Showing posts with label data classification. Show all posts
Showing posts with label data classification. Show all posts

Wednesday, March 11, 2009

Mission: Possible


It’s a problem with many names. Some refer to it as corporate espionage. Some say it’s business intelligence. Others may even refer to it as spying. Let’s call a spade a spade. It’s not some work of fiction seen only in movies like Mission Impossible or a Tom Clancy novel. Its occurring right here, right now and your organization may be a target. Don’t think so? Neither did The Cleveland Clinic, Kodak, MasterCard, Avery Denison, DuPont, Metaldyne, 3DGeo, or numerous other companies you may or may not have heard of.

Economic espionage, the most commonly accepted term for it, is a federal crime prosecutable under the Economic Espionage Act of 1996. Without getting into technical definitions of what constitutes economic espionage, it is the stealing of trade secrets, from the rightful owner, for the economic benefit of another. As the rightful owner of trade secrets, does this give you a “warm and fuzzy” feeling because there will be repercussions if the offender is caught? Do you feel safe just because someone can be convicted of a crime for stealing your secrets?

There is one hitch however: A provision in the Act that states the owner of that information must take reasonable measures to keep that information secret. What measures are you or your organization taking to ensure that you meet this provision? Are you classifying your data? Are you marking hard and soft copies of files with “Confidential Information”? Are you storing this information in locked file cabinets or safes? Are you using encrypted emails to send this information? Are you encrypting your hard drives on your laptops? Have you had a risk assessment performed? How about a penetration test? Are you educating your employees on what is sensitive information and how to protect it?

If your answer to one or more of these questions is no, good luck trying to convince anyone that you are taking “reasonable measures” to keep your information secret. Lucky for you, if you haven’t already ended up on the front page of the newspaper, you still have time to correct it. This problem can be fixed, and if you made it to this blog, you know who can help you! Good luck!

Read more!

Thursday, August 7, 2008

Data Classification - Time to catch up

After 12 years of protecting U.S. Government’s most sensitive and classified resources, data, personnel, and facilities, I have learned a great number of things. The television show 60 Minutes can do a year's worth of episodes purely on the mismanagement of funding alone at one unnamed facility that I worked at. Argue what you may about the U.S. Government, its spending habits, its leaders, its policies, its “big brother” mentality, or whatever else irks you, but know this: The U.S. Government is the king of data classification. It is better than everyone, including every business you have ever worked for: Fortune 500 companies, financial institutions, manufacturing businesses, utility companies, healthcare facilities, and retail industries.

How does one begin to protect information? Classify it. In order to determine necessary controls and measures that are required to protect information, we must first understand the value of that information. Once the value is understood, we can then determine the impact it will have if it becomes lost or compromised. Will its loss bankrupt our business? Will its compromise put us on the front page of the newspaper? This impact, in turn, determines how it must be protected.

There are dozens of different classifications used in the government. They include Top Secret, Secret, Confidential, Sensitive But Unclassified, , Export Controlled, Limited Distribution, and Restricted Data just to name a few. To take it one step further, the U.S. Government applies handling instructions (like NOFORN or ORCON) and a “Need-To-Know” philosophy to all of its information, meaning that even if I have a Top Secret clearance, I only have access to information that is required for me to fulfill the duties and responsibilities of my position.

Each of these classifications is assigned based on the value of the information and each different classification has it own individual set of instructions for proper handling and safeguarding the information. The higher the value of the data, the more stringent the controls are to protect it.

If your organization doesn’t classify its data, you are most likely not protecting it at a level commensurate to its value, and therefore make it vulnerable to loss or compromise. In data classification, the government reigns. Everyone else, including you, can’t keep up.

Read more!