Contributor

Monitor data access to protect against snooping

Opinion
Sep 29, 20082 mins

A couple of news items this week in the Data Protection Weekly newsletter once again highlight the importance of taking an insider’s approach to data protection.

Many DLP (Data Leak Prevention) strategies focus on the accidental loss of data through inadvertent posting to a corporate website, lost or stolen laptops, and backup tapes gone missing. A Texas Lottery worker was arrested for taking the personal information of 27,000 lottery winners with him when he left. Imagine the value of that list to scam artists, the kind of people who would pay for that data in the first place. In another incident a former employee of the US Department of State pleaded guilty to viewing passport application data of celebrities.

In the case of an employee stealing important data like the list of lottery winners, there are solutions that may have prevented this. Device management coupled with a network filter might have caught him. I imagine that most bad apples in your organization will try simple techniques like emailing themselves spreadsheets before they try more sophisticated methods. It is that first attempt that gives you the early warning and the opportunity to discipline that insider before the damage is done. If you have technology in place that just blocks the action, the insider will figure out a work around even if it means taking a digital photo of their screen like this one. A simple OCR program can then be used to convert the data back into a spreadsheet.

In the case of the passport office there is a bigger issue. The employee was viewing confidential information. This goes on all the time: hospital employees looking at records of celebrities, or even other staff members, police abusing their access to information, maybe the NSA employees looking at SWIFT transactions without prior notification, or bank tellers browsing through the accounts of high net worth depositors. . How can you use rights management to avoid abuse like this? You can’t. But, you can monitor database access and application usage and create an alert when suspicious activity is noticed. Product solutions for this type of monitoring are in their infancy. But as these issues surface data access monitoring (DAM) is becoming a growth industry.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author