Find White Papers
Home
About Us
List Your Papers
    
> IBM > Data Privacy Best Practices

Data Privacy Best Practices

White Paper Published By: IBM

This white paper explains the steps you need to consider when developing your privacy strategy and implementing your first data privacy project. Find out how you can help your organization implement best practices in privacy protection and make your privacy project successful from start to finish.



Tags : 
ibm integrated data management, data privacy, data security, ibm optim data privacy solution, hackers, security breach, best practices for data security, data inventory

IBM
Published:  Feb 18, 2009
Type:  White Paper
Length:  20 pages

Enterprise Data Management SolutionsSeptember 2008
IBM Information Management software
Data privacy best practices:
time to take action!Data privacy best practices: time to take action!Page 2
Executive summaryContents In a technology-driven world, data breaches are not only common, they can also be costly. Privacy violation statistics indicate that the number of incidences and costs associated with data breaches are increasing steadily, proving that organizations 2 Executive summary across industries need to take a more pragmatic approach for protecting information, 3 Why is it important to protect especially in highly vulnerable non-production (development, testing and training) privacy? Understand the facts. environments. Data in non-production can be more susceptible to a breach when 3 What areas are most vulnerable? it is used in development and testing activities, accessed by mobile employees or Understand the risks. outsourced. 4 Considerations for planning a data privacy project In the midst of unprecedented security breaches, the best way to ensure that 13 Additional points to consider confidential information remains protected is to develop and implement a 13 Optim implementation - comprehensive privacy and security strategy. Once organizations realize that a user's perspective protecting privacy is no longer optional, most ask, "Where do we start?", "What are the requirements?" and "What steps should our organization take to implement an enterprise data privacy and security strategy?"
This white paper explains the steps you need to consider when developing your privacy strategy and implementing your first data privacy project. Using proven data masking techniques, such as those provided in the IBM® OptimT Data Privacy Solution, can help your organization implement best practices in privacy protection and make your privacy project successful from start to finish. Lastly, learn how a large retail company implemented Optim to develop a best practice strategy and a successful privacy project, overcoming many of the challenges that occur when implementing a privacy project on an enterprise scale.Data privacy best practices: time to take action!Page 3
Why is it important to protect privacy? Understand the facts.With hackers on the loose and identity theft on the rise, data privacy breaches are impacting our personal and business lives in ways we never dreamed of before. The proof is in the numbers. According to the Privacy Rights Clearing House, since January 2005 in the U.S. alone, the total number of records containing sensitive 1personal information involved in security breaches was 230,441,730. This number is increasing daily.
In this technology age, much of the confidential information that is targeted for theft resides in the business applications and computer systems that drive enterprise business initiatives. Without appropriate measures in place to protect privacy and prevent the severity of a breach, the next company affected could be yours.
Data privacy begins with protecting different types of sensitive application data, no matter where it resides across your organization, in both production and non-production (development testing, and training) environments. However, companies are realizing that the methods for protecting privacy in production environments may not be practical or appropriate for managing data in non-production environments.
What areas are most vulnerable? Understand the risks.The methods for protecting privacy in production versus non-production environments should be different. For example, most production environments have established security and access restrictions to protect against data breaches. Standard security measures can be applied at the network, application and database levels. Physical entry access controls can be extended by implementing multi-factor authentication schemes, such as key tokens or even biometrics. However, these Data privacy best practices: time to take action!Page 4
protective measures cannot simply be replicated across every environment. The methods that protect data in production may not meet the unique requirements for protecting non-production environments, where developers, testers and trainers need more access to realistic data, not less.
A 2007 survey, conducted by the Ponemon Institute and Compuware, showed that an overwhelming number of organizations use liv... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search