Security
8.1 Security Risks
8.1.1 Confidential information held by organisations
Human Resources Information
Human Resources departments hold confidential information such as:
- Salaries and benefits
- Staff personal details
Commercially Sensitive Information
Organisations store sensitive commercial information including:
- Client details
- Stakeholder details
- Intellectual property
- Sales numbers
- Contracts
Access Information
Access information must be kept secure to prevent unauthorised use:
- Usernames
- Passwords
- Multi‑factor authentication details
- Personal Identification Numbers (PIN)
- Access codes and passphrases
- Biometric data
8.1.2 Why organisations must keep information confidential
Reasons for Confidentiality
Organisations must protect confidential information to:
Salaries and benefits:
Salaries and benefits:
- Prevent competitors from offering higher wages
- Avoid disputes over comparable pay
- Protect employee privacy
- Stop competitors contacting staff directly
- Prevent copying of designs and ideas
- Protect client privacy
- Stop competitors targeting clients
- Prevent competitors gaining commercial advantage
- Prevent unauthorised access to systems
8.1.3 Impact of failing to maintain privacy and confidentiality
Impact on Organisations
Failing to protect confidential information can result in:
-
Non‑compliance with regulations:
- Loss of licence to operate
- Loss of customer and stakeholder trust
- Damage to organisational reputation and image
-
Financial loss:
- Fines and penalties
- Refunds
- Loss of earnings or terminated contracts
- Legal action from individuals or regulators
- Overall reduction in system security