Today, RFID is a key technology for supply chain inventory, asset, product, equipment, shipments tracking and more. However, with the increasing deployment of RFID, another question is becoming more and more relevant: who is going to secure the data, maintain compliance, and ensure the RFID information is accurate?
The answer to that question is in the framework of RFID governance. If not properly assigned, an organization may encounter security issues, incorrect inventory records, privacy problems, compliance issues, and expensive operational errors.
How to Govern for RFID?
RFID governance is the policies, responsibilities, controls, and processes for managing RFID and the data it produces.
A good governance framework should cover the following:
- Management of RFID hardware and software.
- The accuracy and ownership of information.
- The control of access and cybersecurity
- Data privacy and regulation adherence
- Device and tag standards
- Retention and sharing of data.
- Incident response
- Third-party management and vendor management.
The goal is more than just to safeguard RFID readers and tags. It is to ensure the security, accuracy, availability, and usefulness of all information generated by the RFID.
Who Should Be the Owner of RFID Security?
RFID security should not be in the IT department’s hands only. Since RFID is a connection between physical activities and digital systems, it should be shared among multiple functions.
IT and Cybersecurity
Typically, IT teams should manage the technical security context of the RFID environment.
They might be responsible for:
- Network security
- Authentication and authorization
- Encryption where appropriate
- Applying system patches and updates.
- Device configuration
- Security monitoring
- Incident response
RFID readers, gateways, middleware, and connected applications can be integrated into a wider technology landscape within an organization. Security measures must thus be similar to the other connected systems.
Manufacturing and Supply Chain Teams
Operations teams ought to be the proprietors of the business and the correctness of the RFID data.
They know the flow of inventory in warehouses, stores, manufacturing plants, and distribution centres. They can be tasked with establishing data needs, process verification, and discrepancies.
For instance, if 500 units were reported as shipped, but only 470 were received, there should be a process in place in operations for determining the cause of the discrepancy.
Legal Teams and Compliance Teams
Compliance and legal professionals are to assist in deciding this in relation to laws, contractual requirements and industry standards as well as in-house policies and procedures.
In particular, when RFID systems are linked with:
- Employee tracking
- Customer information
- Product authentication
- Sensitive assets
- Cross-border data transfers
- Personally identifiable information
Not all RFID implementations pose a serious threat to privacy; organizations need to assess the risk, not take RFID data for granted.
The role of a Data Owner
A key governance decision is the data owner.
The data owner should be accountable for determining:
- The data that is gathered through RFID tags.
- Why it is collected
- Who can access it
- The length of time it is to be stored.
- To what extent can it be modified by which systems
- Different ways of defining data quality
- In situations where information needs to be archived or deleted.
The technology doesn’t have to be managed by the data owner. This person/business should, however, be responsible for the business value and integrity of the information.
Ensuring the Integrity of RFID Data
Security is only a portion of the equation. When the information on the RFID is incorrect, it can have just as much of a negative impact as compromised information.
The lack of data integrity may be caused by:
- Misconfigured readers
- Duplicate tag IDs
- Incorrect tag associations
- Reader interference
- Missed reads
- Duplicate reads
- Product master data is not correct
- Errors in the tagging process made by humans
Hence, organizations need to set up validation procedures.
Useful controls include:
- Unique identification: Make sure each tag is equipped with an appropriate unique identifier.
- Reader validation: Periodic test of readers’ performance and coverage.
- Exception management: Identify unusual events like unexpected quantities, duplicate readings, or unexplainable movements automatically.
- Data reconciliation: Match RFID data with ERP, WMS
- , or other authoritative data systems.
- Audit trails: Ensure that the records indicate major changes in the information associated with RFID.
- Governance and Compliance.
Compliance standards vary by industry, location, type of data collected and intended use. When deploying RFID at scale, organisations should first look at what regulations are applicable.
The following documentation should be undertaken in a governance program:
- The information which the RFID system can gather.
- The location of data stored.
- Who can access it.
- The method of its transmission.
- The amount of time it stays in a person’s system.
- Who gets it (third parties).
- The way incidents are reported and dealt with.
Vendors’ contracts should also be carefully examined. An RFID provider can have hardware, cloud platforms, middleware, analytics systems, or support services, leading to new data and cybersecurity concerns.
The Significance of Third-Party Governance
RFID implementation often requires the participation of many vendors, such as tag makers, reader vendors, software vendors, system integrators, and cloud platforms.
When considering vendors, organizations should consider the following:
- Security practices
- Data ownership provisions
- Access controls
- Software update policies
- Vulnerability management
- Service availability
- Incident notification procedures
- Data retention/deletion policies.
The security of a company’s RFID is only as tough as the weakest component in the chain.
Some Helpful Tips for Improving RFID Governance
These practices should be considered when a company is developing or expanding an RFID initiative:
- Set ownership prior to deployment; do not wait for a security/data quality issue to arise.
- Establish policies: Develop policies for acceptable use, access, retention, and security for the use of RFID.
- Limit access to RFID information according to employees’ roles: Only allow employees to access information regarding the RFID that is relevant to their work.
- Exceptions to be monitored: Unusual RFID events can be indicative of operational and security issues.
- Regularly audit vendors: Perform a review of third-party security and compliance.
- Test recovery procedures: Ensure that RFID systems can recover from outages and/or cyber incidents.
- Check data quality: Monitor the accuracy of data read, number of duplicate records, number of missing reads, and number of reconciliations attempted but failed.
- Review governance from time to time: Governance policies should keep up with the changes in the RFID deployment.
There is no single department that is responsible for RFID governance. Security needs to be in the hands of IT and the cybersecurity team; operational accuracy is in the hands of business and supply chain teams; legal and risk teams should oversee compliance; and data ownership needs to be clearly defined.
Collaborative is the best way: setting accountability and relating security, operations, data management, and compliance.
While RFID can give an amazing level of awareness into physical operations, this awareness is only valuable if the information it captures is reliable and secured. Good RFID governance makes a group of connected readers and tags an accountable, reliable, secure business system.
FAQ
Who should be responsible for RFID security?
IT and security functions should take the lead in RFID security, including network security, access control, device security, RFID monitoring, and incident response, but operations, compliance, and data governance functions should be involved in RFID security matters, including addressing operational and regulatory risks.
How to maintain data integrity in your business using RFID?
Businesses can improve RFID data integrity by applying unique tag numbers, conducting regular reader audits, checking RFID reads for duplicates or omissions, cross-checking RFID data in enterprise systems such as ERP and WMS, and auditing key changes to the RFID data lifecycle.
Why is RFID governance importance for business?
RFID governance provides clarity on who is responsible for what in RFID security, compliance, data integrity, vendor management, and RFID operations, and it enables organizations to mitigate cybersecurity threats, avoid data integrity problems, meet regulatory requirements, and maximize RFID data value.