Assessment Method: Professional Discussion underpinned by a portfolio
S9 is about making sure that whenever you handle digital information—whether storing, sharing, or deleting it—you follow data security principles. This means protecting data from unauthorized access, keeping it accurate, and ensuring it’s only used for the right purpose.
Encrypting files before sending them via email or using secure file-sharing platforms
Applying mailbox rules to prevent sensitive emails from being sent to the wrong recipient
Using Power Automate to create approval workflows for sharing confidential documents
Storing files in secure, access-controlled locations like SharePoint or OneDrive
Following company policies for secure deletion of data
Thinking that saving a file in a shared folder is always secure
Believing that deleting a file from a folder means it’s gone (it may still exist in backups)
Ignoring encryption for sensitive data transfers
Forgetting to apply access controls or permissions
Podcast: Data Security in Practice (Insert your podcast link here)
Protects sensitive data from breaches and misuse
Ensures compliance with legal and organizational requirements
Maintains trust with customers and stakeholders
Screenshots of:
A secure file transfer or encrypted email
A Power Automate approval flow for sensitive data
Mailbox rules for managing confidential communications
A short write-up explaining how you applied data security principles in a real scenario
How do you ensure data is handled securely in your role?
Can you give an example of when you applied data security principles?
Why is it important to follow secure deletion and storage practices?
Equality & Diversity: Ensuring security measures do not disadvantage any user
Sustainability: Reducing paper-based processes by using secure digital systems
British Values: Promoting responsibility and accountability in data security