Data-Centric Security and EU General Data Protection Regulation (GDPR)

Companies need to use an Enterprise Digital Rights Management (EDRM) to control access and use of information in stand-alone files and emails (known as ‘unstructured’ information). This technology (also called Information Right Management or IRM), enables safe data in transit and at rest. Unlike simple encryption, EDRM assigns rights that travel with the data as opposed to simply assigning rights on the system where it's stored.

Ask yourself, “What are the technologies I need?”

While 15% of EU citizens report not trusting businesses with their information, they also lack the tools and training necessary to securely manage their own private information.

EnterpriseGRC Solutions partners with vendors to align their solutions with the regulatory problems that they solve. Seclore is among our clients and highly recommended solutions. If you want to learn more about SECLORE visit Data Centric Security & Rights Management Solutions | Seclore. Please let them know that Robin sent you.


Presented by:
Robin Basham, CEO, Founder, EnterpriseGRC Solutions
Warning, this presentation was created in 2017.
Most content is still relevant.

All that’s sure in life is someone has already lost your data

Designing data strategy is hard

Defining the people who will use that data, even harder

We already see real-world data problems (for example, laptops banned in international flights).

Companies need to use an Enterprise Digital Rights Management (EDRM) to control access and use of information in stand-alone files and emails (known as ‘unstructured’ information). This technology (also called Information Right Management or IRM), enables safe data in transit and at rest. Unlike simple encryption, EDRM assigns rights that travel with the data as opposed to simply assigning rights on the system where it's stored.

Ask yourself, “What are the technologies I need?”

The truth about our private information is we need control over its perpetual use. The companies receiving our data may not have the knowledge, incentive, or bandwidth to implement security for our needs.  Technology must empower the citizen to engage in fearless communication, unencumbered by the clunky mechanics of encryption.

We need to tag our assets, restrict them, call them back, and even delete them from locations where they have been stolen or simply wrongly maintained.

Data Centric Security Products Enable Privacy (GDPR, SOC2, NIST 800-53r4 App J, NIST 800-171, CIS CSF, HIPAA, FISMA)

What is the General Data Protection Regulation – GDPR?

The law applies to all citizens under the European Convention. However, it is equally relevant to any US or other foreign national who wishes to do business with most Europe and Australia.

The Seven Principles of GDPR

  1. Privacy by Design
  2. Data Protection Officer
  3. Opt-In for data collection
  4. Right to be forgotten
  5. Breach notification
  6. One-stop shop
  7. Fines and Enforcement: Violations result in 20 million Euros or 4% of Global Turnover

EU General Data Protection Regulation 2016/679 “GDPR”

Effective May of 2018, GDPR Compliance requires system capabilities to manage citizen privacy; to understand how “sensitive” information comes in, moves around, leaks out. Without enhanced privacy technology integration most businesses won’t be able to “transfer” personal data to:

People don’t trust businesses with their private data

While 15% of EU citizens report not trusting businesses with their information, they also lack the tools to securely manage their own private information.

The data problem is enormous

Issues: Data expiration, Duplicate documents, Documents that no longer serve a business purpose. Most documents exist beyond their legal retention and in many cases, no one knows who owns them.

A breach is a breach – (Common and Not Common Principles)

Aren’t most of us already covered with SOC2 or PCI? 

For example, Trust Services Principles and Criteria P6.7 The entity provides notification of breaches and incidents to affected data subjects, regulators, and others consistent with the entity's privacy commitments and system requirements.​

For example, PCI DSS V3.2.1 12.10 Implement an incident response plan… responding immediately to a system breach.​

For example, 47 out 50 States (US) have Breach Notification laws

General Data Protection Regulation (EU) 2016/679

Article 33 (of 99): “Notification of a personal data breach to the supervisory authority - In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay…”


Even if security within the Enterprise is Perfect – 3rd Party is not

  • 41% to 63% of breaches involved third parties
  • 71% of companies failed to adequately manage risk of third parties
  • 92% of companies planned to expand their use of vendors
  • 90% of anti-corruption actions by DOJ involved 3rd parties

Global Data Protection Regulation proposes solving privacy problems with 8 Data Principles

What if customer information leaks and there’s no way to track the location of the lost data?

Security is One Big business Problem:

General Data Protection requires security CIA triad

Aim for the CIA triad: customer information confidentiality, integrity, availability, preventing wrongful disclosure, manipulation, denial of service

Strong security lowers cyber insurance cost.

Improved cybersecurity earn higher service price and faster service adoption.

Strong cybersecurity gains the approval of major assessors and regulators like FTC, FCC, FDIC, PCI, AICPA, DOJ, ISO and EU

Data-centric security tools reduce security problems

Risk: Stolen (lost) laptop

Actual Risk: Premature breach notification

“Absence of evidence” = no evidence to defend a data breach

Default access to information is set to private, enforcing privacy by design

Log and audit functions exist to prove compliance and even to enforce remediation to violations of access

Response: Early detection of irregular distribution of files leads to better incident identification and response

Data Centric Security Supports Fair and Lawful Processing

GDPR requires that people give their consent to how their data is used

Over time, if the customer or employee disagrees with how the data is being used or with the accuracy of the data, then what?

How do we modify protection on a document once it has left our perimeter?

Data Centric Security Supports Fair and Lawful Processing

Protection persistence travels beyond the perimeter and is tied to the customer’s data.

Based on our understanding, the permissions we grant will change

Companies must honor all reasonable requests to stop processing or ENABLING USE of citizen private information

Audits and Activity Logging create a capacity to perform web-based audits and easily examine a trail of all activities performed on all files for all use

Proving Fair and Lawful Processing

Information-Centric Audits and Activity Logging offers the ability to:

Perform web-based audit trail of all activities performed on all files for all use

Operate with real-time auditing 

Notify file owners for unauthorized file activities; Send a daily digest to file owners summarizing all the day’s file activities; Restrict access to audit logs based on administrative access (e.g. allowed to view only the audit logs of their group/OU); Filter activity logs based on specific criteria; export audit logs as stand-alone files 

Offer users the ability to monitor the usage of files protected by him/her 

Log unauthorized attempts to access and use a file; log file activities while offline; log forensic audit details (machine name, IP address, file path etc.); export audit logs to other reporting and log correlation tools (e.g., BI, SIEM etc.); log access to audit logs for administrators and power

Right to Erasure (“Right to Be Forgotten”)

Individuals have the right to require a company to delete their personal data if the continued processing of data is not justified (especially where the data is inaccurate or incomplete).

Once the business has built operational dependencies on shared information, getting that data back involves a number of business impacts.

Enterprise Data Rights Management (EDRM) and Electronic File Synch and Storage (EFSS) make it possible to remove visibility to that information no matter where it is in the world.

One-Stop-Shop – Centralized Consistent Privacy

European Data Protection Board (EDPB) is far less likely to find fault with an organization taking active protection measures involving data-centric privacy.  With data centric security there’s evidence of consistent rules applied at the moment information is taken into business custody and throughout the data lifecycle.

Avoids over dependence on file encryption

  • If your answer to protecting data is encryption, consider that encryption on its own can be hacked and the greatest barrier to its success is that people simply don’t use it.
  • File encryption alone isn’t persistent, doesn’t protect a file while it is open, does not support revoking access after distribution, and doesn’t provide tracking of what is happening with the file.
  • A data centric product and program approach
  • Know your data flow
  • Identify EU citizen personal data
  • Flag systems needing opt-in, EU data access, correction and deletion requests, and age-gating requirements

Shore up your ISMS

  1. Things to get right:
  2. encryption or pseudonymization of personal data
  3. processes and capabilities to handle personal data access, correction, deletion and
  4. portability requests
  5. a Data Protection Impact Assessment process
  6. a data breach response plan
  7. Some Technologies are more important - DRM plus EFSS

Digital or Information Rights Management (DRM):

A set of technologies that provides control over how a given piece of protected content can be used including what the recipient can do with the file, for how long and from which device/IP location.  Rights Management also provides rich tracking wherever the file goes and provides modification of usage controls or revocation of usage.

Enterprise file sync-and-share (EFSS):

Enterprise file sync-and-share is a service that allows users to save files in cloud or on-premises storage and then access them on other desktop and mobile computing devices. This is a baseline product expectation to any modern enterprise, and soon, we’ll find that all persons are using file storage as opposed to local storage.  We’ll see less thumb drives and more digital storage. 

DLP plus Data Classification

is a comprehensive approach (covering people, processes, and systems) of implementing policies and controls designed specifically to discover, monitor, and protect confidential data wherever it is stored, used, or in transit over the network and at the perimeter.  However, while sensitive information can be detected, DLP does nothing to secure information that must be exchanged to complete business processes. 

Data classification program:

is a program that categorizes data to convey required safeguards for information confidentiality, integrity, and availability; establishes controls required based on value and level of sensitivity.  The challenge is that just because a document is classified, that does nothing to protect the information in transit, at work, or at rest.(Source: Derived from SANS Institute InfoSec Reading Room).

  • How do we start a conversation about Global Data Protection? Ask!
  • Where is the sensitive data and who owns it?
  • How do you know who is accessing it?
  • Where is it flowing and how is it shared- including 3rd parties and vendor access?
  • What is the quantifiable value and risk?
  • How would you like to automate the access control process? What do you most want to accomplish through automation?

Regulatory use cases

  1. Data-Centric Cybersecurity Risk Management
  2. Aids Market Entry = solid cybersecurity and a functioning risk management program.  
  3. Answers Customers demand cyber insurance
  4. Assesses Security Controls is the most critical step of a risk management program. 
  5. Missing the tools and expertise to manage data-centric security = missing the business boat.

Data-Centric emphasis in meeting GDPR

  1. Data-centric security products (like SECLORE) can have an impact on enabling, tracking, or verifying control objectives across multiple control framework domains. The majority of articles with applicability from GDPR are identified within the domains of:
  2. Controller and Processor
  3. Transfer of personal data to third countries or international organizations
  4. Independent Supervisory Authorities
  5. Co-operation and Consistency
  6. Security Risk Assessment Frameworks include data-centric control requirements

We found 144 Control Assertions or objectives that could be better enabled through the implementation of SECLORE application features. 

Protecting the Cloud-Based Business Environments presents major challenges

Understanding a kill chain allows you to slow down your adversaries

  1. Handle changes to major US & World regulations
  2. Transfer & manage cyber risk
  3. Support Cyber Insurance requirements for due diligence, consistent risk assessment and remediation
  4. Stop cloud and container environment data exfiltration
  5. Harness the issue of too many environments and too many things for a traditional risk management approach

How to Address Your IT Security

  • The only way to know whether a security control works or not, or passes or fails, is to test it.
  • For a configuration with known best practices, we can use CIS Security Benchmark to run SCAP resulting in CIS validation. This is not enough.
  • Testing security takes more than just a vulnerability scanning tool that only checks a small number of security controls. Additionally, a vulnerability scan often tests a fraction, approximately five percent, of the security controls.

History of Secure Host Configuration Testing

History of Secure Host Configuration

Make Data the New Perimeter

  • Seclore Document Rights Management: 
    Addresses a Huge Security Gap
  • Where is the Problem?
  • Control Is Important
  • Persistent, Granular Usage Controls
  • Permanence: Protection persists with the file forever
  • Remote Control: 
    File rights can be changed from anywhere in the world
  • Audit Trail:
    All activities are tracked
  • Automatically Audits Usage of Information
  • Automatically captures and consolidates file usage data from distributed environments:

WHO accessed the file,

  • WHAT the user did with the file,
  • WHEN and from WHERE             
  • Usage Policy Attributes
  • Easily Access Protected Documents
  • Browser-based access
  • Lite-weight agents
  • iPhone, iPad, Android, Windows
  • Automated Usage Policies Applied to Files
  • Automate File Protection with Pre-Built Connectors
  • Utilize Any File-Sharing Method Without Risk
  • Protection stays with the file regardless of how it is shared or how it is accessed and utilized

Q & A


Regulatory Compliance: Is Your Organization Ready for GDPR & NIST?  Attend SC Vendor Webcast, sponsored by SECLORE and including EnterpriseGRC Solutions.

Process and Planning

Whether your business resides in the US or Europe or just does business in these regions, regulations such as the General Data Protection Regulation (GDPR) and National Institute of Standards and Technology (NIST) will impact how you do business and with whom you will do business. But what if you could freely cross borders with your regulated data and still be compliant and in control of your data?

Join us for one hour to hear from three experts on what you need to know to get ready for GDPR and NIST before the deadline, and how you can utilize a data-centric security strategy to quickly overcome challenges to being compliant.

In the Webinar you’ll learn: 

  • Key questions to consider when starting your compliance journey
  • How to efficiently address common cross-regulation compliance issues
  • How to collaborate and share information outside your company’s borders and still be compliant and secure 

Who Should Attend? 

If your role is in information security, data loss protection, governance, risk, and compliance, or IT, don’t miss this webcast. 

Speakers
Robin Basham
CEO, Founder, EnterpriseGRC Solutions, Inc.

Bob Metzger
Shareholder, Rogers Joseph O’Donnell, P.C.

Lisa Harchuck Popadic
Director of Legal Business Development, Seclore


Event Registration

Countdown to Regulatory Compliance: Is Your Organization Ready for GDPR & NIST?

Whether your business resides in the US or Europe or just does business in these regions, regulations such as the General Data Protection Regulation (GDPR) and National Institute of Standards and Technology (NIST) will impact how you do business and with whom you will do business. But what if you could freely cross borders with your regulated data and still be compliant and in control of your data?

Join us for one hour to hear from three experts on what you need to know to get ready for GDPR and NIST before the deadline, and how you can utilize a data-centric security strategy to quickly overcome challenges to being compliant.

In the Webinar you’ll learn: 

  • Key questions to consider when starting your compliance journey
  • How to efficiently address common cross-regulation compliance issues
  • How to collaborate and share information outside your company’s borders and still be compliant and secure 

Who Should Attend? 

If your role is in information security, data loss protection, governance, risk and compliance, or IT, don’t miss this webcast. 

To start registration, please enter your details below and click Continue

Seclore; 

Seclore’s Enterprise Digital Rights Management solution enables organizations to persistently control the usage of files wherever they go, both within and outside of organizations’ boundaries.  The ability to automatically enforce and audit who can do what with a file (view, edit, copy, screen capture, print, run macros), from which device and when empowers organizations to embrace BYOD, Cloud services, Enterprise File Synch and Share (EFSS) and external collaboration with confidence.   

Featuring dozens of pre-built connectors for leading enterprise applications (EFSS, DLP, ECM, ERP, and eMail), Seclore’s advanced technology automates the protection of documents as they are downloaded, discovered, and shared to ensure rapid adoption.  Seclore was recently recognized by Frost & Sullivan with a Growth Excellence Award, by Deloitte as one of the ‘50 Fastest Growing Technology Companies,’ and by Gartner as a ‘Cool Vendor,’ due to innovations in browser-based access to protected documents.  With over 4 million users across 400 companies in 29 countries, Seclore expertise and focus on EDRM is helping organizations achieve their data security, governance, and compliance objectives.  

Visit us at www.seclore.com for more information.

Robin Basham

CEO, Founder, EnterpriseGRC Solutions, Inc.

Creator of Facilitated Compliance Management Software and founder of Phoenix Business and Systems Process, Inc., Robin leverages skills spanning security programs, networking and communications, enterprise security architecture and cloud applications, business process, data lifecycle, and systems security continuous monitoring, with proven ability to drive security strategy and management through technology program adoption, automated integrated audit, secure configuration baselines and business technology optimization.  Enterprise ICT GRC and compliance expert and early adopter in both certifying and offering certification programs for Cloud and Virtualization, Robin’s industry experience includes management of systems, controls and data for SaaS (IaaS and PaaS), Finance, Healthcare, Banking, Education, Defense and High Tech.  Robin is a “hands on leader” known for surprising depth in data architecture, programming languages, policy development, and business savvy technical implementations that satisfy all major regulatory requirements.

 
Main Menu