<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Blog &#187; data loss prevention</title>
	<atom:link href="http://blog.securstar.com/tag/data-loss-prevention/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.securstar.com</link>
	<description>SecurStar - Security at it&#039;s highest level</description>
	<lastBuildDate>Mon, 19 Oct 2009 10:51:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Practical Data Loss Prevention</title>
		<link>http://blog.securstar.com/2009/09/19/practical-data-loss-prevention-3/</link>
		<comments>http://blog.securstar.com/2009/09/19/practical-data-loss-prevention-3/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 11:35:38 +0000</pubDate>
		<dc:creator>Michael Mckinzie</dc:creator>
				<category><![CDATA[Risk Analysis]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[laptop security]]></category>
		<category><![CDATA[security policies]]></category>

		<guid isPermaLink="false">http://blog.securstar.com/?p=98</guid>
		<description><![CDATA[(Week 3 of 4)
by Michael McKinzie, CISSP
Last week we talked about data classification and policies and restrictions. My conclusion is it is very difficult for organizations to fully implement a broad restriction of access to personal use sites such as social networking sites, webmail, blogs, YouTube etc.  Although, many tools exist to help enforce [...]]]></description>
			<content:encoded><![CDATA[<p>(Week 3 of 4)<br />
by Michael McKinzie, CISSP</p>
<p>Last week we talked about data classification and policies and restrictions. My conclusion is it is very difficult for organizations to fully implement a broad restriction of access to personal use sites such as social networking sites, webmail, blogs, YouTube etc.  Although, many tools exist to help enforce this policy on the LAN, or corporate network, users may simply be able to use their Internet enabled phone/Smart-phone to access these sites undetected by IT security.</p>
<p>If the organization allows synchronization of email, calendars, notes, documents, files or maybe even hosts an extranet service like a CRM application which is accessible by the mobile sales force, it is important to know the type and class of the data being shared. Mobile Phones may introduce a new risk to compromise sensitive data, which may not be as easy to control as implementing a gateway system or access control list.  Should the organization have access to control personal devices or restrict what users can do on these devices? It probably is not realistic to tell users they cannot bring their mobile phones to work in the event they have a personal or family emergency, or if they want to make a personal call during a break or lunchtime.  Perhaps an approach of limited use would help provide better controls to monitor use versus users turning to alternatives such as their smart-phones. I attended a concert recently where they said no cameras allowed. I wondered how it would be enforced since virtually all new generation phones have an integrated camera; they did not confiscate my phone. Maybe if I tried to march in with a high end SLR, I would have had a problem. What type of risk does this present to organizations? (Maybe another entire discussion)</p>
<p><strong>As a former security consultant, I used the following trust and operations model. </strong></p>
<p>1)	Relied on Managers and Human Resources (HR) for employee background checks, and screening.<br />
2)	Provided network and data access based on job roles and responsibilities; enabled higher level of auditing/logging for first 90 days for all new users to monitor activity<br />
3)	If a user had a high level of access to customer records, financial data or HR, verbose logging was enabled on the systems and reports were provided to the user’s manager on a periodic basis for review.<br />
4)	Implemented security infrastructure and polices, and used BS17799/ISO17799 as a guide; all users would sign a computer use (Zero tolerance) agreement as part of the hiring process.<br />
5)	Promoted awareness/best practices through emails, meetings, and lunch-n-learns. Encouraged users to report suspicious behavior.<br />
6)	Ensured a balance of security and usability. i.e. user visits a site considered non-work related (webmail), a warning message appears to notify them, they are being monitored, but can click through to continue.  A simple but effective reminder to not spend too much time on non-work related sites.</p>
<p>So simply, establishing a trust baseline, but restricting users from roaming servers and data in which they had no reason to access. You would think most Admins would naturally do this, but after countless audits and vulnerability assessments there would almost always be case of users having access to resources which were not necessary.</p>
<p><img src="http://blog.securstar.com/wp-content/uploads/2009/09/quote_week3_securityblog.jpg" alt="quote_week3_securityblog" title="quote_week3_securityblog" width="590" class="aligncenter size-full wp-image-105" /></p>
<p>I believe this is a result of IT not having intimate knowledge of department application servers, initiatives which did not involve IT or job changes, promotions etc and the user is “grand-fathered” in with the original access rights and new permissions are added. Smaller organizations tend to have a flat and open system where many users have full access. The receptionist may handle the book-keeping and customer service and their IT department, most likely an independent computer consultant who wants to ensure productivity while security is sidetracked. In my opinion the small business owner’s data is no less important than a larger organization’s data, so security should be weaved into the any IT deployment of hardware, software, and assignment of users’ rights.</p>
<p><strong>I am interested in hearing your thoughts on:</strong></p>
<p>1.	How do you segregate resources? Roles, Responsibilities, other?<br />
2.	Do you think of soft policies/reminders is an effective approach for non-work use of IT resources? Any experiences you can share?<br />
3.	Should organizations have a policy over personal devices such as smart-phones, personal voice recorders etc. How would you enforce it?</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fblog.securstar.com%2F2009%2F09%2F19%2Fpractical-data-loss-prevention-3%2F&amp;linkname=Practical%20Data%20Loss%20Prevention"><img src="http://blog.securstar.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://blog.securstar.com/2009/09/19/practical-data-loss-prevention-3/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Practical Data Loss Prevention</title>
		<link>http://blog.securstar.com/2009/08/27/practical-data-loss-prevention-2/</link>
		<comments>http://blog.securstar.com/2009/08/27/practical-data-loss-prevention-2/#comments</comments>
		<pubDate>Thu, 27 Aug 2009 19:02:52 +0000</pubDate>
		<dc:creator>Michael Mckinzie</dc:creator>
				<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Risk Analysis]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[laptop security]]></category>
		<category><![CDATA[security policies]]></category>

		<guid isPermaLink="false">http://blog.securstar.com/?p=80</guid>
		<description><![CDATA[So where do we practically begin? Does the organization know what their sensitive data is/classified, where it resides, how it travels through business processes, how it is shared and used? Some of these questions are easy to answer but some might be difficult. Who owns the data? If a user accesses his or her personal email account, or another personal use site, is any information or data downloaded belong to the organization? ]]></description>
			<content:encoded><![CDATA[<p>(Week 2 of 4)<br />
by Michael McKinzie, CISSP</p>
<p>Building on my post from last week I want to invoke thought about how you as an individual or on behalf of your organization approach data loss prevention (DLP).  I used an example of the way we (generally speaking) expect, and rely on our financial institutions to keep our money safe and accurately accounted for but I also mention the expectations banks and institutions place on users and consumers. If we apply this same model to computer use, it is form of a privileged system model (authentication and permissions). i.e. proper authentication to access resources , and permission based rules to govern activities just as the bank controls access to accounts. </p>
<p>The challenge remains there are constant threats to our data from vectors by misuse, social networks, theft, lost devices, malware, viruses, Trojans, botnets, social engineering, integrated business partners, outsourcing  etc. IT administrators adhering to best practices are vigilant in protecting data but are required to  balance it with usability for businesses to remain productive and competitive. Businesses continue to rely on faster and broader communications and data security is often perceived as a hindrance. </p>
<p><em>“Every day, CIOs face the challenge of putting the necessary technologies and processes in place to protect confidential data and comply with federal regulations, but they have to accomplish this without impeding daily business operations.”</em> – <strong>CIO Magazine</strong></p>
<p>So where do we practically begin? Does the organization know what their sensitive data is/classified, where it resides, how it travels through business processes, how it is shared and used? Some of these questions are easy to answer but some might be difficult. Who owns the data? If a user accesses his or her personal email account, or another personal use site, is any information or data downloaded belong to the organization? Does the company have a legal obligation to protect it? Should the company control the user’s content? Do they have a legal obligation to do so to protect company or customer information and interests? </p>
<p>How do we classify data? These are often the questions and challenges facing organizations on a daily basis. Is it practical to just restrict access? Perhaps sales and marketing or the executives of the company have specific needs requiring access? Maybe the company promotes control versus broad restrictions?  I don’t have answers to all of these questions nor do I believe there is a simple answer which applies to all organizations. How do you approach it?</p>
<p><strong>I am interested in hearing your thoughts on:</strong></p>
<p>1. Do you think it is important to classify data formally? If so, have you done this and what was your experience?</p>
<p>2. What do you think is the largest threat to your confidential data?  Users, malicious attacks, social networks, data leakage via lost or stolen devices etc. </p>
<p>3. Do you or your organization promote control over broad restriction policies or how do you determine the best practice? e.g. restrict or block webmail, and social networking sites versus providing limited access with monitoring</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fblog.securstar.com%2F2009%2F08%2F27%2Fpractical-data-loss-prevention-2%2F&amp;linkname=Practical%20Data%20Loss%20Prevention"><img src="http://blog.securstar.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://blog.securstar.com/2009/08/27/practical-data-loss-prevention-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Practical Data Loss Prevention</title>
		<link>http://blog.securstar.com/2009/08/21/practical-data-loss-prevention/</link>
		<comments>http://blog.securstar.com/2009/08/21/practical-data-loss-prevention/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 12:20:02 +0000</pubDate>
		<dc:creator>Michael Mckinzie</dc:creator>
				<category><![CDATA[Risk Analysis]]></category>
		<category><![CDATA[credit card fraud]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[hacking data]]></category>
		<category><![CDATA[laptop security]]></category>
		<category><![CDATA[notebook security]]></category>
		<category><![CDATA[secure data]]></category>
		<category><![CDATA[stolen data]]></category>

		<guid isPermaLink="false">http://blog.securstar.com/?p=53</guid>
		<description><![CDATA[Introduction and practical approach to Data Loss Prevention for Enterprises, small and medium sized business. Forum to discuss DLP and data loss prevention programs.]]></description>
			<content:encoded><![CDATA[<p>(Week 1 of 4)<br />
By  Michael McKinzie, CISSP</p>
<p>Data Loss Prevention or DLP is an interesting and popular topic especially since the largest single incident of data theft recently occurred. Heartland Payment Systems discovered numerous systems were compromised and an estimated 130M consumer credit card numbers were at risk surpassing TJX Companies reported compromise in 2007 of 94M consumer records.</p>
<p>The implications of these incidents can be difficult to measure, but if you just consider the amount of resources to investigate, notify consumers and remediate an incident, the costs rise quickly. In addition if we try to account for any fraudulent activity that may have occurred or the time consumers must spend to monitor credit activity and/or dispute fraudulent   activity this adds to the cost considerably. Will Heartland or TJX Companies disappear, fail or go bankrupt as a result of these security breaches? Well, not likely but is there a negative impact?  If we look for a correlation between stock price and the reported incidences, it is inconclusive; TJX appears to follow the trend of the S&amp;P 500, while Heartland does a nose dive. One thing is certain, the costs to investigate and remediate the data loss is significant having a negative impact on the bottom line in both cases.</p>
<table border="0" style="border:0px;">
<tbody>
<tr>
<td style="border:0px;"><img class="size-medium wp-image-63" title="heartland_stock_image" src="http://blog.securstar.com/wp-content/uploads/2009/08/heartland_stock_image-300x218.jpg" alt="Heartland stock image" width="256" height="186" /></td>
<td style="border:0px;"><img class="size-medium wp-image-64" title="tjx_stock_image" src="http://blog.securstar.com/wp-content/uploads/2009/08/tjx_stock_image-300x220.jpg" alt="TJX Stock" width="255" height="186" /></td>
</tr>
<tr>
<td style="text-align:center; border:0px;">HeartLand Payment Systems</td>
<td style="text-align:center; border:0px;">TJX Companies</td>
</tr>
</tbody>
</table>
<p>Obviously, these are high profile incidences and may have even affected some of you reading this, but probably nothing more than receiving a letter, a new card and asked to monitor your credit reports, and watch for suspicious credit card activity. The questions I have are we as a society just accepting this as the problem is too hard to control or is it merely a cost of doing business today? International boundaries, anonymity of the internet, millions of insecure computers primed for botnets, poor security architecture by software vendors, lack of information security budgets etc., all are significant challenges to protect our information.</p>
<p>I believe there is a personal and corporate responsibility to protect our information just as most of us trust our bank to keep our money safe and it is expected they will do so or more safe than tucked away at home. They also expect consumers to be diligent with access control. They issue ATM cards with user defined Pin Codes (two-factor authentication with limited authorization i.e. maximum daily withdrawal limits), credit cards with signature panels and identifiers or they deliver a battery of questions when we need to obtain any information on our account by phone.</p>
<p><strong>I am interested in hearing your thoughts on:</strong></p>
<p>1. Is the bank/consumer model or concept reliable? Do you think it works reasonably well?<br />
2. Do you think there should be greater responsibility on users, or the organization to ensure data confidentiality?<br />
3. Is Data Loss, a real concern for you or your organization? Why?</p>
<p>About Me:</p>
<p>Michael McKinzie, CISSP (Business Development Manager, SecurStar) – security practitioner for 12+ years, worked in IT management, consulting, casino gaming, and on the dark side with encryption and security manufacturers. Still a fan of the C Programming Language by Kernighan and Ritchie and know I will make some money from my autographed copy of Applied Cryptography on eBay some day.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fblog.securstar.com%2F2009%2F08%2F21%2Fpractical-data-loss-prevention%2F&amp;linkname=Practical%20Data%20Loss%20Prevention"><img src="http://blog.securstar.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://blog.securstar.com/2009/08/21/practical-data-loss-prevention/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

