A couple of news items this week in the Data Protection Weekly newsletter once again highlight the importance of taking an insider’s approach to data protection.
Many DLP (Data Leak Prevention) strategies focus on the accidental loss of data through inadvertent posting to a corporate website, lost or stolen laptops, and backup tapes gone missing. A Texas Lottery worker was arrested for taking the personal information of 27,000 lottery winners with him when he left. Imagine the value of that list to scam artists, the kind of people who would pay for that data in the first place. In another incident a former employee of the US Department of State pleaded guilty to viewing passport application data of celebrities.
In the case of an employee stealing important data like the list of lottery winners, there are solutions that may have prevented this. Device management coupled with a network filter might have caught him. I imagine that most bad apples in your organization will try simple techniques like emailing themselves spreadsheets before they try more sophisticated methods. It is that first attempt that gives you the early warning and the opportunity to discipline that insider before the damage is done. If you have technology in place that just blocks the action, the insider will figure out a work around even if it means taking a digital photo of their screen like this one. A simple OCR program can then be used to convert the data back into a spreadsheet.
In the case of the passport office there is a bigger issue. The employee was viewing confidential information. This goes on all the time: hospital employees looking at records of celebrities, or even other staff members, police abusing their access to information, maybe the NSA employees looking at SWIFT transactions without prior notification, or bank tellers browsing through the accounts of high net worth depositors. . How can you use rights management to avoid abuse like this? You can’t. But, you can monitor database access and application usage and create an alert when suspicious activity is noticed. Product solutions for this type of monitoring are in their infancy. But as these issues surface data access monitoring (DAM) is becoming a growth industry.




