A common theme amongst my writing and presentations lately has been that data protection is impossible. Think about it. The whole concept of protecting data from being stolen, lost, or inappropriately used is a set-up for failure. When Rich Mogull started covering the data protection space at Gartner it was considered a small niche in the security market. But in reality data protection is what the entire security space is all about. At one point the editor of Data Protection Weekly confessed to me confusion over what should be included in the catregory of DP: encryption? access control? physical security? The answer is yes.
So a bunch of companies sprang up in response to the data loss disclosures mandated by California 1386. Great ideas. First there was the problem of personally identifiable information (PII) like social security numbers or credit card numbers being emailed off site. Simple solution, put in deep packet inspection devices to do pattern matching and alert or block the transfer of PII. Great, what about other intellectual property such as key financial documents or customet lists? No problem, scan your databases and digitally tag important files. Then apply policies to block the transmission of those files. Wait, what if someone cuts-and-pastes critical info to an email or IM message? No problem, take many slices of each file and hash them.
OK, you have the info sliced and diced every which way but an end user can just copy files to an iPod or thumb drive and walk out the building. OK, let’s monitor evey USB port on every endpoint and prevent it from being used in this way.
OK, what about printing? What about screen shots? No problem. There are technical solutions there as well.
OK smart guy. The CFO wants to leak the new quarterly results. He brings up his spreadsheet on his monitor and uses his cell phone to take a picture of the data and sends it to his buddy. Are you going to stop that? No. So the model breaks down. Complete data protection is impossible. At some point a user needs to access that data and you have to trust that user.
Does that mean don’t do data protection? Of course not. Do everything you can. Encrypt when you can. And then, monitor access to the data. There is significant investment and there is significant pain. But it has to be done. In the meantime prepare for data loss. It will happen.




