Network and device protection continue to consume IT security resources, but they are becoming less and less effective at protecting organizations from cyber threats. Data breaches are now a daily occurrence, creating massive financial burdens for corporations, government agencies, and consumers.
Perimeter breaches will become even more common in the years to come as data volumes continue to grow and IT architecture evolves away from traditional network-based models. In our new digital environment, data-centric security is the only viable option for keeping sensitive information safe.
What Data-Centric Security Is
Most security technology is concerned with where data sits. It protects a laptop, a server, or the network a file crosses. The weakness is structural. As soon as the file moves somewhere else, either another product has to cover it or it travels unprotected.
Data-centric security starts from the other end. It focuses on what needs protecting, which is the file itself, and applies the right protection wherever that file ends up. Sensitive information is identified as soon as it enters the environment. The protection then stays with it for the life of the data.
How It Works in Practice
A typical implementation is a central management console plus software agents on every asset where sensitive data might be created or stored. That means laptops, desktops, servers, mainframes, and mobile devices. Administrators define the appropriate protection for each data type and use case in the console. Each time a file is created or modified, the agent scans it and applies that protection automatically. Authorized users carry on as normal, and everyone else is locked out, including when the file travels outside the company network.
Four Principles
Every organization needs a solution shaped to its own risk and its own business. Even so, the implementations that work share four things. They are controlled centrally. They cover the whole organization without gaps. They rely on automation rather than manual effort. And they adapt as the business changes.
Central control matters because the usual alternative is user-applied encryption, and that carries three problems. Employees may not protect a file when they should. When they do, they still have to get the password to the recipient somehow, which normally means unencrypted email. And the keys end up held by staff rather than administrators, so a forgotten key or a departing employee can cost the organization permanent access to its own data.
Automation takes the user out of the equation. Nobody should be expected to evaluate and secure everything that crosses their desk in a day. The software watches file activity instead, and protects sensitive data the moment it appears.
Policies, Rules, and Workflows
Three terms get used interchangeably and mean different things. Policies are the written documents that set an organization’s standards. Rules are the software settings that apply those policies to particular cases, such as which locations to watch for card numbers and which keys to protect them with. Workflows are the steps the software actually takes, from scanning a file to tagging it and encrypting it.
Before You Choose a Product
Two pieces of work come first. One is a fresh data risk assessment, covering the types of data being created, the use cases and risks attached to each, how well any existing protection is working, and which mandates apply, whether that is GDPR, PCI DSS, HIPAA, or NYCRR 500. The other is written policy. Most organizations have policies for device and network access, but not for the data itself.
On technology, the paper argues against point solutions. Products that address only one or two use cases create exactly the silos and gaps that data-centric security exists to remove. A platform gives administrators one point of control and room to add capabilities later.
Download this whitepaper to gain insight into:
- An overview of the key principles of data-centric security
- Best practices for designing and implementing an effective data-centric security solution
- Tips on choosing your technology
