Data Security

Security is a primary focus at NORTH AMERICAN RECOVERY and is part of our core culture, whether physical, network, or data security. NORTH AMERICAN RECOVERY maintains security on all data, including backup systems in the event of system failure due to natural disaster or otherwise. Coded key fob entry locks on all external doors protect our physical facility. Our building is a medium-high security facility with on-site grounds and building security personnel.

NORTH AMERICAN RECOVERY has implemented several measures to ensure the security of our client's data. All access to the computer system itself is protected by a multiple password scheme. In addition, we do not allow remote connection directly to our internal network. Therefore, an outsider would not even be able to locate our system.

Internally, once access to the system has been granted, the user must then use a user name/password to use system resources. This combination is unique to each user and identifies to the system software which capabilities each particular user is allowed to have.

All routers and firewalls are upgraded regularly and all data is 128-bit encrypted. Dedicated T-1s are used for both voice and data. However, encryption is only one tier in NORTH AMERICAN RECOVERY'S approach to a multi-tiered security solution. Security is not only about protecting our network from outside threats; it is also about protecting from threats from within. The weakest link in any IT security chain is the human element. In order to maintain a genuine security culture everyone in the organization from top to bottom must be informed and motivated about information security. The first step in internal security is awareness. Therefore, all of our employees are aware of and trained to recognize and protect against potential threats. Education and awareness empowers each employee with the knowledge of his or her role in protecting our organization's network, which goes a long way towards mitigating risk.

NORTH AMERICAN RECOVERY's security training program delivers a sequence of awareness modules covering different information security topics every month. The security training materials address general employee issues, managers, and IT people separately, because they have distinct information needs.

Our Acceptable Use Policy (AUP) is a key element of our training and requires passing a written exam for each employee. Our AUP covers e-mail usage, privacy, passwords, laptops, client data, and containment (no employee, e.g.: collector, is permitted to work from home, or remove transportable storage devices such as CD-ROM, USB key, or floppy from the facility, or to transfer data from work to home.

Workforce training is not a single event. Security awareness requires commitment to a continuous program of employee communications and training. As with all other aspects of an employee's job, proper training in security is a core component of our success. Our security training includes:
  1. Policy and procedure documents regarding computer usage, especially regarding Internet and e-mail limitations;
  2. We also teach employees "best practices" when using the Internet or e-mail (for example not opening attachments from unknown senders and keeping passwords private). Other information security issues such as spam, the dangers of accidentally downloading spyware, and phishing expeditions are covered. Unless employees are 100% certain that a communication is legitimate, they assume it is not. It is an immediate termination offense to download unauthorized software or freeware, such as file sharing programs or games. In addition to Internet security training and regular briefings, memos are distributed companywide when new threats arise alerting all staff as to the threat, how to identify it, and what to do if it is encountered.
  3. All employee computers and laptops are equipped with the latest security tools and require two levels of passwords for access. Each employee is educated as to the application and use of each of the tools available, and every computer has automatic 100% full time scans of any file opened or accessed.
  4. NORTH AMERICAN RECOVERY makes sure that all employees are aware of the internal risks. The entire staff is constantly reminded of the importance of reporting unusual or potentially harmful activity among other employees.
  5. Staff are encouraged and rewarded for being security-conscious.
Our layered, multi-tiered approach to security provides both NORTH AMERICAN RECOVERY and our clients maximized security solutions that cover as many bases as possible.

NORTH AMERICAN RECOVERY uses a dual backup methodology. All of our Direct Access Storage Devices (DASDs) are redundant. We maintain a complete backup of the live data. In addition, we do a complete backup nightly. The daily backups are archived for two weeks, the weekly backups are archived for a month, and the monthly backups are archived for a year. Yearly backups are archived indefinitely.