Security and confidentiality

Data security and the confidentiality of person and business-sensitive information must be maintained as part of homeworking arrangements.

Working from home demands extra vigilance to maintain good information security working practices so that the confidentiality and integrity of University information is maintained and the institution’s good reputation is not jeopardised.

These working practices are simple and common sense and can be summarised as follows.

Personal or confidential information should not be stored on:

  • any non-University portable device (eg laptop or PDA)
  • a non-University (eg home) desktop computer
  • a University portable device (eg laptop or PDA) which is transferred off-site (eg taken home) unless appropriate encryption is in place OR
  • on any portable medium (eg CD, DVD, USB memory stick, external hard disk, solid-state or other storage card (eg CompactFlash, SD), other digital storage, etc) which is transferred off-site, unless the storage medium is encrypted.
  • Minimise printing of University files on home printers and ensure all home-printed documents are stored securely and shredded after use.

Staff must take personal responsibility for adhering to these standards and should treat University information with the same care that they would wish to be applied to any personal or confidential information held about them.

Transferring information between the University and home

In most cases it will not be necessary for employees to transfer private or confidential information from the University to home to enable them to work effectively from home as these files can be stored and accessed on the University’s central filestore through the My Exeter staff portal.

Staff should avoid saving documents relating to their University work to the hard drive of their home computer. Where this is necessary while a document is being drafted, the final version should be saved in the U drive (My Documents) or shared N drive via the staff portal and deleted from the home computer (and deleted from the Recycle Bin). All documents should be saved to the U drive or N drive and deleted from the home computer at the end of each working day.

However, if necessary, information can be carried securely between locations using encrypted USB memory sticks.

Policy for information security on laptops and portable media (IT website)

Hard copies of documents

Managers and employees should be aware that data security and confidentiality standards also apply to hard copies of documents. The transfer of such documents between the University and home should be avoided. Managers should not agree to homeworking arrangements unless they are satisfied that appropriate arrangements are in place to maintain the security of such documents. In the interest of data security and sustainability, homeworkers are discouraged from printing and retaining University documents at home.

Securing access at home

Employees must be able to assure their manager that they have a work area at home which allows them to work without other family members having access to any personal or confidential information. This may involve locking their screen with a password if they are away from their home work area and securing any documents and portable storage media at the end of each day.