Seems like the data/information-centric approach to data protection is gathering more steam. Interesting article in CSO Magazine by Forrester analyst Andrew Jaquith talks about giving up control to gain control - using a data-centric security approach. Very interesting.
It talks about forgoing a infrastructure control perspective to being more data-centric and giving up responsibility to those to use the data.
Here is a short excerpt:
"Instead of beating your head against the wall, devolve responsibility to the business, keeping controls closest to the people who use the data. IT security should be primarily responsible only for deploying data protection technologies that require minimal or no customization."
Another excerpt I agree with :
"Confronted with these three challenges, some nervous CIOs and CSOs choose to throw the proverbial kitchen sink at the problem: DLP, encryption-everywhere, enterprise key management, NAC, and employee education. However, this approach will fail because at its roots, the problem of data security stems from four sources: digital information was meant to move; information classification isn't ingrained into work processes; technical solutions aren't standardized; and accountable parties are too far from the controls."
The main one being (highlight above is my emphasis) - data is meant to move, distribute and gain in value! You cannot stop data from moving and be a friend of the business!
Monday, March 30, 2009
Devolution, job responsibilities and data-centric security
Posted by
Manu Namboodiri
at
3:06 PM
0
comments
Labels: data-centric, information-centric
The Chinese Cyber very, very, very, targeted attack
Incredible news about the cyber attack launched from China - and its taking over systems worldwide.
What is amazing about this is the large number of countries attacked - 103 with the small number of actual computers affected - 1200! Just about 10 systems a country - now that's a targeted attack! And to top it off, apparently over 30% were "high-value" systems and those within embassies of many countries.
It is remarkable that something this targeted can be achieved using one malware - unless it is the secondary phase after another one was spread wide, segmented the market and finally targeted those that are important.
Without taking away from the seriousness and criminality of it, the marketer in me is impressed - and shocked.
Posted by
Manu Namboodiri
at
9:38 AM
0
comments
Labels: data leakage
Wednesday, March 18, 2009
Heartland and Visa - a big case of CYA?
The latest salvo in the Heartland saga is Visa's decision to delist both Heartland and RBS WorldPay from the PCI DSS compliance list. According to a harsh assessment by Avivah Litan, Gartner analyst: "It's all legal maneuvering by Visa," Litan said. "This is PCI enforcement as usual: They're making the rules up as they go."
Ouch. These are interesting developments, and raises some questions -
- Is complying to PCI not enough anymore?
- Was Heartland really compliant?
- Or did the auditors not do a good job when they looked at Heartland?
- Do compensating controls not do the work?
- Is the PCI standard too vague and open to interpretation?
- Or is Visa just ensuring it does not get caught in the legal storm brewing around the breach?
Questions, questions...
I hope that this drives the industry forward in creating better standards, better auditors and better solutions that can address the increased threats we face daily - all we can hope is look for the silver lining in this debacle...
Posted by
Manu Namboodiri
at
10:47 AM
0
comments
Labels: data breaches, Fines, PCI
Thursday, March 5, 2009
Fraud affecting the huddled masses
Could not believe the recent Gartner analysis that says that 7.5% of Americans are hit with financial fraud - a good chunk of it due to breach, phishing etc. That is about 22M people, assuming a population of 300M. Thats a lot!
From the article:
"Gartner says financial losses are highest in the case of new-account, credit card and brokerage fraud, with the average cost per incident totaling $1097, $929 and $900, respectively."
The amount of money lost is staggering - if we assume a more conservative number of $500 lost for 22M Americans who have been defrauded - that's a total loss of $11B in 2008!
But wait, there's more -
"Victims of brokerage, credit card and debit card account fraud find it easiest to recover their losses, receiving an average of 100%, 86% and 77% of the funds stolen, respectively."
These defrauded customers get back their money - and the banks have to pay for these losses! (well, they get it back from the customers with increased fines and interest).I guess the point I am making is - the losses are real, the pain is real. We need to work to reduce these losses and fraud.
Posted by
Manu Namboodiri
at
2:52 PM
0
comments
Labels: data breaches, Securing data
Monday, February 23, 2009
The ex-employee threat
We all suspected it, some might have done it as well. According to the latest Ponemon survey, apparently nearly 60% of terminated employees take some company sensitive data with them. But the most troubling aspects are the ability for ex-employees to access company data even after they were let go!
I would think the majority of these can be prevented via good and simple baseline security. Some, of course, will need more sophisticated tools such as DLP etc that can track documents based on content. The hardest part will be stopping malicious users from taking a small set of extremely sensitive documents - for eg. taking a photograph of the document on his PC! If there are a lot of documents, it might be hard for the employee to do these manual tasks.
At the end of the day, one has to trust employees and be able to track documents and prosecute. If one or two high-profile cases end up in court, deterrence will become a good security policy!
Posted by
Manu Namboodiri
at
1:57 PM
0
comments
Labels: data breaches, Securing data, surveys
Tuesday, February 10, 2009
Breaches: The collective yawn
Are the breach laws not effective at all? Are the public not concerned or not paying any attention? Not sure what we should expect - outrage, public demonstrations, letters to senators? But as the recent article from NetworkWorld points out, folks don't seem to much care...
Possibly this apathy is picked up by organizations and combined with the multitude of complex regulations and data protection solutions - and the result is folks not knowing how to address these issues. The challenges may seem too much.
I think the right way to approach the problem is take a risk based approach - what is the most vulnerable area, how do we protect that. Start with something small, since inaction does not help at all. For many organization worried about losing assets outside the organization, protect the mobile data - that which goes outside the organization. This would mean laptops, USB devices to start out with and go from there.
Obviously if the threat is internal negligence, maybe look at DLP solutions that can, based on policy, protect sensitive data from leaking outside the enterprise.
The main point it, start on the path. Don't wait to develop a comprehensive plan that takes a year to study and setup - look for quick hits and gains. As you deploy you will be able to develop the right plan for the enterprise.
Posted by
Manu Namboodiri
at
9:29 AM
0
comments
Labels: data leakage, Securing data
Thursday, February 5, 2009
Breaches - up, up and away!
The news around breaches seem exactly like that of the current economy - gloom and doom all around. The latest in the fusillade is the analysis from Jon Oltsik from ESG. Looks like the number of breaches every year have been increasing - and this year it seems worse. Seems like with all the stuff hapenning (Heartland, the VA settling, the recent Ponemon report, the McAfee trillion dollar news), this new research is on expected territory.
However, one interesting nugget from Jon - 61% of small organizartions had a breach in the last 12 months while 49% of large ones succumbed in the same timeframe. One would have expected the difference to be much higher. Larger organizations have the resources and the security technologies in place to prevent such breaches - much more than do smaller organizations. Could be many reasons for the smallish gap - large companies are bigger targets, have more employees, have stringent disclosure requirements,have more data, etc. All valid reasons...
While this might be true, my hypothesis is that current security measures are also not working in large organizations. Breaches do not just happen in one areas (say laptops), but wherever data goes. And multiple, device-centric approaches to data protection do not mitigate breaches as much as folks would like to think.
One needs a better and more logical approach to data-protection. I firmly believe the information-centric approach is the way to go - protect data once, keep it protected wherever it goes - on any device and for any application.
Posted by
Manu Namboodiri
at
10:01 AM
0
comments
Labels: data breaches, information-centric, surveys