WWII RAF control tower where The First of the Few was filmed is to be converted into rental home
Motorcyclist rushed to hospital after crash on busy Chelmsford road
When the IBM PC and shoulder pads were big, Japan led the chip industry. It's trying to get back there now
When IBM PCs set the standard for personal computing and Madonna topped the charts, Japan led the semiconductor industry. But that 1980s dominance faded as the fabless design and foundry model evolved.…
Why ALL men and women should take testosterone to defy ageing, by world expert doctor FLORENCE COMITE, who's used it for 30 years. Now she tells how it wards off fat and illnesses in definitive guide to 'fountain of youth'
Revealed: Ted Lasso star Anthony Head's long-term partner's cause of death after she passed away 'with very little warning'
Has YOUR local area been taken over by Triads? Churches staffed by slaves, corner shops taken over... top detective reveals how Chinese crime gangs have secretly spread their influence across Britain - and signs to watch out for
Windows Update is a torture chamber for seldom-used PCs
Opinion It's not the first time this has happened to me and it won't be the last. I pulled a laptop that I hadn't used for six months out of a drawer, then waited through three hours and four rounds of reboots for it to update Windows 11 completely.…
WeatherBug Data Says October 8 Is the Real Perfect Date
Read more of this story at Slashdot.
Poll shows Labour slipping into FOURTH behind Greens as local elections pressure mounts on Starmer
Andrew's fate in the line of succession hangs in the balance: ROBERT HAZELL reveals difficulty for lawmakers with 'narrow' legislation in the Palace Confidential newsletter
The OTHER bowel sign you must never ignore that can herald deadly cancer. Yes, it's embarrassing but it tells so much about your health - now doctors reveal the truth
Why Charles may NEVER speak to Andrew again: As Edward and Anne reach out to shamed brother over fears for his 'fragile mental state', we reveal how the King can't forgive him
Britain 'faces stagflation and recession' as oil soars back to $100 a barrel
Labour's North Sea tax grab has left Britain vulnerable, says ALEX BRUMMER
A Hole in Your Plan
Theresa works for a company that handles a fair bit of personally identifiable information that can be tied to health care data, so for them, security matters. They need to comply with security practices laid out by a variety of standards bodies and be able to demonstrate that compliance.
There's a dirty secret about standards compliance, though. Most of these standards are trying to avoid being overly technically prescriptive. So frequently, they may have something like, "a process must exist for securely destroying storage devices before they are disposed of." Maybe it will include some examples of what you could do to meet this standard, but the important thing is that you have to have a process. This means that if you whip up a Word document called "Secure Data Destruction Process" and tell people they should follow it, you can check off that box on your compliance. Sometimes, you need to validate the process; sometimes you need to have other processes which ensure this process is being followed. What you need to do and to what complexity depends on the compliance structure you're beholden to. Some of them are surprisingly flexible, which is a polite way of saying "mostly meaningless".
Theresa's company has a process for safely destroying hard drives. They even validated it, shortly after its introduction. They even have someone who checks that the process has been followed. The process is this: in the basement, someone set up a cheap drill press, and attached a wooden jig to it. You slap the hard drive in the jig, turn on the drill, and brrrrzzzzzz- poke a hole through the platters making the drive unreadable.
There's just one problem with that process: the company recently switched to using SSDs. The SSDs are in a carrier which makes them share the same form factor as old-style spinning disk drives, but that's just a thin plastic shell. The actual electronics package where the data is stored is quite small. Small enough, and located in a position where the little jig attached to the drill guarantees that the drill won't even touch the SSD at all.
For months now, whenever a drive got decommissioned, the IT drone responsible for punching a hole through it has just been drilling through plastic, and nothing else. An unknown quantity of hard drives have been sent out for recycling with PII and health data on them. But it's okay, because the process was followed.
The compliance team at the company will update the process, probably after six months of meetings and planning and approvals from all of the stakeholders. Though it may take longer to glue together a new jig for the SSDs.