Home > Information Security Magazine > Features > That Sinking Feeling
EMAIL THIS LICENSING & REPRINTS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

That Sinking Feeling
by Neil Roiter
Issue: Oct 2006
printer-friendly
licensing & reprints
< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   NEXT PAGE  >

Encrypt. As with monitoring, the key is understanding where your critical data lives and encrypting what's important. But don't underestimate the magnitude of the job. Key management is crucial and difficult: rotating and revoking keys without disruption, making sure the right people have the right keys, and ensuring they aren't lost--and access to your data with them.

"Realize how hard crypto is--the time frame should be years," says Loyalty Lab's Engel. "There are performance considerations, key management, and recovery. The architecture alone--rollouts take a long time."

Separation of duties is an important consideration. It's not that you don't trust DBAs, but best practice means that you have two systems--one providing access to data and one providing keys--managed by different people. Finally, encryption is just part of a layered solution. Many organizations leapt at encryption as a quick fix to satisfy regulatory pressures, but it is neither easy nor a complete fix. Encryption ensures that the external hacker or someone who finds or steals a laptop or backup tape can't read your data. However, the insider threat remains, and encryption won't stop a malicious user who has legitimate access.

Grab low-hanging fruit. Attention to the little things, eliminating the simplest, most obvious risk factors, pays big dividends. You'd find a surprising number of databases still using default admin passwords and IDs.

"Understand and manage easy targets--like blank passwords. If you scan for that, you'd be stunned," says Giambruno. "You've got to fix the basics; that's where protecting data really starts. Follow the top 10 basic security rules, and you'll be fundamentally secure."w

< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   NEXT PAGE  >





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts