• lando55@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 months ago

    Make sure you back up all email and IM communications and don’t rely exclusively on server-side retention (provided your DLP policy allows for this.)

    If it ever comes down to it and you are facing the possibility of being the scapegoat for a security incident, your attorney can review the relevant policy and determine whether or not and when you can use these to demonstrate that you communicated your concerns to management and stakeholders.

    Depending on who you reached out to and who was included, absence of a response to your various methods of communication can be used to establish acceptance of risk by leadership.