Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Methodical Attacks on SSH | Main | Who's Afraid of Virginia's Smartphone? »

Preventing Data Loss "Accidents"

Encryption is like a door lock, it's only useful when it is engaged. A story about a data loss incident at State Street brings this message home.

SearchFinancialSecurity reports that a contractor lost a disk with information about 5,500 employees and 40,000 customer accounts. The data had been encrypted but was decrypted to analyze it. It was not encrypted again after the analysis.

"The devil is in the details of implementation with crypto, where a poor implementation of a good algorithm gives a false sense of security and it's potentially worse than not using encryption at all," [Scott] Crawford [an analyst with Enterprise Management Associates] said. "Even when experts are involved, the processes can be a killer."

Encrypting is like wearing a seat belt. You don't expect to need it every time you use it but you get into the habit of using it every time just in case. Maybe we need YouTube videos with something analogous to crash test dummies flying through a windshield. It's hard to get the graphic impact with data loss prevention than you can with other industrial accidents. The Canadian Workplace Safety and Insurance Board has come up with some graphic videos (as in horror movie graphic) for its worker safety campaign, The ads are designed to shock us into understanding there are no "accidents", our actions and inactions are the problem. We could use something like that to get the message out about IT security.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/748

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net