The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

Storage Blog

Topics:   Storage

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Data Theft


Posted by George Crump, Sep 3, 2008 10:21 AM

The ability to steal company data is no more real today than it was five years ago, but the volume of data that can be stolen is.


This Labor Day weekend I was strolling through the local discount computer store and was reminded of one of the biggest concerns I have been hearing from CIO's lately -- data theft. There are 1-TB USB external hard drives floating around $300 and small, pocket 250-GB drives at around $150.

The real issue is would you rather block or tackle? In yesterday's entry I discussed file auditing and one of its capabilities to know who copied a file and to where. If someone were to copy company-sensitive data you could be alerted to that and stop them before they got out the door ... tackling. You would be better served had that copy never happened in the first place ... blocking. The ultimate would be to have both auditing and blocking integrated so the two applications could work together, sharing policies and metadata... data supervision.

One of the challenges is most people don't see this as stealing, they see it as more the data equivalent of taking home a box of pens from the supply closet. Actually, the office supplies are held in higher regard, probably because they are tangible. People just don't hold digital content in as high regard as cash. A person that would never take a $100 bill off your desk might very well rip a copy of the latest CD or DVD, or might also take home a customer list, a prospect database, Excel, or Word templates. The attitude is that this is not "really stealing."

It falls on the shoulders of the IT professional to lock this data down, while not making the environment too cumbersome to work with. This makes the more draconian approaches, like disabling all USB devices, impractical, and it is the void that data blocking tools could fill. These products allow you to set policies that only allow certain types of users to copy certain types of files to certain types of devices. They can have full access to the files as long as they stay on the network, but allow you to restrict their movement beyond that. I think they are becoming a key requirement in the enterprise.

Data supervision integrates auditing with blocking (among other capabilities) to allow shared policy and common metadata databases. Doing so simplifies the process and allows further examination of what is happening in your enterprise. Say, for example, an executive in your organization has full access and can copy virtually anything to USB devices. You can still have an alert that warns if anyone in the organization is copying a large amount of data to a device in a short period of time -- blocking could then step in and stop the transfer.

For example, if you are in the oil and gas market and suddenly 500 GB of SEG-Y data is being copied to a local USB drive, that could be legitimate, but it also could be theft. With data supervision you will be able to suspend the transfer, investigate who is making the transfer, and why. Then you can make an informed decision as to if that transfer should be allowed to continue.

There is a significant amount of corporate assets that only see life in digital form. Don't let that data walk out the door on a pocket hard drive.

Track us on Twitter: http://twitter.com/storageswiss.

Subscribe to our RSS feed.

George Crump is founder of Storage Switzerland, an analyst firm focused on the virtualization and storage marketplaces. It provides strategic consulting and analysis to storage users, suppliers, and integrators. An industry veteran of more than 25 years, Crump has held engineering and sales positions at various IT industry manufacturers and integrators. Prior to Storage Switzerland, he was CTO at one of the nation's largest integrators.


« 'Say Cheese!' Google Updates Picasa And Web Albums To Version 3.0 | Main | Case Studies In Cloud Computing »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Think Parallel 2010, Five Years of Multicore
  2. It's All In the Strategy, It's All About the Design
  3. How To Do Parallelism Without Getting Egg On Your Face


Join The InformationWeek Group On LinkedIn


  1. iPad Orders Surge, Then Plummet Over Weekend
  2. Windows 7 Is Really That Good
  3. Windows Phone 7 Apps Must Be Microsoft Approved


  1. Cloud Connect: U.S. IT In Forefront
  2. Google Brings Nexus One To AT&T, Rogers Wireless
  3. Intel Launches Six Core Server Processors
  4. Open Government Public Deadline Nears
  5. FBI Goes Undercover On Social Networks
  6. DHS May Be Wasting Data Center Spending

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007