Please support our Tech Talk advertiser:
Jan 18th, 2008, 8:23 am
It doesn’t really matter where you live in the world, the chances are that your country has been hit by some high profile data loss scandal during the course of the last year or so. Everything from retail operations such as TJ Maxx losing the odd 40 million or so customer credit card details to a clever hacker right through to the UK Government literally losing personal and financial data about 25 million people when two discs containing a social security benefits database went missing in the post. The common thread is that there is a need for better information classification, and a consequent implementation of data protection measures based on the level of sensitivity and confidentiality that classification demands, according to the Information Security Forum (ISF).
In its latest report, the ISF suggests that because many existing approaches to information classification are overly complex they rarely deliver business benefits and are often simply ignored. "Traditional Information classification is characterised by the 'Top Secret' rubber stamp in James Bond films," says Nick Frost, the report's author and senior research consultant at the ISF. "Today, information exists in many different forms, from paper documents and verbal communications to the masses of electronic data stored, transmitted and processed. While introducing an effective enterprise wide scheme is daunting, organisations can no longer afford to ignore its importance if further embarrassing data loses are to be avoided." Information classification requires a consistent process to determine the level of confidentiality of a piece of information; the development of techniques for communicating the level of classification; and the practical implementation of measures to protect information accordingly.
According to the report the benefits of successful Information Classification are considerable, by ensuring that information is adequately protected good information classification helps to prevent over- or under-engineering of controls, so reducing potential operational overspend and unnecessary drains on resources. It can also help to enforce better access control policies and be used to demonstrate compliance for legislation such as Data Protection and Privacy along with regulations including HIPAA and Gramm-Leach Bliley.
The report highlights that to achieve these levels of success requires participation across an organisation from HR and Legal to IT and Audit, along with Board level support. "Having senior managers with a shared strategic vision and understanding of information classification and the value it can deliver is critical to overcome budgetary and organisational issues," says the ISF's Nick Frost: "It is also vital to run a successful pilot project to show a 'quick win' to demonstrate the benefits."
In its latest report, the ISF suggests that because many existing approaches to information classification are overly complex they rarely deliver business benefits and are often simply ignored. "Traditional Information classification is characterised by the 'Top Secret' rubber stamp in James Bond films," says Nick Frost, the report's author and senior research consultant at the ISF. "Today, information exists in many different forms, from paper documents and verbal communications to the masses of electronic data stored, transmitted and processed. While introducing an effective enterprise wide scheme is daunting, organisations can no longer afford to ignore its importance if further embarrassing data loses are to be avoided." Information classification requires a consistent process to determine the level of confidentiality of a piece of information; the development of techniques for communicating the level of classification; and the practical implementation of measures to protect information accordingly.
According to the report the benefits of successful Information Classification are considerable, by ensuring that information is adequately protected good information classification helps to prevent over- or under-engineering of controls, so reducing potential operational overspend and unnecessary drains on resources. It can also help to enforce better access control policies and be used to demonstrate compliance for legislation such as Data Protection and Privacy along with regulations including HIPAA and Gramm-Leach Bliley.
The report highlights that to achieve these levels of success requires participation across an organisation from HR and Legal to IT and Audit, along with Board level support. "Having senior managers with a shared strategic vision and understanding of information classification and the value it can deliver is critical to overcome budgetary and organisational issues," says the ISF's Nick Frost: "It is also vital to run a successful pilot project to show a 'quick win' to demonstrate the benefits."
This blog entry was written by Bill Andad, staff writer aka newsguy. It has received 1,804 views, 0 comments, and 11 linkbacks. 1 voter has rated this entry 5 out of 5 stars. It was promoted to featured status Jan 18th, 2008.
•
•
•
•
advice antivirus apple botnet browser business crime daniweb data database development email encryption exploit firefox forensic google government hacking hardware help information internet iphone it linux malware mcafee microsoft mobile news password phishing privacy report research search security spam spyware terrorism trojan uk virus vista vulnerability web windows worm youtube
All Recent Tags Post Comment
•
•
•
•
Only community members can start a blog or comment on blog entries. You must register or log in to contribute.
•
•
•
•
•
•
•
•
DaniWeb Tech Talk Marketplace
Related Blog Entries
- Intel To Focus on Devices, Again (9 Hours Ago)
- New Xbox 360 Dashboard next month (12 Hours Ago)
- 5-4-3-2-1 your website in infected (1 Day Ago)
- Apple ships 2.5 million Macs, sells 11 million iPods and 717,000 iPhones in just 3 months (2 Days Ago)
- Limbo 2 Trojan comes complete with guarantee of invisibility (3 Days Ago)
- More Dark Spots on Apple's MobileMe Migration (3 Days Ago)
- Power-Sipping PC Runs Linux (3 Days Ago)
- British business not getting the IM message (4 Days Ago)
- Fake UPS invoices deliver Pushdo botnet package (4 Days Ago)
- Crystal Ball Sunday #8: Virtual Appliances (4 Days Ago)
Featured Entry