Home > Security Tips > Threat Monitor > Data loss prevention from the inside out
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

THREAT MONITOR

Data loss prevention from the inside out


Noah Schiffman
02.05.2008
Rating: -2.44- (out of 5)


Threat Monitor
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


The traditional business-centric view of computer security has focused on the external threat landscape, often overlooking internal vulnerabilities. Subsequently, recent studies from Ponemon, Orthus and Vontu have revealed that a majority of corporate data loss, often termed data leakage, is caused unintentionally by an organization's own actions.

Listen to Noah Schiffman's tip

Download the author's data leak prevention advice to your computer or favorite MP3 player.
The potential legal liability and brand-reputation damage from corporate data loss has spurred growing demand for data leakage prevention (DLP) technologies. These technologies have largely focused on the need for automated data management. This "inside-out" security paradigm has resulted in corporations striving to achieve rapid data governance via products that emphasize outbound content compliance (OCC) policies, insider threat management, and extrusion prevention systems (EPS).

However, before considering a comprehensive enterprise data management product or platform, information security departments must understand their organizations' business workflow and how it relates to the protection of existing IT assets. This process should include investigating and targeting key aspects of the network infrastructure that may be a source of data loss. Here are some important issues to consider when identifying potential areas of data leakage:

  • As the complexity of an IT infrastructure increases, so does the difficulty of knowing where all the data resides, how it's accessed and by whom.
  • As the roles of data managers and storage managers blur, assigning the responsibility for creating a data ranking system becomes harder to define.
  • The business must strive to assess the criticality of corporate. Once content discovery of all data is completed, a classification scheme must be implemented to categorize data sensitivity. .
  • Those with access to the data are the ones usually responsible for its loss. Identify users with overly permissive access controls, including senior managers, who often request high privilege levels without possessing the proper training in data security.
  • While inbound email is analyzed to protect against internet threats, outbound email is often overlooked as a major source of data loss. The accidental loss of confidential and proprietary information from insider email is one of the largest areas of data loss. The risks associated from activities such as personal web based account use and inappropriate message auto forwarding, can have serious legal, financial and regulatory consequences. .
  • Unauthorized use of Internet protocols and services -- such as IM, peer-to-peer file sharing, blogging, social networking sites and unauthorized uploading (FTP) of data to Web sites -- is a major contributor to data security incidents and should be controlled via a detailed policy.
  • The use of contractors and outside consultants usually requires the creation of new user credentials. However, knowledge and accountability of these user accounts is essential, as they are often lost.
  • Removable storage media, such as flash drives, optical media, external hard drives and personal media devices, create a portable medium for the loss of data.
  • Mobile computing platforms (i.e. laptops, PDAs) allow data to be physically removed from the corporate environment where all monitoring and control is lost.
  • For more information:
    Michael Cobb explains how well database extrusion products can protect an organization's information.

    Learn how corporations can avoid insider threats by forming an incident response plan and monitoring employee behavior.

    Tony Bradley explains how Windows Rights Management Services (WRMS) can help implement document access restrictions and protect sensitive data.
    Strategic planning for prevention
    Enterprise storage has evolved far beyond direct-attached storage (DAS), basic networked file shares and simple database storage. Today's architecture employs storage area networks (SANs) using iSCSI and Fibre Channel, tiered and hierarchical storage models, virtual storage systems, high-end storage arrays and clustered storage. Due to the wide variety of hardware and software and their numerous configurations, the remediation strategies for data leakage are ultimately company specific.

    Nevertheless, the commonality of all DLP planning should involve consideration of the following:

  • Implementing basic company-wide standards and procedures for all employee data usage and information ownership;
  • Assessing and ranking corporate data based on the business risks associated with its loss or exposure;
  • Ensuring detection and classification software uses effective identification algorithms with lexical examination of data content;
  • Performing frequent inventory reviews of business critical data, ensuring proper safeguards are in place and making sure security protocols are up to date;
  • Using an effective data security model that simplifies role based access control (RBAC) and granular control of individual users;
  • Enforcing employee training of corporate email acceptable use policies. Consider messaging protection platforms for automated corporate compliance and policy management of outbound email;
  • Ensuring that employees are aware of computer usage monitoring as a deterrent to attempts at policy circumvention;
  • Administering frequent reviews of user-privilege levels to assess and confirm that the appropriate settings are configured for each user;
  • Embedding access controls directly into sensitive data through use of digital rights management (DRM) technologies;
  • Maintaining data security when dealing with business partners through the use of federated identity management; and
  • Generating routine audit and data-flow assessment reports to monitor data leakage threats and track data locations with respect to time and user request.
  • Do you have a burning IT question?
    Contribute to IT Knowledge Exchange and you could win an Xbox 360 Elite, iPod Touch or $100 Amazon gift certificate. Earn the most Knowledge Points by asking, answering or discussing a question in order to win. Contest runs from January 28th to March 15th.
    Data loss prevention has become a relevant compliance issue and is critical in protecting confidential company data and preserving customer data privacy. Data growth rates today are such that it is a challenge to efficiently manage new and existing data. Corporate security policies that address data proliferation issues must also sustain data availability, business productivity, operational continuity and data restoration. Most importantly, to avoid end-user misperception that your DLP strategy is set of IT laws, thorough communication and education is essential in facilitating acceptance of the organization's DLP program as an important parallel business strategy.

    About the author:
    Noah Schiffman is a reformed former black-hat hacker who has spent nearly a quarter century penetrating the defenses of Fortune 500 companies. Today he works as an independent IT security consultant specializing in risk assessment, pen testing, cryptography and digital forensics, predictive analysis models, security metrics and corporate security policy. He holds degrees in psychology and mechanical engineering, as well as a doctorate in medicine from the Medical University of South Carolina. Schiffman is based in Charleston, S.C.

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Threat Monitor,   Security Awareness Training and Internal Threats,   Information Security Management,   Enterprise Data Protection,   Enterprise Data Governance,   Data Loss Prevention,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Threat Monitor
    How to detect software tampering
    How to prevent phishing attacks with social engineering tests
    An enterprise strategy for Web application security threats
    How SSL-encrypted Web connections are intercepted
    How a corporate Twitter policy can combat social network threats
    Cyberwarfare and the enterprise: Is the threat real?
    Software security threats and employee awareness training
    Newest malware threats
    How to defend against rogue DHCP server malware
    When BIOS updates become malware attacks

    Security Awareness Training and Internal Threats
    Creating a HIPAA employee training program
    Successful rogue antivirus hinges on social engineering
    External attacks start with unintentional mistakes, survey finds
    Security technologies fail to address insider threat management
    Data breach avoidance begins with security basics, panel says
    Monitoring program data and internal controls for risk management
    Software security threats and employee awareness training
    Twitter risks, Facebook threats trouble security pros
    Social engineering training could disrupt botnet growth
    How to write a risk methodology that blends business, security needs

    Enterprise Data Governance
    Creating an enterprise data protection framework
    Analyst DLP study finds maturity, ranks top DLP vendors
    Voltage, RSA spar over tokenization, data protection
    Twitter gets condemned by CISOs at Forrester forum
    PCI DSS compliance requirements: Ensuring data integrity
    Trustwave acquires data loss prevention vendor Vericept
    Data has become too distributed to secure, Forrester says
    Cloud-based security services should start private
    Compliance in the cloud
    How to write technology outsourcing contracts

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    dumpster diving  (SearchSecurity.com)
    Honeynet Project  (SearchSecurity.com)
    insider threat  (SearchSecurity.com)
    National Computer Security Center  (SearchSecurity.com)
    pretexting  (SearchCIO.com)
    shoulder surfing  (SearchSecurity.com)
    single-factor authentication (SFA)  (SearchSecurity.com)
    social engineering  (SearchSecurity.com)
    Total Information Awareness  (SearchSecurity.com)
    trusted computing  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Research Solutions for Network Security, Access Control and Security Threats
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts