Skip to main content
Guidance

Protecting bulk personal data

Fifteen best-practice measures to protect digital bulk data.

Page 4 of 5

How is your system designed, implemented and operated?

Learn about what to look out for in how your system is designed, implemented and operated to help protect your bulk data held by digital services.

Below are points 8-15 of the good practice measures.

Prompt mitigation

How promptly should vulnerabilities be mitigated? As described above, your team will need to triage vulnerabilities to understand their impact within your specific scenario.

However, as a rule of thumb, you should aim for triage and mitigation of issues in external-facing components to take:

  • Hours for vulnerabilities classified ‘Critical’ or ‘High’ or vulnerabilities reported as being actively exploited in the wild
  • Days for vulnerabilities classified ‘Severe’ or ‘Medium’
  • Weeks for vulnerabilities classified ‘Important’, ‘Moderate’ or ‘Low’

Detecting compromised components

In addition to detecting attempted breaches, consider how you would detect one which had already been successful.

Do components in your system need to be directly connected to the internet? Would an alert be raised if they attempted to do so?

Published

Reviewed

Version

1.0