What’s the best way to protect sensitive data?
The answer, of course, is “it depends.” Organizations hold too many different types of sensitive information. They also use too many ways to store and share it. Therefore no single approach fits every case. Instead, each of the common methods—encryption, tokenization, masking, and redaction—suits a particular use case.
Encryption
Typical uses:
- Secure data exchange
- Protecting data at rest
- Structured and unstructured data
Encryption is the strongest and most commonly-used method for protecting sensitive data. In fact, when you implement it properly, no known technology can defeat it.
Encryption uses complex algorithms to convert the original data (plaintext) into unreadable blocks of text (ciphertext). Without the appropriate decryption key, no one can turn that ciphertext back into readable form.
Organizations can apply encryption in many different ways. Each way suits a different use case:
- Network encryption protects data as it travels, and leaves data in the clear at either end of a transmission.
- Transparent encryption protects data at rest, then decrypts the data before authorized users access it.
- Persistent encryption protects data wherever it is stored or copied, so it gives maximum protection against inappropriate use.
- Format preserving encryption protects data while it maintains the original formatting and length.
Tokenization
Typical uses:
- Payment processing systems
- Structured data
Tokenization, like encryption, is reversible. It replaces sensitive data with values that unauthorized parties cannot use. While encryption generates ciphertext from plaintext, tokenization substitutes randomly-generated characters in the same format (token values). A token server stores the relationships between the original values and the token values. Then, when a user or application needs the correct data, the tokenization system looks up the token value and retrieves the original.
Companies often use tokenization to protect credit card numbers and other sensitive information. For example, payment processing systems, customer service databases, and other structured data environments all rely on it. However, length-and-format-preserving encryption can address the same use cases, often with less complexity.
Masking
Typical uses:
- Test environments
- Structured data
Masking is essentially permanent tokenization. Random characters replace sensitive information in the same format as the original data. However, no mechanism retrieves the original values. Because of that, masking suits test environments, which need realistic-looking data but cannot hold actual customer or employee data.
You can also use masking to control access to sensitive data based on entitlements. This approach, known as dynamic data masking, lets authorized users and applications retrieve unmasked data from a database. Meanwhile, it gives masked data to users who may not view the sensitive information.
Redaction
Typical uses:
- Unstructured data
- Legacy data
Redaction permanently removes sensitive data—the digital equivalent of “blacking out” text in printed material. In practice, redaction simply deletes characters from a file or database record. Alternatively, it replaces those characters with asterisks or other placeholders.
Automated data redaction effectively eliminates sensitive data from documents, spreadsheets, and other files. Meanwhile, it leaves the remaining file contents intact. Organizations often adopt this approach because sensitive information spreads once someone extracts it from a database and saves it on file servers, laptops, or desktops.
Choosing a Solution
When users, teams, or organizations share sensitive information, persistent encryption is the most effective option. No other technology protects adequately against misuse while it still allows access by authorized parties. Therefore a detailed strategy for encryption key management is essential. That strategy covers key creation, storage, exchange, and rotation. Because PK Protect needs no endpoint software, its data encryption quickly secures files and data. It also requires no application changes, additional infrastructure, or professional services. And it accomplishes all this without disrupting existing workflows.
For other use cases, your organization’s data profile and compliance goals should drive the choice between encryption, tokenization, masking, and redaction. In some cases, a combination of technologies works best. For example, PK Protect pairs data masking with data encryption to mask or redact sensitive information. As a result, you protect privacy while you maximize data value.
PKWARE can help your organization design and implement a data security strategy that protects data at the moment of creation. Then the strategy keeps data safe wherever files travel. Find out how the data encryption and data masking capabilities in PK Protect help you meet your data protection and compliance goals. Get a free personalized demo now.
