factory. So searching everyone as they enter the building, then watching them like a hawk throughout the day and finally searching them on the way out is not viable and a little intrusive. So how do I go about enforcing things in the areas of risk????to me it seems to be an all or nothing scenario, help please I am treading water on this one. Thanks in advance for all your suggestions.
I work for a large DVD,Video,CDROM, and music CD replication company, recently our managing Director approached me and asked me to do a risk assesment on how easy it is with access to a CD or DVD that we produce to then get that data off site. OK ive thought of the obvious ones:- portable HDD and mp3 players, FTP and e-mail ect. So my first question is apart from the obvious ones are there any other ways of getting data off site? and my second question would be how do we enforce this? a classic example is contractors come on site with laptops these laptops are usually towards the top of the range so they are well equiped firewire, cd writers ect. we have a large factory floor producing thousands of dvds ect. 1 could easily go missing and end up in the laptops drive. so we cant ban laptops ect as they are integral parts of the working environment and we cant take specifications of each laptop that comes through the factory. So searching everyone as they enter the building, then watching them like a hawk throughout the day and finally searching them on the way out is not viable and a little intrusive. So how do I go about enforcing things in the areas of risk????to me it seems to be an all or nothing scenario, help please I am treading water on this one. Thanks in advance for all your suggestions.