Showing posts with label best practices. Show all posts
Showing posts with label best practices. Show all posts

Monday, October 20, 2008

Consumer Self-Protection

Yesterday I posted about weaknesses in systems deployed by the IRS. In that post, I used the weaknesses as an example of the limits of government regulation, given that they showed that even the government itself couldn't keep its house in order. However, something I didn't explicitly address in that post is that the weaknesses in the IRS' systems also demonstrate that there are serious limits on what consumers can do to prevent their information from being compromised. After all, you can't avoid paying taxes, and, by definition, the information held by the IRS is highly sensitive financial data. The result is, simply by virtue of being an American and following the law, your information is at risk.*

So what can ordinary consumers do to protect themselves? In the case of information security, for individuals, I'd say that an ounce of cure is worth a pound of prevention. That is, rather than worrying about protecting your data (which should be the responsibility of the merchants/government entities your data is entrusted to) individual consumers should worry about how they'll find out and deal with it if their data is compromised. Easy steps like credit monitoring, promptly disputing unauthorized charges, and maintaining backup accounts/lines of credit in case one gets frozen as a result of fraud can make recovering from the extremely hard to prevent data compromises a substantially less miserable experience.

*As a note, I don't mean to single the IRS out as an exceptionally bad actor. Indeed, if you compare the IRS' security practices with security practices at TJX before their big breach, I think the IRS comes out way ahead.

Friday, November 16, 2007

Protecting Against Yesterday's Threats

Over at Bruce Schneier's blog there's a reference to a paper that includes the criticism of security efforts that "Most 'security' efforts are designed to stop yesterday's attacks but fail completely to stop tomorrow's attacks and are of no use in building invulnerable software. These efforts are a distraction from work that does have long-term value." While I understand the frustration the author of the paper must feel from dealing with the aftermath of new attacks which are not prevented by backward looking technology, I think the criticism is misplaced. The systems which are the most vulnerable are not the ones which will be compromised by an innovative new hack - they're the ones that can be compromised using hacks that have been known for years. Case in point: TJX, where the largest data breach in history took place because of TJX's use of Wired Equivalent Privacy which was known to have been compromised years before the breach (article here). If TJX had protected against yesterday's threats, the individuals who hacked it might have moved on to try and find a softer target, rather than trying to develop some innovative new attack technique to get through at TJX.

From a legal perspective, focusing on the threats of the past also makes sense. In many cases, liability will swing on whether some harm was foreseeable or whether an actor exercised reasonable care. In a court case, it's much harder to argue that a risk of a data breach wasn't foreseeable, or your care was reasonable, if you hadn't even protected against yesterday's (i.e., known) threats. This isn't to say that it isn't also important to try and head off threats before they materialize by using good security practices. However, it's important not to let the perfect be the enemy of the good, or to let the value of learning from the past be overlooked.

Tuesday, July 17, 2007

Department of Energy Levying Security Breach Fines?

Apparently, the Department of Energy (DOE) can levy fines for security breaches - when you're working for them and allow their information to be stolen. At least, that's what's currently happening to the University of California, and a company called Los Alamos National Security, in connection with a loss of classified information from 2006. According to this article from ComputerWorld, the DOE has proposed a fine of $3,000,000 on the University of California, Oakland - the largest fine ever assessed by the DOE. The university, not surprisingly, is fighting back, noting that the breach took place after the university's contract had expired, and noting that the university had taken a number of steps to enhance security. One particular measure taken by the university which is likely to become a trend in other enterprises is the implementation of a diskless and medialess environment, which, when properly implemented, can address one of the most difficult challenges in information security - sensitive data walking off in a portable hard drive or other medium.

Friday, July 6, 2007

And why beholdest thou the mote that is in thy brother's eye?

As if a reminder was necessary, a recent theft of data at Fidelity National Information Services, Inc. has demonstrated that threats to data security doesn't have to come from outside an organization. According to this article from ComputerWorld a senior database administrator - the very person who had responsibility for defining and enforcing data access rights - stole over 2 million consumer records and sold them to a data broker. How can this type of incident be avoided? Well, good personnel policies might help. If there were any red flags (e.g., criminal convictions for related crimes) then putting the former DBA in such a sensitive position would have been a clear mistake. However, not all potential thieves have actually committed a crime (after all, there's always a first time), so looking at an employee's background isn't foolproof. Given that, businesses should make sure that they have in place policies which can detect unauthorized data use (preferably not all enforced by one person, in case that one person happens to be the thief) and then respond quickly, thus minimizing the damage if a theft of data does occur.

Wednesday, June 13, 2007

Risks from P2P Networks

ComputerWorld has a pair of articles up here and here discussing risks posed by P2P networks. The first article focuses on a Dartmouth study which found that substantial amounts of sensitive information, including (ironically) a security evaluation for a bank performed by a third party contractor, is inadvertently made accessible by consumers who download P2P software. The second article provides a concrete example of that danger: a Pfizer employee who installed P2P software on a laptop which was provided by the company for her own home use inadvertently exposed personal data for around 17,000 current and former employees of Pfizer. The take home message from all this? Have policies which control the use of P2P software, and make sure that employees know that violating those policies won't only be a breach of workplace rules, it would also put their own personal data at risk.

Thursday, May 17, 2007

Keep an Eye on Contractors

According to this article from Computer World, IBM has announced that, due to a "transportation incident" with one of its vendors, two tapes containing sensitive employment data have been lost. This is a particularly embarassing failure for IBM, because that company touts its own security and privacy services as a way to stay "one step ahead of hackers and other threats," though it should be a reminder for all companies that good data security isn't limited to internal systems, it involves taking responsibility for your data regardless of where (or with who) it is physically stored.

Wednesday, May 9, 2007

Planning for the Morning After

Computerworld has an interesting article up about what to do when your company's data security has been breached. Some key points in the article include a to-do list (rely on your plan, work with the right people, identify the problem and dig deeper, communicat with stakeholders, connect with colleagues, support your people, move the organization ahead, and take a final look back) as well as a not-to-do list (don't create a power vacuum, don't promise what you can't deliver, don't push too much change too fast, and don't be too hands on) for companies seeking to survive a data security breach. Definitely recommended reading for anyone interested in practical advice for what to do when something inevitably goes wrong.

Sunday, May 6, 2007

Don't Forget the Laptops

While it's easy to focus on the threats posed by hackers, simple physical theft should also be a major source of concern for anyone seeking to minimize the risk of unauthorized information access. As if to provide an object lesson on this point, the TSA (yes, the same people who make you take your shoes off when you need to board a plane) has reported that a lost external hard drive has put social security numbers, and bank and payroll data for about 100,000 current and former employees at risk (see article here and the TSA's public statement here). This is exactly the kind of incident that a good security policy which was designed with more than just hackers in mind could have prevented. Indeed, TSA's security policy ideally would have prohibited such sensitive data from being stored in unencrypted form on such an easily lost (or stolen) device. However, apparently, the TSA either didn't have, or didn't enforce, such a policy and, as a result, they'll be paying for a year of free credit monitoring for potentially effected employees.

Tuesday, March 27, 2007

What do the Leaders Do Differently

The IT Policy Compliance Group has published a useful research report describing best practices for decreasing the incidence of sensitive data loss. One particularly interesting feature of the report is their comparison of what makes leading firms (i.e., those with the fewest lost data incidents) unique. Specifically, the report shows that leading organizations are uniquely employing multiple IT controls to help protect sensitive data and monitoring and measuring controls and procedures to protect data once every four days. The report also shows that leading firms consider two types of non-core business data (IT security data and regulatory audit and reporting data) to be among their most sensitive data. Thus, the report provides not only good comparative data, but also guidance for improving existing practices, and should be considered recommended reading for any organization interested in reducing data loss.

Thursday, March 22, 2007

IM Best Practices

Symantec has put out a white paper which discusses some of the compliance issues related to instant messaging. A particularly useful aspect of the paper is a handy (though not exhaustive) list of regulations which are related to corporate instant messaging.