The internet and external email are important business tools for financial services firms but both increase the risk of data loss or theft if used in an uncontrolled fashion. It is therefore good practice to provide internet and email facilities only to staff with a genuine business need.
You should consider carefully the risks arising from allowing staff to access web-based communication facilities, examples of which include:
- web-based email (eg Hotmail);
- social networking sites (eg Facebook);
- instant messaging (eg MSN Messenger);and
- file sharing software (eg Limewire)
If your staff use these facilities, there is an increased risk that your customer data might be lost or stolen without you knowing. It is good practice to completely block access to these types of internet facilities, especially if staff have access to customer data.
FSA FACTSHEET: Your responsibilities for customer data security
|