|
Regulations and compliance: The business justification for data security |
|
Written by Gil Sever
|
|
Monday, 01 February 2010 09:20 |
|
As the workforce continues to rely and expand its use of mobile devices (i.e. Smartphones and laptops), opportunity for data leakage of sensitive information increases. Let’s explore a real life example; a business executive using his laptop from an airport lounge is communicating via Skype to his family and child’s soccer team coach. He accidently attaches a customer list instead of the soccer team registration. An effective data protection system will warn and block the transfer. This type of accident is fairly common. A recent report from the Ponemon Institute suggests that the most common breaches (64%) occur from company insiders. In the January 2009 study, they found more than 88% of all cases involved insider negligence.
A comprehensive data protection solution can lower these statistics in several ways. First, it can assist organizations in identifying sources of unsecured PHI and PI. For example, advanced discovery tools are capable of quickly locating sensitive data no matter where it resides on your system. Several of our customers have been shocked to learn that their sensitive data resides on endpoints. Second, an effective data protection and leakage prevention system comes bundled with extensive ready to use templates containing policies that “out of the box” will provide effective protection and encryption with little to no user intervention. The more automatic and transparent the system, the better.
Since the majority of leaks occur from an employee’s lack of awareness, educating users is a top priority. Education may occur in the traditional sense, however, a data protection system that includes sophisticated dialog prompts provides “on the job training” of compliance and security policies. This unanticipated side benefit can both prevent a breach as well as train users.
When data is appropriately protected, encrypted and secured, federal and state breach notifications can be avoided. In the long run, organizations can save a significant amount of money and avoid embarrassment and lack of public/consumer trust by deploying the right data protection and leakage prevention solution. The goal for all holders of sensitive data should be to pay a few dollars now, to avoid paying much, much more later. Dollars, customers, credibility and potential lawsuits are all at stake. Look for a comprehensive solution that is transparent and provides the right balance between productivity and protection.
This article is available in full at zdnet.com.
|