Go Back   CORTEX Forums > Best Practices > Subject Matter Expertise > IM Architecture
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read

Data Centric Security

This is a discussion on Data Centric Security within the IM Architecture forums, part of the Subject Matter Expertise category; Analytics Brief: 5 Key Steps To Cybersecurity Technologies like DLP, crypto, and strong access controls help lock down data. By Richard Dreger InformationWeek December 5, 2009 12:00 AM (From the ...


Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 6th December 2009, 10:15 AM   #1
Dashboarder
Guest
 
Posts: n/a
Post Data Centric Security

Analytics Brief: 5 Key Steps To Cybersecurity

Technologies like DLP, crypto, and strong access controls help lock down data.
By Richard Dreger
InformationWeek
December 5, 2009 12:00 AM (From the December 7, 2009 issue)

In our recent InformationWeek Analytics Government IT Priorities survey of federal technology decision makers, cybersecurity was the No. 1 IT initiative within respondents' organizations in terms of importance and leadership focus. For most, cybersecurity means dealing with the Federal Information Security Management Act and its 17 control areas.
The upside to FISMA is that agencies have a consistent and broadly applicable standard for how information security should be applied. The downside is that the true goal of securing sensitive information and preserving core mission processing sometimes gets lost in a maze of requirements. /p>

Here's a summary of our five-step, data-centric plan to ensure you don't lose sight of your end goal. Download the full report free for a limited time.

1. Master controls are out--think data-centric instead
A defense-in-depth architecture relies on a series of integrated, overlapping controls that work together seamlessly to form a strong, homogeneous whole. This approach moves away from using a single master control or appliance that can "do everything" and promotes a distributed and tailored security posture.

2. Embrace data encryption
Whenever sensitive file stores can be copied, the protections afforded by strong physical controls are muted. But if a laptop is secured using an approved whole-disk encryption system, or even if the data resides in separate encrypted "canisters" on the drive, additional authentication credentials are required before accessing the data.

3. Implement strong authentication controls
Authentication involves that most subjective of concepts: attempting to prove that you are indeed who you're asserting yourself to be. Once users have established their identities, role-based access controls can then be applied to limit their actions to only those authorized for a given job.

4. Use data loss prevention to "watch the watchers"
At a gut level, think of data loss prevention technology as an information-vetting system that reviews data content with an eye toward possible threats or policy violations. If a potential problem is found, appropriate actions can be taken to stop the data flow before it leaves the trusted perimeter.

5. Layer on data integrity controls
When systems and applications start breaking or acting in unusual ways, right away we ask, "What changed?" A seemingly simple question, but one that can be very difficult to answer conclusively. Think of data integrity controls as helping to ensure that information, system settings, and file configurations are as you expect them to be--that is, highly secure.


Richard Dreger is president of WaveGard, a vendor-neutral consultancy.
Attached Images
File Type: gif 20091206 251Guidance_chart1.gif (15.4 KB, 0 views)
Attached Files
File Type: pdf C151109_InformationWeek_Analytics_Cyber_Security.pdf (677.9 KB, 0 views)
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiTweet this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
flyTrap interactive Network Security Dashboard Latest News Headlines Other International Vendors 0 28th November 2009 08:21 AM
IBM Receives 'Strong Positive' Rating in Leading Analyst Firm's Managed Security Serv Latest News Headlines IBM and Cognos Forum 0 29th October 2009 03:43 AM
Microsoft releases free security software Latest News Headlines 2009 Q3 News Headlines 0 30th September 2009 03:06 PM
NBN pushes e-security revamp Latest News Headlines 2009 Q3 News Headlines 0 18th August 2009 03:07 AM
Data Warehouse / BI Security Peter O'Donnell Monash University Business Intelligence Blog 0 23rd June 2009 08:34 PM


All times are GMT +11. The time now is 05:17 AM.

© The Business Intelligence Group

Search Engine Optimization by vBSEO