Find White Papers
Home
About Us
List Your Papers
    
> Utimaco > Data Leakage Landscape: Where Data Leaks & How Next Generation Tools Apply

Data Leakage Landscape: Where Data Leaks & How Next Generation Tools Apply

White Paper Published By: Utimaco

Data protection programs at most organizations are concerned with protecting sensitive data from external malicious attacks, relying on technical controls that include perimeter security, network/wireless surveillance and monitoring, application and point security management, and user awareness and education. In this paper, the different leakage points are mapped with regulations and best practices.



Tags : 
leak, leakage, data protection, pci, cardholder, cardholder data, utimaco, database security

Utimaco
Published:  Aug 18, 2008
Type:  White Paper
Length:  15 pages

Sponsored by Utimaco and Trend Micro
Data Leakage Landscape:
Where Data Leaks and
How Next Generation Tools Apply
A SANS Whitepaper - April 2008 Written by Barbara Filkins & Deb Radcliff
The Leaking Faucet
Data Leakage Regulatory Landscape
Regulatory and Data Leakage Landscape
Plug Leaks, Stem the Flow
Data Leakage Landscape 1: Data in Use and in Motion
Data Leakage Landscape 2: Data At Rest and In StorageThe Leaking Faucet
Everyone is familiar with the concept of a data breach - con?dential information, usually per-sonally identifying information, falls into the wrong hands, and then suddenly, the data handler becomes reviled as the next TJ Maxx.
Data protection programs at most organizations are concerned with protecting sensitive data from external malicious attacks, relying on technical controls that include perimeter security, network/wireless surveillance and monitoring, application and point security management, and user awareness and education.
But what about inadvertent data leaks that aren't so sensational, for example unen- Educationcrypted information on a lost or stolen lap-top/USB or other device? Like the steady drip from a leaking faucet, everyday data Financial Dataleaks are making headlines more often than Private DataPersonally Identi?able the nefarious attack scenarios around which Information (SSN, Tax ID)Trade Secretsorganizations plan most, if not all, of their ContractsCon?dential Documentsdata leakage prevention methods. However, Credit Card Informationto truly protect their critical data, organiza- Prevention Health Information Detectiontions also need to plan a more data-centric approach to their security programs to pro-tect against leaks that occur everywhere sensitive data lives, rests or is used.
What type of protections would be required for, say, a training site for hospital call center employees, where actual lab reports and other real patient data are posted in the online train-ing forms? How do you implement the same controls around data being cut/copy/pasted and e-mailed or sent out of the organization by other means?
Indeed, there are so many places data can easily leak out of an organization it would be dif?cult to note them, let alone classify and manage them, without some type of map or landscape that lays them all out. Broadly, these data leak points include:
S ensitive data inappropriately removed, transferred, or sent out via postal mail, e-mail, Web mail, ?le transfers or instant messaging
L ax, improper or missing access controls to systems containing sensitive data, from back-end databases and servers to mobile computers
SSAANNSS AAnnaallyysstt PPrrooggrraamm 11 HDaradtaw Laerea kvaegrseu Lsa Snodfstwcaapree L ost or stolen computers, laptops and mobile devices with sensitive data that is unencrypted; hard disks and portable storage (CDs, USB drives) or backup devices; and paper ?les
I nsecure transmission of personal identi?able and other restricted data
A uthorized insider abuse of databases and other back-end systems
I nsecure or improper destruction of information, encompassing both physical locations (dumpsters) and electronic media (laptops and backups)
R e-use of electronic resources (laptops and backup devices)
L ack of separation of duties and access controls on databases and other shared systems
In this paper, we map these leakage points with regulations and best practices. Protection mechanisms can be simpli?ed by breaking them into ?ve major categories: classic malware protections to prevent system infections, enforceable access controls, encryption, ?ltering for data sensitive data types being sent out of the organization, and education.
In addition to traditional malware defenses, encryption and access controls play a huge role in protecting sensitive data from insiders no matter where the data rests or how it being acted upon. Equally important is the ability to ?lter, log, and take action on outbound traf?c and downloads, which is commonly referred to as Data Leakage Protection (DLP). The last piece, education, can be enforced by the actions of the control systems themselves. For example, automatic encryption policies on some types of program actions (e-mailing... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search