Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, March 20, 2009

A Security Experts Guide to Web 2.0 Security

Written by Roger Thornton & Jennifer Bayuk

Web 2.0 has made the Web a livelier and friendlier place, with social Web sites, wikis, blogs, mashups and interactive services that are fun as well as useful. There are two Web 2.0 concepts that change the game for CISOs, and that they need to understand.

The first is the introduction of rich client interfaces (AJAX, Adobe/Flex) while the other is a shift to community controlled content as opposed to publisher consumer model. Both have serious security issues.

It’s all good news about Web 2.0, right?

Yes, unless you happen to be responsible for securing the Web 2.0 environment for your business or enterprise. Then, you might just lament that we’ve taken the data-rich server model of the 1970’s and grafted it onto the interface-rich client model of the 1980’s and 90’s, giving us more capabilities but also a more complex—and vulnerable—computing environment.

We have to deal with the problems traditionally encountered using interface-rich clients—viruses, Trojans, man in the middle attacks, eavesdropping, replay attacks, rogue servers and others. And all of these apply to every interface in a Web 2.0 mashup, which could have dozens of clients in one application.

In addition, the user community has changed from being simply indifferent to being willfully ignorant of the value of information. Users willingly post the most revealing details about their employers and their professional lives (not to mention their personal lives) on MySpace, Facebook, LinkedIn and Twitter—information that is easily available to just about anyone.

The problem is painfully obvious for the security professional: More complexity and openness creates vulnerabilities and opportunities for attack and the release of confidential information. This all results in more headaches for security professionals who have to be vigilant in order to keep their IT environments secure.

What’s a CISO to do?
Although some companies have tried all options, you can’t easily write your own browser, isolate your users from the Web, or control everything that happens on their PC desktop. However, there are steps you can take that can seriously improve your odds of winning the battle over Web 2.0 vulnerabilities.

For community controlled content:
1. Educate yourself and your company, developers, vendors and end users about Web 2.0 vulnerabilities. Institute a clearing process for the use and inventory of new Web 2.0 components before they are incorporated into your business environment.
2. Segregate users’ network access for those who need and those who don’t need access to social networking sites.
3. Establish a policy identifying inappropriate professional topics for public discussion on the Web or through online social services.
4. Create desktop policies and filters that block, as much as possible, interactions with unknown and untested software.

When deploying rich client interfaces:
5. Assign a cross-functional team to work with software development and application owners to educate themselves on the risks of incorporating Web 2.0 components into applications. Have your own developers recognize and control the use of potentially vulnerable tools such as ActiveX and JavaScript.
6. Require your vendors to meet secure coding standards.
7. Vigorously stay on top of vulnerabilities and exploits. Use your Web 2.0 inventory to establish a quick response plan to mitigate software as issues arise.

Thursday, March 19, 2009

Top Ten Data Security Best Practices

Written by Gordon Rapkin

1: Don’t narrow security focus during economic downturns
When IT budgets are slashed it’s tempting to concentrate only on achieving compliance with regulatory requirements in order to avoid fines, other sanctions and bad publicity.

The problem is that centring security solely on meeting the bare minimums required to be in compliance ensures that critical data is not secured as comprehensively as it should be. Gambling with data security in a downturn is a particularly risky business -- financial pressures logically lead to an increased threat level from those who are hoping to profit from purloined data. Companies should, even in difficult times, work towards comprehensive security rather than simple compliance with regulations.


2: Have a clear picture of enterprise data flow and usage
You can't protect data if you don't know where it is. Comprehensive audits typically reveal sensitive personal data tucked away in places that you’d never expect to find it, unprotected in applications and databases across the network. Conduct a full audit of the entire system and identify all the points and places where sensitive data is processed and stored. Only after you know where the data goes and lives, can you can develop a plan to protect it. The plan should address such issues as data retention and disposal, user access, encryption and auditing.

3: Know your data
If the enterprise doesn’t classify data according to its sensitivity and its worth to the organisation it’s likely that too much money is being spent on securing non-critical data. Conduct a data asset valuation considering a variety of criteria including regulatory compliance mandates, application utilisation, access frequency, update cost and competitive vulnerability to arrive at both a value for the data and a ratio for determining appropriate security costs. Specifically gauge the risk associated with employees and how they use the data. If staff are on a minimum wage, transient and/or have low security awareness, the data may be worth more than their pay, so the risk goes up.

Usage also impacts on the level of security required. If the data only exists on isolated systems behind many layers of access control, then the risk may be lower and the security may be more modulated.

4: Encrypt data end-to-end
Best practices dictate that we protect sensitive data at the point of capture, as it's transferred over any network (including internal networks) and when it is at rest. Malicious hackers won’t restrict themselves to attacking only data at rest, they’re quite happy to intercept information at the point of collection, or anywhere in its travels. The sooner encryption of data occurs, the more secure the environment.

5: Regulation is not a substitute for education
Technology controls should certainly be in place to prevent employees from intentionally or mistakenly misusing data. But it’s important that everyone understands the reasons for the data protection measures which are in place. One of the most positive steps an enterprise can make is to institute ongoing security awareness training for all employees to ensure that they understand how to identify confidential information, the importance of protecting data and systems, acceptable use of system resources, email, the company's security policies and procedures, and how to spot scams. People who understand the importance of protecting data and who are given the tools that help them to do so are a great line of defence against malicious hackers. The other side of this coin is that people will always find a way to thwart security measures that they don't understand, or that impact negatively on their productivity.

6: Unify processes and policies
Disparate data protection projects, whether created by design or due to company mergers, almost always result in a hodge-podge of secured and unsecured systems, with some data on some systems encrypted and some not, some systems regularly purged of old data on a monthly basis and others harbouring customer information that should have been deleted years ago. If this is the case within your enterprise, consider developing an enterprise-wide unified plan to manage sensitive data assets with the technologies, policies and procedures that suit the enterprise’s business needs and enable compliance with applicable regulations and standards.

7: Partner responsibility
Virtually all data protection and privacy regulations state that firms can’t share the risk of compliance, which means that if your outsourcing partner fails to protect your company's data, your company is at fault and is liable for any associated penalties or legal actions that might arise from the exposure of that data. Laws concerning data privacy and security vary internationally. To lessen the chance of sensitive data being exposed deliberately or by mistake, you must ensure that the company you are partnering with — offshore or domestic — takes data security seriously and fully understands the regulations that affect your business.

8: Audit selectively
Auditing shouldn’t be a huge data dump of every possible bit of information. To be useful it should be selective. Selective, granular auditing saves time and reduces performance concerns by focusing on sensitive data only. Ideally, the logs should focus on the most useful information for security managers; that is, activity around protected information. Limiting the accumulation of audit logs in this way helps to ensure that all critical security events will be reviewed.

9: Consider physical security
It seems that every week we hear about the laptop that was left behind in a cab, the DVD disks that were found in the rubbish, the unencrypted backup tapes that showed up sans degaussing for sale on eBay, the flash drive that was used to steal thousands of documents, etc. Doors that lock are as important to security as threat intrusion software. Always consider 'what if this ______ was stolen?' No matter how you fill in the blank, the question elicits a strategy for physical security.

10: Devise value-based data retention policies
Retaining sensitive data can be very valuable for analytic, marketing and relationship purposes, provided it is retained in a secure manner. Make sure that stored data is really being used in a way that brings real benefits to your organisation. The more data you save, the more data you have to protect. If securely storing data is costing more than its value to your organisation, it's time to refine your data retention policy.

Friday, March 6, 2009

Cyber warfare – how secure are your communications?

Written by Mike Simms

Almost every week the media reports on negligent loss of data, much of it highly sensitive. Perhaps with so many people using so much data in so many different places we should not be so surprised.

Today more and more organizations – emergency services, government departments and financial institutions – hold information nationally and access it nationally, and, in some cases, offshore it.

There is relatively little offshoring of information by government. But corporate organizations, credit helpdesks and so on hold their customer relations management overseas.

They share information over the web with a vast number of IT systems and databases. It is almost impossible for anyone to know on what scale this information is accessible.

The aggregation of information, in itself, escalates the level of sensitivity. So there is greater risk of abuse or corruption, either intended or accidental, as in the loss of the child benefit database last year.

Unfortunately, shared technology increases risk, and criminals and vandals are using this same technology to remotely attack data systems. These attacks can be very successful, and by their nature make the deterrent of legal action more difficult.

We are faced with different threat levels to network-based information systems. These range from the careless user who leaves a disc on a train to foreign intelligence services who engage in cyber warfare against perceived enemies.

An example of the latter centres on the Russian incursion into Georgia in response, they said, to Georgia’s attack on the breakaway republic of South Ossetia. In the weeks leading up to this, Russia had disabled the Georgian president’s website with a massive spam attack – what is known in the trade as a ‘denial of service attack.’

So in the quest to satisfy the network-enabled world’s increasing demand for effective data protection, the first step is an accurate assessment of risk.

At the lowest level, but the most common source of threat, are the millions of users themselves. They might lose a data stick, leave a laptop on public transport, or write their password on a Post-it note and stick it on their computer screen!

Next up are the service providers. With outsourcing on the rise you need to be confident your service providers conduct rigorous processes in how they look after their networks and information.

Higher still are the amateur hackers, of which there are many, although they are opportunistic and immediately they hit a firewall will probably move on.

At the pinnacle of threat are sophisticated hackers who are often linked to criminal gangs, and foreign intelligence services. These may be relatively few in number – but they have a lot of resources behind them, and therefore need correspondingly greater efforts to fight them.

Assessing the appropriate level of response for each of these threats is therefore the starting point to resolving the problem. There is no point in overkill, locking down systems so tightly that it imposes on the system’s usability if the information it contains is fairly innocuous.

When it comes to protecting our data many of us, it seems, are still stuck in the Dark Ages. People think IT protection is just about the computer. It is not the computer but the system it is running on that is most vulnerable. We now need to concentrate on how to secure information as it is being transported across networks.

Putting all the necessary protection into computers would be expensive, so making sure that computers can operate on secure and trusted networks is important because of the way we work today, using laptops, working away from the office, all done over public networks.

In Britain, sophisticated information assurance services are being developed which span cryptography, computer network defence, intruder detection and business continuity.

Computer network defence is the front line of cyber warfare. For some clients such as government, banks and financial institutions this means real time 24/7 activities manned by people in special trusted locations, and constant updating of threats.

It is vital to know what level of protection you need. But however good your information assurance is, if someone else has not taken adequate steps they are the weak link and your data is vulnerable because of them. In this network-enabled world we all depend on each other as never before.

Friday, February 27, 2009

Making the Best Use of Your Security Budget in Lean Times: Four Approaches

Written by Elizabeth Ireland

Many predict 2009 will produce the tightest economic conditions in decades. The subprime meltdown, tight credit markets and recession conditions will mean most CIOs will feel the downward spiral of the economy right where it hurts -- in their IT budgets.

Unfortunately, this also coincides with the most serious threat environment security professionals have faced. Hackers’ tactics are becoming more targeted. The increase in the number and business importance of web applications is generating additional enterprise risk. Budgets may get tight, but your responsibility remains the same: minimize risk.

It’s a tall order in the face of possible spending cutbacks, but because budgets are tight, you have to be focused on how to best reduce risk, and it definitely doesn’t mean less attention on security. In fact, at times like these, that may be the biggest mistake. The highest levels of an organization are asking their CIOs “how do we know we’re secure?” The only way you will know that is by understanding the risks, better understanding the ROI, and how it fits into not only your other IT priorities, but also adds to the company’s bottom line. Defending the security budget is always a challenge, but here are four approaches that can help.

1. Metrics make the most compelling argument. Ask yourself this question: Is your security risk going up or down over time and what is impacting it? This is baseline data that every organization needs and should be on track to monitor. If you cannot answer this clearly, realign your projects and priorities to make sure you can get this information on an ongoing basis. Every CIO should know at least three things: how vulnerable are my systems, how safely configured are my systems, and are we prioritizing the security of the highest value assets to the business? Though security metrics are in the early days of development and adoption, the industry is maturing and solid measurements are available. These areas can be assessed and assigned an objective numeric score, allowing you to set your company’s own risk tolerance and use that to make critical decisions about where to allocate funds. As you face increased budget scrutiny, the metrics allow you to identify – and defend as necessary-- where your security priorities are, and how security and risk fit into overall ROI.

2. Compare your baseline to others in your industry. The guarded nature of security data means CIOs trying to access this type of information will have to get creative. A good place to start is the Center for Internet Security -- their consensus baseline configurations can be used as a jumping off point to identify areas of risk. Vertical industry benchmarks will be an evolving area, and another source may be what you can learn from your personal relationships. Seek out others within your industry and find out what metrics they are using and what they are spending as a percentage of their IT budget. Risk tolerance is specific to each organization, but there are similarities within industries that could prove to be helpful.

3. Learn from other areas in your company. Many process-oriented disciplines can be a good area as a proxy for the type of evolution facing security; network operations are a good example. In the early days of network operations, the only scrutiny came if things weren’t working correctly. Over the years, it has matured to a level of operational metrics for uptime and performance, and is embedded in quarterly and annual performance goals. These metrics allow a continuous cycle of performance, measurement and improvement. In addition, network operations can provide an important lesson of single solution economies of scale. Find solutions that work across your entire enterprise—this is the only way to get economies of scale in implementation and ensure you get the critical enterprise-wide risk information that can deliver the metrics you need.

4. Take steps to automate your compliance process. Are you compliant and can you routinely deliver the reports that auditors request? The economic benefits that come from doing this correctly are significant. Audit costs are directly related to how complicated it is to audit and prove the integrity of a business process, so finding a way to save the auditors’ time is one of the single biggest opportunities to drive down costs. Even though your audit costs may be hitting the finance area’s budget, meet with your company’s finance team to understand what audits are costing you, and how the right kind of automation could lessen them and there will certainly be time and resource savings for the security team as well. There isn’t an exact recipe for compliance automation, so talk to your auditors, look at your environment, and begin the discovery of how much time is spent preparing for and reacting to audits. If you’re a company that allows your divisions to individually automate, it’s time to think about taking those principles enterprise-wide.

Regardless of budget conditions, you will still be faced with decisions on which projects have the biggest impact on the business. The threat environment requires that you make the absolute best decisions with your available budget by investing in the right places and getting better use of your resources. Lastly, remember that times of difficulty are often the times of opportunity. Lessons learned now in the face of tighter budgets can spark valuable models of efficiency and progress for the future.

Thursday, January 22, 2009

Security - The Human Factor

Written by Paul Kearney

Much can be learned from history. Take, for example, the Trojan Horse – a contraption that was received as a gift during the siege of Troy but actually contained enemy soldiers. The trick worked for the invaders because the defenders let their greed and curiosity overcomes their caution.

Much can be learned from history. Take, for example, the Trojan Horse – a contraption that was received as a gift during the siege of Troy but actually contained enemy soldiers. The trick worked for the invaders because the defenders let their greed and curiosity overcomes their caution.

And then there was Archimedes – the man employed 200 years BC to produce a machine that could defeat the Romans by smashing their siege ladders as they placed them against the huge city walls of Syracuse. The solution worked for a while until the citizens became over confident and dropped their guard.

In both cases, it wasn’t the failure of the defences that led to defeat but the gullibility, naivety and complacency of the people who trusted them.

Winding on 2000 years or so, machines still challenge the vulnerabilities of organizations and it’s some how appropriate that ‘Trojan’ has become the term used to describe one of today’s most feared types of computer malware.

Other threats include ‘phishing’ (where an e-mail message appears to be from a well-known and trusted organization but isn’t), hacking, electronic fraud, electronic burglary using tiny USB devices, and the physical loss or theft of computer hardware – particularly laptops.
But regardless of the methods used, the real threat isn’t technology, but the human beings that mastermind the attack.

No organization is immune from their attentions – in fact, the bigger the organization, the more likely it is to attract criminals and pranksters driven by the buzz of seeing the results of their handiwork in media headlines.

Massive impact
The consequences of cyber attacks are significant, of course. Security breaches can have a massive impact on an organization’s bottom line. The authoritative Information Security Breaches Survey says the worst incidents currently cost large businesses (with between 250 and 499 employees) between £90,000 and £170,000 ($108,000 and $205,000) and very large businesses (employing 500 or more) between £1 million and £2 million ($1.2 million and 2.2 million).

And cases of security breaches are legion. CDs containing personal data on about seven million families were lost in transit from Her Majesty’s Revenue and Customs (HMRC) and another government department, and the Driver and Vehicle Licensing Agency mislaid a vast quantity of driving and vehicle licence details. A laptop containing sensitive defence data was stolen from the boot of a car in London and millions of customers in Britain and America were claimed to be at risk after credit and debit card records were stolen from retailer TJX’s computer systems. A former informant of the US secret service has been accused of the latter crime, thought to be America’s biggest and most complex case of identity theft.

The list goes on and there’s a constant battle between security professionals and cyber-criminals – organised or merely opportunist – who can find an outlet for data.

Security professionals, however, are often technologists, so their instinct is to look to technical solutions. Unfortunately, if they aren’t designed well, people will make mistakes in using them or just give up on them entirely. And if they aren’t efficient, they can end up hindering the progress of the tasks they are supposed to protect.
There are even security specialists who believe that IT users are merely a nuisance and regard their colleagues as ‘vulnerabilities’ against which their systems must be protected using rigid rules and procedures. This ‘command and control’ mentality can result in unnecessary restrictions on employees going about their work with the perverse effect of reducing security as staff try to find ways around the blocks in their path.

Human characteristics can create weaknesses and loopholes criminals can exploit. Consider people’s natural desire to be helpful, for instance. If an outsider claims to be a colleague wanting help with something, individuals are inclined to help, opening the doors of their fortress as a result. They are just too trusting – unaware of the tricks that people can, and will, get up to. And even security professionals can easily fall into that trap.

Typically somebody rings a helpdesk to say that they are working away and really need to prepare something for an important meeting but have forgotten their password. Impassioned pleas like this can all too often result in passwords being given away.

Con trick
Such tactics are known as ‘social engineering’ but they are merely a new take on an old-fashioned con trick.

Another example on a more physical security level involves people putting on overalls and carrying a clipboard to blag themselves into buildings. Employees just assume they are members of the maintenance team – people who know what they’re doing. And if you look the part, you can get access to all sorts of things…

Some companies employ people who do such things on a ‘white hat’ basis – white hat being an analogy to the old cowboy films where the villain wears a black hat while the sheriff wears a white one. So a ‘white hat hacker’ is somebody who has the skills of a hacker but who is employed to identify vulnerabilities – a typical poacher turned gamekeeper.

We should be designing systems that make best use of the complementary characteristics of people and technology to strengthen security. Computers don’t get tired, and can prevent people making mistakes. But they only do what they are programmed to do, and that may not be enough. Humans tire more readily, exposing themselves to attack. But if they think something odd is going on that they don’t understand, they can use their common sense and report it.

However, there is a potential conflict of interest between productivity and security – if you’re in a rush and working to a deadline you might be tempted to circumvent security measures. Indeed, management can make this worse through productivity and sales incentives.

Organizations need to motivate and educate their employees so that they see security as part of their job and to understand why they are being asked to adopt certain behaviours rather than just being able to ‘tick the box’.

People – asset or vulnerability?
This approach is endorsed in the latest information security breaches survey carried out by PricewaterhouseCoopers for the UK’s Department for Business Enterprise and Regulatory Reform (BERR).

Their report states: “Companies increasingly realise that their people, while their greatest asset, can be their greatest vulnerability and so need to be educated on security risks.”

The survey discovered that more than half of the UK companies screened had not carried out a formal security risk assessment and that 67 per cent did nothing to prevent confidential data leaving their premises on devices such as USB sticks.

Broader research by the European Network Information Security Agency (ENISA) has warned that increased cyber-criminal activity is threatening the economic interests of the EU. The agency has called upon industry to collaborate to make the Internet a safer place to do business globally.

Given that people within an organization can be the weakest link in terms of security, what can be done?
Education is a good start but so is a new approach within IT departments to make software much easier to use securely and a better understanding of human factors rather than total reliance on technology.

There are plenty of academics who specialise in human factors and human computer interactions and some companies have specialist labs that test systems for usability characteristics. But they are mainly aimed at functional features – making things easier to use – rather than the usability of security.

International standards such as ISO 27001 play a part too and lay down technical controls covering such things as usernames and passwords. But only one out of 133 controls covers human issues. In any event, 79 per cent of companies contacted for the BERR survey were unaware of the standard.

Best practice
Standards apart, there’s a need to achieve best practice in terms of user interface design and human factors to maximise security. Enterprises must take responsibility for these issues – it is in their own interests to share knowledge and work together to improve things.

Another positive move would be to embrace the mandatory incident reporting procedures that are commonplace in the aviation industry. Because these highlight not just actual accidents but near-misses, they provide a more accurate view of the situation – one that provides a sounder basis for future security decisions. California, for example, has made it mandatory for companies to report losses of personal information.

Unless action is taken on the human factors of security, the public’s confidence in e-commerce and anything else beginning with ‘e’ will be lost. If something isn’t done quickly, it could be a case of closing the stable door after the Trojan Horse has bolted.

Wednesday, January 21, 2009

Data Protection Basics

Written by Tsvetanka Stoyanova

Data protection is a vast topic because data and the adequate measures to safeguard it against the many threats are fundamental for any IT department. Failing to provide adequate data protection is not only unprofessional; it could be a criminal act and could lead to serious damage for the affected parties and severe penalties for the parties at fault.

There are many Acts and laws, for instance the Data Protection Act of March 2000 or the Sarbanes-Oxley Act. The Sarbanes Act not only makes it highly desirable for a data center or an IT department to take data protection seriously but if you are not serious then sanctions are applied for non-compliance.

There are many reports of leaked data - not to mention the number of cases, which are not reported publicly. Data leakage is very often the result of inadequate protection and this certainly poses the question, should IT pros be responsible of ensuring the adequate protection for the data they are responsible for.

Nobody says data protection is easy. You can never be 100% certain that your data is protected and even if you make every reasonable effort to protect data, there is no guarantee that trouble will not haunt you. But when fundamental data protection rules are violated, the question is not if but when a failure will happen.

Types of Threats for Data
Before you start thinking of ways to protect data, it is essential to know what you are protecting it against. There aren't many types of threats and the degree they can destroy or damage data varies.

Basically, one classification of threats is into internal and external threats. Depending on the type of damage, there are two groups of risks:
• Physical damage. Data can be easily destroyed on deliberately or not and all this could happen in a blink of a second. Natural disasters such as fire, flood, earthquakes, etc. can damage the media on which data is kept, thus destroying it. Accidental or on deliberate data deletion is another physical threat you should provide against.
• Unauthorized access. Physical threats are dangerous but unauthorized data access is not better. Unauthorized access could destroy your data physically but this is not the worst that can happen. When data is accessed by unauthorized individuals, the damage they can do could vary – i.e. disclosure/leakage of sensitive information or modification are just a few examples. The worst is that illegitimate modification could be done by somebody who has legitimate access.

Basically all mishaps to data fall into one of the above categories and there are various measures one can take in order to prevent such events from happening. The following section mentions only some of the most important steps in that direction.

How to Protect Data against Threats
Data is tangible but yet you can't guard it with the same measures as you guard your other physical assets, though certainly some of the rules apply. For instance, while you can insure your cars and other property against theft or fire, you can't insure data against these events but you can make your best to prevent theft or fire and to minimize the damages, if these events occur. Here are some very basic recommendations how to protect the data you are responsible for:

• Physical protection. The response to the physical damage threat is physical protection. As in the OSI model, where networking starts at the physical level, data protection starts with its physical protection. This includes steps such as securing your premises against fire, flood, unauthorized access by external individuals, checking the media you backup on, etc.

• Rules for access to data. When you have rigorous procedures for external access, this minimizes one common threat but still there is more to regulating access. You must secure data along the whole path – from collection, to transit, to reaching its final destination. But even when data is inside the walls of your data center, this still does not mean that it is protected from unauthorized access. Poor corporate security is no guard against unauthorized access. Insider theft is even more common. So, if you don't have rules regarding the access to data and the means to enforce them (i.e. authentication, encryption, granting legitimate access, etc.) you can never consider the job done.

Access rights include all the operations one can perform with data – from gaining read-only access, to modifications, to deletion. Here the most secure rule is to use the least privilege principle – i.e. give a user the minimum rights he or she needs to have in order to be able to do his or her work. Additionally, limit to the minimum the number of people who have access to critical data because if an insider attack happens, it will be easier to narrow down the possible sources of the leakage.

• Intrusion detection, firewalls, malware, etc. I think it is needless to say that common security practices, such as intrusion detection, firewalls, malware scans, installing the latest patches, etc. must be performed on a 24x7 basis because it is just too obvious but let's briefly mention them – just for completeness of the list.
• Backups, disaster recovery. Backups and disaster recovery are also standard practices for data protection both on a physical level and for protection against modification/deletion. Backups and the techniques for disaster recovery allow to have a spare copy of the data, which you can use to restore data from in case it is physically destroyed or has been modified. Obviously, backups and disaster recovery won't help you against leakage and other forms of insider trading but still they have their indispensable place in the data center.
• Keep an eye on the legislation. As I mentioned in the beginning, there is quite a lot of legislation related to data protection. Sometimes the legislation itself will include mandatory provisions about the measures you need to apply in order to fulfill your legal duties, so keeping an eye on changes in the existing legislation and on any new Acts is compulsory.

The above steps are just a drop in the sea of measures, which are required in order to do your best to protect data. It might look very simple to protect data but the consequences of not doing it properly are certainly not simple and the most precise statement about data protection is that it is an ongoing battle with natural and man-made disasters.

Recent Posts