Data-Centric Security and EU General Data Protection Regulation (GDPR)
Companies need to use an Enterprise Digital Rights Management (EDRM) to control access and use of information in stand-alone files and emails (known as ‘unstructured’ information). This technology (also called Information Right Management or IRM), enables safe data in transit and at rest. Unlike simple encryption, EDRM assigns rights that travel with the data as opposed to simply assigning rights on the system where it's stored.
Ask yourself, “What are the technologies I need?”
While 15% of EU citizens report not trusting businesses with their information, they also lack the tools and training necessary to securely manage their own private information.
EnterpriseGRC Solutions partners with vendors to align their solutions with the regulatory problems that they solve. Seclore is among our clients and highly recommended solutions. If you want to learn more about SECLORE visit Data Centric Security & Rights Management Solutions | Seclore. Please let them know that Robin sent you.
Presented by:
Robin Basham, CEO, Founder, EnterpriseGRC Solutions
Warning, this presentation was created in 2017.
Most content is still relevant.
All that’s sure in life is someone has already lost your data
Designing data strategy is hard
Defining the people who will use that data, even harder
We already see real-world data problems (for example, laptops banned in international flights).
Companies need to use an Enterprise Digital Rights Management (EDRM) to control access and use of information in stand-alone files and emails (known as ‘unstructured’ information). This technology (also called Information Right Management or IRM), enables safe data in transit and at rest. Unlike simple encryption, EDRM assigns rights that travel with the data as opposed to simply assigning rights on the system where it's stored.
Ask yourself, “What are the technologies I need?”
The truth about our private information is we need control over its perpetual use. The companies receiving our data may not have the knowledge, incentive, or bandwidth to implement security for our needs. Technology must empower the citizen to engage in fearless communication, unencumbered by the clunky mechanics of encryption.
We need to tag our assets, restrict them, call them back, and even delete them from locations where they have been stolen or simply wrongly maintained.
Data Centric Security Products Enable Privacy (GDPR, SOC2, NIST 800-53r4 App J, NIST 800-171, CIS CSF, HIPAA, FISMA)
What is the General Data Protection Regulation – GDPR?
The law applies to all citizens under the European Convention. However, it is equally relevant to any US or other foreign national who wishes to do business with most Europe and Australia.
The Seven Principles of GDPR
- Privacy by Design
- Data Protection Officer
- Opt-In for data collection
- Right to be forgotten
- Breach notification
- One-stop shop
- Fines and Enforcement: Violations result in 20 million Euros or 4% of Global Turnover
EU General Data Protection Regulation 2016/679 “GDPR”
Effective May of 2018, GDPR Compliance requires system capabilities to manage citizen privacy; to understand how “sensitive” information comes in, moves around, leaks out. Without enhanced privacy technology integration most businesses won’t be able to “transfer” personal data to:
People don’t trust businesses with their private data
While 15% of EU citizens report not trusting businesses with their information, they also lack the tools to securely manage their own private information.
The data problem is enormous
Issues: Data expiration, Duplicate documents, Documents that no longer serve a business purpose. Most documents exist beyond their legal retention and in many cases, no one knows who owns them.
A breach is a breach – (Common and Not Common Principles)
Aren’t most of us already covered with SOC2 or PCI?
For example, Trust Services Principles and Criteria P6.7 The entity provides notification of breaches and incidents to affected data subjects, regulators, and others consistent with the entity's privacy commitments and system requirements.
For example, PCI DSS V3.2.1 12.10 Implement an incident response plan… responding immediately to a system breach.
For example, 47 out 50 States (US) have Breach Notification laws
General Data Protection Regulation (EU) 2016/679
Article 33 (of 99): “Notification of a personal data breach to the supervisory authority - In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay…”
Even if security within the Enterprise is Perfect – 3rd Party is not
- 41% to 63% of breaches involved third parties
- 71% of companies failed to adequately manage risk of third parties
- 92% of companies planned to expand their use of vendors
- 90% of anti-corruption actions by DOJ involved 3rd parties
Global Data Protection Regulation proposes solving privacy problems with 8 Data Principles
What if customer information leaks and there’s no way to track the location of the lost data?
Security is One Big business Problem:
General Data Protection requires security CIA triad
Aim for the CIA triad: customer information confidentiality, integrity, availability, preventing wrongful disclosure, manipulation, denial of service
Strong security lowers cyber insurance cost.
Improved cybersecurity earn higher service price and faster service adoption.
Strong cybersecurity gains the approval of major assessors and regulators like FTC, FCC, FDIC, PCI, AICPA, DOJ, ISO and EU
Data-centric security tools reduce security problems
Risk: Stolen (lost) laptop
Actual Risk: Premature breach notification
“Absence of evidence” = no evidence to defend a data breach
Default access to information is set to private, enforcing privacy by design
Log and audit functions exist to prove compliance and even to enforce remediation to violations of access
Response: Early detection of irregular distribution of files leads to better incident identification and response
Data Centric Security Supports Fair and Lawful Processing
GDPR requires that people give their consent to how their data is used
Over time, if the customer or employee disagrees with how the data is being used or with the accuracy of the data, then what?
How do we modify protection on a document once it has left our perimeter?
Data Centric Security Supports Fair and Lawful Processing
Protection persistence travels beyond the perimeter and is tied to the customer’s data.
Based on our understanding, the permissions we grant will change
Companies must honor all reasonable requests to stop processing or ENABLING USE of citizen private information
Audits and Activity Logging create a capacity to perform web-based audits and easily examine a trail of all activities performed on all files for all use.
Proving Fair and Lawful Processing
Information-Centric Audits and Activity Logging offers the ability to:
Perform web-based audit trail of all activities performed on all files for all use
Operate with real-time auditing
Notify file owners for unauthorized file activities; Send a daily digest to file owners summarizing all the day’s file activities; Restrict access to audit logs based on administrative access (e.g. allowed to view only the audit logs of their group/OU); Filter activity logs based on specific criteria; export audit logs as stand-alone files
Offer users the ability to monitor the usage of files protected by him/her
Log unauthorized attempts to access and use a file; log file activities while offline; log forensic audit details (machine name, IP address, file path etc.); export audit logs to other reporting and log correlation tools (e.g., BI, SIEM etc.); log access to audit logs for administrators and power
Right to Erasure (“Right to Be Forgotten”)
Individuals have the right to require a company to delete their personal data if the continued processing of data is not justified (especially where the data is inaccurate or incomplete).
Once the business has built operational dependencies on shared information, getting that data back involves a number of business impacts.
Enterprise Data Rights Management (EDRM) and Electronic File Synch and Storage (EFSS) make it possible to remove visibility to that information no matter where it is in the world.
One-Stop-Shop – Centralized Consistent Privacy
European Data Protection Board (EDPB) is far less likely to find fault with an organization taking active protection measures involving data-centric privacy. With data centric security there’s evidence of consistent rules applied at the moment information is taken into business custody and throughout the data lifecycle.
Avoids over dependence on file encryption
- If your answer to protecting data is encryption, consider that encryption on its own can be hacked and the greatest barrier to its success is that people simply don’t use it.
- File encryption alone isn’t persistent, doesn’t protect a file while it is open, does not support revoking access after distribution, and doesn’t provide tracking of what is happening with the file.
- A data centric product and program approach
- Know your data flow
- Identify EU citizen personal data
- Flag systems needing opt-in, EU data access, correction and deletion requests, and age-gating requirements
Shore up your ISMS
- Things to get right:
- encryption or pseudonymization of personal data
- processes and capabilities to handle personal data access, correction, deletion and
- portability requests
- a Data Protection Impact Assessment process
- a data breach response plan
- Some Technologies are more important - DRM plus EFSS
Digital or Information Rights Management (DRM):
A set of technologies that provides control over how a given piece of protected content can be used including what the recipient can do with the file, for how long and from which device/IP location. Rights Management also provides rich tracking wherever the file goes and provides modification of usage controls or revocation of usage.
Enterprise file sync-and-share (EFSS):
Enterprise file sync-and-share is a service that allows users to save files in cloud or on-premises storage and then access them on other desktop and mobile computing devices. This is a baseline product expectation to any modern enterprise, and soon, we’ll find that all persons are using file storage as opposed to local storage. We’ll see less thumb drives and more digital storage.
DLP plus Data Classification
is a comprehensive approach (covering people, processes, and systems) of implementing policies and controls designed specifically to discover, monitor, and protect confidential data wherever it is stored, used, or in transit over the network and at the perimeter. However, while sensitive information can be detected, DLP does nothing to secure information that must be exchanged to complete business processes.
Data classification program:
is a program that categorizes data to convey required safeguards for information confidentiality, integrity, and availability; establishes controls required based on value and level of sensitivity. The challenge is that just because a document is classified, that does nothing to protect the information in transit, at work, or at rest.(Source: Derived from SANS Institute InfoSec Reading Room).
- How do we start a conversation about Global Data Protection? Ask!
- Where is the sensitive data and who owns it?
- How do you know who is accessing it?
- Where is it flowing and how is it shared- including 3rd parties and vendor access?
- What is the quantifiable value and risk?
- How would you like to automate the access control process? What do you most want to accomplish through automation?
Regulatory use cases
- Data-Centric Cybersecurity Risk Management
- Aids Market Entry = solid cybersecurity and a functioning risk management program.
- Answers Customers demand cyber insurance
- Assesses Security Controls is the most critical step of a risk management program.
- Missing the tools and expertise to manage data-centric security = missing the business boat.
Data-Centric emphasis in meeting GDPR
- Data-centric security products (like SECLORE) can have an impact on enabling, tracking, or verifying control objectives across multiple control framework domains. The majority of articles with applicability from GDPR are identified within the domains of:
- Controller and Processor
- Transfer of personal data to third countries or international organizations
- Independent Supervisory Authorities
- Co-operation and Consistency
- Security Risk Assessment Frameworks include data-centric control requirements
We found 144 Control Assertions or objectives that could be better enabled through the implementation of SECLORE application features.
Protecting the Cloud-Based Business Environments presents major challenges
Understanding a kill chain allows you to slow down your adversaries
- Handle changes to major US & World regulations
- Transfer & manage cyber risk
- Support Cyber Insurance requirements for due diligence, consistent risk assessment and remediation
- Stop cloud and container environment data exfiltration
- Harness the issue of too many environments and too many things for a traditional risk management approach
How to Address Your IT Security
- The only way to know whether a security control works or not, or passes or fails, is to test it.
- For a configuration with known best practices, we can use CIS Security Benchmark to run SCAP resulting in CIS validation. This is not enough.
- Testing security takes more than just a vulnerability scanning tool that only checks a small number of security controls. Additionally, a vulnerability scan often tests a fraction, approximately five percent, of the security controls.
History of Secure Host Configuration Testing
History of Secure Host Configuration
Make Data the New Perimeter
- Seclore Document Rights Management:
Addresses a Huge Security Gap - Where is the Problem?
- Control Is Important
- Persistent, Granular Usage Controls
- Permanence: Protection persists with the file forever
- Remote Control:
File rights can be changed from anywhere in the world - Audit Trail:
All activities are tracked - Automatically Audits Usage of Information
- Automatically captures and consolidates file usage data from distributed environments:
WHO accessed the file,
- WHAT the user did with the file,
- WHEN and from WHERE
- Usage Policy Attributes
- Easily Access Protected Documents
- Browser-based access
- Lite-weight agents
- iPhone, iPad, Android, Windows
- Automated Usage Policies Applied to Files
- Automate File Protection with Pre-Built Connectors
- Utilize Any File-Sharing Method Without Risk
- Protection stays with the file regardless of how it is shared or how it is accessed and utilized
Q & A
Regulatory Compliance: Is Your Organization Ready for GDPR & NIST? Attend SC Vendor Webcast, sponsored by SECLORE and including EnterpriseGRC Solutions.

Whether your business resides in the US or Europe or just does business in these regions, regulations such as the General Data Protection Regulation (GDPR) and National Institute of Standards and Technology (NIST) will impact how you do business and with whom you will do business. But what if you could freely cross borders with your regulated data and still be compliant and in control of your data?
Join us for one hour to hear from three experts on what you need to know to get ready for GDPR and NIST before the deadline, and how you can utilize a data-centric security strategy to quickly overcome challenges to being compliant.
In the Webinar you’ll learn:
- Key questions to consider when starting your compliance journey
- How to efficiently address common cross-regulation compliance issues
- How to collaborate and share information outside your company’s borders and still be compliant and secure
Who Should Attend?
If your role is in information security, data loss protection, governance, risk, and compliance, or IT, don’t miss this webcast.
Speakers
Robin Basham
CEO, Founder, EnterpriseGRC Solutions, Inc.
Bob Metzger
Shareholder, Rogers Joseph O’Donnell, P.C.
Lisa Harchuck Popadic
Director of Legal Business Development, Seclore
Event Registration
Countdown to Regulatory Compliance: Is Your Organization Ready for GDPR & NIST?
Whether your business resides in the US or Europe or just does business in these regions, regulations such as the General Data Protection Regulation (GDPR) and National Institute of Standards and Technology (NIST) will impact how you do business and with whom you will do business. But what if you could freely cross borders with your regulated data and still be compliant and in control of your data?
Join us for one hour to hear from three experts on what you need to know to get ready for GDPR and NIST before the deadline, and how you can utilize a data-centric security strategy to quickly overcome challenges to being compliant.
In the Webinar you’ll learn:
- Key questions to consider when starting your compliance journey
- How to efficiently address common cross-regulation compliance issues
- How to collaborate and share information outside your company’s borders and still be compliant and secure
Who Should Attend?
If your role is in information security, data loss protection, governance, risk and compliance, or IT, don’t miss this webcast.
To start registration, please enter your details below and click Continue
Seclore;

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics