Cyber Security

Please contact the course administrator to sign up for this course.

Cyber security is a major and ever-evolving risk for organisations. While the nature of the threats has evolved over time, the risks have arguably never been greater for trade unions. In this course, we look at cyber security in the context of the EIS. We’ll explore the unique vulnerabilities that trade unions face in today’s digital landscape and equip you with the knowledge and skills to help defend our organisation from these threats.

Through this course, you’ll gain a solid understanding of common cyber threats, such as malware, phishing, and social engineering, and learn best practices for protecting sensitive data and critical systems. You’ll also discover how to identify suspicious activity, respond to security incidents, and adopt proactive measures to minimize risks. By the end, you’ll be prepared to play a vital role in safeguarding the EIS against cyber attacks, ensuring our operations and members remain secure.

Cyber Security Overview

The purpose of this module is to inform EIS staff on fundamental cybersecurity practices. By the end of the module, participants will understand the importance of security measures in their daily activities and will be equipped to protect themselves and the EIS against common cyber threats.

Lessons

Introduction to Cyber Threats The EIS Cyber Defences

2. Access Control and Data Storage Policy

The purpose of this Access Control and Data Storage Policy is to establish guidelines and procedures for controlling access to information systems, data, and resources within all sections of the EIS, from Headquarters to Area Offices to Local and Self-governing Associations to individual school, college and university. This policy aims to ensure the confidentiality, integrity, and availability of organisational information while preventing unauthorised access and protecting sensitive data. 

Lessons

2.1 Access Control and Data Storage Policy: Your Responsibility 2.2 Access Control and Data Storage Policy: Working from Outside the Office 2.3 Access Control and Data Storage Policy: Data Storage Review: Access Control and Data Storage Policy

3. Email and Internet Acceptable Use Policy

The purpose of this Email and Internet Acceptable Usage Policy is to ensure the responsible and secure use of email and internet resources within all sections of the EIS, from Headquarters to Area Offices to Local and Self-governing Associations to individual school, college and university. This policy outlines the guidelines and expectations for staff, contractors, and other users to promote a safe, efficient, and professional computing environment. 

Lessons

3.1 Email and Internet Acceptable Usage Policy: Explanation Review: Email and Internet Acceptable Use Policy

4. Information Exchange Policy

The purpose of this Information Exchange Policy is to establish guidelines and standards for the secure and efficient exchange of information, within the EIS by those outlined in Section 3 of this policy, both internally and outside the organisation. This policy aims to ensure the confidentiality, integrity, and timely availability of information while promoting compliance with legal and regulatory requirements. 

Lessons

4.1 Information Exchange Policy Review: Information Exchange Policy

5. Password Policy

The purpose of this Password Policy is to establish requirements and guidelines for creating, managing, and securing passwords resources within all sections of the EIS, from Headquarters to Area Offices to Local and Self-governing Associations to individual school, college and university to ensure the confidentiality, integrity, and availability of sensitive information. Passwords provide entry to the Organisation’s IT resources, access to the network, e-mail, business applications etc. Any misuse of passwords could result in the confidentiality, integrity or availability of vital information being compromised (e.g. privacy breaches, Ransomware attacks, etc.) and/or in the Organisation being held responsible for illegal activities such as transmission of offensive material via its communications systems.

Lessons

5.1 Password Policy: Password Creation Review: Password Policy

6. Security Incidents Policy

This purpose of this policy is to outline the security incident and GDPR data breach user guidance for the EIS. It defines what constitutes a security incident and a data breach, and what are the roles and responsibilities of the users in preventing, reporting, and responding to them. It also explains the legal and regulatory obligations of the Organisation under the General Data Protection Regulation (GDPR) and other applicable laws.It is essential that incidents are not only investigated but that corrective action is taken, the results are monitored, and support and training is provided. Similarly, potential incidents should also be documented, and preventive action taken. This will help inform future user support and training provision.  This policy will ensure that:  Security incidents are reported and resolved in the minimum amount of time.  Potential security incidents are prevented from happening in many cases. EIS security is continually improved by the application of corrective and preventive action.  

Lessons

6.1 Security Incidents Policy: Incidents and Breaches 6.2 Security Incidents Policy: Reporting and Response 6.3 Security Incidents Policy: How to Prevent Incidents & Breaches Review: Security Incidents Policy

7. Data Retention Policy

The EIS is committed to protecting the privacy and security of its members, staff, and other stakeholders, as well as fulfilling its legal obligations under the Data Protection Act 2018 and the General Data Protection Regulation (GDPR). This policy sets out the principles and procedures for retaining and disposing of data held by the EIS, with a particular emphasis on special category data, which requires a higher level of protection and justification for processing. 

Lessons

7.1 Data Retention Policy: Principle and Objectives 7.2 Data Retention Policy: Data Retention 7.3 Data Retention Policy: Email Retention Policy  Review: Data Retention Policy

8. WhatsApp Policy

This policy outlines the acceptable use of WhatsApp for conducting EIS union business securely and in compliance with the General Data Protection Regulation (GDPR).  

Lessons

8.1 WhatsApp Policy: The Policy 8.2 WhatsApp Policy: Usage Guidelines Review: WhatsApp Policy

Cyber Security Conclusion

In today’s digital world, cybersecurity is more important than ever. This training has covered essential topics designed to help protect both personal and organisational data from cyber threats.

Lessons

TUC Guide : Cyber Security for Unions Conclusion