Crisis Management - Training, Practicing And Testing - UNECE

Transcription

Crisis management –training, practicingand testingJanika TarkomaJOINT UNECE/EUROSTAT WORK SESSION ONSTATISTICAL DATA CONFIDENTIALITY 201928 November, 2019Janika Tarkoma1

Content Guidelines Education for personnel Training Copy – paste -mistakeCongratulations, you’re a winner!In Finland we have this thing called TAISTOTailored training for Statistics Finland Lessons to share28 November, 2019Janika Tarkoma2

Guidelines for crisis management General guidelines forgovernment agencies General guidelines coveringtopics from general awarenessto specific topics Publicly available information Common baseline for eachagency28 November, 2019Janika Tarkoma Statistics Finland’s guidelines General guidelines includingrisks from delay in statisticsrelease to data securityattacks and physicalenvironment risks Comprehensive crisiscommunication guidelines Specific guidelines for differentdisturbance situations3

28 November, 2019Janika Tarkoma4

Education General education forgovernment agencies Study material on data securityand disclosure controlincluding videos and test –mandatory for all civil servants Eoppiva – wide range ofeducation for civil servants28 November, 2019Janika Tarkoma Statistics Finland’s education Orientation Courses as a part of theinternal training Short courses on changes inlegislation, guidelines etc.5

Copy – paste -mistake A diagram was copied to a presentation with microdataincluded and this microdata set included direct identifiers Search engines were able to read the microdata from slidesharing database Information was deleted from web before publicannouncement and further precautions were available Human errors will occur Have safe environment for informing these errors28 November, 2019Janika Tarkoma6

Congratulations, you’re a winner! Traditional email scam with pay only postage fee for youraward. Email in Finnish linked to look-a-like webpage with trafficencryption. Email address and webpage address nonsense Importance of informing personnel and citizens28 November, 2019Janika Tarkoma7

In Finland we have this thing calledTAISTO Voluntary based security and data protection managementtraining for government agencies Simulation of a data security breach Personnel information hacked Hacked information is published Media, including tv-reporters, request details Importance of information sharing and being well prepared– non speculating press releases28 November, 2019Janika Tarkoma8

Tailored training forStatistics Finland Simulated trainings on media and government connectionsand another on internal and governmental coordination Need for simple situation specific lists in addition tocomprehensive guidelines Importance of easy to check current status information Stick to facts in press releases and interviews28 November, 2019Janika Tarkoma9

Lessons to share Effective training – both general awareness and simulations STAY CALM Clear responsibilities and up-to-date contact information Current situation updated and available for all Internal and external communication should be efficient Log all the actions Summary and analysis/feedback afterwards – learningpurposes28 November, 2019Janika Tarkoma10

Thank you!28 November, 2019Janika Tarkoma11

Crisis management - training, practicing and testing Janika Tarkoma JOINT UNECE/EUROSTAT WORK SESSION ON STATISTICAL DATA CONFIDENTIALITY 2019. 28 November, 2019 Janika Tarkoma 1. . Have safe environment for informing these errors 28 November, 2019 Janika Tarkoma 6. Congratulations, you're a winner! .