Skip Links

Network World

  • Social Web 
  • Email 
  • Close
Everything that matters: Exploring what's most important in IT today
And what doesn't matter See all articles See all articles

Three IT projects that matter

Privacy, enterprise rights management and data-center automation projects are proving invaluable as companies look for new ways to protect data
By Sandra Gittlen , Network World , 12/20/2007

While rapid-fire cost-savings and consolidation efforts typically dominate an IT executive's annual to-do list, what's getting the green light this year are multiphase projects that protect organizations from regulatory fallout and data leakage.

At the California Department of Health Care Services (DHCS), for example, increased federal mandates and heightened media attention have led to a focus on projects that prevent data loss, says Christy Quinlan, CIO at the Sacramento agency.

"I know that whatever we spend on projects to secure data would be a whole lot cheaper than having to deal with even one leak," she says.

IT executives in a cross-section of industries, including government, education and the private sector, share the sentiment. In fact, three specific project areas – privacy, enterprise rights management and data center automation – are all getting the go-ahead because they can enable better data protection.

Privacy

Since she took office as CIO in 2005, Quinlan has had a laser-like focus on improving the systems at the DHCS, a 2007 Enterprise All-Star Award honorable mention designee. She describes herself as a doer, not a talker, and doesn’t understand why implementing new technologies takes some IT teams so long. Being a doer served her well earlier this year when the U.S. Social Security Administration (SSA) notified her team that its main system, Medi-Cal, was in violation of the Health Insurance Portability and Accountability Act regulations.

The mainframe-based application lacked the ability to prove that only need-to-know personnel were gaining access to private patient information, the SSA said. More than 70,000 workers in 58 counties use Medi-Cal to access Medicare and Medicaid claims.

There’s still no requirement to encrypt desktops, but why wouldn’t you when you could have tremendous credibility damage if data were lost?, Christy Quinlan

To come into compliance, Quinlan needed to install role-based access privileges coupled with auditable time-stamping. "The SSA said we only had a short time to fix the problem or it was going to deny us access to its network," she says. The DHCS had no time to rewrite the Medi-Cal application code itself or to do any major system changes.

Instead, the agency opted to tack IBM's Resource Access Control Facility (RACF) onto the mainframe to manage and log role-based permissions atop the Medi-Cal system’s own basic built-in privileges. Now Quinlan can set multilevel security policies based on users and the types of files they are trying to access. "This depth of tracking allows us to create a full audit trail," she says.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

looking for a sugar daddy with a 12inch cock? well im him baby. check me out here. Most of my pics and...- Anonymous

Join the Discussion