| | May-June 2016ENTERPRISE SECURITY8| | October 2016ENTERPRISE SECURITY8Sensitive Data Protection Processes--A Key to IT SecurityBy Randy Marchany, CISO, Virginia Tech IT Security Officene of the common mistakes organizations make is to focus on the technologies rather than protecting the organization's sensitive data. Certainly, protecting devices is a necessary task but it's the data that counts. There are no device breach notification laws. There are a lot of data breach notification laws so it's only logical that organizations focus on data security first. General steps for handling sensitive data management include: · Identifying data types that are protected by criminal, civil, regulatory laws· Locating where these data files are stored · Identifying the data owner who controls access to that data· Protecting the data using business process and technologyMonitoring all traffic involving sensitive data especially outbound trafficLet's examine each of these steps. We start with identifying the data types that are protected by laws and/or regulations. A good place to start is with your state's data breach notification law(s). For example, the Commonwealth of Virginia's data breach notification law (COVA Title 18.2-186.6) identifies the following as personal information that requires notification if exposed inappropriately:"Personal information" means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of the Commonwealth, when the data elements are neither encrypted nor redacted:1. Social security number;2. Driver's license number or state identification card number issued in lieu of a driver's license number; or3. Financial account number, or credit card or debit card number, in combination with any required security code, access code, or password that would permit access to a resident's financial accounts.The term does not include information that is lawfully obtained from publicly available information, or from federal, state, or local government records lawfully made available to the general public.Our organization has a standard that basically says any file including databases that contains social security number, credit card number, passport number, driver's license number, bank or credit account numbers that must be encrypted at rest or in transit. Regulatory laws describe specific security practices for data types such as credit cards (PCI), student records (FERPA), and classified research (ITAR). If any of your data falls under these or other regulatory umbrellas, you have additional requirements governing the storage and transmission of these data types.The next step is to find where these data types are located in your organization. There are commercial and freeware tools that can help you in this search. Commercial products such as Spirion formerly IdentityFinder, Varonis, Digital Island and freeware products such as Find_SSNs can be used to find files on computers that contain sensitive information. This is a very complex task and can surprise you with where such data is located. Individuals tend to be "digital packrats" because they tend to never delete files on the belief that "I might need it later". Pretty soon, files that are over 10 years old may be found on company desktops. Once found, you should ask "do you still need to use this (these) file(s) for your job?" If so, protect the file OIN MY OPINION
<
Page 7 |
Page 9 >