110 likes | 426 Views
Data Loss Prevention. Steve Scott Manager, Information Security Operations. Data Loss Prevention . Well, more like Data Loss Identification We watch for data leaving inappropriately Based on “patterns” or Based on our data! 2.7 million records from the data warehouse Updated weekly
E N D
Data Loss Prevention Steve Scott Manager, Information Security Operations
Data Loss Prevention • Well, more like Data Loss Identification • We watch for data leaving inappropriately • Based on “patterns” or • Based on our data! • 2.7 million records from the data warehouse • Updated weekly • Only looking for “ugly” stuff initially
Inappropriate?? • “Clear Text” protocols, like email, pass your data in the clear over the Internet and others along the path can read the data. • Other protocols that are bad: http instead of https, chat, FTP, telnet and others…
Why should we care? • At work, HIPAA • HIPAA violation due to willful neglect but violation is corrected within the required time period $10,000 per violation, with an annual maximum of $250,000 for repeat violations $50,000 per violation, with an annual maximum of $1.5 million • At home, identity theft
Incidents so far • 65 in 60 days • 62 email related • 11 sourced from external addresses • 40 requests for corrective action plans • One vendor running a website improperly