We recently had an IT system installed for document control. This has the usual username/password control. But what freaked me out was seeing that the passwords are not only stored in clear text in the database, but they're also shown to the admin girls! I've had to change passwords on other systems now, to ensure the integrity of those systems.
The supplier contends that we did not specify password encryption. But I'm sure there's something in the DPA which says that information should be kept secure, so therefore he should be doing it simply to comply with the law. Please tell me where, what clauses etc apply if this is the case.
Thanks
2006-12-19
05:08:29
·
4 answers
·
asked by
Geoff M
5
in
Computers & Internet
➔ Security
Thanks for the 3 answers thus far. I'd like to comment on the 3rd one as that has pointed out an important point: this document control system contains documents that are confidential - only certain people are allowed to see those documents. If, as admin, I can see the passwords, then I have access to those documents.... payroll, bonuses, health records... scary.
2006-12-19
06:06:32 ·
update #1