The information management challenge: information security for humanitarian NGOs in the field
Humanitarian organisations hold information that people are willing to kill for. Most of them manage it with the same habits they use for a donor report.
What is at risk
The record catalogues the categories of information a field office normally holds. Beneficiary registration data, including names, locations, family composition and sometimes biometrics. Staff records, including next-of-kin, medical information and home addresses. Security information: incident records, threat assessments, movement logs and the identities of people who provided information. Programme data, which in a conflict setting reveals who is being served and therefore who is not. Financial records. And communications, which carry all of the above.
The harm that follows from each is different. Beneficiary data can be used to target, to recruit, to extort or to establish control over a population. Staff data exposes families. Security information, if it reaches the wrong party, identifies sources and reveals what the organisation knows and does not know. Programme data used by an armed actor shows exactly where the organisation is present and where it is not.
Who wants it
States, including the state that hosts the programme, which frequently has a legitimate legal claim to some of it and an illegitimate interest in the rest. Armed groups, who want to know who is being served and who is talking to the organisation. Criminal networks, interested in the money and in the movement data. And, increasingly, anyone who can buy the data or take it from a device.
What the record recommended
- Decide what is collected at all. The first information security measure is not collecting data the programme does not need. Registration exercises routinely gather detail that no programme decision requires and that is dangerous to hold.
- Separate the datasets. Identifiable data held separately from analysis, with the analysis version carrying no names and no precise locations.
- Set retention and destroy on schedule. Data kept indefinitely is a liability that grows, and most organisations have no policy on how long they keep anything.
- Encrypt devices and use a defined standard for transfer. Including a rule on what may be sent over which channel, and an explicit prohibition on carrying unencrypted beneficiary data on removable media.
- Train staff on behaviour, not only on tools. What may be discussed in a vehicle, at a checkpoint, in a guesthouse or on a social media account. Most disclosures are human rather than technical.
- Give staff a route to refuse. A member of staff asked at a checkpoint to hand over a laptop, or asked by an authority to provide a registration list, needs a stated position from the organisation and a person to call.
- Plan for the device being taken. Remote wipe, what is on the device in the first place, and who is informed when one is lost.
Practical guidance and research on the security of humanitarian staff, for the organisations that send them.