Showing posts with label Regulatory Compliance. Show all posts
Showing posts with label Regulatory Compliance. Show all posts

Tuesday, March 5, 2013

N8 IDENTITY ENABLES COMPLIANCE AND REDUCES RISK WITH ITS NEW APPROACH TO IDENTITY AND ACCESS GOVERNANCE


Jay O’Donnell, president and CEO of N8 Identity, says: 

The majority of vendor solutions take a reactive approach to identity management (IAM) by allowing policy violations to occur and then reporting on access violations after the fact. Our flagship product, Employee Lifecycle Manager (ELM), is breaking new ground in the IAM industry by taking a proactive approach and preventing inappropriate access from being granted and identity governance violations from occurring in the first place. This ensures continued compliance with SOX, HIPAA, PIPEDA and other federal security regulations.

Enterprise customers are starting to understand that reporting and attestation are not enough to meet their identity governance requirements. ELM is unique in the industry today in that it enables continuous compliance thereby reducing risk significantly. It also generates enormous process efficiency and cost savings within an organization, which is a huge advantage. Support costs are decreased drastically and help desk calls become almost nonexistent, which minimizes the business burden while simultaneously improving IT agility.

ELM leverages its customers’ existing investment in identity and related infrastructure, eliminating the need to ‘rip and replace’ so customers need not worry that any existing employee information will be lost in the upgrade process. Furthermore, onboarding processes from all departments are unified and streamlined which cuts the onboarding time down significantly and enables new employees to be productive immediately. This boost in efficiency allows time and budgets to be allocated more intelligently as needed.

ELM provides a unified set of business processes, which helps the user experience remain consistent across global organizations so that all facets of the company are on the same page.  This approach solves compliance requirements by incorporating organizational controls within the business process that proactively prevent access policy breaches.  In addition, the strong audit and reporting capabilities within ELM are essential for meeting SOX, HIPAA, PIPEDA and other federal security regulations. 

Thursday, November 22, 2012

The New Privacy Environment: European Union Leads the Way on Personal Data Protection


- Andy Green, Technical Content Specialist at Varonis, says:

We all understand the risks in accidentally revealing a social security number. But are there other pieces of less identifying or even anonymous information that taken together act like a social security number? The European Union is breaking new ground on consumer privacy as it begins to reform its own regulations. The EU’s broader ideas on personal identity have even made their way across the pond into proposed new US regulations.

The history of the European Union’s consumer privacy and data security regulations begins with its 1995 Data Protection Directive–or EU 96/46/EC for security wonks. EU directives provide guidance to its member nations’ legislatures, who then are free to craft their own specific laws. The DPD has been influential in shaping the vocabulary and, less charitably, the jargon of the consumer privacy discussion on both sides of the Atlantic.

In the US, the starting point for discussion on data security is Sarbanes-Oxley, which became law in 2002. In comparing and contrasting the two, it’s fair to say the DPD was more focused on securing consumer information, but more inclusive—unlike SOX--in covering both public and private companies. To this day in the US there’s currently no single comprehensive law on consumer privacy.

The EU’s original directive is significant because it defined personal data as “information relating to an identified or identifiable person.” For example, by EU rules, street address, name, and phone number are personal data; height, eye color, and model of car you drive are not. This notion of personal data as a type of key is part of the definition used in privacy laws outside the EU--including the US. In North America, though, we’ve come up with our own term for personal data, calling it instead “personally identifiable information” or PII.

By the way, the EU regulators intentionally created a less explicit definition of personal data so that it would encompass new technologies. In 2012, data related to an identifiable person could now be an email address, IP address, and for some EU nations, even a photo image. 

To bring the story up to date, security experts began to realize that along with personal data there was other data--let’s call it quasi-personal--that if released could also be used to relate back to an individual. The data magic to accomplish identification typically requires matching a collection of anonymous data points-- birth dates (or years), zip codes, ethnicity, and perhaps even car model driven--against publicly available databases. 

For example, there are well documented cases involving anonymized hospital discharge records subsequently used to re-identify the original patients!

With Facebook now up to 1 billion active users, it’s fair to say that the Web is overflowing with personal data at all levels of detail. Essentially social networks have provided hackers—the new ominous player on the scene—with a huge public repository to match against (c.f. Matt Honan).

To get a better understanding of how it’s possible to re-identify an individual, let’s review a variation on the aforementioned case. While the technique is not always guaranteed to uniquely identify a person (this depends on the available related information), it can often produce a narrowed down list of highly likely subjects.

Suppose, for argument’s sake, a European mortgage company analyzes a health report from a large public hospital. The records show that five individuals were being treated for a rare disease. Their ages were also published. Assuming the patients live near the hospital, the mortgage lender then simply filters its database on zip code and birth year. Working with a smaller set of records, it then scans social media sites or other online forums, filtering on the retrieved names and other data, all the while looking, for say, “get well” messages. If it finds a few matches, and with the additional new data points from the social site … I think you see where this is leading.

The good news is that the EU countries have long recognized that their laws have not kept pace. And the EU governing body is currently in the process of reforming the 1995 directive, taking into account the new realities of public data on the Web and the blurring of personal and anonymous data. To get a sense of the EU’s new thinking on personal data, refer to this work-in-progress paper.

And there are also rumblings of change in the US along the same lines as the EU reforms. Keep an eye here to Data Center Post and to our own blog at blog.varonis.com, where we'll be writing more about US laws and what this will all mean for your company’s data protection policies in future posts.

Wednesday, October 19, 2011

Border Games: Do You Know Your Data Privacy Laws?

- Jim Latimer, chief strategy officer at CentriLogic (http://www.centrilogic.com/), says:

In today’s highly-regulated business world, the geographic location of data is as important as the technology that keeps it accessible and secure. Not only is the way data stored important to maintaining corporate policies, but so too is keeping data in a physical location that doesn’t breach industry regulations.

There's no lack of rules governing business today, such as HIPAA in healthcare and Sarbanes-Oxley for public companies. Then there are the ever-growing list of corporate policies and customer service agreements to meet. Of course, businesses must be adept when it comes to securing their data and networks, and must understand the implications of physical storage locations. This is a lot for any single company to manage efficiently today, in our world of razor-thin IT budgets and staffs.

Another wrinkle concerns The Patriot Act, which grants the U.S. government the power to intercept or seize any data stored in or that passes through the U.S., regardless of where the data was collected. This summer, Microsoft noted that data stored on its EU cloud service is subject to The Patriot Act, since Microsoft is based in the United States.

The question of the cloud

A growing number of businesses are taking their corporate (including customer) data to the cloud, but there has to be caution around where sensitive data is stored and who might have access to it. Businesses that operate internationally and collect personal data around the world need to understand the applicable privacy and data compliance laws. For example, storing private customer data from a European nation in a U.S.-based data center where Patriot Act provisions expose that data to inspection and seizure without informing the targeted individuals would breach the EU's Data Protection Directive.

Some companies hesitate to move critical applications and data to the cloud, given concerns around how they will control different data sets and deal with the complexity of compliance. Managing cross-border data storage and access requires planning, legal review and close collaboration with outsourcing and hosting partners.

The cloud has become a global phenomenon, with applications and data stored around the world in a way that’s invisible to the end-user. Yet data is geographic (or at least geopolitical) in nature and has to be treated with that reality in mind. This will be a challenge for data center managers and CIOs, as companies increasingly use the cloud and outsourcing to run their businesses. If cross-border risk management isn't part of your data strategy -- it's time to make it so.

Thursday, April 28, 2011

Protecting Your Data From Breach Attempts and Unauthorized Access


- Dana Tamir, senior product marketing manager at Imperva (www.imperva.com), says:

Data is constantly at risk from hackers that launch advanced, automated, and large scale attacks as well as from malicious and privileged insiders that may abuse their access for economic or personal gain. Data Security has also become subject to intense regulatory scrutiny – so much so that any viable Data Security solution must be able to address the requirements imposed by auditors and regulators. Organizations need to protect data which lives on file servers and databases, and is accessed by users via a variety of methods. Addressing only one part of the data lifecycle is not enough. This is why Imperva SecureSphere provides data security solutions to protect applications and the underlying databases and file servers where the data lives.

SecureSphere addresses critical datacenter concerns and regulatory compliance requirements. With all the threats to data security in today's IT landscape, and the growing sophistication of data related attacks, these solutions have become a top priority in datacenters. The concerns are even bigger where information technology turns to cloud computing, virtualization and outsourcing. Access controls, monitoring and enforcement of corporate policies are key to ensure data is stored and accessed in an appropriate manner.

SecureSphere enables organizations to implement processes and controls that meet regulations such as PCI and SOX, and protect data from breach attempts and unauthorized access.

The biggest challenge IT managers face today is implementation of effective controls and addressing regulatory requirements (such as auditing access to regulated data, limiting access rights and scanning for vulnerabilities) across heterogeneous, distributed platforms. Sensitive data is constantly at risk from hackers that launch advanced, automated, and large scale attacks as well as from malicious and privileged insiders that may abuse their access for economic or personal gain. The attacks are becoming more sophisticated and more complex, and as a result IT managers need solutions that provide in-depth, contextual analysis of events.

SecureSphere protects sensitive data from hackers and malicious insiders, provides a fast and cost-effective route to regulatory compliance and establishes a repeatable process for data risk management. SecureSphere Data Security Solutions provide:
  • Data Breach Prevention: Real-time protection against hackers and malicious insiders targeting sensitive data
  • Regulatory and Industry Compliance: Fast and cost-effective route to compliance with full visibility into data usage, vulnerabilities and access rights
  • Data Risk Management: Continuous and repeatable process for identifying and mitigating data risk
Powering the SecureSphere Data Security Suite is a common platform that provides flexible deployment options, unified management, deep analytics and customizable reporting. The SecureSphere platform enables enterprise scalability and accelerates time to value.

In order to select effective data security solutions IT and data center managers need to consider the following:

  • Regulatory Compliance: If the main driver for deploying data security solutions is compliance, make sure the solution can fully address the regulation. For database activity monitoring solutions (DAM) and file activity monitoring solutions (FAM) this typically means that the solution can provides details about each event to answer Who?, What?, When? Where? and How? The solution must monitor privileged users as they have unrestricted access to the data platform. This means the all privileged activities must be captured, regardless of the source tool or access path (direct, indirect). The solution should enforce corporate configurations and access policies. Separation of duties is key for ensuring the validity of an audit trail. To ensure the audit trail’s integrity, nobody should have the ability to access or modify the data in the audit repository. Predefined policies and reports are also important as they shorten the time to value. Make sure you can easily customize these to meet unique requirements.
  • Attack Protection: To lower the impact of a data breach and prevent attacks, consider the solution’s ability to provide real-time alerts and block attacks. SecureSphere provides comprehensive protection against sophisticated attacks such as SQL injections through integrated web application firewall (WAF), database activity monitoring (DAM) and file activity monitoring (FAM). It can also block database attacks that are preformed at the protocol level (buffer overflow, denial of service, etc.). To prevent fraudulent activity and identify compromised credentials the solution needs to identify abnormal behaviors. SecureSphere’s patented profiling capability automatically alerts, and optionally blocks, activity that deviates from observed behaviors. SecureSphere reputation-based security provides automated defense against automated attacks.
  • Attack Prevention: To lower the risk of a data breach IT must assess the vulnerability of applications and databases. SecureSphere risk explorer will enable organizations to identify areas of risk to data and prioritize remediation efforts. SecureSphere also provides the ability to remediate discovered vulnerabilities by applying virtual patches. Users with excessive rights are often at the heart of data breach events. By identifying and eliminating excessive rights and ensuring user access is limited to business need to know, organizations can significantly lower the risk of a data breach.
Imperva delivers not just traditional enterprise products, but also very large scale solutions for service providers and cloud infrastructure services, as well as product and service options that scale to meet the needs of mid-market and small businesses. SecureSphere is able to offer a wide range of deployment models, critical for meeting the unique requirements of different IT environments.

Wednesday, October 27, 2010

Government Regulations: Impacting The Data Center

- Ken Gabriel, Global Lead for ERP services at KPMG International (www.kpmg.com), says:

The government will surely implement a series of controls on stimulus spending. Companies, organizations and even state and local governments that share in the stimulus funds will need to maintain appropriate record-keeping. Transparency will become extremely important to provide insight as to how the money is spent and the need for companies to provide timely information will put more demands on technology to supply that information. That, in turn, will require the focus of the CIO in concert with operations.

When you consider the major government regulations, including HIPAA and Sarbox, what impact these regulations are having on enterprise data centers?

Many IT organizations feel the strain from anticipated demands for more detailed, timely information as a result of an expected rise in government oversight as well as a heightened regulatory environment. In the current economic environment, where many organizations are reducing their IT costs, there is a delicate balance to comply with the regulations and maintain a reasonable cost structure. With the reductions in IT staff, many companies have seen an increase in the number of control deficiencies in the past year.

What changes have these data centers had to put in place as a result of new regulations? What requirements are they being asked to meet?

With Sarbanes-Oxley, for example, IT organizations were challenged to help the operations and finance unit streamline a series of controls over financial reporting. Those that embedded their controls and utilized technology to help manage the process were able to streamline what previously may have been a complicated series of manual controls.

Government Regulations: Keep Pounding on TCO

- Idan Shoham, Chief Technology Officer at Hitachi ID Systems (www.Hitachi-ID.com), says:

Statement: "And with the government using its funds to boost the economy and businesses in particular, more government regulations and restrictions are sure to follow." Agree/disagree? Why/whynot?

Absolutely. It's all about optics, unfortunately. Citizens want to see that their hard earned tax money isn't wasted, so they demand regulation, and politicians are more than happy to oblige.

Regulation is often a good thing, but only if it's focused on real issues and not too intrusive.

For examples of regulations that came too quickly, and probably caused more harm than good, you need look no further than Sarbanes-Oxley (hugely expensive to implement, and yielding only dubious transparency) and Gramm-Leach-Bliley, which apparently enabled some of the financial shenanigans that led to the current mess.

When you consider the major government regulations, including HIPAA and Sarbox, what impact these regulations are having on enterprise data centers?

The impact on IT is actually fairly positive -- various regulations demand strong internal controls, to support governance and privacy protection programs. Internal controls depend on sound IT security, and that's exactly what IT departments have been spending on.

The impact outside of IT, it seems to me, is not so uniformly positive...

What changes have these data centers had to put in place as a result of new regulations? What requirements are they being asked to meet?

Lots of things are being handled in a more robust manner these days than in the past. Some examples:

* Better processes to deactivate access when employees and contractors leave.
* Stronger passwords that change more often.
* Periodic reviews of and corrections to user security privileges (i.e.,
access certification).
* Regular changes to privileged passwords and controls over disclosure
of those passwords.

The common threads here are to ensure that sensitive access is hard to "hack into" and that legitimate access matches a least privilege policy.

Are data centers meeting minimum guidelines or going "above and beyond"?

Well, most regulations are extremely ambiguous when it comes to IT security requirements. As a result, data centers are taking an "industry best practices" approach, which I think actually raises the bar substantially from where legislators may have placed it.

About the only widespread regulation I'm aware of that's specific with regard to IT security is PCI, and I'd say that most organizations make a pretty strong effort to comply with the guidelines in PCI, in part because they really are common sense measures.

How are these regulations impacting data centers in the health/education/government arenas?

Pretty uniformly, I'd say. The main business driver in each of these is privacy protection -- of patients, students, staff, employees, citizens, etc. That depends on internal controls, which depend on IT security.
That's a pretty strong theme..

Feel free to add anything that you think our readers (IT/data center managers; 275,000+ readership) might want to know.

The real difference today, as compared to a year ago, is that while security remains important, budgets are shrinking. Companies have to continue to deliver results, but with fewer resources.

My advice to readers is to keep pounding on TCO. If you're going to buy a privileged password management system, or an access certification product, or whatever, make sure you understand license costs, maintenance, implementation services, hardware requirements, training costs, ongoing support, etc. For some products, there is also an ROI to be had. For example, if you automate password reset processes, you can reduce help desk costs while improving password security.

Monday, October 11, 2010

Government Regulations: Impacting The Data Center (Health)

- William M. Miaoulis, Subject Matter Specialist for Phoenix Health Systems (www.phoenixhealth.com), says:

Certainly we have new and old federal laws which will continue to be expanded. In fact, Healthcare IT is directly impacted by the American Recovery and Reinvestment Act of 2009. The infusion of funds, coupled with the mandate for ‘meaningful use’ will drive the move to enhanced data capture that comes with full automation. Although most of the actual specifics are still to be defined, there is specific HIPAA legislation in the language of the Act. It appears some regulation will come directly from Health and Human Services, via the Office of the National Coordinator as well as additional legislation via the Health Information Technology for Economic and Clinical Health (HITECH) Act. As further details are defined, we’ll see regulatory requirements and restrictions coupled with implementation standards to provide a foundation for the evaluation determining compliance.

What impact are the major government regulations having on enterprise data centers?
Initial impacts include an increased need for processing power, as EMR implementations become far widespread due to government initiatives, they become more complex as well as more prevalent in the marketplace. Longer term, organizations will also have to take a harder look at redundant facilities and data to ensure that the information to treat patients is available when necessary. The ‘hybrid’ days when data redundancy was split between a paper chart and an EMR at most organizations are rapidly approaching extinction.

What changes have data centers put in place as a result of new regulations?
Changes to data centers will vary depending on an organizations risk analysis as required by HIPAA. This Risk Analysis is different for every organization, but has often times lead to enhanced environmental controls such as implementation of fire suppression systems, redundant power, enhanced cooling and better separation of data among data centers.

Are data centers meeting or exceeding minimum guidelines?
The minimum guidelines are / are not extreme. The regulations are not specific with regard to the physical security. But many Hospital Data centers are located in high risks areas. Often times in rooms which can flood or have water pipes running above the computers. Still other healthcare organizations have designed and developed data centers that maintain a high level of security and environmental controls.

How are regulations impacting data centers?
The true impact to data centers is directly attributable to the changes being forced at the adoption level. While technology is pushed at the clinical delivery sites, the need for faster, more reliable processing will be felt. With the depth of information increasing in the electronic record, and the reduction in ‘onsite’ paper chart reliance, the need for recovery processes that can provide patient data at the time of treatment becomes critical.

The importance of having data centers that are protected from both natural disasters (earth quake, flooding, and tornado) and protection from intruders will only increase the need for physically secure data centers. Understanding your current and future vulnerabilities and threats will be critical. Currently, physical security at data centers is inconsistent and haphazard at best; some are highly secure; most are not. While great effort has been put into the protection of the network infrastructure, little effort is put into understanding physical vulnerabilities and threats. The expansion of electronic data also expands the vulnerability at the data center site; a disaster or significant crisis event at a large data center could significantly cripple the healthcare network and make recovery difficult.

Thursday, September 2, 2010

Staying On Top Of Data Center and IT Regulations

- Kurt Stoever, Vice President of Service and Support at Quality Tech (www.qualitytech.com), says:

Keeping abreast of Data Center/IT Regulations can be a difficult task for a nationwide technology services company such as Quality Technology Services much less a multi-national or global firm. To allow QualityTech to focus its efforts, QualityTech staffed and trained a corporate resource responsible for compliance achievement, audit, and control.

Lesson 1: Create a corporate entity that has broad responsibility for Data Center/IT Regulations. A central organization is essential for allowing focus on and maintaining an unbiased opinion on various regulations. QualityTech’s Audit and Control Group designs the companies’ compliance roadmap, maintains regulatory awareness, performs research into emerging standards, assists clients with internal audits and designs supporting policies. QualityTech’s Audit and Control Group also performs research into emerging standards, performs gap analysis between today and a state of compliance and provides internal and external standards training.

Lesson 2: Let business results dictate certification efforts. For data center operators or IT departments regulations apply to the context of their business or “behavior”. It is financially unreasonable for any technology service provider to endeavor to adopt all frameworks, certifications and regulatory compliance requirements that may be useful. QualityTech has embraced ITIL as its service delivery framework. This decision allowed QualityTech to communicate internally and externally using a broadly accepted dictionary. As standards and certifications emerge, QualityTech evaluates its current and future client portfolio to determine the need and return on the certification investment. Typically, new compliance initiatives draw guidance from industry consortiums. How does QualityTech ensure its stays engaged and informed?

Lesson 3: Steer the conversation. As one would expect, new regulations frequently address an industry’s most pressing needs for oversight or standardization. Organizations in the growing space of outsourcing, like QualityTech, can find themselves forced to adopted standards that don’t apply to the organization but apply to a service. By identifying industry specific groups and joining same, outsourcers have an opportunity to be part of the message and on occasion steer. Advisory boards like The Green Grid, AFCOM, ASHREA, BOMA, AFCOM, ASIS, and others encourage involvement from a variety of stakeholders including outsourcers.

Monday, August 9, 2010

PCI and Regulatory Compliance in the Data Center

- Sarah Carter, director of marketing at FaceTime Communications (www.facetime.com)

According to FaceTime’s fifth annual user survey, “The Collaborative Internet: Usage Trends, End User Attitudes and IT Impact,” IT managers are not prepared to deal with archiving and eDiscovery for regulatory compliance. Of the IT managers surveyed, 77% can archive and retrieve e-mail; 38% can store and retrieve IM and chat; 29% can retrieve audio conferences; and 22% archive web conferences. Even fewer retain personal blogs (18%), content posted to social networks (19%), or Twitter posts (13%).

Advice for data center managers to prevent PCI- and regulatory compliance-related problems:

Start by getting visibility into what’s going on. Our same survey shows dramatic variations between what IT managers believ was going on, what end users are doing – and the actual data being tracked from 155 FaceTime applicances shows what is really going on.

Here’s just some of the variances that we found:

• Comparing IT estimates with actual network data and end-user attitudes shows dramatic variances.
• Sixty-two percent of IT professionals estimate that social networking is present on their networks, where the actual data shows social networking present in 100% of cases. File sharing tools (websites or P2P applications) were found to be present in 74% of locations, with only 32% of IT professionals estimate that they were in use. Web-based chat was also found in 95% of locations, with only 31% of IT professional estimating that they were in use.

From the same FaceTime user survey cited above, IT managers in 66% of organizations indicate they have received some kind of guidance from legal counsel for archiving e-mail; 40% for archiving IM and chat; and 27% for archiving social media content.

Facetime’s best tip: Involve legal and HR in the creation and implementation of effective policies and procedures to support eDiscovery. The FaceTime survey shows that in 72% of companies surveyed, IT is involved in creating policies and procedures for archiving and retrieval of company communications. Legal counsel is involved 60% of the time, and human resources just 36% or the time.

The best strategy is to create clearly defined policies and procedures and make sure that they are widely disseminated (and reiterated regularly) to end users to minimize violations, and to provide a recourse in the event of a violation (both as a disciplinary measure for offending employees, and as a means of recovering data traffic).

Inability to comply with regulatory audits can be very expensive. According to recent research by the Aberdeen Group, the cost for non compliance ranges from $1.1 million for a HIPAA violation, 1.3 million for a PCI DSS violation, $1.4 million for an SEC violation, to $2.1 million for a SOX violation.

Most regulatory bodies won’t accept excuses when IT managers cannot produce an audit trail of Web 2.0 content. In fact, FINRA, the Financial Industry Regulatory Authority, has a stated “no grace” policy, so companies are foolish if they don’t put in some kind of technology to monitor, control, and archive social media conversations. In the long run, an investment in Web 2.0 monitoring and eDiscovery technology is cheap insurance.