<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance &#187; Vendor Risk</title>
	<atom:link href="http://blog.kraasecurity.com/category/vendor-risk/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 06 Jul 2011 01:12:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Data Lifecycle Management: How to reduce risk, Part 2</title>
		<link>http://blog.kraasecurity.com/2010/05/02/data-lifecycle-management-how-to-reduce-risk-part-2/</link>
		<comments>http://blog.kraasecurity.com/2010/05/02/data-lifecycle-management-how-to-reduce-risk-part-2/#comments</comments>
		<pubDate>Sun, 02 May 2010 19:58:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Vendor Risk]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Company]]></category>
		<category><![CDATA[Consultants]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Data Lifecycle Management]]></category>
		<category><![CDATA[General and Freelance]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=225</guid>
		<description><![CDATA[Data Lifecycle Management: How to reduce risk Part 2 The Data Lifecycle Management (DLM) goes through 5 steps: creation, usage, transport, storage and destruction. Most companies have parts of this lifecycle under control, but that means there are lots of areas for gaps in the control measures that could let a threat affect the data. [...]]]></description>
			<content:encoded><![CDATA[<h2>Data Lifecycle Management: How to reduce risk</h2>
<p>Part 2<br />
The <strong>Data Lifecycle Management</strong> (DLM) goes through 5 steps: creation, usage, transport, storage and destruction. Most companies have parts of this lifecycle under control, but that means there are lots of areas for gaps in the control measures that could let a threat affect the data. The multiple part blog, (I am not sure how many parts it will take), will walk through the steps of the data lifecycle and what a company can do to implement a good process for all the data management challenges.</p>
<p>In the first part of this series, we covered what it means to say you have or want a data lifecycle management process.  So why do we need something different from what we are already doing around DLM?</p>
<h2>Why does traditional security not work for DLM?</h2>
<p>Users have risky behavior. They will always have risk behavior and we rely on mostly <a class="zem_slink freebase/en/technology" title="Technology" rel="wikinvest" href="http://www.wikinvest.com/industry/Technology">technology</a> controls to keep them in a secure box.  Solutions aimed at the external threats coming in, not the regulation and governance of internal communications going out. Problems we see are typically:</p>
<ul>
<li><strong>Unauthorized application use</strong>: 70% of IT say the use of unauthorized programs result in as many as half of data loss incidents.</li>
<li><strong>Misuse of corporate computers</strong>: 44% of employees share work devices with others without supervision.</li>
<li><strong>Unauthorized access</strong>: 39% of IT said they have dealt with an employee accessing unauthorized parts of a company’s network or facility.</li>
<li><strong>Remote worker security</strong>: 46% of employees transfer files between work and personal computers.</li>
<li><strong>Misuse of passwords</strong>: 18% of employees share passwords with co-workers.</li>
</ul>
<p>The reasons typical technology controls will not work in the full DLM process are:</p>
<ul>
<li>Products are not geared to protect a full life cycle of a customer records</li>
<li>Most solutions and processes are outward facing, based on perimeter security</li>
<li><a title="pgp encryption" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">Encryption</a> can affect data management</li>
<li>Real-time <a title="intrusion detection" href="http://www.kraasecurity.com/managed-services/intrusion-defense/intrusion-detection">intrusion detection</a> and remediation is rare</li>
<li>Context and intent of messages was not analyzed properly</li>
<li>Functional areas in organizations create different policies, monitoring requirements, enforcement priorities and reporting</li>
<li>New technologies can avoid security measures</li>
<li>Technologies look at the network, the operating system or the application not the data across all environments</li>
<li>Not mapped properly to regulations</li>
</ul>
<h2>What risks does customer data loss pose for organizations?</h2>
<p>If we know that security is not working, what are the risks we face? A very recent example of how this can have a practical affect is with the <strong><a title="massachusetts privacy" href="http://www.kraasecurity.com/compliance/201-cmr-1700-massachusetts-privacy-law">Massachusetts Privacy Law 201 CMR 17.00</a>. </strong>Loss of data can have a great financial impact with this law. <strong> </strong>Key things we need to consider include:</p>
<ul>
<li>Penalties: Not complying with regulations can cause civil and financial penalties</li>
<li>Confidence: Loss of customer confidence because of a customer <a title="data loss prevention" href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">data breach </a>can lose customers</li>
<li>Reputation: Damage to reputation will lose customer and damage relationships</li>
<li>Competitive Advantage: Information and customers can move to competitors</li>
<li>Costs: <a class="zem_slink" title="Ponemon Institute" rel="homepage" href="http://www.ponemon.org/">Ponemon Institute</a>’s 2008 annual study, average $6.6 million per breach.</li>
<li>Valuation: Decreased stock prices could result</li>
</ul>
<p>I will continue this process in the next post…</p>
<p>Gary Bahadur<br />
<a title="network security risk assessment" href="http://www.kraasecurity.com">http://www.kraasecurity.com</p>
<p>http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
Address: 200 Se 1st St #601 Miami FL 33131</p>
<p>*Managed Security Services<br />
*Vulnerability Management<br />
*Compliance &amp; Policy Development<br />
*PGP Security<br />
*FREE Website Security Test</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/March2010/10/c8461.html&amp;a=14480228&amp;rid=9695555b-dc62-4f4d-b5f8-8de22da37117&amp;e=bf95a820287a2b52a1b11bb045c269a3">Analyst Study Shows Employees Continue to Put Data at Risk</a> (newswire.ca)</li>
<li class="zemanta-article-ul-li"><a href="http://eon.businesswire.com/news/eon/20100427005421/en">Perception of Data Security at Odds with Reality, Accenture Study Finds</a> (eon.businesswire.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.newstatesman.com/technology/2010/03/data-protection-theft-loss">Data protection a priority for CEOs</a> (newstatesman.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2259432/hsbc-understated-threat">HSBC admits to understating data theft</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2256724/breach-numbers-fall-while-costs">Breach numbers fall while costs rise Ponemon study finds</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.techcrunchit.com/2010/04/29/symantec-shells-out-370-million-for-data-encryption-companies-pgp-and-guardianedge/">Symantec Shells Out $370 Million For Data Encryption Companies PGP and GuardianEdge</a> (techcrunchit.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/60b0d89f-8c7a-413e-b843-f7ff3b827813/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=60b0d89f-8c7a-413e-b843-f7ff3b827813" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/05/02/data-lifecycle-management-how-to-reduce-risk-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

