* Safeguarding your organization's sensitive data
EMC’s acquisition of RSA Security, which closed last month, created a storm of controversy over the price paid relative to the perceived value gained. When the deal was first announced in June, I commented in this newsletter that there was more to the acquisition than was first apparent.
I spoke with the view of someone who has actually implemented a worldwide data authentication architecture based on applied cryptography – RSA’s original core value. I’ve experienced first hand just how hard-won success in data security can really be.
How critical – and how tangible – have data security risks become? The scale of regulatory penalties – which indicate the degree to which regulators are insisting that businesses address risks such as customer identity theft – gives one of the clearest measures. The Federal Trade Commission began this year by fining data broker ChoicePoint $15 million for lax security standards. The settlement was a “record-breaker,” according to FTC Commissioner Jon Leibowitz, and included $5 million for the establishment of a restitution fund for incident victims. In more than one case, the FTC has required offenders to implement an information security program subject to audit every other year for 20 years.
Penalties are not the only indicator of tangible impact. Here at Enterprise Management Associates (EMA), we recently followed the closing stock prices of six companies that had disclosed an information security breach between February 2005 and June 2006. Within a month of disclosure, the average price of these stocks fell by 5%, and remained in a range of 2.4% to 8.5% below that of the date of disclosure for another eight months. It did not recover to pre-incident levels for nearly a year. In the case of one of the six, the company’s stock fell 14% within a week of public disclosure, reaching a low point of 19% below pre-incident value on the 45th business day after the initial breach was first made public.
These factors have made the security of information one of the highest priorities for the enterprise today – and it is one of the most significant challenges the business will face. Sensitive information is found literally everywhere in an organization. It often has little structure that lends itself to recognition by tools that can automate the enforcement of information security policy.
These two challenges – the need to recognize sensitive information as well as information security risks, and the application of policy in response – have led to the emergence of products that address threats to the security of information itself. They are fast becoming some of the most creative applications of technologies that recognize structure in a mass of unstructured information, and are often coupled with high capability for the discovery and retrieval of relevant data out of large volumes of information. This is a critical capability when rapid information discovery may be vital to identifying information security risks, in the responsive analysis of forensic data in the event of a legal discovery action, to demonstrate compliance, or to identify security gaps.
Sophisticated as they are, however, these solutions cannot succeed unless they are built on a foundation of solid, security-relevant IT management and – most importantly – on a security-aware culture of people and process that includes subversion-resistant enforcement of a philosophy of “trust, but verify” concerning the actions of individuals.
On Tuesday, Oct. 3, I’ll be hosting an EMA Webcast at 11 a.m. Eastern (8 a.m. Pacific) that examines the emergence these products and technologies. Emerging technologies that have arisen to address these challenges specifically, such as content monitoring and filtering for the prevention of information leaks, information structure and classification management, and enterprise information rights management, will be examined along with new approaches to cryptography that have made this valuable technology far more accessible for securing data. We’ll examine the value of a comprehensive strategy in light of technologies such as IT security risk management and security information and event management, and the advantages of leveraging IT governance initiatives that enhance security throughout the enterprise, as well as developments in end-point security and network access control that add to the arsenal available to the enterprise.
I’ll look at each in the context of an information security strategy built on the comprehensive management of IT for security and compliance and people and process factors, and discuss the products that address the security of information itself. We invite you to join us by signing up for this event.




