Home > Security Tips > Network Security Tactics > Legislative mandates and cyber threats demand secured networks
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Legislative mandates and cyber threats demand secured networks


Vijay Ahuja
02.04.2003
Rating: -3.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   




The time has come when the legislative mandates and cyber threats should prompt you to evaluate the security of your sensitive information residing in storage networks.

Traditionally, businesses have focused on securing "data in flight" as it traverses the open networks including the Internet. Technologies such as SSL (Secure Sockets Layer) and IPSec protect the sensitive data over open networks. When in storage, company confidential information resides for indefinite periods of time, thereby giving attackers almost unlimited time and opportunity to steal or corrupt stored data.

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 includes a mandate to protect any individually identifiable health-related information. The U.S. Department of Health and Human Services published the final regulation in December 2000 which has a compliance date of April 14, 2003 (April 14, 2004 for small health plans). This rule covers health plans, health clearinghouses and healthcare providers who conduct certain financial and administrative transactions electronically. Covered entities must implement standards to protect and guard against the misuse of individually identifiable health information; failure may trigger civil or criminal penalties. Click here for details.

At the same time, identity theft is a fast growing cyber crime where attackers are stealing individual identities, then misusing the stolen credit cards or ordering news one. Details on this topic are available here. Last week, Canada experienced its biggest identity theft when records of 180,000 clients of an insurance company were lost.

So how can you protect sensitive data in storage?

Data in store can be secured against theft by storing it in encrypted format using a standard cryptographic algorithm. There are several storage security vendors offering encryption of stored data e.g. Neoscale, Decru, Ingrian and Vormetric. One of the complexities of securing data over extended periods (i.e. years) is the issue of key management. Vendors need to provide easy and secure ways to store and retrieve the encryption keys, while the stored data goes through company reorganizations and changes of system administrators.

The integrity of the stored information can also be assured by implementing hash schemes using digital signatures. The hash digest is stored and compared from time to time with new hashes to verify if there has been unauthorized modification of data. Tripwire offers such a solution.

So, if you feel you have sensitive information stored in your storage devices, you should first develop and implement a security policy that addresses the above exposures. While evaluating storage security technologies or products for the above:

1. Understand how the encryption keys are managed, so you can retrieve your original data at anytime over next 5-7 years.

2. Ensure that you can secure your primary storage as well as backup (tapes, etc.).

3. Determine if you can also ensure integrity of data, with or without data encryption.


For more information on storage security such as encryption and data flight, check out Vijay's Ask the Expert category on SearchStorage.com.

For more information on HIPAA, visit Kevin Beaver's Ask the Expert category on SearchSecurity.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Security Audit, Compliance and Standards,   HIPAA,   Enterprise Data Protection,   Disk Encryption and File Encryption,   Application and Platform Security,   Database Security Management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Security Tactics
Screencast: Find rogue wireless acess points with Vistumbler
How to prepare for a secure network hardware upgrade
Preventing SQL injection attacks: A network admin's perspective
Screencast: How to launch an OpenVAS scan
Wireless network guidelines for PCI DSS compliance
Aligning network security with business priorities
Scanning with N-Stalker offers basic Web application security assessment
Lifecycle of a network security vulnerability
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Network access control technology: Over-hyped or underused?

HIPAA
Cost of security, IT management add up at healthcare facilities, study finds
Healthcare security spending remains sluggish, report shows
Creating a HIPAA employee training program
FTC extends breach notification to Web-based health repositories
Are there guidelines to create a HIPAA-compliant data center?
HHS HIPAA guidance on encryption requirements and data destruction
Writing a patient identifier policy to prevent common HIPAA violations
HIPAA compliance: New regulations change the game
HIPAA compliance manual: Training, audit and requirement checklist
Key elements of a HIPAA compliance checklist
HIPAA Research

Disk Encryption and File Encryption
Health Net healthcare data breach affects1.5 million
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Should developers create libraries of common cryptographic algorithms?
What is an encryption collision?
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
Voltage, RSA spar over tokenization, data protection
Truth, lies and fiction about encryption
What are new and commonly used public-key cryptography algorithms?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Advanced Encryption Standard  (SearchSecurity.com)
data key  (SearchSecurity.com)
Encrypting File System  (SearchSecurity.com)
encryption  (SearchSecurity.com)
Escrowed Encryption Standard  (SearchSecurity.com)
network encryption  (SearchSecurity.com)
output feedback  (SearchSecurity.com)
Quiz: Cryptography  (SearchSecurity.com)
Rijndael  (SearchSecurity.com)
Twofish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts