Free E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Security Resource Centre
Security
SYMANTEC
||
Endpoint Security
Data security a big focus in 2007

By: Jaikumar Vijayan
Computerworld (U.S. online)

Regulatory requirements and increasing consumer concerns about information security breaches are making data-level security controls a top priority for 2007, according to IT managers at the Computer Security Institute (CSI) trade show in Orlando held in November.

After years of implementing technologies such as firewalls and intrusion detection systems to keep network perimeters safe, companies now must move similar controls down to the data level, they said.

"The data now matters above everything else," said John Ceraolo, director of information security for JM Family Enterprises Inc., a US$9.4 billion auto distribution and financing company based in Deerfield Beach, Fla.

Non-public information of all sorts needs to be protected, whether it is at rest or in transit, he said. And that requires an increasing focus on measures such as data classification and encryption, stronger user access and authentication and usage monitoring and auditing, Ceraolo said.

Most "blocking and tackling" that was needed to handle network threats has, to a large extent, already been accomplished via technologies such as firewalls, and intrusion detection and prevention systems, said Mark Burnett, director of IT security and compliance at Gaylord Entertainment Co. in Nashville.

The goal now is to put multi-layered defenses around the data as well, he said. "We are layering technology controls to make sure we can identify where the information is passing across our network" and protect it.

"The overall driving force behind our [security] program is reputation management. We have worked hard to build the Gaylord brand," he said. "Any one incident could ruin all that work."

Also driving the focus are regulations that Gaylord is required to comply with such as the Payment Card Industry (PCI) data security standard mandated by the major credit card companies and Sarbanes-Oxley, he said. "We absolutely recognize the need to protect sensitive information and are working hard to fulfill that obligation," he said.

Ann Garrett, the chief information security officer at the North Carolina state office of information technology in Raleigh, said that a new state law governing the use of personally identifiable information has elevated the need for security controls at the data level. The law went into effect for private industry on Oct. 1 and will apply to state agencies on Oct. 1, 2007.

"We have a strong network firewall, intrusion detection system and intrusion prevention system," Garrett said. What's lacking are controls for mitigating user errors at the end point, she said. As a result, there's an increased focus on data encryption - and on ways to log and audit user transactions.

"We have to add accountability and auditability" at the end point, she said. "There is a whole lot of emphasis on protecting personally identifiable information right now," Howard said during a panel discussion. "Congress, the Office of Management and Budget and Inspectors General are looking over our shoulders closely."

Howard's agency earlier this year disclosed that it had lost a back-up disk containing sensitive data on 757 current and former HUD employees. "We pulled back the sheet and discovered there is a lot to do" to protect personally identifiable data, Howard said.

HUD plans to have an implementation plan in place by the end of the year to address issues identified so far, he said. Among the planned measures are data encryption, two-factor authentication of users and the ability to more closely monitor user activity.

"There are so many vulnerabilities out there, there aren't enough hackers to take advantage of all of them," Howard said. So it's important to take a holistic risk-based approach to securing data and to understand that it's about "people, process and technology," he said.

More Resources
||
More Resources

Stay Informed
We're working on bringing you more info on Security.
Enter your e-mail address to be notified the moment new content is posted.
This email address will be used solely for the purpose of notifying the user when content is updated within the site. Please refer to our Privacy Policy for further information.

Featured Resource Paper
Symantec Internet Security Threat Report (July 1 - December 31, 2006)
Download this report now to discover the trends and methodologies underlying network attacks today. Understand how an increasing interoperability between diverse threats and methods can lead to networks being compromised and used in concert as global networks of malicious activity that support their own continued growth. Complimentary with registration.
IT Risk Management Report (Trends through December 2006)
IT Risk is a growing component of total Operational Risk. IT Risk Management, which includes security, availability, performance and compliance elements, each with its own drivers and capacity for harm, is emerging as a separate practice. This study examined IT Risk, along with the technology and process controls used to mitigate it, in a year-long study based on in-depth structured interviews with more than 500 IT professionals around the world.
E-Discovery and Electronic Document Retention in Canada
This paper is a guide to understanding the role of the IT department in the management of electronic documents and support of e-discovery, given new legislature described as "SOX for the CIO". Even without these changes, the issues related to how day-to-day document retention policies and practices affect the outcome of litigation, has become patently obvious at the board level. This will undoubtedly bring new interest to existing guidelines on e-discovery in Ontario and in Canada, as many Canadian companies must now consider these amendments as they do business in Canada, or are subject by contractual terms to US laws.
Symantec Enterprise Security ManagerTM for C-SOX:  Bill 198 and the Canadian Securities Administrators' Multilateral Instruments
The time to develop a plan of action for the Canadian rules on the Sarbanes-Oxley Act ("CSOX") was December 31, 2006, and to put them into operation by end of December, 2007. Controls which have been developed and templated by Symantec for use with Symantec Enterprise Security Manager to manage SOX compliance in the US, are equally valid and useful in managing CSOX compliance in Canada. This paper seeks to show how the Canadian Securities Administrators' rules map to the equivalent US legislation.
"Dear Privacy Officer" - the Nightmare Letter
Given the public's knowledge on the occurrence of privacy breaches brought about by reports in the media, and that in fact these may be underreported, companies should be prepared for Canadians exercising their right to inquire not only what an organization knows about them, but whether their personal information is at risk or has been exposed. Organizations would do well to be prepared for the receipt of the 'nightmare access letter' from an irate consumer who knows a little too much about privacy and information technology. This white paper provides an overview of the principles relating to safeguarding and access. In addition, it includes an example of an access letter, offered as a tool for C-level executives on the forefront of dealing with privacy breach fallout.

Copyright 2006 IT World Canada, Inc. All Rights Reserved.
Designated trademarks and brands are the property of their respective owners.