Home > Security All-in-One Guides > Compliance > Process improvement > Data security > Elements of a data protection strategy
All-in-One Guides: Compliance:
EMAIL THIS
 START   SOX SCHOOL   INFOSEC-RELATED REGS   STANDARDS   PROCESS IMPROVEMENT   PEOPLE & POLICY   TECHNOLOGY   AUDITS   
Process improvement


Data security
<< PREVIOUS | NEXT >>: Secure data transmission methods

Elements of a data protection strategy

20 Oct 2005 | Prentice Hall PTR

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Data Protection and Lifecycle Management

By Tom Petrocelli
$39.99, 288 pages
Prentice Hall PTR

In this excerpt from Chapter 1 of Data Protection and Lifecycle Management, author Tom Petrocelli addresses the importance of data protection as it pertains to regulatory compliance and outlines the five components of a data protection strategy.

[An] important business driver for data protection is the recent spate of regulations. Governments throughout the world have begun imposing new regulations on electronic communications and stored data. Businesses face dire consequences for noncompliance. Some countries hold company executives criminally liable for failure to comply with laws regarding electronic communications and documents. These regulations often define what information must be retained, for how long, and under what conditions. Other laws are designed to ensure the privacy of the information contained in documents, files, and databases. Loss of critical communications can be construed as a violation of these regulations and may subject the corporation to fines and the managers to legal action…

MORE INFORMATION

Download Chapter 1, Introduction to data protection

Visit our resource center for tips and expert advice on storage security

Read more book reviews, excerpts and chapters

Data protection is just what it sounds like: protecting important data from damage, alteration or loss. Although that sounds simple enough, data protection encompasses a host of technology, business processes and best practices. Different techniques must be used for different aspects of data protection. For example, securing storage infrastructure is necessary to ensure that data is not altered or maliciously destroyed. To protect against inadvertent data loss or permanent corruption, a solid backup strategy with accompanying technology is needed.

The size of an enterprise determines which practices, processes or technologies are used for data protection. It is not reasonable to assume that a small business can deploy expensive, high-end solutions to protect important data. On the other hand, backing up data to tape or disk is certainly something that any enterprise can do. A large enterprise will have both the resources and the motivation to use more advanced technology.

The goal is the same no matter what the size or makeup of the company. Data protection strives to minimize business losses due to the lack of verifiable data integrity and availability.

The practices and techniques to consider when developing a data protection strategy are:

  • Backup and recovery: the safeguarding of data by making offline copies of the data to be restored in the event of disaster or data corruption.
  • Remote data movement: the real-time or near-real-time moving of data to a location outside the primary storage system or to another facility to protect against physical damage to systems and buildings. The two most common forms of this technique are remote copy and replication. These techniques duplicate data from one system to another, in a different location.
  • Storage system security: applying best practices and security technology to the storage system to augment server and network security measures.
  • Data Lifecycle Management (DLM): the automated movement of critical data to online and offline storage. Important aspects of DLM are placing data considered to be in a final state into read-only storage, where it cannot be changed, and moving data to different types of storage depending on its age.
  • Information Lifecycle Management (ILM): a comprehensive strategy for valuing, cataloging and protecting information assets. It is tied to regulatory compliance as well. ILM, while similar to DLM, operates on information, not raw data. Decisions are driven by the content of the information, requiring policies to take into account the context of the information.

All these methods should be deployed together to form a proper data protection strategy.

Read the rest of Chapter 1, Introduction to data protection



BROWSE BY TAG
Enterprise Data Protection,   Enterprise Data Governance,   Data security,   Compliance,   Process improvement,   Identity Theft and Data Security Breaches,   Data Loss Prevention,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: Secure data transmission methods
VIEW ALL IN THIS CATEGORY

RELATED CONTENT
Enterprise Data Governance
How to protect distributed information flows
Interpreting 'risk' in the Massachusetts data protection law
Creating an enterprise data protection framework
Analyst DLP study finds maturity, ranks top DLP vendors
Voltage, RSA spar over tokenization, data protection
Twitter gets condemned by CISOs at Forrester forum
PCI DSS compliance requirements: Ensuring data integrity
Trustwave acquires data loss prevention vendor Vericept
Data has become too distributed to secure, Forrester says
Cloud-based security services should start private

Data security
Secure data transmission methods

Identity Theft and Data Security Breaches
MA 201 CMR 17 enforcement less likely with prompt reporting, cooperation
No major PCI DSS revision expected in 2010
Data breach costs continue to rise in 2009, Ponemon study finds
Chinese hacker attacks target Google Gmail accounts, top tech firms
Facebook, McAfee partner to fix social network security issues
Hacker pleads guilty to orchestrating Heartland credit card heist
MasterCard reverses PCI compliance requirement
Verizon report goes deep inside data breach investigations
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cut-and-paste attack  (SearchSecurity.com)
data masking  (SearchSecurity.com)
data splitting  (SearchSecurity.com)
deperimeterization  (SearchSecurity.com)
Google hacking  (SearchSecurity.com)
masquerade  (SearchSecurity.com)
snooping  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts