The InformationWeek -- Blogs
Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Seven Steps To Follow When Data Leakage Strikes


Posted by Larry Greenemeier, Dec 14, 2006 06:25 PM

At a recent summit on "data leakage," which sounds like an unfortunate side effect to a prescription medication, Experian Corp. chief information security officer James Christiansen provided a very useful rundown of what to do before, during, and after a data breach or a court-issued subpoena for data.


As states continue to pass laws that hold companies accountable for lost or stolen data, federal legislation on this subject is making its way, albeit slowly, through Congress. The courts have also tightened their reins on data discovery by amending the Federal Rules of Civil Procedure to compel companies to produce any and all available data pertinent to a court case. No longer will you be able to say, "I left that document in my other briefcase."

Christiansen's cardinal rules of responding to data leakage:
1) Put together a Cyber Incident Response Team (CIRT) that reports to the top executives in charge of both IT and the business as a whole while still having the autonomy to initiate an emergency response plan as needed.

2) CIRT members should include personnel from IT management and IT security as well as business managers, legal counsel, public relations, human resources, a law enforcement liaison, and senior company management. Each should know his or her role in an emergency, such as a security breach or a subpoena for data.

3) Control your communications or you'll wind up having more explaining to do in court. Once a lawsuit has been filed and the flurry of e-mails starts to fly, employees put their company in a deep hole by writing CYA e-mails that say things like, "I told them not to do that." "This kills companies in court all the time," Christiansen says.

4) Create a signal that can quickly be communicated throughout your organization when it's time to circle the wagons. As chief information security officer at GM, Christiansen implemented a color-coded "threat advisory management" warning system similar to the warning system adopted by Homeland Security following 9/11. When a red or orange alert is issued, management and employees should know exactly what procedures to follow to protect and preserve company data.

5) Offer a whistle-blower hotline or some other means for employees to confidentially report on suspicious or criminal activity that should be further investigated. Assign a code to each tipster's name so that identities aren't revealed. Nearly 70% of the time, insiders tip companies off to a problem, Christiansen says.

6) Make sure your legal team has authorized any investigation your organization conducts in the wake of a data breach or subpoena for information.

7) Create a template for a letter that will be sent to clients so that correspondence can be sent out as quickly as possible. Decide ahead of time who will sign and authorize the final letter.

Christiansen's advice isn't the antidote for data leakage, but it'll certainly help you stop the bleeding.

« Reckoning On Robots | Main | Wal-Mart Can Laugh Off KO By Elmo T.M.X. »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Visual Studio 2010 Multi-Monitor Support Helps Debugging Parallel Code
  2. Sequential Programming: Like Eating Peas with a Straw.
  3. Biomolecular device using self-assembled DNA nanostructures?


Join The InformationWeek Group On LinkedIn


                           


  1. More Reasons Why Linux Misses The Desktop
  2. Too Much Netbook For Too Litl?
  3. Motorola Explains Why Droid Doesn't Have Multi-Touch
  4. Sprint And T-Mobile Headed The Wrong Direction


  1. Apple Releases Snow Leopard Security Patch
  2. 9 In 10 Web Apps Have Serious Flaws
  3. Agency For International Development Outsources To CSC
  4. Health IT Career Tips
  5. RIM, Adobe Team For BlackBerry Development
  6. Hadoop Crunches Web-Sized Data

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007