May-June 2016ENTERPRISE SECURITY| | 9using encryption tools. If not, delete the file(s). The next step is to consolidate all of the sensitive data files you find. There are all sorts of options such as private or public cloud services, offline storage, and column encryption of database records.Data owners (trustees) or their designees determine who has permission to access data types. Data owners (trustees) should be C-level, VP or director level employees and be familiar with the protection requirements applied to their data. Some examples of Data Owners and the data they manage are:· Chief Financial Officer (CFO) all company financial data· VP of Human Resources (HR) all company HR data· A sample approval process might look something like this.· A business unit purchases a software payroll application that needs to access the company's financial and HR data.The IT Security Office evaluates the security of the application using vendor security questionnaires, application vulnerability scanning, and interviews. The office prepares a recommendation for the data ownerThe data owner uses the ITSO recommendations along with other information in order to approve or deny access to the HR and financial data.Encryption technologies are an example of protecting the sensitive data elements. There are a wide variety of commercial and freeware encryption tools ranging from Veracrypt, built-in Microsoft Office Encryption, Acrobat PDF encryption, Microsoft Rights Management System (RMS), Varonis, etc. Encryption solutions can become complicated if your sensitive data needs to be sent outside of your organization. In this case, you need to find a solution that will work in two very distinct environments.A continuous monitoring defense strategy that tracks outbound traffic from your network is a very effective way to respond to data exfiltration. Determine which business processes handle sensitive data and find out where and how they send this data within and outside of your network. Profiling this traffic and its destinations is a good first step in the continuous monitoring process. IT threat intelligence services are an example of helping you identify potentially hazardous (to your company's health) data traffic. Remember any traffic (encrypted or not) bound for known suspicious domains is bad and should be interrupted as soon as possible. I've described a few examples of a general sensitive data protection process. A more rigorous and auditable approach is to use the Center for Internet Security (CIS)'s 20 Critical Controls as an operational plan for implementing your sensitive data protection strategy. These controls map to well-known security frameworks and standards. Some of the controls that would apply to the steps mentioned in this article include:Control 1 inventory of authorized and unauthorized devicesControl 2 inventory of authorized and unauthorized softwareControl 5 controlled use of administrative privilegesControl 13 data protectionControl 16 account monitoring and controlControl 18 application software securityRemember, you can't protect what you can't find. Data owners determine the access to data under their control with the IT Security office providing technical recommendations. The security office should not be the final arbiter of who has access to data. ESRandy Marchany A continuous monitoring defense strategy that tracks outbound traffic from your network is a very effective way to respond to data exfiltration
<
Page 8 |
Page 10 >