You need high security. You need Ohio Mobile Shredding.
As the secure destruction environment continues to become increasingly regulated, companies are requiring assurance that their provider is capable of assuming the risk associated with handling data. NAID AAA Certification® provides that assurance.
NAID Certification is an internationally recognized program that routinely audits data-related service providers who are responsible to securely destroy sensitive materials for their clients. The program relies on unannounced and announced audits using third party accredited security professionals to verify compliance with 20 operational aspects of security, including employee screening , access control, training, CCTV image capture, and making sure that the firm complies to written policies and procedures that are consistent with data protection regulatory requirements.
For our customer’s legal compliance and complete peace of mind, Ohio Mobile Shredding invests in meeting the certification requirements and has maintained its NAID AAA Certification® status since 2003.
The International Secure Information Governance & Management Association (i-SIGMA) has released a video that explains how NAID Certification works and why it is important.
Who is i-SIGMA®?
i-SIGMA® is the International Secure Information Governance & Management Association, the non-profit trade association of the information destruction industry. Founded in 1994 originally called NAID. i-SIGMA® has only one purpose – to champion the responsible destruction of confidential information and materials by promoting the highest standards and ethics.
Today i-SIGMA® is recognized internationally by many policymakers and is often called upon to provide counsel to organizations developing information security standards and regulations.
Ohio Mobile Shredding has been a member of NAID/i-SIGMA® since 1996. Our founder and CEO, Timothy J. Oberst, has served NAID as President, Director, Treasurer, and on various committees including the Ethics Committee, the Certification Rules Committee, and the Complaint Resolution Council.
For more information contact:
Nathan Campbell – Chief Executive Officer
International Secure Information Governance & Management Association
3030 N. 3rd Street, Suite 940
Phoenix, AZ 85012, USA
+1 (602) 788-6243
What is NAID AAA Certification®?
The increasing number of laws and regulations requiring information protection emphasizes your responsibility to make careful decisions about how your data is handled and who handles it. If security safeguards are breached, audited or challenged due diligence in the selection of the shredding vendor must be apparent and defensible. Merely saying “but we have a certificate of destruction” is an inadequate defense. Any lawyer, judge or jury would want to know what qualifications the provider possessed for you to choose them. You must be able to defend those qualifications in a court of law.
How can you be certain of the shredding provider’s qualifications? One simple way is to ask them if they are NAID AAA Certified®. i-SIGMA® NAID certification verifies the shredding provider’s qualifications and confirms the security you expect.
Every aspect of a NAID AAA Certified® provider’s operation is controlled by strict security standards. In fact, NAID AAA Certified® standards are so demanding they establish the due diligence required for compliance with HIPAA, Gramm-Leach-Bliley (GLB) and FACTA, and they exceed the standards for reasonableness that is generally accepted by government agencies and courts.
NAID AAA Certification® demands compliance with standards for employee screening and hiring, operational and facility security, the destruction process, and insurance requirements. In all, compliance with more than twenty standards is verified by and independent Certified Protection Professional® (CPP)*. And it doesn’t stop after one inspection; to maintain certification, the shredding provider must pass the verification process annually. And to ensure ongoing compliance, the provider may be randomly audited throughout the year.
By choosing Ohio Mobile Shredding; NAID AAA Certified® since 2003, you demonstrate that you have made your choice about information protection with care, diligence, and respect for the law.
*The CPP is the highest and most recognized security management accreditation achievable. The CPP accreditation is issued to security professionals who meet stringent educational and experience requirements by ASIS International®, the preeminent professional security association.
Downstream Data Coverage helps protect you.
Using outside services for data destruction, records storage, media rotation and many other data-related services has grown so popular because they can do it more securely and more economically than organizations can do it for themselves.
However, as the financial and regulatory compliance liabilities around data protection increase, customers have come to realize that they are inescapably responsible in the unlikely event a data breach or other loss is caused by those vendors – no matter how it happened. Let’s face it, when 47 states have data breach notification laws and with HIPAA now requiring data breach notification across the country for breaches involving healthcare information, customers have the right to be concerned. Fines for improper data disposal and expenses for data breach notification over the last few years are in the tens of millions of dollars and continually increasing.
That‘s why it‘s common for customers to insist that data-related service provider’s reasonably indemnify them from any harmful financial consequences they cause. Unfortunately, many of the professional liability products on the market do not adequately address the risks.
So, how then do customers really know they are protected, when they usually never even see the policy, and if they do see it, they need a lawyer to decipher the language? The best solution is to require a specific policy developed by organizations worth trusting.
When i-SIGMA first learned that many policies contained loopholes that rendered them useless, it started what turned out to be a 4 year project to put together a product that would provide real protections to it members.
Downstream is not available to just any service provider. i-SIGMA also had another goal when helping to create Downstream; to help lower the cost of dependable coverage to its members. To do that, only service providers subject to the security specifications and audits (both announced and surprise) of the NAID AAA Certification® process are eligible for Downstream Data Coverage.
So, by insisting that your service provider has Downstream Data Coverage, you are not only assured they have dependable professional liability coverage, backed by i-SIGMA’s reputation and the resources and integrity of Lloyd’s – you are also assured by their NAID AAA Certification® that you are dealing with an service provider whose operations are intensely audited.
(taken from www.downstreamdata.com)
NAID AAA Certification® Criteria
Ohio Mobile Shredding has met or exceeded the following NAID AAA Certification® criteria:
Employee Screening & Hiring
Operational Security
Facility Security
The Destruction Process
Company Assurances
Benefits of Working with a CSDS Professional
What is a Certified Secure Destruction Specialist (CSDS®)?
The CSDS program is a professional accreditation issued by i-SIGMA, the 20-year-old, non-profit watchdog organization for the secure destruction industry. To earn the accreditation, individuals must prove they have a high degree of competency in a range of data protection regulatory and compliance issues as well as a thorough understanding of physical and operational security.
Why work with a CSDS?
The secure destruction of records and data has become a complicated process over the past decade. With constantly evolving data protection laws, service provider qualifications, media, and policy development and training requirements, designing a compliant program requires a level of expertise not available in most organizations. It is now critical that you work with someone who understands your responsibilities and theirs.
For instance, did you know?
Improper data disposal puts an organization at risk
Prior to 2008, there were few if any regulatory fines for improper data disposal. Since then, in an attempt to curtail the growth of identity theft, millions of dollars in fines have been assessed. Newspapers and broadcast media routinely report incidences of improper disposal. In fact, the U.S. Department of Health and Human Services is now actively training the staff of states’ attorneys general to look for improper disposal of certain types of data.
A CSDS keeps up on data destruction requirements
There is no question that data destruction requirements will continue to evolve. That’s why CSDS professionals are required to continue their education of data protection laws and other changes that will affect their customers. Because they are staying informed, you’re better protected.
Use a CSDS to help you with your secure destruction needs today. Learn more at www.isigmaonline.org.
CSDS competencies
About i-SIGMA®
The International Secure Information Governance & Management Association (i-SIGMA) is the non-profit watchdog organization for the secure data destruction industry founded in 1994. i-SIGMA’s mission is to promote the proper destruction of discarded information by promoting the standards and ethics of its members.
GPS Tracking
All of our trucks are equipped with the latest GPS tracking technology to ensure absolute security in your document destruction. We know where our trucks, and your materials, are at all times.
In addition to providing a higher level of security, our GPS tracking allows us to respond quickly to emergency needs. If a client needs immediate service we can use our GPS system to locate an available truck near the area.
Facility Security
To ensure the security of your records, OMS’ facility is dedicated to destruction operations only. All entrances are locked twenty-four hours a day and access points require key and/or access codes. A closed circuit surveillance system monitors all points and processing activity, and a monitored alarm system is armed when the facility is not occupied.
All non-employees are required to sign a log stating the purpose of their visit and a Confidentiality Agreement. Visitors entering the destruction area must be escorted by an OMS Access Employee at all times.
Our Employees
Before being considered for hire, every OMS candidate must pass an extensive third-party background screening by the FBI and the Bureau of Criminal Investigation (BCI). This includes investigating felony and misdemeanor criminal records, a seven-year employment history, pre-employment drug screens, credit checks and motor vehicle reports for our drivers. Every new employee must also sign a continuing obligation Confidentiality Agreement.
All OMS associates are required to comply with OMS’ written Policies and Procedures as well as the standards required as a NAID AAA Certified® provider. All of our drivers wear easily identifiable uniforms with photo ID’s and are bonded and insured.
And, last but not least, all of our associates are really nice people!
Our Certificate of Destruction is validated by a comprehensive audit trail
At OMS, we don’t just provide you with a “Certificate of Destruction”; we back it up with a detailed audit trail for your record keeping and security. Our unique Certificate of Destruction establishes critical criteria such as transfer of custody and acceptance of fiduciary responsibility for your protection.