Home > Ask the Information Security Experts > Data protection Questions & Answers > What should be part of an employee termination checklist?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

What should be part of an employee termination checklist?

>
QUESTION:
Many workers face being fired due to the global economic crisis. What are the best ways to keep employees from taking sensitive business data with them when they go?


RELATED CONTENT
Data protection
How to detect if machines have been infected with Trojans, keyloggers
What are USB flash drive security best practices?
Are iPhone encryption features on the way?
How to protect employees' personal information and passwords
Are there keylogger monitors that can effectively spot malware?

Security Policies and User Awareness
Cloud-based services require stalwart business continuity plans
Preventing phishing attacks: Enterprise best practices
CISOs take measured steps to reduce social media risks
Increasing information security awareness in the enterprise
How to develop a culture of security in the enterprise
Creating and enforcing a clear-desk policy
Physical security threats: Don't gift your data away
Cut down on calls to help desk with cybersecurity awareness training
Layoffs prompt insider threat fears, cybersecurity survey finds
How to write an information security policy

Data Protection Solutions and Strategy
NSA, cryptoexperts jab at RSA Conference 2010 Cryptographers' Panel
Make PCI DSS compliance easier by reducing scope, outsourcing data
Data Protection Act fines likely limited, audit powers may expand
Websense integrated security system aims to simplify security management
Full disk encryption: Safer and easier than file and folder encryption
No major PCI DSS revision expected in 2010
Data breach costs continue to rise in 2009, Ponemon study finds
Chinese hacker attacks target Google Gmail accounts, top tech firms
Annual security reports offer some hope
Creating and enforcing a clear-desk policy

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Financial Services Authority  (SearchSecurityUK.com)
IISP (Institute of Information Security Professionals)  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Ken Munro EXPERT RESPONSE FROM: Ken Munro

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site
ANSWERED February 2009:
Letting go of someone with high IT privileges could come back to haunt you, especially in a time when redundancies are likely to occur in every sector.

Making any number of redundancies is bound to be difficult, and getting everything right can be a mammoth task. There will be unions to appease, employment legislation to grapple with, tough decisions to be made -- and in the minefield of sensitive HR processes, retrieving a Blackberry from an ex-employee may be the least of your worries.

But being complacent could be a real mistake. Over the past few years, businesses have furnished their employees with ever more sophisticated technology, allowing them to do almost anything when away from the office, from accessing their emails to connecting to the most sensitive parts of the internal network. Vast numbers of workers have been given their own laptops to facilitate remote and flexible working.

Such availability means that any disgruntled employee has a better chance of stealing data or even hacking into your company network. Redundant IT administrators, who may have the technical knowledge and the system privileges to cause some serious damage, are by far the most dangerous -- particularly when you consider that a recent survey by Cyber-Ark Software Ltd. revealed that 88% of the 300 surveyed IT professionals would steal valuable and sensitive company information if they were fired tomorrow. And obviously, disgruntled ex-employees are by far the most likely people to seek revenge against the company that spurned them.

Possibly the most worrying aspect for businesses is this: When redundancies are in the pipeline, there is usually a statutory 'at risk' notification for the employee before their role is made redundant.

Developing an employee termination checklist
What can you do to minimise the damage?

  • First, work closely with your HR department. You need to know about potential redundancies early, so that you can prepare an action plan. Then, if you know who is deemed 'at risk' of redundancy, you might consider implementing a raised level of logging of their activity. File transfer locally would be worrying, so free monitoring tools like 'filemon' could be helpful, but set the filters up carefully to avoid overload!
  • Sent emails will be of great interest, particularly of encrypted or password-protected files. Raise your quarantine levels, and don't just release items on a 'say so' from the member of staff.
  • Consider a higher frequency of backup for email -- how often do you find that departed staff have deleted the contents of their mailbox?
  • Review logging on your applications, particularly those with sensitive data such as your CRM and HR systems.
  • Finally, make sure you have a robust process for closing accounts and recovering equipment allocated to staff members.

    However, if the person being let go is a system administrator with high levels of IT privileges and a seething resentment for management, how can you ensure that your soon to be ex-employee won't attempt some risky business of his/her own? Answer: you probably can't.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Access Management: Authentication, Biometrics, Password Security
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts