The Path of Least Resistance

author-image
DQChannels Bureau
New Update

Fullbrook believes that the answer to data infringement is to put in place
controls that not only provide maximum possible security, but also empower
businesses to get on smoothly with their everyday jobs

Advertisment

I am always amazed when I read about data breaches. Inevitably there is
always the admission that there were controls put in place, and that users had
stepped outside of these business processes which had led to the inevitable loss
of valuable assets or data.

Perhaps the area we see this most is where users exchange information with
third parties, and there are numerous public sector breaches over recent years
that perfectly illustrate this point. Whether it is a misplaced laptop, stolen
USB stick or an unencrypted disk that does not get to its final destination when
sent through the post, the sharing of information, an essential part of any
business's every day existence, is fraught with potential pitfalls.

The answer for most businesses is to restrict this exchange of information.
We attempt to stem the tide by insisting that users cannot exchange any
sensitive data without some kind of permission. We implement hard line controls
and provide few options for users that genuinely need to interact with their
customers, partners and suppliers except to use antiquated systems inevitably
provided by over-worked IT staff.

Advertisment

These systems sometimes take days to use, so it is no surprise when users
attempt to circumnavigate them by sending the information through non-authorized
channels, after all they are merely reacting to the rules of the universe, the
path of least resistance.

I believe the answer to this issue, of course, is to put in place controls
that not only provide us with the highest level of security, but also empower
users to get on with their everyday jobs. This balancing act, security versus
productivity, is the cornerstone of any security process and the Holy Grail, the
security control that makes a user's life easier, is something to which we all
strive.

Solution providers, in my opinion, can follow the following criterion:

Provide the highest levels of security for data: Maintaining the security of
data at all times is essential for any solution that is designed for the
exchange of data between third parties or employees. Far too many of today's
off-the-shelf systems provide security for the data in transit, but lack any
kind of controls for when the data is at rest. Any solution should provide a
secure, auditable repository for data as well as providing a totally secure and
auditable method of file transfer. This allows IT to be confident that the
infrastructure will meet their needs, allowing them to relinquish control of
user creation and control to the business owners, which brings us to the next
important step.

Advertisment

Decide which users or with whom can the data be exchanged: In today's IT
environment, it is often the role of security and IT to say what data should/not
be exchanged, and who should/not exchange it. A simple solution to this is to
provide staff with a system that meets the IT requirements of file exchange
(security, ease of use, ease of management) and allow the owners of the
information being exchanged to authorize who can/not exchange their data. They
will know whether a certain document should be accessed or exchanged by certain
members of staff and via regular reporting, they can easily spot infringements.

Integrate with existing and planned technologies: Any modern security
solution should be able to integrate with existing and planned technologies. In
the case of a third-party file exchange infrastructure, it is essential that any
product works with a company's existing systems, such as its directory
infrastructure, authentication processes and monitoring tools. It should be able
to integrate with other security products such as DLP solutions, and malware and
virus-checking software, and should provide an open architecture that allows
future technology advancements to be easily integrated as the company and its
requirements grow.

Providing this level of integration, not only provides the user with a sense
of familiarity when working with the system, but saves the IT huge amounts of
development and evaluation time, as the systems that are used do not need to be
scoped and acquired, but already exist within the company infrastructure.

Advertisment

Sourcing a solution that meets these three criteria, will provide any company
with a 'path of least resistance' system for third-party file exchange or
governed file exchange as Cyber-ark refers to it. A solution that not only
solves the huge security and business issue but also obeys the laws of physics
at the same time!