How to stop your data leaking

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS

One of the most debilitating IT headaches strikes when confidential data leaks out of the company's network and trickles into the hands of malicious users. No matter how robust your technology is, or how intuitive your detection systems are, restricted data somehow manages to seep through the least guarded nooks and crannies of the enterprise.

Our experts said that the usual and most overlooked sources of data leakage are slapdash database privileges, plain ol' email, and slipshod security policies. Here are some recommended strategies and brand-name solutions.

Stop 'broad-brush' database privileges
According to Chris Johnson, senior manager of product management at BMC Software, misuse by "authorised but unethical" employees can lead to data leakage in the database environment.

Johnson provided three scenarios and recommendations for keeping data protected:

  1. Scenario: An end user who has more database privileges than is really needed, because it can be difficult and/or time consuming to give each person the exact permissions needed. This is typically not done for average users, but non-IT "super users". Senior personnel may be able to demand this kind of privilege.
    Recommendation: "For end users, there really is no excuse for using broad-brush privileges. If I were an IT director today (I have been one before), I would insist on a frequent review of who has what privileges and why. Companies need to decide if they are more interested in security or convenience...Security should win this race in nine out of 10 enterprises."
  2. Scenario: DBAs and network admins who need very powerful privileges to do their job. Although you may be able to limit this privilege to a very small number of people, there is always a DBA who could potentially look at all of your data, and a storage administrator who has copies of your database backups and so on. If an individual isn't trustworthy, there is no limit to potential leakage.
    Recommendation: "For privileged users like DBAs and sys admins, you can use the above approach to a point -- there is no reason to give DBAs access to every database in your enterprise, just the ones they personally work on. When I was an IT director, my policy was to have the 'primary' DBA for each system define and keep the user IDs and passwords private to themselves, but provide copies to me and the data center manager to keep in a 'lock box' in case the primary DBA isn't available. This is a low-tech way to prevent over-distribution of very powerful user IDs and passwords."
  3. Scenario: IT users who don't personally need powerful privileges, but by the nature of their job have the potential to use someone else's privileges. A typical case would be a lower-level data center operations employee who manages the production scheduling environment. Many scheduled jobs will include DBA or sys admin user IDs and passwords. This is a significant threat because a less experienced, possibly less trusted person has the potential to use all the privileges of a more experienced, more trusted person.
    Recommendation: "For both end users and privileged users, put controls in place that help honest people to stay honest. If you implement products that monitor who does what, and make sure everyone knows they are in use, you will discourage a lot of leakage."

Johnson added that identity and access management products such as BMC's CONTROL-SA make it much easier to administer and manage user access across the enterprise. BMC's Database Security Management by IPLocks helps companies keep complete records of who has what privileges and who has changed or queried what data. "[They're] great if you ever need to investigate the cause of a data theft or data integrity problem. And if you let people know this control is in place, it will discourage misbehaviour," Johnson said.

Talkback

Intresting data leaking production from file, document thefts: EagleEyeOS Professional www.eagleeyeos.com
Many more good solutions, such us Document Quarantine, File lifecycle tracking, etc.

via Facebook 21 January, 2006 11:23
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

9 hours ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

9 hours ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

11 hours ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

11 hours ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

12 hours ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

13 hours ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

16 hours ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

16 hours ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

17 hours ago by Mispam on Windows 8 start-up speed forces USB boot workaround
apexwm

I've also seen that Mac OS X for Intel machines is supposed to run in VirtualBox, which would also be a nice solution. I've never tried it though.

19 hours ago by apexwm on xTreme Triple Booting: Linux, Mac & Windows
dave heasman

What I wonder is why when companies are caught bang to rights in not providing contracted services, people bend over to smear the customers? Surely...

19 hours ago by dave heasman on Virgin throttles broadband for high-speed customers
pjc158

Strange statement from HP regarding Mike Lynch and not capable of scaling a company. Autonomy was a $7bn purchase which started as a small company...

20 hours ago by pjc158 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
lojolondon

Or - possibly, they will destroy business by ensuring people do not invest where there is no return. Another socialist idea, well beyond it's...

22 hours ago by lojolondon on Open Data Institute will act as biz incubator
J.A. Watson

Good stuff Jake, very interesting. Thanks. jw

23 hours ago by J.A. Watson on xTreme Triple Booting: Linux, Mac & Windows
openhgs

"the cost of a second LCD screen is about the same as one day of an office worker's time, so this should soon be recouped in extra productivity."...

1 day ago by openhgs on Windows 8 could speed multi-monitor uptake
Thomas Gellhaus

I also installed the KDE version; I also will probably try out razorqt since I really haven't had a chance to before. I'm looking forward to the...

1 day ago by Thomas Gellhaus via Facebook on Mageia 2 Released
francisabigail

Acquiring when reinvention/cannibalization is too challenging for a large organization can be an excellent strategy- still, so many mergers stumble...

2 days ago by francisabigail on Ariba buy parks SAP on Oracle's cloud turf
apexwm

All of the feedback regarding using a touch monitor for a desktop PC is right on. Several months ago, we installed a "demo" multitouch all-in-one...

2 days ago by apexwm on Windows 8 could speed multi-monitor uptake
191706

anyone wanting to triple boot *their* own Mac

2 days ago by 191706 on xTreme Triple Booting: Linux, Mac & Windows
SoapyTablet

Cont.. Biggest Bugbear: Win7's stop-animate-go approach to work, you develop a staggered (not in the above alchohol sense of the word) approach to...

2 days ago by SoapyTablet on Windows 8 could speed multi-monitor uptake