SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Technology

Embedded with a data leak audit team

Embedded with a data leak audit team

By:  Sandra Gittlen  On: 10 May 2009 For: IT World Canada Creator

A data leak team discovers more than 700 leaks of critical information, such as Social Security numbers, pricing, financial information and other sensitive data and 11,000 other potential leaks at a Boston-based pharmaceutical firm

Security consultancy Networks Unlimitedallowed freelance reporter Sandra Gittlen to tag along as it conducted a data leak audit at a Boston pharmaceutical firm, then presented its findings to company execs. In exchange for this type of access, we agreed not to identify the pharma firm.

When the director of IT at a Boston-based, midsize pharmaceutical firm was first approached to participate in a data leakage audit, he was thrilled. He figured the audit would uncover a few weak spots in the company's data leak defenses and he would then be able to leverage the audit results into funding for additional security resources.

"Data leakage is an area that doesn't get a lot of focus until something bad happens. Your biggest hope is that when you raise concerns about data vulnerability, someone will see the value in allowing you to move forward to protect it," the IT director says.

But he got way more than he bargained for. The 15-day audit identified 11,000 potential leaks, and revealed gaping holes in the IT team's security practices.

The audit, conducted by Networks Unlimited in Hudson, Mass., examined outbound e-mail, FTP and Web communications. The targets were leaks of general financial information, corporate plans and strategies, employee and other personal identifiable information, intellectual property and proprietary processes.

Networks Unlimited placed one tap between the corporate LAN and the firewall and a second tap between the external e-mail gateway and the firewall. Networks Unlimited used WebSense software on two servers to monitor unencrypted traffic.

Then it analyzed the traffic with respect to company policy. Specifically, Networks Unlimited looked for violations of the pharmaceutical firm's internal confidentiality policy, corporate information security policy, Massachusetts Privacy Laws (which go into effect in 2010), Health Insurance Portability and Accountability Act (HIPAA), and Security and Exchange Commission and Sarbanes-Oxley regulations.

Auditor Jason Spinosa, senior engineer at Networks Unlimited, says that while he selected the criteria for this audit, he usually recommends that companies take time to determine their policy settings based on their risk profile.


Sign up for our Newsletters












Print |  Views: 1458   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Sandra Gittlen Sandra Gittlen is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Uniform security for a diverse outsourcing world
Uniform security for a diverse outsourcing worldMathias Thurman follows the same security procedures wherever his company's partners are located. From his perspective, the only difference is in the local cuisine
IT security: it’s a process, not a project
IT security: it’s a process, not a projectExperts weigh in on the best approach to IT security. To outsource or not to outsource
Opinion Pinning down policy
Opinion Pinning down policyHow often have you heard, "I'm not sure you can do that; there isn't a policy in place?" I hear it too often, because I hate writing policies. And I hate writing policies because at a very engineering-centric company like mine, generic policies don't go over well.
Dan Swanson's Security Resources: #11
auditing information security helps identify key improvement opportunities while studying leading audit guidance provides a better understanding of what the auditors are looking for, helping make audits more productive (a true win/win).

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.