Showing posts with label DLP. Show all posts
Showing posts with label DLP. Show all posts

Monday, January 16, 2012

Data – The Ultimate Asset

Traditionally, business has looked at land, plant, building, machinery as assets that need to be protected and security thoughts have focused on fortification of the perimeter surrounding the assets. Business was about manufacturing, trading, services and then came the technology age... and life changed. Or did it ?



Unfortunately, businesses transposed traditional experiences into the technology realm thinking that firewalls, anti virus solutions, IDS/IPS and server hardening will protect the perimeter and life will continue securely. Computers became assets, but not data and it has taken a long time for businesses to realize their folly. While mature organizations have taken adequately appropriate steps, a majority continue to give lip service to their data assets.


And therein lies the error of judgment – it is easier to buy a new plant than to make sense of a thousand files with unstructured data. Data is the ultimate asset in the technology age and the dependency on IT systems is growing exponentially. At work we grapple with more information (data) than we can handle and one hoards relevant and irrelevant data. The data which we work on grows into multiple copies across the organization and, whether one likes it or not, dependency on data is absolute.


Business organizations, or individuals, cannot survive in event of non availability or loss of data and must accept that data is their most critical asset. It is essential to enable data security and manage this asset throughout the lifecycle using technologies that enable real time proactive protection.


Data security is critical for business in the manner that


• Confidentiality is maintained and data is not exposed, leaked, lost, stolen or compromised
• Integrity of data is assured and users know that it is not tampered
• And it is available at all times for uninterrupted business operations


Technologies like Security Incident and Event Management (SIEM), Data Loss Prevention (DLP), Information Rights Management (IRM) when deployed together in any organization, provide a high level of protection to the data assets and the organization has control on their assets while inside and outside their infrastructure perimeter. The SIEM will help monitor the network and alert against malicious activity, the DLP system will lock down assets from inappropriate access or transmission and the IRM system will provide the ability to remotely control document access rights.

Saturday, July 2, 2011

Forget DLP, think PLD - the Professional Loser of Data


DLP is the technology of choice when it comes to data protection. However in the past few months we are seeing a plethora of incidents which show the presence of antibodies in the system. 


Antibodies or bacteria in an environment protected by DLP are PLD's. A PLD is a Professional Loser of Data and I am not surprised that most of the PLDs are in Government. Or in high places. 


Take for instance the Adarsh scam - no sooner they started talking of big names that files started disappearing. The files in the Navy, Mantralaya, Mumbai Municipal Corp and the Environment Ministry have all been lost. 


Then we had the CWG scam and saw more PLD action. At first the government supported Mr K by allowing him to continue being tje boss and let loose his PLDs. Well these PLDs did a good job and we read abouyt missing files :)


Radia tapes and  Wikileaks are great examples of big time PLDs at work. 


The latest PLD operation, shockingly, or should I say expectedly, was the enabling the loss of files relating to the Gujarat riots by the Gujarat government. The PLDs did this four years back and it has come to light in an RTI application. And the Gujarat riots are still under investigation ! This just shows the professional capability of the people in power, the PLDs, who were likely to be screwed. The government cites data retention timeframe as the reason why the documents were destroyed saying all actions were taken strictly by the book. 


Now, as I write about this, I wonder why the CBI did not discover the loss of documents when they were arresting Minister Shah. Or maybe one should not be surprised considering the recent incidents where they have thrown cases. 


So, as information security professionals, when we go to plug data leaks and consider insider risks we usually think about disgruntled employee or accidents. It is time to think about the bacteria, the antibody - the PLD. And remember no DLP system will be able to detect or control this guy's action.