Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Preventing data breaches not a technology issue

Insider Threat By Faizel Lakhani , Network World , 06/23/2008
  • Share/Email
  • Comment
  • Print

When security people see headlines about data losses at TJ Maxx, ChoicePoint, DuPont, and the Department of Veterans Affairs, they quickly assume that preventing such loss is a technology problem.

It clearly is not. It is an information problem.

Organizations know that protecting their clients' or employees' data is paramount and that the risk of not protecting it is a story in the Wall Street Journal. However, underneath the public thunder about the loss of credit card and social security numbers and healthcare information, even more confidential information is at risk.

Before Steve Jobs introduced the new iPhone 2.0 last week, did the security people at Apple know what it was or from whom details about it should be kept? I suspect security would have needed to talk with the iPhone business owners, if not with Steve Jobs himself, to find this out. When Pfizer starts developing a blockbuster drug, how does the information security team protect the recipe for the drug before it achieves regulatory approval?

Today, information security (IS) must know what information to protect and from whom. How can IS do this? Security personnel can start by involving the stakeholders in the process of determining what data is sensitive and who needs to know it early in the data creation process. This is a very difficult task, as the main incentive of business stakeholders is to bring in revenue; protecting information is of secondary importance.

However, weaving information protection into the business is a top necessity. Information security teams need to understand and identify the most important data and where it should go before they can protect it. This means that IS needs to take on a new role as partners to the business stakeholders. Historically, IS has lacked the capabilities required to converse about sensitive information and who is allowed to see it. Data loss prevention (DLP) solutions can help, as they examine all content as it leaves an organization's network or an individual's workstation, or as it is stored on the network.

But how can IS determine which data it should protect? I have found this model to be successful:
1) Start by finding out the top projects that the company is working on
2) Build out a definition of what makes up the project (either through scanning data at rest or manually)
3) Analyze where communications about this project are going (through data-in-motion analysis)
4) Map which departments are communicating the information (by leveraging identity information)
5) Interview business stakeholders to determine if these communications are part of business policy
6) Set up rules to look for communications that are outside the norm

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (4)
Login
Forgot your account info?

Respinse: Preventing data breaches not a technology issueBy Anonymous on June 30, 2008, 1:26 pmProtecting credit card, social security and bank account numbers is not obvious to you?

Reply | Read entire comment

It's all a matter of costBy Mike.D. on June 25, 2008, 3:45 pmIf you make private data breaches significantly more expensive than protecting that data in the first place, the breaches will pretty much stop. The way businesses...

Reply | Read entire comment

Response: What is private data and what is not?By Faizel Lakhani on June 25, 2008, 3:28 pmBen: I agree that fixed format privacy data is more easily protectable when it is not fixed format. This certainly solves the problem of privacy data, but what...

Reply | Read entire comment

what is private data and what is not?By BenjaminWright on June 23, 2008, 3:40 pmFaizel: If we render "private" data so it is of no value to criminals, then we don't have to work so hard to prevent unauthorized access to it. For example, the...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Stock Spam: A Classic Scam

Ever since there have been stocks and shares there have been so called "pump 'n' dump" scams. This...

Spyware: Know Your Enemy

Like Macavity, the fictional feline in T. S. Eliot's well-known poem, spyware may be considered to...

The Online Shadow Economy: A Billion Dollar Market For Malware Authors

Malware, meaning computer viruses, trojans and spyware, is about money. The teenagers who wrote...

Webcasts

SQL Server Consolidation: Insights from customers, analysts & HP

Microsoft SQL Server has enjoyed phenomenal success as a database server. Its relatively low cost,...

Minimizing the Risk of Information Security Breaches: Best Practices for SOA Governance and Compliance - Live October 21

Today's enterprises face more information security risks and vulnerabilities than ever before....

Migrating to Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Special Reports

Unified Threat Management from CheckPoint

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.