Archive for November, 2008
“Fine” is a Four Letter Word
Monday, November 24, 2008 10:59 No CommentsFriends sent me the two articles below. One says more regulations (and fines) are coming. The other cites the delay of a pending regulation due to economic conditions.
Fine Likely for Data Breaches
Massachusetts extends compliance deadline on new data-encryption rules
Compliance is the #1 driver for DLP projects. I think, however, that the Massachusetts example will be the standard for [...]
Tuesday’s Tip – Build a Ship, not a Dinghy
Tuesday, November 18, 2008 19:26 1 CommentA few days ago I read a paper on DLP that caught my attention for the wrong reason. The paper was by a reputable vendor. It laid out a number of steps to secure confidential data, and generally speaking was “okay” as far as vendor papers go.
Note: I’m deliberately omitting the vendor’s name to avoid [...]
The Ten Commandments of Data Loss Prevention (DLP)
Tuesday, November 11, 2008 19:34 2 CommentsAs Data Loss Prevention (DLP) emerges as one of today’s hottest technologies, it remains among the least understood.
Organizations continue to invest in tools and processes that make information available and portable. This availability risks leaking confidential data into the public domain and potentially the hands of competitors. This year alone I’ve met with more than [...]
Tuesday’s Tip - Set Expectations
Tuesday, November 11, 2008 15:54 No CommentsAdrian at Securosis had a post today on Data Discovery and Classification. He wrote about a conversation he overheard in which an IT executive expressed his dissatisfaction with his data discovery implementation.
As I mentioned in my comment (see below), I generally attribute this sentiment to a failure to properly set expectations. Ultimately, this is a [...]
Extortionists Just Can’t Get it Right
Friday, November 7, 2008 18:08 No CommentsI’ve received multiple inquiries on this today so I thought I’d post my two cents for the record.
CNET, The New York Times, and a few other news outlets wrote a story about how some bad people threatened to reveal millions of customer records unless the healthcare provider, from whom they apparently stole the information, agreed [...]



