Showing posts with label Data Protection. Show all posts
Showing posts with label Data Protection. Show all posts

Monday, July 29, 2013

Data Centers: A Way to Protect Your Information

The sheer amount of information that companies are collecting in today’s society is exponentially higher than in the past.  According to a McKinsey Global Institute report, the use of ‘Big Data’ will become crucial to remaining competitive, and has the potential to increase a businesses operating margin by over 60 percent.  Maintaining and continuing big data programs is important to gaining a competitive edge.  For this reason, today’s industry leaders are constantly seeking proven ways to protect this critical data and keep their companies up and running in the event of interruptions of any kind, including power failures, viruses, system failures, and more commonly, natural disasters.  With 2013 predictions forecasting above average hurricane activity, it is even more important for companies to develop business continuity plans and begin evaluating disaster recovery solutions.  Many are turning to colocation data centers such as Lam Cloud Management, which offer data center and business continuity solutions as well as years of proven industry experience.

Reliable, Scalable Infrastructure
When evaluating data centers, companies should seek one that is spacious enough for all of their data storage needs. The facility should offer a comprehensive portfolio of data center solutions, including cloud and business continuity services such as Software as a Service (SaaS), hosting, managed services, secure backup and archiving plans, server and desktop virtualization, workplace recovery, and disaster recovery.  Each facility should also be properly equipped with back-up generators and reliable power sources, state-of-the-art cooling and fire suppression equipment, multi-tier security parameters, and other resources to support companies’ business continuity plans. 

Efficient Workplace Recovery
In the event of a natural disaster, the ability to quickly relocate their business operations and team members to a facility complete with ample workplace recovery resources could mean the difference between a quick recovery and continued operations, and potential losses in both revenue and reputation.  With dedicated suites and thousands of single occupancy or shared seats, facilities like Lam Cloud offer their customers an ideal alternate workplace and access to their mission-critical data in a matter of minutes.

The Human Data Center

While reliable infrastructure and efficient data access are two important pieces of an effective workplace recovery solution, a third, and usually most overlooked, is the human element.  The stress of workplace relocation can take its toll on employees, leaving them stressed and confused.  Keeping staff members happy and comfortable is key to maintaining productivity as well as a successful business continuity plan.  For this reason, data centers can offer value-added amenities and features for their customers’ employees.  Lam Cloud Management’s Cranbury data center, for example, features a fully-functioning technology campus, complete with a conference and trade show center, as well as a tech lounge, meeting and seminar rooms, fitness center and locker rooms, cafĂ©, and more.  

Thursday, February 14, 2013

The Next Generation Deduplication Appliance is Here


- Eric Bassier, Director of Data Protection Product Marketing, Quantum, says:

Deduplication technology is maturing, but the market continues to grow.  The deduplication appliance market is expected to grow by about 20% a year for the next three years, and expected to be a $5 billion market by 2015 according to industry analyst IDC.

Companies are investing in deduplication as a means to reduce their backup windows and improve their restore SLAs, but also because it makes replication viable as a disaster recovery strategy. When only a small percentage of the original data size needs to be replicated, then disk-to-disk or disk-to-cloud replication becomes more viable for storing another copy of data in a different location. With newer backup application technologies that make it easier and quicker to restore replicated data and return to business continuance, the lines between backup and disaster recovery are starting to blur.

There are a number of approaches companies can choose for deploying deduplication.  Appliance-based deduplication solutions continue to grow and dominate the market because they offer the best choice for ease of integration, and ensure that the ‘background tasks’ associated with deduplicating data are handled in a way that does not unexpectedly disrupt IT operations.  Background tasks associated with deduplication can include space reclamation, as well as managing the deduplication block pool the big pool of ‘deduplicated’ data blocks. A dedicated appliance can use processing power to complete these tasks when the appliance is not busy with ingesting, replicating, or restoring data.

Optimizing the Data Center with a Faster, More Scalable Deduplication Appliance

The capabilities delivered by faster processors and higher density disk drives continue to race against the realities of increasing data storage requirements. New hardware components have their own challenges that need to be solved to meet customers’ expectations around availability and performance. 



Quantum’s new DXi6800 series deduplication appliances are built on a hardware architecture using 3 TB drives to reduce their data center footprint and power consumption.  By combining a purpose-built appliance architecture with Quantum’s patented variable-length, inline deduplication and high performance file system technology, the DXi6800 is able to deliver best-in-class ingest performance, as well as new features designed to improve system availability - even while benefitting from the improved density of 3 TB drives.  Another benefit of 3 TB drives is improved density and efficiency.  The DXi6800 manages to provide 3PB of capacity in just 14U of rack space – requiring half the data center footprint and power consumption of the market leader. The DXi6800 is also designed to be extremely scalable, enabling customers to maintain their investment in the DXi6800 as their data grows using a unique license-based, pay-as-you-grow approach to capacity expansion. Further, the self-encrypting drives in the DXi6800 offer hardware-based encryption both for data at rest and data in flight, without the incurring the performance penalty typically found with software based approaches. 

The DXi6800 is setting a high-water mark for performance and scalability. If the initial surge of early customer purchases and deployments in advance of the recent announcement is any indication, it’s an advancement the industry has been waiting for.

Friday, February 8, 2013

The Importance of Browser Protection

George Otte, Founder and President of Geeks on Site computer repair, says:


Although the Internet greatly enhances a computer, it also has the ability of rendering it useless. Whereas a computer user may consider restricting internet use for fears of computer harm, safe and conscious navigation is recommended.  Updating your Internet Browser greatly determines the vulnerability of a computer when a user is online. The following information provides helpful tips to keep your computer safe from harm’s way.

Update your Browser.
Like everything else in the computer world, website technology is developed at exponential rates. The demand for the ‘newer and better’, causes companies to create new tools that allow a better user experience. These tools are generated with state of the art technology that demands newer implementations by browsers. Browser developers work hard to satisfy these demands, as they would otherwise lose grounds to rival companies. This race often causes software imperfections which can make a browser vulnerable to hackers and viruses. Since malware is also constantly being updated, browser developers create security patches updates in an attempt to protect their users. Major web browsers such as Internet Explorer, Mozilla Firefox, Google Chrome and Safari usually notify users of these updates and may even update their browsers automatically. Updating your browser allows you to protect yourself against updated malware.

Viruses and malware to avoid.
A virus is software designed to damage your system’s functional components. Malware is software designed to spy and copy valuable information off your browser or hard disk drive.  Some malware may even be designed to hijack and take control over your computer. Among these two categories of ill-intentioned software are:
  • Key Logger- collects critical keyboard stroke information and sends it to hackers.
  • Root Kit -extracts information and in the process, affects system functionality. It may delete or corrupt system drivers.
  • Flaw Exploits - copies login and browsing information. May also delete or corrupt system drivers.
  • Denial of Service - prevents the user from accessing the Internet by consuming all network access resources and demands monetary ransom for the repair.

Ways to Protect your Browser.
There are many ways to protect your computer from malware:
  • Smart online behavior: avoid suspicious websites and dubious links.
  • Avoid downloads from third party sites: Always download software from their mother sites.
  • Delete Spam Email: Do not open junk mail or click on links from unknown senders.
  • Close Pop Ups: Pop ups usually contain malware, ready to be downloaded upon that innocent click.
  • Avoid using foreign storage media: your friend or coworker may be a careless user and has hidden viruses in their flash memory stick. Buy, use, and protect your own. Avoid lending it.
  • Install only One Antivirus Program: update it and run its system scan periodically.  It’s important to install only one antivirus program because running two might cause a conflict and render them both ineffective. Make sure your antivirus has antimalware software (a.k.a. antispyware). Make sure there’s only one antimalware program installed on your computer to avoid threatening conflicts.
  • Activate your Firewall: If your system does not use a third party software firewall, the original Windows firewall should be activated. Firewalls monitor all accesses to a computer.
  • Spam Filters sort your emails: A good spam filter will automatically prevent emails containing viruses and malware from entering your inbox.

There are many threats on line but there are many more ways to protect yourself from them.
Protecting your computer from malware is not difficult if you’re careful. Update your browser, plug-ins and antiviruses from their mother sources constantly. Keep an eye out for suspicious websites and links, and you should be able to navigate the internet freely and safely!

Thursday, November 22, 2012

The New Privacy Environment: European Union Leads the Way on Personal Data Protection


- Andy Green, Technical Content Specialist at Varonis, says:

We all understand the risks in accidentally revealing a social security number. But are there other pieces of less identifying or even anonymous information that taken together act like a social security number? The European Union is breaking new ground on consumer privacy as it begins to reform its own regulations. The EU’s broader ideas on personal identity have even made their way across the pond into proposed new US regulations.

The history of the European Union’s consumer privacy and data security regulations begins with its 1995 Data Protection Directive–or EU 96/46/EC for security wonks. EU directives provide guidance to its member nations’ legislatures, who then are free to craft their own specific laws. The DPD has been influential in shaping the vocabulary and, less charitably, the jargon of the consumer privacy discussion on both sides of the Atlantic.

In the US, the starting point for discussion on data security is Sarbanes-Oxley, which became law in 2002. In comparing and contrasting the two, it’s fair to say the DPD was more focused on securing consumer information, but more inclusive—unlike SOX--in covering both public and private companies. To this day in the US there’s currently no single comprehensive law on consumer privacy.

The EU’s original directive is significant because it defined personal data as “information relating to an identified or identifiable person.” For example, by EU rules, street address, name, and phone number are personal data; height, eye color, and model of car you drive are not. This notion of personal data as a type of key is part of the definition used in privacy laws outside the EU--including the US. In North America, though, we’ve come up with our own term for personal data, calling it instead “personally identifiable information” or PII.

By the way, the EU regulators intentionally created a less explicit definition of personal data so that it would encompass new technologies. In 2012, data related to an identifiable person could now be an email address, IP address, and for some EU nations, even a photo image. 

To bring the story up to date, security experts began to realize that along with personal data there was other data--let’s call it quasi-personal--that if released could also be used to relate back to an individual. The data magic to accomplish identification typically requires matching a collection of anonymous data points-- birth dates (or years), zip codes, ethnicity, and perhaps even car model driven--against publicly available databases. 

For example, there are well documented cases involving anonymized hospital discharge records subsequently used to re-identify the original patients!

With Facebook now up to 1 billion active users, it’s fair to say that the Web is overflowing with personal data at all levels of detail. Essentially social networks have provided hackers—the new ominous player on the scene—with a huge public repository to match against (c.f. Matt Honan).

To get a better understanding of how it’s possible to re-identify an individual, let’s review a variation on the aforementioned case. While the technique is not always guaranteed to uniquely identify a person (this depends on the available related information), it can often produce a narrowed down list of highly likely subjects.

Suppose, for argument’s sake, a European mortgage company analyzes a health report from a large public hospital. The records show that five individuals were being treated for a rare disease. Their ages were also published. Assuming the patients live near the hospital, the mortgage lender then simply filters its database on zip code and birth year. Working with a smaller set of records, it then scans social media sites or other online forums, filtering on the retrieved names and other data, all the while looking, for say, “get well” messages. If it finds a few matches, and with the additional new data points from the social site … I think you see where this is leading.

The good news is that the EU countries have long recognized that their laws have not kept pace. And the EU governing body is currently in the process of reforming the 1995 directive, taking into account the new realities of public data on the Web and the blurring of personal and anonymous data. To get a sense of the EU’s new thinking on personal data, refer to this work-in-progress paper.

And there are also rumblings of change in the US along the same lines as the EU reforms. Keep an eye here to Data Center Post and to our own blog at blog.varonis.com, where we'll be writing more about US laws and what this will all mean for your company’s data protection policies in future posts.

Wednesday, September 26, 2012

65% of organizations are not confident data is protected during migration


- David Gibson, VP of Strategy, Varonis (www.varonis.com), says:

Recently we conducted an industry survey that revealed some interesting results around data migration and security.  While 95% of organizations move data at least once per year, 65% admitted that they were not confident that sensitive data was protected during a migration. While migrations and consolidations affect virtually everyone, 96% of respondents reported concerns when performing data migrations, with many leaving their data overexposed and vulnerable.

Respondents listed the most challenging and time consuming aspects of performing data migrations as maintaining availability (68%), identifying and cleaning up old, unused or redundant objects (67%) and keeping data safe by ensuring correct access permissions (59%).

Despite these security concerns, 65% admitted that they were not very confident that sensitive data was only accessible to the right people during a migration. In fact, 79% admitted that they could not guarantee that their folders and SharePoint drives were safe from global access groups, with one third of these admitting that unprotected folders were rampant or unidentifiable. This is particularly worrying as nearly a third of migrations and consolidations are due to mergers and acquisitions, often leaving unprotected folders open to thousands more people after a migration. 


The survey underscores that maintaining who has access to what is an ongoing problem for organizations. With IDC estimating that 90% of the 1.8 zettabytes generated in 2011 is unstructured and predicting that over the next decade, the information managed by enterprise data centers will grow by a factor of 50, the scale of this problem is likely to explode even further - making manual management of permissions and migration virtually impossible.

Which features would these pros like in a technology to help automate migration activities?  Most hoped for a solution that could provide easy selection criteria for choosing what data to be moved, automate incremental copies (allowing users to use source data during the migration), and automate permissions optimization.

The data migration survey was conducted by Varonis in August 2012 with 200 IT professionals of whom one third were C-level executives. 41% of those questioned were from companies with 5,000 employees or more.  To download the full data migration research report, visit http://www.varonis.com/research/#data-migration


Wednesday, September 5, 2012

Five Ways to Maximize Virtualization Strategies with Power Management Software



Hervé Tardy, vice president and general manager of Eaton's Distributed Power Quality Business Unit (http://www.eaton.com/Eaton/index.htm), says:

Eaton Corporation, an industry leader in power management solutions for virtual environments, recently announced five strategies for information technology (IT) and data center managers to maximize the benefits of virtualization. These strategies, released during VMworld® 2012, describe best practices for VMware® users to preserve business continuity and data integrity through the VMware vCenter™ platform.
  • Enhance productivity with integrated power management solutions

Implement power management software that integrates within the vCenter dashboard to view, monitor and administer all server, storage and power management assets through a single console, as well as receive power alarms in the same window as server and virtual machine alarms.
  • Trigger live migration to protect data

To improve uptime and prevent data loss during an extended power outage, leverage the latest power management software solutions that can automatically trigger live migration, transparently moving virtual machines from an affected server to another server on the network.
  • Automate site recovery processes

To further enhance response time and business continuity, VMware Site Recovery Manager users can implement software solutions that recognize power interruptions and provide automatic virtual machine synchronization and immediate initiation of a backup site.
  • Prioritize loads to enhance response time during power disruptions

Prior to a power disturbance, IT managers should proactively prioritize virtual machines within vCenter so that automated power management software recovery processes can restart the most critical machines at the recovery site, while less critical machines can safely shut down to preserve data integrity. 
  • Extend UPS runtime to protect virtual machines

In the event of an extended outage, business continuity and disaster recovery processes rely on sufficient UPS battery runtime to protect data and critical hardware. IT managers can bolster VMware’s vMotion™ capabilities by installing software that automatically consolidates virtual machines and safely shuts down idle servers in the event of a power failure so that adequate backup time is provided.

To learn more about Eaton’s solutions for virtualization platforms, visitwww.eaton.com/virtualization

Monday, July 2, 2012

What’s Stopping the Cloud from Colossal Growth in Europe?


- David StottSenior Director of Product Management at PerspecSys (http://www.perspecsys.com/), says:

The European Commission acknowledges that Europe must become more ‘cloud active’ to stay competitive in the global economy. And while public cloud adoption in the EU is increasing, it is fragmented in some areas and lags the US by some 3- 5 years. IDC’s recent study “Cloud in Europe: Uptake, Benefits, Barriers, and Market Estimates” assesses the European cloud market, identifies key cloud barriers, and makes straightforward recommendations on how to remove them.

IDC surveyed European business users and consumers and discovered that a full 64% of EU businesses currently use the cloud, and an additional 25% are planning or thinking about it. Those that use cloud applications now, want to expand.

So what’s stopping the cloud from colossal growth in Europe? The research uncovered 12 key obstacles ranging from data residency and security issues to slow performance and limited tax incentives for capital spending. But the majority of survey respondents (62.2%) cited four specific barriers, primarily related to data control:
  1. Legal jurisdiction: Where the does the service reside? Where does the data reside? What if I don’t want my data stored in a specific country?
  2. Security and data protection: Who is responsible for security, data protection, and backups? What happens if something goes wrong?
  3. Trust: How do I tell which services are reliable? Who guarantees data integrity and availability?
  4. Data access and portability: Once I sign a contract, how much interoperability will I have? Can I interact with different services?

Data control is the common denominator, and Europe must take steps to empower data controllers if it wants to maximize cloud adoption benefits. Those surveyed offer clear guidance on what the EU could do, including enacting specific rules on service provider accountability; guaranteeing application and data portability between services; implementing an EU-wide security certification program; clarifying and harmonizing data residency and legal jurisdiction regulations; and fostering EU-wide standardization of cloud services.

These are great suggestions. But aside from regulatory policy changes that could take a long time to deliver, the group also states that demonstrated current success by peers and strong evidence of cloud benefits would greatly enhance adoption. This type of success is possible today with a cloud data protection gateway that allows European cloud users to control their data completely when using cloud SaaS applications. The PersepcSys PRS (Privacy, Residency and Security) Server lets data controllers configure their cloud systems with data protection protocols that overcome the primary residency and security obstacles that are holding Europe back.

PerspecSys Inc. is a leading provider of cloud data protection solutions that enable mission-critical cloud applications to be adopted throughout the enterprise. PerspecSys removes the technical, legal and financial risks of placing sensitive company data in the cloud. PerspecSys accomplishes this for many large, heavily regulated companies across the world by never allowing sensitive data to leave a customer’s network, while maintaining the functionality of cloud applications. Based in Toronto, PerspecSys Inc. is a privately held company backed by investors that include Intel Capital and GrowthWorks. For more information please visit http://www.perspecsys.com/ or follow on Twitter @perspecsys.

Friday, June 22, 2012

Lessons from the Heroku/Amazon Outage


Nati Shalom, CTO of GigaSpaces (http://www.gigaspaces.com/), says:

Late last week we experienced the third significant AWS outage in the past 14 months, as reported by Justin Lee in his report Heroku, Pinterest Among Sites Knocked Offline in Amazon Data Center Outage on theWhirr magazine:
An Amazon data center in Ashburn, Virginia suffered a power outage at 9:45 p.m. PDT on Thursday, causing some websites using AWS cloud technology to go offline. High-profile websites like Heroku, Pinterest, Quora and HootSuite saw downtime, as well as many smaller sites.
In this post I'd like to briefly address the lessons from this experience, and more importantly, focus on the lessons from this sort of failure and their effect on public PaaS offerings, such as Heroku.
Lesson from the Heroku Outage: Choose the Right PaaS for the Job
One of the promises of PaaS is productivity. PaaS providers like Heroku claim to increase productivity by abstracting the user from the details of the underlying infrastructure, and even go so far as to claim that PaaS makes application operations redundant.
Lesson 1: Choose the Right PaaS for the Job
The main lesson from this outage is that relying on the PaaS provider to carry all your operations isn't always a safe bet. When we move to PaaS we still need to understand how they run their disaster recovery, high-availability, and scaling procedures. Heroku-like PaaS also forces you to a lowest common denominator approach to dealing with continuous availability and scalability. In reality, however, there are many tradeoffs between scalability, performance, and high availability. The best fit between those tradeoffs tends to be application specific, so compromising on a lowest common denominator could be less productive and more costly at the end of the day.
Which brings me to the last point in this section -- PaaS was meant to provide a higher productivity for running our apps on the cloud by abstracting the details of how we run our application (the operation) from the application developer. The black-box approach of many of the public PaaS offerings, such as Heroku, is often an extreme measure in this regard. There is often a close coupling between what the application does and the way we run it. A new class of Open PaaS platforms such as Cloudify, CloudFoundry, and OpenShift offer a different open source alternative that gives you more control of the underlying PaaS platform. Cloudify takes it even further, providing an open recipe model that integrates with the likes of Chef, enabling you to easily customize and control your operations without affecting developer productivity.
Lesson 2: Database Availability Must Address Datacenter Failure
The other area that Heroku, and to be honest, most other PaaS offering don't adequately address is database high-availability, which is obviously a tough area. Specificaly, in the event of data center failure or availability zone failure, as in the present case. To deal with database availability, it is necessary to ensure real-time synchronization of the database across sites. The example at the bottom of this post refers to a specific way this can be done, between two mySql instances running on Amazon and Rackspace with Cloudify.
Lesson 3: Coping with Failure, Avoiding a Single Point of Failure
The general lesson from this and previous failures is actually not new. To be fair, this lesson is not specific to AWS or to any cloud service. Failures are inevitable, and often happen when and where we least expect them to. Instead of trying to prevent failure from happening we should design our systems to cope with failure.
The method of dealing with failures is also not that new -- use redundancy, don't rely on a single point failure (including a data center or even a data center provider). Automate the fail-over process, etc...
Haven't Learned from Past Lessons?
The question that comes out of this experience IMO is not necessarily how to deal with failures (those lessons are as old as the mainframe or even older), but rather -- why are we failing to implement the lessons? Assuming that the people running these systems are among the best in the industry makes this question even more intresting. Here is my take on it:
·         We give up responsibility when we move to the cloud: When we move our operations to the cloud, we often assume that we're out-sourcing our data center operation completely, including our disaster recovery procedures. The truth is that when we move to the cloud we're only outsourcing the infrastructure, not our operations, and the responsibility of how to use this infrastructure remain ours. 
·         Complexity: The current DR processes and tools were designed for a pre-cloud world, and do not work well in a dynamic environment, such as the cloud. Many of the tools that are provided by the cloud vendors (Amazon in this specific case) are still fairly complex to use.

Implementing Past Lessons in a Cloud World
The first point is is easy -- we need to assume full responsibility for our applications' disaster recovery procedures, in the cloud world just as if we were running our own data center. The hard part in the cloud world is that we often have less visibility, control, and knowledge of the infrastructure, which affects our ability to protect our applications -- and each sub-component of our application -- from failure. On the other hand, the cloud enables us to spawn new instances easily on various data center locations, a.k.a Availability Zones. 
And so, most failures can be addressed by moving from the failed system to a completely different system regardless of the root cause of the failure. Therefore, the first lesson is that in the cloud world it is easier to implement disaster recovery plans, by moving our application traffic to a completely different redundant system in a snap, rather than trying to protect every component of our application from a failure. If we're willing to tolerate a short window of downtime, we can even use an on-demand backup site rather than pay the consistent cost and overhead of maintaining a hot backup site.
Which brings me to the next point: What do we need to build such a solution?
A consistent redundant environment that is ready to take over in case of failure needs to include the following elements:

·  Workload Migration: Specifically, the ability to clone your application environment and configuration in a consistent way accorss sites, and on demand.
·  Data Synchronization: The ability to maintain a real-time copy of the data between two sites. 
·  Network Connectivity: Enabling the flow of network traffic between two sites.

Which leads to the second challenge: Complexity. Here, I would use an example of a simple web-app and show how we can easily create two sites on demand. I would even go so far as to set this environment on two separate clouds to show how we can ensure an even higher degree of redundancy by running our application across two different cloud providers.
A Step by Step Example: Fail-Over from AWS to Rackspace
In this example, we picked Amazon and Rackspace as the two target sites. The same solution would also work between two availability zones in Amazon or data centers. We've also tried the same example with a combination of HP Cloud Services and a flavor of a private cloud.
The example demonstrates a very simple web application with global load-balancer (Rackspace), and a Web application (Pet Clinic) based on Tomcat as the Web front end and MySQL as the database.
On both ends we used GigaSpaces XAP Transactional WAN replication as a replication channel between the two instances of MySQL and Cloudify to handle the workload migration between the sites.
The Goal: Fail-over with no change to the target application
The goals that we set for ourselves were seamlessness and no change to the target application or database. We achieved this by plugging the replication service into the existing instances of MySQL. The replicating service listened to the MySQL events and replicated every change to its peer MySQL instance. Cloudify enabled us to clone the same application in both Amazon and Rackspace while maintaining a consistent configuration setup as well as consistent scaling and fail-over SLAs. Cloudify does this by abstracting all the information through portable recipe definitions. Cloudify wraps the application instances with its management and control services based on the definition provided in the recipe. This enabled us to clone the environment as well as add elastic scaling without changing the target application (Pet Clinic in this case).
You can read the full details, including code references on Github, in Dotan Horvits' blog post: AWS Outage Thoughts on Disaster Recovery Policies.


Thursday, June 21, 2012

Manage Costs & Risk with Defensible Deletion

- Jim McGann, Index Engines (http://www.indexengines.com/), says:

Organizations have become extremely good at stockpiling electronic data – hoarding it, in fact. Companies continue to add storage and disk space, allowing users to keep more emails and documents rather than purging, resulting in an immense and ever-growing data lake, putting companies at risk.

Between networks, desktops, disaster recovery backup tapes and other environments, documents and emails are copied and replicated several times, making the bulk even worse. Data sits hidden on legacy backup tapes, servers and hard drives like Pandora’s Box, containing unknown information.

For this reason corporate IT departments are embracing defensible deletion strategies, where they can legally purge large quantities of historical data, without violating compliance requirements or company policy. A viable place to start is to break down your data environments and prioritize the data that represents the most risk and liability – creating a tiered classification based on storage capacity and presumed data risk. The highest risk data environments are typically email servers and legacy tapes. Using this approach can make a monumental task much more manageable.

Understanding user files and email across the corporate network is crucial to developing and applying policy. Data mapping is used to profile content across all environments, allowing greater understanding of what data exists and its location. It can provide information such as age of the data, owner, locations, email sender/receiver and even sensitive keywords. An actionable data map can then execute the decisions to keep data or defensibly delete what is no longer required.

Companies need to understand what exists, develop a plan to manage it, and take action. In today’s legal and regulatory climate it is a risky proposition to sit on potential “smoking guns” and hope that judges and lawyers are not technology savvy enough to request this data.

White Paper Link and Write-up: Defensible Deletion Methodology – Link:

http://go.indexengines.com/DDWP 

Defensible deletion has become a key records management strategy for organizations facing frequent litigation. Saving all data, and not managing it according to current regulations and compliance requirements, and those of tomorrow, is too risky. This White Paper will help you kick off a defensible deletion program, defining a methodology and workflow that is manageable and achievable.

Wednesday, June 20, 2012

Safeguarding Sensitive Financial Data

- Chris Jensen, Financial Services Expert, TeleSign (http://www.telesign.com/), says:


Founded in 1819, BankNewport is one of the oldest mutual savings banks in the United States. This historic institution is providing an innovative security technology to keep its customers protected from fraud. Partnering with TeleSign, a market leader in Internet fraud prevention and Intelligent Authentication, BankNewport has implemented tokenless two-factor authentication to secure online account access for customers.

Continually evolving security threats require companies to adopt a layered approach to fraud prevention. Today, many organizations still leverage low-cost challenge questions, however these questions are easily hacked or socially engineered. Instead of relying on these insecure methods or provisioning hardware to users or maintaining software, BankNewport is decreasing security threats by leveraging a technology that is already part of every user’s life, the telephone.

The phone has become the de facto solution to provide layered security because it is easy to use, easy to deploy, and easy to manage. BankNewport is leveraging TeleSign’s phone-based two-factor authentication (2FA) to effectively protect accounts from compromise by employing the user’s phone as the second factor of authentication. With phone-based two-factor authentication BankNewport maintains higher security without increasing complexity or costs associated with traditional methods of authentication.

How it Works
  • ·         User attempts to sign on with their username and password
  • ·         TeleSign sends an automated voice call or SMS to the phone number on record with a one-time PIN code
  • ·         User enters this one-time PIN code onto the website and is authenticated

“Social engineering has made the answers to challenge questions widely available and easy to find. We provide our customers an extra layer of security without compromising their user experience,” said BankNewport eCommerce Assistant Manager, Sonia Williams. "TeleSign 2FA was easy to integrate and has already reduced our help desk costs and given users confidence that they can securely sign in to their bank account and securely complete transactions."
The integration of TeleSign 2FA shields accounts from unauthorized logins and secures account access from unrecognized devices. Verifying the user through a personal device, such as the phone, makes for a more secure banking ecosystem, helping financial institutions like BankNewport address FFIEC guidelines.
TeleSign Two-Factor Authentication adds a critical layer of security beyond username and password. By leveraging the phone as an authentication device, TeleSign improves the user experience while reducing operating costs associated with traditional multifactor authentication methods.

About TeleSign
Every second, of every day, TeleSign protects the world's largest Internet and Cloud properties against fraud. TeleSign Intelligent Authentication provides an easy-to-implement and powerful method for identifying and substantially reducing online fraud and spam using the most widely deployed technology — a user’s phone. The company protects 2.5 billion downstream accounts in more than 200 countries, offering localization services in 87 languages. In 2011, TeleSign ranked #15 on the Deloitte Technology Fast 500™ and was named Visionary in Gartner’s User Authentication Magic Quadrant.

For more information about TeleSign, visit www.telesign.com

Thursday, June 14, 2012

Index Engines Offers a Solution to the Legacy Backup Tape Dilemma


- Jim McGann, VP of Information Discovery, Index Engines (http://www.indexengines.com/), says:

IT professionals regularly struggle with the dilemma of having stacks of legacy backup tapes and ask the question, “Do we hold onto them or not?” Many companies do not have an established policy in place to purge the tapes after they have outlived their disaster recovery purpose, so the tapes just pile up.  The obvious solution: destroy or recycle them.  However, it’s much more complex than that, and due to compliance and legal requirements, IT departments are taking a closer look at these tapes, to eliminate their associated risks while still keeping what is needed.

Two of the most obvious and primary concerns of legacy backup tapes are the importance of their content and the security of that content.  Lying around, these tapes have the potential to pose security risks and thus possess inherent liability. That’s the problem, and now Index Engines has created the solution.

Index Engines, a New Jersey-based enterprise  information discovery company, recently introduced a free “Data Assessment Program for Backup Tapes.” This new program provides a map of all your data on backup tapes, such as unmanaged pst’s and ex-employee files, to better understand the user environment, help establish appropriate policies and promote defensible deletion of irrelevant content.   Qualified enterprise participants in the Data Assessment Program are given the opportunity to process up to five tapes, which will be fully indexed and a report of the content will be generated using Index Engines’ comprehensive enterprise reporting.     

Index Engines has developed an innovative and automated method for data mapping that directly indexes and analyzes backup tapes without the requirement of original software or restoration processes.  This data mapping approach allows users to benchmark the sensitivity of data as well as develop an information governance plan.

The Data Assessment Program demonstrates a unique way to deal with the piles of legacy tapes that have stacked up over the years.  So when it is time for a little office cleaning — or a lot — don’t be alarmed. If you have properly assessed your data, decisions on what can be archived and what can be defensibly deleted can be made confidently to reduce risk and eliminate stacks of unneeded tapes

About the Author
Jim McGann is the eDiscovery expert and VP of Information Discovery for Index Engines (www.indexengines.com). Based in New Jersey, Index Engines’ patented discovery platform provides corporate and legal clients with comprehensive insight into their data to simplify information discovery, classification and management. Email Jim at jim.mcgann@indexengines.com.

Thursday, May 24, 2012

Why Businesses Need Data Center Services








- Pooja Chopra, spokesperson for Spectranet (www.spectranet.in), says:

It has been reported by the U.S. Bureau of Labor Statistics that the majority of SMEs never recover from catastrophic data loss.

In a recent research International Data Center reported that 58 percent of the companies are doing just a local back-up.

Local backups are good and beneficial considering the first step of protection they provide. These are very effective against initial errors such as manual intervention with data, software or hardware failures but these fail when it comes to protection against theft, disaster or multiple software/hardware failure due to voltage.

Seeing the day-to-day growing dependence, it may not be exaggerating that businesses thrive on data and Internet. Yet, it is surprising to see that how businesses are taking risks without thinking much to invest in a data protection plan. Enterprises need to understand that unlike physical assets such as buildings and equipments which can be resurrected quickly through insurance, data loss is practically incurable. It is the most determining factor for the existence of a business. Hence, the need of the hour is to think about enterprise data security plan.

Data security plan, in order to be completely fortified, should meet the three ‘C’s of safe and reliable data center:

Comprehensive: The data plan for enterprises should be universal and unique to fight the threats and challenges ahead. One data plan should be able to work against all the odds such as manual errors, application failures, natural and man-made disasters such as fire, theft, floods etc.

Convenience: It should be plug-n-play for your business and IT department. The maintenance of the servers and security of data should be the worry of data center services providers and not yours. Without changing much into your existing IT architecture, they should be able to provide you the necessary or expanded bandwidth whenever necessary without nudging you for constant care.

Costs: This is the most crucial part. The data center services should fit into your budget. Your vendor should not be increasing the amount of the package or bandwidth costs on monthly basis. The SLA and contract should be with a focus on your business and computing needs.

So, to overcome the challenge of data protection, data center backups are the best method to retain your data and ensure its well being. The data center services providers are offering increasing bandwidth and ubiquity at any location. The data center is remotely monitored. Human involvement is limited to IT engineers and expert maintenance team. The geographical location of data centers also minimizes the risk of earthquake, floods and other natural calamities. They are often situated at low risk zones.

Most of companies and enterprises are opting for the data center solutions after imbibing the role of data in the growth of their ventures. India clearly emerges as the winner seeing the advancements in technology and cost effective trends in data center realms. Providers like Spectranet offer tier- 3 infrastructure set up to equip the companies against any data threat. In the times of disasters, data center India provides quick recovery progress and help business continuity by retrieving the data in the shortest turnaround time.