Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Smartphone Security Threatened by J2ME and Application Challenges | Main | Net Neutrality Finally Gets Attention »

Secure Data, Not Just Devices

Eric Lundquist's Security Shifts to Data is a good summary of some emerging themes about information security. We've understood for a while that the perimeter defenses are not sufficient. In fact, the whole concept of a network perimeter is loosing meaning as business partners and customers are reaching deeper into enterprise applications. We need to protect what's valuable and that's the data. TJX's problem isn't that attackers stole servers or used their devices as bots, the problem is stolen data.

Data loss prevention requires locking down devices but it also requires steps to protect data directly, beginning with encryption. And it's not just about technology, to rephrase James Carville, "It's the policy, stupid", or Lundquist put it:

Protecting data requires developing and deploying an overall company process. Before you try to fix data leakage, you have a lot of work to do. You need to figure out where all your data resides and set levels of protection depending on the degree of data importance. If you decide to encrypt data, you need to figure out how to handle encryption and decryption keys. Who should issue the keys, how long they should exist, ...
.

There is also the problem of mobile devices, which are still working out fundamental security issues, see an earlier post on the J2ME platform for examples. Lundquist also sees this as a key issue:

The move to protecting data instead of devices comes at a crucial time for companies. The power of mobile devices is rapidly increasing to the point where your laptop will appear underpowered compared with the handheld combination phone/e-mail/personal data device.
The development of those mobile devices also means that more confidential corporate data will be moving over more networks.

We need to secure devices to maintain availability and to keep them from being used by others (e.g. bots), but we need to keep data secure because that's the valuable stuff. Data is not tied to a single point in time and space, it moves around, it gets copied, and if it's accessible to a search engine crawler, it might even get indexed.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/223

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net