Contributor

Data protection is impossible

Opinion
Mar 10, 20083 mins

A common theme amongst my writing and presentations lately has been that data protection is impossible.  Think about it.  The whole concept of protecting data from being stolen, lost, or inappropriately used is a set-up for failure.  When Rich Mogull started covering the data protection space at Gartner it was considered a small niche in the security market. But in reality data protection is what the entire security space is all about.  At one point the editor of Data Protection Weekly confessed to me confusion over what should be included in the catregory of DP: encryption? access control? physical security?  The answer is yes.  

So a bunch of companies sprang up in response to the data loss disclosures mandated by California 1386. Great ideas.  First there was the problem of personally identifiable information (PII) like social security numbers or credit card numbers being emailed off site. Simple solution, put in deep packet inspection devices to do pattern matching and alert or block the transfer of PII.  Great, what about other intellectual property such as key financial documents or customet lists?  No problem, scan your databases and digitally tag important files. Then apply policies to block the transmission of those files. Wait, what if someone cuts-and-pastes critical info to an email or IM message?  No problem, take many slices of each file and hash them. 

OK, you have the info sliced and diced every which way but an end user can just copy files to an iPod or thumb drive and walk out the building. OK, let’s monitor evey USB port on every endpoint and prevent it from being used in this way.  

OK, what about printing? What about screen shots?  No problem. There are technical solutions there as well.

OK smart guy. The CFO wants to leak the new quarterly results. He brings up his spreadsheet on his monitor and uses his cell phone to take a picture of the data and sends it to his buddy. Are you going to stop that?  No. So the model breaks down. Complete data protection is impossible. At some point a user needs to access that data and you have to trust that user. 

Does that mean don’t do data protection?  Of course not. Do everything you can. Encrypt when you can. And then, monitor access to the data. There is significant investment and there is significant pain. But it has to be done.  In the meantime prepare for data loss. It will happen.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author