<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-30088005</id><updated>2012-02-16T00:00:33.553-08:00</updated><category term='How to find IP'/><category term='smarter information retrieval'/><category term='what does it mean?'/><category term='Gartner predicts a move away from notebooks'/><category term='Eli Lilly legal documents sent to NY Times'/><category term='Symantec study finds more monies goes to compliance'/><category term='000 accounts compromised'/><category term='Congressinal bill introduced to protect PII'/><category term='PCI compliant'/><category term='IPv6 support from DLP vendor Fidelis'/><category term='Speaking at Gartner in DC'/><category term='Obama cyber security plan'/><category term='link to hack-igations'/><category term='Proof of Concept testing'/><category term='Supreme Court Justice Stephen Breyer PII disclosed'/><category term='SB 1386 extended to include PHI'/><category term='Symantec and HP has data loss in laptop thefts'/><category term='Agent or not'/><category term='30% of sensitive information on is laptops encrypted in the US government'/><category term='Surveys show risk of data breaches for 09'/><category term='building a query for a sensitive document'/><category term='University lost 60'/><category term='DLP chalk talk video'/><category term='DLP a commodity?'/><category term='Password data base found by Finjan'/><category term='eDiscovery news'/><category term='New emphasis on compliance signaled by Obama'/><category term='National security trumps privacy'/><category term='smarter dlp data base scanning'/><category term='FCI in W2K8 R2 and Titus Labs'/><category term='Predator Prey analysis for identifiying sensitive information'/><category term='DRM protection of sensitive information'/><category term='SSN guessing'/><category term='Millions of Student Loan Records Stolen in Data Breach'/><category term='2007 record loss of PII'/><category term='and Identity Management opportunities'/><category term='deployment methodology'/><category term='Ford engineer allegedly stole 4'/><category term='Pattern Matching'/><category term='MSIT using FCI'/><category term='DLP news'/><category term='RMS RSA DLP MSIT'/><category term='Lexis Nexis data breach'/><category term='Data Loss news'/><category term='better mouse trap'/><category term='Roman aqueducts'/><category term='SharePoint security'/><category term='Swedish military information left on USB stick'/><category term='CMS to review hospitals for compliance to HIPAA'/><category term='Classification of Information'/><category term='New DLP players'/><category term='Patient information security'/><category term='DLP missing for Web 2.0'/><category term='IBM deploys PGP'/><category term='Microsoft and EMC partnership'/><category term='Mafia steals PII through using an insider at LexisNexis'/><category term='Health Care Identity Theft'/><category term='DLP marries DRM'/><category term='selection criteria for a DLP solution'/><category term='Pattern Matching book'/><category term='Lawyers investigating Heartland breach'/><category term='necessary steps'/><category term='000 sensitive files'/><category term='Virtualization and cloud security concerns'/><category term='EU privacy laws and IP addresses'/><category term='HIPAA data on the lose'/><category term='FCI in W2K8 R2'/><category term='Banks no longer best in class for protecting customer data'/><category term='Cloud ontology'/><category term='573'/><category term='Vontu coverage on CNN.com'/><category term='creating groups on the fly for DRM protection uses'/><category term='DLP RMS at TechReady Seattle 09'/><category term='White paper release'/><category term='ILP'/><category term='loosing info on 45000 employees'/><category term='USB loss'/><category term='HBI article'/><category term='Missing financial information'/><category term='000 records'/><category term='JCPenney Has Dodged a Huge Bullet... Until Now'/><category term='Protect your database'/><category term='Proposed Virginia legislation'/><category term='T-Mobile staff sold personal data'/><category term='DLP for Database systems'/><category term='PCI and DLP'/><category term='Sears sued over privacy breach'/><category term='RSA improves its DLP suite with more PII detection'/><category term='Can you buy PCI compliance'/><category term='Updated white paper'/><category term='Twitter hacked'/><category term='Data Base security and DLP'/><category term='CompUSA article in 2600'/><category term='PCI-DSS credit card detection on a network'/><category term='users want control'/><category term='6 out of 10 steals data when leaving a company'/><category term='FAA hacked'/><category term='Entitlement management'/><category term='Data Breaches in 2008'/><category term='Classification matters'/><category term='Social Networking'/><category term='DLP selection criteria'/><category term='Un-encrypted laptops stays in the office'/><category term='next steps'/><category term='IT Governance'/><category term='SEC to become more agressive'/><category term='California looks to expand breach notification law'/><category term='CLP'/><category term='DLP'/><category term='NIST guide for protecting PII'/><category term='Omnibank looses customer information'/><category term='Health Care information under attack'/><category term='part of GRC'/><category term='Operational risk management'/><category term='NIST draft PII standard'/><category term='SharePoint growth'/><category term='Royal Navy looses laptop'/><category term='Forrester PCI report'/><category term='Word choices tells the strenght of interpersonal relationships'/><category term='PCI information loss at ski resort'/><category term='tens of millions of records'/><category term='DLP and eDiscovery'/><category term='Network Solutions hacked'/><category term='Prosecutor makes public the city&apos;s passwords'/><category term='What is DLP'/><category term='DLP adds encryption'/><category term='Maybe Biggest breach yet'/><category term='First arrests in Heartland breach'/><category term='Symantec releases data base support for their DLP product'/><category term='Communication controls'/><category term='Powerlaw distribution of sensitive information'/><category term='Heartland facing troubles ahead'/><category term='Users have access to too much information'/><category term='Twitter and Facebook'/><category term='DLP and provisioning'/><category term='Mobile phone information security'/><title type='text'>Information Protection</title><subtitle type='html'>How to secure sensitive information, data loss prevention, for sensitive data in corporations and other organizations, (ILP,CLP,DLP). It covers personal identifiable information, personal health information, credit card information, PII, PCI, PHI etc, and how to protect it. All opinions are mine, and not of my employer or any other organization. For terms of use, see first posting.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default?start-index=101&amp;max-results=100'/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>138</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-30088005.post-7396792822308812352</id><published>2010-04-01T14:59:00.000-07:00</published><updated>2010-04-01T15:01:19.086-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='JCPenney Has Dodged a Huge Bullet... Until Now'/><title type='text'></title><content type='html'>If you ever wondered who company A was, it was JCPenney. It is now reported in media, that JCPenney was "Company A" in the Albert Gonzalez trial. &lt;a href="http://datalossdb.org/incident_highlights/48"&gt;JCPenney Has Dodged a Huge Bullet... Until Now&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7396792822308812352?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7396792822308812352/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7396792822308812352' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7396792822308812352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7396792822308812352'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2010/04/if-you-ever-wondered-who-company-was-it.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3106067105703608957</id><published>2010-03-29T18:11:00.000-07:00</published><updated>2010-03-29T18:12:26.224-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Millions of Student Loan Records Stolen in Data Breach'/><title type='text'></title><content type='html'>According to an article in eWeek - March 29, 2010&lt;br /&gt;Educational Credit Management reported the theft of portable media with Social Security numbers, names, addresses, and other information belonging to some 3.3 million people.&lt;br /&gt;&lt;a href="http://www.eweek.com/c/a/Security/Millions-of-Student-Loan-Records-Stolen-in-Data-Breach-465881/"&gt;Millions of Student Loan Records Stolen in Data Breach&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3106067105703608957?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3106067105703608957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3106067105703608957' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3106067105703608957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3106067105703608957'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2010/03/according-to-article-in-eweek-march-29.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3126542764555737071</id><published>2010-01-26T15:32:00.000-08:00</published><updated>2010-01-26T15:39:06.924-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA data on the lose'/><title type='text'></title><content type='html'>Two health care providers this week experienced significant data losses of personal health care information, one is BlueCross, the other is University Medical Center, UMC. Insurer BlueCross BlueShield told thousands of members this week that a thief stole 57 computer hard drives from call center inChattanooga. See an article in internet news here: &lt;a href="http://www.internetnews.com/welcomead/"&gt;http://www.internetnews.com/welcomead/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;UMC has for more than three months losing personal information of traffic accident victims including social security numbers, birth dates. According to UMC, this has been leaked by someone at University Medical Center. See article in the Las Vegas Sun here: &lt;a href="http://www.lasvegassun.com/news/2010/jan/25/umc-patient-info-leaks-likely-date-back-july/"&gt;http://www.lasvegassun.com/news/2010/jan/25/umc-patient-info-leaks-likely-date-back-july/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3126542764555737071?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3126542764555737071/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3126542764555737071' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3126542764555737071'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3126542764555737071'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2010/01/two-health-care-providers-this-week.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4704846454895276751</id><published>2010-01-25T13:33:00.000-08:00</published><updated>2010-01-25T13:41:22.064-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP chalk talk video'/><title type='text'></title><content type='html'>A video on data loss prevention, rights management usage, RMS, file classification infrastructure in Windows Server 2008 R2, FCI, and RSA Data Loss Prevention, DLP is now available: Video: &lt;a href="http://edge.technet.com/Media/Securing-Sensitive-Information--How-MSIT-uses-ADRMS--RSA-DLP/"&gt;http://edge.technet.com/Media/Securing-Sensitive-Information--How-MSIT-uses-ADRMS--RSA-DLP/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4704846454895276751?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4704846454895276751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4704846454895276751' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4704846454895276751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4704846454895276751'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2010/01/video-on-data-loss-prevention-rights.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-403772518358848144</id><published>2009-12-18T17:38:00.001-08:00</published><updated>2009-12-18T17:40:33.945-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='USB loss'/><title type='text'></title><content type='html'>North Korea may have stolen sensitive information from an unsecured USB, see this article: &lt;a href="http://joongangdaily.joins.com/article/view.asp?aid=2914211"&gt;http://joongangdaily.joins.com/article/view.asp?aid=2914211&lt;/a&gt;. The USB contained information from a secure military network, and got exposed when the USB was accessible via the internet. A good reason why data loss prevention with enterprise rights management is crucial for improved security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-403772518358848144?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/403772518358848144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=403772518358848144' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/403772518358848144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/403772518358848144'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/12/north-korea-may-have-stolen-sensitive.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3268864444863090892</id><published>2009-11-24T09:44:00.001-08:00</published><updated>2009-11-24T09:44:59.993-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Updated white paper'/><title type='text'></title><content type='html'>Updated white paper on how Microsoft IT does Data Loss Prevention, DLP using Rights Management Server, RMS, and RSA DLP: &lt;a href="http://technet.microsoft.com/en-us/library/bb897856.aspx"&gt;http://technet.microsoft.com/en-us/library/bb897856.aspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3268864444863090892?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3268864444863090892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3268864444863090892' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3268864444863090892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3268864444863090892'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/11/updated-white-paper-on-how-microsoft-it.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1399167503403413660</id><published>2009-11-18T10:12:00.001-08:00</published><updated>2009-11-18T10:12:46.225-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='T-Mobile staff sold personal data'/><title type='text'></title><content type='html'>According to BBC, T-Mobile staff sold personal data: &lt;a href="http://news.bbc.co.uk/2/hi/uk_news/8364421.stm"&gt;http://news.bbc.co.uk/2/hi/uk_news/8364421.stm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1399167503403413660?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1399167503403413660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1399167503403413660' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1399167503403413660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1399167503403413660'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/11/according-to-bbc-t-mobile-staff-sold.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4505559282249489318</id><published>2009-10-21T09:52:00.000-07:00</published><updated>2009-10-21T09:53:41.323-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RMS RSA DLP MSIT'/><title type='text'></title><content type='html'>A new Showcase Study on Microsoft IT's use of RMS and RSA DLP has been completed and posted at &lt;a href="http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000005319"&gt;http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000005319&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4505559282249489318?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4505559282249489318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4505559282249489318' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4505559282249489318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4505559282249489318'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/10/new-showcase-study-on-microsoft-its-use.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-349829707742255603</id><published>2009-10-21T09:49:00.001-07:00</published><updated>2009-10-21T09:50:55.918-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MSIT using FCI'/><title type='text'></title><content type='html'>A new white paper has been published to show how MSIT uses FCI in this MSIT Showcase Study &lt;a href="http://vepcdn.microsoft.com/prod/images/64/Area/214/2676/9fd29bc1-bd16-42fe-a39e-f1d91d62aa60.pdf"&gt;http://vepcdn.microsoft.com/prod/images/64/Area/214/2676/9fd29bc1-bd16-42fe-a39e-f1d91d62aa60.pdf&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-349829707742255603?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/349829707742255603/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=349829707742255603' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/349829707742255603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/349829707742255603'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/10/new-white-paper-has-been-published-to.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8920754688827768868</id><published>2009-10-21T09:37:00.000-07:00</published><updated>2009-10-21T09:41:54.180-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ford engineer allegedly stole 4'/><category scheme='http://www.blogger.com/atom/ns#' term='000 sensitive files'/><title type='text'></title><content type='html'>According to an article in &lt;a href="http://darkreading.com/"&gt;http://darkreading.com&lt;/a&gt;, a Ford engineer allegedly stole 4,000 sensitive files by copying and downloading to a &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;USB&lt;/span&gt; device before seeking employment with a Chinese competitor of Ford&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8920754688827768868?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8920754688827768868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8920754688827768868' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8920754688827768868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8920754688827768868'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/10/according-to-article-in-httpdarkreading.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8432930819193226003</id><published>2009-08-26T17:01:00.000-07:00</published><updated>2009-08-26T17:06:38.275-07:00</updated><title type='text'></title><content type='html'>&lt;a href="http://www.ncanet.com/company/MSDLPIntegration.php"&gt;&lt;br /&gt;NCA Security &amp;amp; Technology Conference '09&lt;br /&gt;&lt;br /&gt;Technology Answers to Business http://www.ncanet.com/company/MSDLPIntegration.php&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8432930819193226003?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8432930819193226003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8432930819193226003' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8432930819193226003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8432930819193226003'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/08/nca-security-technology-conference-09.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3341648800750540213</id><published>2009-07-27T16:10:00.000-07:00</published><updated>2009-07-27T16:13:56.971-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='573'/><category scheme='http://www.blogger.com/atom/ns#' term='000 accounts compromised'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Solutions hacked'/><title type='text'></title><content type='html'>Network Solutions hacked, 573,000 accounts compromised&lt;br /&gt;&lt;br /&gt;According to an article in Washington Post, Network Solutions was hacked, and information from 573,000 accounts were accessed by the hackers. &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/07/24/AR2009072403527.html"&gt;http://www.washingtonpost.com/wp-dyn/content/article/2009/07/24/AR2009072403527.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3341648800750540213?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3341648800750540213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3341648800750540213' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3341648800750540213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3341648800750540213'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/07/network-solutions-hacked-573000.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-9140317652157507201</id><published>2009-07-17T08:41:00.000-07:00</published><updated>2009-07-17T08:43:28.852-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Twitter hacked'/><title type='text'></title><content type='html'>Twitter found itself having business secrets exposed here: &lt;a href="http://www.techcrunch.com/2009/07/16/twitters-internal-strategy-laid-bare-to-be-the-pulse-of-the-planet/"&gt;http://www.techcrunch.com/2009/07/16/twitters-internal-strategy-laid-bare-to-be-the-pulse-of-the-planet/&lt;/a&gt; after a hack of a username and password. The information stolen includes strategic meeting minutes, personal information and more.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-9140317652157507201?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/9140317652157507201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=9140317652157507201' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/9140317652157507201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/9140317652157507201'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/07/twitter-found-itself-having-business.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-489534723318595578</id><published>2009-07-17T08:31:00.000-07:00</published><updated>2009-07-17T08:34:27.151-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mafia steals PII through using an insider at LexisNexis'/><title type='text'></title><content type='html'>The breach at Lexis Nexis where PII was stolen, is linked to the Mafia according to this article from internetnews.com: &lt;a href="http://www.internetnews.com/security/article.php/3829911/LexisNexis+Breach+Linked+to+Mafia.htm"&gt;http://www.internetnews.com/security/article.php/3829911/LexisNexis+Breach+Linked+to+Mafia.htm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-489534723318595578?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/489534723318595578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=489534723318595578' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/489534723318595578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/489534723318595578'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/07/breach-at-lexis-nexis-where-pii-was.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8325156653546124072</id><published>2009-07-07T16:45:00.000-07:00</published><updated>2009-07-07T16:49:07.258-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSN guessing'/><title type='text'></title><content type='html'>According to this article in Washington Post, SSNs can be guessed easily using publicly known information: &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/07/06/AR2009070602955.html"&gt;http://www.washingtonpost.com/wp-dyn/content/article/2009/07/06/AR2009070602955.html&lt;/a&gt;. It is also covered inhis article from Fast Company explaining how information users post on Facebook can be used to reverse engineer their SSN: &lt;a href="http://www.fastcompany.com/blog/chris-dannen/techwatch/facebook-new-algorithm-can-guess-your-ssn"&gt;http://www.fastcompany.com/blog/chris-dannen/techwatch/facebook-new-algorithm-can-guess-your-ssn&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8325156653546124072?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8325156653546124072/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8325156653546124072' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8325156653546124072'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8325156653546124072'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/07/according-to-this-article-in-washington.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-6777347722860402123</id><published>2009-07-07T16:01:00.000-07:00</published><updated>2009-07-07T16:26:57.038-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='deployment methodology'/><title type='text'></title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_ksBQLf65JpU/SlPZjzvOO5I/AAAAAAAAAAs/xLHGh9hSrRc/s1600-h/Program+Steps.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 264px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5355863591080573842" border="0" alt="" src="http://3.bp.blogspot.com/_ksBQLf65JpU/SlPZjzvOO5I/AAAAAAAAAAs/xLHGh9hSrRc/s320/Program+Steps.jpg" /&gt;&lt;/a&gt; Methodology for deploying a protection program for sensitive information:&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-6777347722860402123?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/6777347722860402123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=6777347722860402123' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6777347722860402123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6777347722860402123'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/07/methodology-for-deploying-protection.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ksBQLf65JpU/SlPZjzvOO5I/AAAAAAAAAAs/xLHGh9hSrRc/s72-c/Program+Steps.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4500950881453144641</id><published>2009-07-07T15:48:00.000-07:00</published><updated>2009-07-07T15:50:19.731-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FCI in W2K8 R2 and Titus Labs'/><title type='text'></title><content type='html'>Titus Labs has announced that they are capable of using the new File Classification Infrastructure provided in Windows Server 2008 R2.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4500950881453144641?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4500950881453144641/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4500950881453144641' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4500950881453144641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4500950881453144641'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/07/titus-labs-has-announced-that-they-are.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1179504984056373342</id><published>2009-06-23T12:24:00.000-07:00</published><updated>2009-06-23T12:27:25.795-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP missing for Web 2.0'/><title type='text'></title><content type='html'>According to Principal AnalystForrester Research &lt;a href="http://web.eweek.com/t?r=5&amp;amp;c=10369&amp;amp;l=686&amp;amp;ctl=36059:D9690BCC8887B427999DFC18E081D36B&amp;amp;"&gt;Chenxi Wang, Ph.D.&lt;/a&gt; Enterprises lack data leakage protection solutions for Web 2.0 applications. The answer is to deploy DLP and DRM technologies in the enterprise.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1179504984056373342?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1179504984056373342/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1179504984056373342' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1179504984056373342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1179504984056373342'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/06/according-to-principal-analystforrester.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-5700836829687133857</id><published>2009-06-23T11:50:00.000-07:00</published><updated>2009-06-23T11:51:42.541-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Twitter and Facebook'/><title type='text'></title><content type='html'>I have started a twitter, o_O, you can find me by searching for Opedal, and I am building a face book, you can find me by searching for Olav Opedal&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-5700836829687133857?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/5700836829687133857/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=5700836829687133857' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5700836829687133857'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5700836829687133857'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/06/i-have-started-twitter-oo-you-can-find.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7048345661367107544</id><published>2009-06-23T11:41:00.000-07:00</published><updated>2009-06-23T11:42:58.842-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FCI in W2K8 R2'/><title type='text'></title><content type='html'>A new feature in Windows Server 2008 R2, is really interesting. It allows for tagging meta data to files stored in file shares, and allows for search, retention management, classification and protection. Information about File Classification Infrastructure in Server 2008: &lt;a onmousedown="'UntrustedLink.bootstrap($(this)," href="http://blogs.technet.com/filecab/archive/tags/File+Classification+Infrastructure+_2800_FCI_2900_/default.aspx" rel="nofollow" target="_blank"&gt;http://blogs.technet.com/filecab/archive/tags/File+Classification+Infrastructure+_2800_FCI_2900_/default.aspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7048345661367107544?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7048345661367107544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7048345661367107544' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7048345661367107544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7048345661367107544'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/06/new-feature-in-windows-server-2008-r2.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4945814876530669077</id><published>2009-06-23T11:37:00.000-07:00</published><updated>2009-06-23T11:40:59.397-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP RMS at TechReady Seattle 09'/><title type='text'></title><content type='html'>TechReady will be held July 27-31st, 2009, Seattle, Washington, and it will include a talk about DLP and RMS integration&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4945814876530669077?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4945814876530669077/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4945814876530669077' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4945814876530669077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4945814876530669077'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/06/techready-will-be-held-july-27-31st.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8869902869928509269</id><published>2009-05-04T11:13:00.000-07:00</published><updated>2009-05-04T13:51:51.824-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Lexis Nexis data breach'/><title type='text'></title><content type='html'>According to Associated Press, Lexis Nexis is notifying 32000 potential victims of data loss&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8869902869928509269?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8869902869928509269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8869902869928509269' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8869902869928509269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8869902869928509269'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/05/according-to-associated-press-lexis.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7101162897197581598</id><published>2009-04-14T09:49:00.000-07:00</published><updated>2009-04-14T10:01:05.783-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSA improves its DLP suite with more PII detection'/><title type='text'></title><content type='html'>With RSA's new 7.0 release, they have improved their PII scanning capabilities along with reducing the overall TCO of maintaining their DLP solution: &lt;a href="http://www.indiaprwire.com/pressrelease/information-technology/2009041423363.htm"&gt;http://www.indiaprwire.com/pressrelease/information-technology/2009041423363.htm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7101162897197581598?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7101162897197581598/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7101162897197581598' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7101162897197581598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7101162897197581598'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/04/with-rsas-new-7.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1471343500950753803</id><published>2009-03-23T23:18:00.000-07:00</published><updated>2009-03-23T23:19:52.107-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Heartland facing troubles ahead'/><title type='text'></title><content type='html'>Heartland reveals in their annual report that the data breach last year is currently under investigation by SEC, FTC, DOJ, Federal Financial Institutions Examination Council, and the Office of the Comptroller of the Currency. This is in addition to attorneys general of several states, and Canadian authorities.&lt;br /&gt;&lt;br /&gt;This breach is going to be a costly affair for the company if the attrition numbers are continuing to grow. Even more costly will be the loss of sponsorship from their primary sponsor bank. Visa booted Heartland off of its list of processors compliant with the Payment Card Industry data-security standards, or PCI last week.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1471343500950753803?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1471343500950753803/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1471343500950753803' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1471343500950753803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1471343500950753803'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/03/heartland-reveals-in-their-annual.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4112841811603518148</id><published>2009-03-11T22:26:00.000-07:00</published><updated>2009-03-11T22:28:30.764-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='California looks to expand breach notification law'/><title type='text'></title><content type='html'>&lt;a href="http://blog.wired.com/27bstroke6/2009/03/ca-looks-to-exp.html"&gt;California State Sen. Joe Simitian introduced new legislation to Expand Data Breach Notification Law&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;According to the magazine, Wired - March 06, 2009, California State Sen. Joe Simitian has introduced legislation that would require companies to provide more information in their data breach notification letters to consumers and to send notices to state authorities.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4112841811603518148?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4112841811603518148/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4112841811603518148' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4112841811603518148'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4112841811603518148'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/03/california-state-sen.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1276623897647434987</id><published>2009-03-10T10:42:00.000-07:00</published><updated>2009-03-10T11:59:09.431-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='6 out of 10 steals data when leaving a company'/><title type='text'></title><content type='html'>According to a study released by the Ponemon institute, 6 out of 10 US employees stole company data when they left their company according to this article in BBC NEWS: &lt;a href="http://news.bbc.co.uk/2/hi/technology/7902989.stm"&gt;http://news.bbc.co.uk/2/hi/technology/7902989.stm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is really a wake up call, to introduce digital rights management into the corporations to protect customer data, intellectual property and business secrets. Coupling Identity Management practices with DRM will ensure that sensitive information is adequatly protected even when walking out the door when the employee leaves.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1276623897647434987?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1276623897647434987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1276623897647434987' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1276623897647434987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1276623897647434987'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/03/according-to-study-released-by-ponemon.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3568205588664899921</id><published>2009-02-16T13:39:00.001-08:00</published><updated>2009-02-16T13:43:04.311-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='First arrests in Heartland breach'/><title type='text'></title><content type='html'>Three Florida men arrested for using stolen credit card information stemming from the Heartland breach. The value of attempted and actual fraud committed by these three alone exceeds $100,000:&lt;a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9127984&amp;amp;intsrc=hm_list"&gt;http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9127984&amp;amp;intsrc=hm_list&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3568205588664899921?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3568205588664899921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3568205588664899921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3568205588664899921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3568205588664899921'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/02/three-florida-men-arrested-for-using.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-5245901868572249923</id><published>2009-02-09T23:00:00.000-08:00</published><updated>2009-02-09T23:03:11.087-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='loosing info on 45000 employees'/><category scheme='http://www.blogger.com/atom/ns#' term='FAA hacked'/><title type='text'></title><content type='html'>FAA gets unvanted visitors into their computer systems last week according to a union leader, accessing names and national identification numbers of 45,000 employees and retirees, &lt;a href="http://www.msnbc.msn.com/id/29108758/"&gt;View article...&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-5245901868572249923?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/5245901868572249923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=5245901868572249923' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5245901868572249923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5245901868572249923'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/02/faa-gets-unvanted-visitors-into-their.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4124693296725721793</id><published>2009-02-04T12:30:00.000-08:00</published><updated>2009-02-04T12:32:14.484-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft and EMC partnership'/><title type='text'></title><content type='html'>Microsoft and EMC announces a continuance of their partnership, and Ballmer is talking about the DLP collaboration between RSA and Microsoft in this article: &lt;a href="http://news.cnet.com/8301-10805_3-10156015-75.html?tag=newsLeadStoriesArea.1"&gt;http://news.cnet.com/8301-10805_3-10156015-75.html?tag=newsLeadStoriesArea.1&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4124693296725721793?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4124693296725721793/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4124693296725721793' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4124693296725721793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4124693296725721793'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/02/microsoft-and-emc-announces-continuance.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7786747106372613268</id><published>2009-02-03T22:17:00.000-08:00</published><updated>2009-02-03T22:18:07.037-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint security'/><title type='text'></title><content type='html'>Search, SharePoint, tagging of sites and documents for classification purposes&lt;br /&gt;&lt;br /&gt;How would you improve the security of SharePoint. One would be to classify sites and tag classified documents. The problem is the static nature of a search. A DLP pattern or fingerprint, is really nothing else than a search. It is more specialized than a search conducted by a user, however it is still search using regular expressions and fingerprints in addition to keywords etc.&lt;br /&gt;&lt;br /&gt;How can search be improved for security purposes? I believe it is best done by placing more enabling tools in the hands of users. What is needed is improved feedback loops and a better understanding of the users of the system. In other words, can SharePoint security be improved upon by using the playbook from the semantic web movement? I believe it can.&lt;br /&gt;&lt;br /&gt;Here is how I envision it to work. The SharePoint sites are scanned for sensitive information using rules and patterns that has a high accuracy rate, and tag/classify the matching documents found. This result set should then be visible to the users who has access to the site, whether it is directly when visiting the site, or when the site is shown in a search result.&lt;br /&gt;&lt;br /&gt;Because documents of the same type tends to be clustered, the users of the site should be asked about the sensitivity of the documents not yet tagged on the site. According to research done at &lt;a href="http://www.technologyreview.com/web/22040/"&gt;Microsoft&lt;/a&gt; users with similar interests tended to rank their search results similarly. The assumption I would make, is that high frequency users of a specific SharePoint site would classify the documents the same. If these users are then also asked to supply more information about these documents than just the classification level, you can start creating richness in the tagging such as type of document: Health information, financial information, hr information etc. This could also be done automatically if you know what department t he most frequent users belong to. If the automated tag turns out to be wrong, a feedback opportunity to change should be presented to users. An example where this is done in a similar fashion for searches on &lt;a href="http://ask.com/"&gt;Ask.com&lt;/a&gt; where users are presented with information telling them about the soundness of the site they are about to visit using tools from &lt;a href="http://news.cnet.com/8301-1009_3-10155192-83.html?tag=mncol"&gt;Symantec.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7786747106372613268?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7786747106372613268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7786747106372613268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7786747106372613268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7786747106372613268'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/02/search-sharepoint-tagging-of-sites-and.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3088519319111107035</id><published>2009-02-03T22:15:00.000-08:00</published><updated>2009-02-03T22:17:27.590-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='users want control'/><title type='text'></title><content type='html'>&lt;a href="http://www.informationweek.com/news/security/privacy/showArticle.jhtml?articleID=212903005&amp;amp;subSection=News"&gt;Study Finds Consumers Want Control over Data&lt;/a&gt;&lt;br /&gt;Consumers try to protect their privacy, but don't fully understand how privacy and security technologies work or what protection is being provided, according to a new study.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3088519319111107035?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3088519319111107035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3088519319111107035' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3088519319111107035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3088519319111107035'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/02/study-finds-consumers-want-control-over.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2118120393719988013</id><published>2009-02-02T12:10:00.000-08:00</published><updated>2009-02-02T12:12:26.589-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud ontology'/><title type='text'></title><content type='html'>I belive the issues surrounding compliance will follow us into the cloud. Here is a great link that explains the cloud taxonomy and cloud ontology: &lt;a href="http://news.cnet.com/8301-19413_3-10152106-240.html"&gt;http://news.cnet.com/8301-19413_3-10152106-240.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2118120393719988013?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2118120393719988013/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2118120393719988013' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2118120393719988013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2118120393719988013'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/02/i-belive-issues-surrounding-compliance.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-6798372723262582082</id><published>2009-01-29T00:23:00.000-08:00</published><updated>2009-01-29T08:48:53.143-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NIST draft PII standard'/><title type='text'></title><content type='html'>NIST and DLP vendor opportunities&lt;br /&gt;&lt;br /&gt;NIST has published a &lt;a href="http://csrc.nist.gov/publications/drafts/800-122/Draft-SP800-122.pdf"&gt;draft guide&lt;/a&gt; for protecting PII and it will affect best practices and technology choices in years to come when the draft becomes a full standard. The NIST guide provide guidance to organizations on how they should manage PII stored or processed in their systems based on the level of sensitivity.&lt;br /&gt;&lt;br /&gt;If the draft become a released standard, organizations will be using it to prove or disprove the ability to comply with best practices. Therefore mapping technology and policies to the standard is important, and it is important to understand that not one product can solve all of the issues. However a set of complementary products can solve it. DLP products does help in many ways, and it would be good for DLP vendors to start defining best practices that spans beyond DLP such as including Identity Management, Storage, Policy, Policy management, Encryption and risk management. The statement from NIST that not all PII is to be treated the same, is very telling, as a classification and tagging of the data would here help to apply the right set of controls for the high value items, and not overdo the controls for lesser value data.&lt;br /&gt;&lt;br /&gt;Some observed issues with the NIST publication is that it defines PII but does not provide an exhaustive list. For example, for the Census Bureau, there may be additional types of PII that they specify are stricter.&lt;br /&gt;&lt;br /&gt;NIST recommends that each organization Create Policies and Procedures, Conduct Training, De-identify PII, Employ proper Access Enforcement, Esure Transmission Confidentiality, and Audit Events.&lt;br /&gt;&lt;br /&gt;So similar to PCI, DLP might not be the full answer to the story but can provide insight that helps to enable compliance for some of these areas. For de-identifying PII, DLP help by discovering PII. It is then it's up to the organization to de-identify it. This is of course not a straight forward process, and will need some thought before being implemented. With DLP, the organization gains understanding of the business units or groups that are having the most issues and concentrate or focus training activities. Likewise for create policies and procedures - this falls into the realm of understanding the PII inventory and what the priority levels are.&lt;br /&gt;&lt;br /&gt;The new collaboration between RSA and Microsoft for DLP solutions coupled with DRM is clearly a step in the right direction.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-6798372723262582082?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/6798372723262582082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=6798372723262582082' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6798372723262582082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6798372723262582082'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/nist-and-dlp-vendor-opportunities-nist.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1637222986313094735</id><published>2009-01-29T00:10:00.000-08:00</published><updated>2009-01-29T00:12:21.351-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Powerlaw distribution of sensitive information'/><title type='text'></title><content type='html'>Regular search does not consider the fact that sensitive documents are typically found in clusters. If your DLP search engine has found one sensitive document in a location such as a file share or laptop, the probability of there being more is very high, however they are found to be false negatives. For example if a sensitive document is found in a file share, there is a high likely hood that there are other documents of equal sensitivity that are not covered. The usage scenario could be an HR professional storing documents in a folder for a specific task. If the filter only finds one, the current assumption with DLP is that there are no other files in this folder that are sensitive. This is a false assumption based on my observations of real incidents.&lt;br /&gt;&lt;br /&gt;How to remedy for this?&lt;br /&gt;A manual review can be done for the rest of the folder and folders in the tree&lt;br /&gt;The folder can be marked sensitive, and all documents in this folder is then considered sensitive&lt;br /&gt;The folder can be automatically reviewed by a broader capture filter (filters used are usually tuned to reduce false positives leading to a higher number of false negatives)&lt;br /&gt;Finger printing (full or partial) can be used to see if these documents resides elsewhere&lt;br /&gt;Pattern creation can be used to improve the search patterns&lt;br /&gt;Etc.&lt;br /&gt;&lt;br /&gt;The true solution to this is a combined approach using manual inspection, machine learning, and making the assumption that the likely hood of one single sensitive document residing in a repository is low, and that the likely hood of more than one document is sensitive is high, and mitigate the risk of the cluster by classifying, tagging, and protecting the cluster instead of a single document.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1637222986313094735?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1637222986313094735/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1637222986313094735' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1637222986313094735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1637222986313094735'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/regular-search-does-not-consider-fact.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-9197519403937879047</id><published>2009-01-26T21:46:00.000-08:00</published><updated>2009-01-26T21:47:07.061-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP and provisioning'/><title type='text'></title><content type='html'>Content protection should be tied into access certification. It seems that companies are now improving their compliance by implementing provisioning technologies according to the &lt;a href="http://contentmanagement.cbronline.com/news/provisioning_projects_do_pay_analysts_220109"&gt;Burton Group&lt;/a&gt;. Considering how hard it is to control whom should have access to what, I believe that a coupling of provisioning tools and DLP is the next logical step.&lt;br /&gt;&lt;br /&gt;The content custodian should be notified of the type of content by the DLP system, and the choices should be presented to the custodian for protection measures and marrying this with provisioning systems would lessen the burden on the custodian.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-9197519403937879047?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/9197519403937879047/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=9197519403937879047' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/9197519403937879047'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/9197519403937879047'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/content-protection-should-be-tied-into.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2987028357484028686</id><published>2009-01-26T21:07:00.000-08:00</published><updated>2009-01-26T21:08:19.863-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Lawyers investigating Heartland breach'/><title type='text'></title><content type='html'>Not long after the public notification of the breach  of Heartland Payment systems attorney firms such as &lt;a href="http://www.girardgibbs.com/Heartland.asp?_kk=heartland%20data%20breach&amp;amp;_kt=91436fdd-5e3e-41ec-930f-dd3880d72143&amp;amp;gclid=CPqH78X7rZgCFQo9gwodk2ggUg"&gt;Girard Gibbs LLP&lt;/a&gt; start their investigation into the breach, and solicit individuals that may be affected by the breach. This may have been the largest breach ever. The numbers may reach tens of millions of credit and debit card transactions according to this &lt;a href="http://voices.washingtonpost.com/securityfix/2009/01/payment_processor_breach_may_b.html"&gt;article in Washington Post&lt;/a&gt;,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2987028357484028686?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2987028357484028686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2987028357484028686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2987028357484028686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2987028357484028686'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/not-long-after-public-notification-of.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7726179449775949439</id><published>2009-01-25T11:42:00.000-08:00</published><updated>2009-01-25T11:43:04.758-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='New emphasis on compliance signaled by Obama'/><title type='text'></title><content type='html'>President Obama embarks on wide reaching changes in the regulatory environment according to &lt;a href="http://www.msnbc.msn.com/id/28832617/"&gt;New York Times&lt;/a&gt;. This should translate into busy times for any IT department managing regulatory and compliance issues for their companies.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7726179449775949439?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7726179449775949439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7726179449775949439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7726179449775949439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7726179449775949439'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/president-obama-embarks-on-wide.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4946983713711567439</id><published>2009-01-23T21:23:00.001-08:00</published><updated>2009-01-23T21:23:56.521-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Word choices tells the strenght of interpersonal relationships'/><title type='text'></title><content type='html'>Researchers have found a relationship between word choices in communications and how well a relationship is functioning. In other words, content in communications can be used to establish the overall health of a relationship: &lt;a href="http://www.msnbc.msn.com/id/28814669/"&gt;http://www.msnbc.msn.com/id/28814669/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If the choice of words can be used to determine the strength of a relationship based on frequency of certain words, it is not a far conclusion to be drawn that foul play could be found by the same type of study. The choice of words would be different of course, but if there was a large collection of communications that could be mined between criminals, it should be possible to use pattern recognition to ferret out such communications in network traffic.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4946983713711567439?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4946983713711567439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4946983713711567439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4946983713711567439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4946983713711567439'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/researchers-have-found-relationship.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-523772285594411516</id><published>2009-01-23T14:03:00.000-08:00</published><updated>2009-01-23T14:04:14.297-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Obama cyber security plan'/><title type='text'></title><content type='html'>According to &lt;a href="http://www.networkworld.com/news/2009/012009-obama-tech-industry.html?hpg1=bn"&gt;Network World&lt;/a&gt;, Forrester research predicts big opportunities for Tech Firms with the Obama Cyber security plan.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-523772285594411516?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/523772285594411516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=523772285594411516' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/523772285594411516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/523772285594411516'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/according-to-network-world-forrester.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4896317035615869646</id><published>2009-01-21T12:24:00.001-08:00</published><updated>2009-01-21T12:24:36.766-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Breaches in 2008'/><title type='text'></title><content type='html'>Interesting link to coverage of data breaches in 2008: &lt;a href="http://www.insideidtheft.info/breaches.aspx?gclid=CNrSt4epnpgCFSMSagodjCXQmg"&gt;http://www.insideidtheft.info/breaches.aspx?gclid=CNrSt4epnpgCFSMSagodjCXQmg&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4896317035615869646?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4896317035615869646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4896317035615869646' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4896317035615869646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4896317035615869646'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/interesting-link-to-coverage-of-data.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2035089552048663264</id><published>2009-01-21T12:23:00.001-08:00</published><updated>2009-01-21T12:23:47.556-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tens of millions of records'/><category scheme='http://www.blogger.com/atom/ns#' term='Maybe Biggest breach yet'/><title type='text'></title><content type='html'>According to an &lt;a href="http://voices.washingtonpost.com/securityfix/2009/01/payment_processor_breach_may_b.html"&gt;article in Washington Post&lt;/a&gt;, Heartland Payment systems may have had the largest breach ever. The numbers may reach tens of millions of credit and debit card transactions.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2035089552048663264?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2035089552048663264/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2035089552048663264' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2035089552048663264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2035089552048663264'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/according-to-article-in-washington-post.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-6937492478645003116</id><published>2009-01-16T12:58:00.000-08:00</published><updated>2009-01-16T15:26:14.480-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virtualization and cloud security concerns'/><title type='text'></title><content type='html'>Two areas for concern for 09 will be sensitive information going into virtualized environments, and into the cloud.&lt;br /&gt;&lt;br /&gt;According to this article in &lt;a href="http://online.wsj.com/article/SB122930102219005425.html"&gt;WSJ&lt;/a&gt;, The Center for Strategic and International Studies report points out the trend towards greater industrial espionage: Quote from WSJ article "Supposedly confidential corporate information, the report warns, is almost certainly being hacked. As more individuals and companies rely on "cloud computing" -- storing information and services such as email remotely on supposedly secure servers -- foreign intelligence agencies and commercial snoops may have access." This is a troubling statement.&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://www.cio.com/"&gt;CIO magazine&lt;/a&gt;, CIO's are looking towards virtualization and the cloud for 09 to reduce operating and capital expenses. If these are the areas of investment, this is also where the criminals will spend their resources to wrestle valuable information from the rightful owners.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.blogger.com/It%20is%20also%20covered%20in%20this%20article%20from%20Internet%20News:%20http:/www.internetnews.com/security/article.php/3796546/Hackers+to+Take+Aim+at+the+Cloud+Virtualization.htm"&gt;Internet News&lt;/a&gt; is running an article on this subject today&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-6937492478645003116?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/6937492478645003116/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=6937492478645003116' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6937492478645003116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6937492478645003116'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/two-areas-for-concern-for-09-will-be.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-6117641787456525353</id><published>2009-01-16T01:24:00.000-08:00</published><updated>2009-01-16T02:20:16.892-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Predator Prey analysis for identifiying sensitive information'/><title type='text'></title><content type='html'>Using models from nature to identify sensitive information&lt;br /&gt;&lt;br /&gt;One interesting hypothesis would be to evaluate sensitive information with a &lt;a href="http://www.scholarpedia.org/article/Predator-prey_model"&gt;predator-prey model&lt;/a&gt; by realizing that information within an organization is bound by its physical and social networks, in other words there is a topology that can be mapped, and using differential equations, the contours can be described, so the topology of interest is mapped with a modified &lt;a href="http://en.wikipedia.org/wiki/Trophic_web"&gt;trophic web&lt;/a&gt; for the dispersal of information of value. The challenge of course will be to create a &lt;a href="http://en.wikipedia.org/wiki/Nonlinear"&gt;nonlinear&lt;/a&gt; system with the right set of variables. The question is what is the driving factor for these variables, and what would be an anomaly versus a genuine change point?&lt;br /&gt;&lt;br /&gt;Time is of course the great equalizer. A patent expires, so does copy right, however the length of time it takes for the value of a copy right item to decay is much longer than a patent. Same goes for financial information. A 10Q or 10K’s value drastically is reduced upon publication which happens quarterly or annually, respectively.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-6117641787456525353?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/6117641787456525353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=6117641787456525353' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6117641787456525353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6117641787456525353'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/using-models-from-nature-to-identify.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-6820073775646522809</id><published>2009-01-15T22:37:00.000-08:00</published><updated>2009-01-18T09:25:37.138-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='and Identity Management opportunities'/><category scheme='http://www.blogger.com/atom/ns#' term='Social Networking'/><category scheme='http://www.blogger.com/atom/ns#' term='DLP'/><title type='text'></title><content type='html'>Social Networking, DLP, and Identity Management opportunities&lt;br /&gt;&lt;br /&gt;A new area that may lend itself well to understanding the flow of information is social networking theories such as power law distributions, Mandelbrot statistics etc. The problem now of course becomes an issue of information overload. The amounts of data in such an analysis becomes quite large quickly, and the problem is inspection of findings. To make such a system scalable, the system should create local accountability.&lt;br /&gt;&lt;br /&gt;With local accountability, I mean that either the individual will have to sign off on a compliance statement on a regular basis, or the manager, as they would be the closest to know whether the access is appropriate, or excessive.&lt;br /&gt;&lt;br /&gt;Another interesting concept would be to look for change points, and flag these for further inspection. If change suddenly occurs, it should be possible to capture this change. Inspection of file share access, SharePoint access, Line of Business access etc, should be able to reveal a change in behavior such as the example from the data theft at Boeing.&lt;br /&gt;&lt;br /&gt;So, what is needed to evaluate if access is appropriate or if it is misused?&lt;br /&gt;&lt;br /&gt;To begin with, each individual with access to the network must be managed, and their access monitored. However, since most information is not confidential, access to it can be ignored if sensitive information is identified and cataloged.&lt;br /&gt;&lt;br /&gt;To catalog the information, you will have to search across your repositories for sensitive information. I believe that the information as it is found must also be tagged. A tagging using the alternate file stream is interesting, but this tag is lost in most cases when the information leaves the network. A second approach is to tag the metadata of the file itself. This does not get lost when the information leaves the network.&lt;br /&gt;&lt;br /&gt;An interesting approach would be to create a hash of the file as it has been classified and tagged. However if the tag also holds the hash, the hash of the file is altered if it is placed in the meta data of the file. It is not a problem with placing the tag in the alternate file stream. However if you create a hash and place it in the meta data, you could then just sign the file.&lt;br /&gt;&lt;br /&gt;If these hashes are stored in a central repository, the hash can then be used to evaluate if copies of the file exists elsewhere. If copies exists, they should be tagged according to the first file found. This process could also be used to remove the copies.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-6820073775646522809?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/6820073775646522809/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=6820073775646522809' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6820073775646522809'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6820073775646522809'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/social-networking-dlp-and-identity.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-165242948611725778</id><published>2009-01-15T21:32:00.001-08:00</published><updated>2009-01-15T21:32:56.843-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SEC to become more agressive'/><title type='text'></title><content type='html'>New emphasis on SEC's role in policing the financial markets is on its way.&lt;br /&gt;&lt;br /&gt;The Obama's SEC choice wows aggressive action according to this article in MSNBC: &lt;a href="http://www.msnbc.msn.com/id/28674370/"&gt;http://www.msnbc.msn.com/id/28674370/&lt;/a&gt;. What will this do to DLP? I believe it will be a boon to the industry, as this will require much better detection technologies for fraud and misuse of sensitive financial information&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-165242948611725778?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/165242948611725778/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=165242948611725778' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/165242948611725778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/165242948611725778'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/new-emphasis-on-secs-role-in-policing.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3866650301398946509</id><published>2009-01-15T18:11:00.000-08:00</published><updated>2009-01-15T18:52:44.046-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Surveys show risk of data breaches for 09'/><title type='text'></title><content type='html'>Information protection, DLP, Identity Management, outsourcing and vendor management, what is in store for the Enterprise for 2009 and future?&lt;br /&gt;&lt;br /&gt;Information gleaned from several surveys gives a dismal outlook for data breaches.&lt;br /&gt;&lt;br /&gt;In a survey by &lt;a href="http://www.enterprisestrategygroup.com/"&gt;Enterprise Strategy Group&lt;/a&gt;, 50% of their respondents said internal breaches were the direct cause of loss of confidential data, while 19 % were caused by external attacks and 11 % were a combination of external and internal attacks. 14 % of the respondents said data loss came as a result of losing a device containing confidential data.&lt;br /&gt;&lt;br /&gt;In a 2007 study by the &lt;a href="http://www.ponemon.org/"&gt;Ponemon Institute&lt;/a&gt;, "the notification cost for a first party data breach is $197 per a record lost and for third party data breach is $231 per a record lost. (A third party organization includes professional services, outsourcers, vendors, business partners and others who possessed the data and was and responsible for its protection.)"&lt;br /&gt;&lt;br /&gt;In a November survey by &lt;a href="http://www.sailpoint.com/"&gt;SailPoint Technologies&lt;/a&gt; of Fortune 1,000 companies shows that most of them are grossly unprepared to manage information technology (IT) security risk. They polled IT managers and directors and found that out of 116 respondents, 44 percent said that they could not “immediately remove all access privileges for terminated employees” if the company had a massive layoff. More than 65 percent reported that they would not be able to “present a complete record of user access privileges for each employee” if the company’s chief information officer wanted it that same day. And 46 percent said their company “failed an IT or security audit because of a lack of control around user access” in the past five years.&lt;br /&gt;&lt;br /&gt;The good news is of course that DLP vendors have started to integrate with identity management systems help, but there is a long way to go before the problem is solved. The not so good news is that most enterprises do not have a good understanding of who has access to what information. This means that a loss could go undetected for a long time, and cause a higher cost to the enterprise. With the current financial situation with large layoffs, this becomes even more critical to solve.&lt;br /&gt;&lt;br /&gt;The approach I would recommend to solve this issue, is to start cataloging and classifying information and information systems, and tying it to identity management information. Then as the business processes are understood, the principle of least privilege access should be used to manage these systems.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Even though this case is a stand alone case, &lt;a href="http://www.scmagazineus.com/Former-Boeing-employee-charged-in-data-theft/article/35228/"&gt;former Boeing Employee charged in data theft case&lt;/a&gt;, it shows that actively monitoring who has access to sensitive information, and evaluating whether this is appropriate access is paramount. It is an established best practice for fraud prevention, and is a requirement for SOX compliance for financial systems. The issue is of course that enterprises today, do not safeguard critical business information in the same manner as they safeguard SOX information.&lt;br /&gt;&lt;br /&gt;This of course leads one to look at Governance, Risk, and Compliance, to see how risk management can be streamlined for all sensitive information, not just information required by law or regulation to be safeguarded. This will drive down the cost of compliance, improve governance, and reduce the overall risk of loss of information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3866650301398946509?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3866650301398946509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3866650301398946509' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3866650301398946509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3866650301398946509'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/information-protection-dlp-identity.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8899768190527005086</id><published>2009-01-15T16:45:00.001-08:00</published><updated>2009-01-15T16:45:21.341-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NIST guide for protecting PII'/><title type='text'></title><content type='html'>NIST has published a draft guide for protecting PII&lt;br /&gt;&lt;br /&gt;The NIST draft uses the work done by OMB (Office and Management and Budget) Memo from 2007: “information which can be used to distinguish or trace an individual’s identity”. NIST Provides a practical guide for organizations on how to handle PII, by distinguishing the varying levels of sensitivity of the PII as well as how it should be protected: &lt;a href="http://csrc.nist.gov/publications/drafts/800-122/Draft-SP800-122.pdf"&gt;http://csrc.nist.gov/publications/drafts/800-122/Draft-SP800-122.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8899768190527005086?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8899768190527005086/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8899768190527005086' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8899768190527005086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8899768190527005086'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/nist-has-published-draft-guide-for.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2711747977564815262</id><published>2009-01-15T16:35:00.000-08:00</published><updated>2009-01-15T16:36:58.487-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='New DLP players'/><title type='text'></title><content type='html'>While looking at new players in the  DLP space, I ran into Illumant. They have two interesting documents for downloads if you are in the market for DLP: &lt;a href="http://illumant.com/Global/Solutions/DLP.php?gclid=CO6atfmJipgCFRsRagodRAO_DQ"&gt;http://illumant.com/Global/Solutions/DLP.php?gclid=CO6atfmJipgCFRsRagodRAO_DQ&lt;/a&gt;. There is both a white paper describing what should be considered when evaluating DLP vendors, as well as a matrix of vendors and their capabilities. The white paper could have been much more in depth, but is a good overview before starting to look in earnest. Both Forrester and Gartner provides a much more in depth coverage, and it is well worth the investment to purchase both companies' reports prior to investing in a DLP product.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2711747977564815262?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2711747977564815262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2711747977564815262' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2711747977564815262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2711747977564815262'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/while-looking-at-new-players-in-dlp.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7276126656953920835</id><published>2009-01-12T14:27:00.001-08:00</published><updated>2009-01-12T14:27:30.235-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='creating groups on the fly for DRM protection uses'/><title type='text'></title><content type='html'>Using the information already provided by the users to make assumptions about who should have access after protecting the document with DRM.&lt;br /&gt;&lt;br /&gt;If a file share owner has granted read, read write, and admin access to a share, a group could be created dynamically that would include these members, and the rights could be created according to the original ACLs on the file share.&lt;br /&gt;&lt;br /&gt;This would allow a group owner (the share owner) to add and remove users from a document, or sets of documents after they leave the file share. This would solve the problem around managing DRM rights. Currently, it is hard to manage granular sets of rights, as these are not readily automatable. However, with this approach, groups can be built on the fly based on sensitivity of the information and whom has access already. For example, certain PCI information is currently available to a PCI group, in this scenario, DRM rights would be granted to this PCI group on the fly for any document extracted from the central repository&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7276126656953920835?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7276126656953920835/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7276126656953920835' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7276126656953920835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7276126656953920835'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/using-information-already-provided-by.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7448007874545395401</id><published>2009-01-12T14:24:00.000-08:00</published><updated>2009-01-12T14:26:40.960-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Banks no longer best in class for protecting customer data'/><title type='text'></title><content type='html'>Banks falling behind in protecting customer financial data according to a study done by PwC: &lt;a href="http://security.cbronline.com/news/banks_falling_behind_on_data_security_090109"&gt;http://security.cbronline.com/news/banks_falling_behind_on_data_security_090109&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7448007874545395401?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7448007874545395401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7448007874545395401' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7448007874545395401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7448007874545395401'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/banks-falling-behind-in-protecting.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2654268253998524562</id><published>2009-01-12T09:45:00.000-08:00</published><updated>2009-01-12T09:47:24.615-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Congressinal bill introduced to protect PII'/><title type='text'></title><content type='html'>California Senator Dianne Feinstein (D-Calif.) is again proposing data breach legislation to the US Congress. The bill is Bills S.139, the Notification of Risk to Personal Data Act and S.141, the Social Security Number Misuse Prevention Act. This is her second attempt at creating a federal law setting requirements for handling of personally identifiable information. It would require federal agencies as well as business to notify both media and the private person whose information was lost.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.internetnews.com/government/article.php/3795191/New+Data+Breach+Privacy+Bills+in+Congress.htm"&gt;http://www.internetnews.com/government/article.php/3795191/New+Data+Breach+Privacy+Bills+in+Congress.htm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2654268253998524562?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2654268253998524562/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2654268253998524562' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2654268253998524562'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2654268253998524562'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/california-senator-dianne-feinstein-d.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4319203374072437670</id><published>2009-01-08T11:03:00.000-08:00</published><updated>2009-01-08T11:06:02.432-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP news'/><title type='text'></title><content type='html'>Plenty newsworthy items this week in the DLP space. According to Network World, CA will by DLP vendor Orchestria: &lt;a href="http://www.networkworld.com/news/2009/010509-ca-acquires-orchestria.html"&gt;CA to Buy Data-Leak Prevention Vendor&lt;/a&gt;, and ByteandSwitch publishes an article on DLP vendor and DRM partnerships: &lt;br /&gt;&lt;a href="http://www.byteandswitch.com/document.asp?doc_id=169866"&gt;Partnerships Spark New Life into Enterprise DRM&lt;/a&gt;. Of course, there are data breach news as well. Us Businesses reported close to a 50% increase in breaches in 2008: &lt;br /&gt;&lt;a href="http://c.moreover.com/click/here.pl?j1757441302&amp;amp;f=2238"&gt;Data Breaches Rise Almost 50 Percent in 2008&lt;/a&gt;, and CheckFree has to warn 5 million customers.:  &lt;br /&gt;&lt;a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9125078&amp;amp;intsrc=hm_list"&gt;CheckFree Warns 5 Million Customers after Hack&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4319203374072437670?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4319203374072437670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4319203374072437670' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4319203374072437670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4319203374072437670'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/plenty-newsworthy-items-this-week-in.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1776086763078547695</id><published>2009-01-01T12:37:00.000-08:00</published><updated>2009-01-01T12:38:29.230-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='building a query for a sensitive document'/><title type='text'></title><content type='html'>Considerations when building queries for DLP products&lt;br /&gt;&lt;br /&gt;Term weight is normally reduced the longer the document is. This may be counter intuitive to the need for scanning a document for compliance issues such as PCI, as a document with reoccurring terms may lead to a higher risk, than a document with fewer items. So when searching an inverse index, it is important not to reduce the scale either by adding one plus the log, or using the cosine on a vector based search.&lt;br /&gt;&lt;br /&gt;However by doing this, the terms in the query becomes more important. A term that has a high occurrence in both a set containing sensitive documents, and its corresponding set of non sensitive documents will lead to a high occurrence of false positives. Because of this, an effectiveness of terms must be calculated and stored over time. A term with low effectiveness should either be eliminated from the query, or should have a lower weight.&lt;br /&gt;&lt;br /&gt;Several solutions may be available here, one is to combine highly effective terms with less effective terms in a larger pattern. The question though, is if the distribution of terms in sensitive documents take on a Gaussian property with a bell curve, or if there are power law distributions in terms. To this question, I don’t know the answer yet, but I have noticed in practice that the distribution of documents follows power law distributions. This can be used in a query strategy, where an initial query with a high false negative rate is used initially to ferret out areas with a high probability of containing sensitive documents. When this approach is used, a  broader query can be used in this space.&lt;br /&gt;&lt;br /&gt;When considering a space, it can be a geographical space such as a site, it can be a logical site such as a file server supporting the HR department, or it can be a space in time. Most likely it is a combination of the above, and may even have more vectors such as user identity, frequency etc. So far, this is a trial and error based approach. To improve on this approach, large data sets would need to be collected and analyzed.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1776086763078547695?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1776086763078547695/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1776086763078547695' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1776086763078547695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1776086763078547695'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2009/01/considerations-when-building-queries.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7381044283620360278</id><published>2008-12-15T17:38:00.000-08:00</published><updated>2008-12-15T17:39:19.947-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Symantec and HP has data loss in laptop thefts'/><title type='text'></title><content type='html'>In the data loss news:&lt;br /&gt;&lt;br /&gt;Symantec who owns Vontu (a data loss prevention solution) lost sensitive information in a laptop theft. The same fate befell HP according to this PC world article:&lt;br /&gt;&lt;a href="http://www.pcworld.com/article/155372/hp_symantec_warn_employees_after_laptop_thefts.html"&gt;http://www.pcworld.com/article/155372/hp_symantec_warn_employees_after_laptop_thefts.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Sony disclosing children's private information without parents consent: &lt;a href="http://www.iht.com/articles/2008/12/11/technology/sony.php"&gt;http://www.iht.com/articles/2008/12/11/technology/sony.php&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7381044283620360278?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7381044283620360278/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7381044283620360278' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7381044283620360278'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7381044283620360278'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/12/in-data-loss-news-symantec-who-owns.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-6767669241815528110</id><published>2008-12-12T12:23:00.000-08:00</published><updated>2008-12-12T12:26:17.250-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP a commodity?'/><title type='text'></title><content type='html'>looks like &lt;span style="BACKGROUND-COLOR: #ffff00"&gt;DLP is becomming a commodity&lt;/span&gt;. Now a firewall vendor, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Palo&lt;/span&gt; Alto Networks, will offer limited &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;DLP&lt;/span&gt; for free as part of their firewall technology: &lt;a href="http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=212300545"&gt;http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=212300545&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-6767669241815528110?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/6767669241815528110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=6767669241815528110' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6767669241815528110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6767669241815528110'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/12/looks-like-dlp-is-becomming-commodity.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1887562263619371656</id><published>2008-12-12T08:42:00.000-08:00</published><updated>2008-12-12T12:10:42.629-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP marries DRM'/><title type='text'></title><content type='html'>It has been quite some time since I have updated this blog. However, the collaboration between Microsoft and RSA does need mentioning. &lt;a href="http://www.microsoft.com/presspass/press/2008/dec08/12-04EMCRSAPR.mspx"&gt;http://www.microsoft.com/presspass/press/2008/dec08/12-04EMCRSAPR.mspx&lt;/a&gt; It marries Data Loss Prevention with Digital Rights Management. Not to be outdone, Liquid Machines and McAfee follows with this anouncement: &lt;a href="http://www.pcworld.com/businesscenter/article/155185/liquid_machines_mcafee_partner_on_dataloss_prevention.html"&gt;http://www.pcworld.com/businesscenter/article/155185/liquid_machines_mcafee_partner_on_dataloss_prevention.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1887562263619371656?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1887562263619371656/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1887562263619371656' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1887562263619371656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1887562263619371656'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/12/it-has-been-quite-some-time-since-i.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8420726278815623003</id><published>2008-07-31T12:16:00.000-07:00</published><updated>2008-07-31T12:21:16.374-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='30% of sensitive information on is laptops encrypted in the US government'/><title type='text'></title><content type='html'>Government risk for loss of sensitive information still high:&lt;br /&gt;&lt;br /&gt;According to an article in computer world &lt;a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9110983&amp;amp;intsrc=hm_list"&gt;http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9110983&amp;amp;intsrc=hm_list&lt;/a&gt;, only 30% of the laptops containing sensitive information are encrypted.&lt;br /&gt;&lt;br /&gt;Since it is taking the government such a long time to encrypt, I would suggest they deploy encryption based on sensitivity of documents stored on laptops. They should start searching using DLP, and make some assumptions around employee roles and mandate encryption&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8420726278815623003?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8420726278815623003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8420726278815623003' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8420726278815623003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8420726278815623003'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/07/government-risk-for-loss-of-sensitive.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-5095378995591776923</id><published>2008-07-28T15:47:00.000-07:00</published><updated>2008-07-28T15:55:52.106-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Prosecutor makes public the city&apos;s passwords'/><title type='text'></title><content type='html'>What were they thinking? I understand the need to provide the court with adequate evidence (I am not a lawyer), but you would think the &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;prosecutor&lt;/span&gt; would at least ask the court to conceal the information when it exposes an entire city's network.&lt;br /&gt;&lt;br /&gt;San Francisco DA exposes the city's network passwords:&lt;a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9110758&amp;amp;intsrc=hm_list"&gt;http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;articleId&lt;/span&gt;=9110758&amp;amp;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;intsrc&lt;/span&gt;=hm_list&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Maybe it is time to run documents provided to court through a review for sensitivity before actually submitting documents to court? In my own experience, I know that documents containing health information and information about children becomes sealed, and the court has the &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_3"&gt;discretion&lt;/span&gt; to seal any information it finds necessary to seal as long as it does not violate the &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_4"&gt;public's&lt;/span&gt; right to access of information. Clearly, the public does not need to know San Francisco's network passwords, and the tax payers clearly does not need to see their hard earned money being used to reset all these passwords.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-5095378995591776923?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/5095378995591776923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=5095378995591776923' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5095378995591776923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5095378995591776923'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/07/what-were-they-thinking-i-understand.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-915922222103832380</id><published>2008-07-18T13:05:00.001-07:00</published><updated>2008-07-18T13:05:41.298-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smarter information retrieval'/><title type='text'></title><content type='html'>I have earlier described pattern matching, and "smart" information retrieval by first looking at broad groupings of information to create a set, then search the resultant set with a finer granularity in search terms.&lt;br /&gt;&lt;br /&gt;If we use the neo cortex processing as an example, lower levels of information is detected by our sensory organs and processed at a lower level, and a fraction of this information is actually processed in a higher level organ. If we were to process information this way, we could do the following: For each search term, key words being the lowest, we could assign probability of this documents relevance, and then search the resultant set with bigrams. This result set would then be searched with trigrams. These resultant set would then be assigned with a probability of relevance. The finest search using complex patterns would only be used on the final set.&lt;br /&gt;&lt;br /&gt;For each of these searches, a registry (data base) would then serve as the index of this information, and it should correlate to a taxonomy. This taxonomy would then be used to create meta data that would be assigned the document. With this, the opportunity to search for hidden patterns would be possible via data mining techniques.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-915922222103832380?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/915922222103832380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=915922222103832380' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/915922222103832380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/915922222103832380'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/07/i-have-earlier-described-pattern.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-5269277263949310730</id><published>2008-07-14T16:37:00.000-07:00</published><updated>2008-07-14T16:42:08.215-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smarter dlp data base scanning'/><title type='text'></title><content type='html'>One concern I have heard against using the CLR regex support in SQL server 2005, is performance. One way to overcome the cost of expensive regex queries is to do the search a bit smarter. One could start with the LIKE operator, or equivilant in other systems, and then do a sampling of rows in a table that returned results from the LIKE operation. After obtaining a sample rather than the entire table, one could then perform the operation on a separate system, or in a separate thread on the same system. With this approach, very complex patterns could be searched for, and one could create a separate repository from which chuncking could be used. This would work for not only text, but also images and other information as long as the parser can read and understand the format.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-5269277263949310730?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/5269277263949310730/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=5269277263949310730' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5269277263949310730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5269277263949310730'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/07/one-concern-i-have-heard-against-using.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7531544007393720304</id><published>2008-07-14T15:00:00.000-07:00</published><updated>2008-07-14T15:04:24.348-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Symantec releases data base support for their DLP product'/><title type='text'></title><content type='html'>Symantec releases Data Base support for sensitive information: &lt;a href="http://biz.yahoo.com/iw/080624/0409691.html"&gt;http://biz.yahoo.com/iw/080624/0409691.html&lt;/a&gt;&lt;br /&gt;For further thinking about DAM, database access management and scanning data bases for sensitive information, see: &lt;a href="http://securosis.com/"&gt;http://securosis.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7531544007393720304?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7531544007393720304/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7531544007393720304' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7531544007393720304'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7531544007393720304'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/07/symantec-releases-data-base-support-for.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7668814921879796352</id><published>2008-07-14T14:00:00.000-07:00</published><updated>2008-07-14T14:01:27.224-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='better mouse trap'/><title type='text'></title><content type='html'>How to go about crating a better mousetrap (DLP)&lt;br /&gt;&lt;br /&gt;If we go through the questions to ask: Where is it, What is it, Who has access, and how is it protected, we can see there are answers in each one of these four questions that can be used to answer others with a high probability.&lt;br /&gt;&lt;br /&gt;If we think about the where is it. If we look at one particular user, that user will use a limited number of resources to create and store information. She might have a local lap top used for daily work, a hand full of SharePoint sites she visits, a few file shares and maybe two or three data bases typically accessed via a line of business application, and finally and very important, instant messaging and email.&lt;br /&gt;&lt;br /&gt;If we expand the view of this person, and try to define that person in a network, we can look at organizational/hierarchical views of this person, and we can see frequency of communication via SharePoint, file shares, email and IM. With that information, we can create a social network of nodes between her and her co-workers and contacts. If we know that she frequently uses information of high sensitivity, we can apply a higher probability of her network also working on highly sensitive information, or has a greater opportunity to receive sensitive information. Each node going further out, will have a reduced opportunity of receiving sensitive information, unless they also work on sensitive information.  Of course a highly connected node will have higher probability than a lesser connected node.&lt;br /&gt;&lt;br /&gt;With this, we can create network models and base probability of each one of the nodes accessing, or have the potential to access sensitive information. This network diagram would be created by correlating information from email systems, logon events etc, and then correlate this to known repositories of sensitive information. Of course this approach will take several iterations as one would assume that in the beginning, few of the repositories would be classified and catalogued.&lt;br /&gt;&lt;br /&gt;Now, if we start looking at Alice, and what information she receives, we could chunk the sensitive information she receives from let say a data base, and then see if there are hits on these chunks in email, IM, or in documents she creates. If it is, we can then assign a probability of whether the information is sensitive or not. If we have enough information so the probability is higher than a preset threshold, we could then automatically assign the appropriate classification, annotate the information with the appropriate meta data, and assign the correct protection using for example DRM or other encryption technologies, or just set the appropriate access control list permissions on the document.&lt;br /&gt;&lt;br /&gt;Assigning rights to a document or repository then becomes a bit easier as you can glean information from previous transactions. With entitlement monitoring on repositories and in AD, you can then see if Alice should still have this access or not. A further development could be done to create a view into the social network to see if there is an increase or decrease of communications between nodes. If there has been a decrease, the organizational chart may not have been updated, but the node's work may have changed, and therefore may no longer need access to this information. In this case, if Alice owns one or more of these repositories, she could then be notified and queried if this node, Bob, still needs access.  This system could of course also be used to monitor for abnormalities and anomalies.&lt;br /&gt;&lt;br /&gt;We can also make assumptions about sensitivity of information based on protections on the system hosting the information (this may not hold true for end systems, but will generally hold true for financial systems and HR systems etc). If it is encrypted, or have other security measures in place, its probability of containing sensitive information may be higher, however this is a weak assumption in many cases, especially before a program has been put in place to safeguard sensitive information in an organization.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7668814921879796352?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7668814921879796352/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7668814921879796352' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7668814921879796352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7668814921879796352'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/07/how-to-go-about-crating-better.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8878088864443895043</id><published>2008-07-10T16:08:00.000-07:00</published><updated>2008-07-10T16:12:07.367-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Supreme Court Justice Stephen Breyer PII disclosed'/><title type='text'></title><content type='html'>It has been a while since I have updated the blog, but here is an article from MSNBC news I found stressing the need for inspection of information leaving your network: "Last year, a Virginia investment firm employee decided to trade music or a movie on the file-sharing network LimeWire on a company computer. He inadvertently shared his firm's files, including personal data of clients, one of them Supreme Court Justice Stephen Breyer" Seems that no-one including our Supreme Court justices are safe against loss of PII.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8878088864443895043?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8878088864443895043/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8878088864443895043' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8878088864443895043'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8878088864443895043'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/07/it-has-been-while-since-i-have-updated.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4681923252748110116</id><published>2008-06-19T09:06:00.000-07:00</published><updated>2008-06-19T09:10:48.988-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP adds encryption'/><title type='text'></title><content type='html'>The DLP industry is adding encryption capabilities to their offering: &lt;a href="http://www.darkreading.com/document.asp?doc_id=156738&amp;amp;WT.svl=news1_1"&gt;http://www.darkreading.com/document.asp?doc_id=156738&amp;amp;WT.svl=news1_1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I have long been a proponent of adding encryption to sensitive information. I do believe the best approach is to not only enable encryption, but also enable digital rights management to sensitive documents as you would then have a much fuller control of the document lifecycle.&lt;br /&gt;&lt;br /&gt;Furthermore, DLP should be used in conjunction with a retention policy in the business, and become part of the overall information management of the organization. A tighter integration into storage systems for retention is the next logical step.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4681923252748110116?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4681923252748110116/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4681923252748110116' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4681923252748110116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4681923252748110116'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/06/dlp-industry-is-adding-encryption.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2165655688221451694</id><published>2008-06-06T22:22:00.000-07:00</published><updated>2008-06-06T22:26:46.089-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CompUSA article in 2600'/><title type='text'></title><content type='html'>Has credit card information been exposed at CompUSA stores?&lt;br /&gt;&lt;br /&gt;I picked up a copy of the 2600 magazine today, and lo and behold, on page 23 is an article on how to log on to systems in the stores to retrive credit card information. The article describes the logon procedures using credentials not tied directly to a user, but rather a common name (store name) and the password is the same as the logon ID.&lt;br /&gt;&lt;br /&gt;If this is truly the case, this might be a breach of PCI that could potentially impact many of the customers who have shopped at CompUSA. Maybe the bargain price equipment came with a hidden price in loss of customer information?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2165655688221451694?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2165655688221451694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2165655688221451694' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2165655688221451694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2165655688221451694'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/06/has-credit-card-information-been.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8312159561968568815</id><published>2008-06-04T22:53:00.000-07:00</published><updated>2008-06-04T23:00:05.751-07:00</updated><title type='text'></title><content type='html'>Couple of thoughts I have on DLP&lt;br /&gt;&lt;br /&gt;1. It should not be considered a security solution, but more of a compliance solution to information management.&lt;br /&gt;2. It should facilitate retention policies, eDiscovery, and regulatory/policy compliance&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8312159561968568815?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8312159561968568815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8312159561968568815' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8312159561968568815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8312159561968568815'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/06/couple-of-thoughts-i-have-on-dlp-1.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7940727246734579132</id><published>2008-06-04T11:00:00.000-07:00</published><updated>2008-06-04T11:01:20.698-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Speaking at Gartner in DC'/><title type='text'></title><content type='html'>link to the Gartner event: &lt;a href="http://agendabuilder.gartner.com/sec14/webpages/SessionDetail.aspx?EventSessionId=914"&gt;http://agendabuilder.gartner.com/sec14/webpages/SessionDetail.aspx?EventSessionId=914&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7940727246734579132?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7940727246734579132/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7940727246734579132' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7940727246734579132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7940727246734579132'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/06/link-to-gartner-event-httpagendabuilder.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-9092734459729727448</id><published>2008-06-03T10:15:00.000-07:00</published><updated>2008-06-03T10:17:14.028-07:00</updated><title type='text'></title><content type='html'>It's been a while since my last post. I am currently at the Gartner event in Washington DC, where I had the great opportunity to speak to the audience on how Microsoft manages sensitive information. I will post a link to the PPT shortly.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-9092734459729727448?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/9092734459729727448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=9092734459729727448' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/9092734459729727448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/9092734459729727448'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/06/its-been-while-since-my-last-post.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1219622065056226648</id><published>2008-04-07T14:12:00.000-07:00</published><updated>2008-04-07T14:13:18.976-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='University lost 60'/><category scheme='http://www.blogger.com/atom/ns#' term='000 records'/><title type='text'></title><content type='html'>Information Loss at Antioch University:&lt;br /&gt;Failure to patch a Solaris server caused 60,000 users records to be exposed at Antioch University, including social security numbers: &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9075098&amp;amp;intsrc=hm_list"&gt;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9075098&amp;amp;intsrc=hm_list&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1219622065056226648?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1219622065056226648/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1219622065056226648' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1219622065056226648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1219622065056226648'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/04/information-loss-at-antioch-university.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4645374547508288321</id><published>2008-04-07T12:16:00.000-07:00</published><updated>2008-04-07T12:19:42.945-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PCI information loss at ski resort'/><title type='text'></title><content type='html'>Go skiing, loose your PII: &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9074339&amp;amp;intsrc=hm_list"&gt;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9074339&amp;amp;intsrc=hm_list&lt;/a&gt; Credit card information stolen as cards were swiped. Maybe it is time to revisit credit cards with a built in smart card chip? In this instance, 46,000 cards were exposed from the Okemo Mountain Resort ski area in Vermont&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4645374547508288321?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4645374547508288321/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4645374547508288321' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4645374547508288321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4645374547508288321'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/04/go-skiing-loose-your-pii-httpwww.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1333317567820510418</id><published>2008-04-01T17:55:00.000-07:00</published><updated>2008-04-01T17:57:13.623-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='what does it mean?'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI compliant'/><title type='text'></title><content type='html'>PCI compliant, what does that mean?&lt;br /&gt;&lt;br /&gt;Does compliance by an organization to PCI mean that credit card information is safe? According to a news article by informationweek: &lt;a href="http://www.informationweek.com/security/showArticle.jhtml?articleID=206904986"&gt;http://www.informationweek.com/security/showArticle.jhtml?articleID=206904986&lt;/a&gt;, this might not be the case as Hannaford Bros, lost 4.2 million credit and debit card numbers, while stating on their website that they are compliant to the industry PCI standard.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1333317567820510418?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1333317567820510418/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1333317567820510418' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1333317567820510418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1333317567820510418'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/04/pci-compliant-what-does-that-mean-does.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3232909157455027255</id><published>2008-03-27T01:47:00.001-07:00</published><updated>2008-03-27T01:47:58.790-07:00</updated><title type='text'></title><content type='html'>What strategies to follow after you have implemented a DLP solution&lt;br /&gt;&lt;br /&gt;If you deployed a DLP strategy, you have probably deployed it in your high risk areas, and if you have become somewhat mature in your current DLP deployment, the next is how to grow the deployment so that you can secure more areas. As you are becoming more successful, your management, or clients within business groups who is not currently enjoying the protection a DLP solution can give, will ask you to protect their areas as well.&lt;br /&gt;&lt;br /&gt;So, the question becomes, how do you grow both horizontally and vertically? You can grow horizontally by putting in place in place more monitors, but you will quickly find yourself in a situation where your current rules/policies does not meet the needs of the additional areas where you are now scanning, or maybe the business model you deployed for the corporate roll out does not meet the needs of the business unit you are now supporting in addition to the corporate roll out.&lt;br /&gt;&lt;br /&gt;Do you invest in data in motion along with data at rest? Do you invest in end point protection? How about managing different departments ranging from your HR department, to your credit card processing department to your research and development arm. For each one of these, different business problems arise, and different solutions must be put in place. For HR, your main concern is probably the loss or disclosure of personnel data, from your sales organization, customer PII, and from your R&amp;amp;D department, loss of your future bread and butter.&lt;br /&gt;&lt;br /&gt;So the discussion becomes the one of head count, and centralized versus de-centralized. Which model is right, and how to ensure comparable results between them? It is a discussion which will be had in many organizations in the upcoming years. Many IT security shops will have the idea that you should have a centralized approach. This will become increasingly difficult for several reasons. One, only the users/business owners in the respective areas will have an understanding of what is valuable, and needs protection, and what doesn’t. Then you have the issue around different IT departments controlling collaboration and messaging. Each one is important for securing your information. I think the right answer is a mix between centralized/decentralized, where information security runs the majority of the tools, but the business owners and IT collaborates on how to identify IP and business secrets, and create and manage policies dependent on roles.&lt;br /&gt;&lt;br /&gt;There is one undeniable fact. The amount of information is growing, in fact according to IDC, it is growing by 60% a year, with new regulatory requirements means that IT will have to invest more in managing the information for disclosure, protection and retention.&lt;br /&gt;&lt;br /&gt;Demand for storage capacity has grown by 60% per year and shows no signs of slowing down, according to research company IDC. New disclosure laws, which require more data to be preserved and retrievable, also are making storage management a bigger job. &lt;a href="http://www.networkworld.com/news/2008/032108-storage-revolution-jobs.html"&gt;http://www.networkworld.com/news/2008/032108-storage-revolution-jobs.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3232909157455027255?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3232909157455027255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3232909157455027255' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3232909157455027255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3232909157455027255'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/03/what-strategies-to-follow-after-you.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7018140185618351020</id><published>2008-03-13T17:03:00.000-07:00</published><updated>2008-03-13T17:04:18.395-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Health Care Identity Theft'/><title type='text'></title><content type='html'>New concerns regarding health care information misuse. In an article from MSNBC: &lt;a href="http://www.msnbc.msn.com/id/23392229/"&gt;http://www.msnbc.msn.com/id/23392229/&lt;/a&gt; they highlight the impact an impostor can have on your health when your information is abused.&lt;br /&gt;&lt;br /&gt;This should bring attention to the need for medical facilities, and anyone keeping medical information, to be prepared to ensure the accuracy and integrity of the information, as well as protecting it from loss.&lt;br /&gt;&lt;br /&gt;A shift from paper based information management to electronic management, enables greater efficiencies of information management, including sharing of information, but also enables loss of information at a much greater level than anytime before in history.&lt;br /&gt;&lt;br /&gt;Organizations which have not moved to encrypted storage for sensitive information should do so as soon as possible, and improved authentication and authorization models must be put in place where they are lacking.&lt;br /&gt;&lt;br /&gt;Systems must be put in place that ensures that the identity used is that of the person receiving health care, and that only the information needed is available to personnel who provides care, or otherwise handles the information.&lt;br /&gt;&lt;br /&gt;According to FTC, 3% of identity theft victims have had someone else use their medical benefits. With identity theft growing, and medical care becoming more expensive, leaving more out, and the move towards electronic health information management, we are poised for the perfect storm.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7018140185618351020?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7018140185618351020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7018140185618351020' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7018140185618351020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7018140185618351020'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/03/new-concerns-regarding-health-care.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3436372390699249405</id><published>2008-03-10T21:02:00.000-07:00</published><updated>2008-03-10T21:03:14.278-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Operational risk management'/><title type='text'></title><content type='html'>Information loss prevention and operational risk management&lt;br /&gt;&lt;br /&gt;An operational risk framework which would take input across the organization, which also manages exceptions to policy would be  a huge benefit to overall risk management. As business users demand web 2.0 applications, easy to use cell phones with dual use capabilities (read using as email client for work purposes and view video and listen to music for personal use), and exceptions given to systems regarding patch level and security reviews.&lt;br /&gt;&lt;br /&gt;Roll up operational risk summaries would be the only way to measure the aggregate operational risk in the organization. This married with information flow views, which outlines what objects access what information would make the risk decisions easier to make. If you knew who had access to what information where and when on what device, it would be easy to see what the true risk was, and if a request for an exception came in, it would be easy to determine if the additional risk was substantial, or minimal. It would be also easy to envision a self service model , where the user would be allowed to accept some risk, but if the risk moved above a threshold, a manager or security operator would have to grant it. Each business leader could then set an acceptable threshold within the organization, and its policy would then flow down to the individual users.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3436372390699249405?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3436372390699249405/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3436372390699249405' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3436372390699249405'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3436372390699249405'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/03/information-loss-prevention-and.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7440530342567045215</id><published>2008-03-10T20:59:00.001-07:00</published><updated>2008-03-10T20:59:54.464-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mobile phone information security'/><title type='text'></title><content type='html'>It has been a busy few days, and for information loss prevention, a few areas are worthy a highlight. iPhone 2.0 is still questioned if it meets the regulatory requirements for data protection: &lt;a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9067319&amp;amp;intsrc=hm_list"&gt;http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9067319&amp;amp;intsrc=hm_list&lt;/a&gt;. Furthermore, here is a link to an article discussing how BlackBerry servers are ripe for the hacking. Yet another concern for IT security personnel who needs to protect sensitive information on all devices serviced by the organization: &lt;a href="http://techworld.com/security/news/index.cfm?newsID=11663&amp;amp;pagtype=samechan"&gt;http://techworld.com/security/news/index.cfm?newsID=11663&amp;amp;pagtype=samechan&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7440530342567045215?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7440530342567045215/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7440530342567045215' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7440530342567045215'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7440530342567045215'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/03/it-has-been-busy-few-days-and-for.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7784316927880769027</id><published>2008-03-09T23:14:00.000-07:00</published><updated>2008-03-09T23:38:48.828-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Communication controls'/><title type='text'></title><content type='html'>Information control&lt;br /&gt;&lt;br /&gt;Maybe I should rename the blog from information protection, as it is just as much about information control. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;DLP&lt;/span&gt; products along with &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;DRM&lt;/span&gt; products, firewalls and other security controls are mere solutions in place to control the flow of information. It is put in place to prevent flow of information to systems or personnel who should not have this information, and allow the flow to systems or personnel who should have access.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;DLP&lt;/span&gt; tries to identify the type of content, and based on rules, apply various protection mechanisms to the information. In some areas, context is also evaluated. However one area which &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;DLP&lt;/span&gt; has not fully gone into is the area of mapping social graphs to ensure that information does not flow from a highly trusted source to a trusted albeit less trusted than the first source downward in the hierarchy towards an untrusted source.&lt;br /&gt;&lt;br /&gt;Clear areas of such downward flow can be stopped by reducing the access to broad access groups, however human nature is such that obstacles to sharing information usually is overcome, especially if it is easier to circumvent the control than it is to obey it.&lt;br /&gt;&lt;br /&gt;Willful loss of information can only happen if technology, processes and people (the majority) is aligned. The processes much be such that they enable secure sharing to the proper objects, and people must buy into the idea that the value of protecting certain types of information is higher than the cost of loss caused by reducing sharing.&lt;br /&gt;&lt;br /&gt;This can seem contrary to many, as we want to communicate, and we will fail in most of our&lt;br /&gt;endeavors if we do not collaborate, at least within the group we belong. The problem is of course that most people belong to many groups, based on work, ideology, hobbies, neighbourhoods, etc. This means that just looking at the objects who have, had, or can access the information is not enough. You also need to look at who these objects are connected to, and who they are in turn connected to. You need to map out objects that form hubs versus spokes (power law distribution), and where these again lead to.&lt;br /&gt;&lt;br /&gt;One trick used to track such information is to use a 1x1 pixel, to see who receives certain information. This is however not included in most information as it traverses networks, storage areas, end points, data bases, applications etc. Only when you can marry a map of all objects, and their &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_5"&gt;interrelatedness&lt;/span&gt;, and where the information actually moves to and from can you truly understand the risks and or &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_6"&gt;possibilities&lt;/span&gt; the organization have in sharing information within and across boundaries.&lt;br /&gt;&lt;br /&gt;Today's &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;DLP&lt;/span&gt; solutions create classifications in varying degrees, and and some store the result set in a data base, others persist the information within the meta data of the document. Either directly within the document, or in an alternate stream. These can of course be stripped off, and until &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;DRM&lt;/span&gt; becomes pervasive, it will not solve this issue either. Actually &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;DRM&lt;/span&gt; has another problem, in that if information is presented on a screen, it can be copied and the controls are stripped off as a consequence. However &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;DRM&lt;/span&gt; will &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_11"&gt;increase&lt;/span&gt; the effort necessary to improperly distribute information to objects who should not have access.&lt;br /&gt;&lt;br /&gt;In order to support better protection, identity management is another dimension that must be solved. I will not go much into depth in this posting, other than just saying that roles based identity management is hard, and identity management between organizations are even harder, and is a contributor to the problem.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7784316927880769027?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7784316927880769027/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7784316927880769027' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7784316927880769027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7784316927880769027'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/03/information-control-maybe-i-should.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4147860185213846144</id><published>2008-03-05T03:24:00.000-08:00</published><updated>2008-03-05T04:45:09.258-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='National security trumps privacy'/><title type='text'></title><content type='html'>According to a survey by Pursuant, &lt;a href="http://www.pursuantresearch.com/"&gt;http://www.pursuantresearch.com/&lt;/a&gt;, 32% of surveyed government IT personnel do not think they will become compliant with requirements such as HSPD-12, FIPS 201, and FISMA. This article: &lt;a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=206901345"&gt;http://www.informationweek.com/news/showArticle.jhtml?articleID=206901345&lt;/a&gt; states that government IT personnel believes national security trumps privacy&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4147860185213846144?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4147860185213846144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4147860185213846144' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4147860185213846144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4147860185213846144'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/03/according-to-survey-by-pursuant-httpwww.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2057320610165379473</id><published>2008-03-02T23:25:00.000-08:00</published><updated>2008-03-02T23:36:51.980-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Health Care information under attack'/><title type='text'></title><content type='html'>Confluence of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;HIPAA&lt;/span&gt; security audits and increasing attacks from the &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;Internet&lt;/span&gt; creates pressure on health care organizations to protect their patient information: &lt;a href="http://www.networkworld.com/news/2008/022708-healthcare-cyberattacks.html"&gt;http://www.networkworld.com/news/2008/022708-healthcare-cyberattacks.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The four important questions to ask for any custodian of sensitive information should be:&lt;br /&gt;&lt;br /&gt;What information exists on my systems&lt;br /&gt;Where is it located&lt;br /&gt;Who has access&lt;br /&gt;How is it protected&lt;br /&gt;&lt;br /&gt;I believe the only way to find out what information exists, cataloguing and classification is a necessity. To find out where it is, the repositories containing information must be scanned, and content then classified based on this scan. To ensure that only users who need access, has access, entitlement management is key. The information that is classified should then be protected.&lt;br /&gt;&lt;br /&gt;This cannot be achieved with technology alone. People, Process and Technology all go hand in hand to solve this problem.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2057320610165379473?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2057320610165379473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2057320610165379473' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2057320610165379473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2057320610165379473'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/03/confluence-of-hipaa-security-audits-and.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2622618299827253884</id><published>2008-03-02T21:43:00.000-08:00</published><updated>2008-03-02T21:48:27.888-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='selection criteria for a DLP solution'/><title type='text'></title><content type='html'>Selection Criteria for an ILP solution&lt;br /&gt;&lt;br /&gt;Here are the high level selection criteria I would use for selecting a DLP solution&lt;br /&gt;&lt;br /&gt;· Accuracy (I would be willing to trade speed for accuracy if needed)&lt;br /&gt;· Speed (can all high risk areas be scanned efficiently without a high bandwidth cost)&lt;br /&gt;· Scalability (can all high risk areas be scanned efficiently)&lt;br /&gt;· Remediation capabilities (if a scanning solution is deployed without proper remediation, it leaves the organization with a much higher risk than prior to scanning)&lt;br /&gt;· Upfront cost of application&lt;br /&gt;· Upfront cost of services needed to deploy application&lt;br /&gt;· Cost of ownership&lt;br /&gt;o How many headcount are needed to manage incidents and systems&lt;br /&gt;o What is the annual support cost&lt;br /&gt;o What is the total life time cost of the application (3 years)&lt;br /&gt;· Risk reduction provided by application&lt;br /&gt;o How is it measured&lt;br /&gt;o Will result set stand up in court (can I prove due diligence when using these tools)&lt;br /&gt;o Can new regulatory requirements or new corporate policy be set up within a standard framework&lt;br /&gt;o Does the reporting meet the following needs&lt;br /&gt;§ Overall risk reduction&lt;br /&gt;§ Specific risk reduction for business unit/regulatory compliance/regional compliance&lt;br /&gt;§ Can ROI be demonstrated&lt;br /&gt;§ Are executive reports easy to understand&lt;br /&gt;§ Can executive reports be rolled into a CIO scorecard&lt;br /&gt;§ Does the reports for the operations team allow for improving efficiency of team and rules (this drives TCO)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2622618299827253884?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2622618299827253884/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2622618299827253884' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2622618299827253884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2622618299827253884'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/03/selection-criteria-for-ilp-solution.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7290743256122321251</id><published>2008-02-28T21:58:00.000-08:00</published><updated>2008-03-02T20:46:04.125-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Can you buy PCI compliance'/><title type='text'></title><content type='html'>Can you buy PCI compliance, a good article from Information Weeek: &lt;a href="http://informationweek.com/security/showArticle.jhtml?articleID=206800868"&gt;http://informationweek.com/security/showArticle.jhtml?articleID=206800868&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Of course, you can get solid advice from vendors, but technology is just one part of the equation. First, you should evaluate if you have the right skill set in your organization, then you should evaluate your current processes, and re-engineer if needed. Only when you have evaluated both people and processes, should you start evaluating technology&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7290743256122321251?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7290743256122321251/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7290743256122321251' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7290743256122321251'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7290743256122321251'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/can-you-buy-pci-compliance-good-article.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7263016694515032379</id><published>2008-02-28T21:51:00.000-08:00</published><updated>2008-02-28T21:56:21.576-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Password data base found by Finjan'/><title type='text'></title><content type='html'>Password database of stolen passwords found by Finjan: &lt;a href="http://www.eweek.com/c/a/Security/Finjan-Finds-Database-of-8700-Stolen-FTP-Credentials/"&gt;http://www.eweek.com/c/a/Security/Finjan-Finds-Database-of-8700-Stolen-FTP-Credentials/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Passwords should be treated as highly sensitive information as passwords are often reused by users, and can lead to the loss of all types of sensitive information within information systems. However, passwords can be hard to search for unless you already have a database of passwords. In the case passwords has to be stored electronically, they should at all times stay encrypted&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7263016694515032379?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7263016694515032379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7263016694515032379' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7263016694515032379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7263016694515032379'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/password-database-of-stolen-passwords.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1778317691064201262</id><published>2008-02-17T19:13:00.000-08:00</published><updated>2008-02-17T19:18:17.233-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Symantec study finds more monies goes to compliance'/><title type='text'></title><content type='html'>New study from Symantec&lt;br /&gt;&lt;br /&gt;IT organizations are now reporting back to Symantec's survey that work on regulatory compliance is either comparable to other projects, or more important than risk mitigation efforts: &lt;a href="http://www.infoworld.com/article/08/01/31/Study-reframes-IT-risk-management_1.html"&gt;http://www.infoworld.com/article/08/01/31/Study-reframes-IT-risk-management_1.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This should be good news for information loss prevention programs, as PCI is definitely a driver for improved controls on how and when information is shared and to whom.&lt;br /&gt;&lt;br /&gt;I believe the future trends will be divestments in some security strategies historically undertaken by an organization, such as extranet solutions, firewall deployments etc, and that the major investments for the future is in a blend between identity management and entitlement management. If you look at current encryption solutions, they usually stop at the enterprise egress point, as most organizations are not able to convince their partners to agree on a federation model.&lt;br /&gt;&lt;br /&gt;It is time to divest in underperforming security initiatives, and invest in areas where you can find a better return on your investment. Today investment in compliance can provide better ROI than just merely investing in security controls. If you combine your investment so that you improve uptime, enable business, and can prove compliance, you find much more value than just investing in security controls.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.infoworld.com/article/08/01/31/Study-reframes-IT-risk-management_1.html"&gt;http://www.infoworld.com/article/08/01/31/Study-reframes-IT-risk-management_1.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1778317691064201262?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1778317691064201262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1778317691064201262' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1778317691064201262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1778317691064201262'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/new-study-from-symantec-it.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4780753674281775507</id><published>2008-02-09T00:29:00.001-08:00</published><updated>2008-02-09T00:29:41.601-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Base security and DLP'/><title type='text'></title><content type='html'>Data bases and DLP&lt;br /&gt;&lt;br /&gt;Quote from article in eweek:  &lt;a href="http://www.eweek.com/c/a/Security/DLP-DAM-Share-Common-Data-Security-Objectives/"&gt;http://www.eweek.com/c/a/Security/DLP-DAM-Share-Common-Data-Security-Objectives/&lt;/a&gt; "Most every security monitoring technology would benefit from DLP content awareness, which is the ability to recognize sensitive content on the fly," said Paul Proctor, an analyst with Gartner."&lt;br /&gt;&lt;br /&gt;I completely agree, I believe DLP vendors need to address data bases along with repositories email and endpoints. Furthermore, such solutions should also protect any sensitive information leaving the data base&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4780753674281775507?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4780753674281775507/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4780753674281775507' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4780753674281775507'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4780753674281775507'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/data-bases-and-dlp-quote-from-article.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7448210679197179488</id><published>2008-02-09T00:21:00.000-08:00</published><updated>2008-02-09T00:22:16.289-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='eDiscovery news'/><title type='text'></title><content type='html'>Amendments to Federal Rules of Civil Procedure, FRCP, creating opportunities for content management solutions: &lt;a href="http://www.byteandswitch.com/document.asp?doc_id=144806&amp;amp;WT.svl=news1_6"&gt;http://www.byteandswitch.com/document.asp?doc_id=144806&amp;amp;WT.svl=news1_6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Some solutions sit on email, and use keywords and phrases, others enable retrieval from tapes and other media.&lt;br /&gt;&lt;br /&gt;At some time in the not so distant future, eDiscovery solutions and ILP solutions will probably merge, as they are both solving much the same problem.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7448210679197179488?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7448210679197179488/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7448210679197179488' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7448210679197179488'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7448210679197179488'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/amendments-to-federal-rules-of-civil.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-8944452611380181282</id><published>2008-02-08T23:33:00.000-08:00</published><updated>2008-02-08T23:38:19.409-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Eli Lilly legal documents sent to NY Times'/><title type='text'></title><content type='html'>Eli Lilly legal documents wrongfully sent to New York Times in a Billion dollar lawsuit&lt;br /&gt;&lt;br /&gt;Eli Lilly could probably have been better protected if they had in place a federated trust with their law firm, &lt;a href="http://www.pepperlaw.com/"&gt;Pepper Hamilton&lt;/a&gt;, and had the opportunity to protect their confidential communication with their outside counsel. This is truly the case for where Digital Rights Management could really protect their information.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.cnet.co.uk/software/0,39029694,49295453,00.htm"&gt;http://news.cnet.co.uk/software/0,39029694,49295453,00.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This case of information leak is enlightening in several aspects.&lt;br /&gt;&lt;br /&gt;One, Eli Lilly could potentially have lost ground in a serious legal matter&lt;br /&gt;&lt;br /&gt;Two, this is an understandable mistake by the outside counsel, albeit one could argue that more care should have been taken. Awareness is key, and an awareness program can reduce the risk of such incidents.&lt;br /&gt;&lt;br /&gt;Three, when conducting business with partners, just having legal agreements in place on how information is to be handled is not good enough. Contractual obligations should be audited against. This email could potentially have been stopped at the email server if an information loss prevention solution had been in place&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-8944452611380181282?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/8944452611380181282/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=8944452611380181282' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8944452611380181282'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/8944452611380181282'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/eli-lilly-legal-documents-wrongfully.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-2619364521763542209</id><published>2008-02-07T21:38:00.000-08:00</published><updated>2008-02-07T21:39:13.118-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patient information security'/><title type='text'></title><content type='html'>An interesting book from the CEO of Kaiser Permanente, George  Halvorson: &lt;a href="http://www.healthcarereformnow.org/"&gt;http://www.healthcarereformnow.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In the second hard truth, Mr. Halvorson discusses care linkage deficiencies, of which he describes how medical doctors creates paper based medical records for their patients.&lt;br /&gt;&lt;br /&gt;It is commendable that a person like Mr. Halvorson which has so much influence, is actively driving for digitizing health care records. If these records are made easily available to care providers as well as care recipients, great efficiencies can be created.&lt;br /&gt;&lt;br /&gt;Digitizing medical records does come with some security concerns, which should be addressed. Only authorized personnel should have access. Anecdotal evidence which I have seen and heard points to the need for improving the culture in the health care industry in regards to safe guarding patient information. An awareness campaign is needed among care givers to educate them on how to best secure such information. Furthermore, tools needs to be made available to the health care professionals which allows them to continue to provide healthcare without being bogged down with security measures hindering them in their work.&lt;br /&gt;&lt;br /&gt;These tools should address the who, what, when and where in regards to access to highly sensitive information such as patient records, while enabling the health care professionals to spend more time caring for patients. So these tools must enable secure collaboration so each professional who needs access to information readily has this information, however is restricted to only this information and not all information of all patients.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-2619364521763542209?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/2619364521763542209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=2619364521763542209' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2619364521763542209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/2619364521763542209'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/interesting-book-from-ceo-of-kaiser.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4016401730564167899</id><published>2008-02-07T21:10:00.000-08:00</published><updated>2008-02-07T21:13:49.401-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HBI article'/><title type='text'></title><content type='html'>An article discussing learning to address High Business Impact, HBI, in the enterprise in the SC magazine written by Joel Christner with Reconnex: &lt;a href="http://www.scmagazineus.com/Learning-applications-Revolutionizing-data-loss-prevention/article/105073/"&gt;http://www.scmagazineus.com/Learning-applications-Revolutionizing-data-loss-prevention/article/105073/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4016401730564167899?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4016401730564167899/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4016401730564167899' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4016401730564167899'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4016401730564167899'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/article-discussing-learning-to-address.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1924267313680893271</id><published>2008-02-07T20:44:00.001-08:00</published><updated>2008-02-07T21:53:48.833-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Entitlement management'/><title type='text'></title><content type='html'>Entitlement management&lt;br /&gt;&lt;br /&gt;Entitlement management is important not only for your security posture, it is also important for your compliance efforts for SOX and PCI.&lt;br /&gt;&lt;br /&gt;The problem with entitlement management is of course to know who has access to what. You probably know who unless you have too broad of an access policy on your information. How would you know if you have to broad of an access? You need to scan for large user groups, and global groups. These groups should not be allowed for sensitive and highly sensitive information. Do you know all the instances within your organization of sensitive and highly sensitive information? You can of course use DLP to scan for these information types. The problem is of course that the DLP solutions do not map back to who had access when.&lt;br /&gt;&lt;br /&gt;With these questions/problems, what are you to do?&lt;br /&gt;&lt;br /&gt;One, you should scan all your information, and identify where you have highly sensitive and sensitive information.&lt;br /&gt;&lt;br /&gt;When this has been identified, you need to keep a persistent classification of the information, so a classification solution must be deployed and implemented.&lt;br /&gt;&lt;br /&gt;When you have applied the classification, you need to ensure that the large groups and or global groups do not have access to this information.&lt;br /&gt;&lt;br /&gt;For information where you need to validate that users who should have access have access, and users who should not have access does not have access, custodians of the sensitive information are required to validate the users who has access. By forcing the validation at the lowest level possible, you can effectively address the biggest problem in organizations today, which is entitlement creep. Entitlement creep happens when employees move from one job to another, or the job changes over time, and access needs change with them. Most often, when this happens, the employee gets access to the new areas needed for their job, but the old entitlements are not removed. By clearly assigning custodianship at as low of a level as possible, this can be taken care of if the custodians are reminded periodically to validate who should have access, and that they are aware that they are also audited agaist their accountability&lt;br /&gt;&lt;br /&gt;In other words, the full solution is to map your scanning of sensitive information to your identity management systems, as well as a classification and remediation solution&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1924267313680893271?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1924267313680893271/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1924267313680893271' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1924267313680893271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1924267313680893271'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/entitlement-management-entitlement.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-6024955929789251082</id><published>2008-02-06T22:26:00.000-08:00</published><updated>2008-02-06T22:31:44.406-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Users have access to too much information'/><title type='text'></title><content type='html'>According to the Ponemon institute, 69% of employees have access to too much information. This validates the need for tigther entitlement management: &lt;a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=206104613&amp;amp;subSection=News"&gt;http://www.informationweek.com/news/showArticle.jhtml?articleID=206104613&amp;amp;subSection=News&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-6024955929789251082?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/6024955929789251082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=6024955929789251082' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6024955929789251082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/6024955929789251082'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/according-to-ponemon-institute-69-of.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1509360803069700745</id><published>2008-02-04T20:17:00.001-08:00</published><updated>2008-02-04T20:17:40.093-08:00</updated><title type='text'></title><content type='html'>An article by Rich Mogull about selecting the right DLP solution for your needs: &lt;a href="http://www.networkworld.com/columnists/2008/020408insider.html"&gt;http://www.networkworld.com/columnists/2008/020408insider.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Amongst his most important criteria is to identify your key stakeholders within the organization, then agree on what problems to solve and how, then choose the right solution. I very much agree on this approach.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1509360803069700745?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1509360803069700745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1509360803069700745' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1509360803069700745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1509360803069700745'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/article-by-rich-mogull-about-selecting.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-9125805542190889329</id><published>2008-02-04T17:41:00.001-08:00</published><updated>2008-02-04T17:41:36.126-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vontu coverage on CNN.com'/><title type='text'></title><content type='html'>Vontu gets coverage on CNNMoney.com for winning a contract protecting health information at The Mount Sinai Medical Center. It seems that Mount Sinai chose a desktop/laptop solution to protect their information: &lt;a href="http://money.cnn.com/news/newsfeeds/articles/marketwire/0356611.htm"&gt;http://money.cnn.com/news/newsfeeds/articles/marketwire/0356611.htm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-9125805542190889329?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/9125805542190889329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=9125805542190889329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/9125805542190889329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/9125805542190889329'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/vontu-gets-coverage-on-cnnmoney.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-4387163008678919824</id><published>2008-02-04T17:35:00.000-08:00</published><updated>2008-02-04T17:40:59.572-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Agent or not'/><title type='text'></title><content type='html'>Agent versus no agent what is the right answer?&lt;br /&gt;&lt;br /&gt;When looking at DLP as well as other security products such as patch management, anti virus etc, the question comes to mind, is an agent on the end point the answer to the question?&lt;br /&gt;&lt;br /&gt;It is neither yes or no. Agents have two main problems, reach and failure rate. For reach, you have to either force an agent out via a systems management systems solution, GPO, script, or distribution via a portal. To have a 100% reach for a large usually becomes either too expensive or outright impossible if your network is segmented into areas of different management segments, such as lab versus production.&lt;br /&gt;&lt;br /&gt;The right answer is a mix, where you use agents on high risk desktops, laptops and mobile devices, applications or appliances on email servers and data center servers such as repository systems line of business applications and data bases, and applications/appliances on network ingress/egress points. It is also important to note that if you need to transport sensitive information between organizations, you need to ensure contractual obligations are put in place and met between the organizations.&lt;br /&gt;&lt;br /&gt;There are several good ways to deploy agents. One is to use Group Policy Software Installation, GPSI, another is to use System Center, Tivoli or other agent management systems. You could of course also use a portal such that if a user went to a portal (Line of Business) to retrieve sensitive information, they would have to download and install an agent before they were allowed access to the information. The benefit of using an agent management system is of course the breadth of information these systems provide of installation metrics, health metrics, reach etc.&lt;br /&gt;&lt;br /&gt;In my opinion, the perfect agent would be installed seamlessly via an agent management system, and control what the user can do with the information without impeding productivity. So for example, blocking USB might not be the answer if the user has a genuine need to transport information using a USB key. A better solution would be, if information goes on a USB, is it sensitive and is it protected? If the information is sensitive and it is not protected, the solution should interact with the user and make it easy to do the right thing. The same goes for emails, and any other communication where the user may divulge sensitive information. For file transfers, a transfer would either be approved or disapproved based on the content sensitivity and where it is going, and protected appropriately.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-4387163008678919824?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/4387163008678919824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=4387163008678919824' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4387163008678919824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/4387163008678919824'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/agent-versus-no-agent-what-is-right.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-5785212636088238152</id><published>2008-02-01T14:52:00.000-08:00</published><updated>2008-02-01T14:59:40.612-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Omnibank looses customer information'/><title type='text'></title><content type='html'>Omnibank customer information stolen leading to the creation of false ATM card which criminals then used to obtain cash: &lt;a href="http://breachblog.com/2008/01/28/omni.aspx"&gt;http://breachblog.com/2008/01/28/omni.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;According to news stories, the amounts lost were small, but there was clearly an inconvenience to the customers of the bank.&lt;br /&gt;&lt;br /&gt;Unfortunately, these types of attacks will continue to occur.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-5785212636088238152?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/5785212636088238152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=5785212636088238152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5785212636088238152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5785212636088238152'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/omnibank-customer-information-stolen.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-526672431463117487</id><published>2008-02-01T13:22:00.000-08:00</published><updated>2008-02-01T13:33:29.499-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Un-encrypted laptops stays in the office'/><title type='text'></title><content type='html'>Britons working for the UK government are now banned from removing laptops from their offices unless they are encrypted: &lt;a href="http://www.personneltoday.com/articles/2008/01/22/44056/laptops-containing-protected-data-banned-from-leaving-public-sector-offices.html"&gt;http://www.personneltoday.com/articles/2008/01/22/44056/laptops-containing-protected-data-banned-from-leaving-public-sector-offices.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The real question is, is this an enforceable policy? It migth be, but then it begs the question, can current productivty among civil servants be sustained? The answer is no, unless there is a effort put in place to enable civil cervants to encrypt their laptop content easily.&lt;br /&gt;&lt;br /&gt;This issue highlights two important areas for compliance. First of all, do you have effective policies addressing your areas of risk? By effective, I mean, are they clear and understandable, and are the users governed by the policies aware of them. Second important area, is of course compliance to policy. How do you effectively enforce, monitor and audit for compliance to your policy?&lt;br /&gt;&lt;br /&gt;The hard part is of course to balance policy/compliance with business needs. If your policy and compliance efforts impede your business, then you face loss of productivty and probably profits. So a balance between business needs and your security/compliance needs must be obtained.&lt;br /&gt;&lt;br /&gt;The best way to achieve this, is of course to evaluate your current risk profile, and decide if the current risk is something you are willing to accept or not. If you are not willing to accept your current risk, then you must put in place mitigations that moves the risk level to where you are comfortable.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-526672431463117487?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/526672431463117487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=526672431463117487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/526672431463117487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/526672431463117487'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/britons-working-for-uk-government-are.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-5362902497656981857</id><published>2008-02-01T12:53:00.000-08:00</published><updated>2008-02-01T13:11:23.368-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gartner predicts a move away from notebooks'/><title type='text'></title><content type='html'>Gartner predicts that users will move to pocketable devices by 2012: &lt;a href="http://gartner.com/it/page.jsp?id=593207"&gt;http://gartner.com/it/page.jsp?id=593207&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This means that we need to start thinking about content management on mobile devices. There are already systems available that enables full encryption on these devices, but they are not broadly deployed yet.&lt;br /&gt;&lt;br /&gt;A different way of controlling sensitive information on these types of devices would of course be to give information persistent protection at the aggregation points such as email servers, and for line of busines applications at the web interface. DRM is a good solution for this space. You can control who has access when, and to a certain point where, compared to just letting the information get to the devices unprotected.&lt;br /&gt;&lt;br /&gt;Here is a link to what Symantec has to say about mobile phone security: &lt;a href="http://www.symantec.com/about/news/release/article.jsp?prid=20060404_01"&gt;http://www.symantec.com/about/news/release/article.jsp?prid=20060404_01&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-5362902497656981857?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/5362902497656981857/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=5362902497656981857' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5362902497656981857'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/5362902497656981857'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/02/gartner-predicts-that-users-will-move.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1606461347718006529</id><published>2008-01-31T19:40:00.000-08:00</published><updated>2008-01-31T19:46:04.326-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IBM deploys PGP'/><title type='text'></title><content type='html'>Bold and commendable move by IBM&lt;br /&gt;&lt;br /&gt;IBM is deploying PGP to more than 350,000 employees enabling all these employees to keep their sensitive information confidential even if they should loose their laptop: &lt;a href="http://techworld.com/security/news/index.cfm?newsID=11272&amp;amp;pagtype=samechan"&gt;http://techworld.com/security/news/index.cfm?newsID=11272&amp;amp;pagtype=samechan&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1606461347718006529?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1606461347718006529/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1606461347718006529' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1606461347718006529'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1606461347718006529'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/01/bold-and-commendable-move-by-ibm-ibm-is.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-1284461791861550513</id><published>2008-01-30T17:21:00.000-08:00</published><updated>2008-01-30T17:22:01.232-08:00</updated><title type='text'></title><content type='html'>Blogging and DLP&lt;br /&gt;&lt;br /&gt;Should you worry about loosing IP or sensitive information through your employees use of blogs? Well, according to intellectual property attorney Stephen M. Nipper says that employees are more likely to leak closely held data through casual e-mails than through carefully thought-out blog entries. Quote is from the book Naked Conversations.&lt;br /&gt;&lt;br /&gt;I assume it is the same Mr. Nipper who has these blogs, and there is some really interesting reads on IP on these blogs: &lt;a href="http://inventblog.com/"&gt;http://inventblog.com/&lt;/a&gt; ,  &lt;a href="http://www.rethinkip.com/"&gt;http://www.rethinkip.com/&lt;/a&gt; and &lt;a href="http://www.shapeblog.com/"&gt;http://www.shapeblog.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;On the other hand, it would also be prudent to search your public presence for sensitive information if you have the capability&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-1284461791861550513?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/1284461791861550513/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=1284461791861550513' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1284461791861550513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/1284461791861550513'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/01/blogging-and-dlp-should-you-worry-about.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-3052382147661654911</id><published>2008-01-30T17:01:00.000-08:00</published><updated>2008-01-30T17:02:07.196-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint growth'/><title type='text'></title><content type='html'>Why companies and organizations need to think about SharePoint and protecting information within SharePoint.&lt;br /&gt;&lt;br /&gt;According to Forrester, &lt;a href="http://www.eweek.com/c/a/Messaging-and-Collaboration/Businesses-Start-Revving-Your-Enterprise-20-Engines/"&gt;SharePoint Leads Way to Enterprise 2.0&lt;/a&gt;. With its capabilities for storing documents as well as providing a collaborative environment with wiki's and other social networking capabilities, comes the issues around content sensitivity, entitlement management, protection, discovery retention and audits.&lt;br /&gt;&lt;br /&gt;Independent Software Vendors are also jumping on the bandwagon enabling SharePoint increase use in the enterprises and other organizations. Further driving the need for securing content on SharePoint: &lt;a href="http://www.crn.com/software/205801189"&gt;http://www.crn.com/software/205801189&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-3052382147661654911?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/3052382147661654911/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=3052382147661654911' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3052382147661654911'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/3052382147661654911'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/01/why-companies-and-organizations-need-to.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7479855274420465913</id><published>2008-01-30T08:31:00.000-08:00</published><updated>2008-01-30T08:35:05.714-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='link to hack-igations'/><title type='text'></title><content type='html'>Here is a link to several good thoughts on various laws and their implications from a DLP perspective: &lt;a href="http://hack-igations.blogspot.com/search/label/credit%20card%20law"&gt;http://hack-igations.blogspot.com/search/label/credit%20card%20law&lt;/a&gt; (credit card laws), &lt;a href="http://hack-igations.blogspot.com/search/label/data%20breach%20notification"&gt;http://hack-igations.blogspot.com/search/label/data%20breach%20notification&lt;/a&gt; (breach notification)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7479855274420465913?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7479855274420465913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7479855274420465913' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7479855274420465913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7479855274420465913'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/01/here-is-link-to-several-good-thoughts.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30088005.post-7122432626358398073</id><published>2008-01-29T22:22:00.001-08:00</published><updated>2008-01-29T22:24:09.200-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Loss news'/><title type='text'></title><content type='html'>In the data loss news:&lt;br /&gt;&lt;br /&gt;58 year old Greek mathematics professor steals data causing losses of $ 361 million:&lt;br /&gt;&lt;a href="http://news.smh.com.au/greek-authorities-accuse-man-of-selling-stolen-dassault-software/20080126-1o9j.html"&gt;http://news.smh.com.au/greek-authorities-accuse-man-of-selling-stolen-dassault-software/20080126-1o9j.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Choice Point settles to the tune of $ 10 million:&lt;br /&gt;&lt;a href="http://www.consumeraffairs.com/news04/2008/01/choicepoint_settle.html"&gt;http://www.consumeraffairs.com/news04/2008/01/choicepoint_settle.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;7 Citibank employees in Singapore is arrested after taking customer data with them to their new employer UBS:&lt;br /&gt;&lt;a href="http://www.ft.com/cms/s/0/83d71216-caab-11dc-a960-000077b07658,dwp_uuid=e8477cc4-c820-11db-b0dc-000b5df10621.html"&gt;http://www.ft.com/cms/s/0/83d71216-caab-11dc-a960-000077b07658,dwp_uuid=e8477cc4-c820-11db-b0dc-000b5df10621.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Laptop theft leaves unencrypted healthcare information and customer data unaccounted for at an &lt;a href="http://www.telegram.com/article/20080124/ALERT01/769284629"&gt;HMO&lt;/a&gt;,and a &lt;a href="http://software.silicon.com/security/0,39024655,39169821,00.htm"&gt;retailer&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30088005-7122432626358398073?l=nformationprotection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nformationprotection.blogspot.com/feeds/7122432626358398073/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30088005&amp;postID=7122432626358398073' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7122432626358398073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30088005/posts/default/7122432626358398073'/><link rel='alternate' type='text/html' href='http://nformationprotection.blogspot.com/2008/01/in-data-loss-news-58-year-old-greek.html' title=''/><author><name>Olav</name><uri>http://www.blogger.com/profile/08161024474239048756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_ksBQLf65JpU/R3SSQaElp-I/AAAAAAAAAAM/lPp1Bv5DjwU/S220/San%2520Francisco%2520050.jpg'/></author><thr:total>0</thr:total></entry></feed>
