Skip to main content
Guidance

Protecting bulk personal data

Fifteen best-practice measures to protect digital bulk data.

Page 2 of 5

What are you protecting?

It’s important to know what you are protecting and the risks you’ve already taken


Penetration testing

Penetration testing by third parties can be used to help validate the security of your service, but we advise against using it as the sole means of validation.

Penetration tests only validate that you are not vulnerable to known issues on the day of the test. And it is not uncommon for a year or more to elapse between penetration tests. If this were your only means of validation, you could be oblivious to vulnerabilities for long periods of time.

To avoid this, we recommend you establish operational management practices which keep you well-informed of vulnerabilities present in your systems. This includes subscribing to vulnerability notification feeds on the technologies you use, and by performing your own internal vulnerability scanning and testing.

You should know what the penetration testers are going to find, before they find it. Armed with a good understanding of the vulnerabilities present in your system, you can use third-party tests to verify your own expectations. Highly skilled penetration testers can then focus on finding more subtle issues within your system.

Published

Reviewed

Version

1.0